aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLibravatar Tad <tad@spotco.us>2018-03-17 15:56:06 -0400
committerLibravatar Tad <tad@spotco.us>2018-03-17 15:56:06 -0400
commit68fd00cfe4033a0299c481825373df696b7acdb5 (patch)
tree12024f283fcf8a54dfe7750df69f90b420d1c512
parentMerge branch 'master' of https://github.com/netblue30/firejail (diff)
downloadfirejail-68fd00cfe4033a0299c481825373df696b7acdb5.tar.gz
firejail-68fd00cfe4033a0299c481825373df696b7acdb5.tar.zst
firejail-68fd00cfe4033a0299c481825373df696b7acdb5.zip
Move apparmor option to the top of the options list in all profiles
-rw-r--r--etc/ark.profile2
-rw-r--r--etc/atril.profile2
-rw-r--r--etc/audacious.profile2
-rw-r--r--etc/audacity.profile2
-rw-r--r--etc/chromium-common.profile2
-rw-r--r--etc/digikam.profile2
-rw-r--r--etc/electron.profile2
-rw-r--r--etc/eog.profile2
-rw-r--r--etc/eom.profile2
-rw-r--r--etc/firefox-common.profile2
-rw-r--r--etc/galculator.profile2
-rw-r--r--etc/gimp.profile2
-rw-r--r--etc/gnome-calculator.profile2
-rw-r--r--etc/handbrake.profile2
-rw-r--r--etc/inkscape.profile2
-rw-r--r--etc/kate.profile2
-rw-r--r--etc/kdenlive.profile2
-rw-r--r--etc/kodi.profile2
-rw-r--r--etc/krita.profile2
-rw-r--r--etc/kwrite.profile2
-rw-r--r--etc/libreoffice.profile2
-rw-r--r--etc/mpv.profile2
-rw-r--r--etc/okular.profile2
-rw-r--r--etc/openshot.profile2
-rw-r--r--etc/qbittorrent.profile2
-rw-r--r--etc/rhythmbox.profile2
-rw-r--r--etc/smplayer.profile2
-rw-r--r--etc/totem.profile2
-rw-r--r--etc/transmission-gtk.profile2
-rw-r--r--etc/transmission-qt.profile3
-rw-r--r--etc/vlc.profile2
31 files changed, 31 insertions, 32 deletions
diff --git a/etc/ark.profile b/etc/ark.profile
index f3e366854..beeb652cf 100644
--- a/etc/ark.profile
+++ b/etc/ark.profile
@@ -16,6 +16,7 @@ include /etc/firejail/disable-programs.inc
16 16
17include /etc/firejail/whitelist-var-common.inc 17include /etc/firejail/whitelist-var-common.inc
18 18
19apparmor
19caps.drop all 20caps.drop all
20# net none 21# net none
21netfilter 22netfilter
@@ -29,7 +30,6 @@ novideo
29protocol unix 30protocol unix
30seccomp 31seccomp
31shell none 32shell none
32apparmor
33 33
34private-dev 34private-dev
35private-tmp 35private-tmp
diff --git a/etc/atril.profile b/etc/atril.profile
index 5d8cc54bd..a05f11076 100644
--- a/etc/atril.profile
+++ b/etc/atril.profile
@@ -17,6 +17,7 @@ include /etc/firejail/disable-programs.inc
17 17
18include /etc/firejail/whitelist-var-common.inc 18include /etc/firejail/whitelist-var-common.inc
19 19
20apparmor
20caps.drop all 21caps.drop all
21machine-id 22machine-id
22no3d 23no3d
@@ -31,7 +32,6 @@ protocol unix
31seccomp 32seccomp
32shell none 33shell none
33tracelog 34tracelog
34apparmor
35 35
36private-bin atril, atril-previewer, atril-thumbnailer 36private-bin atril, atril-previewer, atril-thumbnailer
37private-dev 37private-dev
diff --git a/etc/audacious.profile b/etc/audacious.profile
index 818d4455b..93ba5a45d 100644
--- a/etc/audacious.profile
+++ b/etc/audacious.profile
@@ -15,6 +15,7 @@ include /etc/firejail/disable-programs.inc
15 15
