Commit message (Collapse) | Author | Age | |
---|---|---|---|
* | overlayfs work, fixed hedgwoars profile | netblue30 | 2016-03-17 |
| | |||
* | cfg chroot, seccomp | netblue30 | 2016-03-13 |
| | |||
* | cfg userns | netblue30 | 2016-03-13 |
| | |||
* | cfg bind | netblue30 | 2016-03-12 |
| | |||
* | cfg x11 | netblue30 | 2016-03-12 |
| | |||
* | fixes | netblue30 | 2016-03-12 |
| | |||
* | build fixes | netblue30 | 2016-03-12 |
| | |||
* | file transfer fixes | netblue30 | 2016-03-12 |
| | |||
* | compile time support to disable file transfer | netblue30 | 2016-03-12 |
| | |||
* | file transfer feature | netblue30 | 2016-03-11 |
| | |||
* | file transfer feature | netblue30 | 2016-03-11 |
| | |||
* | nosound support in profile files | netblue30 | 2016-03-11 |
| | |||
* | file transfer options | netblue30 | 2016-03-11 |
| | |||
* | --get option | netblue30 | 2016-03-11 |
| | |||
* | cleanup | netblue30 | 2016-03-10 |
| | |||
* | Merge pull request #363 from ligthyear/fixing-exit-code | netblue30 | 2016-03-10 |
|\ | | | | | Forward exit code from child process | ||
| * | Forward exit code from child process | Benjamin Kampmann | 2016-03-10 |
| | | | | | | | | | | | | | | | | This changeset reads the status code of the child process run inside the sandbox and forwards it to the outer process. Which in turn makes that result its own exiting status code. Fixes #358 | ||
* | | centos8 user namespace fix | netblue30 | 2016-03-10 |
| | | |||
* | | overlayfs fix for home directories mounted on a different partition | netblue30 | 2016-03-10 |
| | | |||
* | | overlay fix | netblue30 | 2016-03-10 |
| | | |||
* | | fix overlayfs problem | netblue30 | 2016-03-09 |
|/ | |||
* | fixes | netblue30 | 2016-03-09 |
| | |||
* | fs work | netblue30 | 2016-03-08 |
| | |||
* | logging fixes | netblue30 | 2016-03-07 |
| | |||
* | fixes | netblue30 | 2016-03-05 |
| | |||
* | documentation | netblue30 | 2016-03-04 |
| | |||
* | --ls | netblue30 | 2016-03-04 |
| | |||
* | --ls | netblue30 | 2016-03-04 |
| | |||
* | cleanup | netblue30 | 2016-03-03 |
| | |||
* | debugging | netblue30 | 2016-03-02 |
| | |||
* | cleanup | netblue30 | 2016-03-02 |
| | |||
* | added ipc-namespace profile command | netblue30 | 2016-03-02 |
| | |||
* | sshd fixes | netblue30 | 2016-03-01 |
| | |||
* | scp fixes | netblue30 | 2016-03-01 |
| | |||
* | fix typo | Vasya Novikov | 2016-03-01 |
| | |||
* | firemon fixes | netblue30 | 2016-02-29 |
| | |||
* | various fixes | netblue30 | 2016-02-28 |
| | |||
* | firemon fixes | netblue30 | 2016-02-27 |
| | |||
* | man page fixes | netblue30 | 2016-02-27 |
| | |||
* | Merge branch 'master' of https://github.com/netblue30/firejail | netblue30 | 2016-02-26 |
|\ | |||
| * | Fix manual typo | andrew160 | 2016-02-26 |
| | | |||
* | | x11 support | netblue30 | 2016-02-26 |
|/ | |||
* | x11 fixes | netblue30 | 2016-02-25 |
| | |||
* | x11 work | netblue30 | 2016-02-24 |
| | |||
* | x11 work | netblue30 | 2016-02-24 |
| | |||
* | allow --interface only to root user for --enable-network=restricted | netblue30 | 2016-02-24 |
| | |||
* | x11 work | netblue30 | 2016-02-24 |
| | |||
* | Merge branch 'master' of https://github.com/netblue30/firejail | netblue30 | 2016-02-24 |
|\ | |||
| * | Merge pull request #319 from yumkam/network-restricted | netblue30 | 2016-02-24 |
| |\ | | | | | | | Add compile-time option to restrict --net= to root only | ||
| | * | Add compile-time option to restrict --net= to root only | Yuriy M. Kaminskiy | 2016-02-23 |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | ./configure --enable-network=restricted allows only --net=none to non-root users. Other variants delegate too much power to non-root users and dangerous (it completely bypasses system-wide firewall and routing, it allows introducing arbitrary-chosen MAC and IP interfaces on LAN [disregarding DHCP policy], etc). Root already had power to twiddle with anything, so no sense to restrain her, and --net=none looks safe enough (and still useful) for ordinary users. |