From 0ec8ec63375efaf87a5f8af48c83eac560dacd20 Mon Sep 17 00:00:00 2001 From: netblue30 Date: Thu, 21 Sep 2017 08:15:19 -0400 Subject: added ffmpeg.profile, removed ssh-agent from firecfg --- etc/ffmpeg.profile | 33 +++++++++++++++++++++++++++++++++ 1 file changed, 33 insertions(+) create mode 100644 etc/ffmpeg.profile (limited to 'etc/ffmpeg.profile') diff --git a/etc/ffmpeg.profile b/etc/ffmpeg.profile new file mode 100644 index 000000000..e098c95e3 --- /dev/null +++ b/etc/ffmpeg.profile @@ -0,0 +1,33 @@ +# Firejail profile for default +# This file is overwritten after every install/update +quiet +# Persistent local customizations +include /etc/firejail/ffmpeg.local +# Persistent global definitions +include /etc/firejail/globals.local + +include /etc/firejail/disable-common.inc +include /etc/firejail/disable-devel.inc +include /etc/firejail/disable-passwdmgr.inc +include /etc/firejail/disable-programs.inc + +caps.drop all +net none +no3d +nodvd +nosound +notv +novideo +nonewprivs +noroot +# protocol none - needs to be implemented! +seccomp +# seccomp.keep futex,write,read,munmap,fstat,mprotect,mmap,open,close,stat,lseek,brk,rt_sigaction,rt_sigprocmask,ioctl,access,select,madvise,getpid,clone,execve,fcntl,getdents,readlink,getrlimit,getrusage,statfs,getpriority,setpriority,arch_prctl,sched_getaffinity,set_tid_address,set_robust_list,getrandom +# memory-deny-write-execute - it breaks old versions of ffmpeg +shell none +tracelog + +private-tmp +private-dev +private-bin ffmpeg +include /etc/firejail/whitelist-var-common.inc -- cgit v1.2.3-54-g00ecf