From fa10ab0e093a4224b16491273b0162b0e0a77a3a Mon Sep 17 00:00:00 2001 From: valoq Date: Sat, 19 Nov 2016 21:57:42 +0100 Subject: many new profiles --- etc/skanlite.profile | 21 +++++++++++++++++++++ 1 file changed, 21 insertions(+) create mode 100644 etc/skanlite.profile (limited to 'etc/skanlite.profile') diff --git a/etc/skanlite.profile b/etc/skanlite.profile new file mode 100644 index 000000000..6e8face75 --- /dev/null +++ b/etc/skanlite.profile @@ -0,0 +1,21 @@ +# skanlite profile +include /etc/firejail/disable-common.inc +include /etc/firejail/disable-programs.inc +include /etc/firejail/disable-devel.inc +include /etc/firejail/disable-passwdmgr.inc + +caps.drop all +netfilter +nogroups +nonewprivs +noroot +nosound +shell none +#seccomp +protocol unix + +private-bin skanlite +# private-dev +# private-tmp +# private-etc + -- cgit v1.2.3-70-g09d2 From 35cf892b0bcb9b5a88e70c211c5dab3b65b86c2b Mon Sep 17 00:00:00 2001 From: valoq Date: Sat, 19 Nov 2016 23:10:01 +0100 Subject: minor fix --- etc/skanlite.profile | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) (limited to 'etc/skanlite.profile') diff --git a/etc/skanlite.profile b/etc/skanlite.profile index 6e8face75..4dcfa64d9 100644 --- a/etc/skanlite.profile +++ b/etc/skanlite.profile @@ -12,7 +12,7 @@ noroot nosound shell none #seccomp -protocol unix +protocol unix,inet,inet6 private-bin skanlite # private-dev -- cgit v1.2.3-70-g09d2