aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLibravatar Tad <tad@spotco.us>2018-09-19 15:32:18 -0400
committerLibravatar Tad <tad@spotco.us>2018-09-19 15:32:48 -0400
commitc0ba48bec1bc11c98cbac3c6cc9fdf117dcb98d1 (patch)
tree83e0f2b4020db3c9ae6c0501aab2d30f56df086e
parent0.9.56 released (diff)
downloadfirejail-c0ba48bec1bc11c98cbac3c6cc9fdf117dcb98d1.tar.gz
firejail-c0ba48bec1bc11c98cbac3c6cc9fdf117dcb98d1.tar.zst
firejail-c0ba48bec1bc11c98cbac3c6cc9fdf117dcb98d1.zip
Misc profile hardening
-rw-r--r--etc/android-studio.profile2
-rw-r--r--etc/apktool.profile2
-rw-r--r--etc/bless.profile2
-rw-r--r--etc/dex2jar.profile2
-rw-r--r--etc/gitg.profile2
-rw-r--r--etc/jd-gui.profile2
-rw-r--r--etc/liferea.profile1
-rw-r--r--etc/lollypop.profile2
-rw-r--r--etc/meld.profile2
-rw-r--r--etc/minetest.profile2
-rw-r--r--etc/mumble.profile1
-rw-r--r--etc/patch.profile2
-rw-r--r--etc/picard.profile2
-rw-r--r--etc/pithos.profile1
-rw-r--r--etc/remmina.profile2
-rw-r--r--etc/sdat2img.profile2
-rw-r--r--etc/shellcheck.profile2
-rw-r--r--etc/soundconverter.profile2
-rw-r--r--etc/sqlitebrowser.profile2
-rw-r--r--etc/vlc.profile2
-rw-r--r--etc/xonotic.profile1
21 files changed, 37 insertions, 1 deletions
diff --git a/etc/android-studio.profile b/etc/android-studio.profile
index d845bd4b9..8f5cd56cc 100644
--- a/etc/android-studio.profile
+++ b/etc/android-studio.profile
@@ -20,6 +20,8 @@ include /etc/firejail/disable-common.inc
20include /etc/firejail/disable-passwdmgr.inc 20include /etc/firejail/disable-passwdmgr.inc
21include /etc/firejail/disable-programs.inc 21include /etc/firejail/disable-programs.inc
22 22
23include /etc/firejail/whitelist-var-common.inc
24
23caps.drop all 25caps.drop all
24netfilter 26netfilter
25nodvd 27nodvd
diff --git a/etc/apktool.profile b/etc/apktool.profile
index 2043cf5af..d157b1478 100644
--- a/etc/apktool.profile
+++ b/etc/apktool.profile
@@ -12,6 +12,8 @@ include /etc/firejail/disable-passwdmgr.inc
12include /etc/firejail/disable-programs.inc 12include /etc/firejail/disable-programs.inc
13include /etc/firejail/disable-xdg.inc 13include /etc/firejail/disable-xdg.inc
14 14
15include /etc/firejail/whitelist-var-common.inc
16
15caps.drop all 17caps.drop all
16net none 18net none
17no3d 19no3d
diff --git a/etc/bless.profile b/etc/bless.profile
index 01f75b00d..0da3436e8 100644
--- a/etc/bless.profile
+++ b/etc/bless.profile
@@ -14,6 +14,8 @@ include /etc/firejail/disable-interpreters.inc
14include /etc/firejail/disable-passwdmgr.inc 14include /etc/firejail/disable-passwdmgr.inc
15include /etc/firejail/disable-programs.inc 15include /etc/firejail/disable-programs.inc
16 16
17include /etc/firejail/whitelist-var-common.inc
18
17caps.drop all 19caps.drop all
18net none 20net none
19no3d 21no3d
diff --git a/etc/dex2jar.profile b/etc/dex2jar.profile
index b61d68e06..da59fc71a 100644
--- a/etc/dex2jar.profile
+++ b/etc/dex2jar.profile
@@ -19,6 +19,8 @@ include /etc/firejail/disable-passwdmgr.inc