16include /etc/firejail/whitelist-var-common.inc 16include /etc/firejail/whitelist-var-common.inc
17 17
18apparmor
18caps.drop all 19caps.drop all
19netfilter 20netfilter
20nogroups 21nogroups
@@ -26,7 +27,6 @@ protocol unix,inet,inet6
26seccomp 27seccomp
27shell none 28shell none
28tracelog 29tracelog
29apparmor
30 30
31# private-bin audacious 31# private-bin audacious
32private-dev 32private-dev
diff --git a/etc/audacity.profile b/etc/audacity.profile
index 3575e297a..8c85dd6be 100644
--- a/etc/audacity.profile
+++ b/etc/audacity.profile
@@ -16,6 +16,7 @@ include /etc/firejail/disable-programs.inc
16 16
17include /etc/firejail/whitelist-var-common.inc 17include /etc/firejail/whitelist-var-common.inc
18 18
19apparmor
19caps.drop all 20caps.drop all
20#net none 21#net none
21no3d 22no3d
@@ -29,7 +30,6 @@ protocol unix
29seccomp 30seccomp
30shell none 31shell none
31tracelog 32tracelog
32apparmor
33 33
34private-bin audacity 34private-bin audacity
35private-dev 35private-dev
diff --git a/etc/chromium-common.profile b/etc/chromium-common.profile
index 0e7e185d0..a11947334 100644
--- a/etc/chromium-common.profile
+++ b/etc/chromium-common.profile
@@ -17,13 +17,13 @@ whitelist ${HOME}/.pki
17include /etc/firejail/whitelist-common.inc 17include /etc/firejail/whitelist-common.inc
18include /etc/firejail/whitelist-var-common.inc 18include /etc/firejail/whitelist-var-common.inc
19 19
20apparmor
20caps.keep sys_chroot,sys_admin 21caps.keep sys_chroot,sys_admin
21netfilter 22netfilter
22nodvd 23nodvd
23nogroups 24nogroups
24notv 25notv
25shell none 26shell none
26apparmor
27 27
28disable-mnt 28disable-mnt
29private-dev 29private-dev
diff --git a/etc/digikam.profile b/etc/digikam.profile
index 179204036..516876c6b 100644
--- a/etc/digikam.profile
+++ b/etc/digikam.profile
@@ -17,6 +17,7 @@ include /etc/firejail/disable-programs.inc
17 17
18include /etc/firejail/whitelist-var-common.inc 18include /etc/firejail/whitelist-var-common.inc
19 19
20apparmor
20caps.drop all 21caps.drop all
21netfilter 22netfilter
22nodvd 23nodvd
@@ -28,7 +29,6 @@ protocol unix,inet,inet6,netlink
28seccomp 29seccomp
29# seccomp.keep fallocate,getrusage,openat,access,arch_prctl,bind,brk,chdir,chmod,clock_getres,clone,close,connect,dup2,dup3,eventfd2,execve,fadvise64,fcntl,fdatasync,flock,fstat,fstatfs,ftruncate,futex,getcwd,getdents,getegid,geteuid,getgid,getpeername,getpgrp,getpid,getppid,getrandom,getresgid,getresuid,getrlimit,getsockname,getsockopt,gettid,getuid,inotify_add_watch,inotify_init,inotify_init1,inotify_rm_watch,ioctl,lseek,lstat,madvise,mbind,memfd_create,mkdir,mmap,mprotect,msync,munmap,nanosleep,open,pipe,pipe2,poll,ppoll,prctl,pread64,pwrite64,read,readlink,readlinkat,recvfrom,recvmsg,rename,rt_sigaction,rt_sigprocmask,rt_sigreturn,sched_getaffinity,sched_getparam,sched_get_priority_max,sched_get_priority_min,sched_getscheduler,sched_setscheduler,sched_yield,sendmsg,sendto,setgid,setresgid,setresuid,set_robust_list,setsid,setsockopt,set_tid_address,setuid,shmat,shmctl,shmdt,shmget,shutdown,socket,stat,statfs,sysinfo,timerfd_create,umask,uname,unlink,wait4,waitid,write,writev,fchmod,fchown,unshare,exit,exit_group 