aboutsummaryrefslogtreecommitdiffstats
path: root/etc/profile-m-z
diff options
context:
space:
mode:
authorLibravatar rusty-snake <41237666+rusty-snake@users.noreply.github.com>2020-05-02 17:58:02 +0000
committerLibravatar GitHub <noreply@github.com>2020-05-02 17:58:02 +0000
commit49280197ccf830b708b1b7c4d6fb8b3590f44da2 (patch)
tree76ae21d4faa96a2970738aedc693b6b9ed3183c8 /etc/profile-m-z
parentfixes for zeal.profile (diff)
downloadfirejail-49280197ccf830b708b1b7c4d6fb8b3590f44da2.tar.gz
firejail-49280197ccf830b708b1b7c4d6fb8b3590f44da2.tar.zst
firejail-49280197ccf830b708b1b7c4d6fb8b3590f44da2.zip
various hardening (#3394)
Diffstat (limited to 'etc/profile-m-z')
-rw-r--r--etc/profile-m-z/megaglest.profile4
-rw-r--r--etc/profile-m-z/minetest.profile3
-rw-r--r--etc/profile-m-z/ostrichriders.profile2
-rw-r--r--etc/profile-m-z/pingus.profile10
-rw-r--r--etc/profile-m-z/scorched3d-wrapper.profile3
-rw-r--r--etc/profile-m-z/scorched3d.profile3
-rw-r--r--etc/profile-m-z/supertux2.profile5
-rw-r--r--etc/profile-m-z/torcs.profile4
-rw-r--r--etc/profile-m-z/transmission-gtk.profile1
9 files changed, 34 insertions, 1 deletions
diff --git a/etc/profile-m-z/megaglest.profile b/etc/profile-m-z/megaglest.profile
index 86e7f129e..19f9edf05 100644
--- a/etc/profile-m-z/megaglest.profile
+++ b/etc/profile-m-z/megaglest.profile
@@ -18,9 +18,13 @@ include disable-xdg.inc
18 18
19mkdir ${HOME}/.megaglest 19mkdir ${HOME}/.megaglest
20whitelist ${HOME}/.megaglest 20whitelist ${HOME}/.megaglest
21whitelist /usr/share/megaglest
21include whitelist-common.inc 22include whitelist-common.inc
23include whitelist-runuser-common.inc
24include whitelist-usr-share-common.inc
22include whitelist-var-common.inc 25include whitelist-var-common.inc
23 26
27apparmor
24caps.drop all 28caps.drop all
25ipc-namespace 29ipc-namespace
26netfilter 30netfilter
diff --git a/etc/profile-m-z/minetest.profile b/etc/profile-m-z/minetest.profile
index 619173024..f201b13d7 100644
--- a/etc/profile-m-z/minetest.profile
+++ b/etc/profile-m-z/minetest.profile
@@ -21,7 +21,10 @@ mkdir ${HOME}/.cache/minetest
21mkdir ${HOME}/.minetest 21mkdir ${HOME}/.minetest
22whitelist ${HOME}/.cache/minetest 22whitelist ${HOME}/.cache/minetest
23whitelist ${HOME}/.minetest 23whitelist ${HOME}/.minetest
24whitelist /usr/share/minetest
24include whitelist-common.inc 25include whitelist-common.inc
26include whitelist-runuser-common.inc
27include whitelist-usr-share-common.inc
25include whitelist-var-common.inc 28include whitelist-var-common.inc
26 29
27caps.drop all 30caps.drop all
diff --git a/etc/profile-m-z/ostrichriders.profile b/etc/profile-m-z/ostrichriders.profile
index 378d267f6..4cd4dae17 100644
--- a/etc/profile-m-z/ostrichriders.profile
+++ b/etc/profile-m-z/ostrichriders.profile
@@ -18,7 +18,9 @@ include disable-xdg.inc
18 18
19mkdir ${HOME}/.ostrichriders 19mkdir ${HOME}/.ostrichriders
20whitelist ${HOME}/.ostrichriders 20whitelist ${HOME}/.ostrichriders
21whitelist /usr/share/ostrichriders
21include whitelist-common.inc 22include whitelist-common.inc
23include whitelist-usr-share-common.inc
22include whitelist-var-common.inc 24include whitelist-var-common.inc
23 25
24caps.drop all 26caps.drop all
diff --git a/etc/profile-m-z/pingus.profile b/etc/profile-m-z/pingus.profile
index cfe45b9c9..0b6a9ad5f 100644
--- a/etc/profile-m-z/pingus.profile
+++ b/etc/profile-m-z/pingus.profile
@@ -14,10 +14,14 @@ include disable-exec.inc
14include disable-interpreters.inc 14include disable-interpreters.inc
15include disable-passwdmgr.inc 15include disable-passwdmgr.inc
16include disable-programs.inc 16include disable-programs.inc
17include disable-xdg.inc
17 18
18mkdir ${HOME}/.pingus 19mkdir ${HOME}/.pingus
19whitelist ${HOME}/.pingus 20whitelist ${HOME}/.pingus
21whitelist /usr/share/pingus
20include whitelist-common.inc 22include whitelist-common.inc
23include whitelist-runuser-common.inc
24include whitelist-usr-share-common.inc
21include whitelist-var-common.inc 25include whitelist-var-common.inc
22 26
23apparmor 27apparmor
