[PR #1103] [MERGED] Update unbound profile to block 3D acceleration. #3847

Closed
opened 2026-05-05 10:09:02 -06:00 by gitea-mirror · 0 comments
Owner

📋 Pull Request Information

Original PR: https://github.com/netblue30/firejail/pull/1103
Author: @Ferroin
Created: 2/15/2017
Status: Merged
Merged: 2/17/2017
Merged by: @netblue30

Base: masterHead: patch-1


📝 Commits (1)

  • fe45ca4 Update unbound profile to block 3D acceleration.

📊 Changes

1 file changed (+1 additions, -0 deletions)

View changed files

📝 etc/unbound.profile (+1 -0)

📄 Description

There is no legitimate reason for a caching DNS resolver to need 3D acceleration. Unbound adheres to this already, so any attempts to access GPU hardware from it are by definition either bugs or the result of an exploit, so let's just block access to the GPU.

Tested on my local systems with about 2 dozen different permutations of unbound configuration, double checked by looking through the source code for Unbound.


🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.

## 📋 Pull Request Information **Original PR:** https://github.com/netblue30/firejail/pull/1103 **Author:** [@Ferroin](https://github.com/Ferroin) **Created:** 2/15/2017 **Status:** ✅ Merged **Merged:** 2/17/2017 **Merged by:** [@netblue30](https://github.com/netblue30) **Base:** `master` ← **Head:** `patch-1` --- ### 📝 Commits (1) - [`fe45ca4`](https://github.com/netblue30/firejail/commit/fe45ca43c468a21e225a05beda867f93db88f897) Update unbound profile to block 3D acceleration. ### 📊 Changes **1 file changed** (+1 additions, -0 deletions) <details> <summary>View changed files</summary> 📝 `etc/unbound.profile` (+1 -0) </details> ### 📄 Description There is no legitimate reason for a caching DNS resolver to need 3D acceleration. Unbound adheres to this already, so any attempts to access GPU hardware from it are by definition either bugs or the result of an exploit, so let's just block access to the GPU. Tested on my local systems with about 2 dozen different permutations of unbound configuration, double checked by looking through the source code for Unbound. --- <sub>🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.</sub>
gitea-mirror 2026-05-05 10:09:02 -06:00
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference: github-starred/firejail#3847
No description provided.