harden redeclipse

This commit is contained in:
rusty-snake 2020-09-02 13:03:54 +02:00
parent 8f23b47309
commit 7c21aad234

View file

@ -14,10 +14,14 @@ include disable-exec.inc
include disable-interpreters.inc
include disable-passwdmgr.inc
include disable-programs.inc
include disable-xdg.inc
mkdir ${HOME}/.redeclipse
whitelist ${HOME}/.redeclipse
whitelist /usr/share/redeclipse
include whitelist-common.inc
include whitelist-runuser-common.inc
include whitelist-usr-share-common.inc
include whitelist-var-common.inc
caps.drop all
@ -32,8 +36,13 @@ novideo
protocol unix,inet,inet6
seccomp
shell none
tracelog
disable-mnt
#private-bin redeclipse,sh,man
private-cache
private-dev
private-tmp
dbus-user none
dbus-system none