aboutsummaryrefslogtreecommitdiffstats
path: root/etc/profile-m-z
diff options
context:
space:
mode:
authorLibravatar rusty-snake <41237666+rusty-snake@users.noreply.github.com>2020-10-23 14:06:37 +0200
committerLibravatar rusty-snake <41237666+rusty-snake@users.noreply.github.com>2020-10-23 14:06:37 +0200
commit582ae38e811a7a768d2cfbcf93e711ebbc984e07 (patch)
treef290de320d79ced20ee3e194e91e12cab0d0baea /etc/profile-m-z
parentMerge pull request #3683 from jmetrius/vlc-aacs-fix (diff)
downloadfirejail-582ae38e811a7a768d2cfbcf93e711ebbc984e07.tar.gz
firejail-582ae38e811a7a768d2cfbcf93e711ebbc984e07.tar.zst
firejail-582ae38e811a7a768d2cfbcf93e711ebbc984e07.zip
harden peek; update README.md; add gnome-sound-…
…recorder to firecfg.config
Diffstat (limited to 'etc/profile-m-z')
-rw-r--r--etc/profile-m-z/peek.profile24
1 files changed, 21 insertions, 3 deletions
diff --git a/etc/profile-m-z/peek.profile b/etc/profile-m-z/peek.profile
index 66fdd6496..28a7da404 100644
--- a/etc/profile-m-z/peek.profile
+++ b/etc/profile-m-z/peek.profile
@@ -17,7 +17,18 @@ include disable-passwdmgr.inc
17include disable-programs.inc 17include disable-programs.inc
18include disable-xdg.inc 18include disable-xdg.inc
19 19
20#mkdir ${HOME}/.cache/peek
21#whitelist ${HOME}/.cache/peek
22#whitelist ${PICTURES}
23#whitelist ${VIDEOS}
24#include whitelist-common.inc
25include whitelist-runuser-common.inc
26include whitelist-usr-share-common.inc
27include whitelist-var-common.inc
28
29apparmor
20caps.drop all 30caps.drop all
31machine-id
21net none 32net none
22no3d 33no3d
23nodvd 34nodvd
@@ -31,13 +42,20 @@ novideo
31protocol unix 42protocol unix
32seccomp 43seccomp
33shell none 44shell none
45tracelog
34 46
35# private-bin breaks gif mode, mp4 and webm mode work fine however 47disable-mnt
36# private-bin convert,ffmpeg,peek 48private-bin bash,convert,ffmpeg,firejail,fish,peek,sh,which,zsh
37private-dev 49private-dev
50private-etc dconf,firejail,fonts,gtk-3.0,login.defs,pango,passwd,X11
38private-tmp 51private-tmp
39 52
40dbus-user none 53dbus-user filter
54dbus-user.own com.uploadedlobster.peek
55dbus-user.talk ca.desrt.dconf
56dbus-user.talk org.freedesktop.FileManager1
57dbus-user.talk org.freedesktop.Notifications
58dbus-user.talk org.gnome.Shell.Screencast
41dbus-system none 59dbus-system none
42 60
43memory-deny-write-execute 61memory-deny-write-execute