aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLibravatar Tad <tad@spotco.us>2017-04-17 17:11:24 -0400
committerLibravatar Tad <tad@spotco.us>2017-04-17 17:11:24 -0400
commit4f238b75de05d91f200305335da1f019810ac149 (patch)
tree40f021c8d9e7bb70f7bd0a868d571286fa438420
parentMerge pull request #1229 from SpotComms/firecfg2 (diff)
downloadfirejail-4f238b75de05d91f200305335da1f019810ac149.tar.gz
firejail-4f238b75de05d91f200305335da1f019810ac149.tar.zst
firejail-4f238b75de05d91f200305335da1f019810ac149.zip
Harden more profiles
-rw-r--r--etc/bleachbit.profile1
-rw-r--r--etc/bless.profile1
-rw-r--r--etc/chromium.profile15
-rw-r--r--etc/dino.profile1
-rw-r--r--etc/eog.profile1
-rw-r--r--etc/evince.profile1
-rw-r--r--etc/evolution.profile1
-rw-r--r--etc/file-roller.profile1
-rw-r--r--etc/firefox.profile2
-rw-r--r--etc/gedit.profile1
-rw-r--r--etc/gimp.profile1
-rw-r--r--etc/gnome-calculator.profile1
-rw-r--r--etc/hexchat.profile1
-rw-r--r--etc/jd-gui.profile1
-rw-r--r--etc/lollypop.profile1
-rw-r--r--etc/multimc5.profile1
-rw-r--r--etc/mumble.profile1
-rw-r--r--etc/pdfsam.profile1
-rw-r--r--etc/pithos.profile1
-rw-r--r--etc/polari.profile11
-rw-r--r--etc/ssh.profile1
-rw-r--r--etc/steam.profile1
-rw-r--r--etc/totem.profile1
-rw-r--r--etc/vlc.profile1
-rw-r--r--etc/wget.profile1
-rw-r--r--etc/wireshark.profile1
-rw-r--r--etc/xonotic.profile1
27 files changed, 48 insertions, 4 deletions
diff --git a/etc/bleachbit.profile b/etc/bleachbit.profile
index 7ea55f505..fe08de40e 100644
--- a/etc/bleachbit.profile
+++ b/etc/bleachbit.profile
@@ -9,6 +9,7 @@ include /etc/firejail/disable-devel.inc
9include /etc/firejail/disable-passwdmgr.inc 9include /etc/firejail/disable-passwdmgr.inc
10 10
11caps.drop all 11caps.drop all
12ipc-namespace
12net none 13net none
13netfilter 14netfilter
14no3d 15no3d
diff --git a/etc/bless.profile b/etc/bless.profile
index 869f13cc0..f4b5c2e2f 100644
--- a/etc/bless.profile
+++ b/etc/bless.profile
@@ -17,6 +17,7 @@ include /etc/firejail/disable-devel.inc
17 17
18#Options 18#Options
19caps.drop all 19caps.drop all
20ipc-namespace
20net none 21net none
21netfilter 22netfilter
22no3d 23no3d
diff --git a/etc/chromium.profile b/etc/chromium.profile
index 995c0001b..071c8a18a 100644
--- a/etc/chromium.profile
+++ b/etc/chromium.profile
@@ -8,12 +8,8 @@ noblacklist ~/.cache/chromium
8noblacklist ~/.pki 8noblacklist ~/.pki
9include /etc/firejail/disable-common.inc 9include /etc/firejail/disable-common.inc
10include /etc/firejail/disable-programs.inc 10include /etc/firejail/disable-programs.inc
11
12# chromium is distributed with a perl script on Arch 11# chromium is distributed with a perl script on Arch
13# include /etc/firejail/disable-devel.inc 12# include /etc/firejail/disable-devel.inc
14#
15
16netfilter
17 13
18whitelist ${DOWNLOADS} 14whitelist ${DOWNLOADS}
19mkdir ~/.config/chromium 15mkdir ~/.config/chromium
@@ -27,3 +23,14 @@ whitelist ~/.pki
27whitelist ~/.config/chromium-flags.conf 23whitelist ~/.config/chromium-flags.conf
28 24
29include /etc/firejail/whitelist-common.inc 25include /etc/firejail/whitelist-common.inc
26
27ipc-namespace
28netfilter
29nogroups
30shell none
31
32private-dev
33private-tmp
