aboutsummaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
authorLibravatar Fred-Barclay <Fred-Barclay@users.noreply.github.com>2017-09-24 14:19:14 -0500
committerLibravatar Fred-Barclay <Fred-Barclay@users.noreply.github.com>2017-09-24 14:19:14 -0500
commite3d22faf5a107c6e1717cfbb145a358e054b55f0 (patch)
treef1b29b2ed9fad34d9df49f474cd9221417b94c93 /etc
parenttighten mate-calc profile (diff)
downloadfirejail-e3d22faf5a107c6e1717cfbb145a358e054b55f0.tar.gz
firejail-e3d22faf5a107c6e1717cfbb145a358e054b55f0.tar.zst
firejail-e3d22faf5a107c6e1717cfbb145a358e054b55f0.zip
Harden mate-* profiles
Diffstat (limited to 'etc')
-rw-r--r--etc/mate-color-select.profile9
-rw-r--r--etc/mate-dictionary.profile10
2 files changed, 18 insertions, 1 deletions
diff --git a/etc/mate-color-select.profile b/etc/mate-color-select.profile
index 26ce42fbf..7df7d7faa 100644
--- a/etc/mate-color-select.profile
+++ b/etc/mate-color-select.profile
@@ -11,6 +11,11 @@ include /etc/firejail/disable-devel.inc
11include /etc/firejail/disable-passwdmgr.inc 11include /etc/firejail/disable-passwdmgr.inc
12include /etc/firejail/disable-programs.inc 12include /etc/firejail/disable-programs.inc
13 13
14whitelist ${HOME}/.config/gtk-3.0
15whitelist ${HOME}/.fonts
16whitelist ${HOME}/.icons
17whitelist ${HOME}/.themes
18
14caps.drop all 19caps.drop all
15netfilter 20netfilter
16no3d 21no3d
@@ -26,9 +31,11 @@ seccomp
26shell none 31shell none
27 32
28disable-mnt 33disable-mnt
29private 34private-bin mate-color-select
35private-etc fonts
30private-dev 36private-dev
31private-tmp 37private-tmp
32 38
39memory-deny-write-execute
33noexec ${HOME} 40noexec ${HOME}
34noexec /tmp 41noexec /tmp
diff --git a/etc/mate-dictionary.profile b/etc/mate-dictionary.profile
index f0de57e0d..3f85addaf 100644
--- a/etc/mate-dictionary.profile
+++ b/etc/mate-dictionary.profile
@@ -12,6 +12,12 @@ include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-passwdmgr.inc 12include /etc/firejail/disable-passwdmgr.inc
13include /etc/firejail/disable-programs.inc 13include /etc/firejail/disable-programs.inc
14 14
15whitelist ${HOME}/.config/mate/mate-dictionary
16whitelist ${HOME}/.config/gtk-3.0
17whitelist ${HOME}/.fonts
18whitelist ${HOME}/.icons
19whitelist ${HOME}/.themes
20
15caps.drop all 21caps.drop all
16netfilter 22netfilter
17no3d 23no3d
@@ -27,8 +33,12 @@ seccomp
27shell none 33shell none
28 34
29disable-mnt 35disable-mnt
36private-bin mate-dictionary
37private-etc fonts,resolv.conf
38private-opt mate-dictionary
30private-dev 39private-dev
31private-tmp 40private-tmp
32 41
42memory-deny-write-execute
33noexec ${HOME} 43noexec ${HOME}
34noexec /tmp 44noexec /tmp