60 Commits

Author SHA256 Message Date
f73898aa29 Accepting request 1298122 from Virtualization
Automatic submission by obs-autosubmit

OBS-URL: https://build.opensuse.org/request/show/1298122
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/firejail?expand=0&rev=22
2025-08-07 14:49:57 +00:00
17accc71d2 Accepting request 1294517 from Virtualization
- update to version 0.9.74:
  * security: fix sscanf rv checks (CodeQL) (#6184)
  * feature: private-etc rework: improve handling of /etc/resolv.conf and add
  * private-etc groups (#6400 #5518 #5608 #5609 #5629 #5638 #5641 #5642 #5643
  * #5650 #5681 #5737 #5844 #5989 #6016 #6104 #5655 #6435 #6514 #6515)
  * feature: Add "keep-shell-rc" command and option (#1127 #5634)
  * feature: Print the argument when failing with "too long arguments" (#5677)
  * feature: a random hostname is assigned to each sandbox unless
  * overwritten using --hostname command
  * feature: add IPv6 support for --net.print option
  * feature: QUIC (HTTP/3) support in --nettrace
  * feature: add seccomp filters for --restrict-namespaces
  * feature: stats support for --nettrace
  * feature: add doas support in firecfg and jailcheck (#5899 #5900)
  * feature: firecfg: add firecfg.d & add ignore command (#2097 #5245 #5876
  * #6153 #6268)
  * feature: expand simple macros in more commands (--chroot= --netfilter=
  * --netfilter6= --trace=) (#6032 #6109)
  * feature: add Landlock support (#5269 #6078 #6115 #6125 #6187 #6195 #6200
  * #6228 #6260 #6302 #6305)
  * feature: add support for comm, coredump, and prctl procevents in firemon
  * (#6414 #6415)
  * feature: add notpm command & keep tpm devices in private-dev (#6379 #6390)
  * feature: fshaper.sh: support tc on NixOS (#6426 #6431)
  * feature: add aarch64 syscalls (#5821 #6574)
  * feature: add --disable-sandbox-check configure flag (#6592)
  * feature: block /dev/ntsync & add keep-dev-ntsync command (#6655 #6660)
  * modif: Stop forwarding own double-dash to the shell (#5599 #5600)
  * modif: Prevent sandbox name (--name=) and host name (--hostname=)
  * from containing only digits (#5578 #5741)
  * modif: Escape control characters of the command line (#5613)
  * modif: Allow mostly only ASCII letters and digits for sandbox name
  * (--name=) and host name (--hostname=) (#5708 #5856)
  * modif: make private-lib a configure-time option, disabled by default (see
  * --enable-private-lib) (#5727 #5732)
  * modif: Improve --version/--help & print version on startup (#5829 #6172)
  * modif: improve errExit error messages (#5871)
  * modif: drop deprecated 'shell' option references (#5894)
  * modif: keep pipewire group unless nosound is used (#5992 #5993)
  * modif: fcopy: use lstat when copying directory (#5378 #5957)
  * modif: private-dev: keep /dev/kfd unless no3d is used (#6380)
  * modif: keep /sys/module/nvidia* if prop driver and no no3d (#6372 #6387)
  * modif: clarify error messages in profile.c (#6605)
  * modif: keep plugdev group unless nou2f is used (#6664)
  * removal: firemon: remove --interface option (it duplicates the firejail
  * --net.print= option) (0e48f99)
  * removal: remove support for LTS and firetunnel (db09546)
  * bugfix: fix --hostname and --hosts-file commands
  * bugfix: fix examples in firejail-local AppArmor profile (#5717)
  * bugfix: arp.c: ensure positive timeout on select(2) (#5806)
  * bugfix: Wrong syscall names for s390_pci_mmio_read and s390_pci_mmio_write
  * (#5965 #5976)
  * bugfix: firejail --ls reports wrong file sizes for large files (#5982
  * #6086)
  * bugfix: fix startup race condition for /run/firejail directory (#6307)
  * bugfix: fix various resource leaks (#6367)
  * bugfix: profstats: fix restrict-namespaces max count (#6369)
  * bugfix: remove --noautopulse from --help and zsh comp (#6401)
  * bugfix: parse --debug before using it (#6579)
  * bugfix: fix possible memory leak in fs_home.c (#6598)
  * bugfix: do not interact with dbus directory if dbus proxy is disabled
  * (#6591)
  * bugfix: firecfg: check full .desktop filename in check_profile() (#6674)
  * build: auto-generate syntax files (#5627)
  * build: mark all phony targets as such (#5637)
  * build: mkdeb.sh: pass all arguments to ./configure (#5654)
  * build: deb: enable apparmor by default & remove deb-apparmor (#5668)
  * build: Fix whitespace and add .editorconfig (#5674)
  * build: remove for loop initial declarations to fix building with old
  * compilers (#5778)
  * build: enable compiler warnings by default (#5842)
  * build: remove -mretpoline and NO_EXTRA_CFLAGS (#5859)
  * build: disable all built-in implicit make rules (#5864)
  * build: organize and standardize make vars and targets (#5866)
  * build: fix seccomp filters and man pages always being rebuilt when running
  * make (#5156 #5898)
  * build: fix hardcoded make & remove unnecessary distclean targets (#5911)
  * build: dist and asc improvements (#5916)
  * build: fix some shellcheck issues & use config.sh in more scripts (#5927)
  * build: firecfg.config sorting improvements (#5942)
  * build: codespell improvements (#5955)
  * build: add missing makefile dep & syntax improvements (#5956)
  * build: sort.py: use case-sensitive sorting (#6070)
  * build: mkrpm.sh: append instead of override configure args (#6126)
  * build: use CPPFLAGS instead of INCLUDE in compile targets (#6159)
  * build: use full paths on compile/link targets (#6158)
  * build: automatically generate header dependencies (#6164)
  * build: improve main clean target (#6186)
  * build: mkrpm.sh improvements (#6196)
  * build: move errExit macro into inline function (#6217)
  * build: allow overriding certain tools & sync targets with CI (#6222)
  * build: reduce hardcoding and inconsistencies & add installcheck target
  * (#6230 #6620)
  * build: sort.py: filter empty and duplicate items (#6261)
  * build: fix "warning: "_FORTIFY_SOURCE" redefined" (#6282 #6283)
  * build: sort.py: add -h/-i/-n/-- options (#6290 #6339 #6562)
  * build: add strip target and simplify install targets (#6342)
  * build: remove clean dependency from cppcheck targets (#6343)
  * build: allow overriding common tools (#6354)
  * build: standardize install commands (#6366)
  * build: improve reliability/portability of date command usage (#6403 #6404)
  * build: sort.py: strip whitespace in profiles (#6556)
  * build: sort.py: fix whitespace in entire profile (#6593)
  * build: sort.py: quote diff lines (#6594)
  * build: remove cppcheck-old target/job (#6676)
  * ci: always update the package db before installing packages (#5742)
  * ci: fix codeql unable to download its own bundle (#5783)
  * ci: split configure/build/install commands on gitlab (#5784)
  * ci: fix swapped name/email arguments in debian_ci (#5795)
  * ci: formatting and misc improvements (#5802)
  * ci: run for every branch instead of just master (#5815)
  * ci: upgrade debian:stretch to debian:buster (#5818)
  * ci: standardize apt-get update/install & misc improvements (#5857)
  * ci: Update step-security/harden-runner and update allowed endpoints (#5953)
  * ci: whitelist paths, reorganize workflows & speed-up tests (#5960 #6627)
  * ci: fix dependabot duplicated workflow runs (#5984)
  * ci: allow running workflows manually (#6026)
  * ci: add timeout limits (#6178)
  * ci: make dependabot updates monthly and bump PR limit (#6338)
  * contrib/syntax: remove 'text/plain' from firejail-profile.lang.in (#6057
  * #6059)
  * contrib/vim: match profile files more broadly (#5850)
  * contrib/vim: add ftplugin file (based on cfg.vim) (#6680)
  * test: split individual test groups in github workflows
  * test: add chroot, appimage and network tests in github workflows
  * docs: remove apparmor options in --help when building without apparmor
  * support (#5589)
  * docs: fix typos (#5693)
  * docs: markdown formatting and misc improvements (#5757)
  * docs: add uninstall instructions to README.md (#5812)
  * docs: add precedence info to manpage & fix noblacklist example (#6358
  * #6359)
  * docs: bug_report.md: use absolute path in 'steps to reproduce' (#6382)
  * docs: man: format and sort some private- items (#6398)
  * docs: man: improve blacklist/whitelist examples with spaces (#6425)
  * docs: add build_issue.md issue template (#6423)
  * docs: man: sort commands (firejail.1) (#6451)
  * docs: man: fix bold in command TPs (#6472)
  * docs: man: fix wrong escapes (#6474)
  * docs: github: streamline environment in issue templates (#6471 #6607)
  * docs: fix typos of --enable-selinux configure option (#6526)
  * docs: clarify intro and build section in README (#6524)
  * docs: clarify that other tools may not be in PPA (#6407)
  * docs: use GitHub issues as the bug reporting address (#6525)
  * docs: update distribution table & add note in SECURITY.md (#6624)
  * docs: clarify unmaintained status of overlayfs in configure.ac (#6632)
  * docs: improve whitelist and blacklist descriptions in man pages (#6622)
  * docs: note that --build may generate a non-functional profile (#6653)
  * legal: selinux.c: Split Copyright notice & use same license as upstream
  * (#5667)
  * profiles: qutebrowser: fix links not opening in the existing instance
  * (#5601 #5618)
  * profiles: clarify userns comments (#5686)
  * profiles: bulk rename electron to electron-common (#5700)
  * profiles: streamline seccomp socket comment (#5735)
  * profiles: drop hostname option from all profiles (#5702)
  * profiles: move read-only config entries to disable-common.inc (#5763)
  * profiles: standardize on just "GTK" on comments (#5794)
  * profiles: bleachbit: allow erasing Trash contents (#5337 #5902)
  * profiles: improvements to profiles using private (#5946)
  * profiles: standardize commented code and eol comments (#5987)
  * profiles: disable-common: add more suid programs (#6049 #6051 #6052)
  * profiles: replace private-opt with whitelist & document private-opt issues
  * (#6021)
  * profiles: drop paths already in wusc (#6218)
  * profiles: deny access to ~/.config/autostart (#6257)
  * profiles: replace x11 socket blacklist with disable-X11.inc (#6286)
  * profiles: sort blacklist sections (#6289)
  * profiles: rename disable-X11.inc to disable-x11.inc (#6294)
  * profiles: add allow-nodejs.inc to profile.template (#6298)
  * profiles: add allow-php.inc to profile.template (#6299)
  * profiles: clarify and add opengl-game to profile.template (#6300)
  * profiles: allow-ssh: allow /etc/ssh/ssh_revoked_hosts (#6308 #6309)
  * profiles: libreoffice: support signing documents with GPG (#6352 #6353)
  * profiles: blacklist i3 IPC socket & dir except for i3 itself (#6361)
  * profiles: librewolf: add new dbus name (io.gitlab.firefox) (#6413 #6473)
  * profiles: nextcloud: fix access to ~/Nextcloud (#5877 #6478)
  * profiles: ssh: add ${RUNUSER}/gvfsd-sftp (#5816 #6479)
  * profiles: firecfg: disable text editors (#6002 #6477)
  * profiles: browsers: centralize/sync/improve comments (#6486)
  * profiles: keepassxc: add new socket location (#5447 #6391)
  * profiles: signal-desktop: allow org.freedesktop.secrets (#6498)
  * profiles: firefox-common: allow org.freedesktop.portal.Documents (#6444
  * #6499)
  * profiles: keepassxc: allow access to ssh-agent socket (#3314 #6531)
  * profiles: firecfg.config: disable dnsmasq (#6533)
  * profiles: game-launchers: disable nou2f (#6534)
  * profiles: anki: fix opening, allow media & add to firecfg (#6544 #6545)
  * profiles: wget: allow ~/.local/share/wget (#6542)
  * profiles: wget: unify wget2 into wget profile (#6551)
  * profiles: tesseract: disable private-tmp to fix ocrmypdf (#6550 #6552)
  * profiles: ensure allow-lua where mpv is allowed (#6555)
  * profiles: video-players: add missing /usr/share paths (#6557)
  * profiles: clamav: add /etc/clamav (#6565)
  * profiles: lutris: add comment for gamescope workaround (#6192)
  * profiles: disable-common: add bubblejail paths (#6571)
  * profiles: fix misc in kmail/transmission-qt & add kontact.profile (#5905)
  * profiles: misc changes and self-ref fixes in ghostwriter/peek (#5648)
  * profiles: firecfg: fix sha384sum & add b2sum/cksum (#6578)
  * profiles: refactor com.github.johnfactotum.Foliate into foliate.profile
  * (#6582)
  * profiles: anki: fix dark mode detection & misc changes (#6581)
  * profiles: tor: add memory-deny-write-execute (#6641)
  * profiles: torbrowser-launcher: move path from dc to dp (#6640)
  * profiles: ytmdesktop: add redirect & whitelist /opt/ytmdesktop (#6662
  * #6666)
  * profiles: seahorse: add redirect org.gnome.seahorse.Application (#6658
  * #6673)
  * profiles: godot: ignore noexec in home to fix addons (#6686)
  * new profiles: qpdf and redirects (fix-qdf, qpdf, zlib-flate) (#5675)
  * new profiles: parsecd (#5646 #5682)
  * new profiles: lobster (#5706 #5847 #5885 #6155)
  * new profiles: ani-cli (#5707 #5733 #5892 #5954)
  * new profiles: discord redirects (DiscordPTB, discord-ptb) (#5729)
  * new profiles: jami and postman (#5691)
  * new profiles: mov-cli (#5710)
  * new profiles: standard-notes (#5761)
  * new profiles: url-eater (#5780)
  * new profiles: fbreader redirect (FBReader) (d88c8d4)
  * new profiles: rssguard (#5881)
  * new profiles: mullvad-browser (#5887)
  * new profiles: sniffnet (#5920)
  * new profiles: daisy (#5935)
  * new profiles: reader (#5934)
  * new profiles: journal-viewer (#5943)
  * new profiles: clac (#5947)
  * new profiles: blender redirect (blender-3.6) (#6013)
  * new profiles: fluffychat (#6007)
  * new profiles: lettura (#6027)
  * new profiles: brz and bzr (Breezy) (#6028)
  * new profiles: floorp (#6030 #6683)
  * new profiles: tidal-hifi (#6008 #6009)
  * new profiles: termshark (#6039)
  * new profiles: tiny-rdm (#6083)
  * new profiles: rawtherapee (#6180)
  * new profiles: electron-cash (#6181)
  * new profiles: gnome-boxes (#6226)
  * new profiles: virt-manager (#6227)
  * new profiles: ledger-live-desktop (#6219)
  * new profiles: lz4 and redirects (#6241)
  * new profiles: qt5ct (#6249)
  * new profiles: qt6ct (#6250)
  * new profiles: green-recoder (#6237)
  * new profiles: bpftop (#6231)
  * new profiles: erd (#6236)
  * new profiles: lyriek (#6245)
  * new profiles: statusof (#6253)
  * new profiles: cloneit (#6232)
  * new profiles: deadlink (#6233)
  * new profiles: dexios (#6234)
  * new profiles: koreader (#6243)
  * new profiles: editorconfiger (#6235)
  * new profiles: localsend_app (#6244)
  * new profiles: rymdport (#6251)
  * new profiles: textroom (#6254)
  * new profiles: tvnamer (#6256)
  * new profiles: mimetype (#6247)
  * new profiles: session-desktop (#6259)
  * new profiles: metadata-cleaner (#6246)
  * new profiles: tqemu (#6255)
  * new profiles: gh (GitHub CLI) (#6293)
  * new profiles: axel (#6315)
  * new profiles: several kids programs (alienblaster geki2 geki3 lbreakouthd
  * tuxtype typespeed) (4c5f558)
  * new profiles: loupe (#6327 #6333)
  * new profiles: d-spy (#6328)
  * new profiles: nhex (#6341)
  * new profiles: armcord (#6365)
  * new profiles: dtui (#6422)
  * new profiles: singularity (Endgame: Singularity) (#6463)
  * new profiles: prismlauncher (#6558)
  * new profiles: irssi (#6549)
  * new profiles: syncthing (#6536)
  * new profiles: obsidian (#6314)
  * new profiles: b3sum (blake3) (#6577)
  * new profiles: aria2p/aria2rpc (#6583 #6609)
  * new profiles: buku (#6584)
  * new profiles: monero-wallet-cli (#6586)
  * new profiles: tremc (#6590)
  * new profiles: device-flasher.linux (CalyxOS) (#6616)
  * new profiles: hledger/hledger-ui (#6585)
  * new profiles: ncmpcpp (#6587)
  * new profiles: pyradio (#6589)
  * new profiles: vesktop (#6654)
  * new profiles: nsxiv (#6588)
  * new profiles: remmina-file-wrapper (#6669)
  * new profiles: ouch (#6678)
  * new profiles: xarchiver (#6679)