34
35noexec ${HOME}
36noexec /tmp
diff --git a/etc/dino.profile b/etc/dino.profile
index 3de858618..5f587ef8a 100644
--- a/etc/dino.profile
+++ b/etc/dino.profile
@@ -16,6 +16,7 @@ whitelist ${HOME}/.local/share/dino
16include /etc/firejail/whitelist-common.inc 16include /etc/firejail/whitelist-common.inc
17 17
18caps.drop all 18caps.drop all
19ipc-namespace
19netfilter 20netfilter
20no3d 21no3d
21nogroups 22nogroups
diff --git a/etc/eog.profile b/etc/eog.profile
index 7c2cd557c..32ceebb1d 100644
--- a/etc/eog.profile
+++ b/etc/eog.profile
@@ -11,6 +11,7 @@ include /etc/firejail/disable-devel.inc
11include /etc/firejail/disable-passwdmgr.inc 11include /etc/firejail/disable-passwdmgr.inc
12 12
13caps.drop all 13caps.drop all
14ipc-namespace
14net none 15net none
15netfilter 16netfilter
16no3d 17no3d
diff --git a/etc/evince.profile b/etc/evince.profile
index ae50425b9..508a0d1a5 100644
--- a/etc/evince.profile
+++ b/etc/evince.profile
@@ -11,6 +11,7 @@ include /etc/firejail/disable-devel.inc
11include /etc/firejail/disable-passwdmgr.inc 11include /etc/firejail/disable-passwdmgr.inc
12 12
13caps.drop all 13caps.drop all
14ipc-namespace
14netfilter 15netfilter
15#net none - creates some problems on some distributions 16#net none - creates some problems on some distributions
16no3d 17no3d
diff --git a/etc/evolution.profile b/etc/evolution.profile
index 04bf480ff..6fe58cbf9 100644
--- a/etc/evolution.profile
+++ b/etc/evolution.profile
@@ -20,6 +20,7 @@ include /etc/firejail/disable-devel.inc
20include /etc/firejail/disable-passwdmgr.inc 20include /etc/firejail/disable-passwdmgr.inc
21 21
22caps.drop all 22caps.drop all
23ipc-namespace
23netfilter 24netfilter
24no3d 25no3d
25nogroups 26nogroups
diff --git a/etc/file-roller.profile b/etc/file-roller.profile
index a3f687651..6bc74c79d 100644
--- a/etc/file-roller.profile
+++ b/etc/file-roller.profile
@@ -9,6 +9,7 @@ include /etc/firejail/disable-devel.inc
9include /etc/firejail/disable-passwdmgr.inc 9include /etc/firejail/disable-passwdmgr.inc
10 10
11caps.drop all 11caps.drop all
12ipc-namespace
12net none 13net none
13netfilter 14netfilter
14no3d 15no3d
diff --git a/etc/firefox.profile b/etc/firefox.profile
index 4d96c05c8..0013062a5 100644
--- a/etc/firefox.profile
+++ b/etc/firefox.profile
@@ -16,7 +16,9 @@ include /etc/firejail/disable-programs.inc
16include /etc/firejail/disable-devel.inc 16include /etc/firejail/disable-devel.inc
17 17
18caps.drop all 18caps.drop all
19ipc-namespace
19netfilter 20netfilter
21nogroups
20nonewprivs 22nonewprivs
21noroot 23noroot
22protocol unix,inet,inet6,netlink 24protocol unix,inet,inet6,netlink
diff --git a/etc/gedit.profile b/etc/gedit.profile
index 07bdb1bbe..2c429c808 100644
--- a/etc/gedit.profile
+++ b/etc/gedit.profile
@@ -14,6 +14,7 @@ include /etc/firejail/disable-programs.inc
14include /etc/firejail/disable-passwdmgr.inc 14include /etc/firejail/disable-passwdmgr.inc
15 15
16caps.drop all 16caps.drop all
17ipc-namespace
17netfilter 18netfilter
18net none 19net none
19no3d 20no3d
diff --git a/etc/gimp.profile b/etc/gimp.profile
index 5f8ccb4fb..59d88e9ec 100644
--- a/etc/gimp.profile
+++ b/etc/gimp.profile
