aboutsummaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
authorLibravatar glitsj16 <glitsj16@users.noreply.github.com>2019-03-12 07:18:32 +0000
committerLibravatar GitHub <noreply@github.com>2019-03-12 07:18:32 +0000
commitcf6d5a6910007ae83a629778a00398b7e205e071 (patch)
tree9b0327e86dbef63f6c90499aa439e9c9574dbf0d /etc
parentSupport older versions of font-manager (#2561) (diff)
downloadfirejail-cf6d5a6910007ae83a629778a00398b7e205e071.tar.gz
firejail-cf6d5a6910007ae83a629778a00398b7e205e071.tar.zst
firejail-cf6d5a6910007ae83a629778a00398b7e205e071.zip
Harden galculator (#2562)
Diffstat (limited to 'etc')
-rw-r--r--etc/galculator.profile8
1 files changed, 8 insertions, 0 deletions
diff --git a/etc/galculator.profile b/etc/galculator.profile
index 509d9bd05..203d0a455 100644
--- a/etc/galculator.profile
+++ b/etc/galculator.profile
@@ -13,6 +13,7 @@ include disable-devel.inc
13include disable-interpreters.inc 13include disable-interpreters.inc
14include disable-passwdmgr.inc 14include disable-passwdmgr.inc
15include disable-programs.inc 15include disable-programs.inc
16include disable-xdg.inc
16 17
17mkdir ${HOME}/.config/galculator 18mkdir ${HOME}/.config/galculator
18whitelist ${HOME}/.config/galculator 19whitelist ${HOME}/.config/galculator
@@ -21,6 +22,8 @@ include whitelist-var-common.inc
21 22
22apparmor 23apparmor
23caps.drop all 24caps.drop all
25hostname galculator
26ipc-namespace
24net none 27net none
25nodbus 28nodbus
26nodvd 29nodvd
@@ -37,7 +40,12 @@ shell none
37tracelog 40tracelog
38 41
39private-bin galculator 42private-bin galculator
43private-cache
40private-dev 44private-dev
41private-etc alternatives,fonts 45private-etc alternatives,fonts
42private-lib 46private-lib
43private-tmp 47private-tmp
48
49memory-deny-write-execute
50noexec ${HOME}
51noexec /tmp