aboutsummaryrefslogtreecommitdiffstats
path: root/etc/psi-plus.profile
diff options
context:
space:
mode:
authorLibravatar Tad <tad@spotco.us>2017-07-05 09:40:54 -0400
committerLibravatar Tad <tad@spotco.us>2017-08-02 00:13:42 -0400
commit0dba38435ef92ccc01cc9ff23b69df55489ec983 (patch)
treedfd1d8db02f579183fa77acdbde9aa315596220f /etc/psi-plus.profile
parentx11/xpra support (diff)
downloadfirejail-0dba38435ef92ccc01cc9ff23b69df55489ec983.tar.gz
firejail-0dba38435ef92ccc01cc9ff23b69df55489ec983.tar.zst
firejail-0dba38435ef92ccc01cc9ff23b69df55489ec983.zip
Harden profiles
- Added 'disable-devel.conf' to many profiles - Added 'disable-mnt' to many profiles - Added 'noexec' to many profiles - Removed 'netfilter' and 'net none' from profiles with 'protocol unix' - Cleaned up profiles using defaults
Diffstat (limited to 'etc/psi-plus.profile')
-rw-r--r--etc/psi-plus.profile16
1 files changed, 15 insertions, 1 deletions
diff --git a/etc/psi-plus.profile b/etc/psi-plus.profile
index e3ffad9a1..9500731fe 100644
--- a/etc/psi-plus.profile
+++ b/etc/psi-plus.profile
@@ -8,7 +8,9 @@ include /etc/firejail/psi-plus.local
8# Firejail profile for Psi+ 8# Firejail profile for Psi+
9noblacklist ${HOME}/.config/psi+ 9noblacklist ${HOME}/.config/psi+
10noblacklist ${HOME}/.local/share/psi+ 10noblacklist ${HOME}/.local/share/psi+
11
11include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-programs.inc 14include /etc/firejail/disable-programs.inc
13include /etc/firejail/disable-passwdmgr.inc 15include /etc/firejail/disable-passwdmgr.inc
14 16
@@ -20,10 +22,22 @@ whitelist ~/.local/share/psi+
20mkdir ~/.cache/psi+ 22mkdir ~/.cache/psi+
21whitelist ~/.cache/psi+ 23whitelist ~/.cache/psi+
22 24
25include /etc/firejail/whitelist-common.inc
26
23caps.drop all 27caps.drop all
24netfilter 28netfilter
29no3d
30nogroups
31nonewprivs
25noroot 32noroot
33novideo
26protocol unix,inet,inet6 34protocol unix,inet,inet6
27seccomp 35seccomp
36shell none
28 37
29include /etc/firejail/whitelist-common.inc 38private-dev
39private-tmp
40disable-mnt
41
42noexec ${HOME}
43noexec /tmp