aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLibravatar Tad <tad@spotco.us>2017-08-13 15:49:50 -0400
committerLibravatar Tad <tad@spotco.us>2017-08-13 15:53:04 -0400
commit104dde49c0744b73ce795b9a4086607232a18305 (patch)
tree1b67dd83bb2bf6a8a208f485e9cc39061bde74bf
parentFix copy-paste (diff)
downloadfirejail-104dde49c0744b73ce795b9a4086607232a18305.tar.gz
firejail-104dde49c0744b73ce795b9a4086607232a18305.tar.zst
firejail-104dde49c0744b73ce795b9a4086607232a18305.zip
Fix nodvd placement
-rw-r--r--etc/0ad.profile2
-rw-r--r--etc/2048-qt.profile2
-rw-r--r--etc/7z.profile2
-rw-r--r--etc/Cryptocat.profile2
-rw-r--r--etc/Mathematica.profile2
-rw-r--r--etc/Thunar.profile2
-rw-r--r--etc/Xephyr.profile2
-rw-r--r--etc/Xvfb.profile2
-rw-r--r--etc/abrowser.profile2
-rw-r--r--etc/akregator.profile2
-rw-r--r--etc/android-studio.profile2
-rw-r--r--etc/apktool.profile2
-rw-r--r--etc/arduino.profile2
-rw-r--r--etc/ark.profile2
-rw-r--r--etc/arm.profile2
-rw-r--r--etc/atom-beta.profile2
-rw-r--r--etc/atom.profile2
-rw-r--r--etc/atool.profile2
-rw-r--r--etc/atril.profile2
-rw-r--r--etc/audacity.profile2
-rw-r--r--etc/aweather.profile2
-rw-r--r--etc/baloo_file.profile2
-rw-r--r--etc/baobab.profile2
-rw-r--r--etc/bibletime.profile2
-rw-r--r--etc/bitlbee.profile2
-rw-r--r--etc/bleachbit.profile2
-rw-r--r--etc/blender.profile2
-rw-r--r--etc/bless.profile2
-rw-r--r--etc/brave.profile2
-rw-r--r--etc/caja.profile2
-rw-r--r--etc/calibre.profile2
-rw-r--r--etc/catfish.profile2
-rw-r--r--etc/cherrytree.profile2
-rw-r--r--etc/chromium.profile2
-rw-r--r--etc/claws-mail.profile2
-rw-r--r--etc/clipit.profile2
-rw-r--r--etc/conkeror.profile2
-rw-r--r--etc/corebird.profile2
-rw-r--r--etc/cpio.profile2
-rw-r--r--etc/curl.profile2
-rw-r--r--etc/cvlc.profile2
-rw-r--r--etc/cyberfox.profile2
-rw-r--r--etc/darktable.profile2
-rw-r--r--etc/deluge.profile2
-rw-r--r--etc/dex2jar.profile2
-rw-r--r--etc/dia.profile2
-rw-r--r--etc/digikam.profile2
-rw-r--r--etc/dillo.profile2
-rw-r--r--etc/dino.profile2
-rw-r--r--etc/display.profile2
-rw-r--r--etc/dnscrypt-proxy.profile2
-rw-r--r--etc/dnsmasq.profile2
-rw-r--r--etc/dolphin.profile2
-rw-r--r--etc/dosbox.profile2
-rw-r--r--etc/dragon.profile2
-rw-r--r--etc/dropbox.profile2
-rw-r--r--etc/electron.profile2
-rw-r--r--etc/elinks.profile2
-rw-r--r--etc/emacs.profile2
-rw-r--r--etc/empathy.profile2
-rw-r--r--etc/enchant.profile2
-rw-r--r--etc/engrampa.profile2
-rw-r--r--etc/eog.profile2
-rw-r--r--etc/eom.profile2
-rw-r--r--etc/epiphany.profile2
-rw-r--r--etc/etr.profile2
-rw-r--r--etc/evince.profile2
-rw-r--r--etc/evolution.profile2
-rw-r--r--etc/exiftool.profile2
-rw-r--r--etc/fbreader.profile2
-rw-r--r--etc/feh.profile2
-rw-r--r--etc/file-roller.profile2
-rw-r--r--etc/file.profile2
-rw-r--r--etc/filezilla.profile2
-rw-r--r--etc/firefox.profile2
-rw-r--r--etc/flashpeak-slimjet.profile2
-rw-r--r--etc/flowblade.profile2
-rw-r--r--etc/fontforge.profile2
-rw-r--r--etc/fossamail.profile2
-rw-r--r--etc/franz.profile2
-rw-r--r--etc/frozen-bubble.profile2
-rw-r--r--etc/gajim.profile2
-rw-r--r--etc/galculator.profile2
-rw-r--r--etc/geany.profile2
-rw-r--r--etc/gedit.profile2
-rw-r--r--etc/geeqie.profile2
-rw-r--r--etc/gimp.profile2
-rw-r--r--etc/git.profile2
-rw-r--r--etc/gitg.profile2
-rw-r--r--etc/gitter.profile2
-rw-r--r--etc/gjs.profile2
-rw-r--r--etc/globaltime.profile2
-rw-r--r--etc/gnome-2048.profile2
-rw-r--r--etc/gnome-books.profile2
-rw-r--r--etc/gnome-calculator.profile2
-rw-r--r--etc/gnome-chess.profile2
-rw-r--r--etc/gnome-clocks.profile2
-rw-r--r--etc/gnome-contacts.profile2
-rw-r--r--etc/gnome-documents.profile2
-rw-r--r--etc/gnome-font-viewer.profile2
-rw-r--r--etc/gnome-maps.profile2
-rw-r--r--etc/gnome-photos.profile2
-rw-r--r--etc/gnome-twitch.profile2
-rw-r--r--etc/gnome-weather.profile2
-rw-r--r--etc/goobox.profile2
-rw-r--r--etc/google-chrome-beta.profile2
-rw-r--r--etc/google-chrome-unstable.profile2
-rw-r--r--etc/google-chrome.profile2
-rw-r--r--etc/google-play-music-desktop-player.profile2
-rw-r--r--etc/gpa.profile2
-rw-r--r--etc/gpg-agent.profile2
-rw-r--r--etc/gpg.profile2
-rw-r--r--etc/gpicview.profile2
-rw-r--r--etc/gpredict.profile2
-rw-r--r--etc/gthumb.profile2
-rw-r--r--etc/gucharmap.profile2
-rw-r--r--etc/gwenview.profile2
-rw-r--r--etc/gzip.profile2
-rw-r--r--etc/hashcat.profile2
-rw-r--r--etc/hedgewars.profile2
-rw-r--r--etc/hexchat.profile2
-rw-r--r--etc/highlight.profile2
-rw-r--r--etc/hugin.profile2
-rw-r--r--etc/icecat.profile2
-rw-r--r--etc/idea.sh.profile2
-rw-r--r--etc/img2txt.profile2
-rw-r--r--etc/inkscape.profile2
-rw-r--r--etc/inox.profile2
-rw-r--r--etc/iridium.profile2
-rw-r--r--etc/jd-gui.profile2
-rw-r--r--etc/jitsi.profile2
-rw-r--r--etc/k3b.profile2
-rw-r--r--etc/kate.profile2
-rw-r--r--etc/kcalc.profile2
-rw-r--r--etc/keepass.profile2
-rw-r--r--etc/keepassx.profile2
-rw-r--r--etc/keepassx2.profile2
-rw-r--r--etc/keepassxc.profile2
-rw-r--r--etc/kmail.profile2
-rw-r--r--etc/knotes.profile2
-rw-r--r--etc/konversation.profile2
-rw-r--r--etc/ktorrent.profile2
-rw-r--r--etc/kwrite.profile2
-rw-r--r--etc/leafpad.profile2
-rw-r--r--etc/less.profile2
-rw-r--r--etc/libreoffice.profile2
-rw-r--r--etc/liferea.profile2
-rw-r--r--etc/luminance-hdr.profile2
-rw-r--r--etc/lximage-qt.profile2
-rw-r--r--etc/lxmusic.profile2
-rw-r--r--etc/lxterminal.profile2
-rw-r--r--etc/lynx.profile2
-rw-r--r--etc/mate-calc.profile2
-rw-r--r--etc/mate-color-select.profile2
-rw-r--r--etc/mate-dictionary.profile2
-rw-r--r--etc/mcabber.profile2
-rw-r--r--etc/mediainfo.profile2
-rw-r--r--etc/mediathekview.profile2
-rw-r--r--etc/meld.profile2
-rw-r--r--etc/midori.profile2
-rw-r--r--etc/mousepad.profile2
-rw-r--r--etc/multimc5.profile2
-rw-r--r--etc/mumble.profile2
-rw-r--r--etc/mupdf.profile2
-rw-r--r--etc/mupen64plus.profile2
-rw-r--r--etc/mutt.profile2
-rw-r--r--etc/nautilus.profile2
-rw-r--r--etc/nemo.profile2
-rw-r--r--etc/netsurf.profile2
-rw-r--r--etc/nylas.profile2
-rw-r--r--etc/obs.profile2
-rw-r--r--etc/odt2txt.profile2
-rw-r--r--etc/okular.profile2
-rw-r--r--etc/open-invaders.profile2
-rw-r--r--etc/openshot.profile2
-rw-r--r--etc/opera-beta.profile2
-rw-r--r--etc/opera.profile2
-rw-r--r--etc/orage.profile2
-rw-r--r--etc/palemoon.profile2
-rw-r--r--etc/parole.profile2
-rw-r--r--etc/pcmanfm.profile2
-rw-r--r--etc/pdfsam.profile2
-rw-r--r--etc/pdftotext.profile2
-rw-r--r--etc/peek.profile2
-rw-r--r--etc/picard.profile2
-rw-r--r--etc/pidgin.profile2
-rw-r--r--etc/pingus.profile2
-rw-r--r--etc/pithos.profile2
-rw-r--r--etc/pix.profile2
-rw-r--r--etc/pluma.profile2
-rw-r--r--etc/polari.profile2
-rw-r--r--etc/psi-plus.profile2
-rw-r--r--etc/qbittorrent.profile2
-rw-r--r--etc/qemu-launcher.profile2
-rw-r--r--etc/qemu-system-x86_64.profile2
-rw-r--r--etc/qlipper.profile2
-rw-r--r--etc/qpdfview.profile2
-rw-r--r--etc/qtox.profile2
-rw-r--r--etc/quassel.profile2
-rw-r--r--etc/quiterss.profile2
-rw-r--r--etc/qupzilla.profile2
-rw-r--r--etc/qutebrowser.profile2
-rw-r--r--etc/rambox.profile2
-rw-r--r--etc/ranger.profile2
-rw-r--r--etc/remmina.profile2
-rw-r--r--etc/ristretto.profile2
-rw-r--r--etc/rtorrent.profile2
-rw-r--r--etc/scribus.profile2
-rw-r--r--etc/sdat2img.profile2
-rw-r--r--etc/seamonkey.profile2
-rw-r--r--etc/server.profile2
-rw-r--r--etc/silentarmy.profile2
-rw-r--r--etc/simple-scan.profile2
-rw-r--r--etc/simutrans.profile2
-rw-r--r--etc/skanlite.profile2
-rw-r--r--etc/skype.profile2
-rw-r--r--etc/skypeforlinux.profile2
-rw-r--r--etc/slack.profile2
-rw-r--r--etc/snap.profile2
-rw-r--r--etc/soundconverter.profile2
-rw-r--r--etc/sqlitebrowser.profile2
-rw-r--r--etc/ssh-agent.profile2
-rw-r--r--etc/ssh.profile2
-rw-r--r--etc/start-tor-browser.profile2
-rw-r--r--etc/steam.profile2
-rw-r--r--etc/stellarium.profile2
-rw-r--r--etc/strings.profile2
-rw-r--r--etc/supertux2.profile2
-rw-r--r--etc/synfigstudio.profile2
-rw-r--r--etc/tar.profile2
-rw-r--r--etc/telegram.profile2
-rw-r--r--etc/tracker.profile2
-rw-r--r--etc/transmission-cli.profile2
-rw-r--r--etc/transmission-gtk.profile2
-rw-r--r--etc/transmission-qt.profile2
-rw-r--r--etc/transmission-show.profile2
-rw-r--r--etc/truecraft.profile2
-rw-r--r--etc/tuxguitar.profile2
-rw-r--r--etc/uget-gtk.profile2
-rw-r--r--etc/unbound.profile2
-rw-r--r--etc/unknown-horizons.profile2
-rw-r--r--etc/unrar.profile2
-rw-r--r--etc/unzip.profile2
-rw-r--r--etc/uudeview.profile2
-rw-r--r--etc/uzbl-browser.profile2
-rw-r--r--etc/viewnior.profile2
-rw-r--r--etc/viking.profile2
-rw-r--r--etc/vim.profile2
-rw-r--r--etc/virtualbox.profile2
-rw-r--r--etc/vivaldi.profile2
-rw-r--r--etc/vym.profile2
-rw-r--r--etc/w3m.profile2
-rw-r--r--etc/warzone2100.profile2
-rw-r--r--etc/waterfox.profile2
-rw-r--r--etc/weechat.profile2
-rw-r--r--etc/wesnoth.profile2
-rw-r--r--etc/wget.profile2
-rw-r--r--etc/wine.profile2
-rw-r--r--etc/wire.profile2
-rw-r--r--etc/wireshark.profile2
-rw-r--r--etc/xchat.profile2
-rw-r--r--etc/xed.profile2
-rw-r--r--etc/xfburn.profile2
-rw-r--r--etc/xfce4-dict.profile2
-rw-r--r--etc/xfce4-notes.profile2
-rw-r--r--etc/xiphos.profile2
-rw-r--r--etc/xonotic.profile2
-rw-r--r--etc/xpdf.profile2
-rw-r--r--etc/xpra.profile2
-rw-r--r--etc/xreader.profile2
-rw-r--r--etc/xviewer.profile2
-rw-r--r--etc/xzdec.profile2
-rw-r--r--etc/youtube-dl.profile2
-rw-r--r--etc/zathura.profile2
-rw-r--r--etc/zoom.profile2
275 files changed, 275 insertions, 275 deletions
diff --git a/etc/0ad.profile b/etc/0ad.profile
index 5ee386268..9ca9834a8 100644
--- a/etc/0ad.profile
+++ b/etc/0ad.profile
@@ -24,6 +24,7 @@ include /etc/firejail/whitelist-common.inc
24 24
25caps.drop all 25caps.drop all
26netfilter 26netfilter
27nodvd
27nogroups 28nogroups
28nonewprivs 29nonewprivs
29noroot 30noroot
@@ -40,4 +41,3 @@ private-tmp
40 41
41noexec ${HOME} 42noexec ${HOME}
42noexec /tmp 43noexec /tmp
43nodvd
diff --git a/etc/2048-qt.profile b/etc/2048-qt.profile
index e235bd51e..06cc69503 100644
--- a/etc/2048-qt.profile
+++ b/etc/2048-qt.profile
@@ -15,6 +15,7 @@ include /etc/firejail/disable-programs.inc
15 15
16caps.drop all 16caps.drop all
17netfilter 17netfilter
18nodvd
18nogroups 19nogroups
19nonewprivs 20nonewprivs
20noroot 21noroot
@@ -31,4 +32,3 @@ private-tmp
31 32
32noexec ${HOME} 33noexec ${HOME}
33noexec /tmp 34noexec /tmp
34nodvd
diff --git a/etc/7z.profile b/etc/7z.profile
index 4357cbcd1..ea67bbe19 100644
--- a/etc/7z.profile
+++ b/etc/7z.profile
@@ -11,6 +11,7 @@ blacklist /tmp/.X11-unix
11ignore noroot 11ignore noroot
12net none 12net none
13no3d 13no3d
14nodvd
14nosound 15nosound
15notv 16notv
16novideo 17novideo
@@ -20,4 +21,3 @@ tracelog
20private-dev 21private-dev
21 22
22include /etc/firejail/default.profile 23include /etc/firejail/default.profile
23nodvd
diff --git a/etc/Cryptocat.profile b/etc/Cryptocat.profile
index 261fe1373..add122a5e 100644
--- a/etc/Cryptocat.profile
+++ b/etc/Cryptocat.profile
@@ -14,6 +14,7 @@ include /etc/firejail/disable-programs.inc
14 14
15caps.drop all 15caps.drop all
16netfilter 16netfilter
17nodvd
17nogroups 18nogroups
18nonewprivs 19nonewprivs
19noroot 20noroot
@@ -25,4 +26,3 @@ shell none
25 26
26private-dev 27private-dev
27private-tmp 28private-tmp
28nodvd
diff --git a/etc/Mathematica.profile b/etc/Mathematica.profile
index b92851c0b..924f74389 100644
--- a/etc/Mathematica.profile
+++ b/etc/Mathematica.profile
@@ -21,8 +21,8 @@ whitelist ~/Documents/Wolfram Mathematica
21include /etc/firejail/whitelist-common.inc 21include /etc/firejail/whitelist-common.inc
22 22
23caps.drop all 23caps.drop all
24nodvd
24nonewprivs 25nonewprivs
25noroot 26noroot
26notv 27notv
27seccomp 28seccomp
28nodvd
diff --git a/etc/Thunar.profile b/etc/Thunar.profile
index 74146d6e3..f4a5c9f54 100644
--- a/etc/Thunar.profile
+++ b/etc/Thunar.profile
@@ -17,6 +17,7 @@ include /etc/firejail/disable-passwdmgr.inc
17caps.drop all 17caps.drop all
18netfilter 18netfilter
19no3d 19no3d
20nodvd
20nogroups 21nogroups
21nonewprivs 22nonewprivs
22noroot 23noroot
@@ -27,4 +28,3 @@ protocol unix
27seccomp 28seccomp
28shell none 29shell none
29tracelog 30tracelog
30nodvd
diff --git a/etc/Xephyr.profile b/etc/Xephyr.profile
index 9c533437b..c0c322b67 100644
--- a/etc/Xephyr.profile
+++ b/etc/Xephyr.profile
@@ -22,6 +22,7 @@ include /etc/firejail/whitelist-common.inc
22 22
23caps.drop all 23caps.drop all
24# Xephyr needs to be allowed access to the abstract Unix socket namespace. 24# Xephyr needs to be allowed access to the abstract Unix socket namespace.
25nodvd
25nogroups 26nogroups
26nonewprivs 27nonewprivs
27# In noroot mode, Xephyr cannot create a socket in the real /tmp/.X11-unix. 28# In noroot mode, Xephyr cannot create a socket in the real /tmp/.X11-unix.
@@ -39,4 +40,3 @@ private
39private-dev 40private-dev
40# private-etc ld.so.conf,ld.so.cache,resolv.conf,host.conf,nsswitch.conf,gai.conf,hosts,hostname 41# private-etc ld.so.conf,ld.so.cache,resolv.conf,host.conf,nsswitch.conf,gai.conf,hosts,hostname
41private-tmp 42private-tmp
42nodvd
diff --git a/etc/Xvfb.profile b/etc/Xvfb.profile
index 69420c3a8..7921e0d06 100644
--- a/etc/Xvfb.profile
+++ b/etc/Xvfb.profile
@@ -23,6 +23,7 @@ include /etc/firejail/whitelist-common.inc
23 23
24caps.drop all 24caps.drop all
25# Xvfb needs to be allowed access to the abstract Unix socket namespace. 25# Xvfb needs to be allowed access to the abstract Unix socket namespace.
26nodvd
26nogroups 27nogroups
27nonewprivs 28nonewprivs
28# In noroot mode, Xvfb cannot create a socket in the real /tmp/.X11-unix. 29# In noroot mode, Xvfb cannot create a socket in the real /tmp/.X11-unix.
