aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLibravatar glitsj16 <glitsj16@users.noreply.github.com>2019-02-20 22:55:48 +0000
committerLibravatar GitHub <noreply@github.com>2019-02-20 22:55:48 +0000
commit970d0bb1f783297a5d66672a9450befbe9948d8f (patch)
tree31225c1cd7fd089ff4eb25dbfacea1d1af35064c
parentMerge pull request #2428 from glitsj16/assogiate (diff)
parentHarden devilspie2 profile (diff)
downloadfirejail-970d0bb1f783297a5d66672a9450befbe9948d8f.tar.gz
firejail-970d0bb1f783297a5d66672a9450befbe9948d8f.tar.zst
firejail-970d0bb1f783297a5d66672a9450befbe9948d8f.zip
Merge pull request #2435 from glitsj16/devilspies
Harden devilspie{2} profiles
-rw-r--r--etc/devilspie.profile3
-rw-r--r--etc/devilspie2.profile2
2 files changed, 5 insertions, 0 deletions
diff --git a/etc/devilspie.profile b/etc/devilspie.profile
index a809bee0c..d0a1ccf41 100644
--- a/etc/devilspie.profile
+++ b/etc/devilspie.profile
@@ -13,9 +13,12 @@ include disable-devel.inc
13include disable-interpreters.inc 13include disable-interpreters.inc
14include disable-passwdmgr.inc 14include disable-passwdmgr.inc
15include disable-programs.inc 15include disable-programs.inc
16include disable-xdg.inc
16 17
18apparmor
17caps.drop all 19caps.drop all
18ipc-namespace 20ipc-namespace
21# machine-id breaks audio; it should work fine in setups where sound is not required
19machine-id 22machine-id
20net none 23net none
21no3d 24no3d
diff --git a/etc/devilspie2.profile b/etc/devilspie2.profile
index d8c10413b..fbf765fa2 100644
--- a/etc/devilspie2.profile
+++ b/etc/devilspie2.profile
@@ -13,7 +13,9 @@ include disable-devel.inc
13include disable-interpreters.inc 13include disable-interpreters.inc
14include disable-passwdmgr.inc 14include disable-passwdmgr.inc
15include disable-programs.inc 15include disable-programs.inc
16include disable-xdg.inc
16 17
18apparmor
17caps.drop all 19caps.drop all
18ipc-namespace 20ipc-namespace
19machine-id 21machine-id