diff options
author | Tad <tad@spotco.us> | 2017-09-16 14:11:43 -0400 |
---|---|---|
committer | Tad <tad@spotco.us> | 2017-09-18 18:24:13 -0400 |
commit | 3c3602fe4e747f3489c917f4de991c9043df9751 (patch) | |
tree | 052baee1387ce11b9ecd00e49a7c96d59f92d480 /etc/brackets.profile | |
parent | Fixup 36 profiles (diff) | |
download | firejail-3c3602fe4e747f3489c917f4de991c9043df9751.tar.gz firejail-3c3602fe4e747f3489c917f4de991c9043df9751.tar.zst firejail-3c3602fe4e747f3489c917f4de991c9043df9751.zip |
Harden 25 profiles
Diffstat (limited to 'etc/brackets.profile')
-rw-r--r-- | etc/brackets.profile | 14 |
1 files changed, 9 insertions, 5 deletions
diff --git a/etc/brackets.profile b/etc/brackets.profile index 151d88bdd..0a8c592a7 100644 --- a/etc/brackets.profile +++ b/etc/brackets.profile | |||
@@ -14,12 +14,16 @@ include /etc/firejail/disable-passwdmgr.inc | |||
14 | include /etc/firejail/disable-programs.inc | 14 | include /etc/firejail/disable-programs.inc |
15 | 15 | ||
16 | caps.drop all | 16 | caps.drop all |
17 | # Comment out or use --ignore=net if you want to install extensions or themes | 17 | netfilter |
18 | net none | 18 | nodvd |
19 | # Disable these if you use live preview (until I figure out a workaround) | 19 | nogroups |
20 | # Doing so should be relatively safe since there is no network access | 20 | nonewprivs |
21 | noroot | 21 | noroot |
22 | nosound | ||
23 | notv | ||
24 | novideo | ||
25 | protocol unix,inet,inet6 | ||
22 | seccomp | 26 | seccomp |
27 | shell none | ||
23 | 28 | ||
24 | private-bin bash,brackets,readlink,dirname,google-chrome,cat | ||
25 | private-dev | 29 | private-dev |