aboutsummaryrefslogtreecommitdiffstats
path: root/etc/freshclam.profile
diff options
context:
space:
mode:
authorLibravatar Tad <tad@spotco.us>2017-09-18 14:27:58 -0400
committerLibravatar Tad <tad@spotco.us>2017-09-18 14:27:58 -0400
commitae5948cb84bd1327ab9f6f0577fd75bfe9a74787 (patch)
treeee6f8a1bd5659453c8ecf24036adaef8f11bee3b /etc/freshclam.profile
parentAdd a profile for ClamAV's clamscan (diff)
downloadfirejail-ae5948cb84bd1327ab9f6f0577fd75bfe9a74787.tar.gz
firejail-ae5948cb84bd1327ab9f6f0577fd75bfe9a74787.tar.zst
firejail-ae5948cb84bd1327ab9f6f0577fd75bfe9a74787.zip
Add a profile for clamdscan, clamdtop, and freshclam
Diffstat (limited to 'etc/freshclam.profile')
-rw-r--r--etc/freshclam.profile34
1 files changed, 34 insertions, 0 deletions
diff --git a/etc/freshclam.profile b/etc/freshclam.profile
new file mode 100644
index 000000000..08eac5595
--- /dev/null
+++ b/etc/freshclam.profile
@@ -0,0 +1,34 @@
1# Firejail profile for freshclam
2# This file is overwritten after every install/update
3quiet
4# Persistent local customizations
5include /etc/firejail/clamav.local
6# Persistent global definitions
7include /etc/firejail/globals.local
8
9
10caps.keep setgid,setuid
11ipc-namespace
12netfilter
13no3d
14nodvd
15nogroups
16nonewprivs
17nosound
18notv
19novideo
20protocol unix,inet,inet6
21seccomp
22shell none
23tracelog
24
25disable-mnt
26private
27private-dev
28private-tmp
29writable-var
30writable-var-log
31
32memory-deny-write-execute
33noexec ${HOME}
34noexec /tmp