aboutsummaryrefslogtreecommitdiffstats
path: root/etc/highlight.profile
diff options
context:
space:
mode:
authorLibravatar Fred Barclay <Fred-Barclay@users.noreply.github.com>2017-08-02 09:37:20 -0500
committerLibravatar GitHub <noreply@github.com>2017-08-02 09:37:20 -0500
commitcaaac4417bd9b4116681c96fa1127b3f78c33d1d (patch)
tree0c1fd52865432943dff536a7679408bec47df683 /etc/highlight.profile
parentget_mempolicy syscall was temporarily removed from the default seccomp list. ... (diff)
parentFixes (diff)
downloadfirejail-caaac4417bd9b4116681c96fa1127b3f78c33d1d.tar.gz
firejail-caaac4417bd9b4116681c96fa1127b3f78c33d1d.tar.zst
firejail-caaac4417bd9b4116681c96fa1127b3f78c33d1d.zip
Merge pull request #1367 from SpotComms/mh
Harden profiles
Diffstat (limited to 'etc/highlight.profile')
-rw-r--r--etc/highlight.profile3
1 files changed, 1 insertions, 2 deletions
diff --git a/etc/highlight.profile b/etc/highlight.profile
index 58e7f89f5..fefbcc55d 100644
--- a/etc/highlight.profile
+++ b/etc/highlight.profile
@@ -12,14 +12,13 @@ include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-passwdmgr.inc 12include /etc/firejail/disable-passwdmgr.inc
13 13
14caps.drop all 14caps.drop all
15net none
15nogroups 16nogroups
16nonewprivs 17nonewprivs
17noroot 18noroot
18nosound 19nosound
19protocol unix 20protocol unix
20seccomp 21seccomp
21netfilter
22net none
23no3d 22no3d
24shell none 23shell none
25tracelog 24tracelog