@@ -40,4 +41,3 @@ private
40private-dev 41private-dev
41private-etc ld.so.conf,ld.so.cache,resolv.conf,host.conf,nsswitch.conf,gai.conf,hosts,hostname 42private-etc ld.so.conf,ld.so.cache,resolv.conf,host.conf,nsswitch.conf,gai.conf,hosts,hostname
42private-tmp 43private-tmp
43nodvd
diff --git a/etc/abrowser.profile b/etc/abrowser.profile
index e31b422c5..3251ef8aa 100644
--- a/etc/abrowser.profile
+++ b/etc/abrowser.profile
@@ -37,6 +37,7 @@ include /etc/firejail/whitelist-common.inc
37 37
38caps.drop all 38caps.drop all
39netfilter 39netfilter
40nodvd
40nonewprivs 41nonewprivs
41noroot 42noroot
42notv 43notv
@@ -45,4 +46,3 @@ seccomp
45tracelog 46tracelog
46 47
47# private-etc passwd,group,hostname,hosts,localtime,nsswitch.conf,resolv.conf,gtk-2.0,pango,fonts,iceweasel,firefox,adobe,mime.types,mailcap,asound.conf,pulse 48# private-etc passwd,group,hostname,hosts,localtime,nsswitch.conf,resolv.conf,gtk-2.0,pango,fonts,iceweasel,firefox,adobe,mime.types,mailcap,asound.conf,pulse
48nodvd
diff --git a/etc/akregator.profile b/etc/akregator.profile
index d47ce4df0..12bb06fb5 100644
--- a/etc/akregator.profile
+++ b/etc/akregator.profile
@@ -16,6 +16,7 @@ include /etc/firejail/disable-programs.inc
16caps.drop all 16caps.drop all
17netfilter 17netfilter
18no3d 18no3d
19nodvd
19nogroups 20nogroups
20nonewprivs 21nonewprivs
21noroot 22noroot
@@ -31,4 +32,3 @@ private-tmp
31 32
32noexec ${HOME} 33noexec ${HOME}
33noexec /tmp 34noexec /tmp
34nodvd
diff --git a/etc/android-studio.profile b/etc/android-studio.profile
index 07d67c639..1e1953780 100644
--- a/etc/android-studio.profile
+++ b/etc/android-studio.profile
@@ -20,6 +20,7 @@ include /etc/firejail/disable-programs.inc
20 20
21caps.drop all 21caps.drop all
22netfilter 22netfilter
23nodvd
23nogroups 24nogroups
24nonewprivs 25nonewprivs
25noroot 26noroot
@@ -33,4 +34,3 @@ private-dev
33# private-tmp 34# private-tmp
34 35
35noexec /tmp 36noexec /tmp
36nodvd
diff --git a/etc/apktool.profile b/etc/apktool.profile
index 58854df3b..b4ff45c7c 100644
--- a/etc/apktool.profile
+++ b/etc/apktool.profile
@@ -14,6 +14,7 @@ include /etc/firejail/disable-programs.inc
14caps.drop all 14caps.drop all
15net none 15net none
16no3d 16no3d
17nodvd
17nogroups 18nogroups
18nonewprivs 19nonewprivs
19noroot 20noroot
@@ -28,4 +29,3 @@ private-dev
28 29
29noexec ${HOME} 30noexec ${HOME}
30noexec /tmp 31noexec /tmp
31nodvd
diff --git a/etc/arduino.profile b/etc/arduino.profile
index d1938c01a..b529ec266 100644
--- a/etc/arduino.profile
+++ b/etc/arduino.profile
@@ -17,6 +17,7 @@ include /etc/firejail/disable-programs.inc
17caps.drop all 17caps.drop all
18netfilter 18netfilter
19no3d 19no3d
20nodvd
20nogroups 21nogroups
21nonewprivs 22nonewprivs
22noroot 23noroot
@@ -31,4 +32,3 @@ private-tmp
31 32
32noexec ${HOME} 33noexec ${HOME}
33noexec /tmp 34noexec /tmp
34nodvd
diff --git a/etc/ark.profile b/etc/ark.profile
index 2ac7089fb..2ed25a4e6 100644
--- a/etc/ark.profile
+++ b/etc/ark.profile
@@ -14,6 +14,7 @@ include /etc/firejail/disable-programs.inc
14 14
15caps.drop all 15caps.drop all
16netfilter 16netfilter
17nodvd
17nogroups 18nogroups
18nonewprivs 19nonewprivs
19noroot 20noroot
@@ -28,4 +29,3 @@ shell none
28private-dev 29private-dev
29# private-etc 30# private-etc
30private-tmp 31private-tmp
31nodvd
diff --git a/etc/arm.profile b/etc/arm.profile
index a75130e4d..5845958fa 100644
--- a/etc/arm.profile
+++ b/etc/arm.profile
@@ -20,6 +20,7 @@ caps.drop all
20ipc-namespace 20ipc-namespace
21netfilter 21netfilter
22no3d 22no3d
23nodvd
23nogroups 24nogroups
24nonewprivs 25nonewprivs
25noroot 26noroot
@@ -39,4 +40,3 @@ private-tmp
39 40
40noexec ${HOME} 41noexec ${HOME}
41noexec /tmp 42noexec /tmp
42nodvd
diff --git a/etc/atom-beta.profile b/etc/atom-beta.profile
index 395f4e350..4869ef4ea 100644
--- a/etc/atom-beta.profile
+++ b/etc/atom-beta.profile
@@ -14,6 +14,7 @@ include /etc/firejail/disable-programs.inc
14 14
15caps.drop all 15caps.drop all
16netfilter 16netfilter
17nodvd
17nogroups 18nogroups
18nonewprivs 19nonewprivs
19noroot 20noroot
@@ -26,4 +27,3 @@ shell none
26 27
27private-dev 28private-dev
28private-tmp 29private-tmp
29nodvd
diff --git a/etc/atom.profile b/etc/atom.profile
index 2a0c46355..8629c3dd8 100644
--- a/etc/atom.profile
+++ b/etc/atom.profile
@@ -14,6 +14,7 @@ include /etc/firejail/disable-programs.inc
14 14
15caps.drop all 15caps.drop all
16netfilter 16netfilter
17nodvd
17nogroups 18nogroups
18nonewprivs 19nonewprivs
19noroot 20noroot
@@ -26,4 +27,3 @@ shell none
26 27
27private-dev 28private-dev
28private-tmp 29private-tmp
29nodvd
diff --git a/etc/atool.profile b/etc/atool.profile
index cd06b4b2a..c2e772f9d 100644
--- a/etc/atool.profile
+++ b/etc/atool.profile
@@ -15,6 +15,7 @@ include /etc/firejail/disable-programs.inc
15caps.drop all 15caps.drop all
16netfilter 16netfilter
17no3d 17no3d
18nodvd
18nogroups 19nogroups
19nonewprivs 20nonewprivs
20noroot 21noroot
@@ -30,4 +31,3 @@ tracelog
30private-dev 31private-dev
31private-etc none 32private-etc none
32private-tmp 33private-tmp
33nodvd
diff --git a/etc/atril.profile b/etc/atril.profile
index 1c0d3a11d..7109d343e 100644
--- a/etc/atril.profile
+++ b/etc/atril.profile
@@ -14,6 +14,7 @@ include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc 14include /etc/firejail/disable-programs.inc
15 15
16caps.drop all 16caps.drop all
17nodvd
17nogroups 18nogroups
18nonewprivs 19nonewprivs
19noroot 20noroot
@@ -28,4 +29,3 @@ tracelog
28private-bin atril, atril-previewer, atril-thumbnailer 29private-bin atril, atril-previewer, atril-thumbnailer
29private-dev 30private-dev
30private-tmp 31private-tmp
31nodvd
diff --git a/etc/audacity.profile b/etc/audacity.profile
index f2e4d2b5b..b5a15b04c 100644
--- a/etc/audacity.profile
+++ b/etc/audacity.profile
@@ -15,6 +15,7 @@ include /etc/firejail/disable-programs.inc
15caps.drop all 15caps.drop all
16net none 16net none
17no3d 17no3d
18nodvd
18nogroups 19nogroups
19nonewprivs 20nonewprivs
20noroot 21noroot
@@ -31,4 +32,3 @@ private-tmp
31 32
32noexec ${HOME} 33noexec ${HOME}
33noexec /tmp 34noexec /tmp
34nodvd
diff --git a/etc/aweather.profile b/etc/aweather.profile
index 4c2664a91..ef811b330 100644
--- a/etc/aweather.profile
+++ b/etc/aweather.profile
@@ -18,6 +18,7 @@ include /etc/firejail/whitelist-common.inc
18 18
19caps.drop all 19caps.drop all
20netfilter 20netfilter
21nodvd
21nogroups 22nogroups
22nonewprivs 23nonewprivs
23noroot 24noroot
@@ -32,4 +33,3 @@ tracelog
32private-bin aweather 33private-bin aweather
33private-dev 34private-dev
34private-tmp 35private-tmp
35nodvd
diff --git a/etc/baloo_file.profile b/etc/baloo_file.profile
index 80c5ea0b0..2809089e6 100644
--- a/etc/baloo_file.profile
+++ b/etc/baloo_file.profile
@@ -18,6 +18,7 @@ include /etc/firejail/disable-passwdmgr.inc
18include /etc/firejail/disable-programs.inc 18include /etc/firejail/disable-programs.inc
19 19
20caps.drop all 20caps.drop all
21nodvd
21nogroups 22nogroups
22nonewprivs 23nonewprivs
23noroot 24noroot
@@ -40,4 +41,3 @@ noexec /tmp
40# read-only ${HOME} 41# read-only ${HOME}
41# read-write ${HOME}/.local/share 42# read-write ${HOME}/.local/share
42# noexec ${HOME}/.local/share 43# noexec ${HOME}/.local/share
43nodvd
diff --git a/etc/baobab.profile b/etc/baobab.profile
index 5eef557bc..014f8869c 100644
--- a/etc/baobab.profile
+++ b/etc/baobab.profile
@@ -14,6 +14,7 @@ include /etc/firejail/disable-passwdmgr.inc
14caps.drop all 14caps.drop all
15net none 15net none
16no3d 16no3d
17nodvd
17nogroups 18nogroups
18nonewprivs 19nonewprivs
19noroot 20noroot
@@ -30,4 +31,3 @@ private-tmp
30memory-deny-write-execute 31memory-deny-write-execute
31noexec ${HOME} 32noexec ${HOME}
32noexec /tmp 33noexec /tmp
33nodvd
diff --git a/etc/bibletime.profile b/etc/bibletime.profile
index 158733660..73d31c205 100644
--- a/etc/bibletime.profile
+++ b/etc/bibletime.profile
@@ -24,6 +24,7 @@ include /etc/firejail/whitelist-common.inc
24 24
25caps.drop all 25caps.drop all
26netfilter 26netfilter
27nodvd
27nogroups 28nogroups
28nonewprivs 29nonewprivs
29noroot 30noroot
@@ -39,4 +40,3 @@ tracelog
39private-dev 40private-dev
40private-etc fonts,resolv.conf,sword,sword.conf,passwd 41private-etc fonts,resolv.conf,sword,sword.conf,passwd
41private-tmp 42private-tmp
42nodvd
diff --git a/etc/bitlbee.profile b/etc/bitlbee.profile
index 0566029cb..0b61e7b9f 100644
--- a/etc/bitlbee.profile
+++ b/etc/bitlbee.profile
@@ -15,6 +15,7 @@ include /etc/firejail/disable-programs.inc
15 15
16netfilter 16netfilter
17no3d 17no3d
18nodvd
18nonewprivs 19nonewprivs
19nosound 20nosound
20notv 21notv
@@ -30,4 +31,3 @@ private-tmp
30read-write /var/lib/bitlbee 31read-write /var/lib/bitlbee
31 32
32noexec /tmp 33noexec /tmp
33nodvd
diff --git a/etc/bleachbit.profile b/etc/bleachbit.profile
index 0c1670283..f3498e9b9 100644
--- a/etc/bleachbit.profile
+++ b/etc/bleachbit.profile
@@ -14,6 +14,7 @@ include /etc/firejail/disable-passwdmgr.inc
14caps.drop all 14caps.drop all
15net none 15net none
16no3d 16no3d
17nodvd
17nogroups 18nogroups
18nonewprivs 19nonewprivs
19noroot 20noroot
@@ -32,4 +33,3 @@ shell none
32memory-deny-write-execute 33memory-deny-write-execute
33noexec ${HOME} 34noexec ${HOME}
34noexec /tmp 35noexec /tmp
35nodvd
diff --git a/etc/blender.profile b/etc/blender.profile
index 438be7e41..f7ecbce55 100644
--- a/etc/blender.profile
+++ b/etc/blender.profile
@@ -14,6 +14,7 @@ include /etc/firejail/disable-programs.inc
14 14
15caps.drop all 15caps.drop all
16netfilter 16netfilter
17nodvd
17nogroups 18nogroups
18nonewprivs 19nonewprivs
19noroot 20noroot
@@ -27,4 +28,3 @@ private-tmp
27 28
28noexec ${HOME} 29noexec ${HOME}
29noexec /tmp 30noexec /tmp
30nodvd
diff --git a/etc/bless.profile b/etc/bless.profile
index 6da8187b1..8285e4473 100644
--- a/etc/bless.profile
+++ b/etc/bless.profile
@@ -15,6 +15,7 @@ include /etc/firejail/disable-programs.inc
15caps.drop all 15caps.drop all
16net none 16net none
17no3d 17no3d
18nodvd
18nogroups 19nogroups
19nonewprivs 20nonewprivs
20noroot 21noroot
@@ -31,4 +32,3 @@ private-tmp
31 32
32noexec ${HOME} 33noexec ${HOME}
33noexec /tmp 34noexec /tmp
34nodvd
diff --git a/etc/brave.profile b/etc/brave.profile
index a512bd133..4a908c884 100644
--- a/etc/brave.profile
+++ b/etc/brave.profile
@@ -30,9 +30,9 @@ include /etc/firejail/whitelist-common.inc
30netfilter 30netfilter
31# nonewprivs 31# nonewprivs
32# noroot 32# noroot
33nodvd
33notv 34notv
34# protocol unix,inet,inet6,netlink 35# protocol unix,inet,inet6,netlink
35# seccomp 36# seccomp
36 37
37# disable-mnt 38# disable-mnt
38nodvd
diff --git a/etc/caja.profile b/etc/caja.profile
index 35b0ce040..d234e6c9b 100644
--- a/etc/caja.profile
+++ b/etc/caja.profile
@@ -19,6 +19,7 @@ include /etc/firejail/disable-passwdmgr.inc
19 19
20caps.drop all 20caps.drop all
21netfilter 21netfilter
22nodvd
22nogroups 23nogroups
23nonewprivs 24nonewprivs
24noroot 25noroot
@@ -33,4 +34,3 @@ tracelog
33# private-dev 34# private-dev
34# private-etc fonts 35# private-etc fonts
35# private-tmp 36# private-tmp
36nodvd
diff --git a/etc/calibre.profile b/etc/calibre.profile
index d1371839c..aa0de473c 100644
--- a/etc/calibre.profile
+++ b/etc/calibre.profile
@@ -16,6 +16,7 @@ include /etc/firejail/disable-programs.inc
16caps.drop all 16caps.drop all
17netfilter 17netfilter
18no3d 18no3d
19nodvd
19nogroups 20nogroups
20nonewprivs 21nonewprivs
21noroot 22noroot
@@ -33,4 +34,3 @@ private-tmp
33 34
34noexec ${HOME} 35noexec ${HOME}
35noexec /tmp 36noexec /tmp
36nodvd
diff --git a/etc/catfish.profile b/etc/catfish.profile
index 2f9c35220..498f3b6ee 100644
--- a/etc/catfish.profile
+++ b/etc/catfish.profile
@@ -14,6 +14,7 @@ include /etc/firejail/disable-devel.inc
14caps.drop all 14caps.drop all
15net none 15net none
16no3d 16no3d
17nodvd
17nogroups 18nogroups
18nonewprivs 19nonewprivs
19noroot 20noroot
@@ -30,4 +31,3 @@ tracelog
30# private-bin bash,catfish,env,locate,ls,mlocate,python,python2,python2.7,python3,python3.5,python3.5m,python3m 31# private-bin bash,catfish,env,locate,ls,mlocate,python,python2,python2.7,python3,python3.5,python3.5m,python3m
31# private-dev 32# private-dev
32# private-tmp 33# private-tmp
33nodvd
diff --git a/etc/cherrytree.profile b/etc/cherrytree.profile
index 901bfed1e..88be562c8 100644
--- a/etc/cherrytree.profile
+++ b/etc/cherrytree.profile
@@ -17,6 +17,7 @@ include /etc/firejail/disable-programs.inc
17caps.drop all 17caps.drop all
18netfilter 18netfilter
19no3d 19no3d
20nodvd
20nogroups 21nogroups
21nonewprivs 22nonewprivs
22noroot 23noroot
@@ -33,4 +34,3 @@ private-tmp
33 34
34noexec ${HOME} 35noexec ${HOME}
35noexec /tmp 36noexec /tmp
36nodvd
diff --git a/etc/chromium.profile b/etc/chromium.profile
index 7637b8ea5..37b2e51a6 100644
--- a/etc/chromium.profile
+++ b/etc/chromium.profile
@@ -27,6 +27,7 @@ include /etc/firejail/whitelist-common.inc
27 27
28caps.keep sys_chroot,sys_admin 28caps.keep sys_chroot,sys_admin
29netfilter 29netfilter
30nodvd
30nogroups 31nogroups
31notv 32notv
32shell none 33shell none
@@ -36,4 +37,3 @@ private-dev
36 37
37noexec ${HOME} 38noexec ${HOME}
38noexec /tmp 39noexec /tmp
39nodvd
diff --git a/etc/claws-mail.profile b/etc/claws-mail.profile
index d1470adfb..bc045fb77 100644
--- a/etc/claws-mail.profile
+++ b/etc/claws-mail.profile
@@ -16,6 +16,7 @@ include /etc/firejail/disable-programs.inc
16 16
17caps.drop all 17caps.drop all
18netfilter 18netfilter
19nodvd
19nogroups 20nogroups
20nonewprivs 21nonewprivs
21noroot 22noroot
@@ -27,4 +28,3 @@ shell none
27 28
28private-dev 29private-dev
29private-tmp 30private-tmp
30nodvd
diff --git a/etc/clipit.profile b/etc/clipit.profile
index 64a635efb..e6ee7b636 100644
--- a/etc/clipit.profile
+++ b/etc/clipit.profile
@@ -16,6 +16,7 @@ include /etc/firejail/disable-programs.inc
16caps.drop all 16caps.drop all
17netfilter 17netfilter
18no3d 18no3d
19nodvd
19nogroups 20nogroups
20nonewprivs 21nonewprivs
21noroot 22noroot
@@ -32,4 +33,3 @@ private-tmp
32 33
33noexec ${HOME} 34noexec ${HOME}
34noexec /tmp 35noexec /tmp
35nodvd
diff --git a/etc/conkeror.profile b/etc/conkeror.profile
index efee37106..f6a9eefb6 100644
--- a/etc/conkeror.profile
+++ b/etc/conkeror.profile
@@ -25,9 +25,9 @@ include /etc/firejail/whitelist-common.inc
25 25
26caps.drop all 26caps.drop all
27netfilter 27netfilter
28nodvd
28nonewprivs 29nonewprivs
29noroot 30noroot
30notv 31notv
31protocol unix,inet,inet6 32protocol unix,inet,inet6
32seccomp 33seccomp
33nodvd
diff --git a/etc/corebird.profile b/etc/corebird.profile
index 39726d13a..87f7a970b 100644
--- a/etc/corebird.profile
+++ b/etc/corebird.profile
@@ -13,8 +13,8 @@ include /etc/firejail/disable-programs.inc
13 13
14caps.drop all 14caps.drop all
15netfilter 15netfilter
16nodvd
16noroot 17noroot
17notv 18notv
18protocol unix,inet,inet6 19protocol unix,inet,inet6
19seccomp 20seccomp
20nodvd
diff --git a/etc/cpio.profile b/etc/cpio.profile
index 3f25393b0..f082d2e40 100644
--- a/etc/cpio.profile
+++ b/etc/cpio.profile
@@ -19,6 +19,7 @@ caps.drop all
19net none 19net none
20net none 20net none
21no3d 21no3d
22nodvd
22nosound 23nosound
23notv 24notv
24seccomp 25seccomp
@@ -26,4 +27,3 @@ shell none
26tracelog 27tracelog
27 28
28private-dev 29private-dev
29nodvd
diff --git a/etc/curl.profile b/etc/curl.profile
index dea5b3db8..af7eabf59 100644
--- a/etc/curl.profile
+++ b/etc/curl.profile
@@ -17,6 +17,7 @@ include /etc/firejail/disable-programs.inc
17caps.drop all 17caps.drop all
18netfilter 18netfilter
19no3d 19no3d
20nodvd
20nogroups 21nogroups
21nonewprivs 22nonewprivs
22noroot 23noroot
@@ -33,4 +34,3 @@ private-tmp
33 34
34noexec ${HOME} 35noexec ${HOME}
35noexec /tmp 36noexec /tmp
36nodvd
diff --git a/etc/cvlc.profile b/etc/cvlc.profile
index b0052eeab..ee1346617 100644
--- a/etc/cvlc.profile
+++ b/etc/cvlc.profile
@@ -14,6 +14,7 @@ include /etc/firejail/disable-programs.inc
14 14
15caps.drop all 15caps.drop all
16netfilter 16netfilter
17nodvd
17nogroups 18nogroups
18nonewprivs 19nonewprivs
19noroot 20noroot
@@ -29,4 +30,3 @@ private-dev
29private-tmp 30private-tmp
30 31
31memory-deny-write-execute 32memory-deny-write-execute
32nodvd
diff --git a/etc/cyberfox.profile b/etc/cyberfox.profile
index 5cd75208b..63f6ea845 100644
--- a/etc/cyberfox.profile
+++ b/etc/cyberfox.profile
@@ -52,6 +52,7 @@ include /etc/firejail/whitelist-common.inc
52 52
53caps.drop all 53caps.drop all
54netfilter 54netfilter
55nodvd
55nogroups 56nogroups
56nonewprivs 57nonewprivs
57noroot 58noroot
@@ -69,4 +70,3 @@ private-tmp
69 70
70noexec ${HOME} 71noexec ${HOME}
71noexec /tmp 72noexec /tmp
72nodvd
diff --git a/etc/darktable.profile b/etc/darktable.profile
index 51cb197b0..e04163486 100644
--- a/etc/darktable.profile
+++ b/etc/darktable.profile
@@ -15,6 +15,7 @@ include /etc/firejail/disable-programs.inc
15 15
16caps.drop all 16caps.drop all
17netfilter 17netfilter
18nodvd
18nogroups 19nogroups
19nonewprivs 20nonewprivs
20noroot 21noroot
@@ -30,4 +31,3 @@ private-tmp
30 31
31noexec ${HOME} 32noexec ${HOME}
32noexec /tmp 33noexec /tmp
33nodvd
diff --git a/etc/deluge.profile b/etc/deluge.profile
index da477e4c3..c311d2fa7 100644
--- a/etc/deluge.profile
+++ b/etc/deluge.profile
@@ -19,6 +19,7 @@ include /etc/firejail/whitelist-common.inc
19 19
20caps.drop all 20caps.drop all
21netfilter 21netfilter
22nodvd
22nonewprivs 23nonewprivs
23noroot 24noroot
24nosound 25nosound
@@ -32,4 +33,3 @@ shell none
32# private-bin deluge,sh,python,uname 33# private-bin deluge,sh,python,uname
33private-dev 34private-dev
34private-tmp 35private-tmp
35nodvd
diff --git a/etc/dex2jar.profile b/etc/dex2jar.profile
index a3a1c4ad5..858baba6d 100644
--- a/etc/dex2jar.profile
+++ b/etc/dex2jar.profile
@@ -15,6 +15,7 @@ include /etc/firejail/disable-programs.inc
15caps.drop all 15caps.drop all
16net none 16net none
17no3d 17no3d
18nodvd
18nogroups 19nogroups
19nonewprivs 20nonewprivs
20noroot 21noroot
@@ -29,4 +30,3 @@ private-dev
29 30
30noexec ${HOME} 31noexec ${HOME}
31noexec /tmp 32noexec /tmp
32nodvd
diff --git a/etc/dia.profile b/etc/dia.profile
index 14724c321..a625ab36d 100644
--- a/etc/dia.profile
+++ b/etc/dia.profile
@@ -15,6 +15,7 @@ include /etc/firejail/disable-programs.inc
15caps.drop all 15caps.drop all
16netfilter 16netfilter
17no3d 17no3d
18nodvd
18nogroups 19nogroups
19nonewprivs 20nonewprivs
20noroot 21noroot
@@ -31,4 +32,3 @@ private-tmp
31 32
32noexec ${HOME} 33noexec ${HOME}
33noexec /tmp 34noexec /tmp
34nodvd
diff --git a/etc/digikam.profile b/etc/digikam.profile
index 1a39f5a9d..43191ec06 100644
--- a/etc/digikam.profile
+++ b/etc/digikam.profile
@@ -16,6 +16,7 @@ include /etc/firejail/disable-programs.inc
