mirror of
https://github.com/netblue30/firejail.git
synced 2026-05-21 06:45:29 -06:00
added notv to most profiles
This commit is contained in:
parent
a42f6028e2
commit
b97ca53e7b
291 changed files with 293 additions and 0 deletions
|
|
@ -39,3 +39,4 @@ private-tmp
|
|||
|
||||
noexec ${HOME}
|
||||
noexec /tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -30,3 +30,4 @@ private-tmp
|
|||
|
||||
noexec ${HOME}
|
||||
noexec /tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -20,3 +20,4 @@ tracelog
|
|||
private-dev
|
||||
|
||||
include /etc/firejail/default.profile
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -24,3 +24,4 @@ shell none
|
|||
|
||||
private-dev
|
||||
private-tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -24,3 +24,4 @@ caps.drop all
|
|||
nonewprivs
|
||||
noroot
|
||||
seccomp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -26,3 +26,4 @@ protocol unix
|
|||
seccomp
|
||||
shell none
|
||||
tracelog
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -38,3 +38,4 @@ private
|
|||
private-dev
|
||||
# private-etc ld.so.conf,ld.so.cache,resolv.conf,host.conf,nsswitch.conf,gai.conf,hosts,hostname
|
||||
private-tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -39,3 +39,4 @@ private
|
|||
private-dev
|
||||
private-etc ld.so.conf,ld.so.cache,resolv.conf,host.conf,nsswitch.conf,gai.conf,hosts,hostname
|
||||
private-tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -44,3 +44,4 @@ seccomp
|
|||
tracelog
|
||||
|
||||
# private-etc passwd,group,hostname,hosts,localtime,nsswitch.conf,resolv.conf,gtk-2.0,pango,fonts,iceweasel,firefox,adobe,mime.types,mailcap,asound.conf,pulse
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -30,3 +30,4 @@ private-tmp
|
|||
|
||||
noexec ${HOME}
|
||||
noexec /tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -24,3 +24,4 @@ shell none
|
|||
private-dev
|
||||
# private-etc none
|
||||
private-tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -32,3 +32,4 @@ private-dev
|
|||
# private-tmp
|
||||
|
||||
noexec /tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -27,3 +27,4 @@ private-dev
|
|||
|
||||
noexec ${HOME}
|
||||
noexec /tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -30,3 +30,4 @@ private-tmp
|
|||
|
||||
noexec ${HOME}
|
||||
noexec /tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -27,3 +27,4 @@ shell none
|
|||
private-dev
|
||||
# private-etc
|
||||
private-tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -38,3 +38,4 @@ private-tmp
|
|||
|
||||
noexec ${HOME}
|
||||
noexec /tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -25,3 +25,4 @@ shell none
|
|||
|
||||
private-dev
|
||||
private-tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -25,3 +25,4 @@ shell none
|
|||
|
||||
private-dev
|
||||
private-tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -29,3 +29,4 @@ tracelog
|
|||
private-dev
|
||||
private-etc none
|
||||
private-tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -27,3 +27,4 @@ tracelog
|
|||
private-bin atril, atril-previewer, atril-thumbnailer
|
||||
private-dev
|
||||
private-tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -25,3 +25,4 @@ tracelog
|
|||
|
||||
private-bin audacious
|
||||
private-tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -30,3 +30,4 @@ private-tmp
|
|||
|
||||
noexec ${HOME}
|
||||
noexec /tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -31,3 +31,4 @@ tracelog
|
|||
private-bin aweather
|
||||
private-dev
|
||||
private-tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -39,3 +39,4 @@ noexec /tmp
|
|||
# read-only ${HOME}
|
||||
# read-write ${HOME}/.local/share
|
||||
# noexec ${HOME}/.local/share
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -29,3 +29,4 @@ private-tmp
|
|||
memory-deny-write-execute
|
||||
noexec ${HOME}
|
||||
