aboutsummaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
authorLibravatar Tad <tad@spotco.us>2018-03-18 21:35:55 -0400
committerLibravatar Tad <tad@spotco.us>2018-03-18 21:35:55 -0400
commit5018a209d23e7f7e7dae2a93b3b57a40e5e3a980 (patch)
tree5da1d145515595c1ee94bd1ef13d090fb8bfaa82 /etc
parenttypo (diff)
downloadfirejail-5018a209d23e7f7e7dae2a93b3b57a40e5e3a980.tar.gz
firejail-5018a209d23e7f7e7dae2a93b3b57a40e5e3a980.tar.zst
firejail-5018a209d23e7f7e7dae2a93b3b57a40e5e3a980.zip
Misc profile hardening and fixes
Diffstat (limited to 'etc')
-rw-r--r--etc/asunder.profile3
-rw-r--r--etc/atool.profile1
-rw-r--r--etc/brasero.profile1
-rw-r--r--etc/frozen-bubble.profile2
-rw-r--r--etc/gnome-twitch.profile1
-rw-r--r--etc/open-invaders.profile1
-rw-r--r--etc/pingus.profile1
-rw-r--r--etc/simutrans.profile1
-rw-r--r--etc/supertux2.profile2
-rw-r--r--etc/terasology.profile2
10 files changed, 11 insertions, 4 deletions
diff --git a/etc/asunder.profile b/etc/asunder.profile
index ce68f8897..0fbc3a158 100644
--- a/etc/asunder.profile
+++ b/etc/asunder.profile
@@ -10,8 +10,6 @@ noblacklist ${HOME}/.asunder_album_genre
10noblacklist ${HOME}/.asunder_album_title 10noblacklist ${HOME}/.asunder_album_title
11noblacklist ${HOME}/.asunder_album_artist 11noblacklist ${HOME}/.asunder_album_artist
12 12
13
14
15include /etc/firejail/disable-common.inc 13include /etc/firejail/disable-common.inc
16include /etc/firejail/disable-devel.inc 14include /etc/firejail/disable-devel.inc
17include /etc/firejail/disable-passwdmgr.inc 15include /etc/firejail/disable-passwdmgr.inc
@@ -29,7 +27,6 @@ protocol unix,inet,inet6
29seccomp 27seccomp
30shell none 28shell none
31 29
32
33#private-bin vlc,cvlc,nvlc,rvlc,qvlc,svlc 30#private-bin vlc,cvlc,nvlc,rvlc,qvlc,svlc
34private-dev 31private-dev
35private-tmp 32private-tmp
diff --git a/etc/atool.profile b/etc/atool.profile
index c2e772f9d..4cc3f02de 100644
--- a/etc/atool.profile
+++ b/etc/atool.profile
@@ -14,6 +14,7 @@ include /etc/firejail/disable-programs.inc
14 14
15caps.drop all 15caps.drop all
16netfilter 16netfilter
17net none
17no3d 18no3d
18nodvd 19nodvd
19nogroups 20nogroups
diff --git a/etc/brasero.profile b/etc/brasero.profile
index f90d4688a..90a7b176e 100644
--- a/etc/brasero.profile
+++ b/etc/brasero.profile
@@ -13,6 +13,7 @@ include /etc/firejail/disable-passwdmgr.inc
13include /etc/firejail/disable-programs.inc 13include /etc/firejail/disable-programs.inc
14 14
15caps.drop all 15caps.drop all
16net none
16nogroups 17nogroups
17nonewprivs 18nonewprivs
18noroot 19noroot
diff --git a/etc/frozen-bubble.profile b/etc/frozen-bubble.profile
index 0660137e0..ca38ed1b8 100644
--- a/etc/frozen-bubble.profile
+++ b/etc/frozen-bubble.profile
@@ -10,6 +10,7 @@ blacklist /run/user/*/bus
10noblacklist ${HOME}/.frozen-bubble 10noblacklist ${HOME}/.frozen-bubble
11 11
12include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-devel.inc
13include /etc/firejail/disable-passwdmgr.inc 14include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc 15include /etc/firejail/disable-programs.inc
15 16
@@ -29,6 +30,7 @@ protocol unix,netlink
29seccomp 30seccomp
30shell none 31shell none
31 32
33disable-mnt
32# private-bin frozen-bubble 34# private-bin frozen-bubble
