From eaf30fc536c22340bc3a15217f11edb749d73ff4 Mon Sep 17 00:00:00 2001 From: netblue30 Date: Sat, 2 Feb 2019 12:45:29 -0500 Subject: remove noexec home from chromium-based browsers --- RELNOTES | 3 +++ etc/chromium-common.profile | 3 ++- 2 files changed, 5 insertions(+), 1 deletion(-) diff --git a/RELNOTES b/RELNOTES index 02bceb2be..97020115f 100644 --- a/RELNOTES +++ b/RELNOTES @@ -1,5 +1,8 @@ firejail (0.9.59) baseline; urgency=low * work in progress + * cgroup flag in /etc/firejail/firejail.config file + * name-change flag in /etc/firejail.config file + * --name rework * enable/disable cgroup in firejail.config -- netblue30 Sun, 27 Jan 2019 08:00:00 -0500 diff --git a/etc/chromium-common.profile b/etc/chromium-common.profile index 13ed13058..7d8bc15ba 100644 --- a/etc/chromium-common.profile +++ b/etc/chromium-common.profile @@ -34,7 +34,8 @@ disable-mnt private-dev # private-tmp - problems with multiple browser sessions -noexec ${HOME} +# breaks DRM binaries +#noexec ${HOME} noexec /tmp # the file dialog needs to work without d-bus -- cgit v1.2.3-54-g00ecf