aboutsummaryrefslogtreecommitdiffstats
path: root/etc/pithos.profile
diff options
context:
space:
mode:
authorLibravatar Fred Barclay <Fred-Barclay@users.noreply.github.com>2017-08-07 13:41:08 -0500
committerLibravatar GitHub <noreply@github.com>2017-08-07 13:41:08 -0500
commite24b15f8647997dbb26a7152c921af94e36294ce (patch)
tree4c98b42844c8c67853643d4b4b7253dbd8764f1e /etc/pithos.profile
parentmerges (diff)
parentUnify last 8 profiles (diff)
downloadfirejail-e24b15f8647997dbb26a7152c921af94e36294ce.tar.gz
firejail-e24b15f8647997dbb26a7152c921af94e36294ce.tar.zst
firejail-e24b15f8647997dbb26a7152c921af94e36294ce.zip
Merge pull request #1427 from SpotComms/pr
Unify all profiles
Diffstat (limited to 'etc/pithos.profile')
-rw-r--r--etc/pithos.profile23
1 files changed, 8 insertions, 15 deletions
diff --git a/etc/pithos.profile b/etc/pithos.profile
index c08f27f17..7eea5d8c2 100644
--- a/etc/pithos.profile
+++ b/etc/pithos.profile
@@ -1,25 +1,18 @@
1# Persistent global definitions go here 1# Firejail profile for pithos
2include /etc/firejail/globals.local 2# This file is overwritten after every install/update
3 3# Persistent local customizations
4# This file is overwritten during software install.
5# Persistent customizations should go in a .local file.
6include /etc/firejail/pithos.local 4include /etc/firejail/pithos.local
5# Persistent global definitions
6include /etc/firejail/globals.local
7 7
8#
9#Profile for pithos
10#
11 8
12#Blacklist Paths
13include /etc/firejail/disable-common.inc 9include /etc/firejail/disable-common.inc
14include /etc/firejail/disable-programs.inc
15include /etc/firejail/disable-passwdmgr.inc
16include /etc/firejail/disable-devel.inc 10include /etc/firejail/disable-devel.inc
17 11include /etc/firejail/disable-passwdmgr.inc
12include /etc/firejail/disable-programs.inc
18include /etc/firejail/whitelist-common.inc 13include /etc/firejail/whitelist-common.inc
19 14
20#Options
21caps.drop all 15caps.drop all
22#ipc-namespace
23netfilter 16netfilter
24no3d 17no3d
25nogroups 18nogroups
@@ -30,9 +23,9 @@ protocol unix,inet,inet6
30seccomp 23seccomp
31shell none 24shell none
32 25
26disable-mnt
33private-dev 27private-dev
34private-tmp 28private-tmp
35disable-mnt
36 29
37noexec ${HOME} 30noexec ${HOME}
38noexec /tmp 31noexec /tmp