aboutsummaryrefslogtreecommitdiffstats
path: root/etc/ricochet.profile
diff options
context:
space:
mode:
authorLibravatar Tad <tad@spotco.us>2017-09-16 14:11:43 -0400
committerLibravatar Tad <tad@spotco.us>2017-09-18 18:24:13 -0400
commit3c3602fe4e747f3489c917f4de991c9043df9751 (patch)
tree052baee1387ce11b9ecd00e49a7c96d59f92d480 /etc/ricochet.profile
parentFixup 36 profiles (diff)
downloadfirejail-3c3602fe4e747f3489c917f4de991c9043df9751.tar.gz
firejail-3c3602fe4e747f3489c917f4de991c9043df9751.tar.zst
firejail-3c3602fe4e747f3489c917f4de991c9043df9751.zip
Harden 25 profiles
Diffstat (limited to 'etc/ricochet.profile')
-rw-r--r--etc/ricochet.profile10
1 files changed, 9 insertions, 1 deletions
diff --git a/etc/ricochet.profile b/etc/ricochet.profile
index 423dfb887..6da0e21d5 100644
--- a/etc/ricochet.profile
+++ b/etc/ricochet.profile
@@ -19,14 +19,22 @@ include /etc/firejail/whitelist-common.inc
19 19
20caps.drop all 20caps.drop all
21ipc-namespace 21ipc-namespace
22netfilter
23no3d
24nodvd
22nogroups 25nogroups
26nonewprivs
23noroot 27noroot
28notv
29novideo
30protocol unix,inet,inet6
24seccomp 31seccomp
25shell none 32shell none
26 33
34disable-mnt
27private-bin ricochet,tor 35private-bin ricochet,tor
28private-dev 36private-dev
29#private-etc fonts,tor,X11,alternatives 37#private-etc fonts,tor,X11,alternatives
30 38
31noexec /home 39noexec ${HOME}
32noexec /tmp 40noexec /tmp