OBS-URL: https://build.opensuse.org/request/show/1294517
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/firejail?expand=0&rev=21
2025-07-21 17:59:50 +00:00
Sebastian Wagner
f2e8b272f3 - update to version 0.9.74:
* security: fix sscanf rv checks (CodeQL) (#6184)
  * feature: private-etc rework: improve handling of /etc/resolv.conf and add
  * private-etc groups (#6400 #5518 #5608 #5609 #5629 #5638 #5641 #5642 #5643
  * #5650 #5681 #5737 #5844 #5989 #6016 #6104 #5655 #6435 #6514 #6515)
  * feature: Add "keep-shell-rc" command and option (#1127 #5634)
  * feature: Print the argument when failing with "too long arguments" (#5677)
  * feature: a random hostname is assigned to each sandbox unless
  * overwritten using --hostname command
  * feature: add IPv6 support for --net.print option
  * feature: QUIC (HTTP/3) support in --nettrace
  * feature: add seccomp filters for --restrict-namespaces
  * feature: stats support for --nettrace
  * feature: add doas support in firecfg and jailcheck (#5899 #5900)
  * feature: firecfg: add firecfg.d & add ignore command (#2097 #5245 #5876
  * #6153 #6268)
  * feature: expand simple macros in more commands (--chroot= --netfilter=
  * --netfilter6= --trace=) (#6032 #6109)
  * feature: add Landlock support (#5269 #6078 #6115 #6125 #6187 #6195 #6200
  * #6228 #6260 #6302 #6305)
  * feature: add support for comm, coredump, and prctl procevents in firemon
  * (#6414 #6415)
  * feature: add notpm command & keep tpm devices in private-dev (#6379 #6390)
  * feature: fshaper.sh: support tc on NixOS (#6426 #6431)
  * feature: add aarch64 syscalls (#5821 #6574)
  * feature: add --disable-sandbox-check configure flag (#6592)
  * feature: block /dev/ntsync & add keep-dev-ntsync command (#6655 #6660)
  * modif: Stop forwarding own double-dash to the shell (#5599 #5600)
  * modif: Prevent sandbox name (--name=) and host name (--hostname=)
  * from containing only digits (#5578 #5741)

