mirror of
https://github.com/netblue30/firejail.git
synced 2026-05-21 06:45:29 -06:00
Move apparmor option to the top of the options list in all profiles
This commit is contained in:
parent
82f5c2175e
commit
68fd00cfe4
31 changed files with 31 additions and 32 deletions
|
|
@ -16,6 +16,7 @@ include /etc/firejail/disable-programs.inc
|
|||
|
||||
include /etc/firejail/whitelist-var-common.inc
|
||||
|
||||
apparmor
|
||||
caps.drop all
|
||||
# net none
|
||||
netfilter
|
||||
|
|
@ -29,7 +30,6 @@ novideo
|
|||
protocol unix
|
||||
seccomp
|
||||
shell none
|
||||
apparmor
|
||||
|
||||
private-dev
|
||||
private-tmp
|
||||
|
|
|
|||
|
|
@ -17,6 +17,7 @@ include /etc/firejail/disable-programs.inc
|
|||
|
||||
include /etc/firejail/whitelist-var-common.inc
|
||||
|
||||
apparmor
|
||||
caps.drop all
|
||||
machine-id
|
||||
no3d
|
||||
|
|
@ -31,7 +32,6 @@ protocol unix
|
|||
seccomp
|
||||
shell none
|
||||
tracelog
|
||||
apparmor
|
||||
|
||||
private-bin atril, atril-previewer, atril-thumbnailer
|
||||
private-dev
|
||||
|
|
|
|||
|
|
@ -15,6 +15,7 @@ include /etc/firejail/disable-programs.inc
|
|||
|
||||
include /etc/firejail/whitelist-var-common.inc
|
||||
|
||||
apparmor
|
||||
caps.drop all
|
||||
netfilter
|
||||
nogroups
|
||||
|
|
@ -26,7 +27,6 @@ protocol unix,inet,inet6
|
|||
seccomp
|
||||
shell none
|
||||
tracelog
|
||||
apparmor
|
||||
|
||||
# private-bin audacious
|
||||
private-dev
|
||||
|
|
|
|||
|
|
@ -16,6 +16,7 @@ include /etc/firejail/disable-programs.inc
|
|||
|
||||
include /etc/firejail/whitelist-var-common.inc
|
||||
|
||||
apparmor
|
||||
caps.drop all
|
||||
#net none
|
||||
no3d
|
||||
|
|
@ -29,7 +30,6 @@ protocol unix
|
|||
seccomp
|
||||
shell none
|
||||
tracelog
|
||||
apparmor
|
||||
|
||||
private-bin audacity
|
||||
private-dev
|
||||
|
|
|
|||
|
|
@ -17,13 +17,13 @@ whitelist ${HOME}/.pki
|
|||
include /etc/firejail/whitelist-common.inc
|
||||
include /etc/firejail/whitelist-var-common.inc
|
||||
|
||||
apparmor
|
||||
caps.keep sys_chroot,sys_admin
|
||||
netfilter
|
||||
nodvd
|
||||
nogroups
|
||||
notv
|
||||
shell none
|
||||
apparmor
|
||||
|
||||
disable-mnt
|
||||
private-dev
|
||||
|
|
|
|||
|
|
@ -17,6 +17,7 @@ include /etc/firejail/disable-programs.inc
|
|||
|
||||
include /etc/firejail/whitelist-var-common.inc
|
||||
|
||||
apparmor
|
||||
caps.drop all
|
||||
netfilter
|
||||
nodvd
|
||||
|
|
@ -28,7 +29,6 @@ protocol unix,inet,inet6,netlink
|
|||
seccomp
|
||||
