aboutsummaryrefslogtreecommitdiffstats
path: root/etc/display.profile
diff options
context:
space:
mode:
authorLibravatar Fred Barclay <Fred-Barclay@users.noreply.github.com>2017-08-02 09:37:20 -0500
committerLibravatar GitHub <noreply@github.com>2017-08-02 09:37:20 -0500
commitcaaac4417bd9b4116681c96fa1127b3f78c33d1d (patch)
tree0c1fd52865432943dff536a7679408bec47df683 /etc/display.profile
parentget_mempolicy syscall was temporarily removed from the default seccomp list. ... (diff)
parentFixes (diff)
downloadfirejail-caaac4417bd9b4116681c96fa1127b3f78c33d1d.tar.gz
firejail-caaac4417bd9b4116681c96fa1127b3f78c33d1d.tar.zst
firejail-caaac4417bd9b4116681c96fa1127b3f78c33d1d.zip
Merge pull request #1367 from SpotComms/mh
Harden profiles
Diffstat (limited to 'etc/display.profile')
-rw-r--r--etc/display.profile7
1 files changed, 3 insertions, 4 deletions
diff --git a/etc/display.profile b/etc/display.profile
index 7cde8bd54..c2c46cba3 100644
--- a/etc/display.profile
+++ b/etc/display.profile
@@ -12,14 +12,13 @@ include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-passwdmgr.inc 12include /etc/firejail/disable-passwdmgr.inc
13 13
14caps.drop all 14caps.drop all
15seccomp
16protocol unix
17netfilter
18net none 15net none
19nonewprivs 16nonewprivs
20noroot
21nogroups 17nogroups
18noroot
22nosound 19nosound
20protocol unix
21seccomp
23shell none 22shell none
24x11 xorg 23x11 xorg
25 24