From 4a1d906e89c0d0f8ebe6dce16b8b7c05f2c6084f Mon Sep 17 00:00:00 2001 From: netblue30 Date: Fri, 20 Jan 2017 09:20:11 -0500 Subject: profile merges --- etc/disable-common.inc | 5 +---- etc/vlc.profile | 2 +- etc/xmms.profile | 11 +++++++++++ 3 files changed, 13 insertions(+), 5 deletions(-) create mode 100644 etc/xmms.profile (limited to 'etc') diff --git a/etc/disable-common.inc b/etc/disable-common.inc index 6a3586e81..de8a9bfe7 100644 --- a/etc/disable-common.inc +++ b/etc/disable-common.inc @@ -75,12 +75,9 @@ blacklist /etc/profile.d blacklist /etc/rc.local blacklist /etc/anacrontab -# General startup files +# Startup files read-only ${HOME}/.xinitrc read-only ${HOME}/.xserverrc -read-only ${HOME}/.profile - -# Shell startup files read-only ${HOME}/.antigen read-only ${HOME}/.bash_login read-only ${HOME}/.bashrc diff --git a/etc/vlc.profile b/etc/vlc.profile index 2fd763f25..df9fcab03 100644 --- a/etc/vlc.profile +++ b/etc/vlc.profile @@ -8,7 +8,7 @@ include /etc/firejail/disable-passwdmgr.inc caps.drop all netfilter -nogroups +# nogroups nonewprivs noroot protocol unix,inet,inet6,netlink diff --git a/etc/xmms.profile b/etc/xmms.profile new file mode 100644 index 000000000..4a482f49e --- /dev/null +++ b/etc/xmms.profile @@ -0,0 +1,11 @@ +# xmms media player profile +include /etc/firejail/disable-common.inc +include /etc/firejail/disable-programs.inc +include /etc/firejail/disable-devel.inc +include /etc/firejail/disable-passwdmgr.inc + +caps.drop all +nonewprivs +noroot +protocol unix,inet,inet6 +seccomp -- cgit v1.2.3-70-g09d2