summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLibravatar netblue30 <netblue30@yahoo.com>2016-03-27 09:13:22 -0400
committerLibravatar netblue30 <netblue30@yahoo.com>2016-03-27 09:13:22 -0400
commit570f845a012c8328fcd97839b728844ae1c640f2 (patch)
tree90b7c3428eec20d294d83511db72e6a3394df6d6
parentlxterinal profile fix (diff)
downloadfirejail-570f845a012c8328fcd97839b728844ae1c640f2.tar.gz
firejail-570f845a012c8328fcd97839b728844ae1c640f2.tar.zst
firejail-570f845a012c8328fcd97839b728844ae1c640f2.zip
consolidated disable-terminals into disable-common
-rw-r--r--Makefile.in1
-rw-r--r--etc/Mathematica.profile3
-rw-r--r--etc/audacious.profile1
-rw-r--r--etc/bitlbee.profile1
-rw-r--r--etc/cherrytree.profile1
-rw-r--r--etc/chromium.profile1
-rw-r--r--etc/clementine.profile1
-rw-r--r--etc/conkeror.profile1
-rw-r--r--etc/deadbeef.profile1
-rw-r--r--etc/deluge.profile1
-rw-r--r--etc/disable-common.inc6
-rw-r--r--etc/disable-mgmt.inc0
-rw-r--r--etc/disable-secret.inc23
-rw-r--r--etc/disable-terminals.inc5
-rw-r--r--etc/dnscrypt-proxy.profile1
-rw-r--r--etc/dropbox.profile1
-rw-r--r--etc/empathy.profile1
-rw-r--r--etc/epiphany.profile2
-rw-r--r--etc/evince.profile2
-rw-r--r--etc/fbreader.profile2
-rw-r--r--etc/filezilla.profile2
-rw-r--r--etc/firefox.profile1
-rw-r--r--etc/flashpeak-slimjet.profile1
-rw-r--r--etc/generic.profile2
-rw-r--r--etc/gnome-mplayer.profile2
-rw-r--r--etc/google-chrome-beta.profile1
-rw-r--r--etc/google-chrome-unstable.profile1
-rw-r--r--etc/google-chrome.profile1
-rw-r--r--etc/hedgewars.profile2
-rw-r--r--etc/hexchat.profile2
-rw-r--r--etc/kmail.profile3
-rw-r--r--etc/lxterminal.profile4
-rw-r--r--etc/midori.profile2
-rw-r--r--etc/mupen64plus.profile3
-rw-r--r--etc/openbox.profile7
-rw-r--r--etc/opera-beta.profile1
-rw-r--r--etc/opera.profile1
-rw-r--r--etc/parole.profile4
-rw-r--r--etc/pidgin.profile3
-rw-r--r--etc/polari.profile3
-rw-r--r--etc/qbittorrent.profile3
-rw-r--r--etc/qtox.profile3
-rw-r--r--etc/quassel.profile3
-rw-r--r--etc/qutebrowser.profile2
-rw-r--r--etc/rhythmbox.profile3
-rw-r--r--etc/rtorrent.profile2
-rw-r--r--etc/seamonkey.profile3
-rw-r--r--etc/skype.profile2
-rw-r--r--etc/ssh.profile3
-rw-r--r--etc/steam.profile2
-rw-r--r--etc/telegram.profile1
-rw-r--r--etc/totem.profile3
-rw-r--r--etc/transmission-gtk.profile3
-rw-r--r--etc/transmission-qt.profile3
-rw-r--r--etc/uget-gtk.profile3
-rw-r--r--etc/unbound.profile2
-rw-r--r--etc/vivaldi.profile1
-rw-r--r--etc/vlc.profile3
-rw-r--r--etc/weechat.profile2
-rw-r--r--etc/wesnoth.profile1
-rw-r--r--etc/wine.profile2
-rw-r--r--etc/xchat.profile2
-rw-r--r--platform/debian/conffiles1
63 files changed, 61 insertions, 93 deletions
diff --git a/Makefile.in b/Makefile.in
index 5951394d7..df010c199 100644
--- a/Makefile.in
+++ b/Makefile.in
@@ -145,7 +145,6 @@ realinstall:
145 install -c -m 0644 .etc/uget-gtk.profile $(DESTDIR)/$(sysconfdir)/firejail/. 145 install -c -m 0644 .etc/uget-gtk.profile $(DESTDIR)/$(sysconfdir)/firejail/.
146 install -c -m 0644 .etc/mupen64plus.profile $(DESTDIR)/$(sysconfdir)/firejail/. 146 install -c -m 0644 .etc/mupen64plus.profile $(DESTDIR)/$(sysconfdir)/firejail/.
147 install -c -m 0644 .etc/disable-programs.inc $(DESTDIR)/$(sysconfdir)/firejail/. 147 install -c -m 0644 .etc/disable-programs.inc $(DESTDIR)/$(sysconfdir)/firejail/.
148 install -c -m 0644 .etc/disable-terminals.inc $(DESTDIR)/$(sysconfdir)/firejail/.
149 install -c -m 0644 .etc/lxterminal.profile $(DESTDIR)/$(sysconfdir)/firejail/. 148 install -c -m 0644 .etc/lxterminal.profile $(DESTDIR)/$(sysconfdir)/firejail/.
150 install -c -m 0644 .etc/cherrytree.profile $(DESTDIR)/$(sysconfdir)/firejail/. 149 install -c -m 0644 .etc/cherrytree.profile $(DESTDIR)/$(sysconfdir)/firejail/.
