aboutsummaryrefslogtreecommitdiffstats
path: root/etc/keepassx.profile
diff options
context:
space:
mode:
authorLibravatar Fred-Barclay <Fred-Barclay@users.noreply.github.com>2017-10-04 16:24:36 -0500
committerLibravatar Fred-Barclay <Fred-Barclay@users.noreply.github.com>2017-10-04 16:24:36 -0500
commitc6259375dff79484b9f3d587da9fbfa76a3b68b9 (patch)
tree1b7c010c2f6b0886ccd7a537bb146f7f46cb1d7f /etc/keepassx.profile
parentTighten spotify profile (diff)
downloadfirejail-c6259375dff79484b9f3d587da9fbfa76a3b68b9.tar.gz
firejail-c6259375dff79484b9f3d587da9fbfa76a3b68b9.tar.zst
firejail-c6259375dff79484b9f3d587da9fbfa76a3b68b9.zip
Tighten multiple profiles.
This adds whitelist-var-common, machine-id, memory-deny-write-execute, and noexec home and tmp when possible.
Diffstat (limited to 'etc/keepassx.profile')
-rw-r--r--etc/keepassx.profile3
1 files changed, 3 insertions, 0 deletions
diff --git a/etc/keepassx.profile b/etc/keepassx.profile
index 9d943d89c..27ca408f5 100644
--- a/etc/keepassx.profile
+++ b/etc/keepassx.profile
@@ -15,6 +15,8 @@ include /etc/firejail/disable-devel.inc
15include /etc/firejail/disable-passwdmgr.inc 15include /etc/firejail/disable-passwdmgr.inc
16include /etc/firejail/disable-programs.inc 16include /etc/firejail/disable-programs.inc
17 17
18include /etc/firejail/whitelist-var-common.inc
19
18caps.drop all 20caps.drop all
19machine-id 21machine-id
20net none 22net none
@@ -36,5 +38,6 @@ private-dev
36private-etc fonts,machine-id 38private-etc fonts,machine-id
37private-tmp 39private-tmp
38 40
41memory-deny-write-execute
39noexec ${HOME} 42noexec ${HOME}
40noexec /tmp 43noexec /tmp