aboutsummaryrefslogtreecommitdiffstats
path: root/etc/ffmpeg.profile
diff options
context:
space:
mode:
authorLibravatar glitsj16 <glitsj16@users.noreply.github.com>2019-02-24 21:22:41 +0000
committerLibravatar GitHub <noreply@github.com>2019-02-24 21:22:41 +0000
commitadad97e8029880317e33f65ee5d6a18189363e8b (patch)
tree20ea682559d1bd08233e80d66b64ee2d52e61816 /etc/ffmpeg.profile
parentHarden exiftool.profile (#2456) (diff)
downloadfirejail-adad97e8029880317e33f65ee5d6a18189363e8b.tar.gz
firejail-adad97e8029880317e33f65ee5d6a18189363e8b.tar.zst
firejail-adad97e8029880317e33f65ee5d6a18189363e8b.zip
Harden ffmpeg.profile (#2457)
Diffstat (limited to 'etc/ffmpeg.profile')
-rw-r--r--etc/ffmpeg.profile5
1 files changed, 5 insertions, 0 deletions
diff --git a/etc/ffmpeg.profile b/etc/ffmpeg.profile
index 8aa6198df..44b5d5530 100644
--- a/etc/ffmpeg.profile
+++ b/etc/ffmpeg.profile
@@ -15,7 +15,9 @@ include disable-programs.inc
15 15
16include whitelist-var-common.inc 16include whitelist-var-common.inc
17 17
18apparmor
18caps.drop all 19caps.drop all
20machine-id
19net none 21net none
20no3d 22no3d
21nodbus 23nodbus
@@ -33,7 +35,10 @@ shell none
33tracelog 35tracelog
34 36
35private-bin ffmpeg 37private-bin ffmpeg
38private-cache
36private-dev 39private-dev
37private-tmp 40private-tmp
38 41
39# memory-deny-write-execute - it breaks old versions of ffmpeg 42# memory-deny-write-execute - it breaks old versions of ffmpeg
43noexec ${HOME}
44noexec /tmp