151 install -c -m 0644 .etc/wesnoth.profile $(DESTDIR)/$(sysconfdir)/firejail/. 150 install -c -m 0644 .etc/wesnoth.profile $(DESTDIR)/$(sysconfdir)/firejail/.
diff --git a/etc/Mathematica.profile b/etc/Mathematica.profile
index c3ce7b618..1ee50b4d4 100644
--- a/etc/Mathematica.profile
+++ b/etc/Mathematica.profile
@@ -5,10 +5,11 @@ mkdir ~/.Wolfram Research
5whitelist ~/.Wolfram Research 5whitelist ~/.Wolfram Research
6whitelist ~/Documents/Wolfram Mathematica 6whitelist ~/Documents/Wolfram Mathematica
7include /etc/firejail/whitelist-common.inc 7include /etc/firejail/whitelist-common.inc
8
8include /etc/firejail/disable-common.inc 9include /etc/firejail/disable-common.inc
9include /etc/firejail/disable-programs.inc 10include /etc/firejail/disable-programs.inc
10include /etc/firejail/disable-devel.inc 11include /etc/firejail/disable-devel.inc
11include /etc/firejail/disable-terminals.inc 12
12caps.drop all 13caps.drop all
13seccomp 14seccomp
14noroot 15noroot
diff --git a/etc/audacious.profile b/etc/audacious.profile
index 49417fbfe..690463a46 100644
--- a/etc/audacious.profile
+++ b/etc/audacious.profile
@@ -2,7 +2,6 @@
2include /etc/firejail/disable-common.inc 2include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 3include /etc/firejail/disable-programs.inc
4include /etc/firejail/disable-devel.inc 4include /etc/firejail/disable-devel.inc
5include /etc/firejail/disable-terminals.inc
6blacklist ${HOME}/.pki/nssdb 5blacklist ${HOME}/.pki/nssdb
7blacklist ${HOME}/.lastpass 6blacklist ${HOME}/.lastpass
8blacklist ${HOME}/.keepassx 7blacklist ${HOME}/.keepassx
diff --git a/etc/bitlbee.profile b/etc/bitlbee.profile
index c3bd58298..753e42480 100644
--- a/etc/bitlbee.profile
+++ b/etc/bitlbee.profile
@@ -3,7 +3,6 @@ noblacklist /sbin
3noblacklist /usr/sbin 3noblacklist /usr/sbin
4include /etc/firejail/disable-common.inc 4include /etc/firejail/disable-common.inc
5include /etc/firejail/disable-programs.inc 5include /etc/firejail/disable-programs.inc
6include /etc/firejail/disable-terminals.inc
7protocol unix,inet,inet6 6protocol unix,inet,inet6
8private 7private
9private-dev 8private-dev
diff --git a/etc/cherrytree.profile b/etc/cherrytree.profile
index 09e87f043..349cc7acf 100644
--- a/etc/cherrytree.profile
+++ b/etc/cherrytree.profile
@@ -2,7 +2,6 @@
2include /etc/firejail/disable-common.inc 2include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 3include /etc/firejail/disable-programs.inc
4include /etc/firejail/disable-devel.inc 4include /etc/firejail/disable-devel.inc
5include /etc/firejail/disable-terminals.inc
6 5
7whitelist ${HOME}/cherrytree 6whitelist ${HOME}/cherrytree
8mkdir ~/.config 7mkdir ~/.config
diff --git a/etc/chromium.profile b/etc/chromium.profile
index 751426db8..58f62daa2 100644
--- a/etc/chromium.profile
+++ b/etc/chromium.profile
@@ -4,7 +4,6 @@ noblacklist ~/.cache/chromium
4noblacklist ~/keepassx.kdbx 4noblacklist ~/keepassx.kdbx
5include /etc/firejail/disable-common.inc 5include /etc/firejail/disable-common.inc
6include /etc/firejail/disable-programs.inc 6include /etc/firejail/disable-programs.inc
7include /etc/firejail/disable-terminals.inc
8 7
9# chromium is distributed with a perl script on Arch 8# chromium is distributed with a perl script on Arch
10# include /etc/firejail/disable-devel.inc 9# include /etc/firejail/disable-devel.inc
diff --git a/etc/clementine.profile b/etc/clementine.profile
index 4737541db..cc0614551 100644
--- a/etc/clementine.profile
+++ b/etc/clementine.profile
@@ -1,7 +1,6 @@
1# Clementine media player profile 1# Clementine media player profile
2include /etc/firejail/disable-common.inc 2include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 3include /etc/firejail/disable-programs.inc
4include /etc/firejail/disable-terminals.inc
5include /etc/firejail/disable-devel.inc 4include /etc/firejail/disable-devel.inc
6blacklist ${HOME}/.pki/nssdb 5blacklist ${HOME}/.pki/nssdb
7blacklist ${HOME}/.lastpass 6blacklist ${HOME}/.lastpass
diff --git a/etc/conkeror.profile b/etc/conkeror.profile
index 57fedac61..67e529d0a 100644
--- a/etc/conkeror.profile
+++ b/etc/conkeror.profile
@@ -2,7 +2,6 @@
2noblacklist ${HOME}/.conkeror.mozdev.org 2noblacklist ${HOME}/.conkeror.mozdev.org
3include /etc/firejail/disable-common.inc 3include /etc/firejail/disable-common.inc
4include /etc/firejail/disable-programs.inc 4include /etc/firejail/disable-programs.inc
5include /etc/firejail/disable-terminals.inc
6caps.drop all 5caps.drop all
7seccomp 6seccomp
8protocol unix,inet,inet6 7protocol unix,inet,inet6
