From f61820a0a16c5751c96cff154e12d3cfe374ba99 Mon Sep 17 00:00:00 2001 From: netblue30 Date: Wed, 4 Oct 2017 08:44:52 -0400 Subject: removed lxterminal support, blacklisting the terminal in disable-common.inc --- etc/disable-common.inc | 1 + etc/lxterminal.profile | 19 ------------------- 2 files changed, 1 insertion(+), 19 deletions(-) delete mode 100644 etc/lxterminal.profile diff --git a/etc/disable-common.inc b/etc/disable-common.inc index d943950d4..021e6349e 100644 --- a/etc/disable-common.inc +++ b/etc/disable-common.inc @@ -290,6 +290,7 @@ blacklist /tmp/.lxterminal-socket* blacklist /tmp/tmux-* # disable terminals running as server resulting in sandbox escape +blacklist ${PATH}/lxterminal blacklist ${PATH}/gnome-terminal blacklist ${PATH}/gnome-terminal.wrapper blacklist ${PATH}/lilyterm diff --git a/etc/lxterminal.profile b/etc/lxterminal.profile deleted file mode 100644 index dbbd1ace0..000000000 --- a/etc/lxterminal.profile +++ /dev/null @@ -1,19 +0,0 @@ -# Firejail profile for lxterminal -# This file is overwritten after every install/update -# Persistent local customizations -include /etc/firejail/lxterminal.local -# Persistent global definitions -include /etc/firejail/globals.local - - -include /etc/firejail/disable-common.inc -include /etc/firejail/disable-passwdmgr.inc -include /etc/firejail/disable-programs.inc - -caps.drop all -netfilter -# noroot - somehow this breaks on Debian Jessie! -nodvd -notv -protocol unix,inet,inet6 -seccomp -- cgit v1.2.3-54-g00ecf