aboutsummaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
authorLibravatar smitsohu <smitsohu@gmail.com>2017-08-31 23:18:45 +0200
committerLibravatar smitsohu <smitsohu@gmail.com>2017-08-31 23:18:45 +0200
commit24934a4710e2acd015292e41414e24a7c3197038 (patch)
treef27789958aa1ad06ad7967ab6b2d92a3918257a8 /etc
parentmerges (diff)
downloadfirejail-24934a4710e2acd015292e41414e24a7c3197038.tar.gz
firejail-24934a4710e2acd015292e41414e24a7c3197038.tar.zst
firejail-24934a4710e2acd015292e41414e24a7c3197038.zip
improve servers, harden musescore
Diffstat (limited to 'etc')
-rw-r--r--etc/cpio.profile2
-rw-r--r--etc/cvlc.profile2
-rw-r--r--etc/dnscrypt-proxy.profile7
-rw-r--r--etc/dnsmasq.profile3
-rw-r--r--etc/file.profile1
-rw-r--r--etc/musescore.profile5
-rw-r--r--etc/unbound.profile7
7 files changed, 24 insertions, 3 deletions
diff --git a/etc/cpio.profile b/etc/cpio.profile
index 4122e2c92..7f4bc4a84 100644
--- a/etc/cpio.profile
+++ b/etc/cpio.profile
@@ -17,9 +17,9 @@ include /etc/firejail/disable-programs.inc
17 17
18caps.drop all 18caps.drop all
19net none 19net none
20net none
21no3d 20no3d
22nodvd 21nodvd
22nonewprivs
23nosound 23nosound
24notv 24notv
25novideo 25novideo
diff --git a/etc/cvlc.profile b/etc/cvlc.profile
index f095f487e..81ccbc530 100644
--- a/etc/cvlc.profile
+++ b/etc/cvlc.profile
@@ -5,7 +5,7 @@ include /etc/firejail/cvlc.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8# clvc doesn't like private-bin 8# cvlc doesn't like private-bin
9ignore private-bin 9ignore private-bin
10 10
11# Redirect 11# Redirect
diff --git a/etc/dnscrypt-proxy.profile b/etc/dnscrypt-proxy.profile
index 7d48905ee..e99a2b89b 100644
--- a/etc/dnscrypt-proxy.profile
+++ b/etc/dnscrypt-proxy.profile
@@ -5,6 +5,8 @@ include /etc/firejail/dnscrypt-proxy.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8blacklist /tmp/.X11-unix
9
8noblacklist /sbin 10noblacklist /sbin
9noblacklist /usr/sbin 11noblacklist /usr/sbin
10 12
@@ -13,12 +15,17 @@ include /etc/firejail/disable-devel.inc
13include /etc/firejail/disable-passwdmgr.inc 15include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc 16include /etc/firejail/disable-programs.inc
15 17
18caps
16no3d 19no3d
17nodvd 20nodvd
21nonewprivs
18nosound 22nosound
19notv 23notv
20novideo 24novideo
21seccomp.drop mount,umount2,ptrace,kexec_load,kexec_file_load,open_by_handle_at,init_module,finit_module,delete_module,iopl,ioperm,swapon,swapoff,syslog,process_vm_readv,process_vm_writev,sysfs,_sysctl,adjtimex,clock_adjtime,lookup_dcookie,perf_event_open,fanotify_init,kcmp,add_key,request_key,keyctl,uselib,acct,modify_ldt,pivot_root,io_setup,io_destroy,io_getevents,io_submit,io_cancel,remap_file_pages,mbind,get_mempolicy,set_mempolicy,migrate_pages,move_pages,vmsplice,perf_event_open 25seccomp.drop mount,umount2,ptrace,kexec_load,kexec_file_load,open_by_handle_at,init_module,finit_module,delete_module,iopl,ioperm,swapon,swapoff,syslog,process_vm_readv,process_vm_writev,sysfs,_sysctl,adjtimex,clock_adjtime,lookup_dcookie,perf_event_open,fanotify_init,kcmp,add_key,request_key,keyctl,uselib,acct,modify_ldt,pivot_root,io_setup,io_destroy,io_getevents,io_submit,io_cancel,remap_file_pages,mbind,get_mempolicy,set_mempolicy,migrate_pages,move_pages,vmsplice,perf_event_open
22 26
27disable-mnt
23private 28private
