From cc43847b2c77b0e2bc80ea273c38971325aed065 Mon Sep 17 00:00:00 2001 From: Tobias Schmidl Date: Mon, 18 Feb 2019 13:07:47 +0100 Subject: webui-aria2: Added @glitsj16's comments - Reordered the "include disable" statements - Added `nodbus`, `nosound`, `noexec` --- etc/webui-aria2.profile | 10 ++++++++-- 1 file changed, 8 insertions(+), 2 deletions(-) diff --git a/etc/webui-aria2.profile b/etc/webui-aria2.profile index eb91820b0..5bc9c122b 100644 --- a/etc/webui-aria2.profile +++ b/etc/webui-aria2.profile @@ -9,17 +9,20 @@ include globals.local noblacklist ${PATH}/node include disable-common.inc -include disable-passwdmgr.inc -include disable-programs.inc include disable-devel.inc include disable-interpreters.inc +include disable-passwdmgr.inc +include disable-programs.inc +include disable-xdg.inc caps.drop all netfilter +nodbus nodvd nogroups nonewprivs noroot +nosound notv nou2f novideo @@ -30,3 +33,6 @@ shell none private-cache private-dev private-tmp + +noexec ${HOME} +noexec /tmp -- cgit v1.2.3-70-g09d2