From 0ec8ec63375efaf87a5f8af48c83eac560dacd20 Mon Sep 17 00:00:00 2001 From: netblue30 Date: Thu, 21 Sep 2017 08:15:19 -0400 Subject: added ffmpeg.profile, removed ssh-agent from firecfg --- README.md | 2 +- etc/ffmpeg.profile | 33 +++++++++++++++++++++++++++++++++ platform/debian/conffiles | 1 + src/firecfg/firecfg.config | 3 ++- 4 files changed, 37 insertions(+), 2 deletions(-) create mode 100644 etc/ffmpeg.profile diff --git a/README.md b/README.md index c9e04ee3c..26f3dc3c5 100644 --- a/README.md +++ b/README.md @@ -180,4 +180,4 @@ calligraflow, calligraplan, calligraplanwork, calligrasheets, calligrastage, calligrawords, cin, dooble, dooble-qt4, fetchmail, freecad, freecadcmd, google-earth, imagej, karbon, kdenlive, krita, linphone, lmms, macrofusion, mpd, natron, Natron, ricochet, shotcut, teamspeak3, tor, tor-browser-en, Viber, x-terminal-emulator, zart, -conky, arch-audit +conky, arch-audit, ffmpeg diff --git a/etc/ffmpeg.profile b/etc/ffmpeg.profile new file mode 100644 index 000000000..e098c95e3 --- /dev/null +++ b/etc/ffmpeg.profile @@ -0,0 +1,33 @@ +# Firejail profile for default +# This file is overwritten after every install/update +quiet +# Persistent local customizations +include /etc/firejail/ffmpeg.local +# Persistent global definitions +include /etc/firejail/globals.local + +include /etc/firejail/disable-common.inc +include /etc/firejail/disable-devel.inc +include /etc/firejail/disable-passwdmgr.inc +include /etc/firejail/disable-programs.inc + +caps.drop all +net none +no3d +nodvd +nosound +notv +novideo +nonewprivs +noroot +# protocol none - needs to be implemented! +seccomp +# seccomp.keep futex,write,read,munmap,fstat,mprotect,mmap,open,close,stat,lseek,brk,rt_sigaction,rt_sigprocmask,ioctl,access,select,madvise,getpid,clone,execve,fcntl,getdents,readlink,getrlimit,getrusage,statfs,getpriority,setpriority,arch_prctl,sched_getaffinity,set_tid_address,set_robust_list,getrandom +# memory-deny-write-execute - it breaks old versions of ffmpeg +shell none +tracelog + +private-tmp +private-dev +private-bin ffmpeg +include /etc/firejail/whitelist-var-common.inc diff --git a/platform/debian/conffiles b/platform/debian/conffiles index af6547f7f..27623aee3 100644 --- a/platform/debian/conffiles +++ b/platform/debian/conffiles @@ -358,3 +358,4 @@ /etc/firejail/yandex-browser.profile /etc/firejail/itch.profile /etc/firejail/whitelist-var-common.inc +/etc/firejail/ffmpeg diff --git a/src/firecfg/firecfg.config b/src/firecfg/firecfg.config index e4e3e4972..5a36f5e3e 100644 --- a/src/firecfg/firecfg.config +++ b/src/firecfg/firecfg.config @@ -99,6 +99,7 @@ evolution exiftool fbreader feh +ffmpeg file-roller filezilla firefox @@ -292,7 +293,7 @@ soundconverter spotify sqlitebrowser ssh -ssh-agent +# ssh-agent - problems on Arch with Fish shell (#1568) start-tor-browser steam stellarium -- cgit v1.2.3-54-g00ecf