@@ -33,9 +37,13 @@ novideo
33protocol unix,netlink 37protocol unix,netlink
34seccomp 38seccomp
35shell none 39shell none
40tracelog
36 41
37# private-bin pingus 42disbale-mnt
43private-bin pingus,pingus.bin,sh
44private-cache
38private-dev 45private-dev
46private-etc machine-id
39private-tmp 47private-tmp
40 48
41dbus-user none 49dbus-user none
diff --git a/etc/profile-m-z/scorched3d-wrapper.profile b/etc/profile-m-z/scorched3d-wrapper.profile
index 9cbb19bff..507d0827e 100644
--- a/etc/profile-m-z/scorched3d-wrapper.profile
+++ b/etc/profile-m-z/scorched3d-wrapper.profile
@@ -3,5 +3,8 @@
3# Persistent local customizations 3# Persistent local customizations
4include scorched3d-wrapper.local 4include scorched3d-wrapper.local
5 5
6whitelist /usr/share/opengl-games-utils
7private-bin basename,bash,cut,glxinfo,grep,head,sed,zenity
8
6# Redirect 9# Redirect
7include scorched3d.profile 10include scorched3d.profile
diff --git a/etc/profile-m-z/scorched3d.profile b/etc/profile-m-z/scorched3d.profile
index b5e51198b..6a1003c33 100644
--- a/etc/profile-m-z/scorched3d.profile
+++ b/etc/profile-m-z/scorched3d.profile
@@ -18,7 +18,10 @@ include disable-xdg.inc
18 18
19mkdir ${HOME}/.scorched3d 19mkdir ${HOME}/.scorched3d
20whitelist ${HOME}/.scorched3d 20whitelist ${HOME}/.scorched3d
21whitelist /usr/share/scorched3d
21include whitelist-common.inc 22include whitelist-common.inc
23include whitelist-runuser-common.inc
24include whitelist-usr-share-common.inc
22include whitelist-var-common.inc 25include whitelist-var-common.inc
23 26
24caps.drop all 27caps.drop all
diff --git a/etc/profile-m-z/supertux2.profile b/etc/profile-m-z/supertux2.profile
index e1cdb114c..ceaae8fbf 100644
--- a/etc/profile-m-z/supertux2.profile
+++ b/etc/profile-m-z/supertux2.profile
@@ -14,10 +14,14 @@ include disable-exec.inc
14include disable-interpreters.inc 14include disable-interpreters.inc
15include disable-passwdmgr.inc 15include disable-passwdmgr.inc
16include disable-programs.inc 16include disable-programs.inc
17include disable-xdg.inc
17 18
18mkdir ${HOME}/.local/share/supertux2 19mkdir ${HOME}/.local/share/supertux2
19whitelist ${HOME}/.local/share/supertux2 20whitelist ${HOME}/.local/share/supertux2
21whitelist /usr/share/supertux2
20include whitelist-common.inc 22include whitelist-common.inc
23include whitelist-runuser-common.inc
24include whitelist-usr-share-common.inc
21include whitelist-var-common.inc 25include whitelist-var-common.inc
22 26
23apparmor 27apparmor
@@ -33,6 +37,7 @@ novideo
33protocol unix,netlink 37protocol unix,netlink
34seccomp 38seccomp
35shell none 39shell none
40tracelog
36 41
37disable-mnt 42disable-mnt
38# private-bin supertux2 43# private-bin supertux2
diff --git a/etc/profile-m-z/torcs.profile b/etc/profile-m-z/torcs.profile
index 8dcd7447b..1ed78934e 100644
--- a/etc/profile-m-z/torcs.profile
+++ b/etc/profile-m-z/torcs.profile
@@ -18,7 +18,10 @@ include disable-xdg.inc
18 18
19mkdir ${HOME}/.torcs 19mkdir ${HOME}/.torcs
20whitelist ${HOME}/.torcs 20whitelist ${HOME}/.torcs
21whitelist /usr/share/games/torcs
22whitelist /var/games/torcs
21include whitelist-common.inc 23include whitelist-common.inc
24include whitelist-usr-share-common.inc
22include whitelist-var-common.inc 25include whitelist-var-common.inc
23 26
24caps.drop all 27caps.drop all
@@ -37,6 +40,7 @@ shell none
37tracelog 40tracelog
38 41
39disable-mnt 42disable-mnt
43private-bin bash,chmod,cp,mkdir,rm,torcs
40private-cache 44private-cache
41private-dev 45private-dev
42private-tmp 46private-tmp
diff --git a/etc/profile-m-z/transmission-gtk.profile b/etc/profile-m-z/transmission-gtk.profile
index baa970307..03111ec56 100644
--- a/etc/profile-m-z/transmission-gtk.profile
+++ b/etc/profile-m-z/transmission-gtk.profile
@@ -10,6 +10,7 @@ include globals.local
10include whitelist-runuser-common.inc 10include whitelist-runuser-common.inc
11 11
12private-bin transmission-gtk 12private-bin transmission-gtk
13private-cache
13 14
14ignore memory-deny-write-execute 15ignore memory-deny-write-execute
15 16