aboutsummaryrefslogtreecommitdiffstats
path: root/etc/google-chrome.profile
diff options
context:
space:
mode:
authorLibravatar Fred Barclay <Fred-Barclay@users.noreply.github.com>2017-08-02 09:37:20 -0500
committerLibravatar GitHub <noreply@github.com>2017-08-02 09:37:20 -0500
commitcaaac4417bd9b4116681c96fa1127b3f78c33d1d (patch)
tree0c1fd52865432943dff536a7679408bec47df683 /etc/google-chrome.profile
parentget_mempolicy syscall was temporarily removed from the default seccomp list. ... (diff)
parentFixes (diff)
downloadfirejail-caaac4417bd9b4116681c96fa1127b3f78c33d1d.tar.gz
firejail-caaac4417bd9b4116681c96fa1127b3f78c33d1d.tar.zst
firejail-caaac4417bd9b4116681c96fa1127b3f78c33d1d.zip
Merge pull request #1367 from SpotComms/mh
Harden profiles
Diffstat (limited to 'etc/google-chrome.profile')
-rw-r--r--etc/google-chrome.profile16
1 files changed, 13 insertions, 3 deletions
diff --git a/etc/google-chrome.profile b/etc/google-chrome.profile
index 84e0c6cdc..e6fceadec 100644
--- a/etc/google-chrome.profile
+++ b/etc/google-chrome.profile
@@ -16,9 +16,6 @@ include /etc/firejail/disable-programs.inc
16# include /etc/firejail/disable-devel.inc 16# include /etc/firejail/disable-devel.inc
17# 17#
18 18
19caps.keep sys_chroot,sys_admin
20netfilter
21
22whitelist ${DOWNLOADS} 19whitelist ${DOWNLOADS}
23mkdir ~/.config/google-chrome 20mkdir ~/.config/google-chrome
24whitelist ~/.config/google-chrome 21whitelist ~/.config/google-chrome
@@ -27,3 +24,16 @@ whitelist ~/.cache/google-chrome
27mkdir ~/.pki 24mkdir ~/.pki
28whitelist ~/.pki 25whitelist ~/.pki
29include /etc/firejail/whitelist-common.inc 26include /etc/firejail/whitelist-common.inc
27
28caps.keep sys_chroot,sys_admin
29#ipc-namespace
30netfilter
31nogroups
32shell none
33
34private-dev
35#private-tmp - problems with multiple browser sessions
36#disable-mnt
37
38noexec ${HOME}
39noexec /tmp