30# seccomp.keep fallocate,getrusage,openat,access,arch_prctl,bind,brk,chdir,chmod,clock_getres,clone,close,connect,dup2,dup3,eventfd2,execve,fadvise64,fcntl,fdatasync,flock,fstat,fstatfs,ftruncate,futex,getcwd,getdents,getegid,geteuid,getgid,getpeername,getpgrp,getpid,getppid,getrandom,getresgid,getresuid,getrlimit,getsockname,getsockopt,gettid,getuid,inotify_add_watch,inotify_init,inotify_init1,inotify_rm_watch,ioctl,lseek,lstat,madvise,mbind,memfd_create,mkdir,mmap,mprotect,msync,munmap,nanosleep,open,pipe,pipe2,poll,ppoll,prctl,pread64,pwrite64,read,readlink,readlinkat,recvfrom,recvmsg,rename,rt_sigaction,rt_sigprocmask,rt_sigreturn,sched_getaffinity,sched_getparam,sched_get_priority_max,sched_get_priority_min,sched_getscheduler,sched_setscheduler,sched_yield,sendmsg,sendto,setgid,setresgid,setresuid,set_robust_list,setsid,setsockopt,set_tid_address,setuid,shmat,shmctl,shmdt,shmget,shutdown,socket,stat,statfs,sysinfo,timerfd_create,umask,uname,unlink,wait4,waitid,write,writev,fchmod,fchown,unshare,exit,exit_group
30shell none 31shell none
31apparmor
32 32
33# private-bin program 33# private-bin program
34# private-dev - prevents libdc1394 loading; this lib is used to connect to a camera device 34# private-dev - prevents libdc1394 loading; this lib is used to connect to a camera device
diff --git a/etc/electron.profile b/etc/electron.profile
index 2ff61914e..222beada0 100644
--- a/etc/electron.profile
+++ b/etc/electron.profile
@@ -11,6 +11,7 @@ include /etc/firejail/disable-programs.inc
11 11
12whitelist ${DOWNLOADS} 12whitelist ${DOWNLOADS}
13 13
14apparmor
14caps.drop all 15caps.drop all
15netfilter 16netfilter
16nodvd 17nodvd
@@ -20,4 +21,3 @@ noroot
20notv 21notv
21protocol unix,inet,inet6,netlink 22protocol unix,inet,inet6,netlink
22seccomp 23seccomp
23apparmor
diff --git a/etc/eog.profile b/etc/eog.profile
index e5302a84f..545a6e432 100644
--- a/etc/eog.profile
+++ b/etc/eog.profile
@@ -19,6 +19,7 @@ include /etc/firejail/disable-programs.inc
19 19
20include /etc/firejail/whitelist-var-common.inc 20include /etc/firejail/whitelist-var-common.inc
21 21
22apparmor
22caps.drop all 23caps.drop all
23# net none - makes settings immutable 24# net none - makes settings immutable
24no3d 25no3d
@@ -32,7 +33,6 @@ novideo
32protocol unix 33protocol unix
33seccomp 34seccomp
34shell none 35shell none
35apparmor
36 36
37private-bin eog 37private-bin eog
38private-dev 38private-dev
diff --git a/etc/eom.profile b/etc/eom.profile
index e5024a2bf..c7c92db0e 100644
--- a/etc/eom.profile
+++ b/etc/eom.profile
@@ -19,6 +19,7 @@ include /etc/firejail/disable-programs.inc
19 19
20include /etc/firejail/whitelist-var-common.inc 20include /etc/firejail/whitelist-var-common.inc
21 21
22apparmor
22caps.drop all 23caps.drop all
23# net none - makes settings immutable 24# net none - makes settings immutable
24no3d 25no3d
@@ -33,7 +34,6 @@ protocol unix
33seccomp 34seccomp
34shell none 35shell none
35tracelog 36tracelog
36apparmor