OBS-URL: https://build.opensuse.org/package/show/Virtualization/firejail?expand=0&rev=55
2025-07-19 11:13:47 +00:00
81306e609a Accepting request 1236792 from Virtualization
OBS-URL: https://build.opensuse.org/request/show/1236792
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/firejail?expand=0&rev=20
2025-01-12 10:20:18 +00:00
Sebastian Wagner
90c0107930 - Load/reload AppArmor profiles when installing the package (boo#1235142#c1)
OBS-URL: https://build.opensuse.org/package/show/Virtualization/firejail?expand=0&rev=53
2025-01-10 06:33:14 +00:00
e1238352af Accepting request 1144048 from Virtualization
OBS-URL: https://build.opensuse.org/request/show/1144048
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/firejail?expand=0&rev=19
2024-02-05 21:01:03 +00:00
Sebastian Wagner
e4644503bf Accepting request 1144042 from home:adkorte:branches:Virtualization
- Use sysuser-tools to generate firejail group

OBS-URL: https://build.opensuse.org/request/show/1144042
OBS-URL: https://build.opensuse.org/package/show/Virtualization/firejail?expand=0&rev=51
2024-02-04 20:59:51 +00:00
3f121b056c Accepting request 1079767 from Virtualization
Automatic submission by obs-autosubmit

OBS-URL: https://build.opensuse.org/request/show/1079767
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/firejail?expand=0&rev=18
2023-04-16 18:13:35 +00:00
Sebastian Wagner
4bea3e4122 - update to version 0.9.72:
* modif: move hardcoded apps recognized by default in uiapps file
  * modif: remove sandbox edit dialog and replace it with uiapps file
  * feature: added uiapps file for default and user apps configuration
  * feature: added a system network monitor in sandbox stats
  * feature: added apparmor support in firejail-ui
  * feature: added bluetooth support in firejail-ui
  * feature: print final sandbox configuration in firejail-ui
  * bugfixes

OBS-URL: https://build.opensuse.org/package/show/Virtualization/firejail?expand=0&rev=49
2023-04-09 15:22:50 +00:00
4e0f543415 Accepting request 984254 from Virtualization
Automatic submission by obs-autosubmit

OBS-URL: https://build.opensuse.org/request/show/984254
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/firejail?expand=0&rev=17
2022-06-23 08:23:38 +00:00
Sebastian Wagner
02185620d8 - remove patches fix-internet-access.patch and fix-CVE-2022-31214.patch
as they are integrated upstream
- update to version 0.9.70:
 - security: CVE-2022-31214 - root escalation in --join logic
 - Reported by Matthias Gerstner, working exploit code was provided to our
 - development team. In the same time frame, the problem was independently
 - reported by Birk Blechschmidt. Full working exploit code was also provided.
 - feature: enable shell tab completion with --tab (#4936)
 - feature: disable user profiles at compile time (#4990)
 - feature: Allow resolution of .local names with avahi-daemon in the apparmor
 - profile (#5088)
 - feature: always log seccomp errors (#5110)
 - feature: firecfg --guide, guided user configuration (#5111)
 - feature: --oom, kernel OutOfMemory-killer (#5122)
 - modif: --ids feature needs to be enabled at compile time (#5155)
 - modif: --nettrace only available to root user
 - rework: whitelist restructuring (#4985)
 - rework: firemon, speed up and lots of fixes
 - bugfix: --private-cwd not expanding macros, broken hyperrogue (#4910)
 - bugfix: nogroups + wrc prints confusing messages (#4930 #4933)
 - bugfix: openSUSE Leap - whitelist-run-common.inc (#4954)
 - bugfix: fix printing in evince (#5011)
 - bugfix: gcov: fix gcov functions always declared as dummy (#5028)
 - bugfix: Stop warning on safe supplementary group clean (#5114)
 - build: remove ultimately unused INSTALL and RANLIB check macros (#5133)
 - build: mkdeb.sh.in: pass remaining arguments to ./configure (#5154)
 - ci: replace centos (EOL) with almalinux (#4912)
 - ci: fix --version not printing compile-time features (#5147)
 - ci: print version after install & fix apparmor support on build_apparmor
 - (#5148)

OBS-URL: https://build.opensuse.org/package/show/Virtualization/firejail?expand=0&rev=47
2022-06-14 20:25:23 +00:00
c4df071dcc Accepting request 981393 from Virtualization
- fix bsc#1199148 CVE-2022-31214 by adding patch fix-CVE-2022-31214.patch
  using commits from upstream.

OBS-URL: https://build.opensuse.org/request/show/981393
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/firejail?expand=0&rev=16
2022-06-09 12:11:55 +00:00
Sebastian Wagner
b09fab085f - fix bsc#1199148 CVE-2022-31214 by adding patch fix-CVE-2022-31214.patch
using commits from upstream.

OBS-URL: https://build.opensuse.org/package/show/Virtualization/firejail?expand=0&rev=45
2022-06-08 21:08:53 +00:00
90201d7f9f Accepting request 958270 from Virtualization
- add fix-internet-access.patch to fix boo#1196542

OBS-URL: https://build.opensuse.org/request/show/958270
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/firejail?expand=0&rev=15
2022-03-01 16:03:56 +00:00
Sebastian Wagner
566ad0a710 - add fix-internet-access.patch to fix boo#1196542
OBS-URL: https://build.opensuse.org/package/show/Virtualization/firejail?expand=0&rev=44
2022-02-28 19:39:03 +00:00
f715d4c5b7 Accepting request 956436 from Virtualization
Automatic submission by obs-autosubmit

OBS-URL: https://build.opensuse.org/request/show/956436
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/firejail?expand=0&rev=14
2022-02-21 16:46:50 +00:00
Sebastian Wagner
48b9cccdb4 add apparmor directories to file list
Failed in the Request to Factory

OBS-URL: https://build.opensuse.org/package/show/Virtualization/firejail?expand=0&rev=43
2022-02-14 11:13:24 +00:00
Sebastian Wagner
a9233baa33 - update to firejail 0.9.68:
- security: on Ubuntu, the PPA is now recommended over the distro package
 - (see README.md) (#4748)
 - security: bugfix: private-cwd leaks access to the entire filesystem
 - (#4780); reported by Hugo Osvaldo Barrera
 - feature: remove (some) environment variables with auth-tokens (#4157)
 - feature: ALLOW_TRAY condition (#4510 #4599)
 - feature: add basic Firejail support to AppArmor base abstraction (#3226
 - #4628)
 - feature: intrusion detection system (--ids-init, --ids-check)
 - feature: deterministic shutdown command (--deterministic-exit-code,
 - --deterministic-shutdown) (#928 #3042 #4635)
 - feature: noprinters command (#4607 #4827)
 - feature: network monitor (--nettrace)
 - feature: network locker (--netlock) (#4848)
 - feature: whitelist-ro profile command (#4740)
 - feature: disable pipewire with --nosound (#4855)
 - feature: Unset TMP if it doesn't exist inside of sandbox (#4151)
 - feature: Allow apostrophe in whitelist and blacklist (#4614)
 - feature: AppImage support in --build command (#4878)
 - modifs: exit code: distinguish fatal signals by adding 128 (#4533)
 - modifs: firecfg.config is now installed to /etc/firejail/ (#408 #4669)
 - modifs: close file descriptors greater than 2 (--keep-fd) (#4845)
 - modifs: nogroups now stopped causing certain system groups to be dropped,
 - which are now controlled by the relevant "no" options instead (such as
 - nosound -> drop audio group), which fixes device access issues on systems
 - not using (e)logind (such as with seatd) (#4632 #4725 #4732 #4851)
 - removal: --disable-whitelist at compile time
 - removal: whitelist=yes/no in /etc/firejail/firejail.config
 - bugfix: Fix sndio support (#4362 #4365)

