aboutsummaryrefslogtreecommitdiffstats
path: root/etc/gcloud.profile
diff options
context:
space:
mode:
authorLibravatar smitsohu <smitsohu@gmail.com>2019-03-12 20:44:51 +0000
committerLibravatar GitHub <noreply@github.com>2019-03-12 20:44:51 +0000
commitaa2bdffc4b4d0437dd710a70546c87b8f882b100 (patch)
treee44a8864ec0964a6c72caa7b6297ca90d7e8fd21 /etc/gcloud.profile
parentHarden meld.profile (#2577) (diff)
downloadfirejail-aa2bdffc4b4d0437dd710a70546c87b8f882b100.tar.gz
firejail-aa2bdffc4b4d0437dd710a70546c87b8f882b100.tar.zst
firejail-aa2bdffc4b4d0437dd710a70546c87b8f882b100.zip
add disable-exec.inc to all profiles with apparmor (#2576)
* add disable-exec.inc to all profiles with apparmor - #2385 #2505 * drop disable-exec.inc from generic electron.profile
Diffstat (limited to 'etc/gcloud.profile')
-rw-r--r--etc/gcloud.profile9
1 files changed, 4 insertions, 5 deletions
diff --git a/etc/gcloud.profile b/etc/gcloud.profile
index d9df8fd37..a08aebf2c 100644
--- a/etc/gcloud.profile
+++ b/etc/gcloud.profile
@@ -5,12 +5,16 @@ include gcloud.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8# noexec ${HOME} will break user-local installs of gcloud tooling
9ignore noexec ${HOME}
10
8noblacklist ${HOME}/.boto 11noblacklist ${HOME}/.boto
9noblacklist ${HOME}/.config/gcloud 12noblacklist ${HOME}/.config/gcloud
10noblacklist /var/run/docker.sock 13noblacklist /var/run/docker.sock
11 14
12include disable-common.inc 15include disable-common.inc
13include disable-devel.inc 16include disable-devel.inc
17include disable-exec.inc
14include disable-programs.inc 18include disable-programs.inc
15 19
16apparmor 20apparmor
@@ -34,8 +38,3 @@ disable-mnt
34private-dev 38private-dev
35private-etc alternatives,ca-certificates,ssl,hosts,localtime,nsswitch.conf,resolv.conf,pki,crypto-policies,ld.so.cache 39private-etc alternatives,ca-certificates,ssl,hosts,localtime,nsswitch.conf,resolv.conf,pki,crypto-policies,ld.so.cache
36private-tmp 40private-tmp
37
38noexec /tmp
39
40# will break user-local installs of gcloud tooling
41# noexec ${HOME}