aboutsummaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
authorLibravatar glitsj16 <glitsj16@users.noreply.github.com>2020-05-27 18:23:44 +0000
committerLibravatar GitHub <noreply@github.com>2020-05-27 18:23:44 +0000
commit3d7a75b5e74a22766398e65a23d833e3442163d2 (patch)
tree65ac8b4e163b6796b278df8a96710b7f38b3fce0 /etc
parentnew profile: mocp (#3437) (diff)
downloadfirejail-3d7a75b5e74a22766398e65a23d833e3442163d2.tar.gz
firejail-3d7a75b5e74a22766398e65a23d833e3442163d2.tar.zst
firejail-3d7a75b5e74a22766398e65a23d833e3442163d2.zip
harden mpg123.profile (#3438)
* harden mpg123.profile * drop nodvd from mpg123.profile
Diffstat (limited to 'etc')
-rw-r--r--etc/profile-m-z/mpg123.profile10
1 files changed, 7 insertions, 3 deletions
diff --git a/etc/profile-m-z/mpg123.profile b/etc/profile-m-z/mpg123.profile
index 6e18aa401..b1ab81c1e 100644
--- a/etc/profile-m-z/mpg123.profile
+++ b/etc/profile-m-z/mpg123.profile
@@ -1,13 +1,13 @@
1# Firejail profile for mpg123 1# Firejail profile for mpg123
2# Description: MPEG audio player/decoder 2# Description: MPEG audio player/decoder
3# This file is overwritten after every install/update 3# This file is overwritten after every install/update
4quiet
4# Persistent local customizations 5# Persistent local customizations
5include mpg123.local 6include mpg123.local
6# Persistent global definitions 7# Persistent global definitions
7include globals.local 8include globals.local
8 9
9noblacklist ${MUSIC} 10noblacklist ${MUSIC}
10noblacklist ${VIDEOS}
11 11
12include disable-common.inc 12include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
@@ -23,19 +23,23 @@ include whitelist-var-common.inc
23apparmor 23apparmor
24caps.drop all 24caps.drop all
25netfilter 25netfilter
26no3d
26nogroups 27nogroups
27nonewprivs 28nonewprivs
28noroot 29noroot
30notv
29nou2f 31nou2f
32novideo
30protocol unix,inet,inet6,netlink 33protocol unix,inet,inet6,netlink
31seccomp 34seccomp
32shell none 35shell none
36tracelog
33 37
34#private-bin mpg123* 38#private-bin mpg123*
35private-dev 39private-dev
36private-tmp 40private-tmp
37 41
38memory-deny-write-execute
39
40dbus-user none 42dbus-user none
41dbus-system none 43dbus-system none
44
45memory-deny-write-execute