Harden enchant.profile (#2455)

This commit is contained in:
glitsj16 2019-02-24 21:11:55 +00:00 committed by GitHub
parent 549427d4af
commit 17b7a99c68
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23

View file

@ -15,8 +15,11 @@ include disable-passwdmgr.inc
include disable-programs.inc
include disable-xdg.inc
apparmor
caps.drop all
netfilter
ipc-namespace
machine-id
net none
no3d
nodbus
nodvd
@ -32,12 +35,13 @@ seccomp
shell none
tracelog
# private-bin enchant, enchant-*
private-bin enchant, enchant-*
private-cache
private-dev
private-etc alternatives
private-lib
private-tmp
# memory-deny-write-execute
memory-deny-write-execute
noexec ${HOME}
noexec /tmp