summaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
authorLibravatar glitsj16 <glitsj16@users.noreply.github.com>2019-03-27 03:01:48 +0000
committerLibravatar GitHub <noreply@github.com>2019-03-27 03:01:48 +0000
commite401fdacf99d792434af8bb052e3b22979c12d8b (patch)
treec406b1ee89c7194610542b04657991dd2164061a /etc
parentmount runtime seccomp files read-only (#2602) (diff)
downloadfirejail-e401fdacf99d792434af8bb052e3b22979c12d8b.tar.gz
firejail-e401fdacf99d792434af8bb052e3b22979c12d8b.tar.zst
firejail-e401fdacf99d792434af8bb052e3b22979c12d8b.zip
Refactor pidgin as whitelist profile (#2620)
Diffstat (limited to 'etc')
-rw-r--r--etc/pidgin.profile17
1 files changed, 12 insertions, 5 deletions
diff --git a/etc/pidgin.profile b/etc/pidgin.profile
index 91a204557..444478149 100644
--- a/etc/pidgin.profile
+++ b/etc/pidgin.profile
@@ -6,14 +6,24 @@ include pidgin.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9mkdir ${HOME}/.purple
9noblacklist ${HOME}/.purple 10noblacklist ${HOME}/.purple
11whitelist ${HOME}/.purple
12
13ignore noexec ${RUNUSER}
14ignore noexec /dev/shm
10 15
11include disable-common.inc 16include disable-common.inc
12include disable-devel.inc 17include disable-devel.inc
18include disable-exec.inc
13include disable-interpreters.inc 19include disable-interpreters.inc
14include disable-passwdmgr.inc 20include disable-passwdmgr.inc
15include disable-programs.inc 21include disable-programs.inc
22include disable-xdg.inc
23include whitelist-common.inc
24include whitelist-var-common.inc
16 25
26apparmor
17caps.drop all 27caps.drop all
18netfilter 28netfilter
19nodvd 29nodvd
@@ -24,13 +34,10 @@ notv
24nou2f 34nou2f
25protocol unix,inet,inet6 35protocol unix,inet,inet6
26seccomp 36seccomp
27shell none 37# shell none
28tracelog 38tracelog
29 39
30private-bin pidgin 40# private-bin pidgin
31private-cache 41private-cache
32private-dev 42private-dev
33private-tmp 43private-tmp
34
35noexec ${HOME}
36noexec /tmp