Firejail: Making cgroup feature configurable in firejail.config

Created on 27 Jan 2019  路  3Comments  路  Source: netblue30/firejail

Currently some functionality can be globally disabled in /etc/firejail/firejail.config.
Can you please extend it to allow disabling --cgroup?
Some users might want to disallow that as it can place the process in a different cgroup with different restrictions.

enhancement

Most helpful comment

All 3 comments

Awesome, thanks.
I will probably backport it to Debian's 0.9.58 package, as this was mentioned in a bug report (https://bugs.debian.org/916920) and disable it in the default configuration.

No problem, and thanks for the fix! Somehow I've missed strncmp!

Was this page helpful?
0 / 5 - 0 ratings

Related issues

reinerh picture reinerh  路  3Comments

ghost picture ghost  路  3Comments

dandelionred picture dandelionred  路  3Comments

polyzen picture polyzen  路  4Comments

Fincer picture Fincer  路  4Comments