# seccomp.keep fallocate,getrusage,openat,access,arch_prctl,bind,brk,chdir,chmod,clock_getres,clone,close,connect,dup2,dup3,eventfd2,execve,fadvise64,fcntl,fdatasync,flock,fstat,fstatfs,ftruncate,futex,getcwd,getdents,getegid,geteuid,getgid,getpeername,getpgrp,getpid,getppid,getrandom,getresgid,getresuid,getrlimit,getsockname,getsockopt,gettid,getuid,inotify_add_watch,inotify_init,inotify_init1,inotify_rm_watch,ioctl,lseek,lstat,madvise,mbind,memfd_create,mkdir,mmap,mprotect,msync,munmap,nanosleep,open,pipe,pipe2,poll,ppoll,prctl,pread64,pwrite64,read,readlink,readlinkat,recvfrom,recvmsg,rename,rt_sigaction,rt_sigprocmask,rt_sigreturn,sched_getaffinity,sched_getparam,sched_get_priority_max,sched_get_priority_min,sched_getscheduler,sched_setscheduler,sched_yield,sendmsg,sendto,setgid,setresgid,setresuid,set_robust_list,setsid,setsockopt,set_tid_address,setuid,shmat,shmctl,shmdt,shmget,shutdown,socket,stat,statfs,sysinfo,timerfd_create,umask,uname,unlink,wait4,waitid,write,writev,fchmod,fchown,unshare,exit,exit_group
|
||||
shell none
|
||||
apparmor
|
||||
|
||||
# private-bin program
|
||||
# private-dev - prevents libdc1394 loading; this lib is used to connect to a camera device
|
||||
|
|
|
|||
|
|
@ -11,6 +11,7 @@ include /etc/firejail/disable-programs.inc
|
|||
|
||||
whitelist ${DOWNLOADS}
|
||||
|
||||
apparmor
|
||||
caps.drop all
|
||||
netfilter
|
||||
nodvd
|
||||
|
|
@ -20,4 +21,3 @@ noroot
|
|||
notv
|
||||
protocol unix,inet,inet6,netlink
|
||||
seccomp
|
||||
apparmor
|
||||
|
|
|
|||
|
|
@ -19,6 +19,7 @@ include /etc/firejail/disable-programs.inc
|
|||
|
||||
include /etc/firejail/whitelist-var-common.inc
|
||||
|
||||
apparmor
|
||||
caps.drop all
|
||||
# net none - makes settings immutable
|
||||
no3d
|
||||
|
|
@ -32,7 +33,6 @@ novideo
|
|||
protocol unix
|
||||
seccomp
|
||||
shell none
|
||||
apparmor
|
||||
|
||||
private-bin eog
|
||||
private-dev
|
||||
|
|
|
|||
|
|
@ -19,6 +19,7 @@ include /etc/firejail/disable-programs.inc
|
|||
|
||||
include /etc/firejail/whitelist-var-common.inc
|
||||
|
||||
apparmor
|
||||
caps.drop all
|
||||
# net none - makes settings immutable
|
||||
no3d
|
||||
|
|
@ -33,7 +34,6 @@ protocol unix
|
|||
seccomp
|
||||
shell none
|
||||
tracelog
|
||||
apparmor
|
||||
|
||||
private-bin eom
|
||||
private-dev
|
||||
|
|
|
|||
|
|
@ -20,6 +20,7 @@ whitelist ${HOME}/.pki
|
|||
include /etc/firejail/whitelist-common.inc
|
||||
include /etc/firejail/whitelist-var-common.inc
|
||||
|
||||
apparmor
|
||||
caps.drop all
|
||||
# machine-id breaks pulse audio; it should work fine in setups where sound is not required
|
||||
#machine-id
|
||||
|
|
@ -33,7 +34,6 @@ protocol unix,inet,inet6,netlink
|
|||
seccomp
|
||||
shell none
|
||||
tracelog
|
||||
apparmor
|
||||
|
||||
disable-mnt
|
||||
private-dev
|
||||
|
|
|
|||
|
|
@ -19,6 +19,7 @@ whitelist ${HOME}/.config/galculator
|
|||
include /etc/firejail/whitelist-common.inc
|
||||
include /etc/firejail/whitelist-var-common.inc
|
||||
|
||||
apparmor
|
||||
caps.drop all
|
||||
net none
|
||||
nodvd
|
||||
|
|
@ -32,7 +33,6 @@ protocol unix
|
|||
seccomp
|
||||
shell none
|
||||
tracelog
|
||||
apparmor
|
||||
|
||||
private-bin galculator
|
||||
private-dev
|
||||
|
|
|
|||