@@ -9,6 +9,7 @@ include /etc/firejail/disable-programs.inc
9include /etc/firejail/disable-passwdmgr.inc 9include /etc/firejail/disable-passwdmgr.inc
10 10
11caps.drop all 11caps.drop all
12ipc-namespace
12netfilter 13netfilter
13net none 14net none
14nogroups 15nogroups
diff --git a/etc/gnome-calculator.profile b/etc/gnome-calculator.profile
index e9366f07d..28f0d646c 100644
--- a/etc/gnome-calculator.profile
+++ b/etc/gnome-calculator.profile
@@ -16,6 +16,7 @@ include /etc/firejail/whitelist-common.inc
16 16
17#Options 17#Options
18caps.drop all 18caps.drop all
19ipc-namespace
19netfilter 20netfilter
20#net none 21#net none
21no3d 22no3d
diff --git a/etc/hexchat.profile b/etc/hexchat.profile
index d24f492d8..18cbcea5c 100644
--- a/etc/hexchat.profile
+++ b/etc/hexchat.profile
@@ -12,6 +12,7 @@ include /etc/firejail/disable-programs.inc
12include /etc/firejail/disable-devel.inc 12include /etc/firejail/disable-devel.inc
13 13
14caps.drop all 14caps.drop all
15ipc-namespace
15netfilter 16netfilter
16no3d 17no3d
17nogroups 18nogroups
diff --git a/etc/jd-gui.profile b/etc/jd-gui.profile
index 6ff618187..61841e2c5 100644
--- a/etc/jd-gui.profile
+++ b/etc/jd-gui.profile
@@ -16,6 +16,7 @@ include /etc/firejail/disable-devel.inc
16 16
17#Options 17#Options
18caps.drop all 18caps.drop all
19ipc-namespace
19net none 20net none
20netfilter 21netfilter
21no3d 22no3d
diff --git a/etc/lollypop.profile b/etc/lollypop.profile
index e84118b9e..d6d2cdd73 100644
--- a/etc/lollypop.profile
+++ b/etc/lollypop.profile
@@ -17,6 +17,7 @@ include /etc/firejail/disable-devel.inc
17 17
18#Options 18#Options
19caps.drop all 19caps.drop all
20ipc-namespace
20netfilter 21netfilter
21no3d 22no3d
22nogroups 23nogroups
diff --git a/etc/multimc5.profile b/etc/multimc5.profile
index 12a7646ae..4b561405b 100644
--- a/etc/multimc5.profile
+++ b/etc/multimc5.profile
@@ -25,6 +25,7 @@ include /etc/firejail/whitelist-common.inc
25 25
26#Options 26#Options
27caps.drop all 27caps.drop all
28ipc-namespace
28netfilter 29netfilter
29nogroups 30nogroups
30nonewprivs 31nonewprivs
diff --git a/etc/mumble.profile b/etc/mumble.profile
index c5c6a4d1a..19d7a131a 100644
--- a/etc/mumble.profile
+++ b/etc/mumble.profile
@@ -17,6 +17,7 @@ whitelist ${HOME}/.local/share/data/Mumble
17include /etc/firejail/whitelist-common.inc 17include /etc/firejail/whitelist-common.inc
18 18
19caps.drop all 19caps.drop all
20ipc-namespace
20netfilter 21netfilter
21no3d 22no3d
22nonewprivs 23nonewprivs
diff --git a/etc/pdfsam.profile b/etc/pdfsam.profile
index dfe463c98..db8aacaa5 100644
--- a/etc/pdfsam.profile
+++ b/etc/pdfsam.profile
@@ -14,6 +14,7 @@ include /etc/firejail/disable-devel.inc
14 14
15#Options 15#Options
16caps.drop all 16caps.drop all
17ipc-namespace
17net none 18net none
18netfilter 19netfilter
19no3d 20no3d
diff --git a/etc/pithos.profile b/etc/pithos.profile
index c25b5772b..f599283fb 100644
--- a/etc/pithos.profile
+++ b/etc/pithos.profile
@@ -16,6 +16,7 @@ include /etc/firejail/whitelist-common.inc
16 16
17#Options 17#Options
18caps.drop all 18caps.drop all
19ipc-namespace
19netfilter 20netfilter
20no3d 21no3d
21nogroups 22nogroups
diff --git a/etc/polari.profile b/etc/polari.profile