37 37
38private-bin eom 38private-bin eom
39private-dev 39private-dev
diff --git a/etc/firefox-common.profile b/etc/firefox-common.profile
index 021c9b6a4..12d160155 100644
--- a/etc/firefox-common.profile
+++ b/etc/firefox-common.profile
@@ -20,6 +20,7 @@ whitelist ${HOME}/.pki
20include /etc/firejail/whitelist-common.inc 20include /etc/firejail/whitelist-common.inc
21include /etc/firejail/whitelist-var-common.inc 21include /etc/firejail/whitelist-var-common.inc
22 22
23apparmor
23caps.drop all 24caps.drop all
24# machine-id breaks pulse audio; it should work fine in setups where sound is not required 25# machine-id breaks pulse audio; it should work fine in setups where sound is not required
25#machine-id 26#machine-id
@@ -33,7 +34,6 @@ protocol unix,inet,inet6,netlink
33seccomp 34seccomp
34shell none 35shell none
35tracelog 36tracelog
36apparmor
37 37
38disable-mnt 38disable-mnt
39private-dev 39private-dev
diff --git a/etc/galculator.profile b/etc/galculator.profile
index c851e7038..b28c7943f 100644
--- a/etc/galculator.profile
+++ b/etc/galculator.profile
@@ -19,6 +19,7 @@ whitelist ${HOME}/.config/galculator
19include /etc/firejail/whitelist-common.inc 19include /etc/firejail/whitelist-common.inc
20include /etc/firejail/whitelist-var-common.inc 20include /etc/firejail/whitelist-var-common.inc
21 21
22apparmor
22caps.drop all 23caps.drop all
23net none 24net none
24nodvd 25nodvd
@@ -32,7 +33,6 @@ protocol unix
32seccomp 33seccomp
33shell none 34shell none
34tracelog 35tracelog
35apparmor
36 36
37private-bin galculator 37private-bin galculator
38private-dev 38private-dev
diff --git a/etc/gimp.profile b/etc/gimp.profile
index 1f15677a1..3cc012a88 100644
--- a/etc/gimp.profile
+++ b/etc/gimp.profile
@@ -15,6 +15,7 @@ include /etc/firejail/disable-programs.inc
15 15
16include /etc/firejail/whitelist-var-common.inc 16include /etc/firejail/whitelist-var-common.inc
17 17
18apparmor
18caps.drop all 19caps.drop all
19net none 20net none
20nodvd 21nodvd
@@ -26,7 +27,6 @@ notv
26protocol unix 27protocol unix
27seccomp 28seccomp
28shell none 29shell none
29apparmor
30 30
31private-dev 31private-dev
32private-tmp 32private-tmp
diff --git a/etc/gnome-calculator.profile b/etc/gnome-calculator.profile
index b6fcb0668..d13208a1e 100644
--- a/etc/gnome-calculator.profile
+++ b/etc/gnome-calculator.profile
@@ -14,6 +14,7 @@ include /etc/firejail/disable-programs.inc
14include /etc/firejail/whitelist-common.inc 14include /etc/firejail/whitelist-common.inc
15include /etc/firejail/whitelist-var-common.inc 15include /etc/firejail/whitelist-var-common.inc
16 16
17apparmor
17caps.drop all 18caps.drop all
18netfilter 19netfilter
19no3d 20no3d
@@ -27,7 +28,6 @@ novideo
27protocol unix,inet,inet6 28protocol unix,inet,inet6
28seccomp 29seccomp
29shell none 30shell none
30apparmor
31 31
32disable-mnt 32disable-mnt
33private-bin gnome-calculator 33private-bin gnome-calculator
diff --git a/etc/handbrake.profile b/etc/handbrake.profile
index dd814222b..b99842d60 100644
--- a/etc/handbrake.profile
+++ b/etc/handbrake.profile
