aboutsummaryrefslogtreecommitdiffstats
path: root/etc/Thunar.profile
diff options
context:
space:
mode:
authorLibravatar Tad <tad@spotco.us>2017-07-05 09:40:54 -0400
committerLibravatar Tad <tad@spotco.us>2017-08-02 00:13:42 -0400
commit0dba38435ef92ccc01cc9ff23b69df55489ec983 (patch)
treedfd1d8db02f579183fa77acdbde9aa315596220f /etc/Thunar.profile
parentx11/xpra support (diff)
downloadfirejail-0dba38435ef92ccc01cc9ff23b69df55489ec983.tar.gz
firejail-0dba38435ef92ccc01cc9ff23b69df55489ec983.tar.zst
firejail-0dba38435ef92ccc01cc9ff23b69df55489ec983.zip
Harden profiles
- Added 'disable-devel.conf' to many profiles - Added 'disable-mnt' to many profiles - Added 'noexec' to many profiles - Removed 'netfilter' and 'net none' from profiles with 'protocol unix' - Cleaned up profiles using defaults
Diffstat (limited to 'etc/Thunar.profile')
-rw-r--r--etc/Thunar.profile12
1 files changed, 2 insertions, 10 deletions
diff --git a/etc/Thunar.profile b/etc/Thunar.profile
index ed8a37add..e62ce4e2d 100644
--- a/etc/Thunar.profile
+++ b/etc/Thunar.profile
@@ -16,20 +16,12 @@ include /etc/firejail/disable-devel.inc
16include /etc/firejail/disable-passwdmgr.inc 16include /etc/firejail/disable-passwdmgr.inc
17 17
18caps.drop all 18caps.drop all
19netfilter 19no3d
20nogroups
21nonewprivs 20nonewprivs
22noroot 21noroot
23nosound 22nosound
23novideo
24protocol unix 24protocol unix
25seccomp 25seccomp
26shell none 26shell none
27tracelog 27tracelog
28
29#
30# depending on your usage, you can enable some of the commands below:
31#
32# private-bin program
33# private-etc none
34# private-dev
35# private-tmp