aboutsummaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
authorLibravatar rusty-snake <print_hello_world+Public@protonmail.com>2020-01-08 14:46:03 +0100
committerLibravatar rusty-snake <print_hello_world+Public@protonmail.com>2020-01-08 14:46:26 +0100
commit105dce9bba1136484251daf645e578d64366bbed (patch)
treeb87b8cc22f56a7a51f294be32cebdfa50da60595 /etc
parentMerge pull request #3102 from kris7t/dhcp-client (diff)
downloadfirejail-105dce9bba1136484251daf645e578d64366bbed.tar.gz
firejail-105dce9bba1136484251daf645e578d64366bbed.tar.zst
firejail-105dce9bba1136484251daf645e578d64366bbed.zip
misc profile fixups and hardening
Diffstat (limited to 'etc')
-rw-r--r--etc/celluloid.profile2
-rw-r--r--etc/curl.profile1
-rw-r--r--etc/gimp.profile1
-rw-r--r--etc/midori.profile7
-rw-r--r--etc/pdftotext.profile2
-rw-r--r--etc/shotcut.profile1
6 files changed, 13 insertions, 1 deletions
diff --git a/etc/celluloid.profile b/etc/celluloid.profile
index ab68c7f13..5a3bf0008 100644
--- a/etc/celluloid.profile
+++ b/etc/celluloid.profile
@@ -29,7 +29,7 @@ include whitelist-var-common.inc
29apparmor 29apparmor
30caps.drop all 30caps.drop all
31netfilter 31netfilter
32# nodbus -- uses dconf 32# nodbus -- uses dconf, MPRIS
33nogroups 33nogroups
34nonewprivs 34nonewprivs
35noroot 35noroot
diff --git a/etc/curl.profile b/etc/curl.profile
index 2624e5545..679f5a152 100644
--- a/etc/curl.profile
+++ b/etc/curl.profile
@@ -33,6 +33,7 @@ novideo
33protocol inet,inet6 33protocol inet,inet6
34seccomp 34seccomp
35shell none 35shell none
36tracelog
36 37
37# private-bin curl 38# private-bin curl
38private-cache 39private-cache
diff --git a/etc/gimp.profile b/etc/gimp.profile
index 5c0631eb2..94035bc02 100644
--- a/etc/gimp.profile
+++ b/etc/gimp.profile
@@ -21,6 +21,7 @@ noblacklist ${PICTURES}
21 21
22include disable-common.inc 22include disable-common.inc
23include disable-exec.inc 23include disable-exec.inc
24include disable-devel.inc
24include disable-passwdmgr.inc 25include disable-passwdmgr.inc
25include disable-programs.inc 26include disable-programs.inc
26include disable-xdg.inc 27include disable-xdg.inc
diff --git a/etc/midori.profile b/etc/midori.profile
index ffae4919f..e11e2acaa 100644
--- a/etc/midori.profile
+++ b/etc/midori.profile
@@ -9,6 +9,7 @@ include globals.local
9# noexec ${HOME} breaks DRM binaries. 9# noexec ${HOME} breaks DRM binaries.
10?BROWSER_ALLOW_DRM: ignore noexec ${HOME} 10?BROWSER_ALLOW_DRM: ignore noexec ${HOME}
11 11
12noblacklist ${HOME}/.cache/midori
12noblacklist ${HOME}/.config/midori 13noblacklist ${HOME}/.config/midori
13noblacklist ${HOME}/.local/share/midori 14noblacklist ${HOME}/.local/share/midori
14# noblacklist ${HOME}/.local/share/webkit 15# noblacklist ${HOME}/.local/share/webkit
@@ -16,11 +17,17 @@ noblacklist ${HOME}/.local/share/midori
16noblacklist ${HOME}/.pki 17noblacklist ${HOME}/.pki
17noblacklist ${HOME}/.local/share/pki 18noblacklist ${HOME}/.local/share/pki
18 19
20noblacklist ${HOME}/.cache/gnome-mplayer
21noblacklist ${HOME}/.config/gnome-mplayer
22noblacklist ${HOME}/.lastpass
23
19include disable-common.inc 24include disable-common.inc
20include disable-devel.inc 25include disable-devel.inc
21include disable-exec.inc 26include disable-exec.inc
22include disable-interpreters.inc 27include disable-interpreters.inc
28#include disable-passwdmgr.inc
23include disable-programs.inc 29include disable-programs.inc
30include disable-xdg.inc
24 31
25mkdir ${HOME}/.cache/midori 32mkdir ${HOME}/.cache/midori
26mkdir ${HOME}/.config/midori 33mkdir ${HOME}/.config/midori
diff --git a/etc/pdftotext.profile b/etc/pdftotext.profile
index e9572d914..f8448f514 100644
--- a/etc/pdftotext.profile
+++ b/etc/pdftotext.profile
@@ -22,6 +22,7 @@ include whitelist-usr-share-common.inc
22include whitelist-var-common.inc 22include whitelist-var-common.inc
23 23
24caps.drop all 24caps.drop all
25ipc-namespace
25machine-id 26machine-id
26net none 27net none
27no3d 28no3d
@@ -41,6 +42,7 @@ tracelog
41x11 none 42x11 none
42 43
43private-bin pdftotext 44private-bin pdftotext
45private-cache
44private-dev 46private-dev
45private-etc alternatives 47private-etc alternatives
46private-tmp 48private-tmp
diff --git a/etc/shotcut.profile b/etc/shotcut.profile
index 5b3c5439d..072cc2c0d 100644
--- a/etc/shotcut.profile
+++ b/etc/shotcut.profile
@@ -29,6 +29,7 @@ nou2f
29protocol unix 29protocol unix
30seccomp 30seccomp
31shell none 31shell none
32tracelog
32 33
33#private-bin melt,nice,qmelt,shotcut 34#private-bin melt,nice,qmelt,shotcut
34private-cache 35private-cache