summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLibravatar rusty-snake <print_hello_world+GitHub@protonmail.com>2019-03-07 20:22:00 +0000
committerLibravatar glitsj16 <glitsj16@users.noreply.github.com>2019-03-07 20:22:00 +0000
commit76e0bc8fb9fb4c5d4540fe2a86798218786bc035 (patch)
tree9c0a5b28f94566659a4dafac1c4abdf21b0155ea
parentAdd fakeroot support for makepkg on Arch (#2536) (diff)
downloadfirejail-76e0bc8fb9fb4c5d4540fe2a86798218786bc035.tar.gz
firejail-76e0bc8fb9fb4c5d4540fe2a86798218786bc035.tar.zst
firejail-76e0bc8fb9fb4c5d4540fe2a86798218786bc035.zip
Harden gnome-clocks.profile (#2534)
* Harden gnome-clocks.profile * Review #2534
-rw-r--r--etc/gnome-clocks.profile8
1 files changed, 5 insertions, 3 deletions
diff --git a/etc/gnome-clocks.profile b/etc/gnome-clocks.profile
index 83ece0fce..32a7ca918 100644
--- a/etc/gnome-clocks.profile
+++ b/etc/gnome-clocks.profile
@@ -6,7 +6,6 @@ include gnome-clocks.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9
10include disable-common.inc 9include disable-common.inc
11include disable-devel.inc 10include disable-devel.inc
12include disable-interpreters.inc 11include disable-interpreters.inc
@@ -14,8 +13,10 @@ include disable-passwdmgr.inc
14include disable-programs.inc 13include disable-programs.inc
15include disable-xdg.inc 14include disable-xdg.inc
16 15
16include whitelist-common.inc
17include whitelist-var-common.inc 17include whitelist-var-common.inc
18 18
19apparmor
19caps.drop all 20caps.drop all
20netfilter 21netfilter
21no3d 22no3d
@@ -32,9 +33,10 @@ shell none
32tracelog 33tracelog
33 34
34disable-mnt 35disable-mnt
35# private-bin gnome-clocks 36private-bin gnome-clocks,gsound-play
37private-cache
36private-dev 38private-dev
37# private-etc alternatives,fonts,ca-certificates,ssl,pki,crypto-policies 39private-etc alternatives,fonts,ca-certificates,ssl,pki,crypto-policies,machine-id,hosts,pkcs11,localtime,gtk-3.0,dconf
38private-tmp 40private-tmp
39 41
40noexec ${HOME} 42noexec ${HOME}