aboutsummaryrefslogtreecommitdiffstats
path: root/etc/profile-a-l/clipit.profile
diff options
context:
space:
mode:
authorLibravatar glitsj16 <glitsj16@users.noreply.github.com>2022-12-12 13:10:48 +0000
committerLibravatar GitHub <noreply@github.com>2022-12-12 13:10:48 +0000
commitf99a296347a3a70fe898915746306dfe78bcdeae (patch)
tree090feeb8301e595e07614af34e67b22c91ecdfe5 /etc/profile-a-l/clipit.profile
parentsmall nettrace fixes (diff)
downloadfirejail-f99a296347a3a70fe898915746306dfe78bcdeae.tar.gz
firejail-f99a296347a3a70fe898915746306dfe78bcdeae.tar.zst
firejail-f99a296347a3a70fe898915746306dfe78bcdeae.zip
clipit hardening (#5521)
* clipit hardening * clipit: fix hardening * clipit: add xdotool lib to private-lib
Diffstat (limited to 'etc/profile-a-l/clipit.profile')
-rw-r--r--etc/profile-a-l/clipit.profile14
1 files changed, 14 insertions, 0 deletions
diff --git a/etc/profile-a-l/clipit.profile b/etc/profile-a-l/clipit.profile
index ef1800aaa..0356547cd 100644
--- a/etc/profile-a-l/clipit.profile
+++ b/etc/profile-a-l/clipit.profile
@@ -13,7 +13,9 @@ include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
14include disable-exec.inc 14include disable-exec.inc
15include disable-interpreters.inc 15include disable-interpreters.inc
16include disable-proc.inc
16include disable-programs.inc 17include disable-programs.inc
18include disable-shell.inc
17include disable-xdg.inc 19include disable-xdg.inc
18 20
19mkdir ${HOME}/.config/clipit 21mkdir ${HOME}/.config/clipit
@@ -21,6 +23,8 @@ mkdir ${HOME}/.local/share/clipit
21whitelist ${HOME}/.config/clipit 23whitelist ${HOME}/.config/clipit
22whitelist ${HOME}/.local/share/clipit 24whitelist ${HOME}/.local/share/clipit
23include whitelist-common.inc 25include whitelist-common.inc
26include whitelist-run-common.inc
27include whitelist-runuser-common.inc
24include whitelist-usr-share-common.inc 28include whitelist-usr-share-common.inc
25include whitelist-var-common.inc 29include whitelist-var-common.inc
26 30
@@ -34,6 +38,7 @@ nodvd
34nogroups 38nogroups
35noinput 39noinput
36nonewprivs 40nonewprivs
41noprinters
37noroot 42noroot
38nosound 43nosound
39notv 44notv
@@ -41,9 +46,18 @@ nou2f
41novideo 46novideo
42protocol unix 47protocol unix
43seccomp 48seccomp
49tracelog
44 50
45disable-mnt 51disable-mnt
52private-bin clipit,xdotool
46private-cache 53private-cache
47private-dev 54private-dev
55private-lib libxdo.so.*
48private-tmp 56private-tmp
49 57
58dbus-user none
59dbus-system none
60
61#memory-deny-write-execute
62restrict-namespaces
63read-only ${HOME}