Restricted lf #1786
Replies: 2 comments
-
What would be different in normal and restricted lf? |
Beta Was this translation helpful? Give feedback.
-
The rvim and rnano version both disable some dangerous features that are available by default in their normal version. lf lf is run as root without a custom lfrc, which would have to be manually installed by the user, there should be no dangerous features available in the sense of rvim or rnano restrictions. Manually configured file preview scripts would probably represent the most significant risks in lf in general. If security is a concern, there is an easy to configure option to execute the preview script in a sandbox which will reduce the risks significantly. Alternatively you can also use apparmor to confine applications that are automatically executed by lf preview scripts. https://github.com/roddhjav/apparmor.d is a decent collection of profiles that include most of such application. |
Beta Was this translation helpful? Give feedback.
-
Vim and nano packages include more restricted versions
rvim
andrnano
that minimize their capabilities in order to be safe to run as root.Thoughts on creating a similar stripped-down version of lf?
Beta Was this translation helpful? Give feedback.
All reactions