16 16
17caps.drop all 17caps.drop all
18netfilter 18netfilter
19nodvd
19nogroups 20nogroups
20nonewprivs 21nonewprivs
21noroot 22noroot
@@ -32,4 +33,3 @@ private-tmp
32 33
33noexec ${HOME} 34noexec ${HOME}
34noexec /tmp 35noexec /tmp
35nodvd
diff --git a/etc/dillo.profile b/etc/dillo.profile
index e1f0594e1..aa8a395e1 100644
--- a/etc/dillo.profile
+++ b/etc/dillo.profile
@@ -21,10 +21,10 @@ include /etc/firejail/whitelist-common.inc
21 21
22caps.drop all 22caps.drop all
23netfilter 23netfilter
24nodvd
24nonewprivs 25nonewprivs
25noroot 26noroot
26notv 27notv
27protocol unix,inet,inet6 28protocol unix,inet,inet6
28seccomp 29seccomp
29tracelog 30tracelog
30nodvd
diff --git a/etc/dino.profile b/etc/dino.profile
index 9355f7e6a..72f4f40b2 100644
--- a/etc/dino.profile
+++ b/etc/dino.profile
@@ -20,6 +20,7 @@ include /etc/firejail/whitelist-common.inc
20caps.drop all 20caps.drop all
21netfilter 21netfilter
22no3d 22no3d
23nodvd
23nogroups 24nogroups
24nonewprivs 25nonewprivs
25noroot 26noroot
@@ -38,4 +39,3 @@ private-tmp
38 39
39noexec ${HOME} 40noexec ${HOME}
40noexec /tmp 41noexec /tmp
41nodvd
diff --git a/etc/display.profile b/etc/display.profile
index d8bbd4423..44d37d5b2 100644
--- a/etc/display.profile
+++ b/etc/display.profile
@@ -13,6 +13,7 @@ include /etc/firejail/disable-programs.inc
13 13
14caps.drop all 14caps.drop all
15net none 15net none
16nodvd
16nogroups 17nogroups
17nonewprivs 18nonewprivs
18noroot 19noroot
@@ -27,4 +28,3 @@ private-bin display
27private-dev 28private-dev
28private-etc none 29private-etc none
29private-tmp 30private-tmp
30nodvd
diff --git a/etc/dnscrypt-proxy.profile b/etc/dnscrypt-proxy.profile
index 101e3afb0..d82efef04 100644
--- a/etc/dnscrypt-proxy.profile
+++ b/etc/dnscrypt-proxy.profile
@@ -14,10 +14,10 @@ include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc 14include /etc/firejail/disable-programs.inc
15 15
16no3d 16no3d
17nodvd
17nosound 18nosound
18notv 19notv
19seccomp.drop mount,umount2,ptrace,kexec_load,kexec_file_load,open_by_handle_at,init_module,finit_module,delete_module,iopl,ioperm,swapon,swapoff,syslog,process_vm_readv,process_vm_writev,sysfs,_sysctl,adjtimex,clock_adjtime,lookup_dcookie,perf_event_open,fanotify_init,kcmp,add_key,request_key,keyctl,uselib,acct,modify_ldt,pivot_root,io_setup,io_destroy,io_getevents,io_submit,io_cancel,remap_file_pages,mbind,get_mempolicy,set_mempolicy,migrate_pages,move_pages,vmsplice,perf_event_open 20seccomp.drop mount,umount2,ptrace,kexec_load,kexec_file_load,open_by_handle_at,init_module,finit_module,delete_module,iopl,ioperm,swapon,swapoff,syslog,process_vm_readv,process_vm_writev,sysfs,_sysctl,adjtimex,clock_adjtime,lookup_dcookie,perf_event_open,fanotify_init,kcmp,add_key,request_key,keyctl,uselib,acct,modify_ldt,pivot_root,io_setup,io_destroy,io_getevents,io_submit,io_cancel,remap_file_pages,mbind,get_mempolicy,set_mempolicy,migrate_pages,move_pages,vmsplice,perf_event_open
20 21
21private 22private
22private-dev 23private-dev
23nodvd
diff --git a/etc/dnsmasq.profile b/etc/dnsmasq.profile
index b6ca68bf2..bf52a5d8a 100644
--- a/etc/dnsmasq.profile
+++ b/etc/dnsmasq.profile
@@ -16,6 +16,7 @@ include /etc/firejail/disable-programs.inc
16caps 16caps
17netfilter 17netfilter
18no3d 18no3d
19nodvd
19nonewprivs 20nonewprivs
20nosound 21nosound
21notv 22notv
@@ -25,4 +26,3 @@ seccomp
25disable-mnt 26disable-mnt
26private 27private
27private-dev 28private-dev
28nodvd
diff --git a/etc/dolphin.profile b/etc/dolphin.profile
index 6bd4fd38f..7566e927b 100644
--- a/etc/dolphin.profile
+++ b/etc/dolphin.profile
@@ -19,6 +19,7 @@ include /etc/firejail/disable-passwdmgr.inc
19 19
20caps.drop all 20caps.drop all
21netfilter 21netfilter
22nodvd
22nogroups 23nogroups
23nonewprivs 24nonewprivs
24noroot 25noroot
@@ -32,4 +33,3 @@ shell none
32# private-dev 33# private-dev
33# private-etc 34# private-etc
34# private-tmp 35# private-tmp
35nodvd
diff --git a/etc/dosbox.profile b/etc/dosbox.profile
index 700458169..bec2960f1 100644
--- a/etc/dosbox.profile
+++ b/etc/dosbox.profile
@@ -14,6 +14,7 @@ include /etc/firejail/disable-programs.inc
14 14
15caps.drop all 15caps.drop all
16netfilter 16netfilter
17nodvd
17nogroups 18nogroups
18nonewprivs 19nonewprivs
19noroot 20noroot
@@ -26,4 +27,3 @@ tracelog
26private-bin dosbox 27private-bin dosbox
27private-dev 28private-dev
28private-tmp 29private-tmp
29nodvd
diff --git a/etc/dragon.profile b/etc/dragon.profile
index 4bab76e7d..211c2432f 100644
--- a/etc/dragon.profile
+++ b/etc/dragon.profile
@@ -14,6 +14,7 @@ include /etc/firejail/disable-programs.inc
14 14
15caps.drop all 15caps.drop all
16netfilter 16netfilter
17nodvd
17nogroups 18nogroups
18nonewprivs 19nonewprivs
19noroot 20noroot
@@ -30,4 +31,3 @@ private-tmp
30 31
31noexec ${HOME} 32noexec ${HOME}
32noexec /tmp 33noexec /tmp
33nodvd
diff --git a/etc/dropbox.profile b/etc/dropbox.profile
index de41691b8..c8670357c 100644
--- a/etc/dropbox.profile
+++ b/etc/dropbox.profile
@@ -26,6 +26,7 @@ include /etc/firejail/whitelist-common.inc
26caps.drop all 26caps.drop all
27netfilter 27netfilter
28no3d 28no3d
29nodvd
29nogroups 30nogroups
30nonewprivs 31nonewprivs
31noroot 32noroot
@@ -40,4 +41,3 @@ private-dev
40private-tmp 41private-tmp
41 42
42noexec /tmp 43noexec /tmp
43nodvd
diff --git a/etc/electron.profile b/etc/electron.profile
index a60704035..9b21c1bfd 100644
--- a/etc/electron.profile
+++ b/etc/electron.profile
@@ -12,10 +12,10 @@ include /etc/firejail/disable-programs.inc
12 12
13caps.drop all 13caps.drop all
14netfilter 14netfilter
15nodvd
15nogroups 16nogroups
16nonewprivs 17nonewprivs
17noroot 18noroot
18notv 19notv
19protocol unix,inet,inet6,netlink 20protocol unix,inet,inet6,netlink
20seccomp 21seccomp
21nodvd
diff --git a/etc/elinks.profile b/etc/elinks.profile
index 530e41217..10fd19f71 100644
--- a/etc/elinks.profile
+++ b/etc/elinks.profile
@@ -17,6 +17,7 @@ include /etc/firejail/disable-programs.inc
17caps.drop all 17caps.drop all
18netfilter 18netfilter
19no3d 19no3d
20nodvd
20nogroups 21nogroups
21nonewprivs 22nonewprivs
22noroot 23noroot
@@ -32,4 +33,3 @@ tracelog
32private-dev 33private-dev
33# private-etc none 34# private-etc none
34private-tmp 35private-tmp
35nodvd
diff --git a/etc/emacs.profile b/etc/emacs.profile
index c262c9900..8351d6c42 100644
--- a/etc/emacs.profile
+++ b/etc/emacs.profile
@@ -14,10 +14,10 @@ include /etc/firejail/disable-programs.inc
14 14
15caps.drop all 15caps.drop all
16netfilter 16netfilter
17nodvd
17nogroups 18nogroups
18nonewprivs 19nonewprivs
19noroot 20noroot
20notv 21notv
21protocol unix,inet,inet6 22protocol unix,inet,inet6
22seccomp 23seccomp
23nodvd
diff --git a/etc/empathy.profile b/etc/empathy.profile
index e85bf324d..b2cfa369c 100644
--- a/etc/empathy.profile
+++ b/etc/empathy.profile
@@ -12,10 +12,10 @@ include /etc/firejail/disable-programs.inc
12 12
13caps.drop all 13caps.drop all
14netfilter 14netfilter
15nodvd
15nogroups 16nogroups
16nonewprivs 17nonewprivs
17noroot 18noroot
18notv 19notv
19protocol unix,inet,inet6 20protocol unix,inet,inet6
20seccomp 21seccomp
21nodvd
diff --git a/etc/enchant.profile b/etc/enchant.profile
index 5574eeae0..a7b549a4c 100644
--- a/etc/enchant.profile
+++ b/etc/enchant.profile
@@ -14,6 +14,7 @@ include /etc/firejail/disable-programs.inc
14 14
15caps.drop all 15caps.drop all
16netfilter 16netfilter
17nodvd
17nogroups 18nogroups
18nonewprivs 19nonewprivs
19noroot 20noroot
@@ -28,4 +29,3 @@ tracelog
28# private-dev 29# private-dev
29# private-etc fonts 30# private-etc fonts
30# private-tmp 31# private-tmp
31nodvd
diff --git a/etc/engrampa.profile b/etc/engrampa.profile
index 9ac577da0..e10fd6084 100644
--- a/etc/engrampa.profile
+++ b/etc/engrampa.profile
@@ -13,6 +13,7 @@ include /etc/firejail/disable-programs.inc
13 13
14caps.drop all 14caps.drop all
15netfilter 15netfilter
16nodvd
16nogroups 17nogroups
17nonewprivs 18nonewprivs
18noroot 19noroot
@@ -28,4 +29,3 @@ tracelog
28private-dev 29private-dev
29# private-etc fonts 30# private-etc fonts
30# private-tmp 31# private-tmp
31nodvd
diff --git a/etc/eog.profile b/etc/eog.profile
index 8dfd01ea1..54d5a1a88 100644
--- a/etc/eog.profile
+++ b/etc/eog.profile
@@ -18,6 +18,7 @@ include /etc/firejail/disable-programs.inc
18caps.drop all 18caps.drop all
19net none 19net none
20no3d 20no3d
21nodvd
21nogroups 22nogroups
22nonewprivs 23nonewprivs
23noroot 24noroot
@@ -36,4 +37,3 @@ private-tmp
36memory-deny-write-execute 37memory-deny-write-execute
37noexec ${HOME} 38noexec ${HOME}
38noexec /tmp 39noexec /tmp
39nodvd
diff --git a/etc/eom.profile b/etc/eom.profile
index d5470ef24..6fd069b5c 100644
--- a/etc/eom.profile
+++ b/etc/eom.profile
@@ -16,6 +16,7 @@ include /etc/firejail/disable-passwdmgr.inc
16include /etc/firejail/disable-programs.inc 16include /etc/firejail/disable-programs.inc
17 17
18caps.drop all 18caps.drop all
19nodvd
19nogroups 20nogroups
20nonewprivs 21nonewprivs
21noroot 22noroot
@@ -33,4 +34,3 @@ private-tmp
33 34
34noexec ${HOME} 35noexec ${HOME}
35noexec /tmp 36noexec /tmp
36nodvd
diff --git a/etc/epiphany.profile b/etc/epiphany.profile
index f3a880bd6..0f9a9cf55 100644
--- a/etc/epiphany.profile
+++ b/etc/epiphany.profile
@@ -24,8 +24,8 @@ include /etc/firejail/whitelist-common.inc
24 24
25caps.drop all 25caps.drop all
26netfilter 26netfilter
27nodvd
27nonewprivs 28nonewprivs
28notv 29notv
29protocol unix,inet,inet6 30protocol unix,inet,inet6
30seccomp 31seccomp
31nodvd
diff --git a/etc/etr.profile b/etc/etr.profile
index 5529c2ed6..96e8b46d9 100644
--- a/etc/etr.profile
+++ b/etc/etr.profile
@@ -17,6 +17,7 @@ include /etc/firejail/whitelist-common.inc
17 17
18caps.drop all 18caps.drop all
19net none 19net none
20nodvd
20nogroups 21nogroups
21nonewprivs 22nonewprivs
22noroot 23noroot
@@ -29,4 +30,3 @@ shell none
29private-dev 30private-dev
30# private-etc none 31# private-etc none
31private-tmp 32private-tmp
32nodvd
diff --git a/etc/evince.profile b/etc/evince.profile
index a929c8c4f..5c6215bb2 100644
--- a/etc/evince.profile
+++ b/etc/evince.profile
@@ -15,6 +15,7 @@ include /etc/firejail/disable-programs.inc
15caps.drop all 15caps.drop all
16netfilter 16netfilter
17no3d 17no3d
18nodvd
18nogroups 19nogroups
19nonewprivs 20nonewprivs
20noroot 21noroot
@@ -35,4 +36,3 @@ private-etc fonts
35memory-deny-write-execute 36memory-deny-write-execute
36noexec ${HOME} 37noexec ${HOME}
37noexec /tmp 38noexec /tmp
38nodvd
diff --git a/etc/evolution.profile b/etc/evolution.profile
index ef4c9f627..2f7f25ff8 100644
--- a/etc/evolution.profile
+++ b/etc/evolution.profile
@@ -23,6 +23,7 @@ include /etc/firejail/disable-programs.inc
23caps.drop all 23caps.drop all
24netfilter 24netfilter
25no3d 25no3d
26nodvd
26nogroups 27nogroups
27nonewprivs 28nonewprivs
28noroot 29noroot
@@ -37,4 +38,3 @@ private-tmp
37 38
38noexec ${HOME} 39noexec ${HOME}
39noexec /tmp 40noexec /tmp
40nodvd
diff --git a/etc/exiftool.profile b/etc/exiftool.profile
index 8b56e810d..565212161 100644
--- a/etc/exiftool.profile
+++ b/etc/exiftool.profile
@@ -20,6 +20,7 @@ include /etc/firejail/disable-programs.inc
20caps.drop all 20caps.drop all
21net none 21net none
22no3d 22no3d
23nodvd
23nogroups 24nogroups
24nonewprivs 25nonewprivs
25noroot 26noroot
@@ -34,4 +35,3 @@ tracelog
34private-dev 35private-dev
35private-etc none 36private-etc none
36private-tmp 37private-tmp
37nodvd
diff --git a/etc/fbreader.profile b/etc/fbreader.profile
index 0756a1d40..19d45a1d8 100644
--- a/etc/fbreader.profile
+++ b/etc/fbreader.profile
@@ -14,6 +14,7 @@ include /etc/firejail/disable-programs.inc
14 14
15caps.drop all 15caps.drop all
16netfilter 16netfilter
17nodvd
17nonewprivs 18nonewprivs
18noroot 19noroot
19nosound 20nosound
@@ -25,4 +26,3 @@ shell none
25private-bin fbreader,FBReader 26private-bin fbreader,FBReader
26private-dev 27private-dev
27private-tmp 28private-tmp
28nodvd
diff --git a/etc/feh.profile b/etc/feh.profile
index 1798527f7..61b456e34 100644
--- a/etc/feh.profile
+++ b/etc/feh.profile
@@ -13,6 +13,7 @@ include /etc/firejail/disable-programs.inc
13 13
14caps.drop all 14caps.drop all
15net none 15net none
16nodvd
16nogroups 17nogroups
17nonewprivs 18nonewprivs
18noroot 19noroot
@@ -26,4 +27,3 @@ private-bin feh
26private-dev 27private-dev
27private-etc feh 28private-etc feh
28private-tmp 29private-tmp
29nodvd
diff --git a/etc/file-roller.profile b/etc/file-roller.profile
index ff8d8c9eb..1ecb3c632 100644
--- a/etc/file-roller.profile
+++ b/etc/file-roller.profile
@@ -14,6 +14,7 @@ include /etc/firejail/disable-programs.inc
14caps.drop all 14caps.drop all
15net none 15net none
16no3d 16no3d
17nodvd
17nogroups 18nogroups
18nonewprivs 19nonewprivs
19noroot 20noroot
@@ -33,4 +34,3 @@ private-dev
33memory-deny-write-execute 34memory-deny-write-execute
34noexec ${HOME} 35noexec ${HOME}
35noexec /tmp 36noexec /tmp
36nodvd
diff --git a/etc/file.profile b/etc/file.profile
index 389e89426..9a4dba7ef 100644
--- a/etc/file.profile
+++ b/etc/file.profile
@@ -16,6 +16,7 @@ caps.drop all
16hostname file 16hostname file
17net none 17net none
18no3d 18no3d
19nodvd
19nogroups 20nogroups
20nonewprivs 21nonewprivs
21nosound 22nosound
@@ -29,4 +30,3 @@ x11 none
29private-bin file 30private-bin file
30private-dev 31private-dev
31private-etc magic.mgc,magic,localtime 32private-etc magic.mgc,magic,localtime
32nodvd
diff --git a/etc/filezilla.profile b/etc/filezilla.profile
index cb8c38a14..63bfd1e0d 100644
--- a/etc/filezilla.profile
+++ b/etc/filezilla.profile
@@ -14,6 +14,7 @@ include /etc/firejail/disable-programs.inc
14 14
15caps.drop all 15caps.drop all
16netfilter 16netfilter
17nodvd
17nonewprivs 18nonewprivs
18noroot 19noroot
19nosound 20nosound
@@ -25,4 +26,3 @@ shell none
25private-bin filezilla,uname,sh,bash,dash,python,lsb_release,fzputtygen,fzsftp 26private-bin filezilla,uname,sh,bash,dash,python,lsb_release,fzputtygen,fzsftp
26private-dev 27private-dev
27private-tmp 28private-tmp
28nodvd
diff --git a/etc/firefox.profile b/etc/firefox.profile
index d4de1332d..7229ba45b 100644
--- a/etc/firefox.profile
+++ b/etc/firefox.profile
@@ -52,6 +52,7 @@ include /etc/firejail/whitelist-common.inc
52 52
53caps.drop all 53caps.drop all
54netfilter 54netfilter
55nodvd
55nogroups 56nogroups
56nonewprivs 57nonewprivs
57noroot 58noroot
@@ -69,4 +70,3 @@ private-tmp
69 70
70noexec ${HOME} 71noexec ${HOME}
71noexec /tmp 72noexec /tmp
72nodvd
diff --git a/etc/flashpeak-slimjet.profile b/etc/flashpeak-slimjet.profile
index a661c179a..8a8337802 100644
--- a/etc/flashpeak-slimjet.profile
+++ b/etc/flashpeak-slimjet.profile
@@ -30,9 +30,9 @@ include /etc/firejail/whitelist-common.inc
30 30
31caps.drop all 31caps.drop all
32netfilter 32netfilter
33nodvd
33nonewprivs 34nonewprivs
34noroot 35noroot
35notv 36notv
36protocol unix,inet,inet6,netlink 37protocol unix,inet,inet6,netlink
37seccomp 38seccomp
38nodvd
diff --git a/etc/flowblade.profile b/etc/flowblade.profile
index 557948c84..79dab0751 100644
--- a/etc/flowblade.profile
+++ b/etc/flowblade.profile
@@ -15,6 +15,7 @@ include /etc/firejail/disable-programs.inc
15 15
16caps.drop all 16caps.drop all
17netfilter 17netfilter
18nodvd
18nogroups 19nogroups
19nonewprivs 20nonewprivs
20noroot 21noroot
@@ -28,4 +29,3 @@ private-tmp
28 29
29noexec ${HOME} 30noexec ${HOME}
30noexec /tmp 31noexec /tmp
31nodvd
diff --git a/etc/fontforge.profile b/etc/fontforge.profile
index 835f913d4..29295f8a0 100644
--- a/etc/fontforge.profile
+++ b/etc/fontforge.profile
@@ -14,6 +14,7 @@ include /etc/firejail/disable-programs.inc
14 14
15caps.drop all 15caps.drop all
16netfilter 16netfilter
17nodvd
17nogroups 18nogroups
18nonewprivs 19nonewprivs
19noroot 20noroot
@@ -29,4 +30,3 @@ private-tmp
29 30
30noexec ${HOME} 31noexec ${HOME}
31noexec /tmp 32noexec /tmp
32nodvd
diff --git a/etc/fossamail.profile b/etc/fossamail.profile
index ef89561e9..74073d8d1 100644
--- a/etc/fossamail.profile
+++ b/etc/fossamail.profile
@@ -17,7 +17,7 @@ whitelist ~/.fossamail
17whitelist ~/.gnupg 17whitelist ~/.gnupg
18include /etc/firejail/whitelist-common.inc 18include /etc/firejail/whitelist-common.inc
19 19
20nodvd
20notv 21notv
21 22
22include /etc/firejail/firefox.profile 23include /etc/firejail/firefox.profile
23nodvd
diff --git a/etc/franz.profile b/etc/franz.profile
index 52758dc0c..f83b5018c 100644
--- a/etc/franz.profile
+++ b/etc/franz.profile
@@ -24,6 +24,7 @@ include /etc/firejail/whitelist-common.inc
24 24
25caps.drop all 25caps.drop all
26netfilter 26netfilter
27nodvd
27nogroups 28nogroups
28nonewprivs 29nonewprivs
29noroot 30noroot
@@ -38,4 +39,3 @@ private-tmp
38 39
39noexec ${HOME} 40noexec ${HOME}
40noexec /tmp 41noexec /tmp
41nodvd
diff --git a/etc/frozen-bubble.profile b/etc/frozen-bubble.profile
index 6417ce812..40aa6d58d 100644
--- a/etc/frozen-bubble.profile
+++ b/etc/frozen-bubble.profile
@@ -17,6 +17,7 @@ include /etc/firejail/whitelist-common.inc
17 17
18caps.drop all 18caps.drop all
19net none 19net none
20nodvd
20nogroups 21nogroups
21nonewprivs 22nonewprivs
22noroot 23noroot
@@ -29,4 +30,3 @@ shell none
29private-dev 30private-dev
30# private-etc none 31# private-etc none
31private-tmp 32private-tmp
32nodvd
diff --git a/etc/gajim.profile b/etc/gajim.profile
index f69391f23..f1929c015 100644
--- a/etc/gajim.profile
+++ b/etc/gajim.profile
@@ -28,6 +28,7 @@ include /etc/firejail/whitelist-common.inc
28 28
29caps.drop all 29caps.drop all
30netfilter 30netfilter
31nodvd
31nogroups 32nogroups
32nonewprivs 33nonewprivs
33noroot 34noroot
@@ -43,4 +44,3 @@ private-dev
43# private-tmp 44# private-tmp
44# Allow the local python 2.7 site packages, in case any plugins are using these 45# Allow the local python 2.7 site packages, in case any plugins are using these
45read-only ${HOME}/.local/lib/python2.7/site-packages/ 46read-only ${HOME}/.local/lib/python2.7/site-packages/
46nodvd
diff --git a/etc/galculator.profile b/etc/galculator.profile
index 9d2ce57e8..a2e855656 100644
--- a/etc/galculator.profile
+++ b/etc/galculator.profile
@@ -18,6 +18,7 @@ include /etc/firejail/whitelist-common.inc
18 18
19caps.drop all 19caps.drop all
20net none 20net none
21nodvd
21nogroups 22nogroups
22nonewprivs 23nonewprivs
23noroot 24noroot
@@ -32,4 +33,3 @@ private-bin galculator
32private-dev 33private-dev
33private-etc fonts 34private-etc fonts
34private-tmp 35private-tmp
35nodvd
diff --git a/etc/geany.profile b/etc/geany.profile
index 530b00192..35e405319 100644
--- a/etc/geany.profile
+++ b/etc/geany.profile
@@ -14,6 +14,7 @@ include /etc/firejail/disable-programs.inc
14caps.drop all 14caps.drop all
15netfilter 15netfilter
