aboutsummaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
authorLibravatar Tad <tad@spotco.us>2017-08-22 20:23:01 -0400
committerLibravatar Tad <tad@spotco.us>2017-08-22 21:31:40 -0400
commita7f934325a3a4f8ca0dd35e5aaf38d309c46da00 (patch)
tree5b5f1d78692c3465b7c93b1004483cbdade06f77 /etc
parentFix Steam regressions (diff)
downloadfirejail-a7f934325a3a4f8ca0dd35e5aaf38d309c46da00.tar.gz
firejail-a7f934325a3a4f8ca0dd35e5aaf38d309c46da00.tar.zst
firejail-a7f934325a3a4f8ca0dd35e5aaf38d309c46da00.zip
Harden /var
Diffstat (limited to 'etc')
-rw-r--r--etc/bitlbee.profile1
-rw-r--r--etc/disable-common.inc12
-rw-r--r--etc/server.profile2
3 files changed, 15 insertions, 0 deletions
diff --git a/etc/bitlbee.profile b/etc/bitlbee.profile
index 0b61e7b9f..1b7b2c258 100644
--- a/etc/bitlbee.profile
+++ b/etc/bitlbee.profile
@@ -7,6 +7,7 @@ include /etc/firejail/globals.local
7 7
8noblacklist /sbin 8noblacklist /sbin
9noblacklist /usr/sbin 9noblacklist /usr/sbin
10noblacklist /var/log
10 11
11include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
12include /etc/firejail/disable-devel.inc 13include /etc/firejail/disable-devel.inc
diff --git a/etc/disable-common.inc b/etc/disable-common.inc
index c220b9c50..294ff6bcb 100644
--- a/etc/disable-common.inc
+++ b/etc/disable-common.inc
@@ -107,15 +107,27 @@ blacklist ${PATH}/zuluCrypt-cli
107blacklist ${PATH}/zuluMount-cli 107blacklist ${PATH}/zuluMount-cli
108 108
109# var 109# var
110blacklist /var/cache/apt
111blacklist /var/cache/pacman
112blacklist /var/lib/apt
113blacklist /var/lib/clamav
114blacklist /var/lib/dkms
110blacklist /var/lib/mysql/mysql.sock 115blacklist /var/lib/mysql/mysql.sock
111blacklist /var/lib/mysqld/mysql.sock 116blacklist /var/lib/mysqld/mysql.sock
117blacklist /var/lib/pacman
118blacklist /var/lib/systemd
119blacklist /var/lib/upower
120blacklist /var/log
112blacklist /var/mail 121blacklist /var/mail
122blacklist /var/opt
113blacklist /var/run/acpid.socket 123blacklist /var/run/acpid.socket
114blacklist /var/run/docker.sock 124blacklist /var/run/docker.sock
115blacklist /var/run/minissdpd.sock 125blacklist /var/run/minissdpd.sock
116blacklist /var/run/mysql/mysqld.sock 126blacklist /var/run/mysql/mysqld.sock
117blacklist /var/run/mysqld/mysqld.sock 127blacklist /var/run/mysqld/mysqld.sock
118blacklist /var/run/rpcbind.sock 128blacklist /var/run/rpcbind.sock
129blacklist /var/run/screens
130blacklist /var/run/systemd
119blacklist /var/spool/anacron 131blacklist /var/spool/anacron
120blacklist /var/spool/cron 132blacklist /var/spool/cron
121 133
diff --git a/etc/server.profile b/etc/server.profile
index 04ef555de..edd4666e1 100644
--- a/etc/server.profile
+++ b/etc/server.profile
@@ -13,6 +13,8 @@ blacklist /tmp/.X11-unix
13 13
14noblacklist /sbin 14noblacklist /sbin
15noblacklist /usr/sbin 15noblacklist /usr/sbin
16# noblacklist /var/log
17# noblacklist /var/opt
16 18
17include /etc/firejail/disable-common.inc 19include /etc/firejail/disable-common.inc
18# include /etc/firejail/disable-devel.inc 20# include /etc/firejail/disable-devel.inc