aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLibravatar glitsj16 <glitsj16@users.noreply.github.com>2019-02-24 21:53:50 +0000
committerLibravatar GitHub <noreply@github.com>2019-02-24 21:53:50 +0000
commite80b99934977a623d8090eee678fac34b2de1950 (patch)
treee9904e5879cdf88d8797e1aafc2d56a2f396ec46
parentHarden gnome-maps.profile (#2462) (diff)
downloadfirejail-e80b99934977a623d8090eee678fac34b2de1950.tar.gz
firejail-e80b99934977a623d8090eee678fac34b2de1950.tar.zst
firejail-e80b99934977a623d8090eee678fac34b2de1950.zip
Harden gucharmap.profile (#2463)
-rw-r--r--etc/gucharmap.profile9
1 files changed, 8 insertions, 1 deletions
diff --git a/etc/gucharmap.profile b/etc/gucharmap.profile
index 13db746f8..c85424de9 100644
--- a/etc/gucharmap.profile
+++ b/etc/gucharmap.profile
@@ -14,8 +14,10 @@ include disable-passwdmgr.inc
14include disable-programs.inc 14include disable-programs.inc
15include disable-xdg.inc 15include disable-xdg.inc
16 16
17apparmor
17caps.drop all 18caps.drop all
18netfilter 19machine-id
20net none
19no3d 21no3d
20nodvd 22nodvd
21nogroups 23nogroups
@@ -30,10 +32,15 @@ seccomp
30shell none 32shell none
31 33
32disable-mnt 34disable-mnt
35# for GTK theme support comment 'private'
33private 36private
34private-cache 37private-cache
35private-dev 38private-dev
36private-tmp 39private-tmp
37 40
41memory-deny-write-execute
38noexec ${HOME} 42noexec ${HOME}
39noexec /tmp 43noexec /tmp
44
45# gucharmap will never write anything
46read-only ${HOME}