16no3d 16no3d
17nodvd
17nogroups 18nogroups
18nonewprivs 19nonewprivs
19noroot 20noroot
@@ -26,4 +27,3 @@ shell none
26 27
27private-dev 28private-dev
28private-tmp 29private-tmp
29nodvd
diff --git a/etc/gedit.profile b/etc/gedit.profile
index 6b9eb5a44..418575e09 100644
--- a/etc/gedit.profile
+++ b/etc/gedit.profile
@@ -17,6 +17,7 @@ include /etc/firejail/disable-programs.inc
17caps.drop all 17caps.drop all
18net none 18net none
19no3d 19no3d
20nodvd
20nogroups 21nogroups
21nonewprivs 22nonewprivs
22noroot 23noroot
@@ -34,4 +35,3 @@ private-tmp
34 35
35noexec ${HOME} 36noexec ${HOME}
36noexec /tmp 37noexec /tmp
37nodvd
diff --git a/etc/geeqie.profile b/etc/geeqie.profile
index 5009940d1..c9f9d0074 100644
--- a/etc/geeqie.profile
+++ b/etc/geeqie.profile
@@ -15,6 +15,7 @@ include /etc/firejail/disable-passwdmgr.inc
15include /etc/firejail/disable-programs.inc 15include /etc/firejail/disable-programs.inc
16 16
17caps.drop all 17caps.drop all
18nodvd
18nogroups 19nogroups
19nonewprivs 20nonewprivs
20noroot 21noroot
@@ -27,4 +28,3 @@ shell none
27# private-bin geeqie 28# private-bin geeqie
28private-dev 29private-dev
29# private-etc X11 30# private-etc X11
30nodvd
diff --git a/etc/gimp.profile b/etc/gimp.profile
index acacc8e28..aa77d6105 100644
--- a/etc/gimp.profile
+++ b/etc/gimp.profile
@@ -13,6 +13,7 @@ include /etc/firejail/disable-programs.inc
13 13
14caps.drop all 14caps.drop all
15net none 15net none
16nodvd
16nogroups 17nogroups
17nonewprivs 18nonewprivs
18noroot 19noroot
@@ -29,4 +30,3 @@ private-tmp
29# if you are not using external plugins, you can enable noexec statement below 30# if you are not using external plugins, you can enable noexec statement below
30# noexec ${HOME} 31# noexec ${HOME}
31noexec /tmp 32noexec /tmp
32nodvd
diff --git a/etc/git.profile b/etc/git.profile
index 34bba1974..92bf66b92 100644
--- a/etc/git.profile
+++ b/etc/git.profile
@@ -23,6 +23,7 @@ include /etc/firejail/disable-programs.inc
23caps.drop all 23caps.drop all
24netfilter 24netfilter
25no3d 25no3d
26nodvd
26nogroups 27nogroups
27nonewprivs 28nonewprivs
28noroot 29noroot
@@ -33,4 +34,3 @@ seccomp
33shell none 34shell none
34 35
35private-dev 36private-dev
36nodvd
diff --git a/etc/gitg.profile b/etc/gitg.profile
index f28fbe03f..869c4a6f5 100644
--- a/etc/gitg.profile
+++ b/etc/gitg.profile
@@ -16,6 +16,7 @@ include /etc/firejail/disable-programs.inc
16 16
17caps.drop all 17caps.drop all
18no3d 18no3d
19nodvd
19nogroups 20nogroups
20nonewprivs 21nonewprivs
21noroot 22noroot
@@ -32,4 +33,3 @@ private-tmp
32memory-deny-write-execute 33memory-deny-write-execute
33noexec ${HOME} 34noexec ${HOME}
34noexec /tmp 35noexec /tmp
35nodvd
diff --git a/etc/gitter.profile b/etc/gitter.profile
index 9bbe605e7..f92f4b167 100644
--- a/etc/gitter.profile
+++ b/etc/gitter.profile
@@ -14,6 +14,7 @@ include /etc/firejail/disable-programs.inc
14 14
15caps.drop all 15caps.drop all
16netfilter 16netfilter
17nodvd
17nogroups 18nogroups
18nonewprivs 19nonewprivs
19noroot 20noroot
@@ -26,4 +27,3 @@ shell none
26private-bin gitter 27private-bin gitter
27private-dev 28private-dev
28private-tmp 29private-tmp
29nodvd
diff --git a/etc/gjs.profile b/etc/gjs.profile
index 1255ec6bb..a856d35b5 100644
--- a/etc/gjs.profile
+++ b/etc/gjs.profile
@@ -19,6 +19,7 @@ include /etc/firejail/disable-programs.inc
19 19
20caps.drop all 20caps.drop all
21netfilter 21netfilter
22nodvd
22nogroups 23nogroups
23nonewprivs 24nonewprivs
24noroot 25noroot
@@ -32,4 +33,3 @@ tracelog
32private-dev 33private-dev
33# private-etc fonts 34# private-etc fonts
34private-tmp 35private-tmp
35nodvd
diff --git a/etc/globaltime.profile b/etc/globaltime.profile
index ac72c87c7..6961a56e9 100644
--- a/etc/globaltime.profile
+++ b/etc/globaltime.profile
@@ -15,6 +15,7 @@ include /etc/firejail/disable-programs.inc
15caps.drop all 15caps.drop all
16netfilter 16netfilter
17no3d 17no3d
18nodvd
18nogroups 19nogroups
19nonewprivs 20nonewprivs
20noroot 21noroot
@@ -31,4 +32,3 @@ private-tmp
31 32
32noexec ${HOME} 33noexec ${HOME}
33noexec /tmp 34noexec /tmp
34nodvd
diff --git a/etc/gnome-2048.profile b/etc/gnome-2048.profile
index 7dba3f58b..7aea3f5a8 100644
--- a/etc/gnome-2048.profile
+++ b/etc/gnome-2048.profile
@@ -19,6 +19,7 @@ include /etc/firejail/whitelist-common.inc
19caps.drop all 19caps.drop all
20netfilter 20netfilter
21no3d 21no3d
22nodvd
22nonewprivs 23nonewprivs
23noroot 24noroot
24notv 25notv
@@ -32,4 +33,3 @@ private-tmp
32 33
33noexec ${HOME} 34noexec ${HOME}
34noexec /tmp 35noexec /tmp
35nodvd
diff --git a/etc/gnome-books.profile b/etc/gnome-books.profile
index c9082995d..5c1d5f137 100644
--- a/etc/gnome-books.profile
+++ b/etc/gnome-books.profile
@@ -17,6 +17,7 @@ include /etc/firejail/disable-programs.inc
17caps.drop all 17caps.drop all
18netfilter 18netfilter
19no3d 19no3d
20nodvd
20nogroups 21nogroups
21nonewprivs 22nonewprivs
22noroot 23noroot
@@ -35,4 +36,3 @@ private-tmp
35 36
36noexec ${HOME} 37noexec ${HOME}
37noexec /tmp 38noexec /tmp
38nodvd
diff --git a/etc/gnome-calculator.profile b/etc/gnome-calculator.profile
index 21019893b..4921fb0c4 100644
--- a/etc/gnome-calculator.profile
+++ b/etc/gnome-calculator.profile
@@ -15,6 +15,7 @@ include /etc/firejail/whitelist-common.inc
15caps.drop all 15caps.drop all
16netfilter 16netfilter
17no3d 17no3d
18nodvd
18nogroups 19nogroups
19nonewprivs 20nonewprivs
20noroot 21noroot
@@ -34,4 +35,3 @@ private-tmp
34memory-deny-write-execute 35memory-deny-write-execute
35noexec ${HOME} 36noexec ${HOME}
36noexec /tmp 37noexec /tmp
37nodvd
diff --git a/etc/gnome-chess.profile b/etc/gnome-chess.profile
index 87b01bf92..688df6dfe 100644
--- a/etc/gnome-chess.profile
+++ b/etc/gnome-chess.profile
@@ -14,6 +14,7 @@ include /etc/firejail/disable-programs.inc
14 14
15caps.drop all 15caps.drop all
16no3d 16no3d
17nodvd
17nogroups 18nogroups
18nonewprivs 19nonewprivs
19noroot 20noroot
@@ -33,4 +34,3 @@ private-tmp
33 34
34noexec ${HOME} 35noexec ${HOME}
35noexec /tmp 36noexec /tmp
36nodvd
diff --git a/etc/gnome-clocks.profile b/etc/gnome-clocks.profile
index b9938e9d2..d9bac48eb 100644
--- a/etc/gnome-clocks.profile
+++ b/etc/gnome-clocks.profile
@@ -14,6 +14,7 @@ include /etc/firejail/disable-programs.inc
14caps.drop all 14caps.drop all
15netfilter 15netfilter
16no3d 16no3d
17nodvd
17nogroups 18nogroups
18nonewprivs 19nonewprivs
19noroot 20noroot
@@ -32,4 +33,3 @@ private-tmp
32 33
33noexec ${HOME} 34noexec ${HOME}
34noexec /tmp 35noexec /tmp
35nodvd
diff --git a/etc/gnome-contacts.profile b/etc/gnome-contacts.profile
index d905bfe63..90c2c2628 100644
--- a/etc/gnome-contacts.profile
+++ b/etc/gnome-contacts.profile
@@ -15,6 +15,7 @@ include /etc/firejail/whitelist-common.inc
15caps.drop all 15caps.drop all
16netfilter 16netfilter
17no3d 17no3d
18nodvd
18nonewprivs 19nonewprivs
19noroot 20noroot
20nosound 21nosound
@@ -29,4 +30,3 @@ private-tmp
29 30
30noexec ${HOME} 31noexec ${HOME}
31noexec /tmp 32noexec /tmp
32nodvd
diff --git a/etc/gnome-documents.profile b/etc/gnome-documents.profile
index e28b787fe..3254f3fbc 100644
--- a/etc/gnome-documents.profile
+++ b/etc/gnome-documents.profile
@@ -17,6 +17,7 @@ include /etc/firejail/disable-programs.inc
17caps.drop all 17caps.drop all
18netfilter 18netfilter
19no3d 19no3d
20nodvd
20nogroups 21nogroups
21nonewprivs 22nonewprivs
22noroot 23noroot
@@ -33,4 +34,3 @@ private-tmp
33 34
34noexec ${HOME} 35noexec ${HOME}
35noexec /tmp 36noexec /tmp
36nodvd
diff --git a/etc/gnome-font-viewer.profile b/etc/gnome-font-viewer.profile
index daf0ddc2a..5ccb28840 100644
--- a/etc/gnome-font-viewer.profile
+++ b/etc/gnome-font-viewer.profile
@@ -14,6 +14,7 @@ include /etc/firejail/disable-programs.inc
14caps.drop all 14caps.drop all
15netfilter 15netfilter
16no3d 16no3d
17nodvd
17nonewprivs 18nonewprivs
18noroot 19noroot
19nosound 20nosound
@@ -28,4 +29,3 @@ private-tmp
28 29
29noexec ${HOME} 30noexec ${HOME}
30noexec /tmp 31noexec /tmp
31nodvd
diff --git a/etc/gnome-maps.profile b/etc/gnome-maps.profile
index 527899aea..cdbf5cbe0 100644
--- a/etc/gnome-maps.profile
+++ b/etc/gnome-maps.profile
@@ -16,6 +16,7 @@ include /etc/firejail/disable-programs.inc
16 16
17caps.drop all 17caps.drop all
18netfilter 18netfilter
19nodvd
19nogroups 20nogroups
20nonewprivs 21nonewprivs
21noroot 22noroot
@@ -35,4 +36,3 @@ private-tmp
35 36
36noexec ${HOME} 37noexec ${HOME}
37noexec /tmp 38noexec /tmp
38nodvd
diff --git a/etc/gnome-photos.profile b/etc/gnome-photos.profile
index c1e9d7b58..0e150f525 100644
--- a/etc/gnome-photos.profile
+++ b/etc/gnome-photos.profile
@@ -16,6 +16,7 @@ include /etc/firejail/disable-programs.inc
16 16
17caps.drop all 17caps.drop all
18netfilter 18netfilter
19nodvd
19nogroups 20nogroups
20nonewprivs 21nonewprivs
21noroot 22noroot
@@ -33,4 +34,3 @@ private-tmp
33 34
34noexec ${HOME} 35noexec ${HOME}
35noexec /tmp 36noexec /tmp
36nodvd
diff --git a/etc/gnome-twitch.profile b/etc/gnome-twitch.profile
index db7739c33..9c94404d1 100644
--- a/etc/gnome-twitch.profile
+++ b/etc/gnome-twitch.profile
@@ -20,6 +20,7 @@ whitelist ${HOME}/.local/share/gnome-twitch
20include /etc/firejail/whitelist-common.inc 20include /etc/firejail/whitelist-common.inc
21 21
22caps.drop all 22caps.drop all
23nodvd
23nogroups 24nogroups
24nonewprivs 25nonewprivs
25noroot 26noroot
@@ -34,4 +35,3 @@ private-tmp
34 35
35noexec ${HOME} 36noexec ${HOME}
36noexec /tmp 37noexec /tmp
37nodvd
diff --git a/etc/gnome-weather.profile b/etc/gnome-weather.profile
index f1db7dab3..4ddbbbde2 100644
--- a/etc/gnome-weather.profile
+++ b/etc/gnome-weather.profile
@@ -17,6 +17,7 @@ include /etc/firejail/disable-programs.inc
17caps.drop all 17caps.drop all
18netfilter 18netfilter
19no3d 19no3d
20nodvd
20nogroups 21nogroups
21nonewprivs 22nonewprivs
22noroot 23noroot
@@ -36,4 +37,3 @@ private-tmp
36 37
37noexec ${HOME} 38noexec ${HOME}
38noexec /tmp 39noexec /tmp
39nodvd
diff --git a/etc/goobox.profile b/etc/goobox.profile
index c7a52c944..9bedaa431 100644
--- a/etc/goobox.profile
+++ b/etc/goobox.profile
@@ -13,6 +13,7 @@ include /etc/firejail/disable-programs.inc
13 13
14caps.drop all 14caps.drop all
15netfilter 15netfilter
16nodvd
16nogroups 17nogroups
17nonewprivs 18nonewprivs
18noroot 19noroot
@@ -26,4 +27,3 @@ tracelog
26# private-dev 27# private-dev
27# private-etc fonts 28# private-etc fonts
28# private-tmp 29# private-tmp
29nodvd
diff --git a/etc/google-chrome-beta.profile b/etc/google-chrome-beta.profile
index 9c8574d3f..a3fdb214a 100644
--- a/etc/google-chrome-beta.profile
+++ b/etc/google-chrome-beta.profile
@@ -25,6 +25,7 @@ include /etc/firejail/whitelist-common.inc
25 25
26caps.keep sys_chroot,sys_admin 26caps.keep sys_chroot,sys_admin
27netfilter 27netfilter
28nodvd
28nogroups 29nogroups
29notv 30notv
30shell none 31shell none
@@ -34,4 +35,3 @@ private-dev
34 35
35noexec ${HOME} 36noexec ${HOME}
36noexec /tmp 37noexec /tmp
37nodvd
diff --git a/etc/google-chrome-unstable.profile b/etc/google-chrome-unstable.profile
index b7ed33703..8de3c5262 100644
--- a/etc/google-chrome-unstable.profile
+++ b/etc/google-chrome-unstable.profile
@@ -25,6 +25,7 @@ include /etc/firejail/whitelist-common.inc
25 25
26caps.keep sys_chroot,sys_admin 26caps.keep sys_chroot,sys_admin
27netfilter 27netfilter
28nodvd
28nogroups 29nogroups
29notv 30notv
30shell none 31shell none
@@ -34,4 +35,3 @@ private-dev
34 35
35noexec ${HOME} 36noexec ${HOME}
36noexec /tmp 37noexec /tmp
37nodvd
diff --git a/etc/google-chrome.profile b/etc/google-chrome.profile
index 6a3c54468..1a86c546e 100644
--- a/etc/google-chrome.profile
+++ b/etc/google-chrome.profile
@@ -25,6 +25,7 @@ include /etc/firejail/whitelist-common.inc
25 25
26caps.keep sys_chroot,sys_admin 26caps.keep sys_chroot,sys_admin
27netfilter 27netfilter
28nodvd
28nogroups 29nogroups
29notv 30notv
30shell none 31shell none
@@ -34,4 +35,3 @@ private-dev
34 35
35noexec ${HOME} 36noexec ${HOME}
36noexec /tmp 37noexec /tmp
37nodvd
diff --git a/etc/google-play-music-desktop-player.profile b/etc/google-play-music-desktop-player.profile
index 641988796..704de6e40 100644
--- a/etc/google-play-music-desktop-player.profile
+++ b/etc/google-play-music-desktop-player.profile
@@ -20,6 +20,7 @@ include /etc/firejail/whitelist-common.inc
20caps.drop all 20caps.drop all
21netfilter 21netfilter
22no3d 22no3d
23nodvd
23nogroups 24nogroups
24nonewprivs 25nonewprivs
25noroot 26noroot
@@ -35,4 +36,3 @@ private-tmp
35 36
36noexec ${HOME} 37noexec ${HOME}
37noexec /tmp 38noexec /tmp
38nodvd
diff --git a/etc/gpa.profile b/etc/gpa.profile
index b33d06ba1..58dfcd3e1 100644
--- a/etc/gpa.profile
+++ b/etc/gpa.profile
@@ -14,6 +14,7 @@ include /etc/firejail/disable-programs.inc
14 14
15caps.drop all 15caps.drop all
16netfilter 16netfilter
17nodvd
17nogroups 18nogroups
18nonewprivs 19nonewprivs
19noroot 20noroot
@@ -26,4 +27,3 @@ tracelog
26 27
27# private-bin gpa,gpg 28# private-bin gpa,gpg
28private-dev 29private-dev
29nodvd
diff --git a/etc/gpg-agent.profile b/etc/gpg-agent.profile
index 852bbc210..13bceaa5a 100644
--- a/etc/gpg-agent.profile
+++ b/etc/gpg-agent.profile
@@ -17,6 +17,7 @@ include /etc/firejail/disable-programs.inc
17caps.drop all 17caps.drop all
18netfilter 18netfilter
19no3d 19no3d
20nodvd
20nogroups 21nogroups
21nonewprivs 22nonewprivs
22noroot 23noroot
@@ -29,4 +30,3 @@ tracelog
29 30
30# private-bin gpg-agent,gpg 31# private-bin gpg-agent,gpg
31private-dev 32private-dev
32nodvd
diff --git a/etc/gpg.profile b/etc/gpg.profile
index 91048db14..d99afdfe2 100644
--- a/etc/gpg.profile
+++ b/etc/gpg.profile
@@ -17,6 +17,7 @@ include /etc/firejail/disable-programs.inc
17caps.drop all 17caps.drop all
18netfilter 18netfilter
19no3d 19no3d
20nodvd
20nogroups 21nogroups
21nonewprivs 22nonewprivs
22noroot 23noroot
@@ -29,4 +30,3 @@ tracelog
29 30
30# private-bin gpg,gpg-agent 31# private-bin gpg,gpg-agent
31private-dev 32private-dev
32nodvd
diff --git a/etc/gpicview.profile b/etc/gpicview.profile
index b8c1d60c0..ec9245e58 100644
--- a/etc/gpicview.profile
+++ b/etc/gpicview.profile
@@ -14,6 +14,7 @@ include /etc/firejail/disable-programs.inc
14 14
15caps.drop all 15caps.drop all
16net none 16net none
17nodvd
17nogroups 18nogroups
18nonewprivs 19nonewprivs
19noroot 20noroot
@@ -28,4 +29,3 @@ private-bin gpicview
28private-dev 29private-dev
29private-etc fonts 30private-etc fonts
30private-tmp 31private-tmp
31nodvd
diff --git a/etc/gpredict.profile b/etc/gpredict.profile
index ed9ef1a1e..f204366c5 100644
--- a/etc/gpredict.profile
+++ b/etc/gpredict.profile
@@ -17,6 +17,7 @@ include /etc/firejail/whitelist-common.inc
17 17
18caps.drop all 18caps.drop all
19netfilter 19netfilter
20nodvd
20nogroups 21nogroups
21nonewprivs 22nonewprivs
22noroot 23noroot
@@ -34,4 +35,3 @@ private-tmp
34 35
35noexec ${HOME} 36noexec ${HOME}
36noexec /tmp 37noexec /tmp
37nodvd
diff --git a/etc/gthumb.profile b/etc/gthumb.profile
index 4b922189a..63ad07894 100644
--- a/etc/gthumb.profile
+++ b/etc/gthumb.profile
@@ -15,6 +15,7 @@ include /etc/firejail/disable-passwdmgr.inc
15include /etc/firejail/disable-programs.inc 15include /etc/firejail/disable-programs.inc
16 16
17caps.drop all 17caps.drop all
18nodvd
18nogroups 19nogroups
19nonewprivs 20nonewprivs
20noroot 21noroot
@@ -28,4 +29,3 @@ tracelog
28private-bin gthumb 29private-bin gthumb
29private-dev 30private-dev
30private-tmp 31private-tmp
31nodvd
diff --git a/etc/gucharmap.profile b/etc/gucharmap.profile
index d9982933d..b6be37439 100644
--- a/etc/gucharmap.profile
+++ b/etc/gucharmap.profile
@@ -14,6 +14,7 @@ include /etc/firejail/disable-programs.inc
14caps.drop all 14caps.drop all
15netfilter 15netfilter
16no3d 16no3d
17nodvd
17nogroups 18nogroups
18nonewprivs 19nonewprivs
19noroot 20noroot
@@ -31,4 +32,3 @@ private-tmp
31 32
32noexec ${HOME} 33noexec ${HOME}
33noexec /tmp 34noexec /tmp
34nodvd
diff --git a/etc/gwenview.profile b/etc/gwenview.profile
index f5507850b..745468912 100644
--- a/etc/gwenview.profile
+++ b/etc/gwenview.profile
@@ -20,6 +20,7 @@ include /etc/firejail/disable-passwdmgr.inc
20include /etc/firejail/disable-programs.inc 20include /etc/firejail/disable-programs.inc
21 21
22caps.drop all 22caps.drop all
23nodvd
23nogroups 24nogroups
24nonewprivs 25nonewprivs
25noroot 26noroot
@@ -36,4 +37,3 @@ private-dev
36 37
37noexec ${HOME} 38noexec ${HOME}
38noexec /tmp 39noexec /tmp
39nodvd
diff --git a/etc/gzip.profile b/etc/gzip.profile
index 5560c8252..3f6ecec2c 100644
--- a/etc/gzip.profile
+++ b/etc/gzip.profile
@@ -11,6 +11,7 @@ blacklist /tmp/.X11-unix
11ignore noroot 11ignore noroot
12net none 12net none
13no3d 13no3d
14nodvd
14nosound 15nosound
15notv 16notv
16shell none 17shell none
@@ -19,4 +20,3 @@ tracelog
19private-dev 20private-dev
20 21
21include /etc/firejail/default.profile 22include /etc/firejail/default.profile
22nodvd
diff --git a/etc/hashcat.profile b/etc/hashcat.profile
index 677c47b13..ae631054b 100644
--- a/etc/hashcat.profile
+++ b/etc/hashcat.profile
@@ -14,6 +14,7 @@ include /etc/firejail/disable-programs.inc
14 14
15caps.drop all 15caps.drop all
16net none 16net none
17nodvd
17nogroups 18nogroups
18nonewprivs 19nonewprivs
19noroot 20noroot
@@ -30,4 +31,3 @@ private-tmp
30 31
31noexec ${HOME} 32noexec ${HOME}
32noexec /tmp 33noexec /tmp
33nodvd
diff --git a/etc/hedgewars.profile b/etc/hedgewars.profile
index 90abe5d27..e2775ffce 100644
--- a/etc/hedgewars.profile
+++ b/etc/hedgewars.profile
@@ -18,6 +18,7 @@ include /etc/firejail/whitelist-common.inc
18 18
19caps.drop all 19caps.drop all
20netfilter 20netfilter
21nodvd
21nogroups 22nogroups
22nonewprivs 23nonewprivs
23noroot 24noroot
@@ -28,4 +29,3 @@ tracelog
28disable-mnt 29disable-mnt
29private-dev 30private-dev
30private-tmp 31private-tmp
31nodvd
diff --git a/etc/hexchat.profile b/etc/hexchat.profile
index 875d07e89..fc817d9f9 100644
--- a/etc/hexchat.profile
+++ b/etc/hexchat.profile
@@ -20,6 +20,7 @@ include /etc/firejail/whitelist-common.inc
20caps.drop all 20caps.drop all
21netfilter 21netfilter
22no3d 22no3d
23nodvd
23nogroups 24nogroups
24nonewprivs 25nonewprivs
25noroot 26noroot
@@ -39,4 +40,3 @@ private-tmp
39 40
40noexec ${HOME} 41noexec ${HOME}
41noexec /tmp 42noexec /tmp
42nodvd
diff --git a/etc/highlight.profile b/etc/highlight.profile
index bbd08cb6b..83b023a90 100644
--- a/etc/highlight.profile
+++ b/etc/highlight.profile
@@ -15,6 +15,7 @@ include /etc/firejail/disable-programs.inc
15caps.drop all 15caps.drop all
16net none 16net none
17no3d 17no3d
18nodvd
18nogroups 19nogroups
19nonewprivs 20nonewprivs
20noroot 21noroot
@@ -29,4 +30,3 @@ private-bin highlight
29private-dev 30private-dev