@@ -14,6 +14,7 @@ include /etc/firejail/disable-programs.inc
14 14
15include /etc/firejail/whitelist-var-common.inc 15include /etc/firejail/whitelist-var-common.inc
16 16
17apparmor
17caps.drop all 18caps.drop all
18netfilter 19netfilter
19nogroups 20nogroups
@@ -23,7 +24,6 @@ novideo
23protocol unix,inet,inet6,netlink 24protocol unix,inet,inet6,netlink
24seccomp 25seccomp
25shell none 26shell none
26apparmor
27 27
28private-dev 28private-dev
29private-tmp 29private-tmp
diff --git a/etc/inkscape.profile b/etc/inkscape.profile
index 924691743..6e669ea2c 100644
--- a/etc/inkscape.profile
+++ b/etc/inkscape.profile
@@ -16,6 +16,7 @@ include /etc/firejail/disable-programs.inc
16 16
17include /etc/firejail/whitelist-var-common.inc 17include /etc/firejail/whitelist-var-common.inc
18 18
19apparmor
19caps.drop all 20caps.drop all
20netfilter 21netfilter
21nodvd 22nodvd
@@ -28,7 +29,6 @@ novideo
28protocol unix 29protocol unix
29seccomp 30seccomp
30shell none 31shell none
31apparmor
32 32
33# private-bin inkscape,potrace - problems on Debian stretch 33# private-bin inkscape,potrace - problems on Debian stretch
34private-dev 34private-dev
diff --git a/etc/kate.profile b/etc/kate.profile
index d1cfef49b..43f38d7e6 100644
--- a/etc/kate.profile
+++ b/etc/kate.profile
@@ -21,6 +21,7 @@ include /etc/firejail/disable-programs.inc
21 21
22include /etc/firejail/whitelist-var-common.inc 22include /etc/firejail/whitelist-var-common.inc
23 23
24apparmor
24caps.drop all 25caps.drop all
25# net none 26# net none
26netfilter 27netfilter
@@ -35,7 +36,6 @@ protocol unix
35seccomp 36seccomp
36shell none 37shell none
37tracelog 38tracelog
38apparmor
39 39
40# private-bin kate 40# private-bin kate
41private-dev 41private-dev
diff --git a/etc/kdenlive.profile b/etc/kdenlive.profile
index a52cd832f..424ad767e 100644
--- a/etc/kdenlive.profile
+++ b/etc/kdenlive.profile
@@ -15,6 +15,7 @@ include /etc/firejail/disable-devel.inc
15include /etc/firejail/disable-passwdmgr.inc 15include /etc/firejail/disable-passwdmgr.inc
16include /etc/firejail/disable-programs.inc 16include /etc/firejail/disable-programs.inc
17 17
18apparmor
18caps.drop all 19caps.drop all
19# net none 20# net none
20nodvd 21nodvd
@@ -25,7 +26,6 @@ notv
25protocol unix,netlink 26protocol unix,netlink
26seccomp 27seccomp
27shell none 28shell none
28apparmor
29 29
30private-bin kdenlive,kdenlive_render,dbus-launch,melt,ffmpeg,ffplay,ffprobe,dvdauthor,genisoimage,vlc,xine,kdeinit5,kshell5,kdeinit5_shutdown,kdeinit5_wrapper,kdeinit4,kshell4,kdeinit4_shutdown,kdeinit4_wrapper 30private-bin kdenlive,kdenlive_render,dbus-launch,melt,ffmpeg,ffplay,ffprobe,dvdauthor,genisoimage,vlc,xine,kdeinit5,kshell5,kdeinit5_shutdown,kdeinit5_wrapper,kdeinit4,kshell4,kdeinit4_shutdown,kdeinit4_wrapper
31private-dev 31private-dev
diff --git a/etc/kodi.profile b/etc/kodi.profile
index 4eb2c9df1..dfe019641 100644
--- a/etc/kodi.profile
+++ b/etc/kodi.profile
@@ -12,6 +12,7 @@ include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-passwdmgr.inc 12include /etc/firejail/disable-passwdmgr.inc
