aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
-rw-r--r--etc/default.profile10
-rw-r--r--etc/file.profile19
2 files changed, 22 insertions, 7 deletions
diff --git a/etc/default.profile b/etc/default.profile
index a2de72695..487e80c64 100644
--- a/etc/default.profile
+++ b/etc/default.profile
@@ -5,11 +5,17 @@ include /etc/firejail/disable-common.inc
5include /etc/firejail/disable-programs.inc 5include /etc/firejail/disable-programs.inc
6include /etc/firejail/disable-passwdmgr.inc 6include /etc/firejail/disable-passwdmgr.inc
7 7
8#blacklist ${HOME}/.wine
9
10caps.drop all 8caps.drop all
11netfilter 9netfilter
10nogroups
12nonewprivs 11nonewprivs
13noroot 12noroot
14protocol unix,inet,inet6 13protocol unix,inet,inet6
15seccomp 14seccomp
15shell none
16
17# private-bin program
18# private-etc none
19# private-dev
20# private-tmp
21
diff --git a/etc/file.profile b/etc/file.profile
index 199a97fad..f709e7f0c 100644
--- a/etc/file.profile
+++ b/etc/file.profile
@@ -1,16 +1,25 @@
1# file profile 1# file profile
2ignore noroot 2include /etc/firejail/disable-common.inc
3include /etc/firejail/default.profile 3include /etc/firejail/disable-programs.inc
4 4include /etc/firejail/disable-passwdmgr.inc
5blacklist /tmp/.X11-unix
6 5
6caps.drop all
7hostname file 7hostname file
8netfilter
8net none 9net none
9no3d 10no3d
11nogroups
12nonewprivs
13#noroot
10nosound 14nosound
11quiet 15protocol unix
16seccomp
12shell none 17shell none
13tracelog 18tracelog
19quiet
20x11 none
21
22blacklist /tmp/.X11-unix
14 23
15private-dev 24private-dev
16private-bin file 25private-bin file