aboutsummaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
authorLibravatar The Fox in the Shell <KellerFuchs@hashbang.sh>2016-05-25 02:46:09 +0200
committerLibravatar The Fox in the Shell <KellerFuchs@hashbang.sh>2016-05-25 15:01:13 +0200
commit845bd06665539af002b1bf74d2b7cb9e6cf11e0e (patch)
tree8f4a6133c718f1e98db1d52869a7d8070dbe9b84 /etc
parentmidori.profile: Use nonewprivs and noroot (diff)
downloadfirejail-845bd06665539af002b1bf74d2b7cb9e6cf11e0e.tar.gz
firejail-845bd06665539af002b1bf74d2b7cb9e6cf11e0e.tar.zst
firejail-845bd06665539af002b1bf74d2b7cb9e6cf11e0e.zip
profiles: Add nonewprivs where sensible
Diffstat (limited to 'etc')
-rw-r--r--etc/0ad.profile1
-rw-r--r--etc/Mathematica.profile1
-rw-r--r--etc/abrowser.profile1
-rw-r--r--etc/atril.profile1
-rw-r--r--etc/audacious.profile1
-rw-r--r--etc/aweather.profile1
-rw-r--r--etc/bitlbee.profile1
-rw-r--r--etc/cherrytree.profile1
-rw-r--r--etc/clementine.profile1
-rw-r--r--etc/cmus.profile1
-rw-r--r--etc/conkeror.profile1
-rw-r--r--etc/cyberfox.profile1
-rw-r--r--etc/deadbeef.profile1
-rw-r--r--etc/default.profile1
-rw-r--r--etc/deluge.profile1
-rw-r--r--etc/dillo.profile1
-rw-r--r--etc/dnsmasq.profile1
-rw-r--r--etc/dropbox.profile1
-rw-r--r--etc/empathy.profile1
-rw-r--r--etc/epiphany.profile2
-rw-r--r--etc/evince.profile1
-rw-r--r--etc/fbreader.profile1
-rw-r--r--etc/filezilla.profile1
-rw-r--r--etc/firefox.profile1
-rw-r--r--etc/flashpeak-slimjet.profile1
-rw-r--r--etc/gnome-mplayer.profile1
-rw-r--r--etc/google-play-music-desktop-player.profile1
-rw-r--r--etc/gpredict.profile1
-rw-r--r--etc/gwenview.profile1
-rw-r--r--etc/hedgewars.profile1
-rw-r--r--etc/hexchat.profile1
-rw-r--r--etc/kmail.profile1
-rw-r--r--etc/mcabber.profile1
-rw-r--r--etc/mupen64plus.profile1
-rw-r--r--etc/netsurf.profile1
-rw-r--r--etc/okular.profile1
-rw-r--r--etc/palemoon.profile1
-rw-r--r--etc/parole.profile1
-rw-r--r--etc/pidgin.profile1
-rw-r--r--etc/polari.profile1
-rw-r--r--etc/qbittorrent.profile1
-rw-r--r--etc/qtox.profile1
-rw-r--r--etc/quassel.profile1
-rw-r--r--etc/quiterss.profile1
-rw-r--r--etc/qutebrowser.profile1
-rw-r--r--etc/rhythmbox.profile1
-rw-r--r--etc/rtorrent.profile1
-rw-r--r--etc/seamonkey.profile1
-rw-r--r--etc/skype.profile1
-rw-r--r--etc/spotify.profile1
-rw-r--r--etc/ssh.profile1
-rw-r--r--etc/steam.profile1
-rw-r--r--etc/stellarium.profile1
-rw-r--r--etc/telegram.profile1
-rw-r--r--etc/totem.profile1
-rw-r--r--etc/transmission-gtk.profile1
-rw-r--r--etc/transmission-qt.profile1
-rw-r--r--etc/uget-gtk.profile1
-rw-r--r--etc/vivaldi.profile1
-rw-r--r--etc/vlc.profile1
-rw-r--r--etc/warzone2100.profile1
-rw-r--r--etc/weechat.profile1
-rw-r--r--etc/wesnoth.profile1
-rw-r--r--etc/wine.profile1
-rw-r--r--etc/xchat.profile1
-rw-r--r--etc/xplayer.profile1
-rw-r--r--etc/xreader.profile1
-rw-r--r--etc/xviewer.profile1
68 files changed, 68 insertions, 1 deletions
diff --git a/etc/0ad.profile b/etc/0ad.profile
index f8a3ce23d..e6540fb5d 100644
--- a/etc/0ad.profile
+++ b/etc/0ad.profile
@@ -12,6 +12,7 @@ protocol unix,inet,inet6,netlink
12netfilter 12netfilter
13tracelog 13tracelog
14noroot 14noroot
15nonewprivs
15 16
16# Whitelists 17# Whitelists
17noblacklist ~/.cache/0ad 18noblacklist ~/.cache/0ad
diff --git a/etc/Mathematica.profile b/etc/Mathematica.profile
index 05131df43..75dbebcf0 100644
--- a/etc/Mathematica.profile
+++ b/etc/Mathematica.profile
