diff options
author | Tad <tad@spotco.us> | 2017-09-16 14:11:43 -0400 |
---|---|---|
committer | Tad <tad@spotco.us> | 2017-09-18 18:24:13 -0400 |
commit | 3c3602fe4e747f3489c917f4de991c9043df9751 (patch) | |
tree | 052baee1387ce11b9ecd00e49a7c96d59f92d480 /etc/dooble.profile | |
parent | Fixup 36 profiles (diff) | |
download | firejail-3c3602fe4e747f3489c917f4de991c9043df9751.tar.gz firejail-3c3602fe4e747f3489c917f4de991c9043df9751.tar.zst firejail-3c3602fe4e747f3489c917f4de991c9043df9751.zip |
Harden 25 profiles
Diffstat (limited to 'etc/dooble.profile')
-rw-r--r-- | etc/dooble.profile | 12 |
1 files changed, 12 insertions, 0 deletions
diff --git a/etc/dooble.profile b/etc/dooble.profile index cbb0f96b8..aabfcd8bb 100644 --- a/etc/dooble.profile +++ b/etc/dooble.profile | |||
@@ -20,8 +20,20 @@ include /etc/firejail/whitelist-common.inc | |||
20 | 20 | ||
21 | caps.drop all | 21 | caps.drop all |
22 | netfilter | 22 | netfilter |
23 | nodvd | ||
24 | nogroups | ||
23 | nonewprivs | 25 | nonewprivs |
24 | noroot | 26 | noroot |
27 | notv | ||
28 | novideo | ||
25 | protocol unix,inet,inet6,netlink | 29 | protocol unix,inet,inet6,netlink |
26 | seccomp | 30 | seccomp |
31 | shell none | ||
27 | tracelog | 32 | tracelog |
33 | |||
34 | disable-mnt | ||
35 | private-dev | ||
36 | private-tmp | ||
37 | |||
38 | noexec ${HOME} | ||
39 | noexec /tmp | ||