aboutsummaryrefslogtreecommitdiffstats
path: root/etc/uefitool.profile
diff options
context:
space:
mode:
authorLibravatar Tad <tad@spotco.us>2017-09-22 08:42:52 -0400
committerLibravatar Tad <tad@spotco.us>2017-09-22 08:42:52 -0400
commit04adc450151cc5107098ef2f555ad526ac9f632e (patch)
treece43807c66368539ffba1630ccedb0819cbc12dc /etc/uefitool.profile
parentFixup merge of #1565 (diff)
downloadfirejail-04adc450151cc5107098ef2f555ad526ac9f632e.tar.gz
firejail-04adc450151cc5107098ef2f555ad526ac9f632e.tar.zst
firejail-04adc450151cc5107098ef2f555ad526ac9f632e.zip
Further fixup #1565 and add a profile for uefitool
Diffstat (limited to 'etc/uefitool.profile')
-rw-r--r--etc/uefitool.profile33
1 files changed, 33 insertions, 0 deletions
diff --git a/etc/uefitool.profile b/etc/uefitool.profile
new file mode 100644
index 000000000..138f69aa8
--- /dev/null
+++ b/etc/uefitool.profile
@@ -0,0 +1,33 @@
1# Firejail profile for uefitool
2# This file is overwritten after every install/update
3# Persistent local customizations
4include /etc/firejail/uefitool.local
5# Persistent global definitions
6include /etc/firejail/globals.local
7
8
9include /etc/firejail/disable-common.inc
10include /etc/firejail/disable-devel.inc
11include /etc/firejail/disable-passwdmgr.inc
12include /etc/firejail/disable-programs.inc
13
14caps.drop all
15ipc-namespace
16net none
17no3d
18nodvd
19nogroups
20nonewprivs
21noroot
22nosound
23notv
24novideo
25protocol unix
26seccomp
27shell none
28
29private-dev
30private-tmp
31
32noexec ${HOME}
33noexec /tmp