aboutsummaryrefslogtreecommitdiffstats
path: root/etc/tar.profile
diff options
context:
space:
mode:
authorLibravatar rusty-snake <print_hello_world+Public@protonmail.com>2019-06-02 17:36:19 +0200
committerLibravatar rusty-snake <print_hello_world+Public@protonmail.com>2019-06-02 17:36:19 +0200
commitf413040c5e4c052b4bc81706b9f12e5dcf0fa5b3 (patch)
tree840dd9d781a13c611b0b61e25161e9f6aef86779 /etc/tar.profile
parentAdd pandoc.profile (diff)
downloadfirejail-f413040c5e4c052b4bc81706b9f12e5dcf0fa5b3.tar.gz
firejail-f413040c5e4c052b4bc81706b9f12e5dcf0fa5b3.tar.zst
firejail-f413040c5e4c052b4bc81706b9f12e5dcf0fa5b3.zip
many profile cleanups (2)
Diffstat (limited to 'etc/tar.profile')
-rw-r--r--etc/tar.profile17
1 files changed, 10 insertions, 7 deletions
diff --git a/etc/tar.profile b/etc/tar.profile
index 14fc00d21..b6a874217 100644
--- a/etc/tar.profile
+++ b/etc/tar.profile
@@ -5,17 +5,19 @@ quiet
5# Persistent local customizations 5# Persistent local customizations
6include tar.local 6include tar.local
7# Persistent global definitions 7# Persistent global definitions
8# added by included profile 8include globals.local
9#include globals.local
10 9
11blacklist /tmp/.X11-unix 10blacklist /tmp/.X11-unix
12 11
12include disable-common.inc
13include disable-devel.inc
13include disable-exec.inc 14include disable-exec.inc
14include disable-interpreters.inc 15include disable-interpreters.inc
15 16include disable-passwdmgr.inc
16ignore noroot 17include disable-programs.inc
17 18
18apparmor 19apparmor
20caps.drop all
19hostname tar 21hostname tar
20ipc-namespace 22ipc-namespace
21machine-id 23machine-id
@@ -24,10 +26,14 @@ no3d
24nodbus 26nodbus
25nodvd 27nodvd
26nogroups 28nogroups
29nonewprivs
30#noroot
27nosound 31nosound
28notv 32notv
29nou2f 33nou2f
30novideo 34novideo
35protocol unix
36seccomp
31shell none 37shell none
32tracelog 38tracelog
33 39
@@ -39,8 +45,5 @@ private-etc alternatives,passwd,group,localtime
39private-lib libfakeroot 45private-lib libfakeroot
40 46
41memory-deny-write-execute 47memory-deny-write-execute
42
43# Debian based distributions need this for 'dpkg --unpack' (incl. synaptic) 48# Debian based distributions need this for 'dpkg --unpack' (incl. synaptic)
44writable-var 49writable-var
45
46include default.profile