diff options
author | 2023-03-16 02:30:52 +0100 | |
---|---|---|
committer | 2023-03-16 15:00:37 +0100 | |
commit | 47e3c82ab58b0d0c02066666aea3f7a04078c86b (patch) | |
tree | 10d06366bb00a50209ea0c24366e599061cff53a /etc/profile-a-l/blink-common-hardened.inc.profile | |
parent | firejail.txt: remove extraneous endif (diff) | |
download | firejail-47e3c82ab58b0d0c02066666aea3f7a04078c86b.tar.gz firejail-47e3c82ab58b0d0c02066666aea3f7a04078c86b.tar.zst firejail-47e3c82ab58b0d0c02066666aea3f7a04078c86b.zip |
create blink-common.profile
Diffstat (limited to 'etc/profile-a-l/blink-common-hardened.inc.profile')
-rw-r--r-- | etc/profile-a-l/blink-common-hardened.inc.profile | 11 |
1 files changed, 11 insertions, 0 deletions
diff --git a/etc/profile-a-l/blink-common-hardened.inc.profile b/etc/profile-a-l/blink-common-hardened.inc.profile new file mode 100644 index 000000000..c092a9746 --- /dev/null +++ b/etc/profile-a-l/blink-common-hardened.inc.profile | |||
@@ -0,0 +1,11 @@ | |||
1 | # This file is overwritten during software install. | ||
2 | # Persistent customizations should go in a .local file. | ||
3 | include blink-common-hardened.inc.local | ||
4 | |||
5 | caps.drop all | ||
6 | nonewprivs | ||
7 | noroot | ||
8 | protocol unix,inet,inet6,netlink | ||
9 | seccomp !chroot | ||
10 | |||
11 | #restrict-namespaces | ||