noexec /tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -38,3 +38,4 @@ tracelog
|
|||
private-dev
|
||||
private-etc fonts,resolv.conf,sword,sword.conf,passwd
|
||||
private-tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -29,3 +29,4 @@ private-tmp
|
|||
read-write /var/lib/bitlbee
|
||||
|
||||
noexec /tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -31,3 +31,4 @@ shell none
|
|||
memory-deny-write-execute
|
||||
noexec ${HOME}
|
||||
noexec /tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -26,3 +26,4 @@ private-tmp
|
|||
|
||||
noexec ${HOME}
|
||||
noexec /tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -30,3 +30,4 @@ private-tmp
|
|||
|
||||
noexec ${HOME}
|
||||
noexec /tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -31,3 +31,4 @@ tracelog
|
|||
memory-deny-write-execute
|
||||
noexec ${HOME}
|
||||
noexec /tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -34,3 +34,4 @@ netfilter
|
|||
# seccomp
|
||||
|
||||
# disable-mnt
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -32,3 +32,4 @@ tracelog
|
|||
# private-dev
|
||||
# private-etc fonts
|
||||
# private-tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -32,3 +32,4 @@ private-tmp
|
|||
|
||||
noexec ${HOME}
|
||||
noexec /tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -29,3 +29,4 @@ tracelog
|
|||
# private-bin bash,catfish,env,locate,ls,mlocate,python,python2,python2.7,python3,python3.5,python3.5m,python3m
|
||||
# private-dev
|
||||
# private-tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -32,3 +32,4 @@ private-tmp
|
|||
|
||||
noexec ${HOME}
|
||||
noexec /tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -35,3 +35,4 @@ private-dev
|
|||
|
||||
noexec ${HOME}
|
||||
noexec /tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -26,3 +26,4 @@ shell none
|
|||
|
||||
private-dev
|
||||
private-tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -19,3 +19,4 @@ novideo
|
|||
protocol unix,inet,inet6
|
||||
# Clementine makes ioprio_set system calls, which are blacklisted by default.
|
||||
seccomp.drop mount,umount2,ptrace,kexec_load,kexec_file_load,name_to_handle_at,open_by_handle_at,create_module,init_module,finit_module,delete_module,iopl,ioperm,swapon,swapoff,syslog,process_vm_readv,process_vm_writev,sysfs,_sysctl,adjtimex,clock_adjtime,lookup_dcookie,perf_event_open,fanotify_init,kcmp,add_key,request_key,keyctl,uselib,acct,modify_ldt,pivot_root,io_setup,io_destroy,io_getevents,io_submit,io_cancel,remap_file_pages,mbind,get_mempolicy,set_mempolicy,migrate_pages,move_pages,vmsplice,chroot,tuxcall,reboot,mfsservctl,get_kernel_syms,bpf,clock_settime,personality,process_vm_writev,query_module,settimeofday,stime,umount,userfaultfd,ustat,vm86,vm86old
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -31,3 +31,4 @@ private-tmp
|
|||
|
||||
noexec ${HOME}
|
||||
noexec /tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -22,3 +22,4 @@ shell none
|
|||
|
||||
private-bin cmus
|
||||
private-etc group
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -29,3 +29,4 @@ nonewprivs
|
|||
noroot
|
||||
protocol unix,inet,inet6
|
||||
seccomp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -16,3 +16,4 @@ netfilter
|
|||
noroot
|
||||
protocol unix,inet,inet6
|
||||
seccomp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -25,3 +25,4 @@ shell none
|
|||
tracelog
|
||||
|
||||
private-dev
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -32,3 +32,4 @@ private-tmp
|
|||
|
||||
noexec ${HOME}
|
||||
noexec /tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -28,3 +28,4 @@ private-dev
|
|||
private-tmp
|
||||
|
||||
memory-deny-write-execute
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -68,3 +68,4 @@ private-tmp
|
|||
|
||||
noexec ${HOME}
|
||||
noexec /tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -29,3 +29,4 @@ private-tmp
|
|||
|
