aboutsummaryrefslogtreecommitdiffstats
path: root/etc/dnscrypt-proxy.profile
diff options
context:
space:
mode:
Diffstat (limited to 'etc/dnscrypt-proxy.profile')
-rw-r--r--etc/dnscrypt-proxy.profile8
1 files changed, 8 insertions, 0 deletions
diff --git a/etc/dnscrypt-proxy.profile b/etc/dnscrypt-proxy.profile
index d0430d5ca..6637b8d02 100644
--- a/etc/dnscrypt-proxy.profile
+++ b/etc/dnscrypt-proxy.profile
@@ -7,6 +7,9 @@ include dnscrypt-proxy.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10blacklist /tmp/.X11-unix
11blacklist ${RUNUSER}/wayland-*
12
10noblacklist /sbin 13noblacklist /sbin
11noblacklist /usr/sbin 14noblacklist /usr/sbin
12 15
@@ -20,10 +23,13 @@ include disable-xdg.inc
20 23
21whitelist /usr/share/dnscrypt-proxy 24whitelist /usr/share/dnscrypt-proxy
22include whitelist-usr-share-common.inc 25include whitelist-usr-share-common.inc
26include whitelist-var-common.inc
23 27
28apparmor
24caps.keep ipc_lock,net_bind_service,setgid,setuid,sys_chroot 29caps.keep ipc_lock,net_bind_service,setgid,setuid,sys_chroot
25ipc-namespace 30ipc-namespace
26machine-id 31machine-id
32netfilter
27no3d 33no3d
28nodbus 34nodbus
29nodvd 35nodvd
@@ -34,6 +40,8 @@ nou2f
34novideo 40novideo
35protocol inet,inet6 41protocol inet,inet6
36seccomp.drop _sysctl,acct,add_key,adjtimex,clock_adjtime,delete_module,fanotify_init,finit_module,get_mempolicy,init_module,io_cancel,io_destroy,io_getevents,io_setup,io_submit,ioperm,iopl,kcmp,kexec_file_load,kexec_load,keyctl,lookup_dcookie,mbind,migrate_pages,modify_ldt,mount,move_pages,open_by_handle_at,perf_event_open,perf_event_open,pivot_root,process_vm_readv,process_vm_writev,ptrace,remap_file_pages,request_key,set_mempolicy,swapoff,swapon,sysfs,syslog,umount2,uselib,vmsplice 42seccomp.drop _sysctl,acct,add_key,adjtimex,clock_adjtime,delete_module,fanotify_init,finit_module,get_mempolicy,init_module,io_cancel,io_destroy,io_getevents,io_setup,io_submit,ioperm,iopl,kcmp,kexec_file_load,kexec_load,keyctl,lookup_dcookie,mbind,migrate_pages,modify_ldt,mount,move_pages,open_by_handle_at,perf_event_open,perf_event_open,pivot_root,process_vm_readv,process_vm_writev,ptrace,remap_file_pages,request_key,set_mempolicy,swapoff,swapon,sysfs,syslog,umount2,uselib,vmsplice
43shell none
44tracelog
37 45
38disable-mnt 46disable-mnt
39private 47private