|
|
@ -15,6 +15,7 @@ include /etc/firejail/disable-programs.inc
|
|||
|
||||
include /etc/firejail/whitelist-var-common.inc
|
||||
|
||||
apparmor
|
||||
caps.drop all
|
||||
net none
|
||||
nodvd
|
||||
|
|
@ -26,7 +27,6 @@ notv
|
|||
protocol unix
|
||||
seccomp
|
||||
shell none
|
||||
apparmor
|
||||
|
||||
private-dev
|
||||
private-tmp
|
||||
|
|
|
|||
|
|
@ -14,6 +14,7 @@ include /etc/firejail/disable-programs.inc
|
|||
include /etc/firejail/whitelist-common.inc
|
||||
include /etc/firejail/whitelist-var-common.inc
|
||||
|
||||
apparmor
|
||||
caps.drop all
|
||||
netfilter
|
||||
no3d
|
||||
|
|
@ -27,7 +28,6 @@ novideo
|
|||
protocol unix,inet,inet6
|
||||
seccomp
|
||||
shell none
|
||||
apparmor
|
||||
|
||||
disable-mnt
|
||||
private-bin gnome-calculator
|
||||
|
|
|
|||
|
|
@ -14,6 +14,7 @@ include /etc/firejail/disable-programs.inc
|
|||
|
||||
include /etc/firejail/whitelist-var-common.inc
|
||||
|
||||
apparmor
|
||||
caps.drop all
|
||||
netfilter
|
||||
nogroups
|
||||
|
|
@ -23,7 +24,6 @@ novideo
|
|||
protocol unix,inet,inet6,netlink
|
||||
seccomp
|
||||
shell none
|
||||
apparmor
|
||||
|
||||
private-dev
|
||||
private-tmp
|
||||
|
|
|
|||
|
|
@ -16,6 +16,7 @@ include /etc/firejail/disable-programs.inc
|
|||
|
||||
include /etc/firejail/whitelist-var-common.inc
|
||||
|
||||
apparmor
|
||||
caps.drop all
|
||||
netfilter
|
||||
nodvd
|
||||
|
|
@ -28,7 +29,6 @@ novideo
|
|||
protocol unix
|
||||
seccomp
|
||||
shell none
|
||||
apparmor
|
||||
|
||||
# private-bin inkscape,potrace - problems on Debian stretch
|
||||
private-dev
|
||||
|
|
|
|||
|
|
@ -21,6 +21,7 @@ include /etc/firejail/disable-programs.inc
|
|||
|
||||
include /etc/firejail/whitelist-var-common.inc
|
||||
|
||||
apparmor
|
||||
caps.drop all
|
||||
# net none
|
||||
netfilter
|
||||
|
|
@ -35,7 +36,6 @@ protocol unix
|
|||
seccomp
|
||||
shell none
|
||||
tracelog
|
||||
apparmor
|
||||
|
||||
# private-bin kate
|
||||
private-dev
|
||||
|
|
|
|||
|
|
@ -15,6 +15,7 @@ include /etc/firejail/disable-devel.inc
|
|||
include /etc/firejail/disable-passwdmgr.inc
|
||||
include /etc/firejail/disable-programs.inc
|
||||
|
||||
apparmor
|
||||
caps.drop all
|
||||
# net none
|
||||
nodvd
|
||||
|
|
@ -25,7 +26,6 @@ notv
|
|||
protocol unix,netlink
|
||||
seccomp
|
||||
shell none
|
||||
apparmor
|
||||
|
||||
private-bin kdenlive,kdenlive_render,dbus-launch,melt,ffmpeg,ffplay,ffprobe,dvdauthor,genisoimage,vlc,xine,kdeinit5,kshell5,kdeinit5_shutdown,kdeinit5_wrapper,kdeinit4,kshell4,kdeinit4_shutdown,kdeinit4_wrapper
|
||||
private-dev
|
||||
|
|
|
|||
|
|
@ -12,6 +12,7 @@ include /etc/firejail/disable-devel.inc
|
|||
include /etc/firejail/disable-passwdmgr.inc
|
||||
include /etc/firejail/disable-programs.inc
|
||||
|
||||
apparmor
|
||||
caps.drop all
|
||||
netfilter
|
||||
nogroups
|
||||
|
|
