aboutsummaryrefslogtreecommitdiffstats
path: root/etc/etr.profile
diff options
context:
space:
mode:
authorLibravatar rusty-snake <print_hello_world+Public@protonmail.com>2019-04-13 12:23:22 +0200
committerLibravatar rusty-snake <print_hello_world+Public@protonmail.com>2019-04-13 12:23:22 +0200
commit947337b257612a0291f883149f1e001ccf26112b (patch)
tree60f54ba8745b106c91aabf5e454ec577c2fe8112 /etc/etr.profile
parentMore disable-exec stuff (#2647) (diff)
downloadfirejail-947337b257612a0291f883149f1e001ccf26112b.tar.gz
firejail-947337b257612a0291f883149f1e001ccf26112b.tar.zst
firejail-947337b257612a0291f883149f1e001ccf26112b.zip
More disable-exec and hardening
Diffstat (limited to 'etc/etr.profile')
-rw-r--r--etc/etr.profile11
1 files changed, 9 insertions, 2 deletions
diff --git a/etc/etr.profile b/etc/etr.profile
index cf13a42de..d93d3de63 100644
--- a/etc/etr.profile
+++ b/etc/etr.profile
@@ -8,14 +8,18 @@ include globals.local
8noblacklist ${HOME}/.etr 8noblacklist ${HOME}/.etr
9 9
10include disable-common.inc 10include disable-common.inc
11include disable-exec.inc
12include disable-interpreters.inc
11include disable-passwdmgr.inc 13include disable-passwdmgr.inc
12include disable-programs.inc 14include disable-programs.inc
15include disable-xdg.inc
13 16
14mkdir ${HOME}/.etr 17mkdir ${HOME}/.etr
15whitelist ${HOME}/.etr 18whitelist ${HOME}/.etr
16include whitelist-common.inc 19include whitelist-common.inc
17include whitelist-var-common.inc 20include whitelist-var-common.inc
18 21
22apparmor
19caps.drop all 23caps.drop all
20net none 24net none
21nodbus 25nodbus
@@ -28,8 +32,11 @@ nou2f
28protocol unix,netlink 32protocol unix,netlink
29seccomp 33seccomp
30shell none 34shell none
35tracelog
31 36
32# private-bin etr 37disable-mnt
38private-bin etr
39private-cache
33private-dev 40private-dev
34# private-etc alternatives 41# private-etc alternatives,drirc,machine-id,openal
35private-tmp 42private-tmp