OBS-URL: https://build.opensuse.org/package/show/Virtualization/firejail?expand=0&rev=42
2022-02-06 21:09:45 +00:00
4804987735 Accepting request 906960 from Virtualization
OBS-URL: https://build.opensuse.org/request/show/906960
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/firejail?expand=0&rev=13
2021-07-18 21:45:05 +00:00
Sebastian Wagner
b1111dceda Accepting request 906957 from home:AndreasStieger:branches:Virtualization
fix Factory (clean) staging

OBS-URL: https://build.opensuse.org/request/show/906957
OBS-URL: https://build.opensuse.org/package/show/Virtualization/firejail?expand=0&rev=41
2021-07-18 18:36:27 +00:00
Sebastian Wagner
e59cb944f7 Accepting request 906934 from home:AndreasStieger:branches:Virtualization
firejail 0.9.66

OBS-URL: https://build.opensuse.org/request/show/906934
OBS-URL: https://build.opensuse.org/package/show/Virtualization/firejail?expand=0&rev=40
2021-07-18 12:48:18 +00:00
5370568b3a Accepting request 870339 from Virtualization
- Update to 0.9.64.4:
  * disabled overlayfs, pending multiple fixes
  * fixed launch firefox for open url in telegram-desktop.profile

OBS-URL: https://build.opensuse.org/request/show/870339
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/firejail?expand=0&rev=12
2021-02-09 20:16:48 +00:00
Sebastian Wagner
d7c0b56c56 Accepting request 870157 from home:13ilya:branches:Virtualization
- Update to 0.9.64.4:
  * disabled overlayfs, pending multiple fixes
  * fixed launch firefox for open url in telegram-desktop.profile

OBS-URL: https://build.opensuse.org/request/show/870157
OBS-URL: https://build.opensuse.org/package/show/Virtualization/firejail?expand=0&rev=38
2021-02-08 07:37:21 +00:00
eedaf3953b Accepting request 867566 from Virtualization
OBS-URL: https://build.opensuse.org/request/show/867566
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/firejail?expand=0&rev=11
2021-01-28 20:29:33 +00:00
Sebastian Wagner
2b52fe676f Accepting request 867564 from home:13ilya:branches:Virtualization
- Update to 0.9.64.2:
  * allow --tmpfs inside $HOME for unprivileged users
  * --disable-usertmpfs compile time option
  * allow AF_BLUETOOTH via --protocol=bluetooth
  * setup guide for new users: contrib/firejail-welcome.sh
  * implement netns in profiles
  * added nolocal6.net IPv6 network filter
  * new profiles: spectacle, chromium-browser-privacy,
    gtk-straw-viewer, gtk-youtube-viewer, gtk2-youtube-viewer,
    gtk3-youtube-viewer, straw-viewer, lutris, dolphin-emu,
    authenticator-rs, servo, npm, marker, yarn, lsar, unar, agetpkg,
    mdr, shotwell, qnapi, new profiles: guvcview, pkglog, kdiff3, CoyIM.

OBS-URL: https://build.opensuse.org/request/show/867564
OBS-URL: https://build.opensuse.org/package/show/Virtualization/firejail?expand=0&rev=36
2021-01-28 19:02:27 +00:00
85d92c65e6 Accepting request 846925 from Virtualization
- packaging fixes
- Update to version 0.9.64:
  * replaced --nowrap option with --wrap in firemon
  * The blocking action of seccomp filters has been changed from
    killing the process to returning EPERM to the caller. To get the
    previous behaviour, use --seccomp-error-action=kill or
    syscall:kill syntax when constructing filters, or override in
    /etc/firejail/firejail.config file.
  * Fine-grained D-Bus sandboxing with xdg-dbus-proxy.
    xdg-dbus-proxy must be installed, if not D-Bus access will be allowed.
    With this version nodbus is deprecated, in favor of dbus-user none and
    dbus-system none and will be removed in a future version.
  * DHCP client support
  * firecfg only fix dektop-files if started with sudo
  * SELinux labeling support
  * custom 32-bit seccomp filter support
  * restrict ${RUNUSER} in several profiles
  * blacklist shells such as bash in several profiles
  * whitelist globbing
  * mkdir and mkfile support for /run/user directory
  * support ignore for include
  * --include on the command line
  * splitting up media players whitelists in whitelist-players.inc
  * new condition: HAS_NOSOUND
  * new profiles: gfeeds, firefox-x11, tvbrowser, rtv, clipgrab, muraster
  * new profiles: gnome-passwordsafe, bibtex, gummi, latex, mupdf-x11-curl
  * new profiles: pdflatex, tex, wpp, wpspdf, wps, et, multimc, mupdf-x11
  * new profiles: gnome-hexgl, com.github.johnfactotum.Foliate, mupdf-gl, mutool
  * new profiles: desktopeditors, impressive, planmaker18, planmaker18free
  * new profiles: presentations18, presentations18free, textmaker18, teams
  * new profiles: textmaker18free, xournal, gnome-screenshot, ripperX
  * new profiles: sound-juicer, com.github.dahenson.agenda, gnome-pomodoro
  * new profiles: gnome-todo, x2goclient, iagno, kmplayer, penguin-command
  * new profiles: frogatto, gnome-mines, gnome-nibbles, lightsoff, warmux
  * new profiles: ts3client_runscript.sh, ferdi, abiword, four-in-a-row
  * new profiles: gnome-mahjongg, gnome-robots, gnome-sudoku, gnome-taquin
  * new profiles: gnome-tetravex, blobwars, gravity-beams-and-evaporating-stars
  * new profiles: hyperrogue, jumpnbump-menu, jumpnbump, magicor, mindless
  * new profiles: mirrormagic, mrrescue, scorched3d-wrapper, scorchwentbonkers
  * new profiles: seahorse-adventures, wordwarvi, xbill, gnome-klotski
  * new profiles: swell-foop, fdns, five-or-more, steam-runtime
  * new profiles: nicotine, plv, mocp, apostrophe, quadrapassel, dino-im
  * new profiles: hitori, bijiben, gnote, gnubik, ZeGrapher, xonotic-sdl-wrapper
  * new profiles: gapplication, openarena_ded, element-desktop, cawbird
  * new profiles: freetube, strawberry, jitsi-meet-desktop
  * new profiles: homebank, mattermost-desktop, newsflash, com.gitlab.newsflash
  * new profiles: sushi, xfce4-screenshooter, org.gnome.NautilusPreviewer, lyx
  * new profiles: minitube, nuclear, mtpaint, minecraft-launcher, gnome-calendar
  * new profiles: vmware, git-cola, otter-browser, kazam, menulibre, musictube
  * new profiles: onboard, fractal, mirage, quaternion, spectral, man, psi
  * new profiles: smuxi-frontend-gnome, balsa, kube, trojita, youtube
  * new profiles: youtubemusic-nativefier, cola, dbus-send, notify-send
  * new profiles: qrencode, ytmdesktop, twitch
  * new profiles: xournalpp, chromium-freeworld, equalx
- remove firejail-0.9.62-fix-usr-etc.patch, included upstream
- remove firejail-apparmor-3.0.diff, included upstream

