aboutsummaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
authorLibravatar netblue30 <netblue30@yahoo.com>2017-10-18 09:15:19 -0400
committerLibravatar netblue30 <netblue30@yahoo.com>2017-10-18 09:15:19 -0400
commitb4c84b85a03da21179803077616fc77aeb9c8e22 (patch)
treecd3282447decd09a065c36c8acb49e932a25aaef /etc
parentremove links for uninstalled programs (diff)
downloadfirejail-b4c84b85a03da21179803077616fc77aeb9c8e22.tar.gz
firejail-b4c84b85a03da21179803077616fc77aeb9c8e22.tar.zst
firejail-b4c84b85a03da21179803077616fc77aeb9c8e22.zip
profile updates
Diffstat (limited to 'etc')
-rw-r--r--etc/aweather.profile1
-rw-r--r--etc/bluefish.profile2
-rw-r--r--etc/clementine.profile5
-rw-r--r--etc/deluge.profile1
-rw-r--r--etc/dillo.profile4
-rw-r--r--etc/etr.profile1
-rw-r--r--etc/fbreader.profile2
-rw-r--r--etc/filezilla.profile1
-rw-r--r--etc/frozen-bubble.profile1
-rw-r--r--etc/lxmusic.profile2
-rw-r--r--etc/mplayer.profile2
-rw-r--r--etc/mupdf.profile2
-rw-r--r--etc/openshot.profile2
-rw-r--r--etc/qpdfview.profile2
-rw-r--r--etc/smplayer.profile2
-rw-r--r--etc/smtube.profile2
-rw-r--r--etc/supertux2.profile1
-rw-r--r--etc/vim.profile2
-rw-r--r--etc/warzone2100.profile1
-rw-r--r--etc/wget.profile2
-rw-r--r--etc/wireshark.profile2
-rw-r--r--etc/xpdf.profile2
22 files changed, 42 insertions, 0 deletions
diff --git a/etc/aweather.profile b/etc/aweather.profile
index ef811b330..62cebdbe5 100644
--- a/etc/aweather.profile
+++ b/etc/aweather.profile
@@ -15,6 +15,7 @@ include /etc/firejail/disable-programs.inc
15mkdir ~/.config/aweather 15mkdir ~/.config/aweather
16whitelist ~/.config/aweather 16whitelist ~/.config/aweather
17include /etc/firejail/whitelist-common.inc 17include /etc/firejail/whitelist-common.inc
18include /etc/firejail/whitelist-var-common.inc
18 19
19caps.drop all 20caps.drop all
20netfilter 21netfilter
diff --git a/etc/bluefish.profile b/etc/bluefish.profile
index f7e322838..052d03425 100644
--- a/etc/bluefish.profile
+++ b/etc/bluefish.profile
@@ -11,6 +11,8 @@ include /etc/firejail/disable-devel.inc
11include /etc/firejail/disable-passwdmgr.inc 11include /etc/firejail/disable-passwdmgr.inc
12include /etc/firejail/disable-programs.inc 12include /etc/firejail/disable-programs.inc
13 13
14include /etc/firejail/whitelist-var-common.inc
15
14caps.drop all 16caps.drop all
15net none 17net none
16no3d 18no3d
diff --git a/etc/clementine.profile b/etc/clementine.profile
index 1d93e5f2c..619086437 100644
--- a/etc/clementine.profile
+++ b/etc/clementine.profile
@@ -12,6 +12,8 @@ include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-passwdmgr.inc 12include /etc/firejail/disable-passwdmgr.inc
13include /etc/firejail/disable-programs.inc 13include /etc/firejail/disable-programs.inc
14 14
15include /etc/firejail/whitelist-var-common.inc
16
15caps.drop all 17caps.drop all
16nonewprivs 18nonewprivs
17noroot 19noroot
@@ -20,3 +22,6 @@ novideo
20protocol unix,inet,inet6 22protocol unix,inet,inet6
21# Clementine makes ioprio_set system calls, which are blacklisted by default. 23# Clementine makes ioprio_set system calls, which are blacklisted by default.
