Firefox for OpenBSD adds support for unveil

In Firefox for OpenBSD implemented file system isolation support via system call unveil(). The necessary patches have already been accepted into firefox upstream and will be included in Firefox 72.

Firefox in OpenBSD was and was previously secured using pledge to restrict access of each process type (main, content and GPU) to system calls, now they will also be restricted access to the file system using unveil(). By default, access is limited to ~/Downloads and /tmp directories; both when downloading files from the network, and when viewing files from a disk. The pledge() and unveil() settings are stored in files in /usr/local/lib/firefox/browser/defaults/preferences/, the contents of which can be overridden in files in /etc/firefox/. The advantage of the second option is that only root can edit these files.

Previously, similar opportunities were added in Chromium and Iridium browsers.

Source: opennet.ru

Add a comment