From ce2b96e2e3bdae0e664fa967171e75fd8fda340b Mon Sep 17 00:00:00 2001 From: smitsohu Date: Tue, 1 May 2018 21:23:35 +0200 Subject: cleanup cin profile: 'protocol unix' implies nonewprivs --- etc/cin.profile | 2 +- etc/natron.profile | 2 +- etc/vlc.profile | 6 +++--- 3 files changed, 5 insertions(+), 5 deletions(-) diff --git a/etc/cin.profile b/etc/cin.profile index 356509da0..e2410e3a5 100644 --- a/etc/cin.profile +++ b/etc/cin.profile @@ -19,7 +19,7 @@ net none nodbus nodvd #nogroups -#nonewprivs +nonewprivs notv noroot protocol unix diff --git a/etc/natron.profile b/etc/natron.profile index e7c597fe2..76e909f83 100644 --- a/etc/natron.profile +++ b/etc/natron.profile @@ -18,7 +18,7 @@ noblacklist /opt/natron include /etc/firejail/disable-common.inc include /etc/firejail/disable-devel.inc -#include /etc/firejail/disable-interpreters.inc +include /etc/firejail/disable-interpreters.inc include /etc/firejail/disable-passwdmgr.inc include /etc/firejail/disable-programs.inc diff --git a/etc/vlc.profile b/etc/vlc.profile index 9ccbb7310..bda027aaa 100644 --- a/etc/vlc.profile +++ b/etc/vlc.profile @@ -20,8 +20,8 @@ include /etc/firejail/whitelist-var-common.inc #apparmor - on Ubuntu 18.04 it refuses to start without dbus access caps.drop all netfilter -# nodbus - problems with KDE -# nogroups +#nodbus +#nogroups nonewprivs noroot protocol unix,inet,inet6,netlink @@ -33,6 +33,6 @@ private-dev private-tmp # mdwe is disabled due to breaking hardware accelerated decoding -# memory-deny-write-execute +#memory-deny-write-execute noexec ${HOME} noexec /tmp -- cgit v1.2.3-70-g09d2