diff options
author | glitsj16 <glitsj16@users.noreply.github.com> | 2019-03-14 12:01:43 +0000 |
---|---|---|
committer | GitHub <noreply@github.com> | 2019-03-14 12:01:43 +0000 |
commit | 097aba97d8cb0a848f1f21018f65c58d48ef3cb2 (patch) | |
tree | bb5159f2651680606ccf7208dd4f48e1add373fe /etc/bsdtar.profile | |
parent | Fixes for seahorse/seahorse-tool (#2592) (diff) | |
download | firejail-097aba97d8cb0a848f1f21018f65c58d48ef3cb2.tar.gz firejail-097aba97d8cb0a848f1f21018f65c58d48ef3cb2.tar.zst firejail-097aba97d8cb0a848f1f21018f65c58d48ef3cb2.zip |
Hardening compressors (#2594)
* Harden atool
* Harden cpio
* Fix ordering in private-* options
* Harden gzip
* Harden tar
* Harden bsdtar
* Harden+ tar
* Harden+ gzip
* Harden+ cpio
* Create bzip2.profile
* Description for bunzip2
* Add bzip2/bunzip2 to firecfg
Diffstat (limited to 'etc/bsdtar.profile')
-rw-r--r-- | etc/bsdtar.profile | 7 |
1 files changed, 7 insertions, 0 deletions
diff --git a/etc/bsdtar.profile b/etc/bsdtar.profile index b6b673976..f964438bc 100644 --- a/etc/bsdtar.profile +++ b/etc/bsdtar.profile | |||
@@ -10,16 +10,20 @@ blacklist /tmp/.X11-unix | |||
10 | 10 | ||
11 | include disable-common.inc | 11 | include disable-common.inc |
12 | # include disable-devel.inc | 12 | # include disable-devel.inc |
13 | include disable-exec.inc | ||
13 | include disable-interpreters.inc | 14 | include disable-interpreters.inc |
14 | include disable-passwdmgr.inc | 15 | include disable-passwdmgr.inc |
15 | include disable-programs.inc | 16 | include disable-programs.inc |
16 | 17 | ||
18 | apparmor | ||
17 | caps.drop all | 19 | caps.drop all |
18 | hostname bsdtar | 20 | hostname bsdtar |
19 | ipc-namespace | 21 | ipc-namespace |
22 | machine-id | ||
20 | netfilter | 23 | netfilter |
21 | no3d | 24 | no3d |
22 | nodvd | 25 | nodvd |
26 | nodbus | ||
23 | nogroups | 27 | nogroups |
24 | nonewprivs | 28 | nonewprivs |
25 | # noroot | 29 | # noroot |
@@ -34,5 +38,8 @@ tracelog | |||
34 | 38 | ||
35 | # support compressed archives | 39 | # support compressed archives |
36 | private-bin sh,bash,bsdcat,bsdcpio,bsdtar,gtar,compress,gzip,lzma,xz,bzip2,lbzip2,lzip,lzop,lz4,libarchive | 40 | private-bin sh,bash,bsdcat,bsdcpio,bsdtar,gtar,compress,gzip,lzma,xz,bzip2,lbzip2,lzip,lzop,lz4,libarchive |
41 | private-cache | ||
37 | private-dev | 42 | private-dev |
38 | private-etc alternatives,passwd,group,localtime | 43 | private-etc alternatives,passwd,group,localtime |
44 | |||
45 | memory-deny-write-execute | ||