diff options
author | Fred Barclay <Fred-Barclay@users.noreply.github.com> | 2020-08-15 17:27:10 -0500 |
---|---|---|
committer | GitHub <noreply@github.com> | 2020-08-15 17:27:10 -0500 |
commit | 5d741795c3bb2060730e282a8f512b999418e098 (patch) | |
tree | 8ff4e8937c10e995b54869ff82effbc73b888fca /etc/profile-m-z/mplayer.profile | |
parent | Merge pull request #3559 from smitsohu/smitsohu-bandwidth (diff) | |
download | firejail-5d741795c3bb2060730e282a8f512b999418e098.tar.gz firejail-5d741795c3bb2060730e282a8f512b999418e098.tar.zst firejail-5d741795c3bb2060730e282a8f512b999418e098.zip |
Use whitelisting for video players (#3472)
* Use whitelisting for video players
See https://github.com/netblue30/firejail/pull/3469
* Update media player whitelists
See reviews at https://github.com/netblue30/firejail/pull/3472
Block $DOCUMENTS
Make $DESKTOP read-only
* Review fixes: include read-only Desktop in whitelist
Diffstat (limited to 'etc/profile-m-z/mplayer.profile')
-rw-r--r-- | etc/profile-m-z/mplayer.profile | 13 |
1 files changed, 9 insertions, 4 deletions
diff --git a/etc/profile-m-z/mplayer.profile b/etc/profile-m-z/mplayer.profile index cd25d6c0b..f4f862cb9 100644 --- a/etc/profile-m-z/mplayer.profile +++ b/etc/profile-m-z/mplayer.profile | |||
@@ -7,8 +7,6 @@ include mplayer.local | |||
7 | include globals.local | 7 | include globals.local |
8 | 8 | ||
9 | noblacklist ${HOME}/.mplayer | 9 | noblacklist ${HOME}/.mplayer |
10 | noblacklist ${MUSIC} | ||
11 | noblacklist ${VIDEOS} | ||
12 | 10 | ||
13 | include disable-common.inc | 11 | include disable-common.inc |
14 | include disable-devel.inc | 12 | include disable-devel.inc |
@@ -16,8 +14,16 @@ include disable-exec.inc | |||
16 | include disable-interpreters.inc | 14 | include disable-interpreters.inc |
17 | include disable-passwdmgr.inc | 15 | include disable-passwdmgr.inc |
18 | include disable-programs.inc | 16 | include disable-programs.inc |
19 | include disable-xdg.inc | ||
20 | 17 | ||
18 | read-only ${DESKTOP} | ||
19 | mkdir ${HOME}/.mplayer | ||
20 | whitelist ${HOME}/.mplayer | ||
21 | whitelist ${DESKTOP} | ||
22 | whitelist ${DOWNLOADS} | ||
23 | whitelist ${MUSIC} | ||
24 | whitelist ${PICTURES} | ||
25 | whitelist ${VIDEOS} | ||
26 | include whitelist-common.inc | ||
21 | include whitelist-usr-share-common.inc | 27 | include whitelist-usr-share-common.inc |
22 | include whitelist-var-common.inc | 28 | include whitelist-var-common.inc |
23 | 29 | ||
@@ -36,4 +42,3 @@ shell none | |||
36 | private-bin mplayer | 42 | private-bin mplayer |
37 | private-dev | 43 | private-dev |
38 | private-tmp | 44 | private-tmp |
39 | |||