aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLibravatar Jose Riha <jose1711@gmail.com>2019-06-15 15:56:08 +0200
committerLibravatar Jose Riha <jose1711@gmail.com>2019-06-17 11:31:18 +0200
commitf97e4fd97064b7f6a6101c1c60d5f88538d89ac6 (patch)
treee711de6e103f1cbfc7477f2fd21036b338f62f5c
parentAdd profile for udiskie (diff)
downloadfirejail-f97e4fd97064b7f6a6101c1c60d5f88538d89ac6.tar.gz
firejail-f97e4fd97064b7f6a6101c1c60d5f88538d89ac6.tar.zst
firejail-f97e4fd97064b7f6a6101c1c60d5f88538d89ac6.zip
Apply suggestions from code review
Co-Authored-By: rusty-snake <print_hello_world+GitHub@protonmail.com>
-rw-r--r--etc/udiskie.profile14
1 files changed, 12 insertions, 2 deletions
diff --git a/etc/udiskie.profile b/etc/udiskie.profile
index 37b5d9a64..7960b4bc3 100644
--- a/etc/udiskie.profile
+++ b/etc/udiskie.profile
@@ -1,7 +1,6 @@
1# Firejail profile for udiskie 1# Firejail profile for udiskie
2# Description: Removable disk automounter using udisks 2# Description: Removable disk automounter using udisks
3# This file is overwritten after every install/update 3# This file is overwritten after every install/update
4# quiet
5# Persistent local customizations 4# Persistent local customizations
6include udiskie.local 5include udiskie.local
7# Persistent global definitions 6# Persistent global definitions
@@ -14,22 +13,33 @@ include disable-common.inc
14include disable-devel.inc 13include disable-devel.inc
15include disable-exec.inc 14include disable-exec.inc
16include disable-interpreters.inc 15include disable-interpreters.inc
17include disable-passwdmgr.inc include disable-programs.inc 16include disable-passwdmgr.inc
17include disable-programs.inc
18include disable-xdg.inc 18include disable-xdg.inc
19 19
20include whitelist-var-common.inc
21
20caps.drop all 22caps.drop all
21machine-id 23machine-id
22net none 24net none
25no3d
23nogroups 26nogroups
24nonewprivs 27nonewprivs
25noroot 28noroot
29nosound
26notv 30notv
27nou2f 31nou2f
28novideo 32novideo
33protocol unix
29seccomp 34seccomp
30shell none 35shell none
31tracelog 36tracelog
32 37
38private-bin awk,cut,dbus-send,egrep,file,grep,head,python,python3,readlink,sed,sh,udiskie,uname,which,xdg-mime,xdg-open,xprop
39# add your configured file browser in udiskie.local, e. g.
40# private-bin nautilus
41# private-bin thunar
33private-cache 42private-cache
34private-dev 43private-dev
44private-etc ld.so.cache,ld.so.preload,ld.so.conf,ld.so.conf.d,locale,locale.alias,locale.conf,localtime,alternatives,mime.types,xdg
35private-tmp 45private-tmp