OBS-URL: https://build.opensuse.org/request/show/846925
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/firejail?expand=0&rev=10
2020-11-08 19:59:06 +00:00
Sebastian Wagner
8cefb6d42d fix file
OBS-URL: https://build.opensuse.org/package/show/Virtualization/firejail?expand=0&rev=34
2020-11-02 22:09:54 +00:00
Sebastian Wagner
478a8d32dc - packaging fixes
OBS-URL: https://build.opensuse.org/package/show/Virtualization/firejail?expand=0&rev=33
2020-11-02 20:06:56 +00:00
Sebastian Wagner
7ad2a2419a - Update to version 0.9.64:
* replaced --nowrap option with --wrap in firemon
  * The blocking action of seccomp filters has been changed from
    killing the process to returning EPERM to the caller. To get the
    previous behaviour, use --seccomp-error-action=kill or
    syscall:kill syntax when constructing filters, or override in
    /etc/firejail/firejail.config file.
  * Fine-grained D-Bus sandboxing with xdg-dbus-proxy.
    xdg-dbus-proxy must be installed, if not D-Bus access will be allowed.
    With this version nodbus is deprecated, in favor of dbus-user none and
    dbus-system none and will be removed in a future version.
  * DHCP client support
  * firecfg only fix dektop-files if started with sudo
  * SELinux labeling support
  * custom 32-bit seccomp filter support
  * restrict ${RUNUSER} in several profiles
  * blacklist shells such as bash in several profiles
  * whitelist globbing
  * mkdir and mkfile support for /run/user directory
  * support ignore for include
  * --include on the command line
  * splitting up media players whitelists in whitelist-players.inc
  * new condition: HAS_NOSOUND
  * new profiles: gfeeds, firefox-x11, tvbrowser, rtv, clipgrab, muraster
  * new profiles: gnome-passwordsafe, bibtex, gummi, latex, mupdf-x11-curl
  * new profiles: pdflatex, tex, wpp, wpspdf, wps, et, multimc, mupdf-x11
  * new profiles: gnome-hexgl, com.github.johnfactotum.Foliate, mupdf-gl, mutool
  * new profiles: desktopeditors, impressive, planmaker18, planmaker18free
  * new profiles: presentations18, presentations18free, textmaker18, teams
  * new profiles: textmaker18free, xournal, gnome-screenshot, ripperX

OBS-URL: https://build.opensuse.org/package/show/Virtualization/firejail?expand=0&rev=32
2020-11-01 17:53:52 +00:00
22bea5c481 Accepting request 844222 from Virtualization
OBS-URL: https://build.opensuse.org/request/show/844222
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/firejail?expand=0&rev=9
2020-10-27 18:00:22 +00:00
Sebastian Wagner
0d233a7a59 Accepting request 844172 from home:cboltz:branches:Virtualization
- Add firejail-apparmor-3.0.diff to make the AppArmor profile compatible with
  AppArmor 3.0 (add missing include <tunables/global>)

I'll submit AppArmor 3.0 to Factory in the next days.
Please forward this fix ASAP - without it, the firejail AppArmor profile will fail to load.

OBS-URL: https://build.opensuse.org/request/show/844172
OBS-URL: https://build.opensuse.org/package/show/Virtualization/firejail?expand=0&rev=30
2020-10-27 07:43:21 +00:00
845ba07aea Accepting request 827727 from Virtualization
OBS-URL: https://build.opensuse.org/request/show/827727
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/firejail?expand=0&rev=8
2020-08-19 16:54:50 +00:00
Sebastian Wagner
30f9931e5a Accepting request 827725 from home:polslinux:branches:Virtualization
- Update to 0.9.62.4
  * fix AppArmor broken in the previous release
  * miscellaneous fixes
- Update to 0.9.62.2
  * fix CVE-2020-17367
  * fix CVE-2020-17368
  * additional hardening and bug fixes
- Remove fix-CVE-2020-17368.patch
- Remove fix-CVE-2020-17367.patch

OBS-URL: https://build.opensuse.org/request/show/827725
OBS-URL: https://build.opensuse.org/package/show/Virtualization/firejail?expand=0&rev=28
2020-08-19 06:28:03 +00:00
a2f2028508 Accepting request 825005 from Virtualization
- Add patches fix-CVE-2020-17367.patch and fix-CVE-2020-17368.patch to fix CVE-2020-17367 and CVE-2020-17368 and boo#1174986

OBS-URL: https://build.opensuse.org/request/show/825005
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/firejail?expand=0&rev=7
2020-08-10 12:57:56 +00:00
Sebastian Wagner
20cd8acbae - Add patches fix-CVE-2020-17367.patch and fix-CVE-2020-17368.patch to fix CVE-2020-17367 and CVE-2020-17368 and boo#1174986
OBS-URL: https://build.opensuse.org/package/show/Virtualization/firejail?expand=0&rev=26
2020-08-08 17:37:44 +00:00
a0a118038b Accepting request 799832 from Virtualization
- Add firejail-0.9.62-fix-usr-etc.patch:
  Check /usr/etc not just /etc
- Replace python interpreter line in sort.py

OBS-URL: https://build.opensuse.org/request/show/799832
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/firejail?expand=0&rev=6
2020-05-03 20:47:44 +00:00
Sebastian Wagner
b9023df37f add patch tag line in specfile
OBS-URL: https://build.opensuse.org/package/show/Virtualization/firejail?expand=0&rev=24
2020-05-03 13:23:47 +00:00
Sebastian Wagner
3bb61c9bf6 Accepting request 798884 from home:jubalh:branches:Virtualization
- Add firejail-0.9.62-fix-usr-etc.patch:
  Check /usr/etc not just /etc
- Replace python interpreter line in sort.py

OBS-URL: https://build.opensuse.org/request/show/798884
OBS-URL: https://build.opensuse.org/package/show/Virtualization/firejail?expand=0&rev=23
2020-05-03 13:21:47 +00:00
f53b9e77cd Accepting request 774571 from Virtualization
- update to version 0.9.62 
  * added file-copy-limit in /etc/firejail/firejail.config
  * profile templates (/usr/share/doc/firejail)
  * allow-debuggers support in profiles
  * several seccomp enhancements
  * compiler flags autodetection
  * move chroot entirely from path based to file descriptor based mounts
  * whitelisting /usr/share in a large number of profiles
  * new scripts in conrib: gdb-firejail.sh and sort.py
  * enhancement: whitelist /usr/share in some profiles
  * added signal mediation to apparmor profile
  * new conditions: HAS_X11, HAS_NET
  * new profiles: qgis, klatexformula, klatexformula_cmdl, links, xlinks
  * new profiles: pandoc, teams-for-linux, OpenArena, gnome-sound-recorder
  * new profiles: godot, tcpdump, tshark, newsbeuter, keepassxc-cli
  * new profiles: keepassxc-proxy, rhythmbox-client, jerry, zeal, mpg123
  * new profiles: conplay, mpg123.bin, mpg123-alsa, mpg123-id3dump, out123
  * new profiles: mpg123-jack, mpg123-nas, mpg123-openal, mpg123-oss
  * new profiles: mpg123-portaudio, mpg123-pulse, mpg123-strip, pavucontrol-qt
  * new profiles: gnome-characters, gnome-character-map, rsync, Whalebird,
  * new profiles: tor-browser (AUR), Zulip, tb-starter-wrapper, bzcat,
  * new profiles: kiwix-desktop, bzcat, zstd, pzstd, zstdcat, zstdgrep, zstdless
  * new profiles: zstdmt, unzstd, i2p, ar, gnome-latex, pngquant, kalgebra
  * new profiles: kalgebramobile, signal-cli, amuled, kfind, profanity
  * new profiles: audio-recorder, cameramonitor, ddgtk, drawio, unf, gmpc
  * new profiles: electron-mail, gist, gist-paste (forwarded request 773543 from darix)

OBS-URL: https://build.opensuse.org/request/show/774571
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/firejail?expand=0&rev=5
2020-02-15 21:25:12 +00:00
Sebastian Wagner
84b9c6c073 Accepting request 773543 from home:darix:playground
- update to version 0.9.62 
  * added file-copy-limit in /etc/firejail/firejail.config
  * profile templates (/usr/share/doc/firejail)
  * allow-debuggers support in profiles
  * several seccomp enhancements
  * compiler flags autodetection
  * move chroot entirely from path based to file descriptor based mounts
  * whitelisting /usr/share in a large number of profiles
  * new scripts in conrib: gdb-firejail.sh and sort.py
  * enhancement: whitelist /usr/share in some profiles
  * added signal mediation to apparmor profile
  * new conditions: HAS_X11, HAS_NET
  * new profiles: qgis, klatexformula, klatexformula_cmdl, links, xlinks
  * new profiles: pandoc, teams-for-linux, OpenArena, gnome-sound-recorder
  * new profiles: godot, tcpdump, tshark, newsbeuter, keepassxc-cli
  * new profiles: keepassxc-proxy, rhythmbox-client, jerry, zeal, mpg123
  * new profiles: conplay, mpg123.bin, mpg123-alsa, mpg123-id3dump, out123
  * new profiles: mpg123-jack, mpg123-nas, mpg123-openal, mpg123-oss
  * new profiles: mpg123-portaudio, mpg123-pulse, mpg123-strip, pavucontrol-qt
  * new profiles: gnome-characters, gnome-character-map, rsync, Whalebird,
  * new profiles: tor-browser (AUR), Zulip, tb-starter-wrapper, bzcat,
  * new profiles: kiwix-desktop, bzcat, zstd, pzstd, zstdcat, zstdgrep, zstdless
  * new profiles: zstdmt, unzstd, i2p, ar, gnome-latex, pngquant, kalgebra
  * new profiles: kalgebramobile, signal-cli, amuled, kfind, profanity
  * new profiles: audio-recorder, cameramonitor, ddgtk, drawio, unf, gmpc
  * new profiles: electron-mail, gist, gist-paste

