summaryrefslogtreecommitdiffstats
path: root/etc/disable-common.inc
diff options
context:
space:
mode:
authorLibravatar smitsohu <smitsohu@gmail.com>2018-10-12 19:55:55 +0200
committerLibravatar smitsohu <smitsohu@gmail.com>2018-10-12 19:55:55 +0200
commitbcf53870f3dab1d1a813337886bd0965976875bd (patch)
treebb6017c2bf2574690ceae4fd6da3238632261810 /etc/disable-common.inc
parentclean homedir pathname (diff)
downloadfirejail-bcf53870f3dab1d1a813337886bd0965976875bd.tar.gz
firejail-bcf53870f3dab1d1a813337886bd0965976875bd.tar.zst
firejail-bcf53870f3dab1d1a813337886bd0965976875bd.zip
consolidate cloud blacklisting, alphabetize, other nitpicks
Diffstat (limited to 'etc/disable-common.inc')
-rw-r--r--etc/disable-common.inc18
1 files changed, 10 insertions, 8 deletions
diff --git a/etc/disable-common.inc b/etc/disable-common.inc
index 0f6e6bd19..ceca17826 100644
--- a/etc/disable-common.inc
+++ b/etc/disable-common.inc
@@ -317,9 +317,11 @@ blacklist /var/backup
317# cloud provider configuration 317# cloud provider configuration
318blacklist ${HOME}/.aws 318blacklist ${HOME}/.aws
319blacklist ${HOME}/.boto 319blacklist ${HOME}/.boto
320blacklist /etc/boto.cfg
321blacklist ${HOME}/.config/gcloud 320blacklist ${HOME}/.config/gcloud
322blacklist ${HOME}/.kube 321blacklist ${HOME}/.kube
322blacklist ${HOME}/.passwd-s3fs
323blacklist ${HOME}/.s3cmd
324blacklist /etc/boto.cfg
323 325
324# system directories 326# system directories
325blacklist /sbin 327blacklist /sbin
@@ -391,14 +393,14 @@ blacklist /vmlinuz*
391# snapshot files 393# snapshot files
392blacklist /.snapshots 394blacklist /.snapshots
393 395
394# complement noexec ${HOME} and noexec /tmp
395noexec /tmp/.X11-unix
396
397# flatpak 396# flatpak
398blacklist ${HOME}/*.config/flatpak 397blacklist ${HOME}/.config/flatpak
399blacklist ${HOME}/*.var 398blacklist ${HOME}/.local/share/flatpak
400blacklist ${HOME}/*.local/share/flatpak 399blacklist ${HOME}/.var
401blacklist /var/lib/flatpak
402blacklist /usr/share/flatpak 400blacklist /usr/share/flatpak
401blacklist /var/lib/flatpak
403# most of the time bwrap is SUID binary 402# most of the time bwrap is SUID binary
404blacklist ${PATH}/bwrap 403blacklist ${PATH}/bwrap
404
405# complement noexec ${HOME} and noexec /tmp
406noexec /tmp/.X11-unix