aboutsummaryrefslogtreecommitdiffstats
path: root/etc/gnome-books.profile
diff options
context:
space:
mode:
authorLibravatar Tad <tad@spotco.us>2017-07-04 10:51:43 -0400
committerLibravatar Tad <tad@spotco.us>2017-07-04 11:35:29 -0400
commit5354f20012b488c50cd556e315b78ad351ae0f9d (patch)
tree89c737f738f8525da446786083473c249b8a9f79 /etc/gnome-books.profile
parentper-profile disable-mnt (diff)
downloadfirejail-5354f20012b488c50cd556e315b78ad351ae0f9d.tar.gz
firejail-5354f20012b488c50cd556e315b78ad351ae0f9d.tar.zst
firejail-5354f20012b488c50cd556e315b78ad351ae0f9d.zip
Harden 50 profiles
Hardened many profiles using disable-mnt and novideo Fixed gnome-font-viewer
Diffstat (limited to 'etc/gnome-books.profile')
-rw-r--r--etc/gnome-books.profile5
1 files changed, 5 insertions, 0 deletions
diff --git a/etc/gnome-books.profile b/etc/gnome-books.profile
index 07431e51b..af6da6cd4 100644
--- a/etc/gnome-books.profile
+++ b/etc/gnome-books.profile
@@ -16,10 +16,12 @@ include /etc/firejail/disable-devel.inc
16include /etc/firejail/disable-passwdmgr.inc 16include /etc/firejail/disable-passwdmgr.inc
17 17
18caps.drop all 18caps.drop all
19no3d
19nogroups 20nogroups
20nonewprivs 21nonewprivs
21noroot 22noroot
22nosound 23nosound
24novideo
23protocol unix 25protocol unix
24seccomp 26seccomp
25netfilter 27netfilter
@@ -30,3 +32,6 @@ tracelog
30private-tmp 32private-tmp
31private-dev 33private-dev
32#private-etc fonts 34#private-etc fonts
35
36noexec ${HOME}
37noexec /tmp