git: 178ffebd1631 - main - security/x11appjail: New port: Tool for creating, verifying, installing, and running AppJails

From: Jesús Daniel Colmenares Oviedo <dtxdf_at_FreeBSD.org>
Date: Sun, 20 Sep 2026 01:02:20 UTC
The branch main has been updated by dtxdf:

URL: https://cgit.FreeBSD.org/ports/commit/?id=178ffebd1631739ff6dfa3ba5b43da9287c0957c

commit 178ffebd1631739ff6dfa3ba5b43da9287c0957c
Author:     Jesús Daniel Colmenares Oviedo <dtxdf@FreeBSD.org>
AuthorDate: 2026-09-20 00:45:25 +0000
Commit:     Jesús Daniel Colmenares Oviedo <dtxdf@FreeBSD.org>
CommitDate: 2026-09-20 01:01:06 +0000

    security/x11appjail: New port: Tool for creating, verifying, installing, and running AppJails
    
    x11appjail is a specialized tool for creating, verifying, installing,
    and running AppJails. An AppJail is a CLI, TUI or X11 application
    that runs inside a FreeBSD jail but is perceived by the end user
    as identical (or at least very similar) to an application running
    directly on the host system.
    
    This tool makes extensive use of appjail(1) as its engine; however,
    unlike the latter, the primary user in x11appjail is neither root
    nor a privileged user, but rather an unprivileged user. The fundamental
    goal of this project is to grant the user limited access to the
    jail, restricted solely to the execution of a CLI, TUI or X11
    application.
    
    WWW: https://github.com/DtxdF/x11appjail
---
 security/Makefile                        |  1 +
 security/x11appjail/Makefile             | 53 ++++++++++++++++++++++++++++++++
 security/x11appjail/distinfo             |  3 ++
 security/x11appjail/files/pkg-message.in | 27 ++++++++++++++++
 security/x11appjail/pkg-descr            | 12 ++++++++
 security/x11appjail/pkg-plist            | 28 +++++++++++++++++
 6 files changed, 124 insertions(+)

