aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLibravatar glitsj16 <glitsj16@users.noreply.github.com>2019-02-24 20:40:30 +0000
committerLibravatar GitHub <noreply@github.com>2019-02-24 20:40:30 +0000
commitcb176565030d229b8905a8873b0bf28b98d78914 (patch)
tree39fa9a749e94448eacffa0c69d711a5b0c467e81
parentdocumentation update (diff)
downloadfirejail-cb176565030d229b8905a8873b0bf28b98d78914.tar.gz
firejail-cb176565030d229b8905a8873b0bf28b98d78914.tar.zst
firejail-cb176565030d229b8905a8873b0bf28b98d78914.zip
Harden arch-audit.profile (#2450)
-rw-r--r--etc/arch-audit.profile7
1 files changed, 5 insertions, 2 deletions
diff --git a/etc/arch-audit.profile b/etc/arch-audit.profile
index 7321f4e90..e28733c63 100644
--- a/etc/arch-audit.profile
+++ b/etc/arch-audit.profile
@@ -17,10 +17,13 @@ include disable-passwdmgr.inc
17include disable-programs.inc 17include disable-programs.inc
18include disable-xdg.inc 18include disable-xdg.inc
19 19
20apparmor
20caps.drop all 21caps.drop all
21ipc-namespace 22ipc-namespace
23machine-id
22netfilter 24netfilter
23no3d 25no3d
26nodbus
24nodvd 27nodvd
25nogroups 28nogroups
26nonewprivs 29nonewprivs
@@ -29,14 +32,14 @@ nosound
29notv 32notv
30nou2f 33nou2f
31novideo 34novideo
32protocol unix,inet,inet6 35protocol inet,inet6
33seccomp 36seccomp
34shell none 37shell none
35 38
36disable-mnt 39disable-mnt
37private 40private
38private-cache
39private-bin arch-audit 41private-bin arch-audit
42private-cache
40private-dev 43private-dev
41private-tmp 44private-tmp
42 45