From d073a425b3e3ed3829a0e042e8c41963f0f40f0e Mon Sep 17 00:00:00 2001 From: netblue30 Date: Thu, 9 Jun 2016 08:42:59 -0400 Subject: whitelist support in /etc/firejail/firejail.config --- src/man/firejail-config.txt | 19 +++++++++++-------- 1 file changed, 11 insertions(+), 8 deletions(-) (limited to 'src/man/firejail-config.txt') diff --git a/src/man/firejail-config.txt b/src/man/firejail-config.txt index 026765f1a..6a66c7f75 100644 --- a/src/man/firejail-config.txt +++ b/src/man/firejail-config.txt @@ -25,6 +25,13 @@ Enable or disable chroot support, default enabled. \fBfile-transfer Enable or disable file transfer support, default enabled. +.TP +\fBforce-nonewprivs +Force use of nonewprivs. This mitigates the possibility of +a user abusing firejail's features to trick a privileged (suid +or file capabilities) process into loading code or configuration +that is partially under their control. Default disabled. + .TP \fBnetwork Enable or disable networking features, default enabled. @@ -45,16 +52,12 @@ Enable or disable seccomp support, default enabled. Enable or disable user namespace support, default enabled. .TP -\fBx11 -Enable or disable X11 sandboxing support, default enabled. +\fBwhitelist +Enable or disable whitelisting support, default enabled. .TP -\fBforce-nonewprivs -Force use of nonewprivs. This mitigates the possibility of -a user abusing firejail's features to trick a privileged (suid -or file capabilities) process into loading code or configuration -that is partially under their control. Default disabled. - +\fBx11 +Enable or disable X11 sandboxing support, default enabled. .TP \fBxephyr-screen -- cgit v1.2.3-70-g09d2