diff --git a/etc/deadbeef.profile b/etc/deadbeef.profile
index 4f222947f..89661d83c 100644
--- a/etc/deadbeef.profile
+++ b/etc/deadbeef.profile
@@ -2,7 +2,6 @@
2include /etc/firejail/disable-common.inc 2include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 3include /etc/firejail/disable-programs.inc
4include /etc/firejail/disable-devel.inc 4include /etc/firejail/disable-devel.inc
5include /etc/firejail/disable-terminals.inc
6blacklist ${HOME}/.pki/nssdb 5blacklist ${HOME}/.pki/nssdb
7blacklist ${HOME}/.lastpass 6blacklist ${HOME}/.lastpass
8blacklist ${HOME}/.keepassx 7blacklist ${HOME}/.keepassx
diff --git a/etc/deluge.profile b/etc/deluge.profile
index aeafb7a4a..eef2a42ee 100644
--- a/etc/deluge.profile
+++ b/etc/deluge.profile
@@ -2,7 +2,6 @@
2include /etc/firejail/disable-common.inc 2include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 3include /etc/firejail/disable-programs.inc
4include /etc/firejail/disable-devel.inc 4include /etc/firejail/disable-devel.inc
5include /etc/firejail/disable-terminals.inc
6blacklist ${HOME}/.pki/nssdb 5blacklist ${HOME}/.pki/nssdb
7blacklist ${HOME}/.lastpass 6blacklist ${HOME}/.lastpass
8blacklist ${HOME}/.keepassx 7blacklist ${HOME}/.keepassx
diff --git a/etc/disable-common.inc b/etc/disable-common.inc
index cb356dcf7..71439e10d 100644
--- a/etc/disable-common.inc
+++ b/etc/disable-common.inc
@@ -125,3 +125,9 @@ blacklist /usr/local/sbin
125 125
126# prevent lxterminal connecting to an existing lxterminal session 126# prevent lxterminal connecting to an existing lxterminal session
127blacklist /tmp/.lxterminal-socket* 127blacklist /tmp/.lxterminal-socket*
128
129# disable terminals running as server
130blacklist ${PATH}/gnome-terminal
131blacklist ${PATH}/gnome-terminal.wrapper
132blacklist ${PATH}/xfce4-terminal
133blacklist ${PATH}/xfce4-terminal.wrapper
diff --git a/etc/disable-mgmt.inc b/etc/disable-mgmt.inc
deleted file mode 100644
index e69de29bb..000000000
--- a/etc/disable-mgmt.inc
+++ /dev/null
diff --git a/etc/disable-secret.inc b/etc/disable-secret.inc
deleted file mode 100644
index 7d29cda31..000000000
--- a/etc/disable-secret.inc
+++ /dev/null
@@ -1,23 +0,0 @@
1# HOME directory
2blacklist ${HOME}/.ssh
3blacklist ${HOME}/.gnome2/keyrings
4blacklist ${HOME}/kde4/share/apps/kwallet
5blacklist ${HOME}/kde/share/apps/kwallet
6blacklist ${HOME}/.local/share/kwalletd
7blacklist ${HOME}/.netrc
8blacklist ${HOME}/.gnupg
9blacklist ${HOME}/*.kdbx
10blacklist ${HOME}/*.kdb
11blacklist ${HOME}/*.key
12blacklist /etc/shadow
13blacklist /etc/gshadow
14blacklist /etc/passwd-
15blacklist /etc/group-
16blacklist /etc/shadow-
17blacklist /etc/gshadow-
18blacklist /etc/passwd+
19blacklist /etc/group+
20blacklist /etc/shadow+
21blacklist /etc/gshadow+
22blacklist /etc/ssh
23blacklist /var/backup
diff --git a/etc/disable-terminals.inc b/etc/disable-terminals.inc
deleted file mode 100644
index c9db48087..000000000
--- a/etc/disable-terminals.inc
+++ /dev/null
@@ -1,5 +0,0 @@
1# disable terminals running as server
2blacklist ${PATH}/gnome-terminal
3blacklist ${PATH}/gnome-terminal.wrapper
4blacklist ${PATH}/xfce4-terminal
5blacklist ${PATH}/xfce4-terminal.wrapper
diff --git a/etc/dnscrypt-proxy.profile b/etc/dnscrypt-proxy.profile
index 368830f15..dc6b783ee 100644
--- a/etc/dnscrypt-proxy.profile
+++ b/etc/dnscrypt-proxy.profile
@@ -4,7 +4,6 @@ noblacklist /usr/sbin
4include /etc/firejail/disable-common.inc 4include /etc/firejail/disable-common.inc
5include /etc/firejail/disable-programs.inc 5include /etc/firejail/disable-programs.inc
6include /etc/firejail/disable-devel.inc 6include /etc/firejail/disable-devel.inc
7include /etc/firejail/disable-terminals.inc
8private 7private
9private-dev 8private-dev
10seccomp.drop mount,umount2,ptrace,kexec_load,kexec_file_load,open_by_handle_at,init_module,finit_module,delete_module,iopl,ioperm,swapon,swapoff,syslog,process_vm_readv,process_vm_writev,sysfs,_sysctl,adjtimex,clock_adjtime,lookup_dcookie,perf_event_open,fanotify_init,kcmp,add_key,request_key,keyctl,uselib,acct,modify_ldt,pivot_root,io_setup,io_destroy,io_getevents,io_submit,io_cancel,remap_file_pages,mbind,get_mempolicy,set_mempolicy,migrate_pages,move_pages,vmsplice,perf_event_open 9seccomp.drop mount,umount2,ptrace,kexec_load,kexec_file_load,open_by_handle_at,init_module,finit_module,delete_module,iopl,ioperm,swapon,swapoff,syslog,process_vm_readv,process_vm_writev,sysfs,_sysctl,adjtimex,clock_adjtime,lookup_dcookie,perf_event_open,fanotify_init,kcmp,add_key,request_key,keyctl,uselib,acct,modify_ldt,pivot_root,io_setup,io_destroy,io_getevents,io_submit,io_cancel,remap_file_pages,mbind,get_mempolicy,set_mempolicy,migrate_pages,move_pages,vmsplice,perf_event_open
