From 2183e4d296e598c6407d4a1f64368039a7ae1efa Mon Sep 17 00:00:00 2001 From: "Kelvin M. Klann" Date: Sun, 27 Mar 2022 18:01:16 -0300 Subject: [PATCH] docs: mention capabilities(7) on --caps As hinted by @rusty-snake[1]. [1] https://github.com/netblue30/firejail/discussions/5064#discussioncomment-2417395 --- src/man/firejail-profile.txt | 1 + src/man/firejail.txt | 1 + 2 files changed, 2 insertions(+) diff --git a/src/man/firejail-profile.txt b/src/man/firejail-profile.txt index 3dd339d94ed..0fe434faccc 100644 --- a/src/man/firejail-profile.txt +++ b/src/man/firejail-profile.txt @@ -483,6 +483,7 @@ Enable AppArmor confinement. .TP \fBcaps Enable default Linux capabilities filter. +See capabilities(7) for details. .TP \fBcaps.drop capability,capability,capability Blacklist given Linux capabilities. diff --git a/src/man/firejail.txt b/src/man/firejail.txt index 41171a4e7c4..7cb1c7e8980 100644 --- a/src/man/firejail.txt +++ b/src/man/firejail.txt @@ -216,6 +216,7 @@ not change the execution of firejail. Linux capabilities is a kernel feature designed to split up the root privilege into a set of distinct privileges. These privileges can be enabled or disabled independently, thus restricting what a process running as root can do in the system. +See capabilities(7) for details. By default root programs run with all capabilities enabled. \-\-caps option disables the following capabilities: CAP_SYS_MODULE, CAP_SYS_RAWIO,