aboutsummaryrefslogtreecommitdiffstats
path: root/src
Commit message (Collapse)AuthorAge
* Merge pull request #2130 from crass/fix-2045Libravatar netblue302018-10-04
|\ | | | | FIX-2045: Fix command name parsing for program paths with spaces.
| * Fix command name parsing so that program paths with spaces do not cause the ↵Libravatar Glenn Washburn2018-10-01
| | | | | | | | wrong or no profile to be detected.
* | incomplete fix: whitelisting of symlinks to other home dirsLibravatar smitsohu2018-10-02
|/ | | | | | | | | belongs to previous commit 51eeef2059f00de117472046601e10a9fd958d51 short summary of the new behavior, which should catch a few corner cases better: - a non-existant file in another homedir (say homedirs are "/foo/user" and "/foo/user2") is silently ignored (previously a tmpfs was mounted on the users homedir, which was wrong) - a symlink pointing to an existing file in another homedir now works (but the link will be always dangling; you need --allusers to see this) - a symlink pointing back to the entire homedir now works as expected
* mount empty home if macro can't be whitelistedLibravatar smitsohu2018-10-01
|
* fs_whitelist: reduce number of loop iterationsLibravatar smitsohu2018-10-01
|
* tiny memleaksLibravatar smitsohu2018-10-01
|
* regression: fix whitelisting of symlinks to other home dirs, small improvementsLibravatar smitsohu2018-10-01
| | | | | | | | handling of home dir paths is more explicit and rigorous now, which should make it easier to audit. Also this should come handy if one day fs_private() supports home directories outside /home rf. #2123
* cleanupLibravatar smitsohu2018-09-30
|
* fixed vim missing from firecfg.configLibravatar veloute2018-09-30
|
* manpage cleanupLibravatar netblue302018-09-26
|
* manpages: fix apparmor profile pathLibravatar Vincent432018-09-22
|
* manpages: fix alignmentLibravatar Vincent432018-09-22
|
* manpages: update AppArmor infoLibravatar Vincent432018-09-22
|
* Fix check for nobody userLibravatar Reiner Herrmann2018-09-21
| | | | Fixes #2117
* 0.9.56 released0.9.56Libravatar netblue302018-09-18
|
* error stringsLibravatar smitsohu2018-09-17
|
* fix --bandwidth, --cpu.printLibravatar netblue302018-09-15
|
* exit if execl fails (arg_audit)Libravatar smitsohu2018-09-11
|
* add switch to disable/enable private-cacheLibravatar smitsohu2018-09-10
|
* small rlimits adjustmentLibravatar smitsohu2018-09-10
|
* remove seccomp warningLibravatar netblue302018-09-09
|
* Merge branch 'master' of http://github.com/netblue30/firejailLibravatar netblue302018-09-09
|\
| * set rlimits at later timepoint during sandbox setupLibravatar smitsohu2018-09-09
| |
* | support for firetunnel utilityLibravatar netblue302018-09-09
|/
* disallow overriding of global rlimits, tiny improvementsLibravatar smitsohu2018-09-06
|
* cleanupLibravatar netblue302018-09-05
|
* improve safe_fd() function for better readability and auditabilityLibravatar smitsohu2018-09-05
|
* fix --shellLibravatar netblue302018-09-03
|
* minor cleanupLibravatar netblue302018-09-03
|
* chroot problem (Debian)Libravatar netblue302018-09-03
|
* MergesLibravatar Tad2018-09-03
|
* additional restrictions for write-permissions on chrootLibravatar smitsohu2018-09-02
|
* chroot problem: default profile not configured by defaultLibravatar netblue302018-09-01
|
* --chroot fixes (Debian problem)Libravatar netblue302018-09-01
|
* error stringsLibravatar smitsohu2018-09-01
|
* consolidate and enhance checks run on chroot directory hierarchy (patch n/n)Libravatar smitsohu2018-09-01
|
* reduce number of chown/chmod calls in fs_chrootLibravatar smitsohu2018-08-31
|
* added whois and dig profilesLibravatar startx20172018-08-30
|
* little tweakLibravatar smitsohu2018-08-30
|
* reject chroot if it is world-writable, related enhancementsLibravatar smitsohu2018-08-30
|
* more silencing of /sys umount warningsLibravatar smitsohu2018-08-29
|
* cleanupLibravatar netblue302018-08-29
|
* cleanupLibravatar netblue302018-08-29
|
* silence warning about failed unmounting of /sys (overlay options)Libravatar smitsohu2018-08-29
|
* cleanupLibravatar netblue302018-08-28
|
* Revert "improve --chroot directory check"Libravatar smitsohu2018-08-28
| | | | | | this was unnecessary This reverts commit 0c2cbf05aa9553fbf5c90fb69928f2b276fead8b.
* improve --chroot directory checkLibravatar smitsohu2018-08-28
|
* fix private-tmp and private-dev in fbuilderLibravatar netblue302018-08-28
|
* Merge branch 'master' of http://github.com/netblue30/firejailLibravatar netblue302018-08-28
|\
| * Merge branch 'master' of https://github.com/netblue30/firejailLibravatar smitsohu2018-08-28
| |\