summaryrefslogtreecommitdiffstats
path: root/etc/tor.profile
diff options
context:
space:
mode:
authorLibravatar Tad <tad@spotco.us>2017-09-16 14:11:43 -0400
committerLibravatar Tad <tad@spotco.us>2017-09-18 18:24:13 -0400
commit3c3602fe4e747f3489c917f4de991c9043df9751 (patch)
tree052baee1387ce11b9ecd00e49a7c96d59f92d480 /etc/tor.profile
parentFixup 36 profiles (diff)
downloadfirejail-3c3602fe4e747f3489c917f4de991c9043df9751.tar.gz
firejail-3c3602fe4e747f3489c917f4de991c9043df9751.tar.zst
firejail-3c3602fe4e747f3489c917f4de991c9043df9751.zip
Harden 25 profiles
Diffstat (limited to 'etc/tor.profile')
-rw-r--r--etc/tor.profile9
1 files changed, 9 insertions, 0 deletions
diff --git a/etc/tor.profile b/etc/tor.profile
index 73577825a..fcb123eef 100644
--- a/etc/tor.profile
+++ b/etc/tor.profile
@@ -23,16 +23,25 @@ include /etc/firejail/disable-programs.inc
23 23
24caps.keep setuid,setgid,net_bind_service,dac_read_search 24caps.keep setuid,setgid,net_bind_service,dac_read_search
25ipc-namespace 25ipc-namespace
26netfilter
26no3d 27no3d
28nodvd
27nogroups 29nogroups
28nonewprivs 30nonewprivs
29nosound 31nosound
32notv
33novideo
34protocol unix,inet,inet6
30seccomp 35seccomp
31shell none 36shell none
32writable-var 37writable-var
33 38
39disable-mnt
34private 40private
35private-bin tor,bash 41private-bin tor,bash
36private-dev 42private-dev
37private-etc tor,passwd 43private-etc tor,passwd
38private-tmp 44private-tmp
45
46noexec ${HOME}
47noexec /tmp