aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLibravatar glitsj16 <glitsj16@users.noreply.github.com>2019-03-06 04:25:41 +0000
committerLibravatar GitHub <noreply@github.com>2019-03-06 04:25:41 +0000
commitf40cdf7ae36db8c14d5bf7ec8c2797ca7721316e (patch)
tree8f935eac1476f43b4b942c2d89305ee128a24f0d
parentAdd dirname to private-bin in spectre-meltdown-checker (#2524) (diff)
downloadfirejail-f40cdf7ae36db8c14d5bf7ec8c2797ca7721316e.tar.gz
firejail-f40cdf7ae36db8c14d5bf7ec8c2797ca7721316e.tar.zst
firejail-f40cdf7ae36db8c14d5bf7ec8c2797ca7721316e.zip
Add network functionality in sqlitebrowser.profile (#2525)
-rw-r--r--etc/sqlitebrowser.profile12
1 files changed, 7 insertions, 5 deletions
diff --git a/etc/sqlitebrowser.profile b/etc/sqlitebrowser.profile
index 6bdd437cd..8122079e1 100644
--- a/etc/sqlitebrowser.profile
+++ b/etc/sqlitebrowser.profile
@@ -18,10 +18,11 @@ include disable-xdg.inc
18 18
19include whitelist-var-common.inc 19include whitelist-var-common.inc
20 20
21apparmor
21caps.drop all 22caps.drop all
22net none 23ipc-namespace
23no3d 24netfilter
24nodbus 25# nodbus - breaks proxy creation
25nodvd 26nodvd
26nogroups 27nogroups
27nonewprivs 28nonewprivs
@@ -30,15 +31,16 @@ nosound
30notv 31notv
31nou2f 32nou2f
32novideo 33novideo
33protocol unix 34protocol unix,inet,inet6,netlink
34seccomp 35seccomp
35shell none 36shell none
36 37
37private-bin sqlitebrowser 38private-bin sqlitebrowser
38private-cache 39private-cache
39private-dev 40private-dev
41private-etc alternatives,ca-certificates,crypto-policies,fonts,group,machine-id,passwd,pki,ssl
40private-tmp 42private-tmp
41 43
42# memory-deny-write-execute - breaks on Arch 44memory-deny-write-execute
43noexec ${HOME} 45noexec ${HOME}
44noexec /tmp 46noexec /tmp