aboutsummaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
authorLibravatar rusty-snake <print_hello_world+Public@protonmail.com>2019-03-13 13:08:53 +0100
committerLibravatar rusty-snake <print_hello_world+Public@protonmail.com>2019-03-13 13:08:53 +0100
commitd4d176470a1c0e9ad2a65428318f78f7c2609332 (patch)
treee4e7ae2dddf48bc8f14c1df4e10bda05e997ad7c /etc
parentadd disable-exec.inc to few more profiles (diff)
downloadfirejail-d4d176470a1c0e9ad2a65428318f78f7c2609332.tar.gz
firejail-d4d176470a1c0e9ad2a65428318f78f7c2609332.tar.zst
firejail-d4d176470a1c0e9ad2a65428318f78f7c2609332.zip
Harden Minetest
Diffstat (limited to 'etc')
-rw-r--r--etc/minetest.profile7
1 files changed, 4 insertions, 3 deletions
diff --git a/etc/minetest.profile b/etc/minetest.profile
index aa50847ea..b3e692446 100644
--- a/etc/minetest.profile
+++ b/etc/minetest.profile
@@ -10,9 +10,11 @@ noblacklist ${HOME}/.minetest
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
13include disable-exec.inc
13include disable-interpreters.inc 14include disable-interpreters.inc
14include disable-passwdmgr.inc 15include disable-passwdmgr.inc
15include disable-programs.inc 16include disable-programs.inc
17include disable-xdg.inc
16 18
17mkdir ${HOME}/.minetest 19mkdir ${HOME}/.minetest
18whitelist ${HOME}/.minetest 20whitelist ${HOME}/.minetest
@@ -33,13 +35,12 @@ novideo
33protocol unix,inet,inet6 35protocol unix,inet,inet6
34seccomp 36seccomp
35shell none 37shell none
38tracelog
36 39
37disable-mnt 40disable-mnt
38private-bin minetest 41private-bin minetest
42private-cache
39private-dev 43private-dev
40# private-etc needs to be updated, see #1702 44# private-etc needs to be updated, see #1702
41#private-etc alternatives,asound.conf,ca-certificates,drirc,fonts,group,host.conf,hostname,hosts,ld.so.cache,ld.so.preload,localtime,nsswitch.conf,passwd,pulse,resolv.conf,ssl,pki,crypto-policies,machine-id 45#private-etc alternatives,asound.conf,ca-certificates,drirc,fonts,group,host.conf,hostname,hosts,ld.so.cache,ld.so.preload,localtime,nsswitch.conf,passwd,pulse,resolv.conf,ssl,pki,crypto-policies,machine-id
42private-tmp 46private-tmp
43
44noexec ${HOME}
45noexec /tmp