From cd0ba20ed678de717ee7769d13447f65f9520e3b Mon Sep 17 00:00:00 2001 From: glitsj16 Date: Fri, 4 May 2018 02:27:06 +0000 Subject: add disable-interpreters.inc to gnome-logs (#1923) * add disable-interpreters.inc to gnome-logs Besides adding `include /etc/firejail/disable-interpreters.inc`, enabling both `private-etc` and `private-lib` (tested with systemd default storage and volatile journal). * Add localtime to private-etc --- etc/gnome-logs.profile | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/etc/gnome-logs.profile b/etc/gnome-logs.profile index 7e7902dff..e5f691544 100644 --- a/etc/gnome-logs.profile +++ b/etc/gnome-logs.profile @@ -7,6 +7,7 @@ include /etc/firejail/globals.local include /etc/firejail/disable-common.inc include /etc/firejail/disable-devel.inc +include /etc/firejail/disable-interpreters.inc include /etc/firejail/disable-passwdmgr.inc include /etc/firejail/disable-programs.inc @@ -31,8 +32,8 @@ shell none disable-mnt private-bin gnome-logs private-dev -#private-etc fonts -#private-lib gdk-pixbuf-2.0,gio,gvfs/libgvfscommon.so,libgconf-2.so.4,librsvg-2.so.2 +private-etc fonts,localtime +private-lib gdk-pixbuf-2.0,gio,gvfs/libgvfscommon.so,libgconf-2.so.4,librsvg-2.so.2 private-tmp writable-var-log -- cgit v1.2.3-54-g00ecf