aboutsummaryrefslogtreecommitdiffstats
path: root/etc
Commit message (Collapse)AuthorAge
* add Fedora fixLibravatar glitsj162021-11-10
| | | | Added Fedora path as per https://github.com/netblue30/firejail/pull/4675#pullrequestreview-802438767. NOTE: there are several other profiles touching /usr/libexec, so untill someone on Fedora can shed some light on what files are installed under /usr/libexec, I only blacklisted ssh-keysign. I'll pick this up tomorrow, a bit pressed for time in the non-digital worlds...
* add Fedora fixesLibravatar glitsj162021-11-10
| | | Added Fedora path as per https://github.com/netblue30/firejail/pull/4675#pullrequestreview-802438767.
* fixes for sshLibravatar glitsj162021-11-10
| | | Counterpart fix for changes in allow-ssh.inc.
* fixes for sshLibravatar glitsj162021-11-10
| | | After seeing https://github.com/netblue30/firejail/commit/9a81078ddbbb4215d06f7d1861481ece05ebda99 it dawned on me that Arch Linux doesn't have /usr/lib/openssh, but uses /usr/lib/ssh instead. That's a different path than what's referenced in our current {allow-ssh,disable-common}.inc files. Some very superficial checks revealed that OpenSSH seems to be packaged quite differently, at least on Debian/Ubuntu and Arch Linux. And then there's version differences on non-rolling distro's to consider. All in all IMO it makes more sense to (no)blacklist /usr/lib/openssh and /usr/lib/ssh instead of referencing all the possible individual files that live under those paths.
* disable-common.inc: fix sshLibravatar netblue302021-11-09
|
* disable-common.inc: more SUIDLibravatar netblue302021-11-09
|
* disable-common.inc: vmware SUID binariesLibravatar netblue302021-11-09
|
* disable-common.inc: disable chrome-sandboxLibravatar netblue302021-11-09
|
* disable-common.inc: blacklist sshLibravatar netblue302021-11-09
|
* adding more SUID executables to disable-common.incLibravatar netblue302021-11-04
|
* apparmor base drop-in: remove chroot/overlay pathsLibravatar smitsohu2021-11-01
| | | | | | As the upstream AppArmor base abstraction does not contain references to paths in /run/firejail/mnt/oroot there is not much point to have them in our drop-in
* ids: add some more pathsLibravatar smitsohu2021-10-31
|
* adding noprofile.profile from rusty-snakeLibravatar netblue302021-10-30
|
* Merge pull request #4643 from rusty-snake/profile-checksLibravatar Kelvin M. Klann2021-10-29
|\ | | | | Profile Checks
| * Sort disaple-programs.incLibravatar rusty-snake2021-10-27
| |
| * Add alteratives and ld.so.cache to all private-etc linesLibravatar rusty-snake2021-10-27
| | | | | | | | Command is the same as in d8d97acb
* | update mpv.profileLibravatar pirate4867431862021-10-24
|/ | | add yt-dlp in private-bin
* Add disable-proc to firefox-commonLibravatar rusty-snake2021-10-23
|
* Remove 'none' from private-etc linesLibravatar rusty-snake2021-10-23
|
* wrc: whitelist journal socketsLibravatar smitsohu2021-10-23
| | | | fixes --tracelog among other things
* add wrc to several profilesLibravatar smitsohu2021-10-23
|
* promote /run/udev/data to wrcLibravatar smitsohu2021-10-23
|
* disable-exec: add /run/shmLibravatar smitsohu2021-10-23
|
* Merge pull request #4628 from smitsohu/aaLibravatar netblue302021-10-21
|\ | | | | add basic Firejail support to AppArmor base abstraction (#3226)
| * add basic Firejail support to AppArmor base abstraction (#3226)Libravatar smitsohu2021-10-21
| |
* | Merge pull request #4600 from crocket/masterLibravatar netblue302021-10-21
|\ \ | | | | | | Add profiles for imv, retroarch, and torbrowser