22seccomp.drop @cpu-emulation,@debug,@obsolete,@privileged,@resources,add_key,fanotify_init,io_cancel,io_destroy,io_getevents,io_setup,io_submit,kcmp,keyctl,name_to_handle_at,ni_syscall,open_by_handle_at,personality,process_vm_readv,ptrace,remap_file_pages,request_key,syslog,umount,userfaultfd,vmsplice 24seccomp.drop @cpu-emulation,@debug,@obsolete,@privileged,@resources,add_key,fanotify_init,io_cancel,io_destroy,io_getevents,io_setup,io_submit,kcmp,keyctl,name_to_handle_at,ni_syscall,open_by_handle_at,personality,process_vm_readv,ptrace,remap_file_pages,request_key,syslog,umount,userfaultfd,vmsplice
25
26private-dev
27private-tmp
diff --git a/etc/deluge.profile b/etc/deluge.profile
index e18e39b1a..5ec849331 100644
--- a/etc/deluge.profile
+++ b/etc/deluge.profile
@@ -16,6 +16,7 @@ mkdir ${HOME}/.config/deluge
16whitelist ${DOWNLOADS} 16whitelist ${DOWNLOADS}
17whitelist ${HOME}/.config/deluge 17whitelist ${HOME}/.config/deluge
18include /etc/firejail/whitelist-common.inc 18include /etc/firejail/whitelist-common.inc
19include /etc/firejail/whitelist-var-common.inc
19 20
20caps.drop all 21caps.drop all
21netfilter 22netfilter
diff --git a/etc/dillo.profile b/etc/dillo.profile
index aa8a395e1..840a568d8 100644
--- a/etc/dillo.profile
+++ b/etc/dillo.profile
@@ -18,6 +18,7 @@ whitelist ${DOWNLOADS}
18whitelist ~/.dillo 18whitelist ~/.dillo
19whitelist ~/.fltk 19whitelist ~/.fltk
20include /etc/firejail/whitelist-common.inc 20include /etc/firejail/whitelist-common.inc
21include /etc/firejail/whitelist-var-common.inc
21 22
22caps.drop all 23caps.drop all
23netfilter 24netfilter
@@ -28,3 +29,6 @@ notv
28protocol unix,inet,inet6 29protocol unix,inet,inet6
29seccomp 30seccomp
30tracelog 31tracelog
32
33private-dev
34private-tmp
diff --git a/etc/etr.profile b/etc/etr.profile
index 96e8b46d9..2438793a8 100644
--- a/etc/etr.profile
+++ b/etc/etr.profile
@@ -14,6 +14,7 @@ include /etc/firejail/disable-programs.inc
14mkdir ~/.etr 14mkdir ~/.etr
15whitelist ~/.etr 15whitelist ~/.etr
16include /etc/firejail/whitelist-common.inc 16include /etc/firejail/whitelist-common.inc
17include /etc/firejail/whitelist-var-common.inc
17 18
18caps.drop all 19caps.drop all
19net none 20net none
diff --git a/etc/fbreader.profile b/etc/fbreader.profile
index 01da2cafe..8e2e5b169 100644
--- a/etc/fbreader.profile
+++ b/etc/fbreader.profile
@@ -12,6 +12,8 @@ include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-passwdmgr.inc 12include /etc/firejail/disable-passwdmgr.inc
13include /etc/firejail/disable-programs.inc 13include /etc/firejail/disable-programs.inc
14 14
15include /etc/firejail/whitelist-var-common.inc
16
15caps.drop all 17caps.drop all
16netfilter 18netfilter
17nodvd 19nodvd
diff --git a/etc/filezilla.profile b/etc/filezilla.profile
index 544c724bc..0f6cb22f3 100644
--- a/etc/filezilla.profile
+++ b/etc/filezilla.profile
@@ -11,6 +11,7 @@ noblacklist ${HOME}/.filezilla
11include /etc/firejail/disable-common.inc 11include /etc/firejail/disable-common.inc
12include /etc/firejail/disable-devel.inc 12include /etc/firejail/disable-devel.inc
13include /etc/firejail/disable-programs.inc 13include /etc/firejail/disable-programs.inc
14include /etc/firejail/whitelist-var-common.inc
14 15
15caps.drop all 16caps.drop all
16netfilter 17netfilter
diff --git a/etc/frozen-bubble.profile b/etc/frozen-bubble.profile
index 40aa6d58d..858917c75 100644
--- a/etc/frozen-bubble.profile
