aboutsummaryrefslogtreecommitdiffstats
path: root/etc/gnome-hexgl.profile
diff options
context:
space:
mode:
authorLibravatar Fred Barclay <Fred-Barclay@users.noreply.github.com>2020-04-07 16:14:25 -0500
committerLibravatar Fred Barclay <Fred-Barclay@users.noreply.github.com>2020-04-07 16:14:25 -0500
commit3848b98961614e1776b29ecfb76ef4c750b6b25f (patch)
tree3c7f0b623978562ee23fba7f52b6a039571cebea /etc/gnome-hexgl.profile
parentdbus-proxy (gnome_games) (diff)
downloadfirejail-3848b98961614e1776b29ecfb76ef4c750b6b25f.tar.gz
firejail-3848b98961614e1776b29ecfb76ef4c750b6b25f.tar.zst
firejail-3848b98961614e1776b29ecfb76ef4c750b6b25f.zip
Replace `nodbus` with dbus-* filters
See - 07fac581f6b9b5ed068f4c54a9521b51826375c5 for new dbus filters - https://github.com/netblue30/firejail/pull/3326#issuecomment-610423183 Except for ocenaudio, access/restrictions on dbus options should be unchanged Ocenaudio profile: dbus filters were sandboxed (initially `nodbus` was enabled) since comments indicated blocking dbus meant preferences were broken
Diffstat (limited to 'etc/gnome-hexgl.profile')
-rw-r--r--etc/gnome-hexgl.profile4
1 files changed, 3 insertions, 1 deletions
diff --git a/etc/gnome-hexgl.profile b/etc/gnome-hexgl.profile
index a06ccc9c1..873a47ea9 100644
--- a/etc/gnome-hexgl.profile
+++ b/etc/gnome-hexgl.profile
@@ -23,7 +23,6 @@ include whitelist-var-common.inc
23apparmor 23apparmor
24caps.drop all 24caps.drop all
25net none 25net none
26nodbus
27nodvd 26nodvd
28nogroups 27nogroups
29nonewprivs 28nonewprivs
@@ -44,5 +43,8 @@ private-dev
44private-etc machine-id 43private-etc machine-id
45private-tmp 44private-tmp
46 45
46dbus-user none
47dbus-system none
48
47read-only ${HOME} 49read-only ${HOME}
48read-write ${HOME}/.cache/mesa_shader_cache 50read-write ${HOME}/.cache/mesa_shader_cache