diff options
Diffstat (limited to 'etc')
-rw-r--r-- | etc/profile-a-l/fdns.profile | 2 | ||||
-rw-r--r-- | etc/profile-m-z/vmplayer.profile | 8 | ||||
-rw-r--r-- | etc/profile-m-z/vmware-player.profile | 2 | ||||
-rw-r--r-- | etc/profile-m-z/vmware-view.profile | 2 | ||||
-rw-r--r-- | etc/profile-m-z/vmware-workstation.profile | 2 | ||||
-rw-r--r-- | etc/profile-m-z/vmware.profile | 4 |
6 files changed, 14 insertions, 6 deletions
diff --git a/etc/profile-a-l/fdns.profile b/etc/profile-a-l/fdns.profile index 77e16a56b..4dbf3c194 100644 --- a/etc/profile-a-l/fdns.profile +++ b/etc/profile-a-l/fdns.profile | |||
@@ -21,6 +21,7 @@ include disable-xdg.inc | |||
21 | #include whitelist-usr-share-common.inc | 21 | #include whitelist-usr-share-common.inc |
22 | #include whitelist-var-common.inc | 22 | #include whitelist-var-common.inc |
23 | 23 | ||
24 | apparmor /usr/bin/fdns | ||
24 | caps.keep kill,net_bind_service,setgid,setuid,sys_admin,sys_chroot | 25 | caps.keep kill,net_bind_service,setgid,setuid,sys_admin,sys_chroot |
25 | ipc-namespace | 26 | ipc-namespace |
26 | # netfilter /etc/firejail/webserver.net | 27 | # netfilter /etc/firejail/webserver.net |
@@ -47,4 +48,3 @@ private-etc @tls-ca,fdns | |||
47 | private-tmp | 48 | private-tmp |
48 | 49 | ||
49 | memory-deny-write-execute | 50 | memory-deny-write-execute |
50 | restrict-namespaces | ||
diff --git a/etc/profile-m-z/vmplayer.profile b/etc/profile-m-z/vmplayer.profile new file mode 100644 index 000000000..4b386fed7 --- /dev/null +++ b/etc/profile-m-z/vmplayer.profile | |||
@@ -0,0 +1,8 @@ | |||
1 | # Firejail profile for vmware-player | ||
2 | # Description: VMWare Workstation Player, used for running virtual machines | ||
3 | # This file is overwritten after every install/update | ||
4 | # Persistent local customizations | ||
5 | include vmplayer.local | ||
6 | |||
7 | # Redirect | ||
8 | include vmware.profile | ||
diff --git a/etc/profile-m-z/vmware-player.profile b/etc/profile-m-z/vmware-player.profile index 582a0f693..8be9acc92 100644 --- a/etc/profile-m-z/vmware-player.profile +++ b/etc/profile-m-z/vmware-player.profile | |||
@@ -1,5 +1,5 @@ | |||
1 | # Firejail profile for vmware-player | 1 | # Firejail profile for vmware-player |
2 | # Description: The industry standard for running multiple operating systems as virtual machines on a single Linux PC. | 2 | # Description: VMWare Workstation Player, used for running virtual machines |
3 | # This file is overwritten after every install/update | 3 | # This file is overwritten after every install/update |
4 | # Persistent local customizations | 4 | # Persistent local customizations |
5 | include vmware-player.local | 5 | include vmware-player.local |
diff --git a/etc/profile-m-z/vmware-view.profile b/etc/profile-m-z/vmware-view.profile index c2fd14811..e924d2119 100644 --- a/etc/profile-m-z/vmware-view.profile +++ b/etc/profile-m-z/vmware-view.profile | |||
@@ -1,5 +1,5 @@ | |||
1 | # Firejail profile for vmware-view | 1 | # Firejail profile for vmware-view |
2 | # Description: VMware Horizon Client | 2 | # Description: VMware Horizon Client, used as a remote desktop client |
3 | # This file is overwritten after every install/update | 3 | # This file is overwritten after every install/update |
4 | # Persistent local customizations | 4 | # Persistent local customizations |
5 | include vmware-view.local | 5 | include vmware-view.local |
diff --git a/etc/profile-m-z/vmware-workstation.profile b/etc/profile-m-z/vmware-workstation.profile index 6290b57f4..5311cd123 100644 --- a/etc/profile-m-z/vmware-workstation.profile +++ b/etc/profile-m-z/vmware-workstation.profile | |||
@@ -1,5 +1,5 @@ | |||
1 | # Firejail profile for vmware-workstation | 1 | # Firejail profile for vmware-workstation |
2 | # Description: The industry standard for running multiple operating systems as virtual machines on a single Linux PC. | 2 | # Description: VMWare Workstation Player, used for running virtual machines |
3 | # This file is overwritten after every install/update | 3 | # This file is overwritten after every install/update |
4 | # Persistent local customizations | 4 | # Persistent local customizations |
5 | include vmware-workstation.local | 5 | include vmware-workstation.local |
diff --git a/etc/profile-m-z/vmware.profile b/etc/profile-m-z/vmware.profile index 7619ef47b..ed4a47a83 100644 --- a/etc/profile-m-z/vmware.profile +++ b/etc/profile-m-z/vmware.profile | |||
@@ -1,5 +1,5 @@ | |||
1 | # Firejail profile for vmware | 1 | # Firejail profile for vmware |
2 | # Description: The industry standard for running multiple operating systems as virtual machines on a single Linux PC. | 2 | # Description: VMWare Workstation Player, used for running virtual machines |
3 | # This file is overwritten after every install/update | 3 | # This file is overwritten after every install/update |
4 | # Persistent local customizations | 4 | # Persistent local customizations |
5 | include vmware.local | 5 | include vmware.local |
@@ -11,7 +11,7 @@ noblacklist ${HOME}/.vmware | |||
11 | noblacklist /usr/lib/vmware | 11 | noblacklist /usr/lib/vmware |
12 | 12 | ||
13 | include disable-common.inc | 13 | include disable-common.inc |
14 | include disable-devel.inc | 14 | #include disable-devel.inc # gcc is used to compile kernel modules |
15 | include disable-exec.inc | 15 | include disable-exec.inc |
16 | include disable-interpreters.inc | 16 | include disable-interpreters.inc |
17 | include disable-programs.inc | 17 | include disable-programs.inc |