summaryrefslogtreecommitdiffstats
path: root/etc/disable-common.inc
diff options
context:
space:
mode:
authorLibravatar netblue30 <netblue30@yahoo.com>2015-10-30 08:55:25 -0400
committerLibravatar netblue30 <netblue30@yahoo.com>2015-10-30 08:55:25 -0400
commit2b37849dbdc1e7be2fac0756a39de8e54b40ae2c (patch)
tree7ddf41d4c3b53176aa978ddd63384e009125bd1b /etc/disable-common.inc
parentrelease 0.9.34-rc1 testing (diff)
downloadfirejail-2b37849dbdc1e7be2fac0756a39de8e54b40ae2c.tar.gz
firejail-2b37849dbdc1e7be2fac0756a39de8e54b40ae2c.tar.zst
firejail-2b37849dbdc1e7be2fac0756a39de8e54b40ae2c.zip
Protect shell startup files
Diffstat (limited to 'etc/disable-common.inc')
-rw-r--r--etc/disable-common.inc33
1 files changed, 33 insertions, 0 deletions
diff --git a/etc/disable-common.inc b/etc/disable-common.inc
index ece906717..87a979034 100644
--- a/etc/disable-common.inc
+++ b/etc/disable-common.inc
@@ -76,3 +76,36 @@ blacklist /etc/profile.d
76blacklist /etc/rc.local 76blacklist /etc/rc.local
77blacklist /etc/anacrontab 77blacklist /etc/anacrontab
78 78
79# General startup files
80read-only ${HOME}/.xinitrc
81read-only ${HOME}/.xserverrc
82read-only ${HOME}/.profile
83
84# Shell startup files
85read-only ${HOME}/.bash_login
86read-only ${HOME}/.bashrc
87read-only ${HOME}/.bash_profile
88read-only ${HOME}/.bash_logout
89read-only ${HOME}/.zshrc
90read-only ${HOME}/.zlogin
91read-only ${HOME}/.zprofile
92read-only ${HOME}/.zlogout
93read-only ${HOME}/.zsh_files
94read-only ${HOME}/.tcshrc
95read-only ${HOME}/.cshrc
96read-only ${HOME}/.csh_files
97
98# Initialization files that allow arbitrary command execution
99read-only ${HOME}/.mailcap
100read-only ${HOME}/.exrc
101read-only ${HOME}/.vimrc
102read-only ${HOME}/.vim
103read-only ${HOME}/.emacs
104read-only ${HOME}/.tmux.conf
105read-only ${HOME}/.iscreenrc
106read-only ${HOME}/.muttrc
107read-only ${HOME}/.xmonad
108
109# The user ~/bin directory can override commands such as ls
110read-only ${HOME}/bin
111