aboutsummaryrefslogtreecommitdiffstats
path: root/etc/profile-m-z/unbound.profile
diff options
context:
space:
mode:
Diffstat (limited to 'etc/profile-m-z/unbound.profile')
-rw-r--r--etc/profile-m-z/unbound.profile52
1 files changed, 52 insertions, 0 deletions
diff --git a/etc/profile-m-z/unbound.profile b/etc/profile-m-z/unbound.profile
new file mode 100644
index 000000000..714a3f2f4
--- /dev/null
+++ b/etc/profile-m-z/unbound.profile
@@ -0,0 +1,52 @@
1# Firejail profile for unbound
2# Description: Validating, recursive, caching DNS resolver
3# This file is overwritten after every install/update
4# Persistent local customizations
5include unbound.local
6# Persistent global definitions
7include globals.local
8
9noblacklist /sbin
10noblacklist /usr/sbin
11
12blacklist /tmp/.X11-unix
13blacklist ${RUNUSER}/wayland-*
14
15include disable-common.inc
16include disable-devel.inc
17include disable-exec.inc
18include disable-interpreters.inc
19include disable-passwdmgr.inc
20include disable-programs.inc
21include disable-xdg.inc
22
23include whitelist-usr-share-common.inc
24
25whitelist /var/lib/unbound
26whitelist /var/run
27
28caps.keep net_admin,net_bind_service,setgid,setuid,sys_chroot,sys_resource
29ipc-namespace
30machine-id
31netfilter
32no3d
33nodvd
34nonewprivs
35nosound
36notv
37nou2f
38novideo
39protocol inet,inet6
40seccomp.drop _sysctl,acct,add_key,adjtimex,clock_adjtime,delete_module,fanotify_init,finit_module,get_mempolicy,init_module,io_cancel,io_destroy,io_getevents,io_setup,io_submit,ioperm,iopl,kcmp,kexec_file_load,kexec_load,keyctl,lookup_dcookie,mbind,migrate_pages,modify_ldt,mount,move_pages,open_by_handle_at,perf_event_open,perf_event_open,pivot_root,process_vm_readv,process_vm_writev,ptrace,remap_file_pages,request_key,set_mempolicy,swapoff,swapon,sysfs,syslog,umount2,uselib,vmsplice
41
42disable-mnt
43private
44private-dev
45private-tmp
46writable-var
47
48dbus-user none
49dbus-system none
50
51# mdwe can break modules/plugins
52memory-deny-write-execute