aboutsummaryrefslogtreecommitdiffstats
path: root/etc/gitter.profile
diff options
context:
space:
mode:
authorLibravatar Fred-Barclay <Fred-Barclay@users.noreply.github.com>2017-10-04 16:24:36 -0500
committerLibravatar Fred-Barclay <Fred-Barclay@users.noreply.github.com>2017-10-04 16:24:36 -0500
commitc6259375dff79484b9f3d587da9fbfa76a3b68b9 (patch)
tree1b7c010c2f6b0886ccd7a537bb146f7f46cb1d7f /etc/gitter.profile
parentTighten spotify profile (diff)
downloadfirejail-c6259375dff79484b9f3d587da9fbfa76a3b68b9.tar.gz
firejail-c6259375dff79484b9f3d587da9fbfa76a3b68b9.tar.zst
firejail-c6259375dff79484b9f3d587da9fbfa76a3b68b9.zip
Tighten multiple profiles.
This adds whitelist-var-common, machine-id, memory-deny-write-execute, and noexec home and tmp when possible.
Diffstat (limited to 'etc/gitter.profile')
-rw-r--r--etc/gitter.profile11
1 files changed, 11 insertions, 0 deletions
diff --git a/etc/gitter.profile b/etc/gitter.profile
index 0a47bf888..3e84455f1 100644
--- a/etc/gitter.profile
+++ b/etc/gitter.profile
@@ -13,7 +13,13 @@ include /etc/firejail/disable-devel.inc
13include /etc/firejail/disable-passwdmgr.inc 13include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc 14include /etc/firejail/disable-programs.inc
15 15
16whitelist ${DOWNLOADS}
17whitelist ~/.config/autostart
18whitelist ~/.config/Gitter
19include /etc/firejail/whitelist-var-common.inc
20
16caps.drop all 21caps.drop all
22machine-id
17netfilter 23netfilter
18nodvd 24nodvd
19nogroups 25nogroups
@@ -25,7 +31,12 @@ protocol unix,inet,inet6,netlink
25seccomp 31seccomp
26shell none 32shell none
27 33
34disable-mnt
28private-bin bash,env,gitter 35private-bin bash,env,gitter
36private-etc fonts,pulse,resolv.conf
29private-opt Gitter 37private-opt Gitter
30private-dev 38private-dev
31private-tmp 39private-tmp
40
41noexec ${HOME}
42noexec /tmp