aboutsummaryrefslogtreecommitdiffstats
path: root/etc/profile-a-l/clementine.profile
diff options
context:
space:
mode:
authorLibravatar netblue30 <netblue30@yahoo.com>2020-10-28 08:16:05 -0400
committerLibravatar netblue30 <netblue30@yahoo.com>2020-10-28 08:16:05 -0400
commit305aa40922c22ee87b017681b9a241b72098224f (patch)
tree43515112eb4e5454e978baf827726b39b6332ac1 /etc/profile-a-l/clementine.profile
parentslightly change changelog date to not have duplicate (diff)
downloadfirejail-305aa40922c22ee87b017681b9a241b72098224f.tar.gz
firejail-305aa40922c22ee87b017681b9a241b72098224f.tar.zst
firejail-305aa40922c22ee87b017681b9a241b72098224f.zip
profile fixes
Diffstat (limited to 'etc/profile-a-l/clementine.profile')
-rw-r--r--etc/profile-a-l/clementine.profile9
1 files changed, 8 insertions, 1 deletions
diff --git a/etc/profile-a-l/clementine.profile b/etc/profile-a-l/clementine.profile
index 4d92157d0..387b5f0a7 100644
--- a/etc/profile-a-l/clementine.profile
+++ b/etc/profile-a-l/clementine.profile
@@ -12,22 +12,29 @@ noblacklist ${MUSIC}
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
15include disable-exec.inc
15include disable-interpreters.inc 16include disable-interpreters.inc
16include disable-passwdmgr.inc 17include disable-passwdmgr.inc
17include disable-programs.inc 18include disable-programs.inc
18include disable-xdg.inc 19include disable-xdg.inc
19 20
20include whitelist-var-common.inc 21include whitelist-var-common.inc
22include whitelist-usr-share-common.inc
23include whitelist-runuser-common.inc
21 24
25apparmor
22caps.drop all 26caps.drop all
23nonewprivs 27nonewprivs
24noroot 28noroot
25notv 29notv
26nou2f 30nou2f
27novideo 31novideo
28protocol unix,inet,inet6 32protocol unix,inet,inet6,netlink
29# blacklisting of ioprio_set system calls breaks clementine 33# blacklisting of ioprio_set system calls breaks clementine
30seccomp !ioprio_set 34seccomp !ioprio_set
31 35
32private-dev 36private-dev
33private-tmp 37private-tmp
38
39dbus-system none
40# dbus-user none