aboutsummaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
authorLibravatar rusty-snake <print_hello_world+Public@protonmail.com>2019-04-12 19:01:38 +0200
committerLibravatar rusty-snake <print_hello_world+Public@protonmail.com>2019-04-12 19:01:38 +0200
commit53dff25d69ad0d1a83dea3ce19d2d54210025f20 (patch)
tree7fddb0caa3e97f2c9a0e416a318b653f0495f2b8 /etc
parentadding disable-exec.inc to the remaining profiles (diff)
downloadfirejail-53dff25d69ad0d1a83dea3ce19d2d54210025f20.tar.gz
firejail-53dff25d69ad0d1a83dea3ce19d2d54210025f20.tar.zst
firejail-53dff25d69ad0d1a83dea3ce19d2d54210025f20.zip
Harden bibletime.profile
Diffstat (limited to 'etc')
-rw-r--r--etc/bibletime.profile7
1 files changed, 6 insertions, 1 deletions
diff --git a/etc/bibletime.profile b/etc/bibletime.profile
index 6e40054f7..c41aafd47 100644
--- a/etc/bibletime.profile
+++ b/etc/bibletime.profile
@@ -14,6 +14,7 @@ noblacklist ${HOME}/.local/share/bibletime
14 14
15include disable-common.inc 15include disable-common.inc
16include disable-devel.inc 16include disable-devel.inc
17include disable-exec.inc
17include disable-interpreters.inc 18include disable-interpreters.inc
18include disable-passwdmgr.inc 19include disable-passwdmgr.inc
19include disable-programs.inc 20include disable-programs.inc
@@ -25,7 +26,9 @@ whitelist ${HOME}/.bibletime
25whitelist ${HOME}/.sword 26whitelist ${HOME}/.sword
26whitelist ${HOME}/.local/share/bibletime 27whitelist ${HOME}/.local/share/bibletime
27include whitelist-common.inc 28include whitelist-common.inc
29include whitelist-var-common.inc
28 30
31apparmor
29caps.drop all 32caps.drop all
30machine-id 33machine-id
31netfilter 34netfilter
@@ -42,7 +45,9 @@ protocol unix,inet,inet6,netlink
42seccomp.drop @clock,@cpu-emulation,@debug,@module,@obsolete,@raw-io,@reboot,@resources,@swap,acct,add_key,bpf,fanotify_init,io_cancel,io_destroy,io_getevents,io_setup,io_submit,ioprio_set,kcmp,keyctl,mount,name_to_handle_at,nfsservctl,ni_syscall,open_by_handle_at,personality,pivot_root,process_vm_readv,ptrace,remap_file_pages,request_key,setdomainname,sethostname,syslog,umount,umount2,userfaultfd,vhangup,vmsplice 45seccomp.drop @clock,@cpu-emulation,@debug,@module,@obsolete,@raw-io,@reboot,@resources,@swap,acct,add_key,bpf,fanotify_init,io_cancel,io_destroy,io_getevents,io_setup,io_submit,ioprio_set,kcmp,keyctl,mount,name_to_handle_at,nfsservctl,ni_syscall,open_by_handle_at,personality,pivot_root,process_vm_readv,ptrace,remap_file_pages,request_key,setdomainname,sethostname,syslog,umount,umount2,userfaultfd,vhangup,vmsplice
43shell none 46shell none
44 47
48disable-mnt
45# private-bin bibletime,qt5ct 49# private-bin bibletime,qt5ct
50private-cache
46private-dev 51private-dev
47private-etc alternatives,fonts,resolv.conf,sword,sword.conf,passwd,machine-id,ca-certificates,ssl,pki,crypto-policies 52private-etc alternatives,ca-certificates,crypto-policies,fonts,login.defs,machine-id,passwd,pki,resolv.conf,ssl,sword,sword.conf
48private-tmp 53private-tmp