| * | Add profiles for imv, retroarch, and torbrowserLibravatar crocket2021-10-17
| | | | | | | | | | | | | | | imv, retroarch, and torbrowser are also added to firecfg.config
* | | Merge pull request #4612 from jose1711/blobwars_fixLibravatar netblue302021-10-21
|\ \ \ | | | | | | | | blobwars: add path to game assets compatible with Arch
| * | | blobwars: add path to game assets compatible with ArchLibravatar Jose Riha2021-10-17
| | | |
* | | | Merge pull request #4613 from jose1711/joystick_supportLibravatar netblue302021-10-21
|\ \ \ \ | | | | | | | | | | Drop noinput for games with joystick/gamepad support
| * | | | Drop noinput for games with joystick/gamepad supportLibravatar Jose Riha2021-10-17
| |/ / / | | | | | | | | | | | | Fixes #4608
* | | | Merge pull request #4621 from jose1711/tremulous_archfixLibravatar netblue302021-10-21
|\ \ \ \ | | | | | | | | | | Fix tremulous profile for Arch users
| * | | | Update etc/profile-m-z/tremulous.profileLibravatar Jose Riha2021-10-19
| | | | | | | | | | | | | | | Co-authored-by: Kelvin M. Klann <kmk3.code@protonmail.com>
| * | | | Update etc/profile-m-z/tremulous.profileLibravatar Jose Riha2021-10-19
| | | | | | | | | | | | | | | Co-authored-by: Kelvin M. Klann <kmk3.code@protonmail.com>
| * | | | Update etc/profile-m-z/tremulous.profileLibravatar Jose Riha2021-10-19
| | | | | | | | | | | | | | | Co-authored-by: rusty-snake <41237666+rusty-snake@users.noreply.github.com>
| * | | | Fix tremulous profile for Arch usersLibravatar Jose Riha2021-10-18
| |/ / /
* | | | Merge pull request #4622 from jose1711/jumnbump_fixLibravatar netblue302021-10-21
|\ \ \ \ | | | | | | | | | | Fix jumpnbump for Arch users
| * | | | Fix jumpnbump for Arch usersLibravatar Jose Riha2021-10-19
| |/ / / | | | | | | | | | | | | Fixes #4611.
* | | | Merge pull request #4624 from jose1711/warsow_archfixLibravatar netblue302021-10-21
|\ \ \ \ | | | | | | | | | | Fix warsow profile for Arch users
| * | | | Update etc/profile-m-z/warsow.profileLibravatar Jose Riha2021-10-19
| | | | | | | | | | | | | | | Co-authored-by: Kelvin M. Klann <kmk3.code@protonmail.com>
| * | | | Update etc/profile-m-z/warsow.profileLibravatar Jose Riha2021-10-19
| | | | | | | | | | | | | | | Co-authored-by: rusty-snake <41237666+rusty-snake@users.noreply.github.com>
| * | | | Update etc/profile-m-z/warsow.profileLibravatar Jose Riha2021-10-19
| | | | | | | | | | | | | | | Co-authored-by: rusty-snake <41237666+rusty-snake@users.noreply.github.com>
| * | | | Fix warsow profile for Arch usersLibravatar Jose Riha2021-10-19
| |/ / / | | | | | | | | | | | | | | | | | | | | Warsow uses a shell wrapper hence requires some modifications. Netlink was added to protocols as the game was segfaulting after changing resolution and saving the setting.
* | | | Merge pull request #4521 from rusty-snake/disable-proc.incLibravatar smitsohu2021-10-20
|\ \ \ \ | |/ / / |/| | | Create disable-proc.inc
| * | | Update disable-proc.incLibravatar rusty-snake2021-10-09
| | | |
| * | | Update disable-proc.incLibravatar rusty-snake2021-09-10
| | | |
| * | | Create disable-proc.incLibravatar rusty-snake2021-09-09
| | | |
* | | | add /run/shm to wrcLibravatar smitsohu2021-10-16
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | found in Debian Bullseye. /run/shm is a symbolic link to /dev/shm, and whitelisting it will just recreate the symbolic link.
* | | | Merge pull request #4599 from rusty-snake/use-allow-trayLibravatar netblue302021-10-10
|\ \ \ \ | | | | | | | | | | Use ?ALLOW_TRAY: (#4510) in profiles
| * | | | Use ?ALLOW_TRAY: (#4510) in profilesLibravatar rusty-snake2021-10-09
| | |/ / | |/| |