||||
noexec ${HOME}
|
||||
noexec /tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -28,3 +28,4 @@ private-tmp
|
|||
|
||||
noexec ${HOME}
|
||||
noexec /tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -21,6 +21,8 @@ nonewprivs
|
|||
noroot
|
||||
# nosound
|
||||
# novideo
|
||||
# notv
|
||||
# no3d
|
||||
protocol unix,inet,inet6
|
||||
seccomp
|
||||
# shell none
|
||||
|
|
|
|||
|
|
@ -31,3 +31,4 @@ shell none
|
|||
# private-bin deluge,sh,python,uname
|
||||
private-dev
|
||||
private-tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -28,3 +28,4 @@ private-dev
|
|||
|
||||
noexec ${HOME}
|
||||
noexec /tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -30,3 +30,4 @@ private-tmp
|
|||
|
||||
noexec ${HOME}
|
||||
noexec /tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -31,3 +31,4 @@ private-tmp
|
|||
|
||||
noexec ${HOME}
|
||||
noexec /tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -26,3 +26,4 @@ noroot
|
|||
protocol unix,inet,inet6
|
||||
seccomp
|
||||
tracelog
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -37,3 +37,4 @@ private-tmp
|
|||
|
||||
noexec ${HOME}
|
||||
noexec /tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -26,3 +26,4 @@ private-bin display
|
|||
private-dev
|
||||
private-etc none
|
||||
private-tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -19,3 +19,4 @@ seccomp.drop mount,umount2,ptrace,kexec_load,kexec_file_load,open_by_handle_at,i
|
|||
|
||||
private
|
||||
private-dev
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -24,3 +24,4 @@ seccomp
|
|||
disable-mnt
|
||||
private
|
||||
private-dev
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -31,3 +31,4 @@ shell none
|
|||
# private-dev
|
||||
# private-etc
|
||||
# private-tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -25,3 +25,4 @@ tracelog
|
|||
private-bin dosbox
|
||||
private-dev
|
||||
private-tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -29,3 +29,4 @@ private-tmp
|
|||
|
||||
noexec ${HOME}
|
||||
noexec /tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -39,3 +39,4 @@ private-dev
|
|||
private-tmp
|
||||
|
||||
noexec /tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -17,3 +17,4 @@ nonewprivs
|
|||
noroot
|
||||
protocol unix,inet,inet6,netlink
|
||||
seccomp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -31,3 +31,4 @@ tracelog
|
|||
private-dev
|
||||
# private-etc none
|
||||
private-tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -19,3 +19,4 @@ nonewprivs
|
|||
noroot
|
||||
protocol unix,inet,inet6
|
||||
seccomp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -17,3 +17,4 @@ nonewprivs
|
|||
noroot
|
||||
protocol unix,inet,inet6
|
||||
seccomp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -27,3 +27,4 @@ tracelog
|
|||
# private-dev
|
||||
# private-etc fonts
|
||||
# private-tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -27,3 +27,4 @@ tracelog
|
|||
private-dev
|
||||
# private-etc fonts
|
||||
# private-tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -35,3 +35,4 @@ private-tmp
|
|||
memory-deny-write-execute
|
||||
noexec ${HOME}
|
||||
noexec /tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -32,3 +32,4 @@ private-tmp
|
|||
|
||||
noexec ${HOME}
|
||||
noexec /tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -27,3 +27,4 @@ netfilter
|
|||
nonewprivs
|
||||
protocol unix,inet,inet6
|
||||
seccomp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -28,3 +28,4 @@ shell none
|
|||
private-dev
|
||||
# private-etc none
|
||||
private-tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -34,3 +34,4 @@ private-etc fonts
|
|||
memory-deny-write-execute
|
||||
noexec ${HOME}
|
||||
noexec /tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -36,3 +36,4 @@ private-tmp
|
|||
|
||||
noexec ${HOME}
|
||||