diff --git a/security/Makefile b/security/Makefile
index b59a916ff519..9dcb36401b7a 100644
--- a/security/Makefile
+++ b/security/Makefile
@@ -1473,6 +1473,7 @@
     SUBDIR += wpa_supplicant-devel
     SUBDIR += wpa_supplicant210
     SUBDIR += wpa_supplicant29
+    SUBDIR += x11appjail
     SUBDIR += xca
     SUBDIR += xhash
     SUBDIR += xinetd
diff --git a/security/x11appjail/Makefile b/security/x11appjail/Makefile
new file mode 100644
index 000000000000..e9c771342bce
--- /dev/null
+++ b/security/x11appjail/Makefile
@@ -0,0 +1,53 @@
+PORTNAME=	x11appjail
+DISTVERSIONPREFIX=	v
+DISTVERSION=	1.0.0
+CATEGORIES=	security
+
+MAINTAINER=	dtxdf@FreeBSD.org
+COMMENT=	Tool for creating, verifying, installing, and running AppJails
+
+LICENSE=	BSD3CLAUSE
+LICENSE_FILE=	${WRKSRC}/LICENSE
+
+RUN_DEPENDS=	appjail:sysutils/appjail \
+		appscript:archivers/appscript \
+		doas:security/doas \
+		git:devel/git@lite \
+		notify-send:devel/libnotify \
+		su-exec:security/su-exec \
+		unixexec:sysutils/unixexec \
+		update-desktop-database:devel/desktop-file-utils \
+		xauth:x11/xauth \
+		xclipsync:sysutils/xclipsync \
+		xdg-open:devel/xdg-utils \
+		xdotool:x11/xdotool \
+		Xephyr:x11-servers/xorg-server@xephyr \
+		xev:x11/xev \
+		xseticon:x11/xseticon \
+		zenity:x11/zenity4
+
+USE_GITHUB=	yes
+GH_ACCOUNT=	DtxdF
+GH_PROJECT=	x11appjail
+
+NO_BUILD=	yes
+SUB_FILES=	pkg-message
+
+OPTIONS_DEFINE=	EXAMPLES
+
+PORTEXAMPLES=	*
+
+post-install-EXAMPLES-on:
+	@${MKDIR} ${STAGEDIR}/${EXAMPLESDIR}
+	@cd ${WRKSRC}/share/examples/x11appjail && ${COPYTREE_SHARE} . ${STAGEDIR}${EXAMPLESDIR}
+	@for app in ${STAGEDIR}${EXAMPLESDIR}/Apps/*; do \
+		${CHMOD} +x $${app}/build.sh; \
+		${CHMOD} +x $${app}/create; \
+		${CHMOD} +x $${app}/install; \
+		${CHMOD} +x $${app}/run; \
+		${CHMOD} +x $${app}/uninstall; \
+		if [ -f "$${app}/X" ]; then ${CHMOD} +x $${app}/X; fi; \
+		${CHMOD} +x $${app}/.reproduce/build.sh; \
+	done
+
+.include <bsd.port.mk>
diff --git a/security/x11appjail/distinfo b/security/x11appjail/distinfo
new file mode 100644
index 000000000000..e413ec4424dc
--- /dev/null
+++ b/security/x11appjail/distinfo
@@ -0,0 +1,3 @@
+TIMESTAMP = 1789850009
+SHA256 (DtxdF-x11appjail-v1.0.0_GH0.tar.gz) = da01a8f590fd3fa6898f6153cee260732be1925ea0bc13e510a514cd34d877dd
+SIZE (DtxdF-x11appjail-v1.0.0_GH0.tar.gz) = 61447
diff --git a/security/x11appjail/files/pkg-message.in b/security/x11appjail/files/pkg-message.in
new file mode 100644
index 000000000000..31bd4c4cb9ae
--- /dev/null
+++ b/security/x11appjail/files/pkg-message.in
@@ -0,0 +1,27 @@
+[
+{ type: install
+  message: <<EOM
+To allow unprivileged users to run AppJails, add the following rule to
+your doas.conf(5):
+
+  permit nopass USER cmd %%PREFIX%%/libexec/x11appjail/map-exec
+
+Replace USER with the user you want to allow to run AppJails. You can
+also use a group for this, so that you do not have to edit your
+doas.conf(5) file every time.
+
+*VERY IMPORTANT*:
+
+1. Do not set keepenv. Environment variables can affect the execution of
+   the mentioned utility or the utilities it depends on. You do not need
+   it, and you should not configure it.
+2. In doas.conf(5), the last rules take precedence; therefore, add the
+   previous rule on the last line.
+
+   You can run the following command and confirm that the environment is
+   not inherited:
+
+     doas %%PREFIX%%/libexec/x11appjail/map-exec env
+EOM
+}
+]
diff --git a/security/x11appjail/pkg-descr b/security/x11appjail/pkg-descr
new file mode 100644
index 000000000000..c03a19554405
--- /dev/null
+++ b/security/x11appjail/pkg-descr
@@ -0,0 +1,12 @@
+x11appjail is a specialized tool for creating, verifying, installing,
+and running AppJails. An AppJail is a CLI, TUI or X11 application
+that runs inside a FreeBSD jail but is perceived by the end user
+as identical (or at least very similar) to an application running
+directly on the host system.
+
+This tool makes extensive use of appjail(1) as its engine; however,
+unlike the latter, the primary user in x11appjail is neither root
+nor a privileged user, but rather an unprivileged user. The fundamental
+goal of this project is to grant the user limited access to the
+jail, restricted solely to the execution of a CLI, TUI or X11
+application.
diff --git a/security/x11appjail/pkg-plist b/security/x11appjail/pkg-plist
new file mode 100644
index 000000000000..1db918b4190b
--- /dev/null
+++ b/security/x11appjail/pkg-plist
@@ -0,0 +1,28 @@
+bin/x11appjail
+lib/x11appjail/common
+libexec/x11appjail/appsiz
+libexec/x11appjail/destroy-jail
+libexec/x11appjail/exec
+libexec/x11appjail/login
+libexec/x11appjail/map-exec
+libexec/x11appjail/misc/simple-desktop-file-utils.sh
+libexec/x11appjail/print-display
+libexec/x11appjail/remove
+libexec/x11appjail/run-cmd
+libexec/x11appjail/service.d/Notification/agent
+libexec/x11appjail/service.d/Notification/exec
+libexec/x11appjail/service.d/Notification/setup
+libexec/x11appjail/service.d/OpenURL/agent
+libexec/x11appjail/service.d/OpenURL/exec
+libexec/x11appjail/service.d/OpenURL/setup
+libexec/x11appjail/veriexec
+share/man/man1/x11appjail.1.gz
+share/man/man5/x11appjail-spec.5.gz
+%%DATADIR%%/appscript/APPSCRIPT
+%%DATADIR%%/scaffold/Makejail
+%%DATADIR%%/scaffold/X
+%%DATADIR%%/scaffold/create
+%%DATADIR%%/scaffold/install
+%%DATADIR%%/scaffold/run
+%%DATADIR%%/scaffold/template.conf
+%%DATADIR%%/scaffold/uninstall