summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLibravatar rusty-snake <print_hello_world+Public@protonmail.com>2019-05-12 12:53:46 +0200
committerLibravatar rusty-snake <print_hello_world+Public@protonmail.com>2019-05-12 12:53:46 +0200
commitda2a3fd0d1780fe7751f33cd9628879a78669118 (patch)
tree0b752daf243495e1d7ffaf070ee3f205f651b3d7
parentUpdate keepassxc.profile (#2687) (diff)
downloadfirejail-da2a3fd0d1780fe7751f33cd9628879a78669118.tar.gz
firejail-da2a3fd0d1780fe7751f33cd9628879a78669118.tar.zst
firejail-da2a3fd0d1780fe7751f33cd9628879a78669118.zip
harden & fix xiphos.profile
-rw-r--r--README4
-rw-r--r--etc/xiphos.profile8
2 files changed, 9 insertions, 3 deletions
diff --git a/README b/README
index fb8ccfb6a..3e48b2a85 100644
--- a/README
+++ b/README
@@ -560,11 +560,11 @@ rusty-snake (https://github.com/rusty-snake)
560 - fixed profiles: freeoffice-textmaker, code, newsboat, aosp, clion 560 - fixed profiles: freeoffice-textmaker, code, newsboat, aosp, clion
561 - fixed profiles: android-studio, git, gitg, github-desktop, idea.sh 561 - fixed profiles: android-studio, git, gitg, github-desktop, idea.sh
562 - fixed profiles: ffmpeg, thunderbird, gnome-system-log, file-roller 562 - fixed profiles: ffmpeg, thunderbird, gnome-system-log, file-roller
563 - fixed profiles: eog, eom 563 - fixed profiles: eog, eom, xiphos
564 - hardened profiles: disable-common.inc, disable-programs.inc 564 - hardened profiles: disable-common.inc, disable-programs.inc
565 - hardened profiles: gajim, evince, ffmpeg, feh-network.inc, qtox 565 - hardened profiles: gajim, evince, ffmpeg, feh-network.inc, qtox
566 - hardened profiles: gnome-clocks, meld, minetest, youtube-dl 566 - hardened profiles: gnome-clocks, meld, minetest, youtube-dl
567 - hardened profiles: bibletime, whois, etr, display, feh, mpv 567 - hardened profiles: bibletime, whois, etr, display, feh, mpv, xiphos
568 - gnome-mpv was renamed to celluloid 568 - gnome-mpv was renamed to celluloid
569 - some typo fixes 569 - some typo fixes
570Salvo 'LtWorf' Tomaselli (https://github.com/ltworf) 570Salvo 'LtWorf' Tomaselli (https://github.com/ltworf)
diff --git a/etc/xiphos.profile b/etc/xiphos.profile
index 3ad03e2c6..33056395e 100644
--- a/etc/xiphos.profile
+++ b/etc/xiphos.profile
@@ -13,6 +13,7 @@ noblacklist ${HOME}/.xiphos
13 13
14include disable-common.inc 14include disable-common.inc
15include disable-devel.inc 15include disable-devel.inc
16include disable-exec.inc
16include disable-interpreters.inc 17include disable-interpreters.inc
17include disable-passwdmgr.inc 18include disable-passwdmgr.inc
18include disable-programs.inc 19include disable-programs.inc
@@ -20,8 +21,11 @@ include disable-programs.inc
20whitelist ${HOME}/.sword 21whitelist ${HOME}/.sword
21whitelist ${HOME}/.xiphos 22whitelist ${HOME}/.xiphos
22include whitelist-common.inc 23include whitelist-common.inc
24include whitelist-var-common.inc
23 25
26apparmor
24caps.drop all 27caps.drop all
28machine-id
25netfilter 29netfilter
26nodvd 30nodvd
27nogroups 31nogroups
@@ -36,7 +40,9 @@ seccomp
36shell none 40shell none
37tracelog 41tracelog
38 42
43disable-mnt
39private-bin xiphos 44private-bin xiphos
45private-cache
40private-dev 46private-dev
41private-etc alternatives,fonts,resolv.conf,sword,ca-certificates,ssl,pki,crypto-policies 47private-etc alternatives,fonts,resolv.conf,sword,ca-certificates,ssli,sword.conf,pki,crypto-policies
42private-tmp 48private-tmp