diff options
author | netblue30 <netblue30@protonmail.com> | 2022-04-10 20:25:28 -0400 |
---|---|---|
committer | netblue30 <netblue30@protonmail.com> | 2022-04-10 20:25:28 -0400 |
commit | f29f815c003adb55ac88b58b541e66ac38efe63b (patch) | |
tree | 20bed63c06e1de00b66d62ad14eef172874d988e /etc/profile-m-z/server.profile | |
parent | Merge pull request #5092 from smitsohu/vlc (diff) | |
download | firejail-f29f815c003adb55ac88b58b541e66ac38efe63b.tar.gz firejail-f29f815c003adb55ac88b58b541e66ac38efe63b.tar.zst firejail-f29f815c003adb55ac88b58b541e66ac38efe63b.zip |
small fixes
Diffstat (limited to 'etc/profile-m-z/server.profile')
-rw-r--r-- | etc/profile-m-z/server.profile | 12 |
1 files changed, 9 insertions, 3 deletions
diff --git a/etc/profile-m-z/server.profile b/etc/profile-m-z/server.profile index 9e40796a6..f1cf0ca59 100644 --- a/etc/profile-m-z/server.profile +++ b/etc/profile-m-z/server.profile | |||
@@ -33,6 +33,9 @@ include globals.local | |||
33 | 33 | ||
34 | noblacklist /sbin | 34 | noblacklist /sbin |
35 | noblacklist /usr/sbin | 35 | noblacklist /usr/sbin |
36 | noblacklist /etc/init.d | ||
37 | noblacklist /var/lib/apt | ||
38 | noblacklist /var/cache/apt | ||
36 | # noblacklist /var/opt | 39 | # noblacklist /var/opt |
37 | 40 | ||
38 | blacklist /tmp/.X11-unix | 41 | blacklist /tmp/.X11-unix |
@@ -50,7 +53,9 @@ include disable-xdg.inc | |||
50 | # include whitelist-usr-share-common.inc | 53 | # include whitelist-usr-share-common.inc |
51 | # include whitelist-var-common.inc | 54 | # include whitelist-var-common.inc |
52 | 55 | ||
53 | apparmor | 56 | # people use to install servers all over the place! |
57 | # apparmor runs executable only from default system locations | ||
58 | # apparmor | ||
54 | caps | 59 | caps |
55 | # ipc-namespace | 60 | # ipc-namespace |
56 | machine-id | 61 | machine-id |
@@ -59,15 +64,16 @@ no3d | |||
59 | nodvd | 64 | nodvd |
60 | # nogroups | 65 | # nogroups |
61 | noinput | 66 | noinput |
62 | # nonewprivs | 67 | nonewprivs |
63 | # noroot | 68 | # noroot |
64 | nosound | 69 | nosound |
65 | notv | 70 | notv |
66 | nou2f | 71 | nou2f |
67 | novideo | 72 | novideo |
68 | # protocol unix,inet,inet6,netlink | 73 | protocol unix,inet,inet6,netlink,packet |
69 | seccomp | 74 | seccomp |
70 | # shell none | 75 | # shell none |
76 | tab # allow tab completion | ||
71 | 77 | ||
72 | disable-mnt | 78 | disable-mnt |
73 | private | 79 | private |