Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

docs: clarify filesystem directives #5388

Open
wants to merge 2 commits into
base: master
Choose a base branch
from
Open
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
17 changes: 16 additions & 1 deletion src/man/firejail-profile.txt
Original file line number Diff line number Diff line change
Expand Up @@ -254,6 +254,15 @@ blacklist /usr/bin/gcc*
blacklist ${PATH}/ifconfig
.br
blacklist ${HOME}/.ssh
.br

.br
Blacklisted files are visible, but get a size of 0 bytes, permissions 400,
ownership set to root:root, and reset timestamps and extended attributes.
rusty-snake marked this conversation as resolved.
Show resolved Hide resolved
I/O operations on them will fail. (including deletes).
Dieterbe marked this conversation as resolved.
Show resolved Hide resolved
.br
Blacklisted directories are visible, but get permissions 400,
ownership set to root:root and reset timestamps. I/O operations on them will fail.

.TP
\fBblacklist-nolog file_or_directory
Expand All @@ -269,9 +278,13 @@ blacklist-nolog /usr/bin/gcc*
.TP
\fBbind directory1,directory2
Mount-bind directory1 on top of directory2. This option is only available when running as root.
Directories will retain the ownership and permissions of the original directory being mounted over. (directory2)
Dieterbe marked this conversation as resolved.
Show resolved Hide resolved
After termination, modificationss affect the overlay directory. (directory1)
.TP
\fBbind file1,file2
Mount-bind file1 on top of file2. This option is only available when running as root.
Files will retain the ownership and permissions of the original file being mounted over (file2)
Dieterbe marked this conversation as resolved.
Show resolved Hide resolved
After termination, deletes do not persist but writes affect the overlayed file (file1)
.TP
\fBdisable-mnt
Disable /mnt, /media, /run/mount and /run/media access.
Expand Down Expand Up @@ -434,7 +447,9 @@ Make directory or file read-only.
Make directory or file read-write.
.TP
\fBtmpfs directory
Mount an empty tmpfs filesystem on top of directory. Directories outside user home or not owned by the user are not allowed. Sandboxes running as root are exempt from these restrictions.
Mount an empty tmpfs filesystem on top of directory. Changes do not persist after termination.
Directories outside user home or not owned by the user are not allowed. Sandboxes running as root are exempt from these restrictions.
This directive has no effect for files (they appear unmodified and changes persist after termination).
glitsj16 marked this conversation as resolved.
Show resolved Hide resolved
Comment on lines +451 to +453
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
Mount an empty tmpfs filesystem on top of directory. Changes do not persist after termination.
Directories outside user home or not owned by the user are not allowed. Sandboxes running as root are exempt from these restrictions.
This directive has no effect for files (they appear unmodified and changes persist after termination).
Mount an empty tmpfs filesystem on top of directory.
Changes do not persist after termination.
Directories outside of the user home or not owned by the user are not allowed.
Sandboxes running as root are exempt from these restrictions.
This directive has no effect for files (they appear unmodified and changes
persist after termination).

Format.

.TP
\fBtracelog
Blacklist violations logged to syslog.
Expand Down