24private-dev 29private-dev
30
31memory-deny-write-execute
diff --git a/etc/dnsmasq.profile b/etc/dnsmasq.profile
index 0893dff35..e38244ef8 100644
--- a/etc/dnsmasq.profile
+++ b/etc/dnsmasq.profile
@@ -5,6 +5,8 @@ include /etc/firejail/dnsmasq.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8blacklist /tmp/.X11-unix
9
8noblacklist /sbin 10noblacklist /sbin
9noblacklist /usr/sbin 11noblacklist /usr/sbin
10 12
@@ -14,7 +16,6 @@ include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc 16include /etc/firejail/disable-programs.inc
15 17
16caps 18caps
17netfilter
18no3d 19no3d
19nodvd 20nodvd
20nonewprivs 21nonewprivs
diff --git a/etc/file.profile b/etc/file.profile
index f3b08e34b..a83b2cf7d 100644
--- a/etc/file.profile
+++ b/etc/file.profile
@@ -21,6 +21,7 @@ nogroups
21nonewprivs 21nonewprivs
22nosound 22nosound
23notv 23notv
24novideo
24protocol unix 25protocol unix
25seccomp 26seccomp
26shell none 27shell none
diff --git a/etc/musescore.profile b/etc/musescore.profile
index bd00bea69..3b5a0b13c 100644
--- a/etc/musescore.profile
+++ b/etc/musescore.profile
@@ -10,6 +10,11 @@ noblacklist ~/.config/MuseScore
10noblacklist ~/.local/share/data/MusE 10noblacklist ~/.local/share/data/MusE
11noblacklist ~/.local/share/data/MuseScore 11noblacklist ~/.local/share/data/MuseScore
12 12
13include /etc/firejail/disable-common.inc
14include /etc/firejail/disable-devel.inc
15include /etc/firejail/disable-passwdmgr.inc
16include /etc/firejail/disable-programs.inc
17
13caps.drop all 18caps.drop all
14netfilter 19netfilter
15no3d 20no3d
diff --git a/etc/unbound.profile b/etc/unbound.profile
index 4775a450d..73c538dbe 100644
--- a/etc/unbound.profile
+++ b/etc/unbound.profile
@@ -5,6 +5,8 @@ include /etc/firejail/unbound.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8blacklist /tmp/.X11-unix
9
8noblacklist /sbin 10noblacklist /sbin
9noblacklist /usr/sbin 11noblacklist /usr/sbin
10 12
@@ -13,12 +15,17 @@ include /etc/firejail/disable-devel.inc
13include /etc/firejail/disable-passwdmgr.inc 15include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc 16include /etc/firejail/disable-programs.inc
15 17
18caps
16no3d 19no3d
17nodvd 20nodvd
21nonewprivs
18nosound 22nosound
19notv 23notv
20novideo 24novideo
21seccomp.drop mount,umount2,ptrace,kexec_load,kexec_file_load,open_by_handle_at,init_module,finit_module,delete_module,iopl,ioperm,swapon,swapoff,syslog,process_vm_readv,process_vm_writev,sysfs,_sysctl,adjtimex,clock_adjtime,lookup_dcookie,perf_event_open,fanotify_init,kcmp,add_key,request_key,keyctl,uselib,acct,modify_ldt,pivot_root,io_setup,io_destroy,io_getevents,io_submit,io_cancel,remap_file_pages,mbind,get_mempolicy,set_mempolicy,migrate_pages,move_pages,vmsplice,perf_event_open 25seccomp.drop mount,umount2,ptrace,kexec_load,kexec_file_load,open_by_handle_at,init_module,finit_module,delete_module,iopl,ioperm,swapon,swapoff,syslog,process_vm_readv,process_vm_writev,sysfs,_sysctl,adjtimex,clock_adjtime,lookup_dcookie,perf_event_open,fanotify_init,kcmp,add_key,request_key,keyctl,uselib,acct,modify_ldt,pivot_root,io_setup,io_destroy,io_getevents,io_submit,io_cancel,remap_file_pages,mbind,get_mempolicy,set_mempolicy,migrate_pages,move_pages,vmsplice,perf_event_open
22 26
27disable-mnt
23private 28private
24private-dev 29private-dev
30
31memory-deny-write-execute