diff options
author | rusty-snake <print_hello_world+Public@protonmail.com> | 2019-06-16 13:04:28 +0200 |
---|---|---|
committer | rusty-snake <print_hello_world+Public@protonmail.com> | 2019-06-16 13:04:28 +0200 |
commit | 4c935269605f9b53578b66b9d9c5596ccb886f0d (patch) | |
tree | a33b75b9d60169b5278cd66473db5a8ee30e3ea4 /etc/skanlite.profile | |
parent | Sort comented private-{bin,etc} lines (diff) | |
download | firejail-4c935269605f9b53578b66b9d9c5596ccb886f0d.tar.gz firejail-4c935269605f9b53578b66b9d9c5596ccb886f0d.tar.zst firejail-4c935269605f9b53578b66b9d9c5596ccb886f0d.zip |
many profile cleanup (4)
containing:
- files forgotten in 4beaf8f9
- workarounds for #903
- commented useless private-etc lines removed
- remove commented seccomp.keep lines
- much more
Diffstat (limited to 'etc/skanlite.profile')
-rw-r--r-- | etc/skanlite.profile | 3 |
1 files changed, 1 insertions, 2 deletions
diff --git a/etc/skanlite.profile b/etc/skanlite.profile index 76b050d18..c10be717b 100644 --- a/etc/skanlite.profile +++ b/etc/skanlite.profile | |||
@@ -16,7 +16,6 @@ include disable-programs.inc | |||
16 | include disable-xdg.inc | 16 | include disable-xdg.inc |
17 | 17 | ||
18 | caps.drop all | 18 | caps.drop all |
19 | # net none | ||
20 | netfilter | 19 | netfilter |
21 | # nodbus | 20 | # nodbus |
22 | nodvd | 21 | nodvd |
@@ -31,6 +30,6 @@ protocol unix,inet,inet6,netlink | |||
31 | seccomp.drop @clock,@cpu-emulation,@debug,@module,@obsolete,@reboot,@resources,@swap,acct,add_key,bpf,chroot,fanotify_init,io_cancel,io_destroy,io_getevents,io_setup,io_submit,iopl,ioprio_set,kcmp,keyctl,mount,name_to_handle_at,nfsservctl,ni_syscall,open_by_handle_at,pciconfig_iobase,pciconfig_read,pciconfig_write,personality,pivot_root,process_vm_readv,ptrace,remap_file_pages,request_key,s390_mmio_read,s390_mmio_write,setdomainname,sethostname,syslog,umount,umount2,userfaultfd,vhangup,vmsplice | 30 | seccomp.drop @clock,@cpu-emulation,@debug,@module,@obsolete,@reboot,@resources,@swap,acct,add_key,bpf,chroot,fanotify_init,io_cancel,io_destroy,io_getevents,io_setup,io_submit,iopl,ioprio_set,kcmp,keyctl,mount,name_to_handle_at,nfsservctl,ni_syscall,open_by_handle_at,pciconfig_iobase,pciconfig_read,pciconfig_write,personality,pivot_root,process_vm_readv,ptrace,remap_file_pages,request_key,s390_mmio_read,s390_mmio_write,setdomainname,sethostname,syslog,umount,umount2,userfaultfd,vhangup,vmsplice |
32 | shell none | 31 | shell none |
33 | 32 | ||
34 | # private-bin skanlite,kbuildsycoca4,kdeinit4 | 33 | # private-bin kbuildsycoca4,kdeinit4,skanlite |
35 | # private-dev | 34 | # private-dev |
36 | # private-tmp | 35 | # private-tmp |