Harden gucharmap.profile (#2463)

This commit is contained in:
glitsj16 2019-02-24 21:53:50 +00:00 committed by GitHub
parent f932d06ac8
commit e80b999349
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23

View file

@ -14,8 +14,10 @@ include disable-passwdmgr.inc
include disable-programs.inc
include disable-xdg.inc
apparmor
caps.drop all
netfilter
machine-id
net none
no3d
nodvd
nogroups
@ -30,10 +32,15 @@ seccomp
shell none
disable-mnt
# for GTK theme support comment 'private'
private
private-cache
private-dev
private-tmp
memory-deny-write-execute
noexec ${HOME}
noexec /tmp
# gucharmap will never write anything
read-only ${HOME}