aboutsummaryrefslogtreecommitdiffstats
path: root/etc/xpdf.profile
diff options
context:
space:
mode:
authorLibravatar Fred Barclay <Fred-Barclay@users.noreply.github.com>2017-08-02 09:37:20 -0500
committerLibravatar GitHub <noreply@github.com>2017-08-02 09:37:20 -0500
commitcaaac4417bd9b4116681c96fa1127b3f78c33d1d (patch)
tree0c1fd52865432943dff536a7679408bec47df683 /etc/xpdf.profile
parentget_mempolicy syscall was temporarily removed from the default seccomp list. ... (diff)
parentFixes (diff)
downloadfirejail-caaac4417bd9b4116681c96fa1127b3f78c33d1d.tar.gz
firejail-caaac4417bd9b4116681c96fa1127b3f78c33d1d.tar.zst
firejail-caaac4417bd9b4116681c96fa1127b3f78c33d1d.zip
Merge pull request #1367 from SpotComms/mh
Harden profiles
Diffstat (limited to 'etc/xpdf.profile')
-rw-r--r--etc/xpdf.profile13
1 files changed, 11 insertions, 2 deletions
diff --git a/etc/xpdf.profile b/etc/xpdf.profile
index 5b3018ce8..ce8cd2459 100644
--- a/etc/xpdf.profile
+++ b/etc/xpdf.profile
@@ -9,17 +9,26 @@ include /etc/firejail/xpdf.local
9# xpdf application profile 9# xpdf application profile
10################################ 10################################
11noblacklist ${HOME}/.xpdfrc 11noblacklist ${HOME}/.xpdfrc
12
12include /etc/firejail/disable-common.inc 13include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-programs.inc 14include /etc/firejail/disable-devel.inc
14include /etc/firejail/disable-passwdmgr.inc 15include /etc/firejail/disable-passwdmgr.inc
16include /etc/firejail/disable-programs.inc
15 17
16caps.drop all 18caps.drop all
17net none 19net none
20no3d
21nogroups
18nonewprivs 22nonewprivs
19noroot 23noroot
24nosound
25novideo
20protocol unix 26protocol unix
21shell none
22seccomp 27seccomp
28shell none
23 29
24private-dev 30private-dev
25private-tmp 31private-tmp
32
33noexec ${HOME}
34noexec /tmp