aboutsummaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
authorLibravatar SkewedZeppelin <8296104+SkewedZeppelin@users.noreply.github.com>2019-03-13 16:08:14 +0000
committerLibravatar GitHub <noreply@github.com>2019-03-13 16:08:14 +0000
commit0bccd25744ae6e6ab3afea22d363b00e64abde98 (patch)
treebfae0a671cdcab21907204dfe14bbaf46728d7bb /etc
parentMerge pull request #2583 from rusty-snake/harden_minetest (diff)
parentAdd disable-exec.inc to qtox (diff)
downloadfirejail-0bccd25744ae6e6ab3afea22d363b00e64abde98.tar.gz
firejail-0bccd25744ae6e6ab3afea22d363b00e64abde98.tar.zst
firejail-0bccd25744ae6e6ab3afea22d363b00e64abde98.zip
Merge pull request #2582 from rusty-snake/harden_qtox
Harden qtox
Diffstat (limited to 'etc')
-rw-r--r--etc/qtox.profile10
1 files changed, 7 insertions, 3 deletions
diff --git a/etc/qtox.profile b/etc/qtox.profile
index 3dc4c6a30..0ca5a5ef0 100644
--- a/etc/qtox.profile
+++ b/etc/qtox.profile
@@ -10,9 +10,11 @@ noblacklist ${HOME}/.config/tox
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
13include disable-exec.inc
13include disable-interpreters.inc 14include disable-interpreters.inc
14include disable-passwdmgr.inc 15include disable-passwdmgr.inc
15include disable-programs.inc 16include disable-programs.inc
17include disable-xdg.inc
16 18
17mkdir ${HOME}/.config/tox 19mkdir ${HOME}/.config/tox
18whitelist ${DOWNLOADS} 20whitelist ${DOWNLOADS}
@@ -20,9 +22,11 @@ whitelist ${HOME}/.config/tox
20include whitelist-common.inc 22include whitelist-common.inc
21include whitelist-var-common.inc 23include whitelist-var-common.inc
22 24
25apparmor
23caps.drop all 26caps.drop all
24ipc-namespace 27ipc-namespace
25netfilter 28netfilter
29nodbus
26nodvd 30nodvd
27nogroups 31nogroups
28nonewprivs 32nonewprivs
@@ -36,9 +40,9 @@ tracelog
36 40
37disable-mnt 41disable-mnt
38private-bin qtox 42private-bin qtox
39private-etc alternatives,fonts,resolv.conf,ld.so.cache,localtime,ca-certificates,ssl,pki,crypto-policies,machine-id,pulse 43private-cache
40private-dev 44private-dev
45private-etc alternatives,fonts,resolv.conf,ld.so.cache,localtime,ca-certificates,ssl,pki,crypto-policies,machine-id,pulse
41private-tmp 46private-tmp
42 47
43noexec ${HOME} 48memory-deny-write-execute
44noexec /tmp