aboutsummaryrefslogtreecommitdiffstats
path: root/etc/gnome-clocks.profile
diff options
context:
space:
mode:
authorLibravatar Tad <tad@spotco.us>2017-07-04 10:51:43 -0400
committerLibravatar Tad <tad@spotco.us>2017-07-04 11:35:29 -0400
commit5354f20012b488c50cd556e315b78ad351ae0f9d (patch)
tree89c737f738f8525da446786083473c249b8a9f79 /etc/gnome-clocks.profile
parentper-profile disable-mnt (diff)
downloadfirejail-5354f20012b488c50cd556e315b78ad351ae0f9d.tar.gz
firejail-5354f20012b488c50cd556e315b78ad351ae0f9d.tar.zst
firejail-5354f20012b488c50cd556e315b78ad351ae0f9d.zip
Harden 50 profiles
Hardened many profiles using disable-mnt and novideo Fixed gnome-font-viewer
Diffstat (limited to 'etc/gnome-clocks.profile')
-rw-r--r--etc/gnome-clocks.profile7
1 files changed, 6 insertions, 1 deletions
diff --git a/etc/gnome-clocks.profile b/etc/gnome-clocks.profile
index 40df92454..129bd6e71 100644
--- a/etc/gnome-clocks.profile
+++ b/etc/gnome-clocks.profile
@@ -12,10 +12,11 @@ include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-passwdmgr.inc 12include /etc/firejail/disable-passwdmgr.inc
13 13
14caps.drop all 14caps.drop all
15no3d
15nogroups 16nogroups
16nonewprivs 17nonewprivs
17noroot 18noroot
18nosound 19novideo
19protocol unix,inet,inet6 20protocol unix,inet,inet6
20seccomp 21seccomp
21netfilter 22netfilter
@@ -26,3 +27,7 @@ tracelog
26private-tmp 27private-tmp
27private-dev 28private-dev
28# private-etc fonts 29# private-etc fonts
30disable-mnt
31
32noexec ${HOME}
33noexec /tmp