aboutsummaryrefslogtreecommitdiffstats
path: root/etc/keepassx2.profile
diff options
context:
space:
mode:
authorLibravatar Fred-Barclay <Fred-Barclay@users.noreply.github.com>2017-10-04 16:24:36 -0500
committerLibravatar Fred-Barclay <Fred-Barclay@users.noreply.github.com>2017-10-04 16:24:36 -0500
commitc6259375dff79484b9f3d587da9fbfa76a3b68b9 (patch)
tree1b7c010c2f6b0886ccd7a537bb146f7f46cb1d7f /etc/keepassx2.profile
parentTighten spotify profile (diff)
downloadfirejail-c6259375dff79484b9f3d587da9fbfa76a3b68b9.tar.gz
firejail-c6259375dff79484b9f3d587da9fbfa76a3b68b9.tar.zst
firejail-c6259375dff79484b9f3d587da9fbfa76a3b68b9.zip
Tighten multiple profiles.
This adds whitelist-var-common, machine-id, memory-deny-write-execute, and noexec home and tmp when possible.
Diffstat (limited to 'etc/keepassx2.profile')
-rw-r--r--etc/keepassx2.profile37
1 files changed, 2 insertions, 35 deletions
diff --git a/etc/keepassx2.profile b/etc/keepassx2.profile
index e20e06b76..ba98df19d 100644
--- a/etc/keepassx2.profile
+++ b/etc/keepassx2.profile
@@ -1,38 +1,5 @@
1# Firejail profile for keepassx2 1# Firejail profile for keepassx2
2# This file is overwritten after every install/update 2# This file is overwritten after every install/update
3# Persistent local customizations
4include /etc/firejail/keepassx2.local
5# Persistent global definitions
6include /etc/firejail/globals.local
7 3
8noblacklist ${HOME}/*.kdb 4# Redirects
9noblacklist ${HOME}/*.kdbx 5include /etc/firejail/keepassx.profile
10noblacklist ${HOME}/.config/keepassx
11noblacklist ${HOME}/.keepassx
12
13include /etc/firejail/disable-common.inc
14include /etc/firejail/disable-devel.inc
15include /etc/firejail/disable-passwdmgr.inc
16include /etc/firejail/disable-programs.inc
17
18caps.drop all
19net none
20no3d
21nodvd
22nogroups
23nonewprivs
24noroot
25nosound
26notv
27novideo
28protocol unix
29seccomp
30shell none
31
32private-bin keepassx2
33private-dev
34private-etc fonts
35private-tmp
36
37noexec ${HOME}
38noexec /tmp