aboutsummaryrefslogtreecommitdiffstats
path: root/etc/baloo_file.profile
diff options
context:
space:
mode:
authorLibravatar smitsohu <smitsohu@gmail.com>2019-01-30 16:12:49 +0100
committerLibravatar smitsohu <smitsohu@gmail.com>2019-01-30 16:12:49 +0100
commit0f7636c1ca3ab81c4d1af13b548bc094d038dcbe (patch)
treeb5b4badbccfe3c8c7cde9bdebae0508842e57829 /etc/baloo_file.profile
parentFixup qtox profile, closes #2374 (diff)
downloadfirejail-0f7636c1ca3ab81c4d1af13b548bc094d038dcbe.tar.gz
firejail-0f7636c1ca3ab81c4d1af13b548bc094d038dcbe.tar.zst
firejail-0f7636c1ca3ab81c4d1af13b548bc094d038dcbe.zip
misc profile hardening (xdg blacklist, private-cache, netfilter)
Diffstat (limited to 'etc/baloo_file.profile')
-rw-r--r--etc/baloo_file.profile2
1 files changed, 2 insertions, 0 deletions
diff --git a/etc/baloo_file.profile b/etc/baloo_file.profile
index e094945b7..875bc7989 100644
--- a/etc/baloo_file.profile
+++ b/etc/baloo_file.profile
@@ -26,6 +26,7 @@ include disable-programs.inc
26include whitelist-var-common.inc 26include whitelist-var-common.inc
27 27
28caps.drop all 28caps.drop all
29netfilter
29no3d 30no3d
30nodvd 31nodvd
31nogroups 32nogroups
@@ -41,6 +42,7 @@ seccomp.drop @cpu-emulation,@debug,@obsolete,@privileged,@resources,add_key,fano
41shell none 42shell none
42# x11 xorg 43# x11 xorg
43 44
45private-cache
44private-bin baloo_file,baloo_file_extractor,baloo_filemetadata_temp_extractor,kbuildsycoca4 46private-bin baloo_file,baloo_file_extractor,baloo_filemetadata_temp_extractor,kbuildsycoca4
45private-dev 47private-dev
46private-tmp 48private-tmp