Merge pull request #2201 from SkewedZeppelin/u2f-ap

Add nou2f to all profiles
This commit is contained in:
netblue30 2018-10-17 08:00:00 -05:00 committed by GitHub
commit 92bff8a23c
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23
323 changed files with 323 additions and 3 deletions

View file

@ -32,6 +32,7 @@ nogroups
nonewprivs
noroot
notv
nou2f
novideo
protocol unix,inet,inet6
seccomp

View file

@ -30,6 +30,7 @@ nonewprivs
noroot
nosound
notv
nou2f
novideo
protocol unix
seccomp

View file

@ -16,6 +16,7 @@ nodbus
nodvd
nosound
notv
nou2f
novideo
shell none
tracelog

View file

@ -21,6 +21,7 @@ nonewprivs
noroot
nosound
notv
nou2f
protocol unix,inet,inet6,netlink
seccomp
shell none

View file

@ -27,6 +27,7 @@ nonewprivs
noroot
nosound
notv
nou2f
novideo
protocol unix,inet,inet6
seccomp

View file

@ -38,6 +38,7 @@ nonewprivs
noroot
nosound
notv
nou2f
novideo
protocol unix,inet,inet6
seccomp

View file

@ -25,6 +25,7 @@ nogroups
nonewprivs
noroot
notv
nou2f
protocol unix,inet,inet6
seccomp
shell none

View file

@ -29,6 +29,7 @@ nonewprivs
# noroot
nosound
notv
nou2f
protocol unix
seccomp
shell none

View file

@ -31,6 +31,7 @@ nonewprivs
#noroot
nosound
notv
nou2f
protocol unix
seccomp
shell none

View file

@ -42,6 +42,7 @@ nogroups
noroot
nosound
notv
nou2f
novideo
# protocol unix,inet,inet6
# seccomp.drop @cpu-emulation,@debug,@obsolete,@privileged,@resources,add_key,fanotify_init,io_cancel,io_destroy,kcmp,keyctl,name_to_handle_at,ni_syscall,open_by_handle_at,personality,process_vm_readv,ptrace,remap_file_pages,request_key,syslog,umount,userfaultfd,vmsplice

View file

@ -31,6 +31,7 @@ nogroups
nonewprivs
noroot
notv
nou2f
novideo
protocol unix,inet,inet6,netlink
# chroot syscalls are needed for setting up the built-in sandbox

View file

@ -23,6 +23,7 @@ nogroups
nonewprivs
noroot
notv
nou2f
novideo
protocol unix,inet,inet6
# seccomp

View file

@ -29,6 +29,7 @@ nonewprivs
noroot
nosound
notv
nou2f
novideo
protocol unix,inet,inet6
seccomp

View file

@ -24,6 +24,7 @@ nogroups
nonewprivs
noroot
notv
nou2f
protocol unix,inet,inet6
seccomp
shell none

View file

@ -24,6 +24,7 @@ nonewprivs
noroot
nosound
notv
nou2f
novideo
protocol unix
seccomp

View file

@ -27,6 +27,7 @@ nonewprivs
noroot
nosound
notv
nou2f
novideo
protocol unix,inet,inet6
seccomp

View file

@ -28,6 +28,7 @@ nogroups
nonewprivs
noroot
notv
nou2f
protocol unix
seccomp
shell none

View file

@ -26,6 +26,7 @@ nonewprivs
noroot
nosound
notv
nou2f
novideo
protocol unix,inet,inet6
seccomp

View file

@ -27,6 +27,7 @@ nonewprivs
noroot
nosound
notv
nou2f
novideo
protocol unix
seccomp

View file

@ -34,6 +34,7 @@ nonewprivs
noroot
nosound
notv
nou2f
novideo
protocol unix,inet,inet6
seccomp

View file

@ -28,6 +28,7 @@ nodbus
# nogroups
nonewprivs
noroot
nou2f
protocol unix,inet,inet6
seccomp
shell none

View file

@ -23,6 +23,7 @@ nonewprivs
noroot
nosound
notv
nou2f
novideo
protocol unix,inet,inet6,netlink
seccomp

View file

@ -31,6 +31,7 @@ nonewprivs
noroot
nosound
notv
nou2f
novideo
protocol unix
seccomp

View file

@ -32,6 +32,7 @@ nonewprivs
noroot
nosound
notv
nou2f
novideo
protocol unix
seccomp

View file

@ -27,6 +27,7 @@ nogroups
nonewprivs
noroot
notv
nou2f
novideo
protocol unix,inet,inet6
seccomp

View file

@ -29,6 +29,7 @@ nogroups
nonewprivs
noroot
notv
nou2f
novideo
protocol unix
seccomp

