aboutsummaryrefslogtreecommitdiffstats
path: root/etc/xonotic.profile
diff options
context:
space:
mode:
authorLibravatar Tad <tad@spotco.us>2017-04-15 08:57:13 -0400
committerLibravatar Tad <tad@spotco.us>2017-04-15 15:25:08 -0400
commit90cd669eba680369c6ba8d96af194b70c8cc8706 (patch)
tree31c4d14fa5b56003b9898c8e6d19f03b7d91b091 /etc/xonotic.profile
parentnoblacklist .config/qt5ct (part 1) (diff)
downloadfirejail-90cd669eba680369c6ba8d96af194b70c8cc8706.tar.gz
firejail-90cd669eba680369c6ba8d96af194b70c8cc8706.tar.zst
firejail-90cd669eba680369c6ba8d96af194b70c8cc8706.zip
Harden some profiles
Diffstat (limited to 'etc/xonotic.profile')
-rw-r--r--etc/xonotic.profile9
1 files changed, 9 insertions, 0 deletions
diff --git a/etc/xonotic.profile b/etc/xonotic.profile
index f2690c6c3..6bfb26484 100644
--- a/etc/xonotic.profile
+++ b/etc/xonotic.profile
@@ -23,7 +23,16 @@ include /etc/firejail/whitelist-common.inc
23#Options 23#Options
24caps.drop all 24caps.drop all
25netfilter 25netfilter
26nogroups
26nonewprivs 27nonewprivs
27noroot 28noroot
28protocol unix,inet,inet6 29protocol unix,inet,inet6
29seccomp 30seccomp
31shell none
32
33private-bin xonotic-sdl,xonotic-glx,blind-id
34private-dev
35private-tmp
36
37noexec ${HOME}
38noexec /tmp