aboutsummaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
authorLibravatar Tad <tad@spotco.us>2017-09-21 08:07:48 -0400
committerLibravatar Tad <tad@spotco.us>2017-09-21 08:07:48 -0400
commite1af15d8e713d53aa9b7d7eeb7cee4336a8323f5 (patch)
treeb34a659a387f964335b17404d5e882caa374eb81 /etc
parentAdd a profile for arch-audit (diff)
downloadfirejail-e1af15d8e713d53aa9b7d7eeb7cee4336a8323f5.tar.gz
firejail-e1af15d8e713d53aa9b7d7eeb7cee4336a8323f5.tar.zst
firejail-e1af15d8e713d53aa9b7d7eeb7cee4336a8323f5.zip
Diffstat (limited to 'etc')
-rw-r--r--etc/arch-audit.profile40
1 files changed, 40 insertions, 0 deletions
diff --git a/etc/arch-audit.profile b/etc/arch-audit.profile
new file mode 100644
index 000000000..d8ed64811
--- /dev/null
+++ b/etc/arch-audit.profile
@@ -0,0 +1,40 @@
1# Firejail profile for arch-audit
2# This file is overwritten after every install/update
3quiet
4# Persistent local customizations
5include /etc/firejail/arch-audit.local
6# Persistent global definitions
7include /etc/firejail/globals.local
8
9
10noblacklist /var/lib/pacman
11
12include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-devel.inc
14include /etc/firejail/disable-passwdmgr.inc
15include /etc/firejail/disable-programs.inc
16
17caps.drop all
18ipc-namespace
19netfilter
20no3d
21nodvd
22nogroups
23nonewprivs
24noroot
25nosound
26notv
27novideo
28protocol unix,inet,inet6
29seccomp
30shell none
31
32disable-mnt
33private
34private-bin arch-audit
35private-dev
36private-tmp
37
38memory-deny-write-execute
39noexec ${HOME}
40noexec /tmp