diff options
author | glitsj16 <glitsj16@users.noreply.github.com> | 2020-01-17 23:31:46 +0000 |
---|---|---|
committer | GitHub <noreply@github.com> | 2020-01-17 23:31:46 +0000 |
commit | f9c9c469a23dbb6d484f82f6ba719d662b784753 (patch) | |
tree | 9485d36a39798b0542ed70b9a5df688bab2c3d69 /etc/devilspie.profile | |
parent | join: wait with effective uid of the user (diff) | |
download | firejail-f9c9c469a23dbb6d484f82f6ba719d662b784753.tar.gz firejail-f9c9c469a23dbb6d484f82f6ba719d662b784753.tar.zst firejail-f9c9c469a23dbb6d484f82f6ba719d662b784753.zip |
hardenings for various profiles (#3160)
* harden devilspie
* harden devilspie2
* harden curl
* harden wget
* harden curl
* harden dig
* harden claws-mail
* harden dnscrypt-proxy
* harden dnscrypt-proxy
* harden dnscrypt-proxy
* harden exfalso
* refactor easystroke as whitelist profile
* refactor enchant as whitelist profile
* safeguard ${DOCUMENTS}
Thanks @rusty-snake for the suggestion.
* drop x11-none
Thanks @rusty-snake for catching this.
* drop x11 none
Thanks @rusty-snake for saving the bacon...
* drop x11 none
Thanks @rusty-snake for catching this.
* drop x11 none
Thanks @rusty-snake for preventing breakage!
* drop ipc-namespace
Better safe than sorry...
Diffstat (limited to 'etc/devilspie.profile')
-rw-r--r-- | etc/devilspie.profile | 3 |
1 files changed, 3 insertions, 0 deletions
diff --git a/etc/devilspie.profile b/etc/devilspie.profile index ad891ffaf..bbbdfd702 100644 --- a/etc/devilspie.profile +++ b/etc/devilspie.profile | |||
@@ -8,6 +8,8 @@ include globals.local | |||
8 | 8 | ||
9 | noblacklist ${HOME}/.devilspie | 9 | noblacklist ${HOME}/.devilspie |
10 | 10 | ||
11 | blacklist /tmp/.X11-unix | ||
12 | |||
11 | include disable-common.inc | 13 | include disable-common.inc |
12 | include disable-devel.inc | 14 | include disable-devel.inc |
13 | include disable-exec.inc | 15 | include disable-exec.inc |
@@ -41,6 +43,7 @@ protocol unix | |||
41 | seccomp | 43 | seccomp |
42 | shell none | 44 | shell none |
43 | tracelog | 45 | tracelog |
46 | x11 none | ||
44 | 47 | ||
45 | disable-mnt | 48 | disable-mnt |
46 | private-bin devilspie | 49 | private-bin devilspie |