@ -21,7 +22,6 @@ protocol unix,inet,inet6,netlink
|
|||
seccomp
|
||||
shell none
|
||||
tracelog
|
||||
apparmor
|
||||
|
||||
private-dev
|
||||
private-tmp
|
||||
|
|
|
|||
|
|
@ -14,6 +14,7 @@ include /etc/firejail/disable-devel.inc
|
|||
include /etc/firejail/disable-passwdmgr.inc
|
||||
include /etc/firejail/disable-programs.inc
|
||||
|
||||
apparmor
|
||||
caps.drop all
|
||||
ipc-namespace
|
||||
# net none
|
||||
|
|
@ -27,7 +28,6 @@ novideo
|
|||
protocol unix
|
||||
seccomp
|
||||
shell none
|
||||
apparmor
|
||||
|
||||
private-dev
|
||||
private-tmp
|
||||
|
|
|
|||
|
|
@ -22,6 +22,7 @@ include /etc/firejail/disable-programs.inc
|
|||
|
||||
include /etc/firejail/whitelist-var-common.inc
|
||||
|
||||
apparmor
|
||||
caps.drop all
|
||||
# net none
|
||||
netfilter
|
||||
|
|
@ -36,7 +37,6 @@ protocol unix
|
|||
seccomp
|
||||
shell none
|
||||
tracelog
|
||||
apparmor
|
||||
|
||||
private-bin kwrite,kbuildsycoca4,kdeinit4
|
||||
private-dev
|
||||
|
|
|
|||
|
|
@ -16,6 +16,7 @@ include /etc/firejail/disable-programs.inc
|
|||
|
||||
include /etc/firejail/whitelist-var-common.inc
|
||||
|
||||
apparmor
|
||||
caps.drop all
|
||||
machine-id
|
||||
netfilter
|
||||
|
|
@ -28,7 +29,6 @@ protocol unix,inet,inet6
|
|||
seccomp
|
||||
shell none
|
||||
tracelog
|
||||
apparmor
|
||||
|
||||
private-dev
|
||||
private-tmp
|
||||
|
|
|
|||
|
|
@ -15,6 +15,7 @@ include /etc/firejail/disable-programs.inc
|
|||
|
||||
include /etc/firejail/whitelist-var-common.inc
|
||||
|
||||
apparmor
|
||||
caps.drop all
|
||||
netfilter
|
||||
nogroups
|
||||
|
|
@ -24,7 +25,6 @@ protocol unix,inet,inet6
|
|||
seccomp
|
||||
shell none
|
||||
tracelog
|
||||
apparmor
|
||||
|
||||
private-bin mpv,youtube-dl,python*,env
|
||||
private-dev
|
||||
|
|
|
|||
|
|
@ -25,6 +25,7 @@ include /etc/firejail/disable-programs.inc
|
|||
|
||||
include /etc/firejail/whitelist-var-common.inc
|
||||
|
||||
apparmor
|
||||
caps.drop all
|
||||
machine-id
|
||||
# net none
|
||||
|
|
@ -40,7 +41,6 @@ protocol unix
|
|||
seccomp
|
||||
shell none
|
||||
tracelog
|
||||
apparmor
|
||||
|
||||
private-bin okular,kbuildsycoca4,kdeinit4,lpr
|
||||
private-dev
|
||||
|
|
|
|||
|
|
@ -15,6 +15,7 @@ include /etc/firejail/disable-programs.inc
|
|||
|
||||
include /etc/firejail/whitelist-var-common.inc
|
||||
|
||||
apparmor
|
||||
caps.drop all
|
||||
netfilter
|
||||
nodvd
|
||||
|
|
@ -25,7 +26,6 @@ notv
|
|||
protocol unix,inet,inet6,netlink
|
||||
seccomp
|
||||
shell none
|
||||
apparmor
|
||||
|
||||
private-dev
|
||||
private-tmp
|
||||
|
|
|
|||
|
|
@ -26,6 +26,7 @@ whitelist ${HOME}/.local/share/data/qBittorrent
|
|||
include /etc/firejail/whitelist-common.inc
|
||||
include /etc/firejail/whitelist-var-common.inc
|
||||
|
||||
apparmor
|
||||
caps.drop all
|
||||
machine-id
|
||||
netfilter
|
||||
|
|
@ -39,7 +40,6 @@ novideo
