aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
-rw-r--r--README.md8
-rw-r--r--etc/audacity.profile2
-rw-r--r--etc/engrampa.profile4
-rw-r--r--etc/eog.profile8
-rw-r--r--etc/eom.profile8
-rw-r--r--etc/file-roller.profile4
-rw-r--r--etc/gedit.profile8
-rw-r--r--etc/gimp.profile8
-rw-r--r--etc/gnome-calculator.profile8
-rw-r--r--etc/kcalc.profile1
-rw-r--r--etc/pluma.profile8
-rw-r--r--etc/rhythmbox.profile6
-rw-r--r--etc/totem.profile6
-rw-r--r--etc/xed.profile8
-rw-r--r--etc/xplayer.profile6
-rw-r--r--etc/xviewer.profile8
16 files changed, 36 insertions, 65 deletions
diff --git a/README.md b/README.md
index 57267e414..4739b22fd 100644
--- a/README.md
+++ b/README.md
@@ -259,12 +259,10 @@ enable/disable apparmor functionality globally. By default the flag is enabled.
259AppArmor deployment: we are starting apparmor by default for the following programs: 259AppArmor deployment: we are starting apparmor by default for the following programs:
260- web browsers: firefox (firefox-common.profile), chromium (chromium-common.profile) 260- web browsers: firefox (firefox-common.profile), chromium (chromium-common.profile)
261- torrent clients: transmission-qt, transmission-gtk, qbittorrent 261- torrent clients: transmission-qt, transmission-gtk, qbittorrent
262- media players: vlc, mpv, audacious, totem, rhythmbox, kodi, smplayer, xplayer 262- media players: vlc, mpv, audacious, kodi, smplayer
263- media editing: kdenlive, audacity, handbrake, gimp, inkscape, krita, openshot 263- media editing: kdenlive, audacity, handbrake, inkscape, krita, openshot
264- image viewers: eom, eog, gwenview, xviewer
265- archive managers: ark, engrampa, file-roller 264- archive managers: ark, engrampa, file-roller
266- text editors: gedit, kwrite, pluma, xed 265- etc.: digikam, libreoffice, okular, gwenview, galculator, kcalc
267- etc.: digikam, gnome-calculator, galculator, kcalc, okular, libreoffice, asunder
268 266
269Checking apparmor status: 267Checking apparmor status:
270````` 268`````
diff --git a/etc/audacity.profile b/etc/audacity.profile
index e8ad7347a..907dbeb55 100644
--- a/etc/audacity.profile
+++ b/etc/audacity.profile
@@ -18,7 +18,7 @@ apparmor
18caps.drop all 18caps.drop all
19net none 19net none
20no3d 20no3d
21# nodbus 21# nodbus - problems on Fedora 27
22nodvd 22nodvd
23nogroups 23nogroups
24nonewprivs 24nonewprivs
diff --git a/etc/engrampa.profile b/etc/engrampa.profile
index 25607d0a0..cf32d579e 100644
--- a/etc/engrampa.profile
+++ b/etc/engrampa.profile
@@ -12,13 +12,11 @@ include /etc/firejail/disable-programs.inc
12 12
13include /etc/firejail/whitelist-var-common.inc 13include /etc/firejail/whitelist-var-common.inc
14 14
15# following line makes settings immutable
16apparmor 15apparmor
17caps.drop all 16caps.drop all
18net none 17net none
19no3d 18no3d
20# following line makes settings immutable 19nodbus
21# nodbus
22nodvd 20nodvd
23nogroups 21nogroups
24nonewprivs 22nonewprivs
diff --git a/etc/eog.profile b/etc/eog.profile
index cbb0dc3cf..66434ae05 100644
--- a/etc/eog.profile
+++ b/etc/eog.profile
@@ -17,13 +17,11 @@ include /etc/firejail/disable-programs.inc
17 17
18include /etc/firejail/whitelist-var-common.inc 18include /etc/firejail/whitelist-var-common.inc
19 19
20# following line makes settings immutable 20# apparmor - makes settings immutable
21apparmor
22caps.drop all 21caps.drop all
23net none 22# net none - makes settings immutable
24no3d 23no3d
25# following line makes settings immutable 24# nodbus - makes settings immutable
26# nodbus
27nodvd 25nodvd
28nogroups 26nogroups
29nonewprivs 27nonewprivs
diff --git a/etc/eom.profile b/etc/eom.profile
index 93acd7f28..48965bcb9 100644
--- a/etc/eom.profile
+++ b/etc/eom.profile
