aboutsummaryrefslogtreecommitdiffstats
path: root/etc/clementine.profile
diff options
context:
space:
mode:
authorLibravatar netblue30 <netblue30@yahoo.com>2017-10-18 09:15:19 -0400
committerLibravatar netblue30 <netblue30@yahoo.com>2017-10-18 09:15:19 -0400
commitb4c84b85a03da21179803077616fc77aeb9c8e22 (patch)
treecd3282447decd09a065c36c8acb49e932a25aaef /etc/clementine.profile
parentremove links for uninstalled programs (diff)
downloadfirejail-b4c84b85a03da21179803077616fc77aeb9c8e22.tar.gz
firejail-b4c84b85a03da21179803077616fc77aeb9c8e22.tar.zst
firejail-b4c84b85a03da21179803077616fc77aeb9c8e22.zip
profile updates
Diffstat (limited to 'etc/clementine.profile')
-rw-r--r--etc/clementine.profile5
1 files changed, 5 insertions, 0 deletions
diff --git a/etc/clementine.profile b/etc/clementine.profile
index 1d93e5f2c..619086437 100644
--- a/etc/clementine.profile
+++ b/etc/clementine.profile
@@ -12,6 +12,8 @@ include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-passwdmgr.inc 12include /etc/firejail/disable-passwdmgr.inc
13include /etc/firejail/disable-programs.inc 13include /etc/firejail/disable-programs.inc
14 14
15include /etc/firejail/whitelist-var-common.inc
16
15caps.drop all 17caps.drop all
16nonewprivs 18nonewprivs
17noroot 19noroot
@@ -20,3 +22,6 @@ novideo
20protocol unix,inet,inet6 22protocol unix,inet,inet6
21# Clementine makes ioprio_set system calls, which are blacklisted by default. 23# Clementine makes ioprio_set system calls, which are blacklisted by default.
22seccomp.drop @cpu-emulation,@debug,@obsolete,@privileged,@resources,add_key,fanotify_init,io_cancel,io_destroy,io_getevents,io_setup,io_submit,kcmp,keyctl,name_to_handle_at,ni_syscall,open_by_handle_at,personality,process_vm_readv,ptrace,remap_file_pages,request_key,syslog,umount,userfaultfd,vmsplice 24seccomp.drop @cpu-emulation,@debug,@obsolete,@privileged,@resources,add_key,fanotify_init,io_cancel,io_destroy,io_getevents,io_setup,io_submit,kcmp,keyctl,name_to_handle_at,ni_syscall,open_by_handle_at,personality,process_vm_readv,ptrace,remap_file_pages,request_key,syslog,umount,userfaultfd,vmsplice
25
26private-dev
27private-tmp