From 3bfb00f627f5d4ff6879d886165fb751868527b0 Mon Sep 17 00:00:00 2001 From: netblue30 Date: Sun, 16 Aug 2015 15:43:50 -0400 Subject: removed mknod from default seccomp filter, some software packages are using named pipes created with mknod --- src/man/firejail.txt | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) (limited to 'src/man/firejail.txt') diff --git a/src/man/firejail.txt b/src/man/firejail.txt index 3e399db72..0b7ed1434 100644 --- a/src/man/firejail.txt +++ b/src/man/firejail.txt @@ -742,7 +742,7 @@ $ firejail \-\-net=eth0 \-\-scan \fB\-\-seccomp Enable seccomp filter and blacklist the syscalls in the default list. The default list is as follows: mount, umount2, ptrace, kexec_load, open_by_handle_at, init_module, finit_module, delete_module, -iopl, ioperm, swapon, swapoff, mknode, syslog, process_vm_readv and process_vm_writev, +iopl, ioperm, swapon, swapoff, syslog, process_vm_readv and process_vm_writev, sysfs,_sysctl, adjtimex, clock_adjtime, lookup_dcookie, perf_event_open, fanotify_init and kcmp. .br -- cgit v1.2.3-70-g09d2