firejail/contrib
Kelvin M. Klann 760f50f78a landlock: move commands into profile and add landlock.enforce
Changes:

* Move commands from --landlock and --landlock.proc= into
  etc/inc/landlock-common.inc
* Remove --landlock and --landlock.proc=
* Add --landlock.enforce

Instead of hard-coding the default commands (and having a separate
command just for /proc), move them into a dedicated profile to make it
easier for users to interact with the entries (view, copy, add ignore
entries, etc).

Only enforce the Landlock commands if --landlock.enforce is supplied.
This allows safely adding Landlock commands to (upstream) profiles while
keeping their enforcement opt-in.  It also makes it simpler to
effectively disable all Landlock commands, by using
`--ignore=landlock.enforce`.

Relates to #6078.
2023-12-11 22:47:11 -03:00
..
syntax landlock: move commands into profile and add landlock.enforce 2023-12-11 22:47:11 -03:00
vim/ftdetect contrib/vim: match profile files more broadly 2023-06-10 14:16:41 -03:00
fix_private-bin.py fix spelling (#4573) 2021-09-22 23:05:33 +02:00
fj-mkdeb.py Update copyright to 2023 (#5664) 2023-02-15 18:57:44 +00:00
fjclip.py Update copyright to 2023 (#5664) 2023-02-15 18:57:44 +00:00
fjdisplay.py Update copyright to 2023 (#5664) 2023-02-15 18:57:44 +00:00
fjresize.py Update copyright to 2023 (#5664) 2023-02-15 18:57:44 +00:00
gdb-firejail.sh *.sh: use consistent indentation 2023-02-20 17:39:31 -03:00
jail_prober.py build: fix codespell errors in more files 2023-08-13 23:23:27 -03:00
sort.py build: sort.py: use case-sensitive sorting 2023-10-27 16:40:39 -03:00
syscalls.sh *.sh: use consistent indentation 2023-02-20 17:39:31 -03:00
update_deb.sh Merge pull request #5668 from kmk3/build-deb-apparmor-default 2023-02-17 09:16:56 -05:00