aboutsummaryrefslogtreecommitdiffstats
path: root/etc/firejail-default
Commit message (Collapse)AuthorAge
* Apparmor: minor fixesLibravatar Vincent432018-02-03
| | | | | 1. Allow for seven digit PID same as upstream do https://gitlab.com/apparmor/apparmor/commit/630cb2a981cdc731847e8fdaafc45bcd337fe747 2. Fixed dbus functionality. Disabled by default.
* apparmor support for --overlay sandboxesLibravatar netblue302018-01-24
|
* Apparmor: Revert /proc changesLibravatar Vincent432018-01-23
|
* Apparmor: fix kodi pluginsLibravatar Vincent432018-01-22
| | | | Kodi plugins need /proc/@PID/net/dev access outside user processes: AVC apparmor="DENIED" operation="open" profile="firejail-default" name="/proc/28/net/dev" pid=2354 comm="kodi.bin" requested_mask="r" denied_mask="r"
* Apparmor: restrict accessLibravatar Vincent432018-01-21
| | | Access to writable files can be restricted to their owner only.
* Revert: Escape '#' character in pathLibravatar Vincent432018-01-17
| | | | | Escaping this create warning and is dropped anyway: Warning from /etc/apparmor.d/firejail-default (/etc/apparmor.d/firejail-default line 163): Character # was quoted unnecessarily, dropped preceding quote ('\') character
* Escape '#' character in pathLibravatar Vincent432018-01-05
|
* Apparmor: fix broken file dialogs in kde plasmaLibravatar Vincent432018-01-04
| | | | | | | | | For some time apparmor started breaking file dialogs in kde plasma (gwenview, calibre, qbittorrent, etc). typical audit report below: AVC apparmor="DENIED" operation="open" profile="firejail-default" name="/run/user/1000/#28520" pid=1997 comm="qbittorrent" requested_mask="w" denied_mask="w" fsuid=1000 ouid=1000 AVC apparmor="DENIED" operation="link" profile="firejail-default" name="/run/user/1000/qBittorrentZcaeTi.1.slave-socket" pid=3679 comm="qbittorrent" requested_mask="l" denied_mask="l" fsuid=1000 ouid=1000 target="/run/user/1000/#79965" This commit fixes this issue. Tested on Archlinux (linux 4.14.11, kde 5.11.5)
* apparmorLibravatar netblue302017-10-12
|
* Enumerate root directories in apparmor profileLibravatar Antonio Russo2017-10-03
| | | | | Replace opaque character class with an explicit list of root-level directories to be granted access.
* Merge pull request #1426 from VladimirSchowalter20/masterLibravatar startx20172017-08-02
|\ | | | | Apparmor: add local configuration
| * Minor fix for completnessLibravatar Vladimir Schowalter2017-08-02
| |
| * Apparmor: add local configurationLibravatar Vladimir Schowalter2017-08-02
| |
* | Apparmor: update whitelist path for kdeLibravatar Vladimir Schowalter2017-08-02
|/
* Add some /proc dirs to firejail apparmor profileLibravatar Vladimir Schowalter2017-08-02
|
* apparmor fixesLibravatar netblue302017-07-21
|
* remove trailing whitespace from etc/Libravatar Fred Barclay2017-05-24
|
* apparmor/appimage supportLibravatar netblue302016-10-09
|
* apparmor fixLibravatar netblue302016-10-04
|
* apparmor fixes for Arch LinuxLibravatar netblue302016-08-04
|
* apparmorLibravatar netblue302016-08-03
|
* apparmorLibravatar netblue302016-08-02