19include /etc/firejail/disable-programs.inc 19include /etc/firejail/disable-programs.inc
20include /etc/firejail/disable-xdg.inc 20include /etc/firejail/disable-xdg.inc
21 21
22include /etc/firejail/whitelist-var-common.inc
23
22caps.drop all 24caps.drop all
23net none 25net none
24no3d 26no3d
diff --git a/etc/gitg.profile b/etc/gitg.profile
index 5a7349eb1..87d8c0a1f 100644
--- a/etc/gitg.profile
+++ b/etc/gitg.profile
@@ -16,6 +16,8 @@ include /etc/firejail/disable-interpreters.inc
16include /etc/firejail/disable-passwdmgr.inc 16include /etc/firejail/disable-passwdmgr.inc
17include /etc/firejail/disable-programs.inc 17include /etc/firejail/disable-programs.inc
18 18
19include /etc/firejail/whitelist-var-common.inc
20
19caps.drop all 21caps.drop all
20no3d 22no3d
21nodvd 23nodvd
diff --git a/etc/jd-gui.profile b/etc/jd-gui.profile
index 81e538153..3a280dab7 100644
--- a/etc/jd-gui.profile
+++ b/etc/jd-gui.profile
@@ -21,6 +21,8 @@ include /etc/firejail/disable-passwdmgr.inc
21include /etc/firejail/disable-programs.inc 21include /etc/firejail/disable-programs.inc
22include /etc/firejail/disable-xdg.inc 22include /etc/firejail/disable-xdg.inc
23 23
24include /etc/firejail/whitelist-var-common.inc
25
24caps.drop all 26caps.drop all
25net none 27net none
26no3d 28no3d
diff --git a/etc/liferea.profile b/etc/liferea.profile
index 673182c10..04c649121 100644
--- a/etc/liferea.profile
+++ b/etc/liferea.profile
@@ -29,6 +29,7 @@ whitelist ${HOME}/.cache/liferea
29whitelist ${HOME}/.config/liferea 29whitelist ${HOME}/.config/liferea
30whitelist ${HOME}/.local/share/liferea 30whitelist ${HOME}/.local/share/liferea
31include /etc/firejail/whitelist-common.inc 31include /etc/firejail/whitelist-common.inc
32include /etc/firejail/whitelist-var-common.inc
32 33
33caps.drop all 34caps.drop all
34netfilter 35netfilter
diff --git a/etc/lollypop.profile b/etc/lollypop.profile
index 0f8f49488..efd40e899 100644
--- a/etc/lollypop.profile
+++ b/etc/lollypop.profile
@@ -22,6 +22,8 @@ include /etc/firejail/disable-passwdmgr.inc
22include /etc/firejail/disable-programs.inc 22include /etc/firejail/disable-programs.inc
23include /etc/firejail/disable-xdg.inc 23include /etc/firejail/disable-xdg.inc
24 24
25include /etc/firejail/whitelist-var-common.inc
26
25caps.drop all 27caps.drop all
26netfilter 28netfilter
27no3d 29no3d
diff --git a/etc/meld.profile b/etc/meld.profile
index 00d5c6caa..1a7935800 100644
--- a/etc/meld.profile
+++ b/etc/meld.profile
@@ -13,6 +13,8 @@ include /etc/firejail/disable-devel.inc
13include /etc/firejail/disable-passwdmgr.inc 13include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc 14include /etc/firejail/disable-programs.inc
15 15
16include /etc/firejail/whitelist-var-common.inc
17
16caps.drop all 18caps.drop all
17net none 19net none
18no3d 20no3d
diff --git a/etc/minetest.profile b/etc/minetest.profile
index 7de546791..3e06b6d30 100644
--- a/etc/minetest.profile