diff --git a/etc/dropbox.profile b/etc/dropbox.profile
index d31d1be8f..3b48f0d49 100644
--- a/etc/dropbox.profile
+++ b/etc/dropbox.profile
@@ -1,7 +1,6 @@
1# dropbox profile 1# dropbox profile
2include /etc/firejail/disable-common.inc 2include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 3include /etc/firejail/disable-programs.inc
4include /etc/firejail/disable-terminals.inc
5blacklist ${HOME}/.pki/nssdb 4blacklist ${HOME}/.pki/nssdb
6blacklist ${HOME}/.lastpass 5blacklist ${HOME}/.lastpass
7blacklist ${HOME}/.keepassx 6blacklist ${HOME}/.keepassx
diff --git a/etc/empathy.profile b/etc/empathy.profile
index 46a69120b..1c46f8b3e 100644
--- a/etc/empathy.profile
+++ b/etc/empathy.profile
@@ -2,7 +2,6 @@
2include /etc/firejail/disable-common.inc 2include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 3include /etc/firejail/disable-programs.inc
4include /etc/firejail/disable-devel.inc 4include /etc/firejail/disable-devel.inc
5include /etc/firejail/disable-terminals.inc
6blacklist ${HOME}/.wine 5blacklist ${HOME}/.wine
7caps.drop all 6caps.drop all
8seccomp 7seccomp
diff --git a/etc/epiphany.profile b/etc/epiphany.profile
index b06e6ea78..319d2b177 100644
--- a/etc/epiphany.profile
+++ b/etc/epiphany.profile
@@ -2,7 +2,7 @@
2include /etc/firejail/disable-common.inc 2include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 3include /etc/firejail/disable-programs.inc
4include /etc/firejail/disable-devel.inc 4include /etc/firejail/disable-devel.inc
5include /etc/firejail/disable-terminals.inc 5
6whitelist ${DOWNLOADS} 6whitelist ${DOWNLOADS}
7mkdir ${HOME}/.local 7mkdir ${HOME}/.local
8mkdir ${HOME}/.local/share 8mkdir ${HOME}/.local/share
diff --git a/etc/evince.profile b/etc/evince.profile
index 7b81c0453..13b342f06 100644
--- a/etc/evince.profile
+++ b/etc/evince.profile
@@ -2,7 +2,7 @@
2include /etc/firejail/disable-common.inc 2include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 3include /etc/firejail/disable-programs.inc
4include /etc/firejail/disable-devel.inc 4include /etc/firejail/disable-devel.inc
5include /etc/firejail/disable-terminals.inc 5
6blacklist ${HOME}/.pki/nssdb 6blacklist ${HOME}/.pki/nssdb
7blacklist ${HOME}/.lastpass 7blacklist ${HOME}/.lastpass
8blacklist ${HOME}/.keepassx 8blacklist ${HOME}/.keepassx
diff --git a/etc/fbreader.profile b/etc/fbreader.profile
index e7d61160e..4b45208d7 100644
--- a/etc/fbreader.profile
+++ b/etc/fbreader.profile
@@ -3,7 +3,7 @@ noblacklist ${HOME}/.FBReader
3include /etc/firejail/disable-common.inc 3include /etc/firejail/disable-common.inc
4include /etc/firejail/disable-programs.inc 4include /etc/firejail/disable-programs.inc
5include /etc/firejail/disable-devel.inc 5include /etc/firejail/disable-devel.inc
6include /etc/firejail/disable-terminals.inc 6
7blacklist ${HOME}/.pki/nssdb 7blacklist ${HOME}/.pki/nssdb
8blacklist ${HOME}/.lastpass 8blacklist ${HOME}/.lastpass
9blacklist ${HOME}/.keepassx 9blacklist ${HOME}/.keepassx
diff --git a/etc/filezilla.profile b/etc/filezilla.profile
index 39689e717..09e56b1ce 100644
--- a/etc/filezilla.profile
+++ b/etc/filezilla.profile
@@ -4,7 +4,7 @@ noblacklist ${HOME}/.config/filezilla
4include /etc/firejail/disable-common.inc 4include /etc/firejail/disable-common.inc
5include /etc/firejail/disable-programs.inc 5include /etc/firejail/disable-programs.inc
6include /etc/firejail/disable-devel.inc 6include /etc/firejail/disable-devel.inc
7include /etc/firejail/disable-terminals.inc 7
8blacklist ${HOME}/.wine 8blacklist ${HOME}/.wine
9caps.drop all 9caps.drop all
10seccomp 10seccomp
diff --git a/etc/firefox.profile b/etc/firefox.profile
index f23f84097..2d2716256 100644
--- a/etc/firefox.profile
+++ b/etc/firefox.profile
@@ -6,7 +6,6 @@ noblacklist ~/keepassx.kdbx
6include /etc/firejail/disable-common.inc 6include /etc/firejail/disable-common.inc
7include /etc/firejail/disable-programs.inc 7include /etc/firejail/disable-programs.inc
8include /etc/firejail/disable-devel.inc 8include /etc/firejail/disable-devel.inc
9include /etc/firejail/disable-terminals.inc
10 9
11caps.drop all 10caps.drop all
12seccomp 11seccomp
diff --git a/etc/flashpeak-slimjet.profile b/etc/flashpeak-slimjet.profile
index 613ef6652..3f6af42b1 100644
--- a/etc/flashpeak-slimjet.profile
+++ b/etc/flashpeak-slimjet.profile
@@ -10,7 +10,6 @@ noblacklist ~/.cache/slimjet
