aboutsummaryrefslogtreecommitdiffstats
path: root/etc/bless.profile
diff options
context:
space:
mode:
authorLibravatar Tad <tad@spotco.us>2017-04-15 08:57:13 -0400
committerLibravatar Tad <tad@spotco.us>2017-04-15 15:25:08 -0400
commit90cd669eba680369c6ba8d96af194b70c8cc8706 (patch)
tree31c4d14fa5b56003b9898c8e6d19f03b7d91b091 /etc/bless.profile
parentnoblacklist .config/qt5ct (part 1) (diff)
downloadfirejail-90cd669eba680369c6ba8d96af194b70c8cc8706.tar.gz
firejail-90cd669eba680369c6ba8d96af194b70c8cc8706.tar.zst
firejail-90cd669eba680369c6ba8d96af194b70c8cc8706.zip
Harden some profiles
Diffstat (limited to 'etc/bless.profile')
-rw-r--r--etc/bless.profile14
1 files changed, 13 insertions, 1 deletions
diff --git a/etc/bless.profile b/etc/bless.profile
index b8325de39..08a756989 100644
--- a/etc/bless.profile
+++ b/etc/bless.profile
@@ -18,7 +18,19 @@ include /etc/firejail/disable-devel.inc
18#Options 18#Options
19caps.drop all 19caps.drop all
20netfilter 20netfilter
21nogroups
21nonewprivs 22nonewprivs
22noroot 23noroot
23protocol unix,inet,inet6 24protocol unix
24seccomp 25seccomp
26shell none
27
28private-dev
29private-etc fonts,mono
30private-tmp
31
32noexec ${HOME}
33noexec /tmp
34
35no3d
36nosound