aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLibravatar netblue30 <netblue30@yahoo.com>2017-09-21 08:15:19 -0400
committerLibravatar netblue30 <netblue30@yahoo.com>2017-09-21 08:15:19 -0400
commit0ec8ec63375efaf87a5f8af48c83eac560dacd20 (patch)
tree978dab36c48f26091d2e1919d1f561d522577737
parentFixup 17a2edf9be3d1144db1a262c5358bf190c9b272b (diff)
downloadfirejail-0ec8ec63375efaf87a5f8af48c83eac560dacd20.tar.gz
firejail-0ec8ec63375efaf87a5f8af48c83eac560dacd20.tar.zst
firejail-0ec8ec63375efaf87a5f8af48c83eac560dacd20.zip
added ffmpeg.profile, removed ssh-agent from firecfg
-rw-r--r--README.md2
-rw-r--r--etc/ffmpeg.profile33
-rw-r--r--platform/debian/conffiles1
-rw-r--r--src/firecfg/firecfg.config3
4 files changed, 37 insertions, 2 deletions
diff --git a/README.md b/README.md
index c9e04ee3c..26f3dc3c5 100644
--- a/README.md
+++ b/README.md
@@ -180,4 +180,4 @@ calligraflow, calligraplan, calligraplanwork, calligrasheets, calligrastage,
180calligrawords, cin, dooble, dooble-qt4, fetchmail, freecad, freecadcmd, google-earth, 180calligrawords, cin, dooble, dooble-qt4, fetchmail, freecad, freecadcmd, google-earth,
181imagej, karbon, kdenlive, krita, linphone, lmms, macrofusion, mpd, natron, Natron, 181imagej, karbon, kdenlive, krita, linphone, lmms, macrofusion, mpd, natron, Natron,
182ricochet, shotcut, teamspeak3, tor, tor-browser-en, Viber, x-terminal-emulator, zart, 182ricochet, shotcut, teamspeak3, tor, tor-browser-en, Viber, x-terminal-emulator, zart,
183conky, arch-audit 183conky, arch-audit, ffmpeg
diff --git a/etc/ffmpeg.profile b/etc/ffmpeg.profile
new file mode 100644
index 000000000..e098c95e3
--- /dev/null
+++ b/etc/ffmpeg.profile
@@ -0,0 +1,33 @@
1# Firejail profile for default
2# This file is overwritten after every install/update
3quiet
4# Persistent local customizations
5include /etc/firejail/ffmpeg.local
6# Persistent global definitions
7include /etc/firejail/globals.local
8
9include /etc/firejail/disable-common.inc
10include /etc/firejail/disable-devel.inc
11include /etc/firejail/disable-passwdmgr.inc
12include /etc/firejail/disable-programs.inc
13
14caps.drop all
15net none
16no3d
17nodvd
18nosound
19notv
20novideo
21nonewprivs
22noroot
23# protocol none - needs to be implemented!
24seccomp
25# seccomp.keep futex,write,read,munmap,fstat,mprotect,mmap,open,close,stat,lseek,brk,rt_sigaction,rt_sigprocmask,ioctl,access,select,madvise,getpid,clone,execve,fcntl,getdents,readlink,getrlimit,getrusage,statfs,getpriority,setpriority,arch_prctl,sched_getaffinity,set_tid_address,set_robust_list,getrandom
26# memory-deny-write-execute - it breaks old versions of ffmpeg
27shell none
28tracelog
29
30private-tmp
31private-dev
32private-bin ffmpeg
33include /etc/firejail/whitelist-var-common.inc
diff --git a/platform/debian/conffiles b/platform/debian/conffiles
index af6547f7f..27623aee3 100644
--- a/platform/debian/conffiles
+++ b/platform/debian/conffiles
@@ -358,3 +358,4 @@
358/etc/firejail/yandex-browser.profile 358/etc/firejail/yandex-browser.profile
359/etc/firejail/itch.profile 359/etc/firejail/itch.profile
360/etc/firejail/whitelist-var-common.inc 360/etc/firejail/whitelist-var-common.inc
361/etc/firejail/ffmpeg
diff --git a/src/firecfg/firecfg.config b/src/firecfg/firecfg.config
index e4e3e4972..5a36f5e3e 100644
--- a/src/firecfg/firecfg.config
+++ b/src/firecfg/firecfg.config
@@ -99,6 +99,7 @@ evolution
99exiftool 99exiftool
100fbreader 100fbreader
101feh 101feh
102ffmpeg
102file-roller 103file-roller
103filezilla 104filezilla
104firefox 105firefox
@@ -292,7 +293,7 @@ soundconverter
292spotify 293spotify
293sqlitebrowser 294sqlitebrowser
294ssh 295ssh
295ssh-agent 296# ssh-agent - problems on Arch with Fish shell (#1568)
296start-tor-browser 297start-tor-browser
297steam 298steam
298stellarium 299stellarium