13include /etc/firejail/disable-programs.inc 13include /etc/firejail/disable-programs.inc
14 14
15apparmor
15caps.drop all 16caps.drop all
16netfilter 17netfilter
17nogroups 18nogroups
@@ -21,7 +22,6 @@ protocol unix,inet,inet6,netlink
21seccomp 22seccomp
22shell none 23shell none
23tracelog 24tracelog
24apparmor
25 25
26private-dev 26private-dev
27private-tmp 27private-tmp
diff --git a/etc/krita.profile b/etc/krita.profile
index 9fddf2214..0f4c5210b 100644
--- a/etc/krita.profile
+++ b/etc/krita.profile
@@ -14,6 +14,7 @@ include /etc/firejail/disable-devel.inc
14include /etc/firejail/disable-passwdmgr.inc 14include /etc/firejail/disable-passwdmgr.inc
15include /etc/firejail/disable-programs.inc 15include /etc/firejail/disable-programs.inc
16 16
17apparmor
17caps.drop all 18caps.drop all
18ipc-namespace 19ipc-namespace
19# net none 20# net none
@@ -27,7 +28,6 @@ novideo
27protocol unix 28protocol unix
28seccomp 29seccomp
29shell none 30shell none
30apparmor
31 31
32private-dev 32private-dev
33private-tmp 33private-tmp
diff --git a/etc/kwrite.profile b/etc/kwrite.profile
index 386ef142c..6e8e33cb3 100644
--- a/etc/kwrite.profile
+++ b/etc/kwrite.profile
@@ -22,6 +22,7 @@ include /etc/firejail/disable-programs.inc
22 22
23include /etc/firejail/whitelist-var-common.inc 23include /etc/firejail/whitelist-var-common.inc
24 24
25apparmor
25caps.drop all 26caps.drop all
26# net none 27# net none
27netfilter 28netfilter
@@ -36,7 +37,6 @@ protocol unix
36seccomp 37seccomp
37shell none 38shell none
38tracelog 39tracelog
39apparmor
40 40
41private-bin kwrite,kbuildsycoca4,kdeinit4 41private-bin kwrite,kbuildsycoca4,kdeinit4
42private-dev 42private-dev
diff --git a/etc/libreoffice.profile b/etc/libreoffice.profile
index a67fafa30..8b801f11e 100644
--- a/etc/libreoffice.profile
+++ b/etc/libreoffice.profile
@@ -16,6 +16,7 @@ include /etc/firejail/disable-programs.inc
16 16
17include /etc/firejail/whitelist-var-common.inc 17include /etc/firejail/whitelist-var-common.inc
18 18
19apparmor
19caps.drop all 20caps.drop all
20machine-id 21machine-id
21netfilter 22netfilter
@@ -28,7 +29,6 @@ protocol unix,inet,inet6
28seccomp 29seccomp
29shell none 30shell none
30tracelog 31tracelog
31apparmor
32 32
33private-dev 33private-dev
34private-tmp 34private-tmp
diff --git a/etc/mpv.profile b/etc/mpv.profile
index e864d5d45..a4dc679f4 100644
--- a/etc/mpv.profile
+++ b/etc/mpv.profile
@@ -15,6 +15,7 @@ include /etc/firejail/disable-programs.inc
15 15
16include /etc/firejail/whitelist-var-common.inc 16include /etc/firejail/whitelist-var-common.inc
17 17
18apparmor
18caps.drop all 19caps.drop all
19netfilter 20netfilter
20nogroups 21nogroups
@@ -24,7 +25,6 @@ protocol unix,inet,inet6
24seccomp 25seccomp
25shell none 26shell none
26tracelog 27tracelog
27apparmor
28 28
29private-bin mpv,youtube-dl,python*,env 29private-bin mpv,youtube-dl,python*,env
30private-dev 30private-dev
diff --git a/etc/okular.profile b/etc/okular.profile
index 016316b29..ffe0d2bfb 100644
--- a/etc/okular.profile
+++ b/etc/okular.profile
