From 8c04e94af899701884bf152180c55299d346b29e Mon Sep 17 00:00:00 2001 From: netblue30 Date: Mon, 18 Sep 2017 09:50:39 -0400 Subject: [PATCH] whitelist /var --- etc/2048-qt.profile | 2 ++ etc/calibre.profile | 2 ++ etc/dosbox.profile | 2 ++ etc/gpicview.profile | 2 ++ etc/handbrake.profile | 2 ++ etc/virtualbox.profile | 1 + etc/youtube-dl.profile | 2 ++ 7 files changed, 13 insertions(+) diff --git a/etc/2048-qt.profile b/etc/2048-qt.profile index 06cc69503..964a9e5fa 100644 --- a/etc/2048-qt.profile +++ b/etc/2048-qt.profile @@ -13,6 +13,8 @@ include /etc/firejail/disable-devel.inc include /etc/firejail/disable-passwdmgr.inc include /etc/firejail/disable-programs.inc +include /etc/firejail/whitelist-var-common.inc + caps.drop all netfilter nodvd diff --git a/etc/calibre.profile b/etc/calibre.profile index aa0de473c..844231032 100644 --- a/etc/calibre.profile +++ b/etc/calibre.profile @@ -13,6 +13,8 @@ include /etc/firejail/disable-common.inc include /etc/firejail/disable-passwdmgr.inc include /etc/firejail/disable-programs.inc +include /etc/firejail/whitelist-var-common.inc + caps.drop all netfilter no3d diff --git a/etc/dosbox.profile b/etc/dosbox.profile index fa9b26e82..a64578e5c 100644 --- a/etc/dosbox.profile +++ b/etc/dosbox.profile @@ -12,6 +12,8 @@ include /etc/firejail/disable-devel.inc include /etc/firejail/disable-passwdmgr.inc include /etc/firejail/disable-programs.inc +include /etc/firejail/whitelist-var-common.inc + caps.drop all netfilter nodvd diff --git a/etc/gpicview.profile b/etc/gpicview.profile index 26bc589ee..1842c9cb1 100644 --- a/etc/gpicview.profile +++ b/etc/gpicview.profile @@ -12,6 +12,8 @@ include /etc/firejail/disable-devel.inc include /etc/firejail/disable-passwdmgr.inc include /etc/firejail/disable-programs.inc +include /etc/firejail/whitelist-var-common.inc + caps.drop all net none nodvd diff --git a/etc/handbrake.profile b/etc/handbrake.profile index 2b33051e2..f5e7bc329 100644 --- a/etc/handbrake.profile +++ b/etc/handbrake.profile @@ -12,6 +12,8 @@ include /etc/firejail/disable-devel.inc include /etc/firejail/disable-passwdmgr.inc include /etc/firejail/disable-programs.inc +include /etc/firejail/whitelist-var-common.inc + caps.drop all netfilter nogroups diff --git a/etc/virtualbox.profile b/etc/virtualbox.profile index 8eef45d8c..b01e6d144 100644 --- a/etc/virtualbox.profile +++ b/etc/virtualbox.profile @@ -22,6 +22,7 @@ whitelist ~/.config/VirtualBox whitelist ~/VirtualBox VMs whitelist ${DOWNLOADS} include /etc/firejail/whitelist-common.inc +include /etc/firejail/whitelist-var-common.inc caps.drop all netfilter diff --git a/etc/youtube-dl.profile b/etc/youtube-dl.profile index e20fb3e99..d41591fd6 100644 --- a/etc/youtube-dl.profile +++ b/etc/youtube-dl.profile @@ -13,6 +13,8 @@ include /etc/firejail/disable-devel.inc include /etc/firejail/disable-passwdmgr.inc include /etc/firejail/disable-programs.inc +include /etc/firejail/whitelist-var-common.inc + caps.drop all ipc-namespace netfilter