@@ -17,13 +17,11 @@ include /etc/firejail/disable-programs.inc
17 17
18include /etc/firejail/whitelist-var-common.inc 18include /etc/firejail/whitelist-var-common.inc
19 19
20# following line makes settings immutable 20# apparmor - makes settings immutable
21apparmor
22caps.drop all 21caps.drop all
23net none 22# net none - makes settings immutable
24no3d 23no3d
25# following line makes settings immutable 24# nodbus - makes settings immutable
26# nodbus
27nodvd 25nodvd
28nogroups 26nogroups
29nonewprivs 27nonewprivs
diff --git a/etc/file-roller.profile b/etc/file-roller.profile
index f21f8af85..eb76d1dbb 100644
--- a/etc/file-roller.profile
+++ b/etc/file-roller.profile
@@ -12,13 +12,11 @@ include /etc/firejail/disable-programs.inc
12 12
13include /etc/firejail/whitelist-var-common.inc 13include /etc/firejail/whitelist-var-common.inc
14 14
15# following line makes settings immutable
16apparmor 15apparmor
17caps.drop all 16caps.drop all
18net none 17net none
19no3d 18no3d
20# following line makes settings immutable 19nodbus
21# nodbus
22nodvd 20nodvd
23nogroups 21nogroups
24nonewprivs 22nonewprivs
diff --git a/etc/gedit.profile b/etc/gedit.profile
index 49d99becf..e78b8a708 100644
--- a/etc/gedit.profile
+++ b/etc/gedit.profile
@@ -16,14 +16,12 @@ include /etc/firejail/disable-programs.inc
16 16
17include /etc/firejail/whitelist-var-common.inc 17include /etc/firejail/whitelist-var-common.inc
18 18
19# following line makes settings immutable 19# apparmor - makes settings immutable
20apparmor
21caps.drop all 20caps.drop all
22machine-id 21machine-id
23net none 22# net none - makes settings immutable
24no3d 23no3d
25# following line makes settings immutable 24# nodbus - makes settings immutable
26# nodbus
27nodvd 25nodvd
28nogroups 26nogroups
29nonewprivs 27nonewprivs
diff --git a/etc/gimp.profile b/etc/gimp.profile
index 5685eb5c1..630f02229 100644
--- a/etc/gimp.profile
+++ b/etc/gimp.profile
@@ -13,12 +13,10 @@ include /etc/firejail/disable-programs.inc
13 13
14include /etc/firejail/whitelist-var-common.inc 14include /etc/firejail/whitelist-var-common.inc
15 15
16# following line makes settings immutable 16# apparmor - makes settings immutable
17apparmor
18caps.drop all 17caps.drop all
19net none 18# net none - makes settings immutable
20# following line makes settings immutable 19# nodbus - makes settings immutable
21# nodbus
22nodvd 20nodvd
23nogroups 21nogroups
24nonewprivs 22nonewprivs
diff --git a/etc/gnome-calculator.profile b/etc/gnome-calculator.profile
index 24615e828..9d737efb1 100644
--- a/etc/gnome-calculator.profile
+++ b/etc/gnome-calculator.profile
@@ -14,13 +14,11 @@ include /etc/firejail/disable-programs.inc
14include /etc/firejail/whitelist-common.inc 14include /etc/firejail/whitelist-common.inc
15include /etc/firejail/whitelist-var-common.inc 15include /etc/firejail/whitelist-var-common.inc
16 16
17# following line makes settings immutable 17# apparmor - makes settings immutable
18apparmor
19caps.drop all 18caps.drop all
20net none 19# net none - makes settings immutable
21no3d 20no3d
22# following line makes settings immutable 21# nodbus - makes settings immutable
23# nodbus
24nodvd 22nodvd
25nogroups 23nogroups
26nonewprivs 24nonewprivs
diff --git a/etc/kcalc.profile b/etc/kcalc.profile
index 0e10dc061..86a3b1462 100644
--- a/etc/kcalc.profile
+++ b/etc/kcalc.profile
@@ -23,7 +23,6 @@ include /etc/firejail/whitelist-var-common.inc
23apparmor 23apparmor
24caps.drop all 24caps.drop all
25net none 25net none
26netfilter
27no3d 26no3d
28nodbus 27nodbus
29nodvd 28nodvd
diff --git a/etc/pluma.profile b/etc/pluma.profile
index da9766a81..d0acfeb1a 100644
--- a/etc/pluma.profile
+++ b/etc/pluma.profile
@@ -14,14 +14,12 @@ include /etc/firejail/disable-programs.inc