+++ b/etc/frozen-bubble.profile
@@ -14,6 +14,7 @@ include /etc/firejail/disable-programs.inc
14mkdir ~/.frozen-bubble 14mkdir ~/.frozen-bubble
15whitelist ~/.frozen-bubble 15whitelist ~/.frozen-bubble
16include /etc/firejail/whitelist-common.inc 16include /etc/firejail/whitelist-common.inc
17include /etc/firejail/whitelist-var-common.inc
17 18
18caps.drop all 19caps.drop all
19net none 20net none
diff --git a/etc/lxmusic.profile b/etc/lxmusic.profile
index 901bdb408..0161ffb63 100644
--- a/etc/lxmusic.profile
+++ b/etc/lxmusic.profile
@@ -13,6 +13,8 @@ include /etc/firejail/disable-devel.inc
13include /etc/firejail/disable-passwdmgr.inc 13include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc 14include /etc/firejail/disable-programs.inc
15 15
16include /etc/firejail/whitelist-var-common.inc
17
16caps.drop all 18caps.drop all
17netfilter 19netfilter
18no3d 20no3d
diff --git a/etc/mplayer.profile b/etc/mplayer.profile
index b431e4695..58b94c171 100644
--- a/etc/mplayer.profile
+++ b/etc/mplayer.profile
@@ -12,6 +12,8 @@ include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-passwdmgr.inc 12include /etc/firejail/disable-passwdmgr.inc
13include /etc/firejail/disable-programs.inc 13include /etc/firejail/disable-programs.inc
14 14
15include /etc/firejail/whitelist-var-common.inc
16
15caps.drop all 17caps.drop all
16netfilter 18netfilter
17# nogroups 19# nogroups
diff --git a/etc/mupdf.profile b/etc/mupdf.profile
index 62527c17d..a25cc352f 100644
--- a/etc/mupdf.profile
+++ b/etc/mupdf.profile
@@ -11,6 +11,8 @@ include /etc/firejail/disable-devel.inc
11include /etc/firejail/disable-passwdmgr.inc 11include /etc/firejail/disable-passwdmgr.inc
12include /etc/firejail/disable-programs.inc 12include /etc/firejail/disable-programs.inc
13 13
14include /etc/firejail/whitelist-var-common.inc
15
14caps.drop all 16caps.drop all
15net none 17net none
16nodvd 18nodvd
diff --git a/etc/openshot.profile b/etc/openshot.profile
index 02f4665d6..1463303b0 100644
--- a/etc/openshot.profile
+++ b/etc/openshot.profile
@@ -13,6 +13,8 @@ include /etc/firejail/disable-devel.inc
13include /etc/firejail/disable-passwdmgr.inc 13include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc 14include /etc/firejail/disable-programs.inc
15 15
16include /etc/firejail/whitelist-var-common.inc
17
16caps.drop all 18caps.drop all
17netfilter 19netfilter
18nodvd 20nodvd
diff --git a/etc/qpdfview.profile b/etc/qpdfview.profile
index 2d1df0f72..6c264778f 100644
--- a/etc/qpdfview.profile
+++ b/etc/qpdfview.profile
@@ -14,6 +14,8 @@ include /etc/firejail/disable-devel.inc
14include /etc/firejail/disable-passwdmgr.inc 14include /etc/firejail/disable-passwdmgr.inc
15include /etc/firejail/disable-programs.inc 15include /etc/firejail/disable-programs.inc
16 16
17include /etc/firejail/whitelist-var-common.inc
18
17caps.drop all 19caps.drop all
18nodvd 20nodvd
19nogroups 21nogroups
diff --git a/etc/smplayer.profile b/etc/smplayer.profile
index 7563ad730..8c68cda1e 100644
--- a/etc/smplayer.profile
+++ b/etc/smplayer.profile
@@ -13,6 +13,8 @@ include /etc/firejail/disable-devel.inc
13include /etc/firejail/disable-passwdmgr.inc 13include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc 14include /etc/firejail/disable-programs.inc
15 15
16include /etc/firejail/whitelist-var-common.inc
17
16caps.drop all 18caps.drop all
17netfilter 19netfilter
18# nogroups 20# nogroups
