aboutsummaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
authorLibravatar glitsj16 <glitsj16@users.noreply.github.com>2019-02-25 00:40:00 +0000
committerLibravatar GitHub <noreply@github.com>2019-02-25 00:40:00 +0000
commit591347192c0b2e0fb89869ce88043a03b7f2ac73 (patch)
treed46453622d79badd7fe784a77a084c0a5eae3b26 /etc
parentHarden eog.profile (#2469) (diff)
downloadfirejail-591347192c0b2e0fb89869ce88043a03b7f2ac73.tar.gz
firejail-591347192c0b2e0fb89869ce88043a03b7f2ac73.tar.zst
firejail-591347192c0b2e0fb89869ce88043a03b7f2ac73.zip
Harden gpicview.profile (#2470)
Diffstat (limited to 'etc')
-rw-r--r--etc/gpicview.profile12
1 files changed, 9 insertions, 3 deletions
diff --git a/etc/gpicview.profile b/etc/gpicview.profile
index af9680b49..2d369fbd8 100644
--- a/etc/gpicview.profile
+++ b/etc/gpicview.profile
@@ -14,9 +14,10 @@ include disable-interpreters.inc
14include disable-passwdmgr.inc 14include disable-passwdmgr.inc
15include disable-programs.inc 15include disable-programs.inc
16 16
17include whitelist-var-common.inc 17apparmor
18
19caps.drop all 18caps.drop all
19ipc-namespace
20machine-id
20net none 21net none
21nodbus 22nodbus
22nodvd 23nodvd
@@ -33,7 +34,12 @@ shell none
33tracelog 34tracelog
34 35
35private-bin gpicview 36private-bin gpicview
37private-cache
36private-dev 38private-dev
37private-etc alternatives,fonts 39private-etc alternatives,fonts,groups,passwd
38private-lib 40private-lib
39private-tmp 41private-tmp
42
43memory-deny-write-execute
44noexec ${HOME}
45noexec /tmp