10noblacklist ~/keepassx.kdbx 10noblacklist ~/keepassx.kdbx
11include /etc/firejail/disable-common.inc 11include /etc/firejail/disable-common.inc
12include /etc/firejail/disable-programs.inc 12include /etc/firejail/disable-programs.inc
13include /etc/firejail/disable-terminals.inc
14 13
15# chromium is distributed with a perl script on Arch 14# chromium is distributed with a perl script on Arch
16# include /etc/firejail/disable-devel.inc 15# include /etc/firejail/disable-devel.inc
diff --git a/etc/generic.profile b/etc/generic.profile
index ae42c8a3b..2bf7a0703 100644
--- a/etc/generic.profile
+++ b/etc/generic.profile
@@ -3,7 +3,7 @@
3################################ 3################################
4include /etc/firejail/disable-common.inc 4include /etc/firejail/disable-common.inc
5include /etc/firejail/disable-programs.inc 5include /etc/firejail/disable-programs.inc
6include /etc/firejail/disable-terminals.inc 6
7blacklist ${HOME}/.pki/nssdb 7blacklist ${HOME}/.pki/nssdb
8blacklist ${HOME}/.lastpass 8blacklist ${HOME}/.lastpass
9blacklist ${HOME}/.keepassx 9blacklist ${HOME}/.keepassx
diff --git a/etc/gnome-mplayer.profile b/etc/gnome-mplayer.profile
index 2313f36fc..1138a73bd 100644
--- a/etc/gnome-mplayer.profile
+++ b/etc/gnome-mplayer.profile
@@ -2,7 +2,7 @@
2include /etc/firejail/disable-common.inc 2include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 3include /etc/firejail/disable-programs.inc
4include /etc/firejail/disable-devel.inc 4include /etc/firejail/disable-devel.inc
5include /etc/firejail/disable-terminals.inc 5
6blacklist ${HOME}/.pki/nssdb 6blacklist ${HOME}/.pki/nssdb
7blacklist ${HOME}/.lastpass 7blacklist ${HOME}/.lastpass
8blacklist ${HOME}/.keepassx 8blacklist ${HOME}/.keepassx
diff --git a/etc/google-chrome-beta.profile b/etc/google-chrome-beta.profile
index 57c224191..8ca049778 100644
--- a/etc/google-chrome-beta.profile
+++ b/etc/google-chrome-beta.profile
@@ -4,7 +4,6 @@ noblacklist ~/.cache/google-chrome-beta
4noblacklist ~/keepassx.kdbx 4noblacklist ~/keepassx.kdbx
5include /etc/firejail/disable-common.inc 5include /etc/firejail/disable-common.inc
6include /etc/firejail/disable-programs.inc 6include /etc/firejail/disable-programs.inc
7include /etc/firejail/disable-terminals.inc
8 7
9# chromium is distributed with a perl script on Arch 8# chromium is distributed with a perl script on Arch
10# include /etc/firejail/disable-devel.inc 9# include /etc/firejail/disable-devel.inc
diff --git a/etc/google-chrome-unstable.profile b/etc/google-chrome-unstable.profile
index e222ccf54..3e238d8f8 100644
--- a/etc/google-chrome-unstable.profile
+++ b/etc/google-chrome-unstable.profile
@@ -4,7 +4,6 @@ noblacklist ~/.cache/google-chrome-unstable
4noblacklist ~/keepassx.kdbx 4noblacklist ~/keepassx.kdbx
5include /etc/firejail/disable-common.inc 5include /etc/firejail/disable-common.inc
6include /etc/firejail/disable-programs.inc 6include /etc/firejail/disable-programs.inc
7include /etc/firejail/disable-terminals.inc
8 7
9# chromium is distributed with a perl script on Arch 8# chromium is distributed with a perl script on Arch
10# include /etc/firejail/disable-devel.inc 9# include /etc/firejail/disable-devel.inc
diff --git a/etc/google-chrome.profile b/etc/google-chrome.profile
index 767f73f88..afc57f948 100644
--- a/etc/google-chrome.profile
+++ b/etc/google-chrome.profile
@@ -4,7 +4,6 @@ noblacklist ~/.cache/google-chrome
4noblacklist ~/keepassx.kdbx 4noblacklist ~/keepassx.kdbx
5include /etc/firejail/disable-common.inc 5include /etc/firejail/disable-common.inc
6include /etc/firejail/disable-programs.inc 6include /etc/firejail/disable-programs.inc
7include /etc/firejail/disable-terminals.inc
8 7
9# chromium is distributed with a perl script on Arch 8# chromium is distributed with a perl script on Arch
10# include /etc/firejail/disable-devel.inc 9# include /etc/firejail/disable-devel.inc
diff --git a/etc/hedgewars.profile b/etc/hedgewars.profile
index a9f1da373..13a311070 100644
--- a/etc/hedgewars.profile
+++ b/etc/hedgewars.profile
@@ -3,12 +3,10 @@
3include /etc/firejail/disable-common.inc 3include /etc/firejail/disable-common.inc
4include /etc/firejail/disable-programs.inc 4include /etc/firejail/disable-programs.inc
5include /etc/firejail/disable-devel.inc 5include /etc/firejail/disable-devel.inc
6include /etc/firejail/disable-terminals.inc
7 6
8caps.drop all 7caps.drop all
9noroot 8noroot
10private-dev 9private-dev
11whitelist /tmp/.X11-unix
12seccomp 10seccomp
13tracelog 11tracelog
14 12