14 14
15include /etc/firejail/whitelist-var-common.inc 15include /etc/firejail/whitelist-var-common.inc
16 16
17# following line makes settings immutable 17# apparmor - makes settings immutable
18apparmor
19caps.drop all 18caps.drop all
20machine-id 19machine-id
21net none 20# net none - makes settings immutable
22no3d 21no3d
23# following line makes settings immutable 22# nodbus - makes settings immutable
24# nodbus
25nodvd 23nodvd
26nogroups 24nogroups
27nonewprivs 25nonewprivs
diff --git a/etc/rhythmbox.profile b/etc/rhythmbox.profile
index f02d0363b..6322f8217 100644
--- a/etc/rhythmbox.profile
+++ b/etc/rhythmbox.profile
@@ -13,13 +13,11 @@ include /etc/firejail/disable-programs.inc
13 13
14include /etc/firejail/whitelist-var-common.inc 14include /etc/firejail/whitelist-var-common.inc
15 15
16# following line makes settings immutable 16# apparmor - makes settings immutable
17apparmor
18caps.drop all 17caps.drop all
19netfilter 18netfilter
20# no3d 19# no3d
21# following line makes settings immutable 20# nodbus - makes settings immutable
22# nodbus
23nogroups 21nogroups
24nonewprivs 22nonewprivs
25noroot 23noroot
diff --git a/etc/totem.profile b/etc/totem.profile
index 0b242ab8f..ad3845d90 100644
--- a/etc/totem.profile
+++ b/etc/totem.profile
@@ -15,12 +15,10 @@ include /etc/firejail/disable-programs.inc
15 15
16include /etc/firejail/whitelist-var-common.inc 16include /etc/firejail/whitelist-var-common.inc
17 17
18# following line makes settings immutable 18# apparmor - makes settings immutable
19apparmor
20caps.drop all 19caps.drop all
21netfilter 20netfilter
22# following line makes settings immutable 21# nodbus - makes settings immutable
23# nodbus
24nogroups 22nogroups
25nonewprivs 23nonewprivs
26noroot 24noroot
diff --git a/etc/xed.profile b/etc/xed.profile
index 5f245f9ff..5d46560b7 100644
--- a/etc/xed.profile
+++ b/etc/xed.profile
@@ -14,14 +14,12 @@ include /etc/firejail/disable-programs.inc
14 14
15include /etc/firejail/whitelist-var-common.inc 15include /etc/firejail/whitelist-var-common.inc
16 16
17# following line makes settings immutable 17# apparmor - makes settings immutable
18apparmor
19caps.drop all 18caps.drop all
20machine-id 19machine-id
21net none 20# net none - makes settings immutable
22no3d 21no3d
23# following line makes settings immutable 22# nodbus - makes settings immutable
24# nodbus
25nodvd 23nodvd
26nogroups 24nogroups
27nonewprivs 25nonewprivs
diff --git a/etc/xplayer.profile b/etc/xplayer.profile
index e0b7b4322..7e475bd58 100644
--- a/etc/xplayer.profile
+++ b/etc/xplayer.profile
@@ -15,12 +15,10 @@ include /etc/firejail/disable-programs.inc
15 15
16include /etc/firejail/whitelist-var-common.inc 16include /etc/firejail/whitelist-var-common.inc
17 17
18# following line makes settings immutable 18# apparmor - makes settings immutable
19apparmor
20caps.drop all 19caps.drop all
21netfilter 20netfilter
22# following line makes settings immutable 21# nodbus - makes settings immutable
23# nodbus
24nogroups 22nogroups
25nonewprivs 23nonewprivs
26noroot 24noroot
diff --git a/etc/xviewer.profile b/etc/xviewer.profile
index 35e9398ad..26f9f0238 100644
--- a/etc/xviewer.profile
+++ b/etc/xviewer.profile
@@ -17,13 +17,11 @@ include /etc/firejail/disable-programs.inc
17 17
18include /etc/firejail/whitelist-var-common.inc 18include /etc/firejail/whitelist-var-common.inc
19 19
20# following line makes settings immutable 20# apparmor - makes settings immutable
21apparmor
22caps.drop all 21caps.drop all
23net none 22# net none - makes settings immutable
24no3d 23no3d
25# following line makes settings immutable 24# nodbus - makes settings immutable
26# nodbus
27nodvd 25nodvd
28nogroups 26nogroups
29nonewprivs 27nonewprivs