aboutsummaryrefslogtreecommitdiffstats
path: root/etc/profile-a-l/fdns.profile
diff options
context:
space:
mode:
Diffstat (limited to 'etc/profile-a-l/fdns.profile')
-rw-r--r--etc/profile-a-l/fdns.profile50
1 files changed, 50 insertions, 0 deletions
diff --git a/etc/profile-a-l/fdns.profile b/etc/profile-a-l/fdns.profile
new file mode 100644
index 000000000..179540806
--- /dev/null
+++ b/etc/profile-a-l/fdns.profile
@@ -0,0 +1,50 @@
1# Firejail profile for server
2# This file is overwritten after every install/update
3# Persistent local customizations
4include fdns.local
5# Persistent global definitions
6include globals.local
7
8noblacklist /sbin
9noblacklist /usr/sbin
10
11blacklist /tmp/.X11-unix
12blacklist ${RUNUSER}/wayland-*
13
14include disable-common.inc
15include disable-devel.inc
16include disable-exec.inc
17include disable-interpreters.inc
18include disable-passwdmgr.inc
19include disable-programs.inc
20include disable-xdg.inc
21
22#include whitelist-usr-share-common.inc
23#include whitelist-var-common.inc
24
25caps.keep kill,net_bind_service,setgid,setuid,sys_admin,sys_chroot
26ipc-namespace
27# netfilter /etc/firejail/webserver.net
28no3d
29nodvd
30nogroups
31nonewprivs
32# noroot
33nosound
34notv
35nou2f
36novideo
37protocol unix,inet,inet6
38#seccomp
39#shell none
40
41disable-mnt
42private
43private-bin bash,fdns,sh
44# private-cache
45private-dev
46private-etc ca-certificates,crypto-policies,fdns,ld.so.cache,ld.so.preload,localtime,nsswitch.conf,passwd,pki,ssl
47# private-lib
48private-tmp
49
50memory-deny-write-execute