+++ b/etc/minetest.profile
@@ -17,10 +17,12 @@ include /etc/firejail/disable-programs.inc
17mkdir ${HOME}/.minetest 17mkdir ${HOME}/.minetest
18whitelist ${HOME}/.minetest 18whitelist ${HOME}/.minetest
19include /etc/firejail/whitelist-common.inc 19include /etc/firejail/whitelist-common.inc
20include /etc/firejail/whitelist-var-common.inc
20 21
21caps.drop all 22caps.drop all
22ipc-namespace 23ipc-namespace
23netfilter 24netfilter
25nodbus
24nodvd 26nodvd
25nogroups 27nogroups
26nonewprivs 28nonewprivs
diff --git a/etc/mumble.profile b/etc/mumble.profile
index f894acb57..c5af9aa42 100644
--- a/etc/mumble.profile
+++ b/etc/mumble.profile
@@ -20,6 +20,7 @@ mkdir ${HOME}/.local/share/data/Mumble
20whitelist ${HOME}/.config/Mumble 20whitelist ${HOME}/.config/Mumble
21whitelist ${HOME}/.local/share/data/Mumble 21whitelist ${HOME}/.local/share/data/Mumble
22include /etc/firejail/whitelist-common.inc 22include /etc/firejail/whitelist-common.inc
23include /etc/firejail/whitelist-var-common.inc
23 24
24caps.drop all 25caps.drop all
25netfilter 26netfilter
diff --git a/etc/patch.profile b/etc/patch.profile
index d4058d6e7..8fa6ac966 100644
--- a/etc/patch.profile
+++ b/etc/patch.profile
@@ -15,6 +15,8 @@ include /etc/firejail/disable-interpreters.inc
15include /etc/firejail/disable-passwdmgr.inc 15include /etc/firejail/disable-passwdmgr.inc
16include /etc/firejail/disable-xdg.inc 16include /etc/firejail/disable-xdg.inc
17 17
18include /etc/firejail/whitelist-var-common.inc
19
18caps.drop all 20caps.drop all
19ipc-namespace 21ipc-namespace
20net none 22net none
diff --git a/etc/picard.profile b/etc/picard.profile
index 2cc0b5c68..8474eeda6 100644
--- a/etc/picard.profile
+++ b/etc/picard.profile
@@ -23,6 +23,8 @@ include /etc/firejail/disable-passwdmgr.inc
23include /etc/firejail/disable-programs.inc 23include /etc/firejail/disable-programs.inc
24include /etc/firejail/disable-xdg.inc 24include /etc/firejail/disable-xdg.inc
25 25
26include /etc/firejail/whitelist-var-common.inc
27
26caps.drop all 28caps.drop all
27no3d 29no3d
28nodvd 30nodvd
diff --git a/etc/pithos.profile b/etc/pithos.profile
index e5af9c973..cbe7ac9c6 100644
--- a/etc/pithos.profile
+++ b/etc/pithos.profile
@@ -20,6 +20,7 @@ include /etc/firejail/disable-programs.inc
20include /etc/firejail/disable-xdg.inc 20include /etc/firejail/disable-xdg.inc
21 21
22include /etc/firejail/whitelist-common.inc 22include /etc/firejail/whitelist-common.inc
23include /etc/firejail/whitelist-var-common.inc
23 24
24caps.drop all 25caps.drop all
25netfilter 26netfilter
diff --git a/etc/remmina.profile b/etc/remmina.profile
index 5078000bb..51c0f2d17 100644
--- a/etc/remmina.profile
+++ b/etc/remmina.profile
@@ -18,6 +18,8 @@ include /etc/firejail/disable-passwdmgr.inc
18include /etc/firejail/disable-programs.inc 18include /etc/firejail/disable-programs.inc
19include /etc/firejail/disable-xdg.inc 19include /etc/firejail/disable-xdg.inc
20 20
