aboutsummaryrefslogtreecommitdiffstats
path: root/etc/inox.profile
diff options
context:
space:
mode:
authorLibravatar smitsohu <smitsohu@gmail.com>2017-10-29 13:06:19 +0100
committerLibravatar smitsohu <smitsohu@gmail.com>2017-10-29 13:06:19 +0100
commit8ef2c87931fa83c2d1fd6b35f23ac650adee6355 (patch)
treead154ca76315d658334fb06b587e1df835fb137a /etc/inox.profile
parentfix for #1614 (--timeout) (diff)
downloadfirejail-8ef2c87931fa83c2d1fd6b35f23ac650adee6355.tar.gz
firejail-8ef2c87931fa83c2d1fd6b35f23ac650adee6355.tar.zst
firejail-8ef2c87931fa83c2d1fd6b35f23ac650adee6355.zip
fix and harden various profiles
Diffstat (limited to 'etc/inox.profile')
-rw-r--r--etc/inox.profile8
1 files changed, 7 insertions, 1 deletions
diff --git a/etc/inox.profile b/etc/inox.profile
index de4d6205b..221acd309 100644
--- a/etc/inox.profile
+++ b/etc/inox.profile
@@ -20,11 +20,17 @@ whitelist ~/.cache/inox
20whitelist ~/.config/inox 20whitelist ~/.config/inox
21whitelist ~/.pki 21whitelist ~/.pki
22include /etc/firejail/whitelist-common.inc 22include /etc/firejail/whitelist-common.inc
23include /etc/firejail/whitelist-var-common.inc
23 24
24caps.keep sys_chroot,sys_admin 25caps.keep sys_chroot,sys_admin
25netfilter 26netfilter
26nodvd 27nodvd
27nogroups 28nogroups
28noroot
29notv 29notv
30shell none 30shell none
31
32private-dev
33# private-tmp - problems with multiple browser sessions
34
35noexec ${HOME}
36noexec /tmp