30# private-etc none 31# private-etc none
31private-tmp 32private-tmp
32nodvd
diff --git a/etc/hugin.profile b/etc/hugin.profile
index 064488daa..d3cd181b1 100644
--- a/etc/hugin.profile
+++ b/etc/hugin.profile
@@ -14,6 +14,7 @@ include /etc/firejail/disable-programs.inc
14 14
15caps.drop all 15caps.drop all
16netfilter 16netfilter
17nodvd
17nogroups 18nogroups
18nonewprivs 19nonewprivs
19noroot 20noroot
@@ -29,4 +30,3 @@ private-tmp
29 30
30noexec ${HOME} 31noexec ${HOME}
31noexec /tmp 32noexec /tmp
32nodvd
diff --git a/etc/icecat.profile b/etc/icecat.profile
index 0477bfc4c..ab7e62180 100644
--- a/etc/icecat.profile
+++ b/etc/icecat.profile
@@ -37,6 +37,7 @@ include /etc/firejail/whitelist-common.inc
37 37
38caps.drop all 38caps.drop all
39netfilter 39netfilter
40nodvd
40nonewprivs 41nonewprivs
41noroot 42noroot
42notv 43notv
@@ -48,4 +49,3 @@ tracelog
48 49
49noexec ${HOME} 50noexec ${HOME}
50noexec /tmp 51noexec /tmp
51nodvd
diff --git a/etc/idea.sh.profile b/etc/idea.sh.profile
index 20ec4f33f..928ec7327 100644
--- a/etc/idea.sh.profile
+++ b/etc/idea.sh.profile
@@ -20,6 +20,7 @@ include /etc/firejail/disable-programs.inc
20 20
21caps.drop all 21caps.drop all
22netfilter 22netfilter
23nodvd
23nogroups 24nogroups
24nonewprivs 25nonewprivs
25noroot 26noroot
@@ -33,4 +34,3 @@ private-dev
33# private-tmp 34# private-tmp
34 35
35noexec /tmp 36noexec /tmp
36nodvd
diff --git a/etc/img2txt.profile b/etc/img2txt.profile
index 342ddf9a3..bd454a2c8 100644
--- a/etc/img2txt.profile
+++ b/etc/img2txt.profile
@@ -13,6 +13,7 @@ include /etc/firejail/disable-programs.inc
13 13
14caps.drop all 14caps.drop all
15net none 15net none
16nodvd
16nogroups 17nogroups
17nonewprivs 18nonewprivs
18noroot 19noroot
@@ -27,4 +28,3 @@ tracelog
27private-dev 28private-dev
28# private-etc none 29# private-etc none
29private-tmp 30private-tmp
30nodvd
diff --git a/etc/inkscape.profile b/etc/inkscape.profile
index 315b0193a..1d24f5d7d 100644
--- a/etc/inkscape.profile
+++ b/etc/inkscape.profile
@@ -14,6 +14,7 @@ include /etc/firejail/disable-programs.inc
14 14
15caps.drop all 15caps.drop all
16netfilter 16netfilter
17nodvd
17nogroups 18nogroups
18nonewprivs 19nonewprivs
19noroot 20noroot
@@ -29,4 +30,3 @@ private-tmp
29 30
30noexec ${HOME} 31noexec ${HOME}
31noexec /tmp 32noexec /tmp
32nodvd
diff --git a/etc/inox.profile b/etc/inox.profile
index aeee91526..6273c4de6 100644
--- a/etc/inox.profile
+++ b/etc/inox.profile
@@ -22,5 +22,5 @@ whitelist ~/.pki
22include /etc/firejail/whitelist-common.inc 22include /etc/firejail/whitelist-common.inc
23 23
24netfilter 24netfilter
25notv
26nodvd 25nodvd
26notv
diff --git a/etc/iridium.profile b/etc/iridium.profile
index 395481793..db9c5c7cf 100644
--- a/etc/iridium.profile
+++ b/etc/iridium.profile
@@ -23,5 +23,5 @@ whitelist ~/.pki
23include /etc/firejail/whitelist-common.inc 23include /etc/firejail/whitelist-common.inc
24 24
25netfilter 25netfilter
26notv
27nodvd 26nodvd
27notv
diff --git a/etc/jd-gui.profile b/etc/jd-gui.profile
index 2422d5b48..c9af51596 100644
--- a/etc/jd-gui.profile
+++ b/etc/jd-gui.profile
@@ -16,6 +16,7 @@ include /etc/firejail/disable-programs.inc
16caps.drop all 16caps.drop all
17net none 17net none
18no3d 18no3d
19nodvd
19nogroups 20nogroups
20nonewprivs 21nonewprivs
21noroot 22noroot
@@ -31,4 +32,3 @@ private-tmp
31 32
32noexec ${HOME} 33noexec ${HOME}
33noexec /tmp 34noexec /tmp
34nodvd
diff --git a/etc/jitsi.profile b/etc/jitsi.profile
index bd636251c..78a57ff46 100644
--- a/etc/jitsi.profile
+++ b/etc/jitsi.profile
@@ -13,6 +13,7 @@ include /etc/firejail/disable-passwdmgr.inc
13include /etc/firejail/disable-programs.inc 13include /etc/firejail/disable-programs.inc
14 14
15caps.drop all 15caps.drop all
16nodvd
16nogroups 17nogroups
17nonewprivs 18nonewprivs
18noroot 19noroot
@@ -24,4 +25,3 @@ tracelog
24 25
25disable-mnt 26disable-mnt
26private-tmp 27private-tmp
27nodvd
diff --git a/etc/k3b.profile b/etc/k3b.profile
index a547cd7b1..87132e775 100644
--- a/etc/k3b.profile
+++ b/etc/k3b.profile
@@ -16,6 +16,7 @@ include /etc/firejail/disable-programs.inc
16 16
17caps.drop all 17caps.drop all
18no3d 18no3d
19nodvd
19nonewprivs 20nonewprivs
20noroot 21noroot
21nosound 22nosound
@@ -29,4 +30,3 @@ tracelog
29# private-bin 30# private-bin
30# private-etc 31# private-etc
31# private-tmp 32# private-tmp
32nodvd
diff --git a/etc/kate.profile b/etc/kate.profile
index 84057f402..ec5d09ce2 100644
--- a/etc/kate.profile
+++ b/etc/kate.profile
@@ -19,6 +19,7 @@ include /etc/firejail/disable-programs.inc
19 19
20caps.drop all 20caps.drop all
21netfilter 21netfilter
22nodvd
22nogroups 23nogroups
23nonewprivs 24nonewprivs
24noroot 25noroot
@@ -34,4 +35,3 @@ tracelog
34private-dev 35private-dev
35# private-etc fonts 36# private-etc fonts
36private-tmp 37private-tmp
37nodvd
diff --git a/etc/kcalc.profile b/etc/kcalc.profile
index fbd4d3e19..f334c4c72 100644
--- a/etc/kcalc.profile
+++ b/etc/kcalc.profile
@@ -14,6 +14,7 @@ include /etc/firejail/disable-programs.inc
14caps.drop all 14caps.drop all
15netfilter 15netfilter
16no3d 16no3d
17nodvd
17nogroups 18nogroups
18nonewprivs 19nonewprivs
19noroot 20noroot
@@ -31,4 +32,3 @@ private-tmp
31 32
32noexec ${HOME} 33noexec ${HOME}
33noexec /tmp 34noexec /tmp
34nodvd
diff --git a/etc/keepass.profile b/etc/keepass.profile
index bdd6c9995..c133ce0fb 100644
--- a/etc/keepass.profile
+++ b/etc/keepass.profile
@@ -21,6 +21,7 @@ include /etc/firejail/disable-programs.inc
21caps.drop all 21caps.drop all
22netfilter 22netfilter
23no3d 23no3d
24nodvd
24nogroups 25nogroups
25nonewprivs 26nonewprivs
26noroot 27noroot
@@ -36,4 +37,3 @@ private-tmp
36 37
37noexec ${HOME} 38noexec ${HOME}
38noexec /tmp 39noexec /tmp
39nodvd
diff --git a/etc/keepassx.profile b/etc/keepassx.profile
index 3eadcace7..9d943d89c 100644
--- a/etc/keepassx.profile
+++ b/etc/keepassx.profile
@@ -19,6 +19,7 @@ caps.drop all
19machine-id 19machine-id
20net none 20net none
21no3d 21no3d
22nodvd
22nogroups 23nogroups
23nonewprivs 24nonewprivs
24noroot 25noroot
@@ -37,4 +38,3 @@ private-tmp
37 38
38noexec ${HOME} 39noexec ${HOME}
39noexec /tmp 40noexec /tmp
40nodvd
diff --git a/etc/keepassx2.profile b/etc/keepassx2.profile
index 7f8380bfa..e20e06b76 100644
--- a/etc/keepassx2.profile
+++ b/etc/keepassx2.profile
@@ -18,6 +18,7 @@ include /etc/firejail/disable-programs.inc
18caps.drop all 18caps.drop all
19net none 19net none
20no3d 20no3d
21nodvd
21nogroups 22nogroups
22nonewprivs 23nonewprivs
23noroot 24noroot
@@ -35,4 +36,3 @@ private-tmp
35 36
36noexec ${HOME} 37noexec ${HOME}
37noexec /tmp 38noexec /tmp
38nodvd
diff --git a/etc/keepassxc.profile b/etc/keepassxc.profile
index fc44bfdd7..f79cda80d 100644
--- a/etc/keepassxc.profile
+++ b/etc/keepassxc.profile
@@ -18,6 +18,7 @@ include /etc/firejail/disable-programs.inc
18caps.drop all 18caps.drop all
19net none 19net none
20no3d 20no3d
21nodvd
21nogroups 22nogroups
22nonewprivs 23nonewprivs
23noroot 24noroot
@@ -36,4 +37,3 @@ private-tmp
36memory-deny-write-execute 37memory-deny-write-execute
37noexec ${HOME} 38noexec ${HOME}
38noexec /tmp 39noexec /tmp
39nodvd
diff --git a/etc/kmail.profile b/etc/kmail.profile
index e5e8b0fef..fdc96c97f 100644
--- a/etc/kmail.profile
+++ b/etc/kmail.profile
@@ -14,6 +14,7 @@ include /etc/firejail/disable-programs.inc
14 14
15caps.drop all 15caps.drop all
16netfilter 16netfilter
17nodvd
17nogroups 18nogroups
18nonewprivs 19nonewprivs
19noroot 20noroot
@@ -24,4 +25,3 @@ tracelog
24 25
25private-dev 26private-dev
26# private-tmp 27# private-tmp
27nodvd
diff --git a/etc/knotes.profile b/etc/knotes.profile
index c482a2f02..a1d303ded 100644
--- a/etc/knotes.profile
+++ b/etc/knotes.profile
@@ -14,6 +14,7 @@ include /etc/firejail/disable-programs.inc
14 14
15caps.drop all 15caps.drop all
16netfilter 16netfilter
17nodvd
17nogroups 18nogroups
18nonewprivs 19nonewprivs
19noroot 20noroot
@@ -28,4 +29,3 @@ tracelog
28private-dev 29private-dev
29# private-etc fonts 30# private-etc fonts
30private-tmp 31private-tmp
31nodvd
diff --git a/etc/konversation.profile b/etc/konversation.profile
index b4f0b5524..8bc263d4d 100644
--- a/etc/konversation.profile
+++ b/etc/konversation.profile
@@ -13,6 +13,7 @@ include /etc/firejail/disable-programs.inc
13 13
14caps.drop all 14caps.drop all
15netfilter 15netfilter
16nodvd
16nogroups 17nogroups
17noroot 18noroot
18notv 19notv
@@ -20,4 +21,3 @@ protocol unix,inet,inet6
20seccomp 21seccomp
21 22
22private-tmp 23private-tmp
23nodvd
diff --git a/etc/ktorrent.profile b/etc/ktorrent.profile
index ae8d929db..c5b887118 100644
--- a/etc/ktorrent.profile
+++ b/etc/ktorrent.profile
@@ -35,6 +35,7 @@ include /etc/firejail/whitelist-common.inc
35caps.drop all 35caps.drop all
36netfilter 36netfilter
37no3d 37no3d
38nodvd
38nogroups 39nogroups
39nonewprivs 40nonewprivs
40noroot 41noroot
@@ -50,4 +51,3 @@ private-tmp
50 51
51noexec ${HOME} 52noexec ${HOME}
52noexec /tmp 53noexec /tmp
53nodvd
diff --git a/etc/kwrite.profile b/etc/kwrite.profile
index b87d453ec..6ba076dc0 100644
--- a/etc/kwrite.profile
+++ b/etc/kwrite.profile
@@ -19,6 +19,7 @@ include /etc/firejail/disable-programs.inc
19 19
20caps.drop all 20caps.drop all
21netfilter 21netfilter
22nodvd
22nogroups 23nogroups
23nonewprivs 24nonewprivs
24noroot 25noroot
@@ -34,4 +35,3 @@ tracelog
34private-dev 35private-dev
35# private-etc fonts 36# private-etc fonts
36private-tmp 37private-tmp
37nodvd
diff --git a/etc/leafpad.profile b/etc/leafpad.profile
index d04ea862d..e7557651b 100644
--- a/etc/leafpad.profile
+++ b/etc/leafpad.profile
@@ -15,6 +15,7 @@ include /etc/firejail/disable-programs.inc
15caps.drop all 15caps.drop all
16netfilter 16netfilter
17no3d 17no3d
18nodvd
18nogroups 19nogroups
19nonewprivs 20nonewprivs
20noroot 21noroot
@@ -29,4 +30,3 @@ private-dev
29 30
30noexec ${HOME} 31noexec ${HOME}
31noexec /tmp 32noexec /tmp
32nodvd
diff --git a/etc/less.profile b/etc/less.profile
index 725673318..e1c42ed76 100644
--- a/etc/less.profile
+++ b/etc/less.profile
@@ -11,6 +11,7 @@ blacklist /tmp/.X11-unix
11ignore noroot 11ignore noroot
12net none 12net none
13no3d 13no3d
14nodvd
14nosound 15nosound
15notv 16notv
16novideo 17novideo
@@ -28,4 +29,3 @@ noexec ${HOME}
28noexec /tmp 29noexec /tmp
29 30
30include /etc/firejail/default.profile 31include /etc/firejail/default.profile
31nodvd
diff --git a/etc/libreoffice.profile b/etc/libreoffice.profile
index b82e402fb..ec7356002 100644
--- a/etc/libreoffice.profile
+++ b/etc/libreoffice.profile
@@ -16,6 +16,7 @@ include /etc/firejail/disable-programs.inc
16 16
17caps.drop all 17caps.drop all
18netfilter 18netfilter
19nodvd
19nogroups 20nogroups
20nonewprivs 21nonewprivs
21noroot 22noroot
@@ -29,4 +30,3 @@ private-dev
29 30
30noexec ${HOME} 31noexec ${HOME}
31noexec /tmp 32noexec /tmp
32nodvd
diff --git a/etc/liferea.profile b/etc/liferea.profile
index cbc3a2bb5..afd5fed6b 100644
--- a/etc/liferea.profile
+++ b/etc/liferea.profile
@@ -25,6 +25,7 @@ include /etc/firejail/whitelist-common.inc
25caps.drop all 25caps.drop all
26netfilter 26netfilter
27# no3d 27# no3d
28nodvd
28nogroups 29nogroups
29nonewprivs 30nonewprivs
30noroot 31noroot
@@ -41,4 +42,3 @@ private-tmp
41 42
42noexec ${HOME} 43noexec ${HOME}
43noexec /tmp 44noexec /tmp
44nodvd
diff --git a/etc/luminance-hdr.profile b/etc/luminance-hdr.profile
index 6fa4b5e86..bd32e0c70 100644
--- a/etc/luminance-hdr.profile
+++ b/etc/luminance-hdr.profile
@@ -14,6 +14,7 @@ include /etc/firejail/disable-programs.inc
14 14
15caps.drop all 15caps.drop all
16netfilter 16netfilter
17nodvd
17nogroups 18nogroups
18nonewprivs 19nonewprivs
19noroot 20noroot
@@ -30,4 +31,3 @@ private-tmp
30 31
31noexec ${HOME} 32noexec ${HOME}
32noexec /tmp 33noexec /tmp
33nodvd
diff --git a/etc/lximage-qt.profile b/etc/lximage-qt.profile
index 9c8dce88b..734f16e92 100644
--- a/etc/lximage-qt.profile
+++ b/etc/lximage-qt.profile
@@ -15,6 +15,7 @@ include /etc/firejail/disable-programs.inc
15caps.drop all 15caps.drop all
16netfilter 16netfilter
17no3d 17no3d
18nodvd
18nogroups 19nogroups
19nonewprivs 20nonewprivs
20noroot 21noroot
@@ -30,4 +31,3 @@ private-tmp
30 31
31noexec ${HOME} 32noexec ${HOME}
32noexec /tmp 33noexec /tmp
33nodvd
diff --git a/etc/lxmusic.profile b/etc/lxmusic.profile
index 67c5e0e9a..901bdb408 100644
--- a/etc/lxmusic.profile
+++ b/etc/lxmusic.profile
@@ -16,6 +16,7 @@ include /etc/firejail/disable-programs.inc
16caps.drop all 16caps.drop all
17netfilter 17netfilter
18no3d 18no3d
19nodvd
19nogroups 20nogroups
20nonewprivs 21nonewprivs
21noroot 22noroot
@@ -30,4 +31,3 @@ private-tmp
30 31
31noexec ${HOME} 32noexec ${HOME}
32noexec /tmp 33noexec /tmp
33nodvd
diff --git a/etc/lxterminal.profile b/etc/lxterminal.profile
index dac9bf957..dbbd1ace0 100644
--- a/etc/lxterminal.profile
+++ b/etc/lxterminal.profile
@@ -13,7 +13,7 @@ include /etc/firejail/disable-programs.inc
13caps.drop all 13caps.drop all
14netfilter 14netfilter
15# noroot - somehow this breaks on Debian Jessie! 15# noroot - somehow this breaks on Debian Jessie!
16nodvd
16notv 17notv
17protocol unix,inet,inet6 18protocol unix,inet,inet6
18seccomp 19seccomp
19nodvd
diff --git a/etc/lynx.profile b/etc/lynx.profile
index 4b981684a..db01a5b8f 100644
--- a/etc/lynx.profile
+++ b/etc/lynx.profile
@@ -15,6 +15,7 @@ include /etc/firejail/disable-programs.inc
15caps.drop all 15caps.drop all
16netfilter 16netfilter
17no3d 17no3d
18nodvd
18nogroups 19nogroups
19nonewprivs 20nonewprivs
20noroot 21noroot
@@ -29,4 +30,3 @@ tracelog
29private-dev 30private-dev
30# private-etc none 31# private-etc none
31private-tmp 32private-tmp
32nodvd
diff --git a/etc/mate-calc.profile b/etc/mate-calc.profile
index e56737691..caf3095a5 100644
--- a/etc/mate-calc.profile
+++ b/etc/mate-calc.profile
@@ -15,6 +15,7 @@ include /etc/firejail/disable-programs.inc
15caps.drop all 15caps.drop all
16netfilter 16netfilter
17no3d 17no3d
18nodvd
18nogroups 19nogroups
19nonewprivs 20nonewprivs
20noroot 21noroot
@@ -31,4 +32,3 @@ private-tmp
31 32
32noexec ${HOME} 33noexec ${HOME}
33noexec /tmp 34noexec /tmp
34nodvd
diff --git a/etc/mate-color-select.profile b/etc/mate-color-select.profile
index 207ea9c67..26ce42fbf 100644
--- a/etc/mate-color-select.profile
+++ b/etc/mate-color-select.profile
@@ -14,6 +14,7 @@ include /etc/firejail/disable-programs.inc
14caps.drop all 14caps.drop all
15netfilter 15netfilter
16no3d 16no3d
17nodvd
17nogroups 18nogroups
18nonewprivs 19nonewprivs
19noroot 20noroot
@@ -31,4 +32,3 @@ private-tmp
31 32
32noexec ${HOME} 33noexec ${HOME}
33noexec /tmp 34noexec /tmp
34nodvd
diff --git a/etc/mate-dictionary.profile b/etc/mate-dictionary.profile
index 8b18c7f4e..f0de57e0d 100644
--- a/etc/mate-dictionary.profile
+++ b/etc/mate-dictionary.profile
@@ -15,6 +15,7 @@ include /etc/firejail/disable-programs.inc
15caps.drop all 15caps.drop all
16netfilter 16netfilter
17no3d 17no3d
18nodvd
18nogroups 19nogroups
19nonewprivs 20nonewprivs
20noroot 21noroot
@@ -31,4 +32,3 @@ private-tmp
31 32
32noexec ${HOME} 33noexec ${HOME}
33noexec /tmp 34noexec /tmp
34nodvd
diff --git a/etc/mcabber.profile b/etc/mcabber.profile
index c9ba56710..bd1ada2b5 100644
--- a/etc/mcabber.profile
+++ b/etc/mcabber.profile
@@ -15,6 +15,7 @@ include /etc/firejail/disable-programs.inc
15 15
16caps.drop all 16caps.drop all
17netfilter 17netfilter
18nodvd
18nonewprivs 19nonewprivs
19noroot 20noroot
20nosound 21nosound
@@ -26,4 +27,3 @@ shell none
26private-bin mcabber 27private-bin mcabber
27private-dev 28private-dev
28private-etc null 29private-etc null
29nodvd
diff --git a/etc/mediainfo.profile b/etc/mediainfo.profile
index 36e237fef..d6a55610f 100644
--- a/etc/mediainfo.profile
+++ b/etc/mediainfo.profile
@@ -15,6 +15,7 @@ include /etc/firejail/disable-programs.inc
15caps.drop all 15caps.drop all
16net none 16net none
17no3d 17no3d
18nodvd
18nogroups 19nogroups
19nonewprivs 20nonewprivs
20noroot 21noroot
@@ -29,4 +30,3 @@ private-bin mediainfo
29private-dev 30private-dev
30private-etc none 31private-etc none
31private-tmp 32private-tmp
32nodvd
diff --git a/etc/mediathekview.profile b/etc/mediathekview.profile
index a4077c416..b90e21e66 100644
--- a/etc/mediathekview.profile
+++ b/etc/mediathekview.profile
@@ -21,6 +21,7 @@ include /etc/firejail/disable-programs.inc
21 21
22caps.drop all 22caps.drop all
23netfilter 23netfilter
24nodvd
24nonewprivs 25nonewprivs
25noroot 26noroot
26notv 27notv
@@ -34,4 +35,3 @@ private-tmp
34 35
35noexec ${HOME} 36noexec ${HOME}
36noexec /tmp 37noexec /tmp
37nodvd
diff --git a/etc/meld.profile b/etc/meld.profile
index 92aefaf78..488b2e365 100644
--- a/etc/meld.profile
+++ b/etc/meld.profile
@@ -15,6 +15,7 @@ include /etc/firejail/disable-programs.inc
15caps.drop all 15caps.drop all
16net none 16net none
17no3d 17no3d
18nodvd
18nogroups 19nogroups
19nonewprivs 20nonewprivs
20noroot 21noroot
@@ -30,4 +31,3 @@ private-tmp
30 31
31noexec ${HOME} 32noexec ${HOME}
32noexec /tmp 33noexec /tmp
33nodvd
diff --git a/etc/midori.profile b/etc/midori.profile
index 3b0b96a52..8ddb37776 100644
--- a/etc/midori.profile
+++ b/etc/midori.profile
@@ -35,10 +35,10 @@ include /etc/firejail/whitelist-common.inc
35 35
36caps.drop all 36caps.drop all
37netfilter 37netfilter
38nodvd
38nonewprivs 39nonewprivs
39# noroot - problems on Ubuntu 14.04 40# noroot - problems on Ubuntu 14.04
40notv 41notv
41protocol unix,inet,inet6,netlink 42protocol unix,inet,inet6,netlink
42seccomp 43seccomp
43tracelog 44tracelog
44nodvd
diff --git a/etc/mousepad.profile b/etc/mousepad.profile
index 325b9d60e..36365fc2f 100644
--- a/etc/mousepad.profile
+++ b/etc/mousepad.profile
@@ -14,6 +14,7 @@ include /etc/firejail/disable-programs.inc
14 14
15caps.drop all 15caps.drop all
16netfilter 16netfilter
17nodvd
17nogroups 18nogroups
18nonewprivs 19nonewprivs
19noroot 20noroot
@@ -27,4 +28,3 @@ tracelog
27private-bin mousepad 28private-bin mousepad
28private-dev 29private-dev
29private-tmp 30private-tmp
30nodvd
diff --git a/etc/multimc5.profile b/etc/multimc5.profile
index a51defafa..fcb351b4d 100644
--- a/etc/multimc5.profile
+++ b/etc/multimc5.profile
@@ -22,6 +22,7 @@ include /etc/firejail/whitelist-common.inc
22 22
23caps.drop all 23caps.drop all
24netfilter 24netfilter
25nodvd
25nogroups 26nogroups
26nonewprivs 27nonewprivs
27noroot 28noroot
@@ -37,4 +38,3 @@ private-tmp
37 38
38noexec ${HOME} 39noexec ${HOME}
39noexec /tmp 40noexec /tmp
40nodvd
diff --git a/etc/mumble.profile b/etc/mumble.profile
index 745b22256..e58dc93f4 100644
--- a/etc/mumble.profile
+++ b/etc/mumble.profile
@@ -22,6 +22,7 @@ include /etc/firejail/whitelist-common.inc
22caps.drop all 22caps.drop all