@@ -16,4 +16,5 @@ include /etc/firejail/disable-passwdmgr.inc
16 16
17caps.drop all 17caps.drop all
18seccomp 18seccomp
19nonewprivs
19noroot 20noroot
diff --git a/etc/abrowser.profile b/etc/abrowser.profile
index 949635258..6a06ce76b 100644
--- a/etc/abrowser.profile
+++ b/etc/abrowser.profile
@@ -11,6 +11,7 @@ seccomp
11protocol unix,inet,inet6,netlink 11protocol unix,inet,inet6,netlink
12netfilter 12netfilter
13tracelog 13tracelog
14nonewprivs
14noroot 15noroot
15 16
16whitelist ${DOWNLOADS} 17whitelist ${DOWNLOADS}
diff --git a/etc/atril.profile b/etc/atril.profile
index d1a7b25f8..c20a8c7b3 100644
--- a/etc/atril.profile
+++ b/etc/atril.profile
@@ -9,6 +9,7 @@ include /etc/firejail/disable-passwdmgr.inc
9caps.drop all 9caps.drop all
10seccomp 10seccomp
11protocol unix,inet,inet6 11protocol unix,inet,inet6
12nonewprivs
12noroot 13noroot
13tracelog 14tracelog
14netfilter 15netfilter
diff --git a/etc/audacious.profile b/etc/audacious.profile
index 290faa260..0a1598dee 100644
--- a/etc/audacious.profile
+++ b/etc/audacious.profile
@@ -7,4 +7,5 @@ include /etc/firejail/disable-passwdmgr.inc
7caps.drop all 7caps.drop all
8seccomp 8seccomp
9protocol unix,inet,inet6 9protocol unix,inet,inet6
10nonewprivs
10noroot 11noroot
diff --git a/etc/aweather.profile b/etc/aweather.profile
index d7f510a7e..dd508e736 100644
--- a/etc/aweather.profile
+++ b/etc/aweather.profile
@@ -12,6 +12,7 @@ include /etc/firejail/disable-programs.inc
12# Call these options 12# Call these options
13caps.drop all 13caps.drop all
14netfilter 14netfilter
15nonewprivs
15noroot 16noroot
16protocol unix,inet,inet6,netlink 17protocol unix,inet,inet6,netlink
17seccomp 18seccomp
diff --git a/etc/bitlbee.profile b/etc/bitlbee.profile
index fb84c260a..b7ccd132e 100644
--- a/etc/bitlbee.profile
+++ b/etc/bitlbee.profile
@@ -9,3 +9,4 @@ private
9private-dev 9private-dev
10seccomp 10seccomp
11netfilter 11netfilter
12nonewprivs
diff --git a/etc/cherrytree.profile b/etc/cherrytree.profile
index 1f69f61c6..b3a34fc9a 100644
--- a/etc/cherrytree.profile
+++ b/etc/cherrytree.profile
@@ -19,6 +19,7 @@ seccomp
19protocol unix,inet,inet6,netlink 19protocol unix,inet,inet6,netlink
20netfilter 20netfilter
21tracelog 21tracelog
22nonewprivs
22noroot 23noroot
23include /etc/firejail/whitelist-common.inc 24include /etc/firejail/whitelist-common.inc
24nosound 25nosound
diff --git a/etc/clementine.profile b/etc/clementine.profile
index c6271e6e3..fb9dca2a9 100644
--- a/etc/clementine.profile
+++ b/etc/clementine.profile
@@ -7,4 +7,5 @@ include /etc/firejail/disable-passwdmgr.inc
7caps.drop all 7caps.drop all
8seccomp 8seccomp
9protocol unix,inet,inet6 9protocol unix,inet,inet6
10nonewprivs
10noroot 11noroot
diff --git a/etc/cmus.profile b/etc/cmus.profile
index 72b43a70f..16b9c112d 100644
--- a/etc/cmus.profile
+++ b/etc/cmus.profile
@@ -10,6 +10,7 @@ caps.drop all
10seccomp 10seccomp
11protocol unix,inet,inet6 11protocol unix,inet,inet6
12netfilter 12netfilter
13nonewprivs
13noroot 14noroot
14 15
15private-bin cmus 16private-bin cmus
diff --git a/etc/conkeror.profile b/etc/conkeror.profile
index 007eef663..0a7966e4b 100644
--- a/etc/conkeror.profile
+++ b/etc/conkeror.profile
@@ -7,6 +7,7 @@ caps.drop all
7seccomp 7seccomp
8protocol unix,inet,inet6 8protocol unix,inet,inet6
9netfilter 9netfilter
10nonewprivs
10noroot 11noroot
11 12
12whitelist ~/.conkeror.mozdev.org 13whitelist ~/.conkeror.mozdev.org
diff --git a/etc/cyberfox.profile b/etc/cyberfox.profile
index cef9ad464..c5fb25e9a 100644
--- a/etc/cyberfox.profile
+++ b/etc/cyberfox.profile
@@ -11,6 +11,7 @@ seccomp
11protocol unix,inet,inet6,netlink 11protocol unix,inet,inet6,netlink
12netfilter 12netfilter
13tracelog 13tracelog
14nonewprivs
14noroot 15noroot
15 16
16whitelist ${DOWNLOADS} 17whitelist ${DOWNLOADS}
diff --git a/etc/deadbeef.profile b/etc/deadbeef.profile
index 2810e5323..9225ca16e 100644
--- a/etc/deadbeef.profile
+++ b/etc/deadbeef.profile
@@ -9,4 +9,5 @@ include /etc/firejail/disable-passwdmgr.inc
9caps.drop all 9caps.drop all
10seccomp 10seccomp
11protocol unix,inet,inet6 11protocol unix,inet,inet6
12nonewprivs
12noroot 13noroot
diff --git a/etc/default.profile b/etc/default.profile
index f2c7d4114..d836a9f5d 100644
--- a/etc/default.profile
+++ b/etc/default.profile
@@ -11,5 +11,6 @@ caps.drop all
11seccomp 11seccomp
12protocol unix,inet,inet6 12protocol unix,inet,inet6
13netfilter 13netfilter
14nonewprivs
14noroot 15noroot
15 16
diff --git a/etc/deluge.profile b/etc/deluge.profile
index 4043f58f5..f7a2b98e4 100644
--- a/etc/deluge.profile
+++ b/etc/deluge.profile
@@ -9,5 +9,6 @@ caps.drop all
9seccomp 9seccomp
10protocol unix,inet,inet6 10protocol unix,inet,inet6
11netfilter 11netfilter
12nonewprivs
12noroot 13noroot
13nosound 14nosound
diff --git a/etc/dillo.profile b/etc/dillo.profile
index 49c33fb7a..392000ade 100644
--- a/etc/dillo.profile
+++ b/etc/dillo.profile
@@ -11,6 +11,7 @@ seccomp
11protocol unix,inet,inet6 11protocol unix,inet,inet6
12netfilter 12netfilter
13tracelog 13tracelog
14nonewprivs
14noroot 15noroot
15 16
16whitelist ${DOWNLOADS} 17whitelist ${DOWNLOADS}
diff --git a/etc/dnsmasq.profile b/etc/dnsmasq.profile
index 474bc5aca..4459c40dd 100644
--- a/etc/dnsmasq.profile
+++ b/etc/dnsmasq.profile
@@ -11,3 +11,4 @@ protocol unix,inet,inet6,netlink
11netfilter 11netfilter
12private 12private
13private-dev 13private-dev
14nonewprivs
diff --git a/etc/dropbox.profile b/etc/dropbox.profile
index a0a944dce..568ab230a 100644
--- a/etc/dropbox.profile
+++ b/etc/dropbox.profile
@@ -6,4 +6,5 @@ include /etc/firejail/disable-passwdmgr.inc
6caps 6caps
7seccomp 7seccomp
8protocol unix,inet,inet6 8protocol unix,inet,inet6
9nonewprivs
9noroot 10noroot
diff --git a/etc/empathy.profile b/etc/empathy.profile
index 789bdda08..c08398e84 100644
--- a/etc/empathy.profile
+++ b/etc/empathy.profile
@@ -7,3 +7,4 @@ caps.drop all
7seccomp 7seccomp
8protocol unix,inet,inet6 8protocol unix,inet,inet6
9netfilter 9netfilter
10nonewprivs
diff --git a/etc/epiphany.profile b/etc/epiphany.profile
index 95a673bf9..7783a05fd 100644
--- a/etc/epiphany.profile
+++ b/etc/epiphany.profile
@@ -23,4 +23,4 @@ caps.drop all
23seccomp 23seccomp
24protocol unix,inet,inet6 24protocol unix,inet,inet6
25netfilter 25netfilter
26 26nonewprivs
diff --git a/etc/evince.profile b/etc/evince.profile
index c390dcaf3..3c883d43c 100644
--- a/etc/evince.profile
+++ b/etc/evince.profile
@@ -7,5 +7,6 @@ include /etc/firejail/disable-passwdmgr.inc
7caps.drop all 7caps.drop all
8seccomp 8seccomp
9protocol unix,inet,inet6 9protocol unix,inet,inet6
10nonewprivs
10noroot 11noroot
11nosound 12nosound
diff --git a/etc/fbreader.profile b/etc/fbreader.profile
index cfbae1c74..7764a48c9 100644
--- a/etc/fbreader.profile
+++ b/etc/fbreader.profile
@@ -10,5 +10,6 @@ caps.drop all
10seccomp 10seccomp
11protocol unix,inet,inet6 11protocol unix,inet,inet6
12netfilter 12netfilter
13nonewprivs
13noroot 14noroot
14nosound 15nosound
diff --git a/etc/filezilla.profile b/etc/filezilla.profile
index 8542de284..1ab08b568 100644
--- a/etc/filezilla.profile
+++ b/etc/filezilla.profile
@@ -9,6 +9,7 @@ include /etc/firejail/disable-devel.inc
9caps.drop all 9caps.drop all
10seccomp 10seccomp
11protocol unix,inet,inet6 11protocol unix,inet,inet6
12nonewprivs
12noroot 13noroot
13netfilter 14netfilter
14nosound 15nosound
diff --git a/etc/firefox.profile b/etc/firefox.profile
index 1ea94a2c7..6796ef7c4 100644
--- a/etc/firefox.profile
+++ b/etc/firefox.profile
@@ -11,6 +11,7 @@ seccomp
11protocol unix,inet,inet6,netlink 11protocol unix,inet,inet6,netlink
12netfilter 12netfilter
13tracelog 13tracelog
14nonewprivs
14noroot 15noroot
15 16
16whitelist ${DOWNLOADS} 17whitelist ${DOWNLOADS}
diff --git a/etc/flashpeak-slimjet.profile b/etc/flashpeak-slimjet.profile
index 94c672acf..77a95aa17 100644
--- a/etc/flashpeak-slimjet.profile
+++ b/etc/flashpeak-slimjet.profile
@@ -18,6 +18,7 @@ caps.drop all
18seccomp 18seccomp
19protocol unix,inet,inet6,netlink 19protocol unix,inet,inet6,netlink
20netfilter 20netfilter
21nonewprivs
21noroot 22noroot
22 23
23whitelist ${DOWNLOADS} 24whitelist ${DOWNLOADS}
diff --git a/etc/gnome-mplayer.profile b/etc/gnome-mplayer.profile
index ec3698ac8..010b19613 100644
--- a/etc/gnome-mplayer.profile
+++ b/etc/gnome-mplayer.profile
@@ -7,4 +7,5 @@ include /etc/firejail/disable-passwdmgr.inc
7caps.drop all 7caps.drop all
8seccomp 8seccomp
9protocol unix,inet,inet6 9protocol unix,inet,inet6
10nonewprivs
10noroot 11noroot
diff --git a/etc/google-play-music-desktop-player.profile b/etc/google-play-music-desktop-player.profile
index 7fe43f1f6..fe2f79901 100644
--- a/etc/google-play-music-desktop-player.profile
+++ b/etc/google-play-music-desktop-player.profile
@@ -9,6 +9,7 @@ include /etc/firejail/disable-passwdmgr.inc
9caps.drop all 9caps.drop all
10seccomp 10seccomp
11protocol unix,inet,inet6,netlink 11protocol unix,inet,inet6,netlink
12nonewprivs
12noroot 13noroot
13netfilter 14netfilter
14 15
diff --git a/etc/gpredict.profile b/etc/gpredict.profile
index f53cb1b4f..ba9fce37b 100644
--- a/etc/gpredict.profile
+++ b/etc/gpredict.profile
@@ -12,6 +12,7 @@ include /etc/firejail/disable-programs.inc
12# Call these options 12# Call these options
13caps.drop all 13caps.drop all
14netfilter 14netfilter
15nonewprivs
15noroot 16noroot
16protocol unix,inet,inet6,netlink 17protocol unix,inet,inet6,netlink
17seccomp 18seccomp
diff --git a/etc/gwenview.profile b/etc/gwenview.profile
index d61c57adc..87523d825 100644
--- a/etc/gwenview.profile
+++ b/etc/gwenview.profile
@@ -8,6 +8,7 @@ include /etc/firejail/disable-passwdmgr.inc
8caps.drop all 8caps.drop all
9seccomp 9seccomp
10protocol unix 10protocol unix
11nonewprivs
11noroot 12noroot
12nogroups 13nogroups
13private-dev 14private-dev
diff --git a/etc/hedgewars.profile b/etc/hedgewars.profile
index 5ab7cfe72..c5d863bd5 100644
--- a/etc/hedgewars.profile
+++ b/etc/hedgewars.profile
@@ -7,6 +7,7 @@ include /etc/firejail/disable-devel.inc
7include /etc/firejail/disable-passwdmgr.inc 7include /etc/firejail/disable-passwdmgr.inc
8 8
9caps.drop all 9caps.drop all
10nonewprivs
10noroot 11noroot
11private-dev 12private-dev
12seccomp 13seccomp
diff --git a/etc/hexchat.profile b/etc/hexchat.profile
index b77555e55..3eb350660 100644
--- a/etc/hexchat.profile
+++ b/etc/hexchat.profile
@@ -9,6 +9,7 @@ include /etc/firejail/disable-devel.inc
9caps.drop all 9caps.drop all
10seccomp 10seccomp
11protocol unix,inet,inet6 11protocol unix,inet,inet6
12nonewprivs
12noroot 13noroot
13netfilter 14netfilter
14 15
diff --git a/etc/kmail.profile b/etc/kmail.profile
index a7079661b..a47945bc6 100644
--- a/etc/kmail.profile
+++ b/etc/kmail.profile
@@ -10,5 +10,6 @@ caps.drop all
10seccomp 10seccomp
11protocol unix,inet,inet6,netlink 11protocol unix,inet,inet6,netlink
12netfilter 12netfilter
13nonewprivs
13noroot 14noroot
14tracelog 15tracelog
diff --git a/etc/mcabber.profile b/etc/mcabber.profile
index 1d753d7c3..1536194b2 100644
--- a/etc/mcabber.profile
+++ b/etc/mcabber.profile
@@ -11,6 +11,7 @@ caps.drop all
11seccomp 11seccomp
12protocol inet,inet6 12protocol inet,inet6
13netfilter 13netfilter
14nonewprivs
14noroot 15noroot
15 16
16private-bin mcabber 17private-bin mcabber
diff --git a/etc/mupen64plus.profile b/etc/mupen64plus.profile
index 7b38b411a..c9a99bede 100644
--- a/etc/mupen64plus.profile
+++ b/etc/mupen64plus.profile
@@ -16,6 +16,7 @@ mkdir ${HOME}/.config
16mkdir ${HOME}/.config/mupen64plus 16mkdir ${HOME}/.config/mupen64plus
17whitelist ${HOME}/.config/mupen64plus/ 17whitelist ${HOME}/.config/mupen64plus/
18 18
19nonewprivs
19noroot 20noroot
20caps.drop all 21caps.drop all
21seccomp 22seccomp
diff --git a/etc/netsurf.profile b/etc/netsurf.profile
index 26b621126..e01cace7f 100644
--- a/etc/netsurf.profile
+++ b/etc/netsurf.profile
@@ -11,6 +11,7 @@ seccomp
11protocol unix,inet,inet6,netlink 11protocol unix,inet,inet6,netlink
12netfilter 12netfilter
13tracelog 13tracelog
14nonewprivs
14noroot 15noroot
15 16
16whitelist ${DOWNLOADS} 17whitelist ${DOWNLOADS}
diff --git a/etc/okular.profile b/etc/okular.profile
index 7929a8796..5179da787 100644
--- a/etc/okular.profile
+++ b/etc/okular.profile
@@ -9,6 +9,7 @@ include /etc/firejail/disable-passwdmgr.inc
9caps.drop all 9caps.drop all
10seccomp 10seccomp
11protocol unix 11protocol unix
12nonewprivs
12noroot 13noroot
13nogroups 14nogroups
14private-dev 15private-dev
diff --git a/etc/palemoon.profile b/etc/palemoon.profile
index fc4ea453b..4db9b7adc 100644
--- a/etc/palemoon.profile
+++ b/etc/palemoon.profile
@@ -16,6 +16,7 @@ seccomp
16protocol unix,inet,inet6,netlink 16protocol unix,inet,inet6,netlink
17netfilter 17netfilter
18tracelog 18tracelog
19nonewprivs
19noroot 20noroot
20 21
21whitelist ${DOWNLOADS} 22whitelist ${DOWNLOADS}
diff --git a/etc/parole.profile b/etc/parole.profile
index 0c9a72143..c0be0453b 100644
--- a/etc/parole.profile
+++ b/etc/parole.profile
@@ -11,5 +11,6 @@ caps.drop all
11seccomp 11seccomp
12protocol unix,inet,inet6 12protocol unix,inet,inet6
13netfilter 13netfilter
14nonewprivs
14noroot 15noroot
15shell none 16shell none
diff --git a/etc/pidgin.profile b/etc/pidgin.profile
index fd497f082..767da5f55 100644
--- a/etc/pidgin.profile
+++ b/etc/pidgin.profile
@@ -8,4 +8,5 @@ include /etc/firejail/disable-devel.inc
8caps.drop all 8caps.drop all
9seccomp 9seccomp
10protocol unix,inet,inet6 10protocol unix,inet,inet6
11nonewprivs
11noroot 12noroot
diff --git a/etc/polari.profile b/etc/polari.profile
index 0bc46f3f7..7910f4e9b 100644
--- a/etc/polari.profile
+++ b/etc/polari.profile
@@ -24,6 +24,7 @@ include /etc/firejail/whitelist-common.inc
24caps.drop all 24caps.drop all
25seccomp 25seccomp
26protocol unix,inet,inet6 26protocol unix,inet,inet6
27nonewprivs
27noroot 28noroot
28netfilter 29netfilter
29 30
diff --git a/etc/qbittorrent.profile b/etc/qbittorrent.profile
index 8bdc745fb..858fdda4d 100644
--- a/etc/qbittorrent.profile
+++ b/etc/qbittorrent.profile
@@ -8,5 +8,6 @@ caps.drop all
8seccomp 8seccomp
9protocol unix,inet,inet6 9protocol unix,inet,inet6
10netfilter 10netfilter
11nonewprivs
11noroot 12noroot
12nosound 13nosound
diff --git a/etc/qtox.profile b/etc/qtox.profile
index 80acc3873..ca34e932a 100644
--- a/etc/qtox.profile
+++ b/etc/qtox.profile
@@ -12,4 +12,5 @@ include /etc/firejail/whitelist-common.inc
12caps.drop all 12caps.drop all
13seccomp 13seccomp
14protocol unix,inet,inet6 14protocol unix,inet,inet6
15nonewprivs
15noroot 16noroot
diff --git a/etc/quassel.profile b/etc/quassel.profile
index 72004da7f..e68315c1c 100644
--- a/etc/quassel.profile
+++ b/etc/quassel.profile
@@ -6,5 +6,6 @@ include /etc/firejail/disable-devel.inc
6caps.drop all 6caps.drop all
7seccomp 7seccomp
8protocol unix,inet,inet6 8protocol unix,inet,inet6
9nonewprivs
9noroot 10noroot
10netfilter 11netfilter
diff --git a/etc/quiterss.profile b/etc/quiterss.profile
index 411d37dbd..5ad7ead1a 100644
--- a/etc/quiterss.profile
+++ b/etc/quiterss.profile
@@ -20,6 +20,7 @@ seccomp
20protocol unix,inet,inet6 20protocol unix,inet,inet6
21netfilter 21netfilter
22tracelog 22tracelog
23nonewprivs
23noroot 24noroot
24nogroups 25nogroups
25shell none 26shell none
diff --git a/etc/qutebrowser.profile b/etc/qutebrowser.profile
index 934a374de..09d10b0bb 100644
--- a/etc/qutebrowser.profile
+++ b/etc/qutebrowser.profile
@@ -11,6 +11,7 @@ seccomp
11protocol unix,inet,inet6,netlink 11protocol unix,inet,inet6,netlink
12netfilter 12netfilter
13tracelog 13tracelog
14nonewprivs
14noroot 15noroot
15 16
16whitelist ${DOWNLOADS} 17whitelist ${DOWNLOADS}
diff --git a/etc/rhythmbox.profile b/etc/rhythmbox.profile
index 782cd3832..ee0832863 100644
--- a/etc/rhythmbox.profile
+++ b/etc/rhythmbox.profile
@@ -7,5 +7,6 @@ include /etc/firejail/disable-passwdmgr.inc
7caps.drop all 7caps.drop all
8seccomp 8seccomp
9protocol unix,inet,inet6 9protocol unix,inet,inet6
10nonewprivs
10noroot 11noroot
11netfilter 12netfilter
diff --git a/etc/rtorrent.profile b/etc/rtorrent.profile
index ae0430830..9ae2206c1 100644
--- a/etc/rtorrent.profile
+++ b/etc/rtorrent.profile
@@ -8,5 +8,6 @@ caps.drop all
8seccomp 8seccomp
9protocol unix,inet,inet6 9protocol unix,inet,inet6
10netfilter 10netfilter
11nonewprivs
11noroot 12noroot
12nosound 13nosound
diff --git a/etc/seamonkey.profile b/etc/seamonkey.profile
index a10d5b0ec..886af0f67 100644
--- a/etc/seamonkey.profile
+++ b/etc/seamonkey.profile
@@ -10,6 +10,7 @@ seccomp
10protocol unix,inet,inet6,netlink 10protocol unix,inet,inet6,netlink
11netfilter 11netfilter
12tracelog 12tracelog
13nonewprivs
13noroot 14noroot
14 15
15whitelist ${DOWNLOADS} 16whitelist ${DOWNLOADS}
diff --git a/etc/skype.profile b/etc/skype.profile
index 26feac1a4..4c4a34980 100644
--- a/etc/skype.profile
+++ b/etc/skype.profile
@@ -6,6 +6,7 @@ include /etc/firejail/disable-devel.inc
6 6
7caps.drop all 7caps.drop all
8netfilter 8netfilter
9nonewprivs
9noroot 10noroot
10seccomp 11seccomp
11protocol unix,inet,inet6 12protocol unix,inet,inet6
diff --git a/etc/spotify.profile b/etc/spotify.profile
index fd4586dd5..1ee379dea 100644
--- a/etc/spotify.profile
+++ b/etc/spotify.profile
@@ -26,5 +26,6 @@ caps.drop all
26seccomp 26seccomp
27protocol unix,inet,inet6,netlink 27protocol unix,inet,inet6,netlink
28netfilter 28netfilter
29nonewprivs
29noroot 30noroot
30 31
diff --git a/etc/ssh.profile b/etc/ssh.profile
index 7b282bde6..0c4621f66 100644
--- a/etc/ssh.profile
+++ b/etc/ssh.profile
@@ -9,4 +9,5 @@ caps.drop all
9seccomp 9seccomp
10protocol unix,inet,inet6 10protocol unix,inet,inet6
11netfilter 11netfilter
12nonewprivs
12noroot 13noroot
diff --git a/etc/steam.profile b/etc/steam.profile
index 4c96e8258..ae5e93829 100644
--- a/etc/steam.profile
+++ b/etc/steam.profile
@@ -8,6 +8,7 @@ include /etc/firejail/disable-passwdmgr.inc
8 8
9caps.drop all 9caps.drop all
10netfilter 10netfilter
11nonewprivs
11noroot 12noroot
12seccomp 13seccomp
13protocol unix,inet,inet6 14protocol unix,inet,inet6
diff --git a/etc/stellarium.profile b/etc/stellarium.profile
index 7cb74eeaa..148ec949d 100644
--- a/etc/stellarium.profile
+++ b/etc/stellarium.profile
@@ -13,6 +13,7 @@ include /etc/firejail/disable-programs.inc
13# Call these options 13# Call these options
14caps.drop all 14caps.drop all
15netfilter 15netfilter
16nonewprivs
16noroot 17noroot
17protocol unix,inet,inet6,netlink 18protocol unix,inet,inet6,netlink
18seccomp 19seccomp
diff --git a/etc/telegram.profile b/etc/telegram.profile
index df6b6a270..62a0fa404 100644
--- a/etc/telegram.profile
+++ b/etc/telegram.profile
@@ -7,6 +7,7 @@ include /etc/firejail/disable-devel.inc
7caps.drop all 7caps.drop all
8seccomp 8seccomp
9protocol unix,inet,inet6 9protocol unix,inet,inet6
10nonewprivs
10noroot 11noroot
11netfilter 12netfilter
12 13
diff --git a/etc/totem.profile b/etc/totem.profile
index d23167b03..f2bce5dee 100644
--- a/etc/totem.profile
+++ b/etc/totem.profile
@@ -10,5 +10,6 @@ include /etc/firejail/disable-passwdmgr.inc
10caps.drop all 10caps.drop all
11seccomp 11seccomp
12protocol unix,inet,inet6 12protocol unix,inet,inet6
13nonewprivs
13noroot 14noroot
14netfilter 15netfilter
diff --git a/etc/transmission-gtk.profile b/etc/transmission-gtk.profile
index d61d36a8c..e27873f88 100644
--- a/etc/transmission-gtk.profile
+++ b/etc/transmission-gtk.profile
@@ -11,6 +11,7 @@ caps.drop all
11seccomp 11seccomp
12protocol unix,inet,inet6 12protocol unix,inet,inet6
13netfilter 13netfilter
14nonewprivs
14noroot 15noroot
15tracelog 16tracelog
16nosound 17nosound
diff --git a/etc/transmission-qt.profile b/etc/transmission-qt.profile
index 3db7a5452..2caa923d8 100644
--- a/etc/transmission-qt.profile
+++ b/etc/transmission-qt.profile
@@ -11,6 +11,7 @@ caps.drop all
11seccomp 11seccomp
12protocol unix,inet,inet6 12protocol unix,inet,inet6
13netfilter 13netfilter
14nonewprivs
14noroot 15noroot
15tracelog 16tracelog
16nosound 17nosound
diff --git a/etc/uget-gtk.profile b/etc/uget-gtk.profile
index ef5aa7d4a..86e7be6fd 100644
--- a/etc/uget-gtk.profile
+++ b/etc/uget-gtk.profile
@@ -9,6 +9,7 @@ caps.drop all
9seccomp 9seccomp
10protocol unix,inet,inet6 10protocol unix,inet,inet6
11netfilter 11netfilter
12nonewprivs
12noroot 13noroot
13 14
14whitelist ${DOWNLOADS} 15whitelist ${DOWNLOADS}
diff --git a/etc/vivaldi.profile b/etc/vivaldi.profile
index 449d9a168..2049d2bd9 100644
--- a/etc/vivaldi.profile
+++ b/etc/vivaldi.profile
@@ -6,6 +6,7 @@ include /etc/firejail/disable-programs.inc
6include /etc/firejail/disable-devel.inc 6include /etc/firejail/disable-devel.inc
7 7
8netfilter 8netfilter
9nonewprivs
9 10
10whitelist ${DOWNLOADS} 11whitelist ${DOWNLOADS}
11mkdir ~/.config 12mkdir ~/.config
diff --git a/etc/vlc.profile b/etc/vlc.profile
index 061ae6f78..d26034748 100644
--- a/etc/vlc.profile
+++ b/etc/vlc.profile
@@ -9,5 +9,6 @@ include /etc/firejail/disable-passwdmgr.inc
9caps.drop all 9caps.drop all
10seccomp 10seccomp
11protocol unix,inet,inet6 11protocol unix,inet,inet6
12nonewprivs
12noroot 13noroot
13netfilter 14netfilter
diff --git a/etc/warzone2100.profile b/etc/warzone2100.profile
index 7588da657..ceeaca012 100644
--- a/etc/warzone2100.profile
+++ b/etc/warzone2100.profile
@@ -9,6 +9,7 @@ include /etc/firejail/disable-programs.inc
9# Call these options 9# Call these options
10caps.drop all 10caps.drop all
11netfilter 11netfilter
12nonewprivs
12noroot 13noroot
13protocol unix,inet,inet6,netlink 14protocol unix,inet,inet6,netlink
14seccomp 15seccomp
diff --git a/etc/weechat.profile b/etc/weechat.profile
index 280a5f9d8..11b5bd10f 100644
--- a/etc/weechat.profile
+++ b/etc/weechat.profile
@@ -7,5 +7,6 @@ caps.drop all
7seccomp 7seccomp
8protocol unix,inet,inet6 8protocol unix,inet,inet6
9netfilter 9netfilter
10nonewprivs
10noroot 11noroot
11netfilter 12netfilter
diff --git a/etc/wesnoth.profile b/etc/wesnoth.profile
index 340ba0db5..61a87d994 100644
--- a/etc/wesnoth.profile
+++ b/etc/wesnoth.profile
@@ -11,6 +11,7 @@ include /etc/firejail/disable-passwdmgr.inc
11caps.drop all 11caps.drop all
12seccomp 12seccomp
13protocol unix,inet,inet6 13protocol unix,inet,inet6
14nonewprivs
14noroot 15noroot
15 16
16private-dev 17private-dev
diff --git a/etc/wine.profile b/etc/wine.profile
index ea6db8511..18e5346af 100644
--- a/etc/wine.profile
+++ b/etc/wine.profile
@@ -9,5 +9,6 @@ include /etc/firejail/disable-devel.inc
9 9
10caps.drop all 10caps.drop all
11netfilter 11netfilter
12nonewprivs
12noroot 13noroot
13seccomp 14seccomp
diff --git a/etc/xchat.profile b/etc/xchat.profile
index fcea4245e..f4b273693 100644
--- a/etc/xchat.profile
+++ b/etc/xchat.profile
@@ -8,4 +8,5 @@ include /etc/firejail/disable-devel.inc
8caps.drop all 8caps.drop all
9seccomp 9seccomp
10protocol unix,inet,inet6 10protocol unix,inet,inet6
11nonewprivs
11noroot 12noroot
diff --git a/etc/xplayer.profile b/etc/xplayer.profile
index 67a46a7da..fb0e3c910 100644
--- a/etc/xplayer.profile
+++ b/etc/xplayer.profile
@@ -10,6 +10,7 @@ include /etc/firejail/disable-passwdmgr.inc
10caps.drop all 10caps.drop all
11seccomp 11seccomp
12protocol unix,inet,inet6 12protocol unix,inet,inet6
13nonewprivs
13noroot 14noroot
14tracelog 15tracelog
15netfilter 16netfilter
diff --git a/etc/xreader.profile b/etc/xreader.profile
index 7b72d41a6..4b7ed41be 100644
--- a/etc/xreader.profile
+++ b/etc/xreader.profile
@@ -11,6 +11,7 @@ include /etc/firejail/disable-passwdmgr.inc
11caps.drop all 11caps.drop all
12seccomp 12seccomp
13protocol unix,inet,inet6 13protocol unix,inet,inet6
14nonewprivs
14noroot 15noroot
15tracelog 16tracelog
16netfilter 17netfilter
diff --git a/etc/xviewer.profile b/etc/xviewer.profile
index 33e1e3c68..a0c91f0f3 100644
--- a/etc/xviewer.profile
+++ b/etc/xviewer.profile
@@ -9,5 +9,6 @@ caps.drop all
9seccomp 9seccomp
10protocol unix,inet,inet6 10protocol unix,inet,inet6
11noroot 11noroot
12nonewprivs
12tracelog 13tracelog
13netfilter 14netfilter