@@ -25,6 +25,7 @@ include /etc/firejail/disable-programs.inc
25 25
26include /etc/firejail/whitelist-var-common.inc 26include /etc/firejail/whitelist-var-common.inc
27 27
28apparmor
28caps.drop all 29caps.drop all
29machine-id 30machine-id
30# net none 31# net none
@@ -40,7 +41,6 @@ protocol unix
40seccomp 41seccomp
41shell none 42shell none
42tracelog 43tracelog
43apparmor
44 44
45private-bin okular,kbuildsycoca4,kdeinit4,lpr 45private-bin okular,kbuildsycoca4,kdeinit4,lpr
46private-dev 46private-dev
diff --git a/etc/openshot.profile b/etc/openshot.profile
index 5d81df193..ca9110be6 100644
--- a/etc/openshot.profile
+++ b/etc/openshot.profile
@@ -15,6 +15,7 @@ include /etc/firejail/disable-programs.inc
15 15
16include /etc/firejail/whitelist-var-common.inc 16include /etc/firejail/whitelist-var-common.inc
17 17
18apparmor
18caps.drop all 19caps.drop all
19netfilter 20netfilter
20nodvd 21nodvd
@@ -25,7 +26,6 @@ notv
25protocol unix,inet,inet6,netlink 26protocol unix,inet,inet6,netlink
26seccomp 27seccomp
27shell none 28shell none
28apparmor
29 29
30private-dev 30private-dev
31private-tmp 31private-tmp
diff --git a/etc/qbittorrent.profile b/etc/qbittorrent.profile
index 60bcc73d2..8df8177eb 100644
--- a/etc/qbittorrent.profile
+++ b/etc/qbittorrent.profile
@@ -26,6 +26,7 @@ whitelist ${HOME}/.local/share/data/qBittorrent
26include /etc/firejail/whitelist-common.inc 26include /etc/firejail/whitelist-common.inc
27include /etc/firejail/whitelist-var-common.inc 27include /etc/firejail/whitelist-var-common.inc
28 28
29apparmor
29caps.drop all 30caps.drop all
30machine-id 31machine-id
31netfilter 32netfilter
@@ -39,7 +40,6 @@ novideo
39protocol unix,inet,inet6,netlink 40protocol unix,inet,inet6,netlink
40seccomp 41seccomp
41shell none 42shell none
42apparmor
43 43
44private-bin qbittorrent,python* 44private-bin qbittorrent,python*
45private-dev 45private-dev
diff --git a/etc/rhythmbox.profile b/etc/rhythmbox.profile
index b6f16cecf..a20bdb883 100644
--- a/etc/rhythmbox.profile
+++ b/etc/rhythmbox.profile
@@ -13,6 +13,7 @@ include /etc/firejail/disable-programs.inc
13 13
14include /etc/firejail/whitelist-var-common.inc 14include /etc/firejail/whitelist-var-common.inc
15 15
16apparmor
16caps.drop all 17caps.drop all
17netfilter 18netfilter
18# no3d 19# no3d
@@ -25,7 +26,6 @@ protocol unix,inet,inet6
25seccomp 26seccomp
26shell none 27shell none
27tracelog 28tracelog
28apparmor
29 29
30private-bin rhythmbox 30private-bin rhythmbox
31private-dev 31private-dev
diff --git a/etc/smplayer.profile b/etc/smplayer.profile
index d0180e185..64eff5670 100644
--- a/etc/smplayer.profile
+++ b/etc/smplayer.profile
@@ -15,6 +15,7 @@ include /etc/firejail/disable-programs.inc
15 15
16include /etc/firejail/whitelist-var-common.inc 16include /etc/firejail/whitelist-var-common.inc
17 17
18apparmor
18caps.drop all 19caps.drop all
19netfilter 20netfilter
20# nogroups 21# nogroups
@@ -23,7 +24,6 @@ noroot
23protocol unix,inet,inet6,netlink 24protocol unix,inet,inet6,netlink
24seccomp 25seccomp
25shell none 26shell none
26apparmor
27 27
