aboutsummaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
authorLibravatar rusty-snake <print_hello_world+Public@protonmail.com>2019-05-12 12:53:46 +0200
committerLibravatar rusty-snake <print_hello_world+Public@protonmail.com>2019-05-12 12:53:46 +0200
commitda2a3fd0d1780fe7751f33cd9628879a78669118 (patch)
tree0b752daf243495e1d7ffaf070ee3f205f651b3d7 /etc
parentUpdate keepassxc.profile (#2687) (diff)
downloadfirejail-da2a3fd0d1780fe7751f33cd9628879a78669118.tar.gz
firejail-da2a3fd0d1780fe7751f33cd9628879a78669118.tar.zst
firejail-da2a3fd0d1780fe7751f33cd9628879a78669118.zip
harden & fix xiphos.profile
Diffstat (limited to 'etc')
-rw-r--r--etc/xiphos.profile8
1 files changed, 7 insertions, 1 deletions
diff --git a/etc/xiphos.profile b/etc/xiphos.profile
index 3ad03e2c6..33056395e 100644
--- a/etc/xiphos.profile
+++ b/etc/xiphos.profile
@@ -13,6 +13,7 @@ noblacklist ${HOME}/.xiphos
13 13
14include disable-common.inc 14include disable-common.inc
15include disable-devel.inc 15include disable-devel.inc
16include disable-exec.inc
16include disable-interpreters.inc 17include disable-interpreters.inc
17include disable-passwdmgr.inc 18include disable-passwdmgr.inc
18include disable-programs.inc 19include disable-programs.inc
@@ -20,8 +21,11 @@ include disable-programs.inc
20whitelist ${HOME}/.sword 21whitelist ${HOME}/.sword
21whitelist ${HOME}/.xiphos 22whitelist ${HOME}/.xiphos
22include whitelist-common.inc 23include whitelist-common.inc
24include whitelist-var-common.inc
23 25
26apparmor
24caps.drop all 27caps.drop all
28machine-id
25netfilter 29netfilter
26nodvd 30nodvd
27nogroups 31nogroups
@@ -36,7 +40,9 @@ seccomp
36shell none 40shell none
37tracelog 41tracelog
38 42
43disable-mnt
39private-bin xiphos 44private-bin xiphos
45private-cache
40private-dev 46private-dev
41private-etc alternatives,fonts,resolv.conf,sword,ca-certificates,ssl,pki,crypto-policies 47private-etc alternatives,fonts,resolv.conf,sword,ca-certificates,ssli,sword.conf,pki,crypto-policies
42private-tmp 48private-tmp