aboutsummaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
authorLibravatar startx2017 <vradu.startx@yandex.com>2018-08-30 07:29:05 -0400
committerLibravatar startx2017 <vradu.startx@yandex.com>2018-08-30 07:29:05 -0400
commitef4409e7b79b3dabf5a35879138d66b0b8a0c24d (patch)
tree8fceede1113e37c629f0f08e2870b3f91ee5292a /etc
parentlittle tweak (diff)
downloadfirejail-ef4409e7b79b3dabf5a35879138d66b0b8a0c24d.tar.gz
firejail-ef4409e7b79b3dabf5a35879138d66b0b8a0c24d.tar.zst
firejail-ef4409e7b79b3dabf5a35879138d66b0b8a0c24d.zip
added whois and dig profiles
Diffstat (limited to 'etc')
-rw-r--r--etc/dig.profile47
-rw-r--r--etc/whois.profile45
2 files changed, 92 insertions, 0 deletions
diff --git a/etc/dig.profile b/etc/dig.profile
new file mode 100644
index 000000000..4b6ab0975
--- /dev/null
+++ b/etc/dig.profile
@@ -0,0 +1,47 @@
1quiet
2# Firejail profile for dig
3# This file is overwritten after every install/update
4# Persistent local customizations
5include /etc/firejail/dig.local
6# Persistent global definitions
7include /etc/firejail/globals.local
8
9include /etc/firejail/disable-common.inc
10# include /etc/firejail/disable-devel.inc
11# include /etc/firejail/disable-interpreters.inc
12include /etc/firejail/disable-passwdmgr.inc
13include /etc/firejail/disable-programs.inc
14#include /etc/firejail/disable-xdg.inc
15
16whitelist ~/.digrc
17include /etc/firejail/whitelist-common.inc
18include /etc/firejail/whitelist-var-common.inc
19
20caps.drop all
21# ipc-namespace
22netfilter
23no3d
24nodbus
25nodvd
26nogroups
27nonewprivs
28noroot
29nosound
30notv
31novideo
32protocol unix,inet,inet6
33seccomp
34shell none
35
36disable-mnt
37private
38private-bin sh,bash,dig
39private-cache
40private-dev
41# private-etc resolv.conf
42private-lib
43private-tmp
44
45memory-deny-write-execute
46# noexec ${HOME}
47# noexec /tmp
diff --git a/etc/whois.profile b/etc/whois.profile
new file mode 100644
index 000000000..3ef2e1476
--- /dev/null
+++ b/etc/whois.profile
@@ -0,0 +1,45 @@
1quiet
2# Firejail profile for whois
3# This file is overwritten after every install/update
4# Persistent local customizations
5include /etc/firejail/whois.local
6# Persistent global definitions
7include /etc/firejail/globals.local
8
9include /etc/firejail/disable-common.inc
10# include /etc/firejail/disable-devel.inc
11# include /etc/firejail/disable-interpreters.inc
12include /etc/firejail/disable-passwdmgr.inc
13include /etc/firejail/disable-programs.inc
14#include /etc/firejail/disable-xdg.inc
15
16include /etc/firejail/whitelist-var-common.inc
17
18caps.drop all
19# ipc-namespace
20netfilter
21no3d
22nodbus
23nodvd
24nogroups
25nonewprivs
26noroot
27nosound
28notv
29novideo
30protocol inet,inet6
31seccomp
32shell none
33
34disable-mnt
35private
36private-bin sh,bash,whois
37private-cache
38private-dev
39# private-etc hosts,services,whois.conf
40private-lib
41private-tmp
42
43memory-deny-write-execute
44# noexec ${HOME}
45# noexec /tmp