aboutsummaryrefslogtreecommitdiffstats
path: root/etc/start-tor-browser.profile
diff options
context:
space:
mode:
Diffstat (limited to 'etc/start-tor-browser.profile')
-rw-r--r--etc/start-tor-browser.profile19
1 files changed, 10 insertions, 9 deletions
diff --git a/etc/start-tor-browser.profile b/etc/start-tor-browser.profile
index 4d9ebcb2e..d3b0b27e3 100644
--- a/etc/start-tor-browser.profile
+++ b/etc/start-tor-browser.profile
@@ -1,19 +1,19 @@
1# Firejail profile for start-tor-browser 1# Firejail profile for start-tor-browser
2# This file is overwritten after every install/update 2# This file is overwritten after every install/update
3# Persistent local customizations 3# Persistent local customizations
4include /etc/firejail/start-tor-browser.local 4include start-tor-browser.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include globals.local
7 7
8 8
9include /etc/firejail/disable-common.inc 9include disable-common.inc
10include /etc/firejail/disable-devel.inc 10include disable-devel.inc
11include /etc/firejail/disable-interpreters.inc 11include disable-interpreters.inc
12include /etc/firejail/disable-passwdmgr.inc 12include disable-passwdmgr.inc
13include /etc/firejail/disable-programs.inc 13include disable-programs.inc
14include /etc/firejail/disable-xdg.inc 14include disable-xdg.inc
15 15
16include /etc/firejail/whitelist-var-common.inc 16include whitelist-var-common.inc
17 17
18caps.drop all 18caps.drop all
19netfilter 19netfilter
@@ -23,6 +23,7 @@ nogroups
23nonewprivs 23nonewprivs
24noroot 24noroot
25notv 25notv
26nou2f
26novideo 27novideo
27protocol unix,inet,inet6 28protocol unix,inet,inet6
28seccomp.drop @clock,@cpu-emulation,@debug,@module,@obsolete,@raw-io,@reboot,@resources,@swap,acct,add_key,bpf,fanotify_init,io_cancel,io_destroy,io_getevents,io_setup,io_submit,ioprio_set,kcmp,keyctl,mount,name_to_handle_at,nfsservctl,ni_syscall,open_by_handle_at,personality,pivot_root,process_vm_readv,ptrace,remap_file_pages,request_key,setdomainname,sethostname,syslog,umount,umount2,userfaultfd,vhangup,vmsplice 29seccomp.drop @clock,@cpu-emulation,@debug,@module,@obsolete,@raw-io,@reboot,@resources,@swap,acct,add_key,bpf,fanotify_init,io_cancel,io_destroy,io_getevents,io_setup,io_submit,ioprio_set,kcmp,keyctl,mount,name_to_handle_at,nfsservctl,ni_syscall,open_by_handle_at,personality,pivot_root,process_vm_readv,ptrace,remap_file_pages,request_key,setdomainname,sethostname,syslog,umount,umount2,userfaultfd,vhangup,vmsplice