aboutsummaryrefslogtreecommitdiffstats
path: root/etc/stellarium.profile
diff options
context:
space:
mode:
authorLibravatar Fred-Barclay <Fred-Barclay@users.noreply.github.com>2017-10-04 16:24:36 -0500
committerLibravatar Fred-Barclay <Fred-Barclay@users.noreply.github.com>2017-10-04 16:24:36 -0500
commitc6259375dff79484b9f3d587da9fbfa76a3b68b9 (patch)
tree1b7c010c2f6b0886ccd7a537bb146f7f46cb1d7f /etc/stellarium.profile
parentTighten spotify profile (diff)
downloadfirejail-c6259375dff79484b9f3d587da9fbfa76a3b68b9.tar.gz
firejail-c6259375dff79484b9f3d587da9fbfa76a3b68b9.tar.zst
firejail-c6259375dff79484b9f3d587da9fbfa76a3b68b9.zip
Tighten multiple profiles.
This adds whitelist-var-common, machine-id, memory-deny-write-execute, and noexec home and tmp when possible.
Diffstat (limited to 'etc/stellarium.profile')
-rw-r--r--etc/stellarium.profile5
1 files changed, 5 insertions, 0 deletions
diff --git a/etc/stellarium.profile b/etc/stellarium.profile
index 89e2d1a30..360b9f881 100644
--- a/etc/stellarium.profile
+++ b/etc/stellarium.profile
@@ -18,8 +18,10 @@ mkdir ~/.stellarium
18whitelist ~/.config/stellarium 18whitelist ~/.config/stellarium
19whitelist ~/.stellarium 19whitelist ~/.stellarium
20include /etc/firejail/whitelist-common.inc 20include /etc/firejail/whitelist-common.inc
21include /etc/firejail/whitelist-var-common.inc
21 22
22caps.drop all 23caps.drop all
24machine-id
23netfilter 25netfilter
24nodvd 26nodvd
25nogroups 27nogroups
@@ -36,3 +38,6 @@ disable-mnt
36private-bin stellarium 38private-bin stellarium
37private-dev 39private-dev
38private-tmp 40private-tmp
41
42noexec ${HOME}
43noexec /tmp