From 252fd305d7449a4915ccfd246596a0de425efe44 Mon Sep 17 00:00:00 2001 From: rusty-snake Date: Thu, 23 May 2019 13:49:45 +0000 Subject: Harden gnome-chess (#2719) * Harden gnome-chess * Update gnome-chess.profile remove whitelisting --- etc/gnome-chess.profile | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) (limited to 'etc') diff --git a/etc/gnome-chess.profile b/etc/gnome-chess.profile index 2f4626891..04409a5e4 100644 --- a/etc/gnome-chess.profile +++ b/etc/gnome-chess.profile @@ -18,7 +18,10 @@ include disable-xdg.inc include whitelist-var-common.inc +apparmor caps.drop all +machine-id +net none no3d nodvd nogroups @@ -35,6 +38,7 @@ tracelog disable-mnt private-bin fairymax,gnome-chess,hoichess,gnuchess +private-cache private-dev -private-etc alternatives,fonts,gnome-chess +private-etc alternatives,dconf,fonts,gnome-chess,gtk-3.0 private-tmp -- cgit v1.2.3-70-g09d2