diff --git a/data/scripts/Linux-AppImage/AppRun b/data/scripts/Linux-AppImage/AppRun index 232524480..251beddb6 100755 --- a/data/scripts/Linux-AppImage/AppRun +++ b/data/scripts/Linux-AppImage/AppRun @@ -212,7 +212,7 @@ if [ -n "${ULTRAGRID_USE_FIREJAIL-}" ] && [ "$ULTRAGRID_USE_FIREJAIL" != 0 ] && FIREJAIL_OPTS="--profile=$ULTRAGRID_USE_FIREJAIL" else FJ_TMPDIR=${TMPDIR-/tmp/ultragrid-$(id -u)} - FIREJAIL_OPTS="--caps.drop=all --ipc-namespace --nonewprivs --noroot --protocol=unix,inet,inet6,netlink --seccomp --shell=none --disable-mnt --private-bin=none --private-opt=none --mkdir=$FJ_TMPDIR --read-write=$FJ_TMPDIR --writable-var" + FIREJAIL_OPTS="--caps.drop=all --ipc-namespace --nonewprivs --noroot --protocol=unix,inet,inet6,netlink --seccomp --disable-mnt --private-bin=none --private-opt=none --mkdir=$FJ_TMPDIR --read-write=$FJ_TMPDIR --writable-var" FIREJAIL_OPTS="$FIREJAIL_OPTS $(get_firejail_whitelist "$@") --private-etc=alsa,group,hostname,ld.so.conf,ld.so.cache,ld.so.conf.d,nsswitch.conf,passwd,resolv.conf --ignore=novideo" if ! expr "$FIREJAIL_OPTS" : '.*--read-write=/tmp '; then FIREJAIL_OPTS="$FIREJAIL_OPTS --read-only=/tmp"