aboutsummaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
authorLibravatar smitsohu <smitsohu@gmail.com>2017-10-08 01:51:06 +0200
committerLibravatar smitsohu <smitsohu@gmail.com>2017-10-08 01:51:06 +0200
commitc6ce7577ca78c831d15215333e4f7fb9a0977909 (patch)
tree8bb555158f55e3078825319244359a9895c952e6 /etc
parentfldd fixes (diff)
downloadfirejail-c6ce7577ca78c831d15215333e4f7fb9a0977909.tar.gz
firejail-c6ce7577ca78c831d15215333e4f7fb9a0977909.tar.zst
firejail-c6ce7577ca78c831d15215333e4f7fb9a0977909.zip
some profile enhancements
Diffstat (limited to 'etc')
-rw-r--r--etc/dnscrypt-proxy.profile3
-rw-r--r--etc/dnsmasq.profile3
-rw-r--r--etc/unbound.profile3
-rw-r--r--etc/wireshark.profile7
-rw-r--r--etc/xplayer.profile2
-rw-r--r--etc/xreader.profile2
6 files changed, 10 insertions, 10 deletions
diff --git a/etc/dnscrypt-proxy.profile b/etc/dnscrypt-proxy.profile
index 6d4f6349a..458de81e2 100644
--- a/etc/dnscrypt-proxy.profile
+++ b/etc/dnscrypt-proxy.profile
@@ -15,8 +15,7 @@ include /etc/firejail/disable-devel.inc
15include /etc/firejail/disable-passwdmgr.inc 15include /etc/firejail/disable-passwdmgr.inc
16include /etc/firejail/disable-programs.inc 16include /etc/firejail/disable-programs.inc
17 17
18caps 18caps.keep ipc_lock,net_bind_service,setgid,setuid,sys_chroot
19# caps.keep ipc_lock,net_bind_service,setgid,setuid,sys_chroot
20no3d 19no3d
21nodvd 20nodvd
22nonewprivs 21nonewprivs
diff --git a/etc/dnsmasq.profile b/etc/dnsmasq.profile
index 2a1302adb..e6086d1b2 100644
--- a/etc/dnsmasq.profile
+++ b/etc/dnsmasq.profile
@@ -15,8 +15,7 @@ include /etc/firejail/disable-devel.inc
15include /etc/firejail/disable-passwdmgr.inc 15include /etc/firejail/disable-passwdmgr.inc
16include /etc/firejail/disable-programs.inc 16include /etc/firejail/disable-programs.inc
17 17
18caps 18caps.keep net_admin,net_bind_service,net_raw,setgid,setuid
19# caps.keep net_admin,net_bind_service,net_raw,setgid,setuid
20no3d 19no3d
21nodvd 20nodvd
22nonewprivs 21nonewprivs
diff --git a/etc/unbound.profile b/etc/unbound.profile
index d380b5698..c03a25752 100644
--- a/etc/unbound.profile
+++ b/etc/unbound.profile
@@ -15,8 +15,7 @@ include /etc/firejail/disable-devel.inc
15include /etc/firejail/disable-passwdmgr.inc 15include /etc/firejail/disable-passwdmgr.inc
16include /etc/firejail/disable-programs.inc 16include /etc/firejail/disable-programs.inc
17 17
18caps 18caps.keep net_bind_service,setgid,setuid,sys_chroot,sys_resource
19# caps.keep net_bind_service,setgid,setuid,sys_chroot,sys_resource
20no3d 19no3d
21nodvd 20nodvd
22nonewprivs 21nonewprivs
diff --git a/etc/wireshark.profile b/etc/wireshark.profile
index f1a17ba93..35e781f67 100644
--- a/etc/wireshark.profile
+++ b/etc/wireshark.profile
@@ -12,18 +12,19 @@ include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-passwdmgr.inc 12include /etc/firejail/disable-passwdmgr.inc
13include /etc/firejail/disable-programs.inc 13include /etc/firejail/disable-programs.inc
14 14
15# caps.drop all
15caps.keep dac_override,net_admin,net_raw 16caps.keep dac_override,net_admin,net_raw
16netfilter 17netfilter
17no3d 18no3d
18# nogroups - breaks unprivileged wireshark usage 19# nogroups - breaks network traffic capture for unprivileged users
19# nonewprivs - breaks unprivileged wireshark usage 20# nonewprivs - breaks network traffic capture for unprivileged users
20# noroot 21# noroot
21nodvd 22nodvd
22nosound 23nosound
23notv 24notv
24novideo 25novideo
25# protocol unix,inet,inet6,netlink 26# protocol unix,inet,inet6,netlink
26# seccomp - breaks unprivileged wireshark usage 27# seccomp - breaks network traffic capture for unprivileged users
27shell none 28shell none
28tracelog 29tracelog
29 30
diff --git a/etc/xplayer.profile b/etc/xplayer.profile
index 5c845e977..d4a2fa846 100644
--- a/etc/xplayer.profile
+++ b/etc/xplayer.profile
@@ -13,6 +13,8 @@ include /etc/firejail/disable-devel.inc
13include /etc/firejail/disable-passwdmgr.inc 13include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc 14include /etc/firejail/disable-programs.inc
15 15
16include /etc/firejail/whitelist-var-common.inc
17
16caps.drop all 18caps.drop all
17netfilter 19netfilter
18nogroups 20nogroups
diff --git a/etc/xreader.profile b/etc/xreader.profile
index bebcb262f..11e5d1102 100644
--- a/etc/xreader.profile
+++ b/etc/xreader.profile
@@ -32,7 +32,7 @@ tracelog
32 32
33private-bin xreader,xreader-previewer,xreader-thumbnailer 33private-bin xreader,xreader-previewer,xreader-thumbnailer
34private-dev 34private-dev
35# private-etc fonts,ld.so.cache 35private-etc fonts,ld.so.cache
36# xreader needs access to /tmp/mozilla* to work in firefox 36# xreader needs access to /tmp/mozilla* to work in firefox
37# private-tmp 37# private-tmp
38 38