|
@@ -0,0 +1,19 @@
|
|
|
+config BR2_PACKAGE_FIREJAIL
|
|
|
+ bool "firejail"
|
|
|
+ depends on BR2_USE_MMU # fork()
|
|
|
+ depends on BR2_TOOLCHAIN_HAS_THREADS
|
|
|
+ # uClibc: error: ‘EM_ARM’ undeclared
|
|
|
+ depends on !BR2_TOOLCHAIN_USES_UCLIBC
|
|
|
+ help
|
|
|
+ Firejail is a SUID program that reduces the risk of security
|
|
|
+ breaches by restricting the running environment of untrusted
|
|
|
+ applications using Linux namespaces and seccomp-bpf. It
|
|
|
+ allows a process and all its descendants to have their own
|
|
|
+ private view of the globally shared kernel resources, such
|
|
|
+ as the network stack, process table, mount table.
|
|
|
+
|
|
|
+ https://firejail.wordpress.com/
|
|
|
+
|
|
|
+comment "firejail needs a glibc or musl toolchain w/ threads"
|
|
|
+ depends on BR2_USE_MMU
|
|
|
+ depends on !BR2_TOOLCHAIN_USES_UCLIBC || !BR2_TOOLCHAIN_HAS_THREADS
|