From ca9fda58a1b4563d3c7611bcd5e9bb745626f426 Mon Sep 17 00:00:00 2001 From: netblue30 Date: Wed, 15 Nov 2017 07:38:47 -0500 Subject: added ping profile, #1642 --- etc/ping.profile | 48 ++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 48 insertions(+) create mode 100644 etc/ping.profile (limited to 'etc') diff --git a/etc/ping.profile b/etc/ping.profile new file mode 100644 index 000000000..38d5bd70a --- /dev/null +++ b/etc/ping.profile @@ -0,0 +1,48 @@ +# Firejail profile for ping +# This file is overwritten after every install/update +quiet +# Persistent local customizations +include /etc/firejail/ping.local +# Persistent global definitions +include /etc/firejail/globals.local + +include /etc/firejail/disable-common.inc +include /etc/firejail/disable-devel.inc +include /etc/firejail/disable-passwdmgr.inc +include /etc/firejail/disable-programs.inc +include /etc/firejail/whitelist-common.inc + +caps.keep net_raw +ipc-namespace +#net tun0 +#netfilter /etc/firejail/ping.net +netfilter +no3d +nodvd +nogroups +# ping needs to rise privileges, noroot and nonewprivs will kill it +#nonewprivs +#noroot +nosound +notv +novideo + +# protocol command is built using seccomp; nonewprivs will kill it +#protocol unix,inet,inet6,netlink,packet + +# killed by no-new-privs +#seccomp + +disable-mnt +private +#private-bin has mammoth problems with execvp: "No such file or directory" +private-dev +private-etc resolv.conf +private-tmp + +# memory-deny-write-execute is built using seccomp; nonewprivs will kill it +#memory-deny-write-execute +noexec ${HOME} +noexec /tmp + + -- cgit v1.2.3-70-g09d2