aboutsummaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
authorLibravatar rusty-snake <print_hello_world+Public@protonmail.com>2019-03-13 13:10:26 +0100
committerLibravatar rusty-snake <print_hello_world+Public@protonmail.com>2019-03-13 13:10:26 +0100
commit8c68c369bf25e6b2e14d45e4117552313abfc324 (patch)
tree5c08aee8cfc7c751152d6d45d15ec2bf42f0ba6b /etc
parentadd disable-exec.inc to few more profiles (diff)
downloadfirejail-8c68c369bf25e6b2e14d45e4117552313abfc324.tar.gz
firejail-8c68c369bf25e6b2e14d45e4117552313abfc324.tar.zst
firejail-8c68c369bf25e6b2e14d45e4117552313abfc324.zip
Harden qtox
Diffstat (limited to 'etc')
-rw-r--r--etc/qtox.profile7
1 files changed, 6 insertions, 1 deletions
diff --git a/etc/qtox.profile b/etc/qtox.profile
index 3dc4c6a30..2c3b69c46 100644
--- a/etc/qtox.profile
+++ b/etc/qtox.profile
@@ -13,6 +13,7 @@ include disable-devel.inc
13include disable-interpreters.inc 13include disable-interpreters.inc
14include disable-passwdmgr.inc 14include disable-passwdmgr.inc
15include disable-programs.inc 15include disable-programs.inc
16include disable-xdg.inc
16 17
17mkdir ${HOME}/.config/tox 18mkdir ${HOME}/.config/tox
18whitelist ${DOWNLOADS} 19whitelist ${DOWNLOADS}
@@ -20,9 +21,11 @@ whitelist ${HOME}/.config/tox
20include whitelist-common.inc 21include whitelist-common.inc
21include whitelist-var-common.inc 22include whitelist-var-common.inc
22 23
24apparmor
23caps.drop all 25caps.drop all
24ipc-namespace 26ipc-namespace
25netfilter 27netfilter
28nodbus
26nodvd 29nodvd
27nogroups 30nogroups
28nonewprivs 31nonewprivs
@@ -36,9 +39,11 @@ tracelog
36 39
37disable-mnt 40disable-mnt
38private-bin qtox 41private-bin qtox
39private-etc alternatives,fonts,resolv.conf,ld.so.cache,localtime,ca-certificates,ssl,pki,crypto-policies,machine-id,pulse 42private-cache
40private-dev 43private-dev
44private-etc alternatives,fonts,resolv.conf,ld.so.cache,localtime,ca-certificates,ssl,pki,crypto-policies,machine-id,pulse
41private-tmp 45private-tmp
42 46
47memory-deny-write-execute
43noexec ${HOME} 48noexec ${HOME}
44noexec /tmp 49noexec /tmp