From 36d3043762c69150de5adae754ff5c68431af36c Mon Sep 17 00:00:00 2001 From: Fred-Barclay Date: Tue, 28 Nov 2017 20:39:14 -0600 Subject: (Re)add disable-mnt to common browser profiles. --- etc/brave.profile | 2 +- etc/chromium.profile | 1 + etc/conkeror.profile | 2 ++ etc/cyberfox.profile | 3 ++- etc/flashpeak-slimjet.profile | 2 ++ etc/google-chrome.profile | 1 + etc/icecat.profile | 1 + etc/midori.profile | 2 ++ etc/netsurf.profile | 2 ++ etc/opera-beta.profile | 2 ++ etc/opera.profile | 2 ++ etc/palemoon.profile | 2 ++ etc/seamonkey.profile | 1 + etc/start-tor-browser.profile | 1 + etc/torbrowser-launcher.profile | 1 + etc/vivaldi.profile | 1 + etc/yandex-browser.profile | 1 + 17 files changed, 25 insertions(+), 2 deletions(-) diff --git a/etc/brave.profile b/etc/brave.profile index 476d1575a..668e8a244 100644 --- a/etc/brave.profile +++ b/etc/brave.profile @@ -35,4 +35,4 @@ notv # protocol unix,inet,inet6,netlink # seccomp -# disable-mnt +disable-mnt diff --git a/etc/chromium.profile b/etc/chromium.profile index 281d8bf76..64d790121 100644 --- a/etc/chromium.profile +++ b/etc/chromium.profile @@ -32,6 +32,7 @@ nogroups notv shell none +disable-mnt # private-bin chromium,chromium-browser,chromedriver private-dev # private-tmp - problems with multiple browser sessions diff --git a/etc/conkeror.profile b/etc/conkeror.profile index 38c4fdd68..2489e2df4 100644 --- a/etc/conkeror.profile +++ b/etc/conkeror.profile @@ -31,3 +31,5 @@ noroot notv protocol unix,inet,inet6 seccomp + +disable-mnt diff --git a/etc/cyberfox.profile b/etc/cyberfox.profile index a670f6aa3..66cd27461 100644 --- a/etc/cyberfox.profile +++ b/etc/cyberfox.profile @@ -62,9 +62,10 @@ seccomp shell none tracelog +disable-mnt # private-bin cyberfox,which,sh,dbus-launch,dbus-send,env private-dev -# private-dev might prevent video calls going out +private-dev # private-etc passwd,group,hostname,hosts,localtime,nsswitch.conf,resolv.conf,xdg,gtk-2.0,gtk-3.0,X11,pango,fonts,cyberfox,mime.types,mailcap,asound.conf,pulse private-tmp diff --git a/etc/flashpeak-slimjet.profile b/etc/flashpeak-slimjet.profile index feb4087f4..d9be8b9c5 100644 --- a/etc/flashpeak-slimjet.profile +++ b/etc/flashpeak-slimjet.profile @@ -35,3 +35,5 @@ noroot notv protocol unix,inet,inet6,netlink seccomp + +disable-mnt diff --git a/etc/google-chrome.profile b/etc/google-chrome.profile index 2e9524e16..19ebfa974 100644 --- a/etc/google-chrome.profile +++ b/etc/google-chrome.profile @@ -30,6 +30,7 @@ nogroups notv shell none +disable-mnt private-dev # private-tmp - problems with multiple browser sessions diff --git a/etc/icecat.profile b/etc/icecat.profile index 74c51926a..9e5526c95 100644 --- a/etc/icecat.profile +++ b/etc/icecat.profile @@ -45,6 +45,7 @@ protocol unix,inet,inet6,netlink seccomp tracelog +disable-mnt # private-etc passwd,group,hostname,hosts,localtime,nsswitch.conf,resolv.conf,gtk-2.0,pango,fonts,iceweasel,firefox,adobe,mime.types,mailcap,asound.conf,pulse noexec ${HOME} diff --git a/etc/midori.profile b/etc/midori.profile index 7cb5326fb..831f68864 100644 --- a/etc/midori.profile +++ b/etc/midori.profile @@ -42,3 +42,5 @@ notv protocol unix,inet,inet6,netlink seccomp tracelog + +disable-mnt diff --git a/etc/netsurf.profile b/etc/netsurf.profile index 02b35757a..6e8f02328 100644 --- a/etc/netsurf.profile +++ b/etc/netsurf.profile @@ -28,3 +28,5 @@ notv protocol unix,inet,inet6,netlink seccomp tracelog + +disable-mnt diff --git a/etc/opera-beta.profile b/etc/opera-beta.profile index 6079ac7d5..3fe86d26c 100644 --- a/etc/opera-beta.profile +++ b/etc/opera-beta.profile @@ -24,3 +24,5 @@ include /etc/firejail/whitelist-common.inc netfilter nodvd notv + +disable-mnt diff --git a/etc/opera.profile b/etc/opera.profile index 2b9b903ac..fed7564b2 100644 --- a/etc/opera.profile +++ b/etc/opera.profile @@ -28,3 +28,5 @@ include /etc/firejail/whitelist-common.inc netfilter nodvd notv + +disable-mnt diff --git a/etc/palemoon.profile b/etc/palemoon.profile index 8bdcb7334..1112a9bb7 100644 --- a/etc/palemoon.profile +++ b/etc/palemoon.profile @@ -56,3 +56,5 @@ tracelog # private-etc passwd,group,hostname,hosts,localtime,nsswitch.conf,resolv.conf,gtk-2.0,pango,fonts,iceweasel,firefox,adobe,mime.types,mailcap,asound.conf,pulse # private-opt palemoon private-tmp + +disable-mnt diff --git a/etc/seamonkey.profile b/etc/seamonkey.profile index cfd03300a..23072fc0f 100644 --- a/etc/seamonkey.profile +++ b/etc/seamonkey.profile @@ -45,4 +45,5 @@ protocol unix,inet,inet6,netlink seccomp tracelog +disable-mnt # private-etc passwd,group,hostname,hosts,localtime,nsswitch.conf,resolv.conf,gtk-2.0,pango,fonts,iceweasel,firefox,adobe,mime.types,mailcap,asound.conf,pulse diff --git a/etc/start-tor-browser.profile b/etc/start-tor-browser.profile index 57a5c20e3..a2bf47281 100644 --- a/etc/start-tor-browser.profile +++ b/etc/start-tor-browser.profile @@ -24,6 +24,7 @@ seccomp shell none tracelog +disable-mnt private-bin bash,sh,grep,tail,env,gpg,id,readlink,dirname,test,mkdir,ln,sed,cp,rm,getconf private-dev private-etc fonts diff --git a/etc/torbrowser-launcher.profile b/etc/torbrowser-launcher.profile index c2e182cea..81938ca57 100644 --- a/etc/torbrowser-launcher.profile +++ b/etc/torbrowser-launcher.profile @@ -32,6 +32,7 @@ seccomp shell none tracelog +disable-mnt private-bin bash,cp,dirname,env,expr,file,getconf,gpg,grep,id,ln,mkdir,python*,readlink,rm,sed,sh,tail,test,tor-browser-en,torbrowser-launcher private-dev private-etc fonts diff --git a/etc/vivaldi.profile b/etc/vivaldi.profile index 039c8ed58..3a1f72f23 100644 --- a/etc/vivaldi.profile +++ b/etc/vivaldi.profile @@ -27,6 +27,7 @@ nogroups notv shell none +disable-mnt private-dev # private-tmp - problems with multiple browser sessions diff --git a/etc/yandex-browser.profile b/etc/yandex-browser.profile index 605ce3413..1c7769727 100644 --- a/etc/yandex-browser.profile +++ b/etc/yandex-browser.profile @@ -35,6 +35,7 @@ nogroups notv shell none +disable-mnt private-dev # private-tmp - problems with multiple browser sessions -- cgit v1.2.3-54-g00ecf From 59166a33cb8856123e5e31a01d330fc17c0d1764 Mon Sep 17 00:00:00 2001 From: soredake Date: Wed, 29 Nov 2017 13:36:01 +0200 Subject: qtox needs libstdc++.so.6 --- etc/qtox.profile | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/etc/qtox.profile b/etc/qtox.profile index 4d5a7cf59..a8d980a18 100644 --- a/etc/qtox.profile +++ b/etc/qtox.profile @@ -33,7 +33,7 @@ tracelog disable-mnt private-bin qtox -private-etc fonts,resolv.conf +private-etc fonts,resolv.conf,ld.so.cache private-dev private-tmp -- cgit v1.2.3-54-g00ecf From 288d9a8492195e9d6b57a9958d06d9b11fa9e6eb Mon Sep 17 00:00:00 2001 From: Fred-Barclay Date: Wed, 29 Nov 2017 13:25:19 -0600 Subject: Add disable-mnt to surf profile --- etc/surf.profile | 1 + 1 file changed, 1 insertion(+) diff --git a/etc/surf.profile b/etc/surf.profile index 6f7bd16f6..7dcbc280e 100644 --- a/etc/surf.profile +++ b/etc/surf.profile @@ -26,6 +26,7 @@ seccomp shell none tracelog +disable-mnt private-bin ls,surf,sh,bash,curl,dmenu,printf,sed,sleep,st,stterm,xargs,xprop private-dev private-etc passwd,group,hosts,resolv.conf,fonts,ssl -- cgit v1.2.3-54-g00ecf