aboutsummaryrefslogtreecommitdiffstats
path: root/etc/clementine.profile
diff options
context:
space:
mode:
Diffstat (limited to 'etc/clementine.profile')
-rw-r--r--etc/clementine.profile5
1 files changed, 5 insertions, 0 deletions
diff --git a/etc/clementine.profile b/etc/clementine.profile
index 1d93e5f2c..619086437 100644
--- a/etc/clementine.profile
+++ b/etc/clementine.profile
@@ -12,6 +12,8 @@ include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-passwdmgr.inc 12include /etc/firejail/disable-passwdmgr.inc
13include /etc/firejail/disable-programs.inc 13include /etc/firejail/disable-programs.inc
14 14
15include /etc/firejail/whitelist-var-common.inc
16
15caps.drop all 17caps.drop all
16nonewprivs 18nonewprivs
17noroot 19noroot
@@ -20,3 +22,6 @@ novideo
20protocol unix,inet,inet6 22protocol unix,inet,inet6
21# Clementine makes ioprio_set system calls, which are blacklisted by default. 23# Clementine makes ioprio_set system calls, which are blacklisted by default.
22seccomp.drop @cpu-emulation,@debug,@obsolete,@privileged,@resources,add_key,fanotify_init,io_cancel,io_destroy,io_getevents,io_setup,io_submit,kcmp,keyctl,name_to_handle_at,ni_syscall,open_by_handle_at,personality,process_vm_readv,ptrace,remap_file_pages,request_key,syslog,umount,userfaultfd,vmsplice 24seccomp.drop @cpu-emulation,@debug,@obsolete,@privileged,@resources,add_key,fanotify_init,io_cancel,io_destroy,io_getevents,io_setup,io_submit,kcmp,keyctl,name_to_handle_at,ni_syscall,open_by_handle_at,personality,process_vm_readv,ptrace,remap_file_pages,request_key,syslog,umount,userfaultfd,vmsplice
25
26private-dev
27private-tmp