From b7e4f402f4102b105ac428fe0b2f615431388477 Mon Sep 17 00:00:00 2001 From: netblue30 Date: Mon, 16 Mar 2020 15:55:52 -0400 Subject: profile fixes --- etc/2048-qt.profile | 2 ++ etc/calibre.profile | 1 + etc/dia.profile | 2 ++ etc/handbrake.profile | 1 + etc/mate-calc.profile | 1 + etc/midori.profile | 1 + etc/mplayer.profile | 2 ++ etc/musescore.profile | 1 + etc/qpdfview.profile | 1 + etc/scribus.profile | 1 + etc/sol.profile | 1 + etc/tcpdump.profile | 1 + etc/warzone2100.profile | 1 + etc/xpdf.profile | 3 ++- 14 files changed, 18 insertions(+), 1 deletion(-) diff --git a/etc/2048-qt.profile b/etc/2048-qt.profile index 2347039a6..95d482c22 100644 --- a/etc/2048-qt.profile +++ b/etc/2048-qt.profile @@ -23,7 +23,9 @@ whitelist ${HOME}/.config/xiaoyong include whitelist-common.inc include whitelist-var-common.inc +apparmor caps.drop all +net none netfilter nodvd nogroups diff --git a/etc/calibre.profile b/etc/calibre.profile index ad6f0aa0d..d17cfa85f 100644 --- a/etc/calibre.profile +++ b/etc/calibre.profile @@ -19,6 +19,7 @@ include disable-xdg.inc include whitelist-var-common.inc +apparmor caps.drop all netfilter nodvd diff --git a/etc/dia.profile b/etc/dia.profile index bd79797b7..0bfc249fa 100644 --- a/etc/dia.profile +++ b/etc/dia.profile @@ -18,7 +18,9 @@ include disable-interpreters.inc include disable-passwdmgr.inc include disable-programs.inc include disable-xdg.inc +include whitelist-var-common.inc +apparmor caps.drop all net none no3d diff --git a/etc/handbrake.profile b/etc/handbrake.profile index 324c629e3..5b51bd03c 100644 --- a/etc/handbrake.profile +++ b/etc/handbrake.profile @@ -22,6 +22,7 @@ include whitelist-var-common.inc apparmor caps.drop all +net none netfilter nodbus nogroups diff --git a/etc/mate-calc.profile b/etc/mate-calc.profile index 966aa0a13..8bd62ae0b 100644 --- a/etc/mate-calc.profile +++ b/etc/mate-calc.profile @@ -22,6 +22,7 @@ whitelist ${HOME}/.cache/mate-calc whitelist ${HOME}/.config/caja whitelist ${HOME}/.config/mate-menu include whitelist-common.inc +include whitelist-var-common.inc apparmor caps.drop all diff --git a/etc/midori.profile b/etc/midori.profile index 648ce7738..e15259608 100644 --- a/etc/midori.profile +++ b/etc/midori.profile @@ -48,6 +48,7 @@ whitelist ${HOME}/.local/share/webkitgtk whitelist ${HOME}/.pki whitelist ${HOME}/.local/share/pki include whitelist-common.inc +include whitelist-var-common.inc apparmor caps.drop all diff --git a/etc/mplayer.profile b/etc/mplayer.profile index 9ab4f8c7f..82877d9d4 100644 --- a/etc/mplayer.profile +++ b/etc/mplayer.profile @@ -21,7 +21,9 @@ include disable-xdg.inc include whitelist-usr-share-common.inc include whitelist-var-common.inc +apparmor caps.drop all +net none netfilter # nogroups nonewprivs diff --git a/etc/musescore.profile b/etc/musescore.profile index b3693c956..679e82ae8 100644 --- a/etc/musescore.profile +++ b/etc/musescore.profile @@ -23,6 +23,7 @@ include disable-xdg.inc include whitelist-var-common.inc +apparmor caps.drop all netfilter no3d diff --git a/etc/qpdfview.profile b/etc/qpdfview.profile index 863f57ba4..dace1634f 100644 --- a/etc/qpdfview.profile +++ b/etc/qpdfview.profile @@ -20,6 +20,7 @@ include disable-xdg.inc include whitelist-var-common.inc +apparmor caps.drop all machine-id # needs D-Bus when started from a file manager diff --git a/etc/scribus.profile b/etc/scribus.profile index e20cd1b5a..e7faccea1 100644 --- a/etc/scribus.profile +++ b/etc/scribus.profile @@ -40,6 +40,7 @@ include disable-xdg.inc include whitelist-var-common.inc +apparmor caps.drop all net none nodbus diff --git a/etc/sol.profile b/etc/sol.profile index ea1620b31..4c8fdfbb1 100644 --- a/etc/sol.profile +++ b/etc/sol.profile @@ -17,6 +17,7 @@ include disable-xdg.inc include whitelist-common.inc include whitelist-var-common.inc +apparmor caps.drop all ipc-namespace net none diff --git a/etc/tcpdump.profile b/etc/tcpdump.profile index 3c46dfdcb..881fbf49e 100644 --- a/etc/tcpdump.profile +++ b/etc/tcpdump.profile @@ -19,6 +19,7 @@ include disable-xdg.inc include whitelist-common.inc +apparmor caps.keep net_raw ipc-namespace #net tun0 diff --git a/etc/warzone2100.profile b/etc/warzone2100.profile index e65e0a0c3..e33cace49 100644 --- a/etc/warzone2100.profile +++ b/etc/warzone2100.profile @@ -22,6 +22,7 @@ whitelist ${HOME}/.warzone2100-3.2 include whitelist-common.inc include whitelist-var-common.inc +apparmor caps.drop all netfilter nodvd diff --git a/etc/xpdf.profile b/etc/xpdf.profile index 8c405ba1d..cb7ac4a59 100644 --- a/etc/xpdf.profile +++ b/etc/xpdf.profile @@ -19,6 +19,7 @@ include disable-xdg.inc include whitelist-var-common.inc +apparmor caps.drop all machine-id net none @@ -38,4 +39,4 @@ shell none private-dev private-tmp - +memory-deny-write-execute -- cgit v1.2.3-54-g00ecf