OBS-URL: https://build.opensuse.org/request/show/773543
OBS-URL: https://build.opensuse.org/package/show/Virtualization/firejail?expand=0&rev=21
2020-02-15 15:30:46 +00:00
8ee173b52b Accepting request 707400 from Virtualization
- update to version 0.9.60:
 * security bug reported by Austin Morton:
   Seccomp filters are copied into /run/firejail/mnt, and are writable
   within the jail. A malicious process can modify files from inside the
   jail. Processes that are later joined to the jail will not have seccomp
   filters applied.
   CVE-2019-12589
   boo#1137139
 * memory-deny-write-execute now also blocks memfd_create
 * add private-cwd option to control working directory within jail
 * blocking system D-Bus socket with --nodbus
 * bringing back Centos 6 support
 * drop support for flatpak/snap packages
 * new profiles: crow, nyx, mypaint, celluoid, nano, transgui, mpdris2
 * new profiles: sysprof, simplescreenrecorder, geekbench, xfce4-mixer
 * new profiles: pavucontrol, d-feet, seahorse, secret-tool, gnome-keyring
 * new profiles: regextester, hardinfo, gnome-system-log, gnome-nettool
 * new profiles: netactview, redshift, devhelp, assogiate, subdownloader
 * new profiles: font-manager, exfalso, gconf-editor, dconf-editor
 * new profiles: sysprof-cli, seahorse-tool, secret-tool, dconf, gsettings
 * new profiles: code-oss, pragha, Maelstrom, ostrichriders, bzflag
 * new profiles: freeciv, lincity-ng, megaglest, openttd, crawl, crawl-tiles
 * new profiles: teeworlds, torcs, tremulous, warsow, lugaru, manaplus
 * new profiles: pioneer, scorched3d, widelands, freemind, kid3, kid3-qt
 * new profiles: kid3-cli, nomacs, freecol, opencity, openclonk, slashem
 * new profiles: vultureseye, vulturesclaw, anki, cheese, utox, mp3splt
 * new profiles: oggsplt, flacsplt, gramps, newsboat, freeoffice-planmaker
 * new profiles: autokey-gtk, autokey-qt, autokey-run, autokey-shell
 * new profiles: freeoffice-presentations, freeoffice-textmaker, mp3wrap
 * new profiles: inkview, meteo-qt, mp3splt-gtk, ktouch, yelp, cantata

OBS-URL: https://build.opensuse.org/request/show/707400
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/firejail?expand=0&rev=4
2019-06-04 10:14:58 +00:00
Sebastian Wagner
ec099811d6 CVE-2019-12589
boo#1137139

OBS-URL: https://build.opensuse.org/package/show/Virtualization/firejail?expand=0&rev=19
2019-06-04 07:32:22 +00:00
Sebastian Wagner
b32a343fff - update to version 0.9.60:
* security bug reported by Austin Morton:
   Seccomp filters are copied into /run/firejail/mnt, and are writable
   within the jail. A malicious process can modify files from inside the
   jail. Processes that are later joined to the jail will not have seccomp
   filters applied.
 * memory-deny-write-execute now also blocks memfd_create
 * add private-cwd option to control working directory within jail
 * blocking system D-Bus socket with --nodbus
 * bringing back Centos 6 support
 * drop support for flatpak/snap packages
 * new profiles: crow, nyx, mypaint, celluoid, nano, transgui, mpdris2
 * new profiles: sysprof, simplescreenrecorder, geekbench, xfce4-mixer
 * new profiles: pavucontrol, d-feet, seahorse, secret-tool, gnome-keyring
 * new profiles: regextester, hardinfo, gnome-system-log, gnome-nettool
 * new profiles: netactview, redshift, devhelp, assogiate, subdownloader
 * new profiles: font-manager, exfalso, gconf-editor, dconf-editor
 * new profiles: sysprof-cli, seahorse-tool, secret-tool, dconf, gsettings
 * new profiles: code-oss, pragha, Maelstrom, ostrichriders, bzflag
 * new profiles: freeciv, lincity-ng, megaglest, openttd, crawl, crawl-tiles
 * new profiles: teeworlds, torcs, tremulous, warsow, lugaru, manaplus
 * new profiles: pioneer, scorched3d, widelands, freemind, kid3, kid3-qt
 * new profiles: kid3-cli, nomacs, freecol, opencity, openclonk, slashem
 * new profiles: vultureseye, vulturesclaw, anki, cheese, utox, mp3splt
 * new profiles: oggsplt, flacsplt, gramps, newsboat, freeoffice-planmaker
 * new profiles: autokey-gtk, autokey-qt, autokey-run, autokey-shell
 * new profiles: freeoffice-presentations, freeoffice-textmaker, mp3wrap
 * new profiles: inkview, meteo-qt, mp3splt-gtk, ktouch, yelp, cantata

OBS-URL: https://build.opensuse.org/package/show/Virtualization/firejail?expand=0&rev=18
2019-06-02 16:36:27 +00:00
Stephan Kulow
8f910e1f82 Accepting request 670891 from Virtualization
OBS-URL: https://build.opensuse.org/request/show/670891
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/firejail?expand=0&rev=3
2019-02-04 13:25:03 +00:00
8b442f3a70 Accepting request 670512 from home:polslinux:branches:Virtualization
-  update to version 0.9.58:
  * --disable-mnt rework
  * --net.print command
  * GitLab CI/CD integration: disto specific builds
  * profile parser enhancements and conditional handling support
     for HAS_APPIMAGE, HAS_NODBUS, BROWSER_DISABLE_U2F
  * profile name support
  * added explicit nonewprivs support to join option
  * new profiles: QMediathekView, aria2c, Authenticator, checkbashisms
  * new profiles: devilspie, devilspie2, easystroke, github-desktop, min
  * new profiles: bsdcat, bsdcpio, bsdtar, lzmadec, lbunzip2, lbzcat
  * new profiles: lbzip2, lzcat, lzcmp, lzdiff, lzegrep, lzfgrep, lzgrep
  * new profiles: lzless, lzma, lzmainfo, lzmore, unlzma, unxz, xzcat
  * new profiles: xzcmp, xzdiff, xzegrep, xzfgrep, xzgrep, xzless, xzmore
  * new profiles: lzip, artha, nitroshare, nitroshare-cli, nitroshare-nmh
  * new profiles: nirtoshare-send, nitroshare-ui, mencoder, gnome-pie
  * new profiles: masterpdfeditor, QOwnNotes, aisleriot, Mendeley
  * new profiles: feedreader, ocenaudio, mpsyt, thunderbird-wayland
  * new profiles: supertuxkart, ghostwriter, gajim-history-manager
  * bugfixes

OBS-URL: https://build.opensuse.org/request/show/670512
OBS-URL: https://build.opensuse.org/package/show/Virtualization/firejail?expand=0&rev=16
2019-02-03 18:00:19 +00:00
12593f1e6a Accepting request 639122 from Virtualization
Automatic submission by obs-autosubmit

OBS-URL: https://build.opensuse.org/request/show/639122
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/firejail?expand=0&rev=2
2018-10-11 09:47:59 +00:00
Sebastian Wagner
2892572be0 - update to version 0.9.56:
* modif: removed CFG_CHROOT_DESKTOP configuration option
  * modif: removed compile time --enable-network=restricted
  * modif: removed compile time --disable-bind
  * modif: --net=none allowed even if networking was disabled at compile
     time or at run time
  * modif: allow system users to run the sandbox
  * support wireless devices in --net option
  * support tap devices in --net option (tunneling support)
  * allow IP address configuration if the parent interface specified
     by --net is not configured (--netmask)
  * support for firetunnel utility
  * disable U2F devices (--nou2f)
  * add --private-cache to support private ~/.cache
  * support full paths in private-lib
  * globbing support in private-lib
  * support for local user directories in firecfg (--bindir)
  * new profiles: ms-excel, ms-office, ms-onenote, ms-outlook, ms-powerpoint,
  * new profiles: ms-skype, ms-word, riot-desktop, gnome-mpv, snox, gradio,
  * new profiles: standardnotes-desktop, shellcheck, patch, flameshot,
  * new profiles: rview, rvim, vimcat, vimdiff, vimpager, vimtutor, xxd,
  * new profiles: Beaker, electrum, clamtk, pybitmessage, dig, whois,
  * new profiles: jdownloader, Fluxbox, Blackbox, Awesome, i3
  * new profiles: start-tor-browser.desktop

OBS-URL: https://build.opensuse.org/package/show/Virtualization/firejail?expand=0&rev=14
2018-09-22 09:20:11 +00:00
6a7a47dd31 Accepting request 634916 from Virtualization
OBS-URL: https://build.opensuse.org/request/show/634916
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/firejail?expand=0&rev=1
2018-09-18 09:43:16 +00:00
Sebastian Wagner
726c0a1ca4 Accepting request 634910 from home:markoschandras:branches:Virtualization
- Drop ldconfig calls since firejail libraries are installed in their
  own subdirectory which is not scanned by ldconfig.

