aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
-rw-r--r--etc/kmail.profile5
-rw-r--r--etc/kopete.profile2
-rw-r--r--etc/less.profile2
-rw-r--r--etc/mutt.profile2
-rw-r--r--etc/ssh.profile2
-rw-r--r--etc/tar.profile4
-rw-r--r--etc/tor.profile2
-rw-r--r--etc/unbound.profile2
8 files changed, 10 insertions, 11 deletions
diff --git a/etc/kmail.profile b/etc/kmail.profile
index 009b2c063..0b602c79a 100644
--- a/etc/kmail.profile
+++ b/etc/kmail.profile
@@ -53,9 +53,8 @@ protocol unix,inet,inet6,netlink
53# we need to allow chroot, io_getevents, ioprio_set, io_setup, io_submit system calls 53# we need to allow chroot, io_getevents, ioprio_set, io_setup, io_submit system calls
54seccomp.drop @clock,@cpu-emulation,@debug,@module,@obsolete,@raw-io,@reboot,@resources,@swap,acct,add_key,bpf,fanotify_init,io_cancel,io_destroy,kcmp,keyctl,mount,name_to_handle_at,nfsservctl,ni_syscall,open_by_handle_at,personality,pivot_root,process_vm_readv,ptrace,remap_file_pages,request_key,setdomainname,sethostname,syslog,umount,umount2,userfaultfd,vhangup,vmsplice 54seccomp.drop @clock,@cpu-emulation,@debug,@module,@obsolete,@raw-io,@reboot,@resources,@swap,acct,add_key,bpf,fanotify_init,io_cancel,io_destroy,kcmp,keyctl,mount,name_to_handle_at,nfsservctl,ni_syscall,open_by_handle_at,personality,pivot_root,process_vm_readv,ptrace,remap_file_pages,request_key,setdomainname,sethostname,syslog,umount,umount2,userfaultfd,vhangup,vmsplice
55# tracelog 55# tracelog
56# writable-run-user is needed for signing and encrypting emails
57writable-run-user
58 56
59private-dev 57private-dev
60# private-tmp - interrupts connection to akonadi, breaks opening of email attachments 58# private-tmp - interrupts connection to akonadi, breaks opening of email attachments
61 59# writable-run-user is needed for signing and encrypting emails
60writable-run-user
diff --git a/etc/kopete.profile b/etc/kopete.profile
index 5e931ddac..e0bdce059 100644
--- a/etc/kopete.profile
+++ b/etc/kopete.profile
@@ -31,8 +31,8 @@ notv
31nou2f 31nou2f
32protocol unix,inet,inet6,netlink 32protocol unix,inet,inet6,netlink
33seccomp 33seccomp
34writable-var
35 34
36private-dev 35private-dev
37private-tmp 36private-tmp
37writable-var
38 38
diff --git a/etc/less.profile b/etc/less.profile
index bc85e5ad5..897d38b9d 100644
--- a/etc/less.profile
+++ b/etc/less.profile
@@ -34,7 +34,6 @@ protocol unix
34seccomp 34seccomp
35shell none 35shell none
36tracelog 36tracelog
37writable-var-log
38 37
39# The user can have a custom coloring script configured in ${HOME}/.lessfilter. 38# The user can have a custom coloring script configured in ${HOME}/.lessfilter.
40# Enable private-bin and private-lib if you are not using any filter. 39# Enable private-bin and private-lib if you are not using any filter.