33private-dev 35private-dev
34# private-etc none 36# private-etc none
diff --git a/etc/gnome-twitch.profile b/etc/gnome-twitch.profile
index 9c94404d1..9e8f2a241 100644
--- a/etc/gnome-twitch.profile
+++ b/etc/gnome-twitch.profile
@@ -30,6 +30,7 @@ protocol unix,inet,inet6
30seccomp 30seccomp
31shell none 31shell none
32 32
33disable-mnt
33private-dev 34private-dev
34private-tmp 35private-tmp
35 36
diff --git a/etc/open-invaders.profile b/etc/open-invaders.profile
index 331bfa939..191f8d87b 100644
--- a/etc/open-invaders.profile
+++ b/etc/open-invaders.profile
@@ -10,6 +10,7 @@ blacklist /run/user/*/bus
10noblacklist ${HOME}/.openinvaders 10noblacklist ${HOME}/.openinvaders
11 11
12include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-devel.inc
13include /etc/firejail/disable-passwdmgr.inc 14include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc 15include /etc/firejail/disable-programs.inc
15 16
diff --git a/etc/pingus.profile b/etc/pingus.profile
index 65aeedd86..ec7eff632 100644
--- a/etc/pingus.profile
+++ b/etc/pingus.profile
@@ -10,6 +10,7 @@ blacklist /run/user/*/bus
10noblacklist ${HOME}/.pingus 10noblacklist ${HOME}/.pingus
11 11
12include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-devel.inc
13include /etc/firejail/disable-passwdmgr.inc 14include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc 15include /etc/firejail/disable-programs.inc
15 16
diff --git a/etc/simutrans.profile b/etc/simutrans.profile
index 89d1f2925..8b4113d2f 100644
--- a/etc/simutrans.profile
+++ b/etc/simutrans.profile
@@ -10,6 +10,7 @@ blacklist /run/user/*/bus
10noblacklist ${HOME}/.simutrans 10noblacklist ${HOME}/.simutrans
11 11
12include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-devel.inc
13include /etc/firejail/disable-passwdmgr.inc 14include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc 15include /etc/firejail/disable-programs.inc
15 16
diff --git a/etc/supertux2.profile b/etc/supertux2.profile
index 2b5bb07c3..d60d7fa5f 100644
--- a/etc/supertux2.profile
+++ b/etc/supertux2.profile
@@ -10,6 +10,7 @@ blacklist /run/user/*/bus
10noblacklist ${HOME}/.local/share/supertux2 10noblacklist ${HOME}/.local/share/supertux2
11 11
12include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-devel.inc
13include /etc/firejail/disable-passwdmgr.inc 14include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc 15include /etc/firejail/disable-programs.inc
15 16
@@ -29,6 +30,7 @@ protocol unix,netlink
29seccomp 30seccomp
30shell none 31shell none
31 32
33disable-mnt
32# private-bin supertux2 34# private-bin supertux2
33private-dev 35private-dev
34# private-etc none 36# private-etc none
diff --git a/etc/terasology.profile b/etc/terasology.profile
index 3d27134c4..ea25938d3 100644
--- a/etc/terasology.profile
+++ b/etc/terasology.profile
@@ -1,7 +1,7 @@
1# Firejail profile for terasology 1# Firejail profile for terasology
2# This file is overwritten after every install/update 2# This file is overwritten after every install/update
3# Persistent local customizations 3# Persistent local customizations
4include /etc/firejail/default.local 4include /etc/firejail/terasology.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7