aboutsummaryrefslogtreecommitdiffstats
path: root/etc/atool.profile
diff options
context:
space:
mode:
authorLibravatar Tad <tad@spotco.us>2017-08-07 01:22:08 -0400
committerLibravatar Tad <tad@spotco.us>2017-08-07 01:22:08 -0400
commit9e3ba319be6b9546d7e8f450ca419ee2f3f4040b (patch)
tree0aebe82de78a61877c267f4dcb2ebcc13a2e37c9 /etc/atool.profile
parentvarious profile fixes (#1433) (diff)
downloadfirejail-9e3ba319be6b9546d7e8f450ca419ee2f3f4040b.tar.gz
firejail-9e3ba319be6b9546d7e8f450ca419ee2f3f4040b.tar.zst
firejail-9e3ba319be6b9546d7e8f450ca419ee2f3f4040b.zip
Unify all profiles
Diffstat (limited to 'etc/atool.profile')
-rw-r--r--etc/atool.profile19
1 files changed, 9 insertions, 10 deletions
diff --git a/etc/atool.profile b/etc/atool.profile
index 49637aa21..a1da26076 100644
--- a/etc/atool.profile
+++ b/etc/atool.profile
@@ -1,18 +1,20 @@
1# Persistent global definitions go here 1# Firejail profile for atool
2# This file is overwritten after every install/update
3# Persistent local customizations
4include /etc/firejail/atool.local
5# Persistent global definitions
2include /etc/firejail/globals.local 6include /etc/firejail/globals.local
3 7
4# This file is overwritten during software install. 8blacklist /tmp/.X11-unix
5# Persistent customizations should go in a .local file.
6include /etc/firejail/atool.local
7 9
8# atool profile
9include /etc/firejail/disable-common.inc 10include /etc/firejail/disable-common.inc
10include /etc/firejail/disable-programs.inc
11# include /etc/firejail/disable-devel.inc 11# include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-passwdmgr.inc 12include /etc/firejail/disable-passwdmgr.inc
13include /etc/firejail/disable-programs.inc
13 14
14caps.drop all 15caps.drop all
15netfilter 16netfilter
17no3d
16nogroups 18nogroups
17nonewprivs 19nonewprivs
18noroot 20noroot
@@ -20,13 +22,10 @@ nosound
20novideo 22novideo
21protocol unix 23protocol unix
22seccomp 24seccomp
23no3d
24shell none 25shell none
25tracelog 26tracelog
26 27
27blacklist /tmp/.X11-unix
28
29# private-bin atool 28# private-bin atool
30private-tmp
31private-dev 29private-dev
32private-etc none 30private-etc none
31private-tmp