aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
-rw-r--r--etc/profile-a-l/clementine.profile9
-rw-r--r--etc/profile-m-z/ping.profile3
2 files changed, 11 insertions, 1 deletions
diff --git a/etc/profile-a-l/clementine.profile b/etc/profile-a-l/clementine.profile
index 4d92157d0..387b5f0a7 100644
--- a/etc/profile-a-l/clementine.profile
+++ b/etc/profile-a-l/clementine.profile
@@ -12,22 +12,29 @@ noblacklist ${MUSIC}
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
15include disable-exec.inc
15include disable-interpreters.inc 16include disable-interpreters.inc
16include disable-passwdmgr.inc 17include disable-passwdmgr.inc
17include disable-programs.inc 18include disable-programs.inc
18include disable-xdg.inc 19include disable-xdg.inc
19 20
20include whitelist-var-common.inc 21include whitelist-var-common.inc
22include whitelist-usr-share-common.inc
23include whitelist-runuser-common.inc
21 24
25apparmor
22caps.drop all 26caps.drop all
23nonewprivs 27nonewprivs
24noroot 28noroot
25notv 29notv
26nou2f 30nou2f
27novideo 31novideo
28protocol unix,inet,inet6 32protocol unix,inet,inet6,netlink
29# blacklisting of ioprio_set system calls breaks clementine 33# blacklisting of ioprio_set system calls breaks clementine
30seccomp !ioprio_set 34seccomp !ioprio_set
31 35
32private-dev 36private-dev
33private-tmp 37private-tmp
38
39dbus-system none
40# dbus-user none
diff --git a/etc/profile-m-z/ping.profile b/etc/profile-m-z/ping.profile
index 3ef8ad64a..bd95cb1de 100644
--- a/etc/profile-m-z/ping.profile
+++ b/etc/profile-m-z/ping.profile
@@ -54,3 +54,6 @@ private-tmp
54 54
55# memory-deny-write-execute is built using seccomp; nonewprivs will kill it 55# memory-deny-write-execute is built using seccomp; nonewprivs will kill it
56#memory-deny-write-execute 56#memory-deny-write-execute
57
58dbus-user none
59dbus-system none