Skip to content
This repository has been archived by the owner on Jan 15, 2024. It is now read-only.

Improve profile #2

Merged
merged 2 commits into from Oct 31, 2019
Merged

Improve profile #2

merged 2 commits into from Oct 31, 2019

Conversation

madaidan
Copy link
Contributor

  • Restricts signal access to everything in the init-systemd profile
  • Restricts ptrace access to things in init-systemd, whonixcheck and unconfined processes.
  • Restricts /home/** to the owner e.g. /home/user is only accessible by the user user and not even by root.
  • Makes /usr/lib/python3/dist-packages/*/__pycache__/ writable so programs can create it
  • Makes /var/swapfile readable
  • Depends on apparmor-profile-torbrowser as that's needed for TB to work when only a few things are executable in the home dierctory

@adrelanos adrelanos merged commit 72931b1 into Kicksecure:master Oct 31, 2019
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants