aboutsummaryrefslogtreecommitdiffstats
path: root/etc/gedit.profile
diff options
context:
space:
mode:
authorLibravatar Fred-Barclay <Fred-Barclay@users.noreply.github.com>2017-10-04 16:24:36 -0500
committerLibravatar Fred-Barclay <Fred-Barclay@users.noreply.github.com>2017-10-04 16:24:36 -0500
commitc6259375dff79484b9f3d587da9fbfa76a3b68b9 (patch)
tree1b7c010c2f6b0886ccd7a537bb146f7f46cb1d7f /etc/gedit.profile
parentTighten spotify profile (diff)
downloadfirejail-c6259375dff79484b9f3d587da9fbfa76a3b68b9.tar.gz
firejail-c6259375dff79484b9f3d587da9fbfa76a3b68b9.tar.zst
firejail-c6259375dff79484b9f3d587da9fbfa76a3b68b9.zip
Tighten multiple profiles.
This adds whitelist-var-common, machine-id, memory-deny-write-execute, and noexec home and tmp when possible.
Diffstat (limited to 'etc/gedit.profile')
-rw-r--r--etc/gedit.profile2
1 files changed, 2 insertions, 0 deletions
diff --git a/etc/gedit.profile b/etc/gedit.profile
index 928006d08..5bf246d66 100644
--- a/etc/gedit.profile
+++ b/etc/gedit.profile
@@ -19,6 +19,7 @@ include /etc/firejail/whitelist-var-common.inc
19 19
20caps.drop all 20caps.drop all
21# net none - makes settings immutable 21# net none - makes settings immutable
22machine-id
22no3d 23no3d
23nodvd 24nodvd
24nogroups 25nogroups
@@ -37,5 +38,6 @@ private-dev
37# private-etc fonts 38# private-etc fonts
38private-tmp 39private-tmp
39 40
41memory-deny-write-execute
40noexec ${HOME} 42noexec ${HOME}
41noexec /tmp 43noexec /tmp