aboutsummaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
authorLibravatar rusty-snake <print_hello_world+GitHub@protonmail.com>2019-03-13 17:35:00 +0000
committerLibravatar glitsj16 <glitsj16@users.noreply.github.com>2019-03-13 17:35:00 +0000
commitbcb2a2f0a8d597a281156f6bb2b9c2785644ed0e (patch)
treee3d1d358949ba2fdf473a23a4e8fba40820e2d86 /etc
parentMerge pull request #2582 from rusty-snake/harden_qtox (diff)
downloadfirejail-bcb2a2f0a8d597a281156f6bb2b9c2785644ed0e.tar.gz
firejail-bcb2a2f0a8d597a281156f6bb2b9c2785644ed0e.tar.zst
firejail-bcb2a2f0a8d597a281156f6bb2b9c2785644ed0e.zip
Harden youtube-dl.profile (#2584)
* Harden youtube-dl.profile * Add dis-exec to ytdl * Comment mdwe in ytdl
Diffstat (limited to 'etc')
-rw-r--r--etc/youtube-dl.profile16
1 files changed, 13 insertions, 3 deletions
diff --git a/etc/youtube-dl.profile b/etc/youtube-dl.profile
index 0878c91ef..621ffb2b0 100644
--- a/etc/youtube-dl.profile
+++ b/etc/youtube-dl.profile
@@ -19,8 +19,12 @@ noblacklist /usr/lib/python3*
19noblacklist /usr/local/lib/python2* 19noblacklist /usr/local/lib/python2*
20noblacklist /usr/local/lib/python3* 20noblacklist /usr/local/lib/python3*
21 21
22# breaks when installed via pip
23ignore noexec ${HOME}
24
22include disable-common.inc 25include disable-common.inc
23include disable-devel.inc 26include disable-devel.inc
27include disable-exec.inc
24include disable-interpreters.inc 28include disable-interpreters.inc
25include disable-passwdmgr.inc 29include disable-passwdmgr.inc
26include disable-programs.inc 30include disable-programs.inc
@@ -28,10 +32,13 @@ include disable-xdg.inc
28 32
29include whitelist-var-common.inc 33include whitelist-var-common.inc
30 34
35apparmor
31caps.drop all 36caps.drop all
32ipc-namespace 37ipc-namespace
38machine-id
33netfilter 39netfilter
34no3d 40no3d
41nodbus
35nodvd 42nodvd
36nogroups 43nogroups
37nonewprivs 44nonewprivs
@@ -45,8 +52,11 @@ seccomp
45shell none 52shell none
46tracelog 53tracelog
47 54
55disable-mnt
56private-bin youtube-dl,python*,ffmpeg
57private-cache
48private-dev 58private-dev
59private-etc alternatives,ssl,pki,ca-certificates,hostname,hosts,resolv.conf,youtube-dl.conf,crypto-policies,mime.types
60private-tmp
49 61
50# breaks when installed via pip 62# memory-deny-write-execute - breaks on Arch
51#noexec ${HOME}
52noexec /tmp