diff options
author | 2020-04-07 16:14:25 -0500 | |
---|---|---|
committer | 2020-04-07 16:14:25 -0500 | |
commit | 3848b98961614e1776b29ecfb76ef4c750b6b25f (patch) | |
tree | 3c7f0b623978562ee23fba7f52b6a039571cebea /etc/x-terminal-emulator.profile | |
parent | dbus-proxy (gnome_games) (diff) | |
download | firejail-3848b98961614e1776b29ecfb76ef4c750b6b25f.tar.gz firejail-3848b98961614e1776b29ecfb76ef4c750b6b25f.tar.zst firejail-3848b98961614e1776b29ecfb76ef4c750b6b25f.zip |
Replace `nodbus` with dbus-* filters
See
- 07fac581f6b9b5ed068f4c54a9521b51826375c5 for new dbus filters
- https://github.com/netblue30/firejail/pull/3326#issuecomment-610423183
Except for ocenaudio, access/restrictions on dbus options should
be unchanged
Ocenaudio profile: dbus filters were sandboxed (initially `nodbus`
was enabled) since comments indicated blocking dbus meant
preferences were broken
Diffstat (limited to 'etc/x-terminal-emulator.profile')
-rw-r--r-- | etc/x-terminal-emulator.profile | 4 |
1 files changed, 3 insertions, 1 deletions
diff --git a/etc/x-terminal-emulator.profile b/etc/x-terminal-emulator.profile index b6424f342..fe0781336 100644 --- a/etc/x-terminal-emulator.profile +++ b/etc/x-terminal-emulator.profile | |||
@@ -8,7 +8,6 @@ include globals.local | |||
8 | caps.drop all | 8 | caps.drop all |
9 | ipc-namespace | 9 | ipc-namespace |
10 | net none | 10 | net none |
11 | nodbus | ||
12 | nogroups | 11 | nogroups |
13 | noroot | 12 | noroot |
14 | nou2f | 13 | nou2f |
@@ -17,4 +16,7 @@ seccomp | |||
17 | 16 | ||
18 | private-dev | 17 | private-dev |
19 | 18 | ||
19 | dbus-user none | ||
20 | dbus-system none | ||
21 | |||
20 | noexec /tmp | 22 | noexec /tmp |