noexec /tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -33,3 +33,4 @@ tracelog
|
|||
private-dev
|
||||
private-etc none
|
||||
private-tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -24,3 +24,4 @@ shell none
|
|||
private-bin fbreader,FBReader
|
||||
private-dev
|
||||
private-tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -25,3 +25,4 @@ private-bin feh
|
|||
private-dev
|
||||
private-etc feh
|
||||
private-tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -32,3 +32,4 @@ private-dev
|
|||
memory-deny-write-execute
|
||||
noexec ${HOME}
|
||||
noexec /tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -28,3 +28,4 @@ x11 none
|
|||
private-bin file
|
||||
private-dev
|
||||
private-etc magic.mgc,magic,localtime
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -24,3 +24,4 @@ shell none
|
|||
private-bin filezilla,uname,sh,bash,dash,python,lsb_release,fzputtygen,fzsftp
|
||||
private-dev
|
||||
private-tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -68,3 +68,4 @@ private-tmp
|
|||
|
||||
noexec ${HOME}
|
||||
noexec /tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -34,3 +34,4 @@ nonewprivs
|
|||
noroot
|
||||
protocol unix,inet,inet6,netlink
|
||||
seccomp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -27,3 +27,4 @@ private-tmp
|
|||
|
||||
noexec ${HOME}
|
||||
noexec /tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -28,3 +28,4 @@ private-tmp
|
|||
|
||||
noexec ${HOME}
|
||||
noexec /tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -18,3 +18,4 @@ whitelist ~/.gnupg
|
|||
include /etc/firejail/whitelist-common.inc
|
||||
|
||||
include /etc/firejail/firefox.profile
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -37,3 +37,4 @@ private-tmp
|
|||
|
||||
noexec ${HOME}
|
||||
noexec /tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -28,3 +28,4 @@ shell none
|
|||
private-dev
|
||||
# private-etc none
|
||||
private-tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -42,3 +42,4 @@ private-dev
|
|||
# private-tmp
|
||||
# Allow the local python 2.7 site packages, in case any plugins are using these
|
||||
read-only ${HOME}/.local/lib/python2.7/site-packages/
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -31,3 +31,4 @@ private-bin galculator
|
|||
private-dev
|
||||
private-etc fonts
|
||||
private-tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -25,3 +25,4 @@ shell none
|
|||
|
||||
private-dev
|
||||
private-tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -33,3 +33,4 @@ private-tmp
|
|||
|
||||
noexec ${HOME}
|
||||
noexec /tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -26,3 +26,4 @@ shell none
|
|||
# private-bin geeqie
|
||||
private-dev
|
||||
# private-etc X11
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -28,3 +28,4 @@ private-tmp
|
|||
# if you are not using external plugins, you can enable noexec statement below
|
||||
# noexec ${HOME}
|
||||
noexec /tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -32,3 +32,4 @@ seccomp
|
|||
shell none
|
||||
|
||||
private-dev
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -31,3 +31,4 @@ private-tmp
|
|||
memory-deny-write-execute
|
||||
noexec ${HOME}
|
||||
noexec /tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -25,3 +25,4 @@ shell none
|
|||
private-bin gitter
|
||||
private-dev
|
||||
private-tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -31,3 +31,4 @@ tracelog
|
|||
private-dev
|
||||
# private-etc fonts
|
||||
private-tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -30,3 +30,4 @@ private-tmp
|
|||
|
||||
noexec ${HOME}
|
||||
noexec /tmp
|
||||
notv
|
||||
|
|
|
|||
|
|
@ -31,3 +31,4 @@ private-tmp
|
|||
|
||||
noexec ${HOME}
|
||||
noexec /tmp
|
||||
notv
|
||||
|
|
|
|||
Some files were not shown because too many files have changed in this diff Show more
Loading…
Add table
Add a link
Reference in a new issue