@@ -42,5 +41,6 @@ writable-var-log
42# private-lib 41# private-lib
43private-cache 42private-cache
44private-dev 43private-dev
44writable-var-log
45 45
46memory-deny-write-execute 46memory-deny-write-execute
diff --git a/etc/mutt.profile b/etc/mutt.profile
index 419e17e95..c424dbb85 100644
--- a/etc/mutt.profile
+++ b/etc/mutt.profile
@@ -54,6 +54,6 @@ novideo
54protocol unix,inet,inet6 54protocol unix,inet,inet6
55seccomp 55seccomp
56shell none 56shell none
57writable-run-user
58 57
59private-dev 58private-dev
59writable-run-user
diff --git a/etc/ssh.profile b/etc/ssh.profile
index 17d286b18..ce0e54a0d 100644
--- a/etc/ssh.profile
+++ b/etc/ssh.profile
@@ -37,6 +37,6 @@ tracelog
37private-cache 37private-cache
38private-dev 38private-dev
39# private-tmp # Breaks when exiting 39# private-tmp # Breaks when exiting
40writable-run-user
40 41
41memory-deny-write-execute 42memory-deny-write-execute
42writable-run-user
diff --git a/etc/tar.profile b/etc/tar.profile
index 71f7414bc..7e1fa8b92 100644
--- a/etc/tar.profile
+++ b/etc/tar.profile
@@ -43,7 +43,7 @@ private-cache
43private-dev 43private-dev
44private-etc alternatives,group,localtime,passwd 44private-etc alternatives,group,localtime,passwd
45private-lib libfakeroot 45private-lib libfakeroot
46
47memory-deny-write-execute
48# Debian based distributions need this for 'dpkg --unpack' (incl. synaptic) 46# Debian based distributions need this for 'dpkg --unpack' (incl. synaptic)
49writable-var 47writable-var
48
49memory-deny-write-execute
diff --git a/etc/tor.profile b/etc/tor.profile
index e896b609a..13d071635 100644
--- a/etc/tor.profile
+++ b/etc/tor.profile
@@ -40,7 +40,6 @@ novideo
40protocol unix,inet,inet6 40protocol unix,inet,inet6
41seccomp 41seccomp
42shell none 42shell none
43writable-var
44 43
45disable-mnt 44disable-mnt
46private 45private
@@ -49,3 +48,4 @@ private-cache
49private-dev 48private-dev
50private-etc alternatives,ca-certificates,crypto-policies,passwd,pki,ssl,tor 49private-etc alternatives,ca-certificates,crypto-policies,passwd,pki,ssl,tor
51private-tmp 50private-tmp
51writable-var
diff --git a/etc/unbound.profile b/etc/unbound.profile
index 50304d223..e152ee7ea 100644
--- a/etc/unbound.profile
+++ b/etc/unbound.profile
@@ -30,11 +30,11 @@ notv
30nou2f 30nou2f
31novideo 31novideo
32seccomp.drop _sysctl,acct,add_key,adjtimex,clock_adjtime,delete_module,fanotify_init,finit_module,get_mempolicy,init_module,io_cancel,io_destroy,io_getevents,io_setup,io_submit,ioperm,iopl,kcmp,kexec_file_load,kexec_load,keyctl,lookup_dcookie,mbind,migrate_pages,modify_ldt,mount,move_pages,open_by_handle_at,perf_event_open,perf_event_open,pivot_root,process_vm_readv,process_vm_writev,ptrace,remap_file_pages,request_key,set_mempolicy,swapoff,swapon,sysfs,syslog,umount2,uselib,vmsplice 32seccomp.drop _sysctl,acct,add_key,adjtimex,clock_adjtime,delete_module,fanotify_init,finit_module,get_mempolicy,init_module,io_cancel,io_destroy,io_getevents,io_setup,io_submit,ioperm,iopl,kcmp,kexec_file_load,kexec_load,keyctl,lookup_dcookie,mbind,migrate_pages,modify_ldt,mount,move_pages,open_by_handle_at,perf_event_open,perf_event_open,pivot_root,process_vm_readv,process_vm_writev,ptrace,remap_file_pages,request_key,set_mempolicy,swapoff,swapon,sysfs,syslog,umount2,uselib,vmsplice
33writable-var
34 33
35disable-mnt 34disable-mnt
36private 35private
37private-dev 36private-dev
37writable-var
38 38
39# mdwe can break modules/plugins 39# mdwe can break modules/plugins
40memory-deny-write-execute 40memory-deny-write-execute