OBS-URL: https://build.opensuse.org/request/show/634910
OBS-URL: https://build.opensuse.org/package/show/Virtualization/firejail?expand=0&rev=12
2018-09-11 08:20:15 +00:00
Sebastian Wagner
cd8d8218e4 Accepting request 634702 from home:markoschandras:branches:Virtualization
- Remove the rpmlintrc file since the warnings are no longer relevant.

OBS-URL: https://build.opensuse.org/request/show/634702
OBS-URL: https://build.opensuse.org/package/show/Virtualization/firejail?expand=0&rev=11
2018-09-10 10:12:02 +00:00
Sebastian Wagner
925e8bdf31 - Changed the permissions of the firejail executable to 4750.
Setuid mode is used, but only allowed for users in the newly
  created group 'firejail' (boo#1059013).
- Update to version 0.9.54:
  * modif: --force removed
  * modif: --csh, --zsh removed
  * modif: --debug-check-filename removed
  * modif: --git-install and --git-uninstall removed
  * modif: support for private-bin, private-lib and shell none has been
     disabled while running AppImage archives in order to be able to use
     our regular profile files with AppImages.
  * modif: restrictions for /proc, /sys and /run/user directories
     are moved from AppArmor profile into firejail executable
  * modif: unifying Chromium and Firefox browsers profiles.
     All users of Firefox-based browsers who use addons and plugins
     that read/write from ${HOME} will need to uncomment the includes for
     firefox-common-addons.inc in firefox-common.profile.
  * modif: split disable-devel.inc into disable-devel and
     disable-interpreters.inc
  * Firejail user access database (/etc/firejail/firejail.users,
     man firejail-users)
  * add --noautopulse to disable automatic ~/.config/pulse (for complex setups)
  * Spectre mitigation patch for gcc and clang compiler
  * D-Bus handling (--nodbus)
  * AppArmor support for overlayfs and chroot sandboxes
  * AppArmor support for AppImages
  * Enable AppArmor by default for a large number of programs
  * firejail --apparmor.print option
  * firemon --apparmor option
  * apparmor yes/no flag in /etc/firejail/firejail.config

OBS-URL: https://build.opensuse.org/package/show/Virtualization/firejail?expand=0&rev=10
2018-08-26 10:45:50 +00:00
68d6fd1be5 Accepting request 556579 from home:avindra
Note for reviewer: 0.9.51 was skipped.


- Update to version 0.9.52:
  * New features
    + systemd-resolved integration
    + whitelisted /var in most profiles
    + GTK2, GTK3 and Qt4 private-lib support
    + --debug-private-lib
    + test deployment of private-lib for the some apps: evince,
      galculator, gnome-calculator, leafpad, mousepad,
      transmission-gtk, xcalc, xmr-stak-cpu, atril,
      mate-color-select, tar, file, strings, gpicview, eom, eog,
      gedit, pluma
    + netfilter template support
    + various new arguments
      * --writable-run-user
      * --rlimit-as
      * --rlimit-cpu
      * --timeout
      * --build (profile build tool)
      * --netfilter.print
      * --netfilter6.print
  * deprecations in modif 
    + --allow-private-blacklists (blacklisting, read-only,
      read-write, tmpfs and noexec are allowed in private home
      directories
    + remount-proc-sys (firejail.config)
    + follow-symlink-private-bin (firejail.config)
    + --profile-path
  * enhancements
    + support Firejail user config directory in firecfg
    + disable DBus activation in firecfg
    + enumerate root directories in apparmor profile
    + /etc and /usr/share whitelisting support
    + globbing support for --private-bin
  * new profiles: upstreamed profiles from 3 sources:
    + https://github.com/chiraag-nataraj/firejail-profiles
    + https://github.com/nyancat18/fe
    + https://aur.archlinux.org/packages/firejail-profiles
  * new profiles: terasology, surf, rocketchat, clamscan, clamdscan,
    clamdtop, freshclam, xmr-stak-cpu, amule, ardour4, ardour5,
    brackets, calligra, calligraauthor, calligraconverter,
    calligraflow, calligraplan, calligraplanwork, calligrasheets,
    calligrastage, calligrawords, cin, dooble, dooble-qt4,
    fetchmail, freecad, freecadcmd, google-earth,imagej, karbon,
    1kdenlive, krita, linphone, lmms, macrofusion, mpd, natron,
    Natron, ricochet, shotcut, teamspeak3, tor, tor-browser-en,
    Viber, x-terminal-emulator, zart, conky, arch-audit, ffmpeg,
    bluefish, cinelerra, openshot-qt, pinta, uefitool, aosp,
    pdfmod, gnome-ring, xcalc, zaproxy, kopete, cliqz,
    signal-desktop, kget, nheko, Enpass, kwin_x11, krunner, ping,
    bsdtar, makepkg (Arch), archaudit-report cower (Arch), kdeinit4
- Add full link to source tarball from sourceforge
- Add asc file

OBS-URL: https://build.opensuse.org/request/show/556579
OBS-URL: https://build.opensuse.org/package/show/Virtualization/firejail?expand=0&rev=9
2017-12-14 10:26:35 +00:00
c320ca99e4 Accepting request 522777 from home:avindra
- Update to version 0.9.50:
  * New features:
    - per-profile disable-mnt (--disable-mnt)
    - per-profile support to set X11 Xephyr screen size (--xephyr-screen)
    - private /lib directory (--private-lib)
    - disable CDROM/DVD drive (--nodvd)
    - disable DVB devices (--notv)
    - --profile.print
  * modif: --output split in two commands, --output and --output-stderr
  * set xpra-attach yes in /etc/firejail/firejail.config
  * Enhancements:
    - print all seccomp filters under --debug
    - /proc/sys mounting
    - rework IP address assingment for --net options
    - support for newer Xpra versions (2.1+) -
    - all profiles use a standard layout style
    - create /usr/local for firecfg if the directory doesn't exist
    - allow full paths in --private-bin
   * New seccomp features:
    - --memory-deny-write-execute
    - seccomp post-exec
    - block secondary architecture (--seccomp.block_secondary)
    - seccomp syscall groups
    - print all seccomp filters under --debug
    - default seccomp list update
  * new profiles:
    curl, mplayer2, SMPlayer, Calibre, ebook-viewer, KWrite,
    Geary, Liferea, peek, silentarmy, IntelliJ IDEA,
    Android Studio, electron, riot-web, Extreme Tux Racer,
    Frozen Bubble, Open Invaders, Pingus, Simutrans, SuperTux
    telegram-desktop, arm, rambox, apktool, baobab, dex2jar, gitg,
    hashcat, obs, picard, remmina, sdat2img, soundconverter
    truecraft, gnome-twitch, tuxguitar, musescore, neverball
    sqlitebrowse, Yandex Browser, minetest

OBS-URL: https://build.opensuse.org/request/show/522777
OBS-URL: https://build.opensuse.org/package/show/Virtualization/firejail?expand=0&rev=8
2017-09-13 09:08:57 +00:00
a872b3d7c4 Accepting request 517016 from home:tiwai:branches:Virtualization
- Update to version 0.9.48:
  * modifs: whitelisted Transmission, Deluge, qBitTorrent,
    KTorrent;
    please use ~/Downloads directory for saving files
  * modifs: AppArmor made optional; a warning is printed on the
    screen if the sandbox fails to load the AppArmor profile
  * feature: --novideo
  * feature: drop discretionary access control capabilities for
    root sandboxes
  * feature: added /etc/firejail/globals.local for global
    customizations
  * feature: profile support in overlayfs mode
  * new profiles: vym, darktable, Waterfox, digiKam, Catfish,
    HandBrake
  * bugfixes

OBS-URL: https://build.opensuse.org/request/show/517016
OBS-URL: https://build.opensuse.org/package/show/Virtualization/firejail?expand=0&rev=7
2017-08-15 14:51:08 +00:00
f1a8cd5699 - Update to version 0.9.44.4:
* --bandwidth root shell found by Martin Carpenter (CVE-2017-5207)
  * disabled --allow-debuggers when running on kernel versions prior
    to 4.8; a kernel bug in ptrace system call allows a full bypass
    of seccomp filter; problem reported by Lizzie Dixon (CVE-2017-5206)
  * root exploit found by Sebastian Krahmer (CVE-2017-5180)
- Update to version 0.9.44.6:
  * new fix for CVE-2017-5180 reported by Sebastian Krahmer last week
  * major cleanup of file copying code
  * tightening the rules for --chroot and --overlay features
  * ported Gentoo compile patch
  * Nvidia drivers bug in --private-dev
  * fix ASSERT_PERMS_FD macro
  * allow local customization using .local files under /etc/firejail
    backported from our development branch
  * spoof machine-id backported from our development branch
- Remove obsoleted patches:
  firejail-CVE-2017-5180-fix1.patch
  firejail-CVE-2017-5180-fix2.patch