View file

@ -30,8 +30,8 @@ nonewprivs
noroot
nosound
notv
# novideo
nou2f
# novideo
protocol unix
seccomp
shell none

View file

@ -27,6 +27,7 @@ nonewprivs
noroot
nosound
notv
nou2f
novideo
protocol unix,inet,inet6
seccomp

View file

@ -28,6 +28,7 @@ nonewprivs
noroot
nosound
notv
nou2f
novideo
protocol unix
# blacklisting of ioprio_set system calls breaks baloo_file

View file

@ -22,6 +22,7 @@ nonewprivs
noroot
nosound
notv
nou2f
novideo
protocol unix
seccomp

View file

@ -31,6 +31,7 @@ nonewprivs
noroot
nosound
notv
nou2f
novideo
protocol unix,inet,inet6,netlink
seccomp

View file

@ -32,6 +32,7 @@ nonewprivs
noroot
nosound
notv
nou2f
novideo
protocol unix,inet,inet6
seccomp

View file

@ -23,6 +23,7 @@ nodvd
nonewprivs
nosound
notv
nou2f
novideo
protocol unix,inet,inet6
seccomp

View file

@ -28,6 +28,7 @@ nonewprivs
noroot
nosound
notv
nou2f
novideo
protocol unix
seccomp

View file

@ -32,6 +32,7 @@ nogroups
nonewprivs
noroot
notv
nou2f
protocol unix,inet,inet6,netlink
seccomp
shell none

View file

@ -26,6 +26,7 @@ nonewprivs
noroot
nosound
notv
nou2f
novideo
protocol unix
seccomp

View file

@ -24,6 +24,7 @@ nonewprivs
noroot
nosound
notv
nou2f
novideo
protocol unix
seccomp

View file

@ -21,6 +21,7 @@ nonewprivs
noroot
nosound
notv
nou2f
novideo
protocol unix,inet,inet6,netlink
seccomp.drop @clock,@cpu-emulation,@debug,@module,@obsolete,@reboot,@resources,@swap,acct,add_key,bpf,fanotify_init,io_cancel,io_destroy,io_getevents,io_setup,io_submit,iopl,ioprio_set,kcmp,keyctl,mount,name_to_handle_at,nfsservctl,ni_syscall,open_by_handle_at,pciconfig_iobase,pciconfig_read,pciconfig_write,personality,pivot_root,process_vm_readv,ptrace,remap_file_pages,request_key,s390_mmio_read,s390_mmio_write,setdomainname,sethostname,syslog,umount,umount2,userfaultfd,vhangup,vmsplic

View file

@ -25,6 +25,7 @@ nonewprivs
# noroot
nosound
notv
nou2f
novideo
nonewprivs
protocol unix

View file

@ -27,6 +27,7 @@ nonewprivs
noroot
nosound
notv
nou2f
novideo
protocol unix,inet,inet6
seccomp

View file

@ -21,6 +21,7 @@ nogroups
nonewprivs
noroot
notv
nou2f
novideo
protocol unix
seccomp

View file

@ -36,6 +36,7 @@ nonewprivs
noroot
nosound
notv
nou2f
novideo
protocol unix
seccomp

View file

@ -31,6 +31,7 @@ nonewprivs
noroot
nosound
notv
nou2f
novideo
protocol unix,inet,inet6,netlink
seccomp

View file

@ -27,6 +27,7 @@ nodbus
nodvd
nogroups
notv
nou2f
shell none
disable-mnt

View file

@ -21,6 +21,7 @@ nodvd
#nogroups
nonewprivs
notv
nou2f
noroot
protocol unix

View file

@ -18,6 +18,7 @@ nonewprivs
noroot
nosound
notv
nou2f
novideo
protocol unix
seccomp

View file

@ -16,6 +16,7 @@ nonewprivs
noroot
nosound
notv
nou2f
novideo
protocol unix
seccomp

View file

@ -23,6 +23,7 @@ caps.drop all
nonewprivs
noroot
notv
nou2f
novideo
protocol unix,inet,inet6
# blacklisting of ioprio_set system calls breaks clementine

View file

@ -23,6 +23,7 @@ nogroups
nonewprivs
noroot
notv
nou2f
novideo
protocol unix,inet,inet6
seccomp

View file

@ -25,6 +25,7 @@ nonewprivs
noroot
nosound
notv
nou2f
novideo
protocol unix
seccomp

View file

@ -21,6 +21,7 @@ nonewprivs
noroot
nosound
notv
nou2f
novideo
protocol unix,inet,inet6,netlink
seccomp

