From 008bc7fedcb1094116d09649ef52befaa0cb08cf Mon Sep 17 00:00:00 2001 From: Sebastian Hafner <32019589+DropNib@users.noreply.github.com> Date: Wed, 17 Jul 2019 19:08:48 +0200 Subject: document profile support for allow-debuggers in firejail-profile man page (#2861) --- src/man/firejail-profile.txt | 3 +++ 1 file changed, 3 insertions(+) (limited to 'src/man/firejail-profile.txt') diff --git a/src/man/firejail-profile.txt b/src/man/firejail-profile.txt index f97261456..74f99b538 100644 --- a/src/man/firejail-profile.txt +++ b/src/man/firejail-profile.txt @@ -336,6 +336,9 @@ directory, and a skeleton filesystem is created based on the original /var/log. .SH Security filters The following security filters are currently implemented: +.TP +\fBallow-debuggers +Allow tools such as strace and gdb inside the sandbox by whitelisting system calls ptrace and process_vm_readv. .TP \fBapparmor Enable AppArmor confinement. -- cgit v1.2.3-54-g00ecf