From 4196637adc23b071d48efdcc03962c3256eaf511 Mon Sep 17 00:00:00 2001 From: glitsj16 Date: Sun, 24 Feb 2019 21:31:17 +0000 Subject: Harden git.profile (#2459) --- etc/git.profile | 7 +++++++ 1 file changed, 7 insertions(+) (limited to 'etc') diff --git a/etc/git.profile b/etc/git.profile index 243516e88..e2d938416 100644 --- a/etc/git.profile +++ b/etc/git.profile @@ -22,7 +22,10 @@ include disable-common.inc include disable-passwdmgr.inc include disable-programs.inc +apparmor caps.drop all +ipc-namespace +machine-id netfilter no3d nodvd @@ -39,3 +42,7 @@ shell none private-cache private-dev + +memory-deny-write-execute +noexec ${HOME} +noexec /tmp -- cgit v1.2.3-70-g09d2