aboutsummaryrefslogtreecommitdiffstats
path: root/etc/mupdf.profile
diff options
context:
space:
mode:
authorLibravatar Tad <tad@spotco.us>2017-08-07 01:22:08 -0400
committerLibravatar Tad <tad@spotco.us>2017-08-07 01:22:08 -0400
commit9e3ba319be6b9546d7e8f450ca419ee2f3f4040b (patch)
tree0aebe82de78a61877c267f4dcb2ebcc13a2e37c9 /etc/mupdf.profile
parentvarious profile fixes (#1433) (diff)
downloadfirejail-9e3ba319be6b9546d7e8f450ca419ee2f3f4040b.tar.gz
firejail-9e3ba319be6b9546d7e8f450ca419ee2f3f4040b.tar.zst
firejail-9e3ba319be6b9546d7e8f450ca419ee2f3f4040b.zip
Unify all profiles
Diffstat (limited to 'etc/mupdf.profile')
-rw-r--r--etc/mupdf.profile24
1 files changed, 11 insertions, 13 deletions
diff --git a/etc/mupdf.profile b/etc/mupdf.profile
index ca61edfdd..a55a01206 100644
--- a/etc/mupdf.profile
+++ b/etc/mupdf.profile
@@ -1,15 +1,15 @@
1# Persistent global definitions go here 1# Firejail profile for mupdf
2# This file is overwritten after every install/update
3# Persistent local customizations
4include /etc/firejail/mupdf.local
5# Persistent global definitions
2include /etc/firejail/globals.local 6include /etc/firejail/globals.local
3 7
4# This file is overwritten during software install.
5# Persistent customizations should go in a .local file.
6include /etc/firejail/mupdf.local
7 8
8# mupdf reader profile
9include /etc/firejail/disable-common.inc 9include /etc/firejail/disable-common.inc
10include /etc/firejail/disable-programs.inc
11include /etc/firejail/disable-devel.inc 10include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-passwdmgr.inc 11include /etc/firejail/disable-passwdmgr.inc
12include /etc/firejail/disable-programs.inc
13 13
14caps.drop all 14caps.drop all
15net none 15net none
@@ -22,15 +22,13 @@ seccomp
22shell none 22shell none
23tracelog 23tracelog
24 24
25private-tmp 25# private-bin mupdf,sh,tempfile,rm
26private-dev 26private-dev
27private-etc fonts 27private-etc fonts
28 28private-tmp
29# mupdf will never write anything
30read-only ${HOME} 29read-only ${HOME}
31 30
32# 31# CLOBBERED COMMENTS
33# Experimental: 32# Experimental:
34# 33# mupdf will never write anything
35#seccomp.keep access,arch_prctl,brk,clone,close,connect,execve,exit_group,fchmod,fchown,fcntl,fstat,futex,getcwd,getpeername,getrlimit,getsockname,getsockopt,lseek,lstat,mlock,mmap,mprotect,mremap,munmap,nanosleep,open,poll,prctl,read,recvfrom,recvmsg,restart_syscall,rt_sigaction,rt_sigprocmask,select,sendmsg,set_robust_list,set_tid_address,setresgid,setresuid,shmat,shmctl,shmget,shutdown,socket,stat,sysinfo,uname,unshare,wait4,write,writev 34# seccomp.keep access,arch_prctl,brk,clone,close,connect,execve,exit_group,fchmod,fchown,fcntl,fstat,futex,getcwd,getpeername,getrlimit,getsockname,getsockopt,lseek,lstat,mlock,mmap,mprotect,mremap,munmap,nanosleep,open,poll,prctl,read,recvfrom,recvmsg,restart_syscall,rt_sigaction,rt_sigprocmask,select,sendmsg,set_robust_list,set_tid_address,setresgid,setresuid,shmat,shmctl,shmget,shutdown,socket,stat,sysinfo,uname,unshare,wait4,write,writev
36# private-bin mupdf,sh,tempfile,rm