View file

@ -25,6 +25,7 @@ nonewprivs
noroot
nosound
notv
nou2f
novideo
protocol unix,inet,inet6
seccomp

View file

@ -24,6 +24,7 @@ nogroups
nonewprivs
noroot
notv
nou2f
novideo
protocol unix,inet,inet6
seccomp

View file

@ -33,6 +33,7 @@ nonewprivs
noroot
nosound
notv
nou2f
novideo
protocol unix,inet,inet6
seccomp

View file

@ -24,6 +24,7 @@ nodvd
nonewprivs
nosound
notv
nou2f
novideo
seccomp
shell none

View file

@ -24,6 +24,7 @@ nonewprivs
noroot
nosound
notv
nou2f
novideo
protocol unix,inet,inet6
seccomp

View file

@ -25,6 +25,7 @@ nonewprivs
noroot
nosound
notv
nou2f
novideo
protocol unix,inet,inet6
seccomp

View file

@ -23,6 +23,7 @@ nogroups
nonewprivs
noroot
notv
nou2f
novideo
protocol unix,inet,inet6
seccomp

View file

@ -34,6 +34,7 @@ nonewprivs
noroot
nosound
notv
nou2f
novideo
protocol unix,inet,inet6
seccomp

View file

@ -31,6 +31,7 @@ nonewprivs
noroot
nosound
notv
nou2f
novideo
protocol unix
seccomp

View file

@ -26,6 +26,7 @@ nonewprivs
noroot
nosound
notv
nou2f
novideo
protocol unix
seccomp

View file

@ -28,6 +28,7 @@ nonewprivs
noroot
nosound
notv
nou2f
novideo
protocol unix,inet,inet6
seccomp

View file

@ -28,6 +28,7 @@ nodvd
nonewprivs
noroot
notv
nou2f
protocol unix,inet,inet6
seccomp
tracelog

View file

@ -27,6 +27,7 @@ nonewprivs
noroot
nosound
notv
nou2f
novideo
protocol unix,inet,inet6
seccomp

View file

@ -20,6 +20,7 @@ nogroups
nonewprivs
noroot
notv
nou2f
novideo
protocol unix,inet,inet6,netlink
seccomp

View file

@ -31,6 +31,7 @@ nonewprivs
noroot
nosound
notv
nou2f
protocol unix
seccomp
shell none

View file

@ -24,6 +24,7 @@ nodvd
nonewprivs
nosound
notv
nou2f
novideo
seccomp.drop mount,umount2,ptrace,kexec_load,kexec_file_load,open_by_handle_at,init_module,finit_module,delete_module,iopl,ioperm,swapon,swapoff,syslog,process_vm_readv,process_vm_writev,sysfs,_sysctl,adjtimex,clock_adjtime,lookup_dcookie,perf_event_open,fanotify_init,kcmp,add_key,request_key,keyctl,uselib,acct,modify_ldt,pivot_root,io_setup,io_destroy,io_getevents,io_submit,io_cancel,remap_file_pages,mbind,get_mempolicy,set_mempolicy,migrate_pages,move_pages,vmsplice,perf_event_open

View file

@ -24,6 +24,7 @@ nodvd
nonewprivs
nosound
notv
nou2f
novideo
protocol unix,inet,inet6,netlink
seccomp

View file

@ -26,6 +26,7 @@ nogroups
nonewprivs
noroot
notv
nou2f
novideo
protocol unix,inet,inet6,netlink
seccomp

View file

@ -25,6 +25,7 @@ nogroups
nonewprivs
noroot
notv
nou2f
novideo
protocol unix,inet,inet6
seccomp

View file

@ -25,6 +25,7 @@ nogroups
nonewprivs
noroot
notv
nou2f
novideo
protocol unix,inet,inet6
seccomp

View file

@ -34,6 +34,7 @@ nonewprivs
noroot
nosound
notv
nou2f
novideo
protocol unix,inet,inet6
seccomp

View file

@ -37,6 +37,7 @@ nonewprivs
noroot
nosound
notv
nou2f
novideo
protocol unix,inet,inet6
seccomp

View file

@ -26,6 +26,7 @@ nonewprivs
noroot
nosound
notv
nou2f
novideo
protocol unix,inet,inet6
seccomp

View file

@ -25,6 +25,7 @@ nonewprivs
noroot
nosound
notv
nou2f
novideo
protocol unix
seccomp

View file

@ -25,6 +25,7 @@ nonewprivs
noroot
nosound
notv
nou2f
novideo
protocol unix
seccomp

View file

@ -26,6 +26,7 @@ nonewprivs
noroot
nosound
notv
nou2f
novideo
protocol unix
seccomp