28private-bin smplayer,smtube,mplayer,mpv 28private-bin smplayer,smtube,mplayer,mpv
29private-dev 29private-dev
diff --git a/etc/totem.profile b/etc/totem.profile
index 2b591cc69..6dbc5f0c2 100644
--- a/etc/totem.profile
+++ b/etc/totem.profile
@@ -15,6 +15,7 @@ include /etc/firejail/disable-programs.inc
15 15
16include /etc/firejail/whitelist-var-common.inc 16include /etc/firejail/whitelist-var-common.inc
17 17
18apparmor
18caps.drop all 19caps.drop all
19netfilter 20netfilter
20nogroups 21nogroups
@@ -23,7 +24,6 @@ noroot
23protocol unix,inet,inet6 24protocol unix,inet,inet6
24seccomp 25seccomp
25shell none 26shell none
26apparmor
27 27
28private-bin totem 28private-bin totem
29private-dev 29private-dev
diff --git a/etc/transmission-gtk.profile b/etc/transmission-gtk.profile
index d67bda4cc..3d249748d 100644
--- a/etc/transmission-gtk.profile
+++ b/etc/transmission-gtk.profile
@@ -21,6 +21,7 @@ whitelist ${HOME}/.config/transmission
21include /etc/firejail/whitelist-common.inc 21include /etc/firejail/whitelist-common.inc
22include /etc/firejail/whitelist-var-common.inc 22include /etc/firejail/whitelist-var-common.inc
23 23
24apparmor
24caps.drop all 25caps.drop all
25machine-id 26machine-id
26netfilter 27netfilter
@@ -34,7 +35,6 @@ protocol unix,inet,inet6
34seccomp 35seccomp
35shell none 36shell none
36tracelog 37tracelog
37apparmor
38 38
39private-bin transmission-gtk 39private-bin transmission-gtk
40private-dev 40private-dev
diff --git a/etc/transmission-qt.profile b/etc/transmission-qt.profile
index f2bfd1ff6..4f4d9bac1 100644
--- a/etc/transmission-qt.profile
+++ b/etc/transmission-qt.profile
@@ -21,6 +21,7 @@ whitelist ${HOME}/.config/transmission
21include /etc/firejail/whitelist-common.inc 21include /etc/firejail/whitelist-common.inc
22include /etc/firejail/whitelist-var-common.inc 22include /etc/firejail/whitelist-var-common.inc
23 23
24apparmor
24caps.drop all 25caps.drop all
25machine-id 26machine-id
26netfilter 27netfilter
@@ -34,7 +35,6 @@ protocol unix,inet,inet6
34seccomp 35seccomp
35shell none 36shell none
36tracelog 37tracelog
37apparmor
38 38
39private-bin transmission-qt 39private-bin transmission-qt
40private-dev 40private-dev
@@ -42,4 +42,3 @@ private-dev
42private-tmp 42private-tmp
43 43
44# memory-deny-write-execute - problems on Qt 5.10.0, KDE Frameworks 5.41.0 44# memory-deny-write-execute - problems on Qt 5.10.0, KDE Frameworks 5.41.0
45
diff --git a/etc/vlc.profile b/etc/vlc.profile
index c244be08b..dad9a9ae1 100644
--- a/etc/vlc.profile
+++ b/etc/vlc.profile
@@ -15,6 +15,7 @@ include /etc/firejail/disable-programs.inc
15 15
16include /etc/firejail/whitelist-var-common.inc 16include /etc/firejail/whitelist-var-common.inc
17 17
18apparmor
18caps.drop all 19caps.drop all
19netfilter 20netfilter
20# nogroups 21# nogroups
@@ -23,7 +24,6 @@ noroot
23protocol unix,inet,inet6,netlink 24protocol unix,inet,inet6,netlink
24seccomp 25seccomp
25shell none 26shell none
26apparmor
27 27
28private-bin vlc,cvlc,nvlc,rvlc,qvlc,svlc 28private-bin vlc,cvlc,nvlc,rvlc,qvlc,svlc
29private-dev 29private-dev