Commit message (Collapse) | Author | Age | |
---|---|---|---|
* | Fix AppArmor 3.0 support (closes #3659) | Kristóf Marussy | 2020-10-10 |
| | | | | | | | | | | | | AppArmor introduces the @{run} variable, which is used in <abstractions/dbus-strict> and <abstractions/dbus-session-strict> among other places. Thus, we follow suit of the built-in profiles and #include <tunables/global>, which includes <tunables/run> in AppArmor 3.0, defining the variable. As <tunables/global> exists in previous versions of AppArmor, too, this patch does not introduce a backward-compatibility issue with Apparmor 2.x. | ||
* | build: add -fPIE to LDFLAGS | Reiner Herrmann | 2020-10-08 |
| | | | | | | | according to GCC documentation (https://gcc.gnu.org/onlinedocs/gcc/Link-Options.html): "For predictable results, you must also specify the same set of options used for compilation (-fpie, -fPIE, or model suboptions) when you specify this linker option." | ||
* | build: let manpages depend on src/man target instead of non-existing .man files | Reiner Herrmann | 2020-10-06 |
| | |||
* | build: fail mkman.sh when one of the commands fails | Reiner Herrmann | 2020-10-06 |
| | |||
* | Merge pull request #3657 from netblue30/selinux | Reiner Herrmann | 2020-10-06 |
|\ | |||
| * | selinux: exit when selinux is enabled but opening handle fails | Reiner Herrmann | 2020-10-06 |
| | | |||
| * | selinux: don't try to relabel path when selinux is not enabled | Reiner Herrmann | 2020-10-06 |
| | | | | | | | | Fixes: #3654 | ||
* | | Merge pull request #3656 from Neo00001/patch-1 | rusty-snake | 2020-10-06 |
|\ \ | |/ |/| | Update vmware.profile | ||
| * | Update vmware.profile | Neo00001 | 2020-10-06 |
| | | | | | | With private-etc enabled vmware-tools doesn't get installed. Existing VM with an installed vmware-tools works as usual. For the time being keep it commented. | ||
* | | fix indentation | Reiner Herrmann | 2020-10-06 |
|/ | |||
* | Revert "install vim files to addons directory instead of vimfiles" | rusty-snake | 2020-10-06 |
| | | | | | | | | | This reverts commit 4422ce65a9d1e903e583d0f2eca9dc1ee7c839e9. ------ Revert for now as it breaks on some distros (namely Fedora), see https://github.com/netblue30/firejail/commit/4422ce65a9d1e903e583d0f2eca9dc1ee7c839e9#commitcomment-42999952 | ||
* | DHCP fixes | netblue30 | 2020-10-06 |
| | |||
* | install vim files to addons directory instead of vimfiles | Reiner Herrmann | 2020-10-05 |
| | |||
* | Fix typo | Reiner Herrmann | 2020-10-05 |
| | |||
* | Fix spelling | Reiner Herrmann | 2020-10-05 |
| | |||
* | testing | netblue30 | 2020-10-05 |
| | |||
* | set as 0.9.64rc2 for development until we release the real one | netblue30 | 2020-10-05 |
| | |||
* | testing 0.9.64rc1 - disable dumpable working for this release, problems on ↵0.9.64rc1 | netblue | 2020-10-04 |
| | | | | Debian8; we will bring it back in the next release | ||
* | testing 0.9.64rc1 | netblue30 | 2020-10-04 |
| | |||
* | move to addgroup --system (#3632) | netblue30 | 2020-10-03 |
| | |||
* | document compile-time dependency on gawk | netblue30 | 2020-10-03 |
| | |||
* | make test-compile for disable manpages | netblue30 | 2020-10-03 |
| | |||
* | Merge branch 'master' of https://github.com/netblue30/firejail | netblue30 | 2020-10-03 |
|\ | |||
| * | New profile: equalx | rusty-snake | 2020-10-03 |
| | | |||
| * | chromium-freeworld profile (#3633) | rusty-snake | 2020-10-03 |
| | | |||
* | | replaced --enable-man with --disable-man in ./configure | netblue30 | 2020-10-03 |
|/ | |||
* | more on email change | netblue30 | 2020-10-03 |
| | |||
* | Update SECURITY.md | netblue30 | 2020-10-03 |
| | |||
* | changed email address to netblue30 at protonmail dot com | netblue30 | 2020-10-03 |
| | |||
* | Merge pull request #3652 from monich/disable-man | netblue30 | 2020-10-03 |
|\ | | | | | added configure option to disable man pages | ||
| * | added configure option to disable man pages | Slava Monich | 2020-10-03 |
| | | | | | | | | Those are unnecessary in embedded environment. | ||
* | | more nvidia (#3644) | netblue30 | 2020-10-03 |
|/ | |||
* | temporary fix for nvidia/nogroups/noroot issue (#3644, #841) | netblue30 | 2020-10-02 |
| | |||
* | profstats - add count for whitelisted home dir, dbus-user none | netblue30 | 2020-10-02 |
| | |||
* | splitting up media players whitelists in whitelist-players.inc - relnotes | netblue30 | 2020-10-02 |
| | |||
* | splitting up media players whitelists in whitelist-players.inc | netblue30 | 2020-10-02 |
| | |||
* | build: test build with apparmor and selinux in CI | Reiner Herrmann | 2020-10-01 |
| | |||
* | build: drop clang build as it is already checked by github | Reiner Herrmann | 2020-10-01 |
| | |||
* | build: enable clang-10 build in github CI | Reiner Herrmann | 2020-10-01 |
| | |||
* | fix build with clang | Reiner Herrmann | 2020-10-01 |
| | | | | error: adding 'int' to a string does not append to the string [-Werror,-Wstring-plus-int] | ||
* | build: remove -pie from CFLAGS, as it is a linker option | Reiner Herrmann | 2020-10-01 |
| | | | | building with clang printed a warning | ||
* | build: remove jobs from gitlab CI that are already check by github | Reiner Herrmann | 2020-10-01 |
| | |||
* | Create build.yml (#3651) | Reiner Herrmann | 2020-10-01 |
| | |||
* | build: check building with static analyzer in CI | Reiner Herrmann | 2020-10-01 |
| | |||
* | some cleanup for the previous commit (#3530) | netblue30 | 2020-10-01 |
| | |||
* | don't execute include disable-shell.inc for appimages (#3530) | netblue30 | 2020-10-01 |
| | |||
* | document private-bin and private-lib disabled by default when running ↵ | netblue30 | 2020-10-01 |
| | | | | appimages (#3530) | ||
* | disable /pulse for --nosound (#3263) | netblue30 | 2020-10-01 |
| | |||
* | replaced --nowrap with --wrap in firemon (#2992) | netblue30 | 2020-10-01 |
| | |||
* | print error for /home/netblue in profile files (#3071) | netblue30 | 2020-10-01 |
| |