diff --git a/etc/hexchat.profile b/etc/hexchat.profile
index 6ceeaefce..8f6fd6217 100644
--- a/etc/hexchat.profile
+++ b/etc/hexchat.profile
@@ -3,7 +3,7 @@ noblacklist ${HOME}/.config/hexchat
3include /etc/firejail/disable-common.inc 3include /etc/firejail/disable-common.inc
4include /etc/firejail/disable-programs.inc 4include /etc/firejail/disable-programs.inc
5include /etc/firejail/disable-devel.inc 5include /etc/firejail/disable-devel.inc
6include /etc/firejail/disable-terminals.inc 6
7caps.drop all 7caps.drop all
8seccomp 8seccomp
9protocol unix,inet,inet6 9protocol unix,inet,inet6
diff --git a/etc/kmail.profile b/etc/kmail.profile
index 35a1a15a0..78e72a7a7 100644
--- a/etc/kmail.profile
+++ b/etc/kmail.profile
@@ -3,12 +3,13 @@ noblacklist ${HOME}/.gnupg
3include /etc/firejail/disable-common.inc 3include /etc/firejail/disable-common.inc
4include /etc/firejail/disable-programs.inc 4include /etc/firejail/disable-programs.inc
5include /etc/firejail/disable-devel.inc 5include /etc/firejail/disable-devel.inc
6include /etc/firejail/disable-terminals.inc 6
7blacklist ${HOME}/.pki/nssdb 7blacklist ${HOME}/.pki/nssdb
8blacklist ${HOME}/.lastpass 8blacklist ${HOME}/.lastpass
9blacklist ${HOME}/.keepassx 9blacklist ${HOME}/.keepassx
10blacklist ${HOME}/.password-store 10blacklist ${HOME}/.password-store
11blacklist ${HOME}/.wine 11blacklist ${HOME}/.wine
12
12caps.drop all 13caps.drop all
13seccomp 14seccomp
14protocol unix,inet,inet6,netlink 15protocol unix,inet,inet6,netlink
diff --git a/etc/lxterminal.profile b/etc/lxterminal.profile
index e98ac0b83..88a7a8c7a 100644
--- a/etc/lxterminal.profile
+++ b/etc/lxterminal.profile
@@ -2,14 +2,14 @@
2 2
3include /etc/firejail/disable-common.inc 3include /etc/firejail/disable-common.inc
4include /etc/firejail/disable-programs.inc 4include /etc/firejail/disable-programs.inc
5
5blacklist ${HOME}/.pki/nssdb 6blacklist ${HOME}/.pki/nssdb
6blacklist ${HOME}/.lastpass 7blacklist ${HOME}/.lastpass
7blacklist ${HOME}/.keepassx 8blacklist ${HOME}/.keepassx
8blacklist ${HOME}/.password-store 9blacklist ${HOME}/.password-store
10
9caps.drop all 11caps.drop all
10seccomp 12seccomp
11protocol unix,inet,inet6 13protocol unix,inet,inet6
12netfilter 14netfilter
13
14#noroot - somehow this breaks on Debian Jessie! 15#noroot - somehow this breaks on Debian Jessie!
15
diff --git a/etc/midori.profile b/etc/midori.profile
index 1cd686bfe..7fc27e07c 100644
--- a/etc/midori.profile
+++ b/etc/midori.profile
@@ -3,7 +3,7 @@ noblacklist ${HOME}/.config/midori
3include /etc/firejail/disable-common.inc 3include /etc/firejail/disable-common.inc
4include /etc/firejail/disable-programs.inc 4include /etc/firejail/disable-programs.inc
5include /etc/firejail/disable-devel.inc 5include /etc/firejail/disable-devel.inc
6include /etc/firejail/disable-terminals.inc 6
7caps.drop all 7caps.drop all
8seccomp 8seccomp
9protocol unix,inet,inet6 9protocol unix,inet,inet6
diff --git a/etc/mupen64plus.profile b/etc/mupen64plus.profile
index 5a4ad4f24..45dc4757f 100644
--- a/etc/mupen64plus.profile
+++ b/etc/mupen64plus.profile
@@ -3,7 +3,7 @@
3include /etc/firejail/disable-common.inc 3include /etc/firejail/disable-common.inc
4include /etc/firejail/disable-programs.inc 4include /etc/firejail/disable-programs.inc
5include /etc/firejail/disable-devel.inc 5include /etc/firejail/disable-devel.inc
6include /etc/firejail/disable-terminals.inc 6
7mkdir ${HOME}/.local 7mkdir ${HOME}/.local
8mkdir ${HOME}/.local/share 8mkdir ${HOME}/.local/share
9mkdir ${HOME}/.local/share/mupen64plus 9mkdir ${HOME}/.local/share/mupen64plus
@@ -11,6 +11,7 @@ whitelist ${HOME}/.local/share/mupen64plus/
11mkdir ${HOME}/.config 11mkdir ${HOME}/.config
12mkdir ${HOME}/.config/mupen64plus 12mkdir ${HOME}/.config/mupen64plus
13whitelist ${HOME}/.config/mupen64plus/ 13whitelist ${HOME}/.config/mupen64plus/
14
14noroot 15noroot
15caps.drop all 16caps.drop all
16seccomp 17seccomp
diff --git a/etc/openbox.profile b/etc/openbox.profile
index 42eb5e9fa..8a46e6841 100644
--- a/etc/openbox.profile
+++ b/etc/openbox.profile
@@ -1,12 +1,15 @@
1################################ 1################################
2# Generic GUI application profile 2# OpenBox window manager profile
3# - all applications started in OpenBox will run in
4# this profile
3################################ 5################################
4include /etc/firejail/disable-common.inc 6include /etc/firejail/disable-common.inc
5include /etc/firejail/disable-terminals.inc 7
6blacklist ${HOME}/.pki/nssdb 8blacklist ${HOME}/.pki/nssdb