23netfilter 23netfilter
24no3d 24no3d
25nodvd
25nogroups 26nogroups
26nonewprivs 27nonewprivs
27noroot 28noroot
@@ -38,4 +39,3 @@ private-tmp
38memory-deny-write-execute 39memory-deny-write-execute
39noexec ${HOME} 40noexec ${HOME}
40noexec /tmp 41noexec /tmp
41nodvd
diff --git a/etc/mupdf.profile b/etc/mupdf.profile
index 050addfe4..c7bb458df 100644
--- a/etc/mupdf.profile
+++ b/etc/mupdf.profile
@@ -13,6 +13,7 @@ include /etc/firejail/disable-programs.inc
13 13
14caps.drop all 14caps.drop all
15net none 15net none
16nodvd
16nogroups 17nogroups
17nonewprivs 18nonewprivs
18noroot 19noroot
@@ -31,4 +32,3 @@ private-tmp
31 32
32# mupdf will never write anything 33# mupdf will never write anything
33read-only ${HOME} 34read-only ${HOME}
34nodvd
diff --git a/etc/mupen64plus.profile b/etc/mupen64plus.profile
index ad54094f0..9f3be0d27 100644
--- a/etc/mupen64plus.profile
+++ b/etc/mupen64plus.profile
@@ -22,8 +22,8 @@ include /etc/firejail/whitelist-common.inc
22 22
23caps.drop all 23caps.drop all
24net none 24net none
25nodvd
25nonewprivs 26nonewprivs
26noroot 27noroot
27notv 28notv
28seccomp 29seccomp
29nodvd
diff --git a/etc/mutt.profile b/etc/mutt.profile
index 6387fb40b..206edefae 100644
--- a/etc/mutt.profile
+++ b/etc/mutt.profile
@@ -38,6 +38,7 @@ include /etc/firejail/disable-programs.inc
38caps.drop all 38caps.drop all
39netfilter 39netfilter
40no3d 40no3d
41nodvd
41nogroups 42nogroups
42nonewprivs 43nonewprivs
43noroot 44noroot
@@ -48,4 +49,3 @@ seccomp
48shell none 49shell none
49 50
50private-dev 51private-dev
51nodvd
diff --git a/etc/nautilus.profile b/etc/nautilus.profile
index 616d06e99..57d6faa17 100644
--- a/etc/nautilus.profile
+++ b/etc/nautilus.profile
@@ -20,6 +20,7 @@ include /etc/firejail/disable-passwdmgr.inc
20 20
21caps.drop all 21caps.drop all
22netfilter 22netfilter
23nodvd
23nogroups 24nogroups
24nonewprivs 25nonewprivs
25noroot 26noroot
@@ -34,4 +35,3 @@ tracelog
34# private-dev 35# private-dev
35# private-etc fonts 36# private-etc fonts
36# private-tmp 37# private-tmp
37nodvd
diff --git a/etc/nemo.profile b/etc/nemo.profile
index d206e3764..b11ad645a 100644
--- a/etc/nemo.profile
+++ b/etc/nemo.profile
@@ -17,6 +17,7 @@ include /etc/firejail/disable-passwdmgr.inc
17caps.drop all 17caps.drop all
18netfilter 18netfilter
19no3d 19no3d
20nodvd
20nogroups 21nogroups
21nonewprivs 22nonewprivs
22noroot 23noroot
@@ -29,4 +30,3 @@ shell none
29 30
30noexec ${HOME} 31noexec ${HOME}
31noexec /tmp 32noexec /tmp
32nodvd
diff --git a/etc/netsurf.profile b/etc/netsurf.profile
index 36a564715..64aa068b1 100644
--- a/etc/netsurf.profile
+++ b/etc/netsurf.profile
@@ -21,10 +21,10 @@ include /etc/firejail/whitelist-common.inc
21 21
22caps.drop all 22caps.drop all
23netfilter 23netfilter
24nodvd
24nonewprivs 25nonewprivs
25noroot 26noroot
26notv 27notv
27protocol unix,inet,inet6,netlink 28protocol unix,inet,inet6,netlink
28seccomp 29seccomp
29tracelog 30tracelog
30nodvd
diff --git a/etc/nylas.profile b/etc/nylas.profile
index 43445cb1a..5d84d1326 100644
--- a/etc/nylas.profile
+++ b/etc/nylas.profile
@@ -20,6 +20,7 @@ include /etc/firejail/whitelist-common.inc
20 20
21caps.drop all 21caps.drop all
22netfilter 22netfilter
23nodvd
23nogroups 24nogroups
24nonewprivs 25nonewprivs
25noroot 26noroot
@@ -30,4 +31,3 @@ seccomp
30shell none 31shell none
31 32
32private-dev 33private-dev
33nodvd
diff --git a/etc/obs.profile b/etc/obs.profile
index f7d7ac310..101d5c28a 100644
--- a/etc/obs.profile
+++ b/etc/obs.profile
@@ -13,6 +13,7 @@ include /etc/firejail/disable-passwdmgr.inc
13include /etc/firejail/disable-programs.inc 13include /etc/firejail/disable-programs.inc
14 14
15caps.drop all 15caps.drop all
16nodvd
16nogroups 17nogroups
17nonewprivs 18nonewprivs
18noroot 19noroot
@@ -27,4 +28,3 @@ private-tmp
27 28
28noexec ${HOME} 29noexec ${HOME}
29noexec /tmp 30noexec /tmp
30nodvd
diff --git a/etc/odt2txt.profile b/etc/odt2txt.profile
index 71eff62ac..da2d03635 100644
--- a/etc/odt2txt.profile
+++ b/etc/odt2txt.profile
@@ -15,6 +15,7 @@ include /etc/firejail/disable-programs.inc
15caps.drop all 15caps.drop all
16net none 16net none
17no3d 17no3d
18nodvd
18nogroups 19nogroups
19nonewprivs 20nonewprivs
20noroot 21noroot
@@ -30,4 +31,3 @@ private-dev
30private-etc none 31private-etc none
31private-tmp 32private-tmp
32read-only ${HOME} 33read-only ${HOME}
33nodvd
diff --git a/etc/okular.profile b/etc/okular.profile
index 426072331..d03891ebe 100644
--- a/etc/okular.profile
+++ b/etc/okular.profile
@@ -22,6 +22,7 @@ include /etc/firejail/disable-programs.inc
22 22
23caps.drop all 23caps.drop all
24netfilter 24netfilter
25nodvd
25nogroups 26nogroups
26nonewprivs 27nonewprivs
27noroot 28noroot
@@ -40,4 +41,3 @@ private-tmp
40 41
41noexec ${HOME} 42noexec ${HOME}
42noexec /tmp 43noexec /tmp
43nodvd
diff --git a/etc/open-invaders.profile b/etc/open-invaders.profile
index b225bd2d2..998d57f62 100644
--- a/etc/open-invaders.profile
+++ b/etc/open-invaders.profile
@@ -17,6 +17,7 @@ include /etc/firejail/whitelist-common.inc
17 17
18caps.drop all 18caps.drop all
19net none 19net none
20nodvd
20nogroups 21nogroups
21nonewprivs 22nonewprivs
22noroot 23noroot
@@ -29,4 +30,3 @@ shell none
29private-dev 30private-dev
30# private-etc none 31# private-etc none
31private-tmp 32private-tmp
32nodvd
diff --git a/etc/openshot.profile b/etc/openshot.profile
index 2219b670c..02f4665d6 100644
--- a/etc/openshot.profile
+++ b/etc/openshot.profile
@@ -15,6 +15,7 @@ include /etc/firejail/disable-programs.inc
15 15
16caps.drop all 16caps.drop all
17netfilter 17netfilter
18nodvd
18nogroups 19nogroups
19nonewprivs 20nonewprivs
20noroot 21noroot
@@ -28,4 +29,3 @@ private-tmp
28 29
29noexec ${HOME} 30noexec ${HOME}
30noexec /tmp 31noexec /tmp
31nodvd
diff --git a/etc/opera-beta.profile b/etc/opera-beta.profile
index f751d7a8b..c295a2082 100644
--- a/etc/opera-beta.profile
+++ b/etc/opera-beta.profile
@@ -22,5 +22,5 @@ whitelist ~/.pki
22include /etc/firejail/whitelist-common.inc 22include /etc/firejail/whitelist-common.inc
23 23
24netfilter 24netfilter
25notv
26nodvd 25nodvd
26notv
diff --git a/etc/opera.profile b/etc/opera.profile
index 2141fe2ee..553ea6790 100644
--- a/etc/opera.profile
+++ b/etc/opera.profile
@@ -26,5 +26,5 @@ whitelist ~/.pki
26include /etc/firejail/whitelist-common.inc 26include /etc/firejail/whitelist-common.inc
27 27
28netfilter 28netfilter
29notv
30nodvd 29nodvd
30notv
diff --git a/etc/orage.profile b/etc/orage.profile
index d5946ab5b..209c7e9db 100644
--- a/etc/orage.profile
+++ b/etc/orage.profile
@@ -16,6 +16,7 @@ include /etc/firejail/disable-programs.inc
16caps.drop all 16caps.drop all
17netfilter 17netfilter
18no3d 18no3d
19nodvd
19nogroups 20nogroups
20nonewprivs 21nonewprivs
21noroot 22noroot
@@ -32,4 +33,3 @@ private-tmp
32 33
33noexec ${HOME} 34noexec ${HOME}
34noexec /tmp 35noexec /tmp
35nodvd
diff --git a/etc/palemoon.profile b/etc/palemoon.profile
index 962dcd16e..054e876c5 100644
--- a/etc/palemoon.profile
+++ b/etc/palemoon.profile
@@ -41,6 +41,7 @@ include /etc/firejail/whitelist-common.inc
41 41
42caps.drop all 42caps.drop all
43netfilter 43netfilter
44nodvd
44nogroups 45nogroups
45nonewprivs 46nonewprivs
46noroot 47noroot
@@ -55,4 +56,3 @@ tracelog
55# private-etc passwd,group,hostname,hosts,localtime,nsswitch.conf,resolv.conf,gtk-2.0,pango,fonts,iceweasel,firefox,adobe,mime.types,mailcap,asound.conf,pulse 56# private-etc passwd,group,hostname,hosts,localtime,nsswitch.conf,resolv.conf,gtk-2.0,pango,fonts,iceweasel,firefox,adobe,mime.types,mailcap,asound.conf,pulse
56# private-opt palemoon 57# private-opt palemoon
57private-tmp 58private-tmp
58nodvd
diff --git a/etc/parole.profile b/etc/parole.profile
index e37e39789..794d91481 100644
--- a/etc/parole.profile
+++ b/etc/parole.profile
@@ -13,6 +13,7 @@ include /etc/firejail/disable-programs.inc
13 13
14caps.drop all 14caps.drop all
15netfilter 15netfilter
16nodvd
16nonewprivs 17nonewprivs
17noroot 18noroot
18notv 19notv
@@ -22,4 +23,3 @@ shell none
22 23
23private-bin parole,dbus-launch 24private-bin parole,dbus-launch
24private-etc passwd,group,fonts 25private-etc passwd,group,fonts
25nodvd
diff --git a/etc/pcmanfm.profile b/etc/pcmanfm.profile
index 44375234d..3b739b2ac 100644
--- a/etc/pcmanfm.profile
+++ b/etc/pcmanfm.profile
@@ -17,6 +17,7 @@ include /etc/firejail/disable-passwdmgr.inc
17caps.drop all 17caps.drop all
18net none 18net none
19no3d 19no3d
20nodvd
20nonewprivs 21nonewprivs
21noroot 22noroot
22nosound 23nosound
@@ -26,4 +27,3 @@ protocol unix
26seccomp 27seccomp
27shell none 28shell none
28tracelog 29tracelog
29nodvd
diff --git a/etc/pdfsam.profile b/etc/pdfsam.profile
index 4dbc05413..b156513dc 100644
--- a/etc/pdfsam.profile
+++ b/etc/pdfsam.profile
@@ -15,6 +15,7 @@ include /etc/firejail/disable-programs.inc
15caps.drop all 15caps.drop all
16net none 16net none
17no3d 17no3d
18nodvd
18nogroups 19nogroups
19nonewprivs 20nonewprivs
20noroot 21noroot
@@ -30,4 +31,3 @@ private-tmp
30 31
31noexec ${HOME} 32noexec ${HOME}
32noexec /tmp 33noexec /tmp
33nodvd
diff --git a/etc/pdftotext.profile b/etc/pdftotext.profile
index 78fb91d5b..540a428cc 100644
--- a/etc/pdftotext.profile
+++ b/etc/pdftotext.profile
@@ -15,6 +15,7 @@ include /etc/firejail/disable-programs.inc
15caps.drop all 15caps.drop all
16net none 16net none
17no3d 17no3d
18nodvd
18nogroups 19nogroups
19nonewprivs 20nonewprivs
20noroot 21noroot
@@ -30,4 +31,3 @@ private-bin pdftotext
30private-dev 31private-dev
31private-etc none 32private-etc none
32private-tmp 33private-tmp
33nodvd
diff --git a/etc/peek.profile b/etc/peek.profile
index 0157ca9d4..a7ad9865c 100644
--- a/etc/peek.profile
+++ b/etc/peek.profile
@@ -15,6 +15,7 @@ include /etc/firejail/disable-programs.inc
15caps.drop all 15caps.drop all
16net none 16net none
17no3d 17no3d
18nodvd
18nogroups 19nogroups
19nonewprivs 20nonewprivs
20noroot 21noroot
@@ -32,4 +33,3 @@ private-tmp
32memory-deny-write-execute 33memory-deny-write-execute
33noexec ${HOME} 34noexec ${HOME}
34noexec /tmp 35noexec /tmp
35nodvd
diff --git a/etc/picard.profile b/etc/picard.profile
index d855a767d..8dc79b4ad 100644
--- a/etc/picard.profile
+++ b/etc/picard.profile
@@ -15,6 +15,7 @@ include /etc/firejail/disable-programs.inc
15 15
16caps.drop all 16caps.drop all
17no3d 17no3d
18nodvd
18nogroups 19nogroups
19nonewprivs 20nonewprivs
20noroot 21noroot
@@ -30,4 +31,3 @@ private-tmp
30 31
31noexec ${HOME} 32noexec ${HOME}
32noexec /tmp 33noexec /tmp
33nodvd
diff --git a/etc/pidgin.profile b/etc/pidgin.profile
index 113f3ce33..dd610920a 100644
--- a/etc/pidgin.profile
+++ b/etc/pidgin.profile
@@ -14,6 +14,7 @@ include /etc/firejail/disable-programs.inc
14 14
15caps.drop all 15caps.drop all
16netfilter 16netfilter
17nodvd
17nogroups 18nogroups
18nonewprivs 19nonewprivs
19noroot 20noroot
@@ -26,4 +27,3 @@ tracelog
26private-bin pidgin 27private-bin pidgin
27private-dev 28private-dev
28private-tmp 29private-tmp
29nodvd
diff --git a/etc/pingus.profile b/etc/pingus.profile
index 204bc7f40..68d5a98ad 100644
--- a/etc/pingus.profile
+++ b/etc/pingus.profile
@@ -17,6 +17,7 @@ include /etc/firejail/whitelist-common.inc
17 17
18caps.drop all 18caps.drop all
19net none 19net none
20nodvd
20nogroups 21nogroups
21nonewprivs 22nonewprivs
22noroot 23noroot
@@ -29,4 +30,3 @@ shell none
29private-dev 30private-dev
30# private-etc none 31# private-etc none
31private-tmp 32private-tmp
32nodvd
diff --git a/etc/pithos.profile b/etc/pithos.profile
index be6e1b72a..e7c316a39 100644
--- a/etc/pithos.profile
+++ b/etc/pithos.profile
@@ -15,6 +15,7 @@ include /etc/firejail/whitelist-common.inc
15caps.drop all 15caps.drop all
16netfilter 16netfilter
17no3d 17no3d
18nodvd
18nogroups 19nogroups
19nonewprivs 20nonewprivs
20noroot 21noroot
@@ -30,4 +31,3 @@ private-tmp
30 31
31noexec ${HOME} 32noexec ${HOME}
32noexec /tmp 33noexec /tmp
33nodvd
diff --git a/etc/pix.profile b/etc/pix.profile
index 79107c27c..ed9298727 100644
--- a/etc/pix.profile
+++ b/etc/pix.profile
@@ -16,6 +16,7 @@ include /etc/firejail/disable-passwdmgr.inc
16include /etc/firejail/disable-programs.inc 16include /etc/firejail/disable-programs.inc
17 17
18caps.drop all 18caps.drop all
19nodvd
19nogroups 20nogroups
20nonewprivs 21nonewprivs
21noroot 22noroot
@@ -29,4 +30,3 @@ tracelog
29private-bin pix 30private-bin pix
30private-dev 31private-dev
31private-tmp 32private-tmp
32nodvd
diff --git a/etc/pluma.profile b/etc/pluma.profile
index ed64c4cf7..d17a64d1d 100644
--- a/etc/pluma.profile
+++ b/etc/pluma.profile
@@ -14,6 +14,7 @@ include /etc/firejail/disable-programs.inc
14 14
15caps.drop all 15caps.drop all
16net none 16net none
17nodvd
17nogroups 18nogroups
18nonewprivs 19nonewprivs
19noroot 20noroot
@@ -26,4 +27,3 @@ tracelog
26private-bin pluma 27private-bin pluma
27private-dev 28private-dev
28private-tmp 29private-tmp
29nodvd
diff --git a/etc/polari.profile b/etc/polari.profile
index c41581b0d..a990194c9 100644
--- a/etc/polari.profile
+++ b/etc/polari.profile
@@ -27,6 +27,7 @@ include /etc/firejail/whitelist-common.inc
27caps.drop all 27caps.drop all
28netfilter 28netfilter
29no3d 29no3d
30nodvd
30nogroups 31nogroups
31nonewprivs 32nonewprivs
32noroot 33noroot
@@ -43,4 +44,3 @@ private-tmp
43 44
44noexec ${HOME} 45noexec ${HOME}
45noexec /tmp 46noexec /tmp
46nodvd
diff --git a/etc/psi-plus.profile b/etc/psi-plus.profile
index 3611e66f2..72c52d967 100644
--- a/etc/psi-plus.profile
+++ b/etc/psi-plus.profile
@@ -25,6 +25,7 @@ include /etc/firejail/whitelist-common.inc
25caps.drop all 25caps.drop all
26netfilter 26netfilter
27no3d 27no3d
28nodvd
28nogroups 29nogroups
29nonewprivs 30nonewprivs
30noroot 31noroot
@@ -40,4 +41,3 @@ private-tmp
40 41
41noexec ${HOME} 42noexec ${HOME}
42noexec /tmp 43noexec /tmp
43nodvd
diff --git a/etc/qbittorrent.profile b/etc/qbittorrent.profile
index b5b5f2cf5..ea635ab6e 100644
--- a/etc/qbittorrent.profile
+++ b/etc/qbittorrent.profile
@@ -29,6 +29,7 @@ include /etc/firejail/whitelist-common.inc
29caps.drop all 29caps.drop all
30machine-id 30machine-id
31netfilter 31netfilter
32nodvd
32nogroups 33nogroups
33nonewprivs 34nonewprivs
34noroot 35noroot
@@ -42,4 +43,3 @@ seccomp
42private-dev 43private-dev
43# private-etc X11,fonts,xdg,resolv.conf 44# private-etc X11,fonts,xdg,resolv.conf
44private-tmp 45private-tmp
45nodvd
diff --git a/etc/qemu-launcher.profile b/etc/qemu-launcher.profile
index 292b6b266..2738e04bb 100644
--- a/etc/qemu-launcher.profile
+++ b/etc/qemu-launcher.profile
@@ -13,6 +13,7 @@ include /etc/firejail/disable-programs.inc
13 13
14caps.drop all 14caps.drop all
15netfilter 15netfilter
16nodvd
16nogroups 17nogroups
17nonewprivs 18nonewprivs
18noroot 19noroot
@@ -25,4 +26,3 @@ tracelog
25private-tmp 26private-tmp
26 27
27noexec /tmp 28noexec /tmp
28nodvd
diff --git a/etc/qemu-system-x86_64.profile b/etc/qemu-system-x86_64.profile
index a4b962b8a..7a60007fe 100644
--- a/etc/qemu-system-x86_64.profile
+++ b/etc/qemu-system-x86_64.profile
@@ -12,6 +12,7 @@ include /etc/firejail/disable-programs.inc
12 12
13caps.drop all 13caps.drop all
14netfilter 14netfilter
15nodvd
15nogroups 16nogroups
16nonewprivs 17nonewprivs
17noroot 18noroot
@@ -24,4 +25,3 @@ tracelog
24private-tmp 25private-tmp
25 26
26noexec /tmp 27noexec /tmp
27nodvd
diff --git a/etc/qlipper.profile b/etc/qlipper.profile
index 8e5a4f19d..796015654 100644
--- a/etc/qlipper.profile
+++ b/etc/qlipper.profile
@@ -15,6 +15,7 @@ include /etc/firejail/disable-programs.inc
15caps.drop all 15caps.drop all
16netfilter 16netfilter
17no3d 17no3d
18nodvd
18nogroups 19nogroups
19nonewprivs 20nonewprivs
20noroot 21noroot
@@ -31,4 +32,3 @@ private-tmp
31 32
32noexec ${HOME} 33noexec ${HOME}
33noexec /tmp 34noexec /tmp
34nodvd
diff --git a/etc/qpdfview.profile b/etc/qpdfview.profile
index 7fe8567dd..2c652c688 100644
--- a/etc/qpdfview.profile
+++ b/etc/qpdfview.profile
@@ -15,6 +15,7 @@ include /etc/firejail/disable-passwdmgr.inc
15include /etc/firejail/disable-programs.inc 15include /etc/firejail/disable-programs.inc
16 16
17caps.drop all 17caps.drop all
18nodvd
18nogroups 19nogroups
19nonewprivs 20nonewprivs
20noroot 21noroot
@@ -28,4 +29,3 @@ tracelog
28private-bin qpdfview 29private-bin qpdfview
29private-dev 30private-dev
30private-tmp 31private-tmp
31nodvd
diff --git a/etc/qtox.profile b/etc/qtox.profile
index 6fe942eeb..5cbe68c90 100644
--- a/etc/qtox.profile
+++ b/etc/qtox.profile
@@ -22,6 +22,7 @@ include /etc/firejail/whitelist-common.inc
22 22
23caps.drop all 23caps.drop all
24netfilter 24netfilter
25nodvd
25nogroups 26nogroups
26nonewprivs 27nonewprivs
27noroot 28noroot
@@ -37,4 +38,3 @@ private-tmp
37 38
38noexec ${HOME} 39noexec ${HOME}
39noexec /tmp 40noexec /tmp
40nodvd
diff --git a/etc/quassel.profile b/etc/quassel.profile
index 223376272..af0f723f1 100644
--- a/etc/quassel.profile
+++ b/etc/quassel.profile
@@ -12,9 +12,9 @@ include /etc/firejail/disable-programs.inc
12 12
13caps.drop all 13caps.drop all
14netfilter 14netfilter
15nodvd
15nonewprivs 16nonewprivs
16noroot 17noroot
17notv 18notv
18protocol unix,inet,inet6 19protocol unix,inet,inet6
19seccomp 20seccomp
20nodvd
diff --git a/etc/quiterss.profile b/etc/quiterss.profile
index 01bc439cd..6f20f6d7f 100644
--- a/etc/quiterss.profile
+++ b/etc/quiterss.profile
@@ -28,6 +28,7 @@ include /etc/firejail/whitelist-common.inc
28 28
29caps.drop all 29caps.drop all
30netfilter 30netfilter
31nodvd
31nogroups 32nogroups
32nonewprivs 33nonewprivs
33noroot 34noroot
@@ -45,4 +46,3 @@ private-dev
45 46
46noexec ${HOME} 47noexec ${HOME}
47noexec /tmp 48noexec /tmp
48nodvd
diff --git a/etc/qupzilla.profile b/etc/qupzilla.profile
index c34a6031f..7b7086bde 100644
--- a/etc/qupzilla.profile
+++ b/etc/qupzilla.profile
@@ -20,6 +20,7 @@ include /etc/firejail/whitelist-common.inc
20 20
21caps.drop all 21caps.drop all
22netfilter 22netfilter
23nodvd
23noroot 24noroot
24notv 25notv
25protocol unix,inet,inet6,netlink 26protocol unix,inet,inet6,netlink
@@ -27,4 +28,3 @@ seccomp
27tracelog 28tracelog
28 29
29# private-etc passwd,group,hostname,hosts,localtime,nsswitch.conf,resolv.conf,gtk-2.0,pango,fonts,iceweasel,firefox,adobe,mime.types,mailcap,asound.conf,pulse 30# private-etc passwd,group,hostname,hosts,localtime,nsswitch.conf,resolv.conf,gtk-2.0,pango,fonts,iceweasel,firefox,adobe,mime.types,mailcap,asound.conf,pulse
30nodvd
diff --git a/etc/qutebrowser.profile b/etc/qutebrowser.profile
index e041cb04f..31721617f 100644
--- a/etc/qutebrowser.profile
+++ b/etc/qutebrowser.profile
@@ -23,10 +23,10 @@ include /etc/firejail/whitelist-common.inc
23 23
24caps.drop all 24caps.drop all
