aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLibravatar glitsj16 <glitsj16@users.noreply.github.com>2024-03-27 12:26:03 +0000
committerLibravatar GitHub <noreply@github.com>2024-03-27 12:26:03 +0000
commitdbf206dcd67f506cba39bdff02824f5b65ad5934 (patch)
tree0d826458c1bfe3cd983720be05bcba71f7a67de9
parentNew profile: gh (GitHub CLI) (#6293) (diff)
downloadfirejail-dbf206dcd67f506cba39bdff02824f5b65ad5934.tar.gz
firejail-dbf206dcd67f506cba39bdff02824f5b65ad5934.tar.zst
firejail-dbf206dcd67f506cba39bdff02824f5b65ad5934.zip
pkglog: hardening (x11) (#6292)
-rw-r--r--etc/profile-m-z/pkglog.profile4
1 files changed, 4 insertions, 0 deletions
diff --git a/etc/profile-m-z/pkglog.profile b/etc/profile-m-z/pkglog.profile
index 799c8f607..2f200e154 100644
--- a/etc/profile-m-z/pkglog.profile
+++ b/etc/profile-m-z/pkglog.profile
@@ -6,6 +6,8 @@ include pkglog.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9blacklist ${RUNUSER}
10
9# Allow python (blacklisted by disable-interpreters.inc) 11# Allow python (blacklisted by disable-interpreters.inc)
10include allow-python3.inc 12include allow-python3.inc
11 13
@@ -14,6 +16,7 @@ include disable-devel.inc
14include disable-exec.inc 16include disable-exec.inc
15include disable-interpreters.inc 17include disable-interpreters.inc
16include disable-programs.inc 18include disable-programs.inc
19#include disable-x11.inc # x11 none
17include disable-xdg.inc 20include disable-xdg.inc
18 21
19whitelist /var/log/apt/history.log 22whitelist /var/log/apt/history.log
@@ -37,6 +40,7 @@ nou2f
37novideo 40novideo
38seccomp 41seccomp
39tracelog 42tracelog
43x11 none
40 44
41disable-mnt 45disable-mnt
42private 46private