21include /etc/firejail/whitelist-var-common.inc
22
21caps.drop all 23caps.drop all
22nodvd 24nodvd
23nogroups 25nogroups
diff --git a/etc/sdat2img.profile b/etc/sdat2img.profile
index e318dd568..a2a54f838 100644
--- a/etc/sdat2img.profile
+++ b/etc/sdat2img.profile
@@ -19,6 +19,8 @@ include /etc/firejail/disable-passwdmgr.inc
19include /etc/firejail/disable-programs.inc 19include /etc/firejail/disable-programs.inc
20include /etc/firejail/disable-xdg.inc 20include /etc/firejail/disable-xdg.inc
21 21
22include /etc/firejail/whitelist-var-common.inc
23
22caps.drop all 24caps.drop all
23net none 25net none
24no3d 26no3d
diff --git a/etc/shellcheck.profile b/etc/shellcheck.profile
index f6c154183..90fc9cb8c 100644
--- a/etc/shellcheck.profile
+++ b/etc/shellcheck.profile
@@ -16,6 +16,8 @@ include /etc/firejail/disable-passwdmgr.inc
16include /etc/firejail/disable-programs.inc 16include /etc/firejail/disable-programs.inc
17include /etc/firejail/disable-xdg.inc 17include /etc/firejail/disable-xdg.inc
18 18
19include /etc/firejail/whitelist-var-common.inc
20
19caps.drop all 21caps.drop all
20ipc-namespace 22ipc-namespace
21net none 23net none
diff --git a/etc/soundconverter.profile b/etc/soundconverter.profile
index ee4d90265..69efe5244 100644
--- a/etc/soundconverter.profile
+++ b/etc/soundconverter.profile
@@ -21,6 +21,8 @@ include /etc/firejail/disable-passwdmgr.inc
21include /etc/firejail/disable-programs.inc 21include /etc/firejail/disable-programs.inc
22include /etc/firejail/disable-xdg.inc 22include /etc/firejail/disable-xdg.inc
23 23
24include /etc/firejail/whitelist-var-common.inc
25
24caps.drop all 26caps.drop all
25net none 27net none
26no3d 28no3d
diff --git a/etc/sqlitebrowser.profile b/etc/sqlitebrowser.profile
index 75e8ed5c0..0f030d559 100644
--- a/etc/sqlitebrowser.profile
+++ b/etc/sqlitebrowser.profile
@@ -16,6 +16,8 @@ include /etc/firejail/disable-passwdmgr.inc
16include /etc/firejail/disable-programs.inc 16include /etc/firejail/disable-programs.inc
17include /etc/firejail/disable-xdg.inc 17include /etc/firejail/disable-xdg.inc
18 18
19include /etc/firejail/whitelist-var-common.inc
20
19caps.drop all 21caps.drop all
20net none 22net none
21no3d 23no3d
diff --git a/etc/vlc.profile b/etc/vlc.profile
index 20dafba25..594a5944b 100644
--- a/etc/vlc.profile
+++ b/etc/vlc.profile
@@ -25,7 +25,7 @@ include /etc/firejail/whitelist-var-common.inc
25caps.drop all 25caps.drop all
26netfilter 26netfilter
27#nodbus 27#nodbus
28#nogroups 28nogroups
29nonewprivs 29nonewprivs
30noroot 30noroot
31protocol unix,inet,inet6,netlink 31protocol unix,inet,inet6,netlink
diff --git a/etc/xonotic.profile b/etc/xonotic.profile
index 29b2bb382..a7e8edc0f 100644
--- a/etc/xonotic.profile
+++ b/etc/xonotic.profile
@@ -21,6 +21,7 @@ include /etc/firejail/whitelist-var-common.inc
21 21
22caps.drop all 22caps.drop all
23netfilter 23netfilter
24nodbus
24nodvd 25nodvd
25nogroups 26nogroups
26nonewprivs 27nonewprivs