aboutsummaryrefslogtreecommitdiffstats
path: root/etc/profile-a-l/drill.profile
diff options
context:
space:
mode:
authorLibravatar netblue30 <netblue30@yahoo.com>2020-12-12 18:13:44 -0500
committerLibravatar netblue30 <netblue30@yahoo.com>2020-12-12 18:13:44 -0500
commit814bc190479d611ae6ffb442070e76ea61a2ade8 (patch)
treecf69f2c01eb1186f333a056aaaf126fc5cb5bb63 /etc/profile-a-l/drill.profile
parentMerge pull request #3810 from kmk3/dc-add-ldns (diff)
downloadfirejail-814bc190479d611ae6ffb442070e76ea61a2ade8.tar.gz
firejail-814bc190479d611ae6ffb442070e76ea61a2ade8.tar.zst
firejail-814bc190479d611ae6ffb442070e76ea61a2ade8.zip
drill profile
Diffstat (limited to 'etc/profile-a-l/drill.profile')
-rw-r--r--etc/profile-a-l/drill.profile56
1 files changed, 56 insertions, 0 deletions
diff --git a/etc/profile-a-l/drill.profile b/etc/profile-a-l/drill.profile
new file mode 100644
index 000000000..8c59b0cb6
--- /dev/null
+++ b/etc/profile-a-l/drill.profile
@@ -0,0 +1,56 @@
1# Firejail profile for drill
2# Description: DNS lookup utility
3# This file is overwritten after every install/update
4quiet
5# Persistent local customizations
6include drill.local
7# Persistent global definitions
8include globals.local
9
10noblacklist ${PATH}/drill
11
12blacklist /tmp/.X11-unix
13blacklist ${RUNUSER}/wayland-*
14blacklist ${RUNUSER}
15
16include disable-common.inc
17# include disable-devel.inc
18include disable-exec.inc
19# include disable-interpreters.inc
20include disable-passwdmgr.inc
21include disable-programs.inc
22include disable-xdg.inc
23
24include whitelist-common.inc
25include whitelist-usr-share-common.inc
26include whitelist-var-common.inc
27
28apparmor
29caps.drop all
30ipc-namespace
31machine-id
32netfilter
33no3d
34nodvd
35nogroups
36nonewprivs
37noroot
38nosound
39notv
40nou2f
41novideo
42protocol unix,inet,inet6
43seccomp
44shell none
45tracelog
46
47disable-mnt
48private
49private-bin bash,drill,sh
50private-dev
51private-tmp
52
53dbus-user none
54dbus-system none
55
56memory-deny-write-execute