Skip to content

Commit

Permalink
Merge pull request #6653 from kmk3/docs-clarify-build
Browse files Browse the repository at this point in the history
docs: note that --build may generate a non-functional profile
  • Loading branch information
kmk3 authored Feb 21, 2025
2 parents 82d5587 + 468e1d2 commit 733f9a9
Showing 1 changed file with 23 additions and 3 deletions.
26 changes: 23 additions & 3 deletions src/man/firejail.1.in
Original file line number Diff line number Diff line change
Expand Up @@ -219,7 +219,18 @@ $ firejail \-\-blacklist="/home/username/My Virtual Machines"
$ firejail \-\-blacklist=/home/username/My\\ Virtual\\ Machines
.TP
\fB\-\-build
The command builds a whitelisted profile. The profile is printed on the screen. The program is run in a very relaxed sandbox, with only \-\-caps.drop=all and \-\-seccomp=!chroot. Programs that raise user privileges are not supported.
The command builds a whitelisted profile.
The profile is printed on the screen.
The program is run in a very relaxed sandbox, with only \-\-caps.drop=all and
\-\-seccomp=!chroot.
Programs that raise user privileges are not supported.
.br

.br
Note: This option is intended for profile debugging and development.
The profile that is generated may be incomplete, non-functional and lacking in
security.
If you want to try to create a new profile, see CONTRIBUTING.md.
.br

.br
Expand All @@ -230,8 +241,17 @@ $ firejail \-\-build vlc ~/Videos/test.mp4
$ firejail \-\-build \-\-appimage ~/Downloads/Subsurface.AppImage
.TP
\fB\-\-build=profile-file
The command builds a whitelisted profile, and saves it in profile-file. The program is run in a very relaxed sandbox,
with only \-\-caps.drop=all and \-\-seccomp=!chroot. Programs that raise user privileges are not supported.
The command builds a whitelisted profile, and saves it in profile-file.
The program is run in a very relaxed sandbox, with only \-\-caps.drop=all and
\-\-seccomp=!chroot.
Programs that raise user privileges are not supported.
.br

.br
Note: This option is intended for profile debugging and development.
The profile that is generated may be incomplete, non-functional and lacking in
security.
If you want to try to create a new profile, see CONTRIBUTING.md.
.br

.br
Expand Down

0 comments on commit 733f9a9

Please sign in to comment.