aboutsummaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
authorLibravatar The Fox in the Shell <KellerFuchs@hashbang.sh>2016-06-18 17:38:01 +0200
committerLibravatar The Fox in the Shell <KellerFuchs@hashbang.sh>2016-06-18 17:40:08 +0200
commit0065456d6d6043206367ad56440943071ed25b69 (patch)
treebdb4a0a88c6e8c463a6972ee272a71d12d2cbb71 /etc
parentdisable-common: Make ~/.profile read-only (diff)
downloadfirejail-0065456d6d6043206367ad56440943071ed25b69.tar.gz
firejail-0065456d6d6043206367ad56440943071ed25b69.tar.zst
firejail-0065456d6d6043206367ad56440943071ed25b69.zip
disable-common: Protect caff's files
Caff (CA fire & forget) is a popular GnuPG helper for keysigning safely.
Diffstat (limited to 'etc')
-rw-r--r--etc/disable-common.inc2
1 files changed, 2 insertions, 0 deletions
diff --git a/etc/disable-common.inc b/etc/disable-common.inc
index aebf099af..c857ff439 100644
--- a/etc/disable-common.inc
+++ b/etc/disable-common.inc
@@ -77,6 +77,7 @@ read-only ${HOME}/.csh_files
77read-only ${HOME}/.profile 77read-only ${HOME}/.profile
78 78
79# Initialization files that allow arbitrary command execution 79# Initialization files that allow arbitrary command execution
80read-only ${HOME}/.caffrc
80read-only ${HOME}/.mailcap 81read-only ${HOME}/.mailcap
81read-only ${HOME}/.exrc 82read-only ${HOME}/.exrc
82read-only ${HOME}/_exrc 83read-only ${HOME}/_exrc
@@ -105,6 +106,7 @@ blacklist ${HOME}/.kde/share/apps/kwallet
105blacklist ${HOME}/.local/share/kwalletd 106blacklist ${HOME}/.local/share/kwalletd
106blacklist ${HOME}/.netrc 107blacklist ${HOME}/.netrc
107blacklist ${HOME}/.gnupg 108blacklist ${HOME}/.gnupg
109blacklist ${HOME}/.caff
108blacklist ${HOME}/*.kdbx 110blacklist ${HOME}/*.kdbx
109blacklist ${HOME}/*.kdb 111blacklist ${HOME}/*.kdb
110blacklist ${HOME}/*.key 112blacklist ${HOME}/*.key