aboutsummaryrefslogtreecommitdiffstats
path: root/etc/profile-m-z/server.profile
diff options
context:
space:
mode:
Diffstat (limited to 'etc/profile-m-z/server.profile')
-rw-r--r--etc/profile-m-z/server.profile10
1 files changed, 7 insertions, 3 deletions
diff --git a/etc/profile-m-z/server.profile b/etc/profile-m-z/server.profile
index 9e40796a6..fd7ffb38d 100644
--- a/etc/profile-m-z/server.profile
+++ b/etc/profile-m-z/server.profile
@@ -33,6 +33,7 @@ include globals.local
33 33
34noblacklist /sbin 34noblacklist /sbin
35noblacklist /usr/sbin 35noblacklist /usr/sbin
36noblacklist /etc/init.d
36# noblacklist /var/opt 37# noblacklist /var/opt
37 38
38blacklist /tmp/.X11-unix 39blacklist /tmp/.X11-unix
@@ -50,7 +51,9 @@ include disable-xdg.inc
50# include whitelist-usr-share-common.inc 51# include whitelist-usr-share-common.inc
51# include whitelist-var-common.inc 52# include whitelist-var-common.inc
52 53
53apparmor 54# people use to install servers all over the place!
55# apparmor runs executable only from default system locations
56# apparmor
54caps 57caps
55# ipc-namespace 58# ipc-namespace
56machine-id 59machine-id
@@ -59,15 +62,16 @@ no3d
59nodvd 62nodvd
60# nogroups 63# nogroups
61noinput 64noinput
62# nonewprivs 65nonewprivs
63# noroot 66# noroot
64nosound 67nosound
65notv 68notv
66nou2f 69nou2f
67novideo 70novideo
68# protocol unix,inet,inet6,netlink 71protocol unix,inet,inet6,netlink,packet
69seccomp 72seccomp
70# shell none 73# shell none
74tab # allow tab completion
71 75
72disable-mnt 76disable-mnt
73private 77private