aboutsummaryrefslogtreecommitdiffstats
path: root/etc/ffmpeg.profile
diff options
context:
space:
mode:
Diffstat (limited to 'etc/ffmpeg.profile')
-rw-r--r--etc/ffmpeg.profile33
1 files changed, 33 insertions, 0 deletions
diff --git a/etc/ffmpeg.profile b/etc/ffmpeg.profile
new file mode 100644
index 000000000..e098c95e3
--- /dev/null
+++ b/etc/ffmpeg.profile
@@ -0,0 +1,33 @@
1# Firejail profile for default
2# This file is overwritten after every install/update
3quiet
4# Persistent local customizations
5include /etc/firejail/ffmpeg.local
6# Persistent global definitions
7include /etc/firejail/globals.local
8
9include /etc/firejail/disable-common.inc
10include /etc/firejail/disable-devel.inc
11include /etc/firejail/disable-passwdmgr.inc
12include /etc/firejail/disable-programs.inc
13
14caps.drop all
15net none
16no3d
17nodvd
18nosound
19notv
20novideo
21nonewprivs
22noroot
23# protocol none - needs to be implemented!
24seccomp
25# seccomp.keep futex,write,read,munmap,fstat,mprotect,mmap,open,close,stat,lseek,brk,rt_sigaction,rt_sigprocmask,ioctl,access,select,madvise,getpid,clone,execve,fcntl,getdents,readlink,getrlimit,getrusage,statfs,getpriority,setpriority,arch_prctl,sched_getaffinity,set_tid_address,set_robust_list,getrandom
26# memory-deny-write-execute - it breaks old versions of ffmpeg
27shell none
28tracelog
29
30private-tmp
31private-dev
32private-bin ffmpeg
33include /etc/firejail/whitelist-var-common.inc