From 223131c24f5dcfe3c362c8e214f3fae2bca8b4b8 Mon Sep 17 00:00:00 2001 From: glitsj16 Date: Sun, 24 Feb 2019 21:36:41 +0000 Subject: Harden gnome-calculator.profile (#2460) --- etc/gnome-calculator.profile | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/etc/gnome-calculator.profile b/etc/gnome-calculator.profile index be4b0c03f..8c1682291 100644 --- a/etc/gnome-calculator.profile +++ b/etc/gnome-calculator.profile @@ -17,8 +17,10 @@ include disable-xdg.inc include whitelist-common.inc include whitelist-var-common.inc -# apparmor - makes settings immutable +apparmor caps.drop all +ipc-namespace +machine-id # net none netfilter no3d @@ -42,6 +44,6 @@ private-dev private-lib gdk-pixbuf-2.*,gio,girepository-1.*,gvfs,libgconf-2.so.*,libgnutls.so.*,libproxy.so.*,librsvg-2.so.*,libxml2.so.* private-tmp -#memory-deny-write-execute - breaks on Arch +memory-deny-write-execute noexec ${HOME} noexec /tmp -- cgit v1.2.3-70-g09d2