aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLibravatar Ondřej Nový <ondrej.novy@firma.seznam.cz>2020-07-17 10:38:29 +0200
committerLibravatar Ondřej Nový <ondrej.novy@firma.seznam.cz>2020-07-20 08:20:12 +0200
commit4c712cbaaf593e4e8cd39d798fba714a2aff51ea (patch)
tree057a2691510c229b1bf825dcd74d39c61831ef24
parentMerge pull request #3516 from smitsohu/busybox (diff)
downloadfirejail-4c712cbaaf593e4e8cd39d798fba714a2aff51ea.tar.gz
firejail-4c712cbaaf593e4e8cd39d798fba714a2aff51ea.tar.zst
firejail-4c712cbaaf593e4e8cd39d798fba714a2aff51ea.zip
Hardend Zoom profile
-rw-r--r--etc/profile-m-z/zoom.profile14
1 files changed, 14 insertions, 0 deletions
diff --git a/etc/profile-m-z/zoom.profile b/etc/profile-m-z/zoom.profile
index 6eac10703..b3125ee50 100644
--- a/etc/profile-m-z/zoom.profile
+++ b/etc/profile-m-z/zoom.profile
@@ -10,8 +10,11 @@ noblacklist ${HOME}/.zoom
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
13include disable-exec.inc
13include disable-interpreters.inc 14include disable-interpreters.inc
15include disable-passwdmgr.inc
14include disable-programs.inc 16include disable-programs.inc
17include disable-xdg.inc
15 18
16mkdir ${HOME}/.cache/zoom 19mkdir ${HOME}/.cache/zoom
17mkfile ${HOME}/.config/zoomus.conf 20mkfile ${HOME}/.config/zoomus.conf
@@ -20,14 +23,25 @@ whitelist ${HOME}/.cache/zoom
20whitelist ${HOME}/.config/zoomus.conf 23whitelist ${HOME}/.config/zoomus.conf
21whitelist ${HOME}/.zoom 24whitelist ${HOME}/.zoom
22include whitelist-common.inc 25include whitelist-common.inc
26include whitelist-runuser-common.inc
27include whitelist-usr-share-common.inc
28include whitelist-var-common.inc
23 29
24caps.drop all 30caps.drop all
25netfilter 31netfilter
26nodvd 32nodvd
33nogroups
27nonewprivs 34nonewprivs
28noroot 35noroot
29notv 36notv
37nou2f
30protocol unix,inet,inet6,netlink 38protocol unix,inet,inet6,netlink
31seccomp !chroot 39seccomp !chroot
40shell none
41tracelog
32 42
43disable-mnt
44private-cache
45private-dev
46private-etc alternatives,ca-certificates,crypto-policies,fonts,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,machine-id,nsswitch.conf,pki,resolv.conf,ssl
33private-tmp 47private-tmp