25netfilter 25netfilter
26nodvd
26nonewprivs 27nonewprivs
27noroot 28noroot
28notv 29notv
29protocol unix,inet,inet6,netlink 30protocol unix,inet,inet6,netlink
30seccomp 31seccomp
31tracelog 32tracelog
32nodvd
diff --git a/etc/rambox.profile b/etc/rambox.profile
index 686691849..2696df86b 100644
--- a/etc/rambox.profile
+++ b/etc/rambox.profile
@@ -21,6 +21,7 @@ include /etc/firejail/whitelist-common.inc
21 21
22caps.drop all 22caps.drop all
23netfilter 23netfilter
24nodvd
24nogroups 25nogroups
25nonewprivs 26nonewprivs
26noroot 27noroot
@@ -28,4 +29,3 @@ notv
28protocol unix,inet,inet6,netlink 29protocol unix,inet,inet6,netlink
29seccomp 30seccomp
30# tracelog 31# tracelog
31nodvd
diff --git a/etc/ranger.profile b/etc/ranger.profile
index 93f517a61..717eca099 100644
--- a/etc/ranger.profile
+++ b/etc/ranger.profile
@@ -18,6 +18,7 @@ include /etc/firejail/disable-programs.inc
18 18
19caps.drop all 19caps.drop all
20net none 20net none
21nodvd
21nogroups 22nogroups
22nonewprivs 23nonewprivs
23noroot 24noroot
@@ -27,4 +28,3 @@ protocol unix
27seccomp 28seccomp
28 29
29private-dev 30private-dev
30nodvd
diff --git a/etc/remmina.profile b/etc/remmina.profile
index 70ce4c465..3bb6aa0b1 100644
--- a/etc/remmina.profile
+++ b/etc/remmina.profile
@@ -15,6 +15,7 @@ include /etc/firejail/disable-passwdmgr.inc
15include /etc/firejail/disable-programs.inc 15include /etc/firejail/disable-programs.inc
16 16
17caps.drop all 17caps.drop all
18nodvd
18nogroups 19nogroups
19nonewprivs 20nonewprivs
20noroot 21noroot
@@ -29,4 +30,3 @@ private-tmp
29 30
30noexec ${HOME} 31noexec ${HOME}
31noexec /tmp 32noexec /tmp
32nodvd
diff --git a/etc/ristretto.profile b/etc/ristretto.profile
index 4f271db58..3de5de34a 100644
--- a/etc/ristretto.profile
+++ b/etc/ristretto.profile
@@ -17,6 +17,7 @@ include /etc/firejail/disable-programs.inc
17caps.drop all 17caps.drop all
18netfilter 18netfilter
19no3d 19no3d
20nodvd
20nogroups 21nogroups
21nonewprivs 22nonewprivs
22noroot 23noroot
@@ -32,4 +33,3 @@ private-tmp
32 33
33noexec ${HOME} 34noexec ${HOME}
34noexec /tmp 35noexec /tmp
35nodvd
diff --git a/etc/rtorrent.profile b/etc/rtorrent.profile
index 258349f1f..a44d99e5b 100644
--- a/etc/rtorrent.profile
+++ b/etc/rtorrent.profile
@@ -13,6 +13,7 @@ include /etc/firejail/disable-programs.inc
13 13
14caps.drop all 14caps.drop all
15netfilter 15netfilter
16nodvd
16nonewprivs 17nonewprivs
17noroot 18noroot
18nosound 19nosound
@@ -24,4 +25,3 @@ shell none
24private-bin rtorrent 25private-bin rtorrent
25private-dev 26private-dev
26private-tmp 27private-tmp
27nodvd
diff --git a/etc/scribus.profile b/etc/scribus.profile
index 7f98065ef..acd6b2239 100644
--- a/etc/scribus.profile
+++ b/etc/scribus.profile
@@ -27,6 +27,7 @@ include /etc/firejail/disable-passwdmgr.inc
27include /etc/firejail/disable-programs.inc 27include /etc/firejail/disable-programs.inc
28 28
29caps.drop all 29caps.drop all
30nodvd
30nonewprivs 31nonewprivs
31noroot 32noroot
32nosound 33nosound
@@ -38,4 +39,3 @@ tracelog
38 39
39private-dev 40private-dev
40# private-tmp 41# private-tmp
41nodvd
diff --git a/etc/sdat2img.profile b/etc/sdat2img.profile
index 06889be33..30c2509eb 100644
--- a/etc/sdat2img.profile
+++ b/etc/sdat2img.profile
@@ -15,6 +15,7 @@ include /etc/firejail/disable-programs.inc
15caps.drop all 15caps.drop all
16net none 16net none
17no3d 17no3d
18nodvd
18nogroups 19nogroups
19nonewprivs 20nonewprivs
20noroot 21noroot
@@ -29,4 +30,3 @@ private-dev
29 30
30noexec ${HOME} 31noexec ${HOME}
31noexec /tmp 32noexec /tmp
32nodvd
diff --git a/etc/seamonkey.profile b/etc/seamonkey.profile
index c9bc2d593..36dde66b0 100644
--- a/etc/seamonkey.profile
+++ b/etc/seamonkey.profile
@@ -37,6 +37,7 @@ include /etc/firejail/whitelist-common.inc
37 37
38caps.drop all 38caps.drop all
39netfilter 39netfilter
40nodvd
40nonewprivs 41nonewprivs
41noroot 42noroot
42notv 43notv
@@ -45,4 +46,3 @@ seccomp
45tracelog 46tracelog
46 47
47# private-etc passwd,group,hostname,hosts,localtime,nsswitch.conf,resolv.conf,gtk-2.0,pango,fonts,iceweasel,firefox,adobe,mime.types,mailcap,asound.conf,pulse 48# private-etc passwd,group,hostname,hosts,localtime,nsswitch.conf,resolv.conf,gtk-2.0,pango,fonts,iceweasel,firefox,adobe,mime.types,mailcap,asound.conf,pulse
48nodvd
diff --git a/etc/server.profile b/etc/server.profile
index 1bc2920d9..04ef555de 100644
--- a/etc/server.profile
+++ b/etc/server.profile
@@ -21,6 +21,7 @@ include /etc/firejail/disable-programs.inc
21 21
22caps 22caps
23no3d 23no3d
24nodvd
24nosound 25nosound
25notv 26notv
26novideo 27novideo
@@ -37,4 +38,3 @@ private-tmp
37# memory-deny-write-execute 38# memory-deny-write-execute
38# noexec ${HOME} 39# noexec ${HOME}
39# noexec /tmp 40# noexec /tmp
40nodvd
diff --git a/etc/silentarmy.profile b/etc/silentarmy.profile
index 2e998b1b9..abc68a499 100644
--- a/etc/silentarmy.profile
+++ b/etc/silentarmy.profile
@@ -13,6 +13,7 @@ include /etc/firejail/disable-programs.inc
13 13
14caps.drop all 14caps.drop all
15netfilter 15netfilter
16nodvd
16nogroups 17nogroups
17nonewprivs 18nonewprivs
18noroot 19noroot
@@ -31,4 +32,3 @@ private-tmp
31 32
32noexec ${HOME} 33noexec ${HOME}
33noexec /tmp 34noexec /tmp
34nodvd
diff --git a/etc/simple-scan.profile b/etc/simple-scan.profile
index faf31d7a3..05ed9f813 100644
--- a/etc/simple-scan.profile
+++ b/etc/simple-scan.profile
@@ -14,6 +14,7 @@ include /etc/firejail/disable-programs.inc
14 14
15caps.drop all 15caps.drop all
16netfilter 16netfilter
17nodvd
17nogroups 18nogroups
18nonewprivs 19nonewprivs
19noroot 20noroot
@@ -28,4 +29,3 @@ tracelog
28# private-dev 29# private-dev
29# private-etc fonts 30# private-etc fonts
30# private-tmp 31# private-tmp
31nodvd
diff --git a/etc/simutrans.profile b/etc/simutrans.profile
index 8e1f6031e..fda5204e2 100644
--- a/etc/simutrans.profile
+++ b/etc/simutrans.profile
@@ -17,6 +17,7 @@ include /etc/firejail/whitelist-common.inc
17 17
18caps.drop all 18caps.drop all
19net none 19net none
20nodvd
20nogroups 21nogroups
21nonewprivs 22nonewprivs
22noroot 23noroot
@@ -29,4 +30,3 @@ shell none
29private-dev 30private-dev
30# private-etc none 31# private-etc none
31private-tmp 32private-tmp
32nodvd
diff --git a/etc/skanlite.profile b/etc/skanlite.profile
index 1fdfc0dd5..0338bc452 100644
--- a/etc/skanlite.profile
+++ b/etc/skanlite.profile
@@ -13,6 +13,7 @@ include /etc/firejail/disable-programs.inc
13 13
14caps.drop all 14caps.drop all
15netfilter 15netfilter
16nodvd
16nogroups 17nogroups
17nonewprivs 18nonewprivs
18noroot 19noroot
@@ -26,4 +27,3 @@ shell none
26# private-dev 27# private-dev
27# private-etc 28# private-etc
28# private-tmp 29# private-tmp
29nodvd
diff --git a/etc/skype.profile b/etc/skype.profile
index 1c78313aa..f3e504a3f 100644
--- a/etc/skype.profile
+++ b/etc/skype.profile
@@ -14,6 +14,7 @@ include /etc/firejail/disable-programs.inc
14 14
15caps.drop all 15caps.drop all
16netfilter 16netfilter
17nodvd
17nogroups 18nogroups
18nonewprivs 19nonewprivs
19noroot 20noroot
@@ -28,4 +29,3 @@ private-tmp
28 29
29noexec ${HOME} 30noexec ${HOME}
30noexec /tmp 31noexec /tmp
31nodvd
diff --git a/etc/skypeforlinux.profile b/etc/skypeforlinux.profile
index 3cd0480c7..b69a208a8 100644
--- a/etc/skypeforlinux.profile
+++ b/etc/skypeforlinux.profile
@@ -14,6 +14,7 @@ include /etc/firejail/disable-programs.inc
14 14
15caps.drop all 15caps.drop all
16netfilter 16netfilter
17nodvd
17nogroups 18nogroups
18nonewprivs 19nonewprivs
19noroot 20noroot
@@ -28,4 +29,3 @@ private-tmp
28 29
29noexec ${HOME} 30noexec ${HOME}
30noexec /tmp 31noexec /tmp
31nodvd
diff --git a/etc/slack.profile b/etc/slack.profile
index f973f2cae..9025e4f75 100644
--- a/etc/slack.profile
+++ b/etc/slack.profile
@@ -24,6 +24,7 @@ include /etc/firejail/whitelist-common.inc
24caps.drop all 24caps.drop all
25name slack 25name slack
26netfilter 26netfilter
27nodvd
27nogroups 28nogroups
28nonewprivs 29nonewprivs
29noroot 30noroot
@@ -37,4 +38,3 @@ private-bin slack
37private-dev 38private-dev
38private-etc fonts,resolv.conf,ld.so.conf,ld.so.cache,localtime 39private-etc fonts,resolv.conf,ld.so.conf,ld.so.cache,localtime
39private-tmp 40private-tmp
40nodvd
diff --git a/etc/snap.profile b/etc/snap.profile
index 175589397..238dffeab 100644
--- a/etc/snap.profile
+++ b/etc/snap.profile
@@ -14,5 +14,5 @@ include /etc/firejail/disable-programs.inc
14whitelist ${DOWNLOADS} 14whitelist ${DOWNLOADS}
15whitelist ~/snap 15whitelist ~/snap
16include /etc/firejail/whitelist-common.inc 16include /etc/firejail/whitelist-common.inc
17notv
18nodvd 17nodvd
18notv
diff --git a/etc/soundconverter.profile b/etc/soundconverter.profile
index a9b59b89a..5d7129b5a 100644
--- a/etc/soundconverter.profile
+++ b/etc/soundconverter.profile
@@ -14,6 +14,7 @@ include /etc/firejail/disable-programs.inc
14caps.drop all 14caps.drop all
15net none 15net none
16no3d 16no3d
17nodvd
17nogroups 18nogroups
18nonewprivs 19nonewprivs
19noroot 20noroot
@@ -29,4 +30,3 @@ private-tmp
29 30
30noexec ${HOME} 31noexec ${HOME}
31noexec /tmp 32noexec /tmp
32nodvd
diff --git a/etc/sqlitebrowser.profile b/etc/sqlitebrowser.profile
index a61aca77a..65e8073c9 100644
--- a/etc/sqlitebrowser.profile
+++ b/etc/sqlitebrowser.profile
@@ -15,6 +15,7 @@ include /etc/firejail/disable-programs.inc
15caps.drop all 15caps.drop all
16net none 16net none
17no3d 17no3d
18nodvd
18nogroups 19nogroups
19nonewprivs 20nonewprivs
20noroot 21noroot
@@ -32,4 +33,3 @@ private-tmp
32memory-deny-write-execute 33memory-deny-write-execute
33noexec ${HOME} 34noexec ${HOME}
34noexec /tmp 35noexec /tmp
35nodvd
diff --git a/etc/ssh-agent.profile b/etc/ssh-agent.profile
index fcfdd057a..ba5115521 100644
--- a/etc/ssh-agent.profile
+++ b/etc/ssh-agent.profile
@@ -19,9 +19,9 @@ include /etc/firejail/disable-programs.inc
19caps.drop all 19caps.drop all
20netfilter 20netfilter
21no3d 21no3d
22nodvd
22nonewprivs 23nonewprivs
23noroot 24noroot
24notv 25notv
25protocol unix,inet,inet6 26protocol unix,inet,inet6
26seccomp 27seccomp
27nodvd
diff --git a/etc/ssh.profile b/etc/ssh.profile
index 905e3900e..da852c6ba 100644
--- a/etc/ssh.profile
+++ b/etc/ssh.profile
@@ -18,6 +18,7 @@ caps.drop all
18ipc-namespace 18ipc-namespace
19netfilter 19netfilter
20no3d 20no3d
21nodvd
21nogroups 22nogroups
22nonewprivs 23nonewprivs
23noroot 24noroot
@@ -34,4 +35,3 @@ private-dev
34memory-deny-write-execute 35memory-deny-write-execute
35noexec ${HOME} 36noexec ${HOME}
36noexec /tmp 37noexec /tmp
37nodvd
diff --git a/etc/start-tor-browser.profile b/etc/start-tor-browser.profile
index b37ed72b7..ca521e08c 100644
--- a/etc/start-tor-browser.profile
+++ b/etc/start-tor-browser.profile
@@ -13,6 +13,7 @@ include /etc/firejail/disable-programs.inc
13 13
14caps.drop all 14caps.drop all
15netfilter 15netfilter
16nodvd
16nogroups 17nogroups
17nonewprivs 18nonewprivs
18noroot 19noroot
@@ -26,4 +27,3 @@ private-bin bash,dash,sh,grep,tail,env,gpg,id,readlink,dirname,test,mkdir,ln,sed
26private-dev 27private-dev
27private-etc fonts 28private-etc fonts
28private-tmp 29private-tmp
29nodvd
diff --git a/etc/steam.profile b/etc/steam.profile
index 8d8eabe6d..96899038a 100644
--- a/etc/steam.profile
+++ b/etc/steam.profile
@@ -24,6 +24,7 @@ include /etc/firejail/disable-programs.inc
24 24
25caps.drop all 25caps.drop all
26netfilter 26netfilter
27nodvd
27nogroups 28nogroups
28nonewprivs 29nonewprivs
29noroot 30noroot
@@ -37,4 +38,3 @@ shell none
37 38
38private-dev 39private-dev
39private-tmp 40private-tmp
40nodvd
diff --git a/etc/stellarium.profile b/etc/stellarium.profile
index 06bbf3445..89e2d1a30 100644
--- a/etc/stellarium.profile
+++ b/etc/stellarium.profile
@@ -21,6 +21,7 @@ include /etc/firejail/whitelist-common.inc
21 21
22caps.drop all 22caps.drop all
23netfilter 23netfilter
24nodvd
24nogroups 25nogroups
25nonewprivs 26nonewprivs
26noroot 27noroot
@@ -35,4 +36,3 @@ disable-mnt
35private-bin stellarium 36private-bin stellarium
36private-dev 37private-dev
37private-tmp 38private-tmp
38nodvd
diff --git a/etc/strings.profile b/etc/strings.profile
index 28f5598cf..f203b963c 100644
--- a/etc/strings.profile
+++ b/etc/strings.profile
@@ -11,6 +11,7 @@ blacklist /tmp/.X11-unix
11ignore noroot 11ignore noroot
12net none 12net none
13no3d 13no3d
14nodvd
14nosound 15nosound
15notv 16notv
16novideo 17novideo
@@ -22,4 +23,3 @@ private-dev
22memory-deny-write-execute 23memory-deny-write-execute
23 24
24include /etc/firejail/default.profile 25include /etc/firejail/default.profile
25nodvd
diff --git a/etc/supertux2.profile b/etc/supertux2.profile
index 910c39aeb..cd6496a7b 100644
--- a/etc/supertux2.profile
+++ b/etc/supertux2.profile
@@ -17,6 +17,7 @@ include /etc/firejail/whitelist-common.inc
17 17
18caps.drop all 18caps.drop all
19net none 19net none
20nodvd
20nogroups 21nogroups
21nonewprivs 22nonewprivs
22noroot 23noroot
@@ -29,4 +30,3 @@ shell none
29private-dev 30private-dev
30# private-etc none 31# private-etc none
31private-tmp 32private-tmp
32nodvd
diff --git a/etc/synfigstudio.profile b/etc/synfigstudio.profile
index 7db148e8d..08ece1e9b 100644
--- a/etc/synfigstudio.profile
+++ b/etc/synfigstudio.profile
@@ -15,6 +15,7 @@ include /etc/firejail/disable-programs.inc
15 15
16caps.drop all 16caps.drop all
17netfilter 17netfilter
18nodvd
18nogroups 19nogroups
19nonewprivs 20nonewprivs
20noroot 21noroot
@@ -30,4 +31,3 @@ private-tmp
30 31
31noexec ${HOME} 32noexec ${HOME}
32noexec /tmp 33noexec /tmp
33nodvd
diff --git a/etc/tar.profile b/etc/tar.profile
index ae520be02..34a4f34d6 100644
--- a/etc/tar.profile
+++ b/etc/tar.profile
@@ -12,6 +12,7 @@ hostname tar
12ignore noroot 12ignore noroot
13net none 13net none
14no3d 14no3d
15nodvd
15nosound 16nosound
16notv 17notv
17shell none 18shell none
@@ -23,4 +24,3 @@ private-dev
23private-etc passwd,group,localtime 24private-etc passwd,group,localtime
24 25
25include /etc/firejail/default.profile 26include /etc/firejail/default.profile
26nodvd
diff --git a/etc/telegram.profile b/etc/telegram.profile
index 38cbe3bd0..e3ccaf1a0 100644
--- a/etc/telegram.profile
+++ b/etc/telegram.profile
@@ -13,6 +13,7 @@ include /etc/firejail/disable-programs.inc
13 13
14caps.drop all 14caps.drop all
15netfilter 15netfilter
16nodvd
16nonewprivs 17nonewprivs
17noroot 18noroot
18notv 19notv
@@ -24,4 +25,3 @@ private-tmp
24 25
25noexec ${HOME} 26noexec ${HOME}
26noexec /tmp 27noexec /tmp
27nodvd
diff --git a/etc/tracker.profile b/etc/tracker.profile
index 9da8931f8..ded2ae2e5 100644
--- a/etc/tracker.profile
+++ b/etc/tracker.profile
@@ -17,6 +17,7 @@ include /etc/firejail/disable-programs.inc
17caps.drop all 17caps.drop all
18netfilter 18netfilter
19no3d 19no3d
20nodvd
20nogroups 21nogroups
21nonewprivs 22nonewprivs
22noroot 23noroot
@@ -31,4 +32,3 @@ tracelog
31# private-dev 32# private-dev
32# private-etc fonts 33# private-etc fonts
33# private-tmp 34# private-tmp
34nodvd
diff --git a/etc/transmission-cli.profile b/etc/transmission-cli.profile
index ffdfe16fe..5752c96f3 100644
--- a/etc/transmission-cli.profile
+++ b/etc/transmission-cli.profile
@@ -15,6 +15,7 @@ include /etc/firejail/disable-programs.inc
15 15
16caps.drop all 16caps.drop all
17netfilter 17netfilter
18nodvd
18nonewprivs 19nonewprivs
19noroot 20noroot
20nosound 21nosound
@@ -30,4 +31,3 @@ private-etc none
30private-tmp 31private-tmp
31 32
32memory-deny-write-execute 33memory-deny-write-execute
33nodvd
diff --git a/etc/transmission-gtk.profile b/etc/transmission-gtk.profile
index 0de1ea99d..c4bf7a08d 100644
--- a/etc/transmission-gtk.profile
+++ b/etc/transmission-gtk.profile
@@ -22,6 +22,7 @@ include /etc/firejail/whitelist-common.inc
22 22
23caps.drop all 23caps.drop all
24netfilter 24netfilter
25nodvd
25nonewprivs 26nonewprivs
26noroot 27noroot
27nosound 28nosound
@@ -36,4 +37,3 @@ private-dev
36private-tmp 37private-tmp
37 38
38memory-deny-write-execute 39memory-deny-write-execute
39nodvd
diff --git a/etc/transmission-qt.profile b/etc/transmission-qt.profile
index 6d71cd945..02e9a5052 100644
--- a/etc/transmission-qt.profile
+++ b/etc/transmission-qt.profile
@@ -22,6 +22,7 @@ include /etc/firejail/whitelist-common.inc
22 22
23caps.drop all 23caps.drop all
24netfilter 24netfilter
25nodvd
25nonewprivs 26nonewprivs
26noroot 27noroot
27nosound 28nosound
@@ -34,4 +35,3 @@ tracelog
34private-bin transmission-qt 35private-bin transmission-qt
35private-dev 36private-dev
36private-tmp 37private-tmp
37nodvd
diff --git a/etc/transmission-show.profile b/etc/transmission-show.profile
index 6fcffe4f8..130defc8e 100644
--- a/etc/transmission-show.profile
+++ b/etc/transmission-show.profile
@@ -15,6 +15,7 @@ include /etc/firejail/disable-programs.inc
15 15
16caps.drop all 16caps.drop all
17net none 17net none
18nodvd
18nonewprivs 19nonewprivs
19noroot 20noroot
20nosound 21nosound
@@ -28,4 +29,3 @@ tracelog
28private-dev 29private-dev
29private-etc none 30private-etc none
30private-tmp 31private-tmp
31nodvd
diff --git a/etc/truecraft.profile b/etc/truecraft.profile
index ccdac70dc..4e48f6c6b 100644
--- a/etc/truecraft.profile
+++ b/etc/truecraft.profile
@@ -20,6 +20,7 @@ whitelist ${HOME}/.config/truecraft
20include /etc/firejail/whitelist-common.inc 20include /etc/firejail/whitelist-common.inc
21 21
22caps.drop all 22caps.drop all
23nodvd
23nogroups 24nogroups
24nonewprivs 25nonewprivs
25noroot 26noroot
@@ -35,4 +36,3 @@ private-tmp
35 36
36noexec ${HOME} 37noexec ${HOME}
37noexec /tmp 38noexec /tmp
38nodvd
diff --git a/etc/tuxguitar.profile b/etc/tuxguitar.profile
index e0f66d877..ddbcce3f6 100644
--- a/etc/tuxguitar.profile
+++ b/etc/tuxguitar.profile
@@ -15,6 +15,7 @@ include /etc/firejail/disable-programs.inc
15 15
16caps.drop all 16caps.drop all
17no3d 17no3d
18nodvd
18nonewprivs 19nonewprivs
19noroot 20noroot
20notv 21notv
@@ -28,4 +29,3 @@ private-tmp
28 29
29# noexec ${HOME} - tuxguitar may fail to launch 30# noexec ${HOME} - tuxguitar may fail to launch
30noexec /tmp 31noexec /tmp
31nodvd
diff --git a/etc/uget-gtk.profile b/etc/uget-gtk.profile
index f85d6a7b9..877ad635b 100644
--- a/etc/uget-gtk.profile
+++ b/etc/uget-gtk.profile
@@ -18,6 +18,7 @@ include /etc/firejail/whitelist-common.inc
18 18
19caps.drop all 19caps.drop all
20netfilter 20netfilter
21nodvd
21nonewprivs 22nonewprivs
22noroot 23noroot
23nosound 24nosound
@@ -29,4 +30,3 @@ shell none
29private-bin uget-gtk 30private-bin uget-gtk
30private-dev 31private-dev
31private-tmp 32private-tmp
32nodvd
diff --git a/etc/unbound.profile b/etc/unbound.profile
index 3ca75b3ef..c1cb86893 100644
--- a/etc/unbound.profile
+++ b/etc/unbound.profile
