blob: 6fd70241c6a57006ca1cecb1e0a9eb27f75d8005 (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
|
# mutt profile
blacklist /tmp/.X11-unix
noblacklist /var/mail
noblacklist /var/spool/mail
noblacklist ${HOME}/.Mail
noblacklist ${HOME}/.bogofilter
noblacklist ${HOME}/.cache/mutt
noblacklist ${HOME}/.elinks
noblacklist ${HOME}/.emacs
noblacklist ${HOME}/.emacs.d
noblacklist ${HOME}/.gnupg
noblacklist ${HOME}/.mail
noblacklist ${HOME}/.mailcap
noblacklist ${HOME}/.msmtprc
noblacklist ${HOME}/.mutt
noblacklist ${HOME}/.muttrc
noblacklist ${HOME}/.signature
noblacklist ${HOME}/.vim
noblacklist ${HOME}/.viminfo
noblacklist ${HOME}/.vimrc
noblacklist ${HOME}/.w3m
noblacklist ${HOME}/Mail
noblacklist ${HOME}/mail
noblacklist ${HOME}/postponed
noblacklist ${HOME}/sent
# custom
quiet
noblacklist ~/.custom
noblacklist ~/.config/msmtp/config
noblacklist ~/.procmailrc
noblacklist ~/.fetchmailrc
noblacklist ~/.getmail
noblacklist ~/.smime
noblacklist ~/apps/utils-mail
noblacklist /usr/bin/fetchmail
noblacklist /usr/bin/getmail
noblacklist /usr/bin/getmails
noblacklist /usr/bin/muttprint
noblacklist /usr/bin/perl
noblacklist /usr/bin/cpan*
noblacklist /usr/share/perl*
noblacklist /usr/lib/perl*
noblacklist ${PATH}/procmail
# allow local mail
whitelist /var/mail
# allow write operations in non-default folders
include whitelist-common.local
include disable-common.inc
include disable-devel.inc
# These restrictions prevent the use of the getmails(1) script
#include disable-interpreters.inc
include disable-passwdmgr.inc
include disable-programs.inc
caps.drop all
netfilter
no3d
nodvd
nogroups
noroot
nosound
notv
nou2f
novideo
writable-run-user
# These restrictions prevent msmtp to use the passwordeval option
#nonewprivs
#protocol unix,inet,inet6
#seccomp
#shell none
private-dev
|