OBS-URL: https://build.opensuse.org/package/show/Virtualization/firejail?expand=0&rev=6
2017-01-16 15:36:03 +00:00
Ismail Dönmez
7a7ff5e7fe Accepting request 448835 from home:tiwai:branches:Virtualization
- Update to version 0.9.44.2:
  Security fixes:
  * overwrite /etc/resolv.conf found by Martin Carpenter
  * TOCTOU exploit for –get and –put found by Daniel Hodson
  * invalid environment exploit found by Martin Carpenter
  * several security enhancements
  Bugfixes:
  * crashing VLC by pressing Ctrl-O
  * use user configured icons in KDE
  * mkdir and mkfile are not applied to private directories
  * cannot open files on Deluge running under KDE
  * –private=dir where dir is the user home directory
  * cannot start Vivaldi browser
  * cannot start mupdf
  * ssh profile problems
  * –quiet
  * quiet in git profile
  * memory corruption
- Fix VUL-0: local root exploit (CVE-2017-5180,bsc#1018259):
  firejail-CVE-2017-5180-fix1.patch
  firejail-CVE-2017-5180-fix2.patch

OBS-URL: https://build.opensuse.org/request/show/448835
OBS-URL: https://build.opensuse.org/package/show/Virtualization/firejail?expand=0&rev=5
2017-01-07 09:27:56 +00:00
Ismail Dönmez
c5bd94cd19 Accepting request 437560 from home:tiwai:branches:Virtualization
- Update to version 0.9.44:
  * CVE-2016-7545 submitted by Aleksey Manevich
  Modifications:
  * removed man firejail-config
  * –private-tmp whitelists /tmp/.X11-unix directory
  * Nvidia drivers added to –private-dev
  * /srv supported by –whitelist
  New features:
  * allow user access to /sys/fs (–noblacklist=/sys/fs)
  * support starting/joining sandbox is a single command (–join-or-start)
  * X11 detection support for –audit
  * assign a name to the interface connected to the bridge (–veth-name)
  * all user home directories are visible (–allusers)
  * add files to sandbox container (–put)
  * blocking x11 (–x11=block)
  * X11 security extension (–x11=xorg)
  * disable 3D hardware acceleration (–no3d)
  * x11 xpra, x11 xephyr, x11 block, allusers, no3d profile commands
  * move files in sandbox (–put)
  * accept wildcard patterns in user name field of restricted shell login feature
  New profiles:
  * qpdfview, mupdf, Luminance HDR, Synfig Studio, Gimp, Inkscape
  * feh, ranger, zathura, 7z, keepass, keepassx,
  * claws-mail, mutt, git, emacs, vim, xpdf, VirtualBox, OpenShot
  * Flowblade, Eye of GNOME (eog), Evolution

OBS-URL: https://build.opensuse.org/request/show/437560
OBS-URL: https://build.opensuse.org/package/show/Virtualization/firejail?expand=0&rev=4
2016-11-03 08:20:46 +00:00
555d6e90b4 Accepting request 431498 from home:tiwai:branches:Virtualization
- Update to version 0.9.42:
  Security fixes:
  * –whitelist deleted files
  * disable x32 ABI in seccomp
  * tighten –chroot
  * terminal sandbox escape
  * several TOCTOU fixes
  Behavior changes:
  * bringing back –private-home option
  * deprecated –user option, please use “sudo -u username firejail”
  * allow symlinks in home directory for –whitelist option
  * Firejail prompt is enabled by env variable FIREJAIL_PROMPT=”yes”
  * recursive mkdir
  * include /dev/snd in –private-dev
  * seccomp filter update
  * release archives moved to .xz format
  New features:
  * AppImage support (–appimage)
  * AppArmor support (–apparmor)
  * Ubuntu snap support (/etc/firejail/snap.profile)
  * Sandbox auditing support (–audit)
  * remove environment variable (–rmenv)
  * noexec support (–noexec)
  * clean local overlay storage directory (–overlay-clean)
  * store and reuse overlay (–overlay-named)
  * allow debugging inside the sandbox with gdb and strace (–allow-debuggers)
  * mkfile profile command
  * quiet profile command
  * x11 profile command
  * option to fix desktop files (firecfg –fix)

OBS-URL: https://build.opensuse.org/request/show/431498
OBS-URL: https://build.opensuse.org/package/show/Virtualization/firejail?expand=0&rev=3
2016-10-13 08:58:49 +00:00
Ismail Dönmez
c0b4cdac0f Accepting request 400690 from home:tiwai:branches:Virtualization
- Update to version 0.9.40:
  * Added firecfg utility
  * New options: -nice, -cpu.print, -writable-etc, -writable-var,
    -read-only
  * X11 support: -x11 option (-x11=xpra, -x11=xephr)
  * Filetransfer options: –ls and –get
  * Added mkdir, ipc-namespace, and nosound profile commands
  * added net, ip, defaultgw, ip6, mac, mtu and iprange profile
    commands
  * Run time config support, man firejail-config
  * AppArmor fixes
  * Default seccomp filter update
  * Disable STUN/WebRTC in default netfilter configuration
  * Lots of new profiles

OBS-URL: https://build.opensuse.org/request/show/400690
OBS-URL: https://build.opensuse.org/package/show/Virtualization/firejail?expand=0&rev=2
2016-06-08 17:13:02 +00:00
755e067884 Accepting request 397032 from home:tiwai:firejail
This is a request for a new package "firejail".
It's a lightweight sandbox using namespace and seccomp.

Let me know if Virtualization doesn't fit as the devel project for such a program.

OBS-URL: https://build.opensuse.org/request/show/397032
OBS-URL: https://build.opensuse.org/package/show/Virtualization/firejail?expand=0&rev=1
2016-05-24 05:12:25 +00:00
4 changed files with 0 additions and 28 deletions

View File

@@ -1,3 +0,0 @@
version https://git-lfs.github.com/spec/v1
oid sha256:82e177c48cfc87f62b088b55efc53ff4612b9740aab5ea35cbf2395e83efe7f4
size 503192

View File

@@ -1,11 +0,0 @@
-----BEGIN PGP SIGNATURE-----
iQEzBAABCgAdFiEE+VEWSZX1xABqc0EeLMs2rfxYSacFAmPFc+MACgkQLMs2rfxY
SacfywgAnwZQTaBTK/bwUgcu3vBeptFtmiAgCRYSbabCXoX2HvssAO3h5Jk8Vxt7
nsauL0Opxw01yocAXD03aS9ShMSB5zzhbk+Svlu6yieIvw4mYCyZbho4baAZA83H
Q7V+HH3CEN1fyRwyA8gcYqEjdrf9fd6EbzoOkokTfg98b+hx5ad08o652G8X3GHI
aYV+Gdc5NJ2ChRo07XeeIfIHHfIBWWrcxhXGhvWHovNaqA0+h+vAZ4RvLvY2pd3J
yq0r+68NciUsoOyJBQvopmFG/xH+fRBDgbui8JP3tyoUr/82BEgPpA89rUiGrft3
lvssRZ9TsjS7lbpd/YdEXqqE/aQcQg==
=skSG
-----END PGP SIGNATURE-----

View File

@@ -1,3 +0,0 @@
version https://git-lfs.github.com/spec/v1
oid sha256:70d8b56c7f87bbf15880ecb2b246ac891e3a1eed85df1b8dd1f00903a50c8113
size 527640

View File

@@ -1,11 +0,0 @@
-----BEGIN PGP SIGNATURE-----
iQEzBAABCgAdFiEE+VEWSZX1xABqc0EeLMs2rfxYSacFAmfisW0ACgkQLMs2rfxY
SacqvAf+JlVKedO98divpP0TI9izdgA+8By3xQgeKyKeoT3jJhqT2a9YEPrkGTc5
BnCFwLhaqPm+JA7q6ytajl0Pr9rIGuVVxf25/GG6W11CZGVWgQEl2oJVXM17Jbq3
sYnj+Sse0ss3dTiWSLBSTJz1mRCdoe0gjy8VbyFa1ARPvhDoy6Jjb0WJMc3iOkni
QZg08O3KlZ2yZJe2aZFeV7bOFs3HgGqjfuPZ1jco3tmmIk9mIyDrlIrQNe04/l+E
G3GsP8mE5qXa8kd+dlldImW+VmGmXvSXZhLYiKcwvB06SJXdpQRPdhjJ4WT5OgrY
j9g59vySPEfFNJ+L1iTmUAK91YT0DA==
=B+g+
-----END PGP SIGNATURE-----