@@ -14,10 +14,10 @@ include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc 14include /etc/firejail/disable-programs.inc
15 15
16no3d 16no3d
17nodvd
17nosound 18nosound
18notv 19notv
19seccomp.drop mount,umount2,ptrace,kexec_load,kexec_file_load,open_by_handle_at,init_module,finit_module,delete_module,iopl,ioperm,swapon,swapoff,syslog,process_vm_readv,process_vm_writev,sysfs,_sysctl,adjtimex,clock_adjtime,lookup_dcookie,perf_event_open,fanotify_init,kcmp,add_key,request_key,keyctl,uselib,acct,modify_ldt,pivot_root,io_setup,io_destroy,io_getevents,io_submit,io_cancel,remap_file_pages,mbind,get_mempolicy,set_mempolicy,migrate_pages,move_pages,vmsplice,perf_event_open 20seccomp.drop mount,umount2,ptrace,kexec_load,kexec_file_load,open_by_handle_at,init_module,finit_module,delete_module,iopl,ioperm,swapon,swapoff,syslog,process_vm_readv,process_vm_writev,sysfs,_sysctl,adjtimex,clock_adjtime,lookup_dcookie,perf_event_open,fanotify_init,kcmp,add_key,request_key,keyctl,uselib,acct,modify_ldt,pivot_root,io_setup,io_destroy,io_getevents,io_submit,io_cancel,remap_file_pages,mbind,get_mempolicy,set_mempolicy,migrate_pages,move_pages,vmsplice,perf_event_open
20 21
21private 22private
22private-dev 23private-dev
23nodvd
diff --git a/etc/unknown-horizons.profile b/etc/unknown-horizons.profile
index c282bb020..5f70843d6 100644
--- a/etc/unknown-horizons.profile
+++ b/etc/unknown-horizons.profile
@@ -16,6 +16,7 @@ whitelist ~/.unknown-horizons
16include /etc/firejail/whitelist-common.inc 16include /etc/firejail/whitelist-common.inc
17 17
18caps.drop all 18caps.drop all
19nodvd
19nogroups 20nogroups
20nonewprivs 21nonewprivs
21noroot 22noroot
@@ -28,4 +29,3 @@ shell none
28private-dev 29private-dev
29# private-etc none 30# private-etc none
30private-tmp 31private-tmp
31nodvd
diff --git a/etc/unrar.profile b/etc/unrar.profile
index b9f2999ae..6a3ac5527 100644
--- a/etc/unrar.profile
+++ b/etc/unrar.profile
@@ -12,6 +12,7 @@ hostname unrar
12ignore noroot 12ignore noroot
13net none 13net none
14no3d 14no3d
15nodvd
15nosound 16nosound
16notv 17notv
17shell none 18shell none
@@ -23,4 +24,3 @@ private-etc passwd,group,localtime
23private-tmp 24private-tmp
24 25
25include /etc/firejail/default.profile 26include /etc/firejail/default.profile
26nodvd
diff --git a/etc/unzip.profile b/etc/unzip.profile
index c391dd7a5..bb30d74cd 100644
--- a/etc/unzip.profile
+++ b/etc/unzip.profile
@@ -12,6 +12,7 @@ hostname unzip
12ignore noroot 12ignore noroot
13net none 13net none
14no3d 14no3d
15nodvd
15nosound 16nosound
16notv 17notv
17shell none 18shell none
@@ -22,4 +23,3 @@ private-dev
22private-etc passwd,group,localtime 23private-etc passwd,group,localtime
23 24
24include /etc/firejail/default.profile 25include /etc/firejail/default.profile
25nodvd
diff --git a/etc/uudeview.profile b/etc/uudeview.profile
index 3b254ba4e..192d13f80 100644
--- a/etc/uudeview.profile
+++ b/etc/uudeview.profile
@@ -10,6 +10,7 @@ include /etc/firejail/globals.local
10hostname uudeview 10hostname uudeview
11ignore noroot 11ignore noroot
12net none 12net none
13nodvd
13nosound 14nosound
14notv 15notv
15shell none 16shell none
@@ -20,4 +21,3 @@ private-dev
20private-etc ld.so.preload 21private-etc ld.so.preload
21 22
22include /etc/firejail/default.profile 23include /etc/firejail/default.profile
23nodvd
diff --git a/etc/uzbl-browser.profile b/etc/uzbl-browser.profile
index 53fc303a0..e7c931f30 100644
--- a/etc/uzbl-browser.profile
+++ b/etc/uzbl-browser.profile
@@ -25,10 +25,10 @@ include /etc/firejail/whitelist-common.inc
25 25
26caps.drop all 26caps.drop all
27netfilter 27netfilter
28nodvd
28nonewprivs 29nonewprivs
29noroot 30noroot
30notv 31notv
31protocol unix,inet,inet6 32protocol unix,inet,inet6
32seccomp 33seccomp
33tracelog 34tracelog
34nodvd
diff --git a/etc/viewnior.profile b/etc/viewnior.profile
index 3dd9a5389..a02845885 100644
--- a/etc/viewnior.profile
+++ b/etc/viewnior.profile
@@ -19,6 +19,7 @@ include /etc/firejail/disable-programs.inc
19 19
20caps.drop all 20caps.drop all
21net none 21net none
22nodvd
22nogroups 23nogroups
23nonewprivs 24nonewprivs
24noroot 25noroot
@@ -33,4 +34,3 @@ private-bin viewnior
33private-dev 34private-dev
34private-etc fonts 35private-etc fonts
35private-tmp 36private-tmp
36nodvd
diff --git a/etc/viking.profile b/etc/viking.profile
index 8b5bff2b8..30e89b511 100644
--- a/etc/viking.profile
+++ b/etc/viking.profile
@@ -16,6 +16,7 @@ include /etc/firejail/disable-programs.inc
16caps.drop all 16caps.drop all
17netfilter 17netfilter
18no3d 18no3d
19nodvd
19nogroups 20nogroups
20nonewprivs 21nonewprivs
21noroot 22noroot
@@ -30,4 +31,3 @@ private-tmp
30 31
31noexec ${HOME} 32noexec ${HOME}
32noexec /tmp 33noexec /tmp
33nodvd
diff --git a/etc/vim.profile b/etc/vim.profile
index 0264930ef..7b5566f5b 100644
--- a/etc/vim.profile
+++ b/etc/vim.profile
@@ -15,10 +15,10 @@ include /etc/firejail/disable-programs.inc
15 15
16caps.drop all 16caps.drop all
17netfilter 17netfilter
18nodvd
18nogroups 19nogroups
19nonewprivs 20nonewprivs
20noroot 21noroot
21notv 22notv
22protocol unix,inet,inet6 23protocol unix,inet,inet6
23seccomp 24seccomp
24nodvd
diff --git a/etc/virtualbox.profile b/etc/virtualbox.profile
index da0b91e09..6e153d559 100644
--- a/etc/virtualbox.profile
+++ b/etc/virtualbox.profile
@@ -24,5 +24,5 @@ include /etc/firejail/whitelist-common.inc
24 24
25caps.drop all 25caps.drop all
26netfilter 26netfilter
27notv
28nodvd 27nodvd
28notv
diff --git a/etc/vivaldi.profile b/etc/vivaldi.profile
index cd4d62e44..503916b26 100644
--- a/etc/vivaldi.profile
+++ b/etc/vivaldi.profile
@@ -21,6 +21,7 @@ include /etc/firejail/whitelist-common.inc
21 21
22caps.keep sys_chroot,sys_admin 22caps.keep sys_chroot,sys_admin
23netfilter 23netfilter
24nodvd
24nogroups 25nogroups
25notv 26notv
26shell none 27shell none
@@ -30,4 +31,3 @@ private-dev
30 31
31noexec ${HOME} 32noexec ${HOME}
32noexec /tmp 33noexec /tmp
33nodvd
diff --git a/etc/vym.profile b/etc/vym.profile
index 702680958..4f60b2ada 100644
--- a/etc/vym.profile
+++ b/etc/vym.profile
@@ -15,6 +15,7 @@ include /etc/firejail/disable-programs.inc
15caps.drop all 15caps.drop all
16netfilter 16netfilter
17no3d 17no3d
18nodvd
18nogroups 19nogroups
19nonewprivs 20nonewprivs
20noroot 21noroot
@@ -31,4 +32,3 @@ private-tmp
31 32
32noexec ${HOME} 33noexec ${HOME}
33noexec /tmp 34noexec /tmp
34nodvd
diff --git a/etc/w3m.profile b/etc/w3m.profile
index 04760d176..b25e19135 100644
--- a/etc/w3m.profile
+++ b/etc/w3m.profile
@@ -17,6 +17,7 @@ include /etc/firejail/disable-programs.inc
17caps.drop all 17caps.drop all
18netfilter 18netfilter
19no3d 19no3d
20nodvd
20nogroups 21nogroups
21nonewprivs 22nonewprivs
22noroot 23noroot
@@ -31,4 +32,3 @@ tracelog
31private-dev 32private-dev
32private-etc none 33private-etc none
33private-tmp 34private-tmp
34nodvd
diff --git a/etc/warzone2100.profile b/etc/warzone2100.profile
index 0a8a73f1f..976f7db5f 100644
--- a/etc/warzone2100.profile
+++ b/etc/warzone2100.profile
@@ -20,6 +20,7 @@ include /etc/firejail/whitelist-common.inc
20 20
21caps.drop all 21caps.drop all
22netfilter 22netfilter
23nodvd
23nogroups 24nogroups
24nonewprivs 25nonewprivs
25noroot 26noroot
@@ -33,4 +34,3 @@ disable-mnt
33private-bin warzone2100 34private-bin warzone2100
34private-dev 35private-dev
35private-tmp 36private-tmp
36nodvd
diff --git a/etc/waterfox.profile b/etc/waterfox.profile
index c842e6700..76b7c86ba 100644
--- a/etc/waterfox.profile
+++ b/etc/waterfox.profile
@@ -52,6 +52,7 @@ include /etc/firejail/whitelist-common.inc
52 52
53caps.drop all 53caps.drop all
54netfilter 54netfilter
55nodvd
55nogroups 56nogroups
56nonewprivs 57nonewprivs
57noroot 58noroot
@@ -69,4 +70,3 @@ private-tmp
69 70
70noexec ${HOME} 71noexec ${HOME}
71noexec /tmp 72noexec /tmp
72nodvd
diff --git a/etc/weechat.profile b/etc/weechat.profile
index 79619bb82..b0971ae19 100644
--- a/etc/weechat.profile
+++ b/etc/weechat.profile
@@ -12,6 +12,7 @@ include /etc/firejail/disable-programs.inc
12 12
13caps.drop all 13caps.drop all
14netfilter 14netfilter
15nodvd
15nonewprivs 16nonewprivs
16noroot 17noroot
17notv 18notv
@@ -21,4 +22,3 @@ seccomp
21# no private-bin support for various reasons: 22# no private-bin support for various reasons:
22# Plugins loaded: alias, aspell, charset, exec, fifo, guile, irc, 23# Plugins loaded: alias, aspell, charset, exec, fifo, guile, irc,
23# logger, lua, perl, python, relay, ruby, script, tcl, trigger, xferloading plugins 24# logger, lua, perl, python, relay, ruby, script, tcl, trigger, xferloading plugins
24nodvd
diff --git a/etc/wesnoth.profile b/etc/wesnoth.profile
index 30f857f47..d6318c81b 100644
--- a/etc/wesnoth.profile
+++ b/etc/wesnoth.profile
@@ -23,6 +23,7 @@ whitelist ${HOME}/.local/share/wesnoth
23include /etc/firejail/whitelist-common.inc 23include /etc/firejail/whitelist-common.inc
24 24
25caps.drop all 25caps.drop all
26nodvd
26nonewprivs 27nonewprivs
27noroot 28noroot
28notv 29notv
@@ -31,4 +32,3 @@ seccomp
31 32
32private-dev 33private-dev
33private-tmp 34private-tmp
34nodvd
diff --git a/etc/wget.profile b/etc/wget.profile
index 23eba46fe..5072cb9c5 100644
--- a/etc/wget.profile
+++ b/etc/wget.profile
@@ -17,6 +17,7 @@ include /etc/firejail/disable-programs.inc
17caps.drop all 17caps.drop all
18netfilter 18netfilter
19no3d 19no3d
20nodvd
20nogroups 21nogroups
21nonewprivs 22nonewprivs
22noroot 23noroot
@@ -34,4 +35,3 @@ private-dev
34 35
35noexec ${HOME} 36noexec ${HOME}
36noexec /tmp 37noexec /tmp
37nodvd
diff --git a/etc/wine.profile b/etc/wine.profile
index 69ad72137..b1bc7df78 100644
--- a/etc/wine.profile
+++ b/etc/wine.profile
@@ -17,9 +17,9 @@ include /etc/firejail/disable-programs.inc
17 17
18caps.drop all 18caps.drop all
19netfilter 19netfilter
20nodvd
20nogroups 21nogroups
21nonewprivs 22nonewprivs
22noroot 23noroot
23notv 24notv
24seccomp 25seccomp
25nodvd
diff --git a/etc/wire.profile b/etc/wire.profile
index 00da13cce..af14f686f 100644
--- a/etc/wire.profile
+++ b/etc/wire.profile
@@ -18,6 +18,7 @@ include /etc/firejail/disable-programs.inc
18 18
19caps.drop all 19caps.drop all
20netfilter 20netfilter
21nodvd
21nogroups 22nogroups
22nonewprivs 23nonewprivs
23noroot 24noroot
@@ -29,4 +30,3 @@ shell none
29disable-mnt 30disable-mnt
30private-dev 31private-dev
31private-tmp 32private-tmp
32nodvd
diff --git a/etc/wireshark.profile b/etc/wireshark.profile
index 1bee919b3..57f4f2f5b 100644
--- a/etc/wireshark.profile
+++ b/etc/wireshark.profile
@@ -18,6 +18,7 @@ no3d
18# nogroups - breaks unprivileged wireshark usage 18# nogroups - breaks unprivileged wireshark usage
19# nonewprivs - breaks unprivileged wireshark usage 19# nonewprivs - breaks unprivileged wireshark usage
20# noroot 20# noroot
21nodvd
21nosound 22nosound
22notv 23notv
23# protocol unix,inet,inet6,netlink 24# protocol unix,inet,inet6,netlink
@@ -32,4 +33,3 @@ private-tmp
32 33
33noexec ${HOME} 34noexec ${HOME}
34noexec /tmp 35noexec /tmp
35nodvd
diff --git a/etc/xchat.profile b/etc/xchat.profile
index 73df480bf..ab62160b5 100644
--- a/etc/xchat.profile
+++ b/etc/xchat.profile
@@ -12,6 +12,7 @@ include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-programs.inc 12include /etc/firejail/disable-programs.inc
13 13
14caps.drop all 14caps.drop all
15nodvd
15nonewprivs 16nonewprivs
16noroot 17noroot
17notv 18notv
@@ -19,4 +20,3 @@ protocol unix,inet,inet6
19seccomp 20seccomp
20 21
21# private-bin requires perl, python, etc. 22# private-bin requires perl, python, etc.
22nodvd
diff --git a/etc/xed.profile b/etc/xed.profile
index b47cca36f..758fb5526 100644
--- a/etc/xed.profile
+++ b/etc/xed.profile
@@ -14,6 +14,7 @@ include /etc/firejail/disable-programs.inc
14 14
15caps.drop all 15caps.drop all
16net none 16net none
17nodvd
17nogroups 18nogroups
18nonewprivs 19nonewprivs
19noroot 20noroot
@@ -26,4 +27,3 @@ tracelog
26private-bin xed 27private-bin xed
27private-dev 28private-dev
28private-tmp 29private-tmp
29nodvd
diff --git a/etc/xfburn.profile b/etc/xfburn.profile
index 4729ebaf7..e80685f0e 100644
--- a/etc/xfburn.profile
+++ b/etc/xfburn.profile
@@ -14,6 +14,7 @@ include /etc/firejail/disable-programs.inc
14 14
15caps.drop all 15caps.drop all
16netfilter 16netfilter
17nodvd
17nogroups 18nogroups
18nonewprivs 19nonewprivs
19noroot 20noroot
@@ -28,4 +29,3 @@ tracelog
28# private-dev 29# private-dev
29# private-etc fonts 30# private-etc fonts
30# private-tmp 31# private-tmp
31nodvd
diff --git a/etc/xfce4-dict.profile b/etc/xfce4-dict.profile
index 3e2d4b1d4..ab52d17e9 100644
--- a/etc/xfce4-dict.profile
+++ b/etc/xfce4-dict.profile
@@ -15,6 +15,7 @@ include /etc/firejail/disable-programs.inc
15caps.drop all 15caps.drop all
16netfilter 16netfilter
17no3d 17no3d
18nodvd
18nogroups 19nogroups
19nonewprivs 20nonewprivs
20noroot 21noroot
@@ -31,4 +32,3 @@ private-tmp
31 32
32noexec ${HOME} 33noexec ${HOME}
33noexec /tmp 34noexec /tmp
34nodvd
diff --git a/etc/xfce4-notes.profile b/etc/xfce4-notes.profile
index 12b7e6de7..868b4796b 100644
--- a/etc/xfce4-notes.profile
+++ b/etc/xfce4-notes.profile
@@ -17,6 +17,7 @@ include /etc/firejail/disable-programs.inc
17caps.drop all 17caps.drop all
18netfilter 18netfilter
19no3d 19no3d
20nodvd
20nogroups 21nogroups
21nonewprivs 22nonewprivs
22noroot 23noroot
@@ -33,4 +34,3 @@ private-tmp
33 34
34noexec ${HOME} 35noexec ${HOME}
35noexec /tmp 36noexec /tmp
36nodvd
diff --git a/etc/xiphos.profile b/etc/xiphos.profile
index ae3e303a3..38e568860 100644
--- a/etc/xiphos.profile
+++ b/etc/xiphos.profile
@@ -22,6 +22,7 @@ include /etc/firejail/whitelist-common.inc
22 22
23caps.drop all 23caps.drop all
24netfilter 24netfilter
25nodvd
25nogroups 26nogroups
26nonewprivs 27nonewprivs
27noroot 28noroot
@@ -36,4 +37,3 @@ private-bin xiphos
36private-dev 37private-dev
37private-etc fonts,resolv.conf,sword 38private-etc fonts,resolv.conf,sword
38private-tmp 39private-tmp
39nodvd
diff --git a/etc/xonotic.profile b/etc/xonotic.profile
index 6a67bde75..c7db00daf 100644
--- a/etc/xonotic.profile
+++ b/etc/xonotic.profile
@@ -18,6 +18,7 @@ include /etc/firejail/whitelist-common.inc
18 18
19caps.drop all 19caps.drop all
20netfilter 20netfilter
21nodvd
21nogroups 22nogroups
22nonewprivs 23nonewprivs
23noroot 24noroot
@@ -34,4 +35,3 @@ private-tmp
34 35
35noexec ${HOME} 36noexec ${HOME}
36noexec /tmp 37noexec /tmp
37nodvd
diff --git a/etc/xpdf.profile b/etc/xpdf.profile
index 1f51c220d..f34358521 100644
--- a/etc/xpdf.profile
+++ b/etc/xpdf.profile
@@ -15,6 +15,7 @@ include /etc/firejail/disable-programs.inc
15caps.drop all 15caps.drop all
16net none 16net none
17no3d 17no3d
18nodvd
18nogroups 19nogroups
19nonewprivs 20nonewprivs
20noroot 21noroot
@@ -30,4 +31,3 @@ private-tmp
30 31
31noexec ${HOME} 32noexec ${HOME}
32noexec /tmp 33noexec /tmp
33nodvd
diff --git a/etc/xpra.profile b/etc/xpra.profile
index 28586f134..2bd91e8b5 100644
--- a/etc/xpra.profile
+++ b/etc/xpra.profile
@@ -26,6 +26,7 @@ whitelist /var/lib/xkb
26 26
27caps.drop all 27caps.drop all
28# xpra needs to be allowed access to the abstract Unix socket namespace. 28# xpra needs to be allowed access to the abstract Unix socket namespace.
29nodvd
29nogroups 30nogroups
30nonewprivs 31nonewprivs
31# In noroot mode, xpra cannot create a socket in the real /tmp/.X11-unix. 32# In noroot mode, xpra cannot create a socket in the real /tmp/.X11-unix.
@@ -44,4 +45,3 @@ shell none
44private-dev 45private-dev
45# private-etc ld.so.conf,ld.so.cache,resolv.conf,host.conf,nsswitch.conf,gai.conf,hosts,hostname,machine-id,xpra,X11 46# private-etc ld.so.conf,ld.so.cache,resolv.conf,host.conf,nsswitch.conf,gai.conf,hosts,hostname,machine-id,xpra,X11
46private-tmp 47private-tmp
47nodvd
diff --git a/etc/xreader.profile b/etc/xreader.profile
index 35358814a..107cefe5e 100644
--- a/etc/xreader.profile
+++ b/etc/xreader.profile
@@ -15,6 +15,7 @@ include /etc/firejail/disable-passwdmgr.inc
15include /etc/firejail/disable-programs.inc 15include /etc/firejail/disable-programs.inc
16 16
17caps.drop all 17caps.drop all
18nodvd
18nogroups 19nogroups
19nonewprivs 20nonewprivs
20noroot 21noroot
@@ -28,4 +29,3 @@ tracelog
28private-bin xreader, xreader-previewer, xreader-thumbnailer 29private-bin xreader, xreader-previewer, xreader-thumbnailer
29private-dev 30private-dev
30private-tmp 31private-tmp
31nodvd
diff --git a/etc/xviewer.profile b/etc/xviewer.profile
index dd3103909..70ad3b895 100644
--- a/etc/xviewer.profile
+++ b/etc/xviewer.profile
@@ -16,6 +16,7 @@ include /etc/firejail/disable-passwdmgr.inc
16include /etc/firejail/disable-programs.inc 16include /etc/firejail/disable-programs.inc
17 17
18caps.drop all 18caps.drop all
19nodvd
19nogroups 20nogroups
20nonewprivs 21nonewprivs
21noroot 22noroot
@@ -32,4 +33,3 @@ private-tmp
32 33
33noexec ${HOME} 34noexec ${HOME}
34noexec /tmp 35noexec /tmp
35nodvd
diff --git a/etc/xzdec.profile b/etc/xzdec.profile
index 18384680f..7f21f5d2f 100644
--- a/etc/xzdec.profile
+++ b/etc/xzdec.profile
@@ -11,6 +11,7 @@ blacklist /tmp/.X11-unix
11ignore noroot 11ignore noroot
12net none 12net none
13no3d 13no3d
14nodvd
14nosound 15nosound
15notv 16notv
16shell none 17shell none
@@ -19,4 +20,3 @@ tracelog
19private-dev 20private-dev
20 21
21include /etc/firejail/default.profile 22include /etc/firejail/default.profile
22nodvd
diff --git a/etc/youtube-dl.profile b/etc/youtube-dl.profile
index e9f6d5641..e20fb3e99 100644
--- a/etc/youtube-dl.profile
+++ b/etc/youtube-dl.profile
@@ -17,6 +17,7 @@ caps.drop all
17ipc-namespace 17ipc-namespace
18netfilter 18netfilter
19no3d 19no3d
20nodvd
20nogroups 21nogroups
21nonewprivs 22nonewprivs
22noroot 23noroot
@@ -32,4 +33,3 @@ private-dev
32 33
33noexec ${HOME} 34noexec ${HOME}
34noexec /tmp 35noexec /tmp
35nodvd
diff --git a/etc/zathura.profile b/etc/zathura.profile
index 9f1c4a3da..0036a3521 100644
--- a/etc/zathura.profile
+++ b/etc/zathura.profile
@@ -15,6 +15,7 @@ include /etc/firejail/disable-programs.inc
15 15
16caps.drop all 16caps.drop all
17net none 17net none
18nodvd
18nogroups 19nogroups
19nonewprivs 20nonewprivs
20noroot 21noroot
@@ -30,4 +31,3 @@ private-etc fonts
30private-tmp 31private-tmp
31read-only ~/ 32read-only ~/
32read-write ~/.local/share/zathura/ 33read-write ~/.local/share/zathura/
33nodvd
diff --git a/etc/zoom.profile b/etc/zoom.profile
index e0902390f..381df9ab5 100644
--- a/etc/zoom.profile
+++ b/etc/zoom.profile
@@ -18,6 +18,7 @@ include /etc/firejail/whitelist-common.inc
18 18
19caps.drop all 19caps.drop all
20netfilter 20netfilter
21nodvd
21nonewprivs 22nonewprivs
22noroot 23noroot
23notv 24notv
@@ -25,4 +26,3 @@ protocol unix,inet,inet6
25seccomp 26seccomp
26 27
27private-tmp 28private-tmp
28nodvd