aboutsummaryrefslogtreecommitdiffstats
path: root/etc/ffmpeg.profile
diff options
context:
space:
mode:
authorLibravatar netblue30 <netblue30@yahoo.com>2017-09-21 08:15:19 -0400
committerLibravatar netblue30 <netblue30@yahoo.com>2017-09-21 08:15:19 -0400
commit0ec8ec63375efaf87a5f8af48c83eac560dacd20 (patch)
tree978dab36c48f26091d2e1919d1f561d522577737 /etc/ffmpeg.profile
parentFixup 17a2edf9be3d1144db1a262c5358bf190c9b272b (diff)
downloadfirejail-0ec8ec63375efaf87a5f8af48c83eac560dacd20.tar.gz
firejail-0ec8ec63375efaf87a5f8af48c83eac560dacd20.tar.zst
firejail-0ec8ec63375efaf87a5f8af48c83eac560dacd20.zip
added ffmpeg.profile, removed ssh-agent from firecfg
Diffstat (limited to 'etc/ffmpeg.profile')
-rw-r--r--etc/ffmpeg.profile33
1 files changed, 33 insertions, 0 deletions
diff --git a/etc/ffmpeg.profile b/etc/ffmpeg.profile
new file mode 100644
index 000000000..e098c95e3
--- /dev/null
+++ b/etc/ffmpeg.profile
@@ -0,0 +1,33 @@
1# Firejail profile for default
2# This file is overwritten after every install/update
3quiet
4# Persistent local customizations
5include /etc/firejail/ffmpeg.local
6# Persistent global definitions
7include /etc/firejail/globals.local
8
9include /etc/firejail/disable-common.inc
10include /etc/firejail/disable-devel.inc
11include /etc/firejail/disable-passwdmgr.inc
12include /etc/firejail/disable-programs.inc
13
14caps.drop all
15net none
16no3d
17nodvd
18nosound
19notv
20novideo
21nonewprivs
22noroot
23# protocol none - needs to be implemented!
24seccomp
25# seccomp.keep futex,write,read,munmap,fstat,mprotect,mmap,open,close,stat,lseek,brk,rt_sigaction,rt_sigprocmask,ioctl,access,select,madvise,getpid,clone,execve,fcntl,getdents,readlink,getrlimit,getrusage,statfs,getpriority,setpriority,arch_prctl,sched_getaffinity,set_tid_address,set_robust_list,getrandom
26# memory-deny-write-execute - it breaks old versions of ffmpeg
27shell none
28tracelog
29
30private-tmp
31private-dev
32private-bin ffmpeg
33include /etc/firejail/whitelist-var-common.inc