index 834a8b3d6..db5fc9487 100644
--- a/etc/polari.profile
+++ b/etc/polari.profile
@@ -23,7 +23,18 @@ include /etc/firejail/whitelist-common.inc
23 23
24caps.drop all 24caps.drop all
25netfilter 25netfilter
26no3d
27nogroups
26nonewprivs 28nonewprivs
27noroot 29noroot
30nosound
28protocol unix,inet,inet6 31protocol unix,inet,inet6
29seccomp 32seccomp
33shell none
34tracelog
35
36private-dev
37private-tmp
38
39noexec ${HOME}
40noexec /tmp
diff --git a/etc/ssh.profile b/etc/ssh.profile
index 425841399..f9750972f 100644
--- a/etc/ssh.profile
+++ b/etc/ssh.profile
@@ -13,6 +13,7 @@ include /etc/firejail/disable-programs.inc
13include /etc/firejail/disable-passwdmgr.inc 13include /etc/firejail/disable-passwdmgr.inc
14 14
15caps.drop all 15caps.drop all
16ipc-namespace
16netfilter 17netfilter
17no3d 18no3d
18nogroups 19nogroups
diff --git a/etc/steam.profile b/etc/steam.profile
index 536588e4b..eef91a0d5 100644
--- a/etc/steam.profile
+++ b/etc/steam.profile
@@ -11,6 +11,7 @@ include /etc/firejail/disable-devel.inc
11include /etc/firejail/disable-passwdmgr.inc 11include /etc/firejail/disable-passwdmgr.inc
12 12
13caps.drop all 13caps.drop all
14ipc-namespace
14netfilter 15netfilter
15nogroups 16nogroups
16nonewprivs 17nonewprivs
diff --git a/etc/totem.profile b/etc/totem.profile
index fadfbb00b..d280296f0 100644
--- a/etc/totem.profile
+++ b/etc/totem.profile
@@ -12,6 +12,7 @@ include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-passwdmgr.inc 12include /etc/firejail/disable-passwdmgr.inc
13 13
14caps.drop all 14caps.drop all
15ipc-namespace
15netfilter 16netfilter
16nogroups 17nogroups
17nonewprivs 18nonewprivs
diff --git a/etc/vlc.profile b/etc/vlc.profile
index 21282dfbd..5d759ffd4 100644
--- a/etc/vlc.profile
+++ b/etc/vlc.profile
@@ -11,6 +11,7 @@ include /etc/firejail/disable-devel.inc
11include /etc/firejail/disable-passwdmgr.inc 11include /etc/firejail/disable-passwdmgr.inc
12 12
13caps.drop all 13caps.drop all
14ipc-namespace
14netfilter 15netfilter
15# nogroups 16# nogroups
16nonewprivs 17nonewprivs
diff --git a/etc/wget.profile b/etc/wget.profile
index 3ba97d95d..52c8b68a1 100644
--- a/etc/wget.profile
+++ b/etc/wget.profile
@@ -9,6 +9,7 @@ include /etc/firejail/disable-programs.inc
9include /etc/firejail/disable-passwdmgr.inc 9include /etc/firejail/disable-passwdmgr.inc
10 10
11caps.drop all 11caps.drop all
12ipc-namespace
12netfilter 13netfilter
13no3d 14no3d
14nogroups 15nogroups
diff --git a/etc/wireshark.profile b/etc/wireshark.profile
index dc224b31c..45ccfb89a 100644
--- a/etc/wireshark.profile
+++ b/etc/wireshark.profile
@@ -17,6 +17,7 @@ include /etc/firejail/disable-passwdmgr.inc
17#noroot 17#noroot
18#protocol unix,inet,inet6,netlink 18#protocol unix,inet,inet6,netlink
19 19
20ipc-namespace
20netfilter 21netfilter
21no3d 22no3d
22nogroups 23nogroups
diff --git a/etc/xonotic.profile b/etc/xonotic.profile
index 6bfb26484..0bf372fc6 100644
--- a/etc/xonotic.profile
+++ b/etc/xonotic.profile
@@ -22,6 +22,7 @@ include /etc/firejail/whitelist-common.inc
22 22
23#Options 23#Options
24caps.drop all 24caps.drop all
25ipc-namespace
25netfilter 26netfilter
26nogroups 27nogroups
27nonewprivs 28nonewprivs