aboutsummaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
Diffstat (limited to 'etc')
-rw-r--r--etc/spotify.profile1
-rw-r--r--etc/start-tor-browser.profile4
-rw-r--r--etc/torbrowser-launcher.profile6
3 files changed, 8 insertions, 3 deletions
diff --git a/etc/spotify.profile b/etc/spotify.profile
index 7f40d4399..4e2718c95 100644
--- a/etc/spotify.profile
+++ b/etc/spotify.profile
@@ -9,7 +9,6 @@ blacklist ${HOME}/.bashrc
9blacklist /lost+found 9blacklist /lost+found
10blacklist /sbin 10blacklist /sbin
11blacklist /srv 11blacklist /srv
12blacklist /sys
13 12
14noblacklist ${HOME}/.cache/spotify 13noblacklist ${HOME}/.cache/spotify
15noblacklist ${HOME}/.config/spotify 14noblacklist ${HOME}/.config/spotify
diff --git a/etc/start-tor-browser.profile b/etc/start-tor-browser.profile
index fe9760ad4..6069c5174 100644
--- a/etc/start-tor-browser.profile
+++ b/etc/start-tor-browser.profile
@@ -17,6 +17,7 @@ include /etc/firejail/whitelist-var-common.inc
17 17
18caps.drop all 18caps.drop all
19netfilter 19netfilter
20nodbus
20nodvd 21nodvd
21nogroups 22nogroups
22nonewprivs 23nonewprivs
@@ -24,8 +25,9 @@ noroot
24notv 25notv
25novideo 26novideo
26protocol unix,inet,inet6 27protocol unix,inet,inet6
27seccomp 28seccomp.drop @clock,@cpu-emulation,@debug,@module,@obsolete,@raw-io,@reboot,@resources,@swap,acct,add_key,bpf,fanotify_init,io_cancel,io_destroy,io_getevents,io_setup,io_submit,ioprio_set,kcmp,keyctl,mount,name_to_handle_at,nfsservctl,ni_syscall,open_by_handle_at,personality,pivot_root,process_vm_readv,ptrace,remap_file_pages,request_key,setdomainname,sethostname,syslog,umount,umount2,userfaultfd,vhangup,vmsplice
28shell none 29shell none
30# tracelog may cause issues, see github issue #1930
29tracelog 31tracelog
30 32
31disable-mnt 33disable-mnt
diff --git a/etc/torbrowser-launcher.profile b/etc/torbrowser-launcher.profile
index c8eecfc4a..f175b6590 100644
--- a/etc/torbrowser-launcher.profile
+++ b/etc/torbrowser-launcher.profile
@@ -20,9 +20,11 @@ include /etc/firejail/disable-devel.inc
20include /etc/firejail/disable-interpreters.inc 20include /etc/firejail/disable-interpreters.inc
21include /etc/firejail/disable-passwdmgr.inc 21include /etc/firejail/disable-passwdmgr.inc
22include /etc/firejail/disable-programs.inc 22include /etc/firejail/disable-programs.inc
23include /etc/firejail/disable-xdg.inc
23 24
24mkdir ${HOME}/.config/torbrowser 25mkdir ${HOME}/.config/torbrowser
25mkdir ${HOME}/.local/share/torbrowser 26mkdir ${HOME}/.local/share/torbrowser
27whitelist ${DOWNLOADS}
26whitelist ${HOME}/.config/torbrowser 28whitelist ${HOME}/.config/torbrowser
27whitelist ${HOME}/.local/share/torbrowser 29whitelist ${HOME}/.local/share/torbrowser
28include /etc/firejail/whitelist-common.inc 30include /etc/firejail/whitelist-common.inc
@@ -30,6 +32,7 @@ include /etc/firejail/whitelist-var-common.inc
30 32
31caps.drop all 33caps.drop all
32netfilter 34netfilter
35nodbus
33nodvd 36nodvd
34nogroups 37nogroups
35nonewprivs 38nonewprivs
@@ -37,8 +40,9 @@ noroot
37notv 40notv
38novideo 41novideo
39protocol unix,inet,inet6 42protocol unix,inet,inet6
40seccomp 43seccomp.drop @clock,@cpu-emulation,@debug,@module,@obsolete,@raw-io,@reboot,@resources,@swap,acct,add_key,bpf,fanotify_init,io_cancel,io_destroy,io_getevents,io_setup,io_submit,ioprio_set,kcmp,keyctl,mount,name_to_handle_at,nfsservctl,ni_syscall,open_by_handle_at,personality,pivot_root,process_vm_readv,ptrace,remap_file_pages,request_key,setdomainname,sethostname,syslog,umount,umount2,userfaultfd,vhangup,vmsplice
41shell none 44shell none
45# tracelog may cause issues, see github issue #1930
42tracelog 46tracelog
43 47
44disable-mnt 48disable-mnt