aboutsummaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
authorLibravatar startx2017 <vradu.startx@yandex.com>2018-09-04 07:37:58 -0400
committerLibravatar startx2017 <vradu.startx@yandex.com>2018-09-04 07:37:58 -0400
commit7770d5cec04ca36648925550cb92f15afce673fd (patch)
tree4b11a4c2562d1eb65b37914f0147fa6e51e8c971 /etc
parentmainline merge (diff)
downloadfirejail-7770d5cec04ca36648925550cb92f15afce673fd.tar.gz
firejail-7770d5cec04ca36648925550cb92f15afce673fd.tar.zst
firejail-7770d5cec04ca36648925550cb92f15afce673fd.zip
mainline merges
Diffstat (limited to 'etc')
-rw-r--r--etc/dig.profile47
1 files changed, 47 insertions, 0 deletions
diff --git a/etc/dig.profile b/etc/dig.profile
new file mode 100644
index 000000000..4b6ab0975
--- /dev/null
+++ b/etc/dig.profile
@@ -0,0 +1,47 @@
1quiet
2# Firejail profile for dig
3# This file is overwritten after every install/update
4# Persistent local customizations
5include /etc/firejail/dig.local
6# Persistent global definitions
7include /etc/firejail/globals.local
8
9include /etc/firejail/disable-common.inc
10# include /etc/firejail/disable-devel.inc
11# include /etc/firejail/disable-interpreters.inc
12include /etc/firejail/disable-passwdmgr.inc
13include /etc/firejail/disable-programs.inc
14#include /etc/firejail/disable-xdg.inc
15
16whitelist ~/.digrc
17include /etc/firejail/whitelist-common.inc
18include /etc/firejail/whitelist-var-common.inc
19
20caps.drop all
21# ipc-namespace
22netfilter
23no3d
24nodbus
25nodvd
26nogroups
27nonewprivs
28noroot
29nosound
30notv
31novideo
32protocol unix,inet,inet6
33seccomp
34shell none
35
36disable-mnt
37private
38private-bin sh,bash,dig
39private-cache
40private-dev
41# private-etc resolv.conf
42private-lib
43private-tmp
44
45memory-deny-write-execute
46# noexec ${HOME}
47# noexec /tmp