View file

@ -30,6 +30,7 @@ nonewprivs
noroot
nosound
notv
nou2f
novideo
protocol unix
seccomp

View file

@ -30,6 +30,7 @@ nonewprivs
noroot
nosound
notv
nou2f
novideo
protocol unix
seccomp

View file

@ -24,6 +24,7 @@ nogroups
nonewprivs
noroot
notv
nou2f
protocol unix,netlink
seccomp
shell none

View file

@ -30,6 +30,7 @@ nonewprivs
noroot
nosound
notv
nou2f
novideo
protocol unix
seccomp

View file

@ -31,6 +31,7 @@ nonewprivs
noroot
nosound
notv
nou2f
novideo
protocol unix,inet,inet6
seccomp

View file

@ -29,6 +29,7 @@ nonewprivs
noroot
nosound
notv
nou2f
novideo
protocol unix
seccomp

View file

@ -28,6 +28,7 @@ nogroups
nonewprivs
noroot
notv
nou2f
protocol unix,inet,inet6,netlink
# blacklisting of chroot system calls breaks falkon
seccomp.drop @clock,@cpu-emulation,@debug,@module,@obsolete,@raw-io,@reboot,@resources,@swap,acct,add_key,bpf,fanotify_init,io_cancel,io_destroy,io_getevents,io_setup,io_submit,ioprio_set,kcmp,keyctl,mount,name_to_handle_at,nfsservctl,ni_syscall,open_by_handle_at,personality,pivot_root,process_vm_readv,ptrace,remap_file_pages,request_key,setdomainname,sethostname,syslog,umount,umount2,userfaultfd,vhangup,vmsplice

View file

@ -25,6 +25,7 @@ nonewprivs
noroot
nosound
notv
nou2f
novideo
protocol unix,inet,inet6
seccomp

View file

@ -22,6 +22,7 @@ nonewprivs
noroot
nosound
notv
nou2f
novideo
protocol unix
seccomp

View file

@ -24,6 +24,7 @@ nonewprivs
noroot
nosound
notv
nou2f
novideo
protocol unix,inet,inet6
seccomp

View file

@ -22,6 +22,7 @@ nodbus
nodvd
nosound
notv
nou2f
novideo
nonewprivs
noroot

View file

@ -25,6 +25,7 @@ nonewprivs
noroot
nosound
notv
nou2f
novideo
protocol unix
seccomp

View file

@ -23,6 +23,7 @@ nogroups
nonewprivs
nosound
notv
nou2f
novideo
protocol unix
seccomp

View file

@ -28,6 +28,7 @@ nonewprivs
noroot
nosound
notv
nou2f
novideo
protocol unix,inet,inet6
seccomp

View file

@ -35,6 +35,7 @@ nogroups
nonewprivs
noroot
notv
nou2f
protocol unix,inet,inet6,netlink
seccomp.drop @clock,@cpu-emulation,@debug,@module,@obsolete,@raw-io,@reboot,@resources,@swap,acct,add_key,bpf,fanotify_init,io_cancel,io_destroy,io_getevents,io_setup,io_submit,ioprio_set,kcmp,keyctl,mount,name_to_handle_at,nfsservctl,ni_syscall,open_by_handle_at,personality,pivot_root,process_vm_readv,ptrace,remap_file_pages,request_key,setdomainname,sethostname,syslog,umount,umount2,userfaultfd,vhangup,vmsplice
shell none

View file

@ -26,6 +26,7 @@ nonewprivs
noroot
nosound
notv
nou2f
novideo
protocol unix,inet,inet6
seccomp

View file

@ -28,6 +28,7 @@ nogroups
nonewprivs
noroot
notv
nou2f
protocol unix,inet,inet6,netlink
seccomp
shell none

View file

@ -30,6 +30,7 @@ nonewprivs
noroot
nosound
notv
nou2f
novideo
protocol unix
seccomp

View file

@ -30,6 +30,7 @@ nogroups
nonewprivs
noroot
notv
nou2f
protocol unix,inet,inet6,netlink
seccomp
shell none

View file

@ -26,6 +26,7 @@ nonewprivs
noroot
nosound
notv
nou2f
novideo
protocol unix
seccomp

View file

@ -16,6 +16,7 @@ nogroups
nonewprivs
nosound
notv
nou2f
novideo
protocol unix,inet,inet6
seccomp

View file

@ -27,6 +27,7 @@ nogroups
nonewprivs
noroot
notv
nou2f
protocol unix,netlink
seccomp
shell none

View file

@ -38,6 +38,7 @@ nogroups
nonewprivs
noroot
notv
nou2f
protocol unix,inet,inet6
seccomp

Some files were not shown because too many files have changed in this diff Show more