7blacklist ${HOME}/.lastpass 9blacklist ${HOME}/.lastpass
8blacklist ${HOME}/.keepassx 10blacklist ${HOME}/.keepassx
9blacklist ${HOME}/.password-store 11blacklist ${HOME}/.password-store
12
10caps.drop all 13caps.drop all
11seccomp 14seccomp
12protocol unix,inet,inet6 15protocol unix,inet,inet6
diff --git a/etc/opera-beta.profile b/etc/opera-beta.profile
index 9659b30de..7b74d6dd1 100644
--- a/etc/opera-beta.profile
+++ b/etc/opera-beta.profile
@@ -5,7 +5,6 @@ noblacklist ~/keepassx.kdbx
5include /etc/firejail/disable-common.inc 5include /etc/firejail/disable-common.inc
6include /etc/firejail/disable-programs.inc 6include /etc/firejail/disable-programs.inc
7include /etc/firejail/disable-devel.inc 7include /etc/firejail/disable-devel.inc
8include /etc/firejail/disable-terminals.inc
9 8
10netfilter 9netfilter
11 10
diff --git a/etc/opera.profile b/etc/opera.profile
index 3c8868896..2d7a9ca06 100644
--- a/etc/opera.profile
+++ b/etc/opera.profile
@@ -5,7 +5,6 @@ noblacklist ~/keepassx.kdbx
5include /etc/firejail/disable-common.inc 5include /etc/firejail/disable-common.inc
6include /etc/firejail/disable-programs.inc 6include /etc/firejail/disable-programs.inc
7include /etc/firejail/disable-devel.inc 7include /etc/firejail/disable-devel.inc
8include /etc/firejail/disable-terminals.inc
9 8
10netfilter 9netfilter
11 10
diff --git a/etc/parole.profile b/etc/parole.profile
index 3369b191c..9f63e5b16 100644
--- a/etc/parole.profile
+++ b/etc/parole.profile
@@ -2,13 +2,15 @@
2include /etc/firejail/disable-common.inc 2include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 3include /etc/firejail/disable-programs.inc
4include /etc/firejail/disable-devel.inc 4include /etc/firejail/disable-devel.inc
5include /etc/firejail/disable-terminals.inc 5
6private-etc passwd,group,fonts 6private-etc passwd,group,fonts
7private-bin parole,dbus-launch 7private-bin parole,dbus-launch
8
8blacklist ${HOME}/.pki/nssdb 9blacklist ${HOME}/.pki/nssdb
9blacklist ${HOME}/.lastpass 10blacklist ${HOME}/.lastpass
10blacklist ${HOME}/.keepassx 11blacklist ${HOME}/.keepassx
11blacklist ${HOME}/.password-store 12blacklist ${HOME}/.password-store
13
12caps.drop all 14caps.drop all
13seccomp 15seccomp
14protocol unix,inet,inet6 16protocol unix,inet,inet6
diff --git a/etc/pidgin.profile b/etc/pidgin.profile
index 8080a8905..ea5d82103 100644
--- a/etc/pidgin.profile
+++ b/etc/pidgin.profile
@@ -3,8 +3,9 @@ noblacklist ${HOME}/.purple
3include /etc/firejail/disable-common.inc 3include /etc/firejail/disable-common.inc
4include /etc/firejail/disable-programs.inc 4include /etc/firejail/disable-programs.inc
5include /etc/firejail/disable-devel.inc 5include /etc/firejail/disable-devel.inc
6include /etc/firejail/disable-terminals.inc 6
7blacklist ${HOME}/.wine 7blacklist ${HOME}/.wine
8
8caps.drop all 9caps.drop all
9seccomp 10seccomp
10protocol unix,inet,inet6 11protocol unix,inet,inet6
diff --git a/etc/polari.profile b/etc/polari.profile
index 5e40aedf5..0bc46f3f7 100644
--- a/etc/polari.profile
+++ b/etc/polari.profile
@@ -2,7 +2,7 @@
2include /etc/firejail/disable-common.inc 2include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 3include /etc/firejail/disable-programs.inc
4include /etc/firejail/disable-devel.inc 4include /etc/firejail/disable-devel.inc
5include /etc/firejail/disable-terminals.inc 5
6mkdir ${HOME}/.local 6mkdir ${HOME}/.local
7mkdir ${HOME}/.local/share/ 7mkdir ${HOME}/.local/share/
8mkdir ${HOME}/.local/share/Empathy 8mkdir ${HOME}/.local/share/Empathy
@@ -20,6 +20,7 @@ whitelist ${HOME}/.cache/telepathy
20mkdir ${HOME}/.purple 20mkdir ${HOME}/.purple
21whitelist ${HOME}/.purple 21whitelist ${HOME}/.purple
22include /etc/firejail/whitelist-common.inc 22include /etc/firejail/whitelist-common.inc
23
23caps.drop all 24caps.drop all
24seccomp 25seccomp
25protocol unix,inet,inet6 26protocol unix,inet,inet6
diff --git a/etc/qbittorrent.profile b/etc/qbittorrent.profile
index 87afb78a6..9ad073b05 100644
--- a/etc/qbittorrent.profile
+++ b/etc/qbittorrent.profile
@@ -2,12 +2,13 @@
2include /etc/firejail/disable-common.inc 2include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 3include /etc/firejail/disable-programs.inc
4include /etc/firejail/disable-devel.inc 4include /etc/firejail/disable-devel.inc
5include /etc/firejail/disable-terminals.inc 5
6blacklist ${HOME}/.pki/nssdb 6blacklist ${HOME}/.pki/nssdb
7blacklist ${HOME}/.lastpass 7blacklist ${HOME}/.lastpass
8blacklist ${HOME}/.keepassx 8blacklist ${HOME}/.keepassx