diff --git a/etc/smtube.profile b/etc/smtube.profile
index 2694dd5b0..a8f57f07e 100644
--- a/etc/smtube.profile
+++ b/etc/smtube.profile
@@ -17,6 +17,8 @@ include /etc/firejail/disable-devel.inc
17include /etc/firejail/disable-passwdmgr.inc 17include /etc/firejail/disable-passwdmgr.inc
18include /etc/firejail/disable-programs.inc 18include /etc/firejail/disable-programs.inc
19 19
20include /etc/firejail/whitelist-var-common.inc
21
20caps.drop all 22caps.drop all
21netfilter 23netfilter
22nodvd 24nodvd
diff --git a/etc/supertux2.profile b/etc/supertux2.profile
index cd6496a7b..ff55e1c40 100644
--- a/etc/supertux2.profile
+++ b/etc/supertux2.profile
@@ -14,6 +14,7 @@ include /etc/firejail/disable-programs.inc
14mkdir ~/.local/share/supertux2 14mkdir ~/.local/share/supertux2
15whitelist ~/.local/share/supertux2 15whitelist ~/.local/share/supertux2
16include /etc/firejail/whitelist-common.inc 16include /etc/firejail/whitelist-common.inc
17include /etc/firejail/whitelist-var-common.inc
17 18
18caps.drop all 19caps.drop all
19net none 20net none
diff --git a/etc/vim.profile b/etc/vim.profile
index 97ed06d96..e1d5da9e3 100644
--- a/etc/vim.profile
+++ b/etc/vim.profile
@@ -23,3 +23,5 @@ notv
23novideo 23novideo
24protocol unix,inet,inet6 24protocol unix,inet,inet6
25seccomp 25seccomp
26
27private-dev
diff --git a/etc/warzone2100.profile b/etc/warzone2100.profile
index 976f7db5f..43eacdafc 100644
--- a/etc/warzone2100.profile
+++ b/etc/warzone2100.profile
@@ -17,6 +17,7 @@ include /etc/firejail/disable-programs.inc
17whitelist ~/.warzone2100-3.1 17whitelist ~/.warzone2100-3.1
18whitelist ~/.warzone2100-3.2 18whitelist ~/.warzone2100-3.2
19include /etc/firejail/whitelist-common.inc 19include /etc/firejail/whitelist-common.inc
20include /etc/firejail/whitelist-var-common.inc
20 21
21caps.drop all 22caps.drop all
22netfilter 23netfilter
diff --git a/etc/wget.profile b/etc/wget.profile
index 5072cb9c5..510ef18f3 100644
--- a/etc/wget.profile
+++ b/etc/wget.profile
@@ -14,6 +14,8 @@ include /etc/firejail/disable-common.inc
14include /etc/firejail/disable-passwdmgr.inc 14include /etc/firejail/disable-passwdmgr.inc
15include /etc/firejail/disable-programs.inc 15include /etc/firejail/disable-programs.inc
16 16
17include /etc/firejail/whitelist-var-common.inc
18
17caps.drop all 19caps.drop all
18netfilter 20netfilter
19no3d 21no3d
diff --git a/etc/wireshark.profile b/etc/wireshark.profile
index 35e781f67..e283b6149 100644
--- a/etc/wireshark.profile
+++ b/etc/wireshark.profile
@@ -12,6 +12,8 @@ include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-passwdmgr.inc 12include /etc/firejail/disable-passwdmgr.inc
13include /etc/firejail/disable-programs.inc 13include /etc/firejail/disable-programs.inc
14 14
15include /etc/firejail/whitelist-var-common.inc
16
15# caps.drop all 17# caps.drop all
16caps.keep dac_override,net_admin,net_raw 18caps.keep dac_override,net_admin,net_raw
17netfilter 19netfilter
diff --git a/etc/xpdf.profile b/etc/xpdf.profile
index f34358521..8caba5cc5 100644
--- a/etc/xpdf.profile
+++ b/etc/xpdf.profile
@@ -12,6 +12,8 @@ include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-passwdmgr.inc 12include /etc/firejail/disable-passwdmgr.inc
13include /etc/firejail/disable-programs.inc 13include /etc/firejail/disable-programs.inc
14 14
15include /etc/firejail/whitelist-var-common.inc
16
15caps.drop all 17caps.drop all
16net none 18net none
17no3d 19no3d