aboutsummaryrefslogtreecommitdiffstats
path: root/etc/server.profile
diff options
context:
space:
mode:
authorLibravatar Tad <tad@spotco.us>2017-08-07 14:24:51 -0400
committerLibravatar Tad <tad@spotco.us>2017-08-07 14:29:40 -0400
commit39dc3c893b5d895ed9db9071dd47b3de7b28f2fd (patch)
treeb76dbe39efe41bded67e3fe95d030b277d4a0236 /etc/server.profile
parentFix comments in 88 profiles (diff)
downloadfirejail-39dc3c893b5d895ed9db9071dd47b3de7b28f2fd.tar.gz
firejail-39dc3c893b5d895ed9db9071dd47b3de7b28f2fd.tar.zst
firejail-39dc3c893b5d895ed9db9071dd47b3de7b28f2fd.zip
Unify last 8 profiles
Diffstat (limited to 'etc/server.profile')
-rw-r--r--etc/server.profile30
1 files changed, 21 insertions, 9 deletions
diff --git a/etc/server.profile b/etc/server.profile
index 2d79fa1c8..b0dd13f80 100644
--- a/etc/server.profile
+++ b/etc/server.profile
@@ -1,25 +1,37 @@
1# Persistent global definitions go here 1# Firejail profile for server
2include /etc/firejail/globals.local 2# This file is overwritten after every install/update
3 3# Persistent local customizations
4# This file is overwritten during software install.
5# Persistent customizations should go in a .local file.
6include /etc/firejail/server.local 4include /etc/firejail/server.local
5# Persistent global definitions
6include /etc/firejail/globals.local
7 7
8# generic server profile 8# generic server profile
9# it allows /sbin and /usr/sbin directories - this is where servers are installed 9# it allows /sbin and /usr/sbin directories - this is where servers are installed
10# depending on your usage, you can enable some of the commands below:
11
12blacklist /tmp/.X11-unix
13
10noblacklist /sbin 14noblacklist /sbin
11noblacklist /usr/sbin 15noblacklist /usr/sbin
16
12include /etc/firejail/disable-common.inc 17include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-programs.inc 18# include /etc/firejail/disable-devel.inc
14include /etc/firejail/disable-passwdmgr.inc 19include /etc/firejail/disable-passwdmgr.inc
20include /etc/firejail/disable-programs.inc
15 21
16blacklist /tmp/.X11-unix 22caps
17
18no3d 23no3d
19nosound 24nosound
20seccomp 25seccomp
21caps
22 26
27# disable-mnt
23private 28private
29# private-bin program
24private-dev 30private-dev
31# private-etc none
32# private-lib
25private-tmp 33private-tmp
34
35# memory-deny-write-execute
36# noexec ${HOME}
37# noexec /tmp