From e401fdacf99d792434af8bb052e3b22979c12d8b Mon Sep 17 00:00:00 2001 From: glitsj16 Date: Wed, 27 Mar 2019 03:01:48 +0000 Subject: Refactor pidgin as whitelist profile (#2620) --- etc/pidgin.profile | 17 ++++++++++++----- 1 file changed, 12 insertions(+), 5 deletions(-) diff --git a/etc/pidgin.profile b/etc/pidgin.profile index 91a204557..444478149 100644 --- a/etc/pidgin.profile +++ b/etc/pidgin.profile @@ -6,14 +6,24 @@ include pidgin.local # Persistent global definitions include globals.local +mkdir ${HOME}/.purple noblacklist ${HOME}/.purple +whitelist ${HOME}/.purple + +ignore noexec ${RUNUSER} +ignore noexec /dev/shm include disable-common.inc include disable-devel.inc +include disable-exec.inc include disable-interpreters.inc include disable-passwdmgr.inc include disable-programs.inc +include disable-xdg.inc +include whitelist-common.inc +include whitelist-var-common.inc +apparmor caps.drop all netfilter nodvd @@ -24,13 +34,10 @@ notv nou2f protocol unix,inet,inet6 seccomp -shell none +# shell none tracelog -private-bin pidgin +# private-bin pidgin private-cache private-dev private-tmp - -noexec ${HOME} -noexec /tmp -- cgit v1.2.3-54-g00ecf