firejail/etc
Shahriar Heidrich 533db20e99
profiles: blacklist i3 IPC socket & dir except for i3 itself (#6361)
This closes the escape route discussed in #6357.

It's left open for i3's own profile, so that people who run i3 itself
sandboxed still have the option to use IPC with it at all.

Reference for file paths:
https://i3wm.org/docs/userguide.html#_interprocess_communication
2024-06-08 08:52:17 +00:00
..
apparmor firejail-local: be less restrictive with torbrowser-launcher 2024-03-16 15:49:07 +00:00
inc profiles: blacklist i3 IPC socket & dir except for i3 itself (#6361) 2024-06-08 08:52:17 +00:00
net fix nolocal netfilter 2022-10-25 14:33:56 -04:00
profile-a-l profiles: blacklist i3 IPC socket & dir except for i3 itself (#6361) 2024-06-08 08:52:17 +00:00
profile-m-z profiles: streamline Firefox URL opening support (#6348) 2024-05-20 05:06:41 +00:00
templates profiles: clarify and add opengl-game to profile.template (#6300) 2024-04-05 12:09:04 +00:00
firejail.config profiles: Miscellaneous cleanups (#5918) 2023-07-25 19:32:12 +00:00
ids.config disable-common.inc: blacklist sudo/doas paths in /etc 2023-07-14 08:08:47 -03:00
login.users