aboutsummaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
authorLibravatar netblue30 <netblue30@yahoo.com>2018-10-11 08:31:14 -0500
committerLibravatar GitHub <noreply@github.com>2018-10-11 08:31:14 -0500
commit5e859d4139324515079762364b12cd976cf1ac31 (patch)
treef3affaf7ed71e7fe15d983c68bd28d7a76ef5f9b /etc
parentMerge pull request #2165 from glitsj16/authenticator (diff)
parentCreate checkbashisms.profile (diff)
downloadfirejail-5e859d4139324515079762364b12cd976cf1ac31.tar.gz
firejail-5e859d4139324515079762364b12cd976cf1ac31.tar.zst
firejail-5e859d4139324515079762364b12cd976cf1ac31.zip
Merge pull request #2166 from glitsj16/checkbashisms
Create checkbashisms.profile
Diffstat (limited to 'etc')
-rw-r--r--etc/checkbashisms.profile49
1 files changed, 49 insertions, 0 deletions
diff --git a/etc/checkbashisms.profile b/etc/checkbashisms.profile
new file mode 100644
index 000000000..c8b8be04e
--- /dev/null
+++ b/etc/checkbashisms.profile
@@ -0,0 +1,49 @@
1# Firejail profile for checkbashisms
2# Description: Lint tool for shell scripts
3# This file is overwritten after every install/update
4quiet
5# Persistent local customizations
6include /etc/firejail/checkbashisms.local
7# Persistent global definitions
8include /etc/firejail/globals.local
9
10noblacklist ${DOCUMENTS}
11
12# Allow perl (blacklisted by disable-interpreters.inc)
13noblacklist ${PATH}/cpan*
14noblacklist ${PATH}/core_perl
15noblacklist ${PATH}/perl
16noblacklist /usr/lib/perl*
17noblacklist /usr/share/perl*
18
19include /etc/firejail/disable-common.inc
20include /etc/firejail/disable-devel.inc
21include /etc/firejail/disable-interpreters.inc
22include /etc/firejail/disable-passwdmgr.inc
23include /etc/firejail/disable-programs.inc
24include /etc/firejail/disable-xdg.inc
25
26include /etc/firejail/whitelist-var-common.inc
27
28caps.drop all
29ipc-namespace
30net none
31no3d
32nodbus
33nodvd
34nogroups
35nonewprivs
36noroot
37nosound
38notv
39novideo
40protocol unix
41seccomp
42shell none
43
44private-dev
45private-tmp
46
47memory-deny-write-execute
48noexec ${HOME}
49noexec /tmp