|
|||
protocol unix,inet,inet6,netlink
|
||||
seccomp
|
||||
shell none
|
||||
apparmor
|
||||
|
||||
private-bin qbittorrent,python*
|
||||
private-dev
|
||||
|
|
|
|||
|
|
@ -13,6 +13,7 @@ include /etc/firejail/disable-programs.inc
|
|||
|
||||
include /etc/firejail/whitelist-var-common.inc
|
||||
|
||||
apparmor
|
||||
caps.drop all
|
||||
netfilter
|
||||
# no3d
|
||||
|
|
@ -25,7 +26,6 @@ protocol unix,inet,inet6
|
|||
seccomp
|
||||
shell none
|
||||
tracelog
|
||||
apparmor
|
||||
|
||||
private-bin rhythmbox
|
||||
private-dev
|
||||
|
|
|
|||
|
|
@ -15,6 +15,7 @@ include /etc/firejail/disable-programs.inc
|
|||
|
||||
include /etc/firejail/whitelist-var-common.inc
|
||||
|
||||
apparmor
|
||||
caps.drop all
|
||||
netfilter
|
||||
# nogroups
|
||||
|
|
@ -23,7 +24,6 @@ noroot
|
|||
protocol unix,inet,inet6,netlink
|
||||
seccomp
|
||||
shell none
|
||||
apparmor
|
||||
|
||||
private-bin smplayer,smtube,mplayer,mpv
|
||||
private-dev
|
||||
|
|
|
|||
|
|
@ -15,6 +15,7 @@ include /etc/firejail/disable-programs.inc
|
|||
|
||||
include /etc/firejail/whitelist-var-common.inc
|
||||
|
||||
apparmor
|
||||
caps.drop all
|
||||
netfilter
|
||||
nogroups
|
||||
|
|
@ -23,7 +24,6 @@ noroot
|
|||
protocol unix,inet,inet6
|
||||
seccomp
|
||||
shell none
|
||||
apparmor
|
||||
|
||||
private-bin totem
|
||||
private-dev
|
||||
|
|
|
|||
|
|
@ -21,6 +21,7 @@ whitelist ${HOME}/.config/transmission
|
|||
include /etc/firejail/whitelist-common.inc
|
||||
include /etc/firejail/whitelist-var-common.inc
|
||||
|
||||
apparmor
|
||||
caps.drop all
|
||||
machine-id
|
||||
netfilter
|
||||
|
|
@ -34,7 +35,6 @@ protocol unix,inet,inet6
|
|||
seccomp
|
||||
shell none
|
||||
tracelog
|
||||
apparmor
|
||||
|
||||
private-bin transmission-gtk
|
||||
private-dev
|
||||
|
|
|
|||
|
|
@ -21,6 +21,7 @@ whitelist ${HOME}/.config/transmission
|
|||
include /etc/firejail/whitelist-common.inc
|
||||
include /etc/firejail/whitelist-var-common.inc
|
||||
|
||||
apparmor
|
||||
caps.drop all
|
||||
machine-id
|
||||
netfilter
|
||||
|
|
@ -34,7 +35,6 @@ protocol unix,inet,inet6
|
|||
seccomp
|
||||
shell none
|
||||
tracelog
|
||||
apparmor
|
||||
|
||||
private-bin transmission-qt
|
||||
private-dev
|
||||
|
|
@ -42,4 +42,3 @@ private-dev
|
|||
private-tmp
|
||||
|
||||
# memory-deny-write-execute - problems on Qt 5.10.0, KDE Frameworks 5.41.0
|
||||
|
||||
|
|
|
|||
|
|
@ -15,6 +15,7 @@ include /etc/firejail/disable-programs.inc
|
|||
|
||||
include /etc/firejail/whitelist-var-common.inc
|
||||
|
||||
apparmor
|
||||
caps.drop all
|
||||
netfilter
|
||||
# nogroups
|
||||
|
|
@ -23,7 +24,6 @@ noroot
|
|||
protocol unix,inet,inet6,netlink
|
||||
seccomp
|
||||
shell none
|
||||
apparmor
|
||||
|
||||
private-bin vlc,cvlc,nvlc,rvlc,qvlc,svlc
|
||||
private-dev
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue