aboutsummaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
authorLibravatar rusty-snake <print_hello_world+Public@protonmail.com>2019-06-15 23:11:00 +0200
committerLibravatar rusty-snake <print_hello_world+Public@protonmail.com>2019-06-15 23:11:00 +0200
commita75c99245e323525c1cdc79981541f68f9420779 (patch)
treed7e3ee74e9cf500798fea539303c51b46b18c4f2 /etc
parentMore sorting private-etc (#2779) (diff)
downloadfirejail-a75c99245e323525c1cdc79981541f68f9420779.tar.gz
firejail-a75c99245e323525c1cdc79981541f68f9420779.tar.zst
firejail-a75c99245e323525c1cdc79981541f68f9420779.zip
some profile fixes
Diffstat (limited to 'etc')
-rw-r--r--etc/aria2c.profile2
-rw-r--r--etc/minetest.profile3
-rw-r--r--etc/tcpdump.profile4
-rw-r--r--etc/tshark.profile5
4 files changed, 7 insertions, 7 deletions
diff --git a/etc/aria2c.profile b/etc/aria2c.profile
index b952ac8a6..3b9dfc365 100644
--- a/etc/aria2c.profile
+++ b/etc/aria2c.profile
@@ -38,7 +38,7 @@ private-bin aria2c,gzip
38# Uncomment the next line (or put 'private-cache' in your aria2c.local) if you don't use Lutris/winetricks (see issue #2772) 38# Uncomment the next line (or put 'private-cache' in your aria2c.local) if you don't use Lutris/winetricks (see issue #2772)
39#private-cache 39#private-cache
40private-dev 40private-dev
41private-etc alternatives,ca-certificates,resolv.conf,ssl 41private-etc alternatives,ca-certificates,crypto-policies,nsswitch.conf,pki,resolv.conf,ssl
42private-lib libreadline.so.* 42private-lib libreadline.so.*
43private-tmp 43private-tmp
44 44
diff --git a/etc/minetest.profile b/etc/minetest.profile
index b3e692446..f656d5a87 100644
--- a/etc/minetest.profile
+++ b/etc/minetest.profile
@@ -6,6 +6,7 @@ include minetest.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.cache/minetest
9noblacklist ${HOME}/.minetest 10noblacklist ${HOME}/.minetest
10 11
11include disable-common.inc 12include disable-common.inc
@@ -16,7 +17,9 @@ include disable-passwdmgr.inc
16include disable-programs.inc 17include disable-programs.inc
17include disable-xdg.inc 18include disable-xdg.inc
18 19
20mkdir ${HOME}/.cache/minetest
19mkdir ${HOME}/.minetest 21mkdir ${HOME}/.minetest
22whitelist ${HOME}/.cache/minetest
20whitelist ${HOME}/.minetest 23whitelist ${HOME}/.minetest
21include whitelist-common.inc 24include whitelist-common.inc
22include whitelist-var-common.inc 25include whitelist-var-common.inc
diff --git a/etc/tcpdump.profile b/etc/tcpdump.profile
index 7713ac6c0..3c46dfdcb 100644
--- a/etc/tcpdump.profile
+++ b/etc/tcpdump.profile
@@ -8,6 +8,7 @@ include globals.local
8 8
9noblacklist /sbin 9noblacklist /sbin
10noblacklist /usr/sbin 10noblacklist /usr/sbin
11
11include disable-common.inc 12include disable-common.inc
12include disable-devel.inc 13include disable-devel.inc
13include disable-exec.inc 14include disable-exec.inc
@@ -15,6 +16,7 @@ include disable-interpreters.inc
15include disable-passwdmgr.inc 16include disable-passwdmgr.inc
16include disable-programs.inc 17include disable-programs.inc
17include disable-xdg.inc 18include disable-xdg.inc
19
18include whitelist-common.inc 20include whitelist-common.inc
19 21
20caps.keep net_raw 22caps.keep net_raw
@@ -30,7 +32,6 @@ nosound
30notv 32notv
31nou2f 33nou2f
32novideo 34novideo
33
34protocol unix,inet,inet6,netlink,packet 35protocol unix,inet,inet6,netlink,packet
35seccomp 36seccomp
36 37
@@ -38,7 +39,6 @@ disable-mnt
38#private 39#private
39#private-bin tcpdump 40#private-bin tcpdump
40private-dev 41private-dev
41#private-etc
42private-tmp 42private-tmp
43 43
44memory-deny-write-execute 44memory-deny-write-execute
diff --git a/etc/tshark.profile b/etc/tshark.profile
index 52ee228a3..ea85f4e8a 100644
--- a/etc/tshark.profile
+++ b/etc/tshark.profile
@@ -13,6 +13,7 @@ include disable-interpreters.inc
13include disable-passwdmgr.inc 13include disable-passwdmgr.inc
14include disable-programs.inc 14include disable-programs.inc
15include disable-xdg.inc 15include disable-xdg.inc
16
16include whitelist-common.inc 17include whitelist-common.inc
17 18
18#caps.keep net_raw 19#caps.keep net_raw
@@ -29,7 +30,6 @@ nosound
29notv 30notv
30nou2f 31nou2f
31novideo 32novideo
32
33#protocol unix,inet,inet6,netlink,packet 33#protocol unix,inet,inet6,netlink,packet
34#seccomp 34#seccomp
35 35
@@ -38,7 +38,4 @@ disable-mnt
38private-cache 38private-cache
39#private-bin tshark 39#private-bin tshark
40private-dev 40private-dev
41#private-etc
42private-tmp 41private-tmp
43
44# memory-deny-write-execute