9blacklist ${HOME}/.password-store 9blacklist ${HOME}/.password-store
10blacklist ${HOME}/.wine 10blacklist ${HOME}/.wine
11
11caps.drop all 12caps.drop all
12seccomp 13seccomp
13protocol unix,inet,inet6 14protocol unix,inet,inet6
diff --git a/etc/qtox.profile b/etc/qtox.profile
index 976e80c31..80acc3873 100644
--- a/etc/qtox.profile
+++ b/etc/qtox.profile
@@ -3,11 +3,12 @@ noblacklist ${HOME}/.config/tox
3include /etc/firejail/disable-common.inc 3include /etc/firejail/disable-common.inc
4include /etc/firejail/disable-programs.inc 4include /etc/firejail/disable-programs.inc
5include /etc/firejail/disable-devel.inc 5include /etc/firejail/disable-devel.inc
6include /etc/firejail/disable-terminals.inc 6
7mkdir ${HOME}/.config/tox 7mkdir ${HOME}/.config/tox
8whitelist ${HOME}/.config/tox 8whitelist ${HOME}/.config/tox
9whitelist ${DOWNLOADS} 9whitelist ${DOWNLOADS}
10include /etc/firejail/whitelist-common.inc 10include /etc/firejail/whitelist-common.inc
11
11caps.drop all 12caps.drop all
12seccomp 13seccomp
13protocol unix,inet,inet6 14protocol unix,inet,inet6
diff --git a/etc/quassel.profile b/etc/quassel.profile
index 073b50623..1fba23784 100644
--- a/etc/quassel.profile
+++ b/etc/quassel.profile
@@ -2,8 +2,9 @@
2include /etc/firejail/disable-common.inc 2include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 3include /etc/firejail/disable-programs.inc
4include /etc/firejail/disable-devel.inc 4include /etc/firejail/disable-devel.inc
5include /etc/firejail/disable-terminals.inc 5
6blacklist ${HOME}/.wine 6blacklist ${HOME}/.wine
7
7caps.drop all 8caps.drop all
8seccomp 9seccomp
9protocol unix,inet,inet6 10protocol unix,inet,inet6
diff --git a/etc/qutebrowser.profile b/etc/qutebrowser.profile
index 31b075c7a..3b7bf2d55 100644
--- a/etc/qutebrowser.profile
+++ b/etc/qutebrowser.profile
@@ -5,8 +5,6 @@ noblacklist ~/.cache/qutebrowser
5include /etc/firejail/disable-common.inc 5include /etc/firejail/disable-common.inc
6include /etc/firejail/disable-programs.inc 6include /etc/firejail/disable-programs.inc
7include /etc/firejail/disable-devel.inc 7include /etc/firejail/disable-devel.inc
8include /etc/firejail/disable-terminals.inc
9
10 8
11caps.drop all 9caps.drop all
12seccomp 10seccomp
diff --git a/etc/rhythmbox.profile b/etc/rhythmbox.profile
index 3215063fa..50838a15b 100644
--- a/etc/rhythmbox.profile
+++ b/etc/rhythmbox.profile
@@ -2,12 +2,13 @@
2include /etc/firejail/disable-common.inc 2include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 3include /etc/firejail/disable-programs.inc
4include /etc/firejail/disable-devel.inc 4include /etc/firejail/disable-devel.inc
5include /etc/firejail/disable-terminals.inc 5
6blacklist ${HOME}/.pki/nssdb 6blacklist ${HOME}/.pki/nssdb
7blacklist ${HOME}/.lastpass 7blacklist ${HOME}/.lastpass
8blacklist ${HOME}/.keepassx 8blacklist ${HOME}/.keepassx
9blacklist ${HOME}/.password-store 9blacklist ${HOME}/.password-store
10blacklist ${HOME}/.wine 10blacklist ${HOME}/.wine
11
11caps.drop all 12caps.drop all
12seccomp 13seccomp
13protocol unix,inet,inet6 14protocol unix,inet,inet6
diff --git a/etc/rtorrent.profile b/etc/rtorrent.profile
index 2c6689811..5575dcd63 100644
--- a/etc/rtorrent.profile
+++ b/etc/rtorrent.profile
@@ -2,7 +2,7 @@
2include /etc/firejail/disable-common.inc 2include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-terminals.inc 3include /etc/firejail/disable-terminals.inc
4include /etc/firejail/disable-devel.inc 4include /etc/firejail/disable-devel.inc
5include /etc/firejail/disable-terminals.inc 5
6caps.drop all 6caps.drop all
7seccomp 7seccomp
8protocol unix,inet,inet6 8protocol unix,inet,inet6
diff --git a/etc/seamonkey.profile b/etc/seamonkey.profile
index 08a6ad521..71a52b3bb 100644
--- a/etc/seamonkey.profile
+++ b/etc/seamonkey.profile
@@ -5,7 +5,6 @@ noblacklist ~/keepassx.kdbx
5include /etc/firejail/disable-common.inc 5include /etc/firejail/disable-common.inc
6include /etc/firejail/disable-programs.inc 6include /etc/firejail/disable-programs.inc
7include /etc/firejail/disable-devel.inc 7include /etc/firejail/disable-devel.inc
8include /etc/firejail/disable-terminals.inc
9 8
10caps.drop all 9caps.drop all
11seccomp 10seccomp
@@ -48,8 +47,6 @@ whitelist ~/.wine-pipelight64
48whitelist ~/.config/pipelight-widevine 47whitelist ~/.config/pipelight-widevine
49whitelist ~/.config/pipelight-silverlight5.1 48whitelist ~/.config/pipelight-silverlight5.1
50 49
51
52
53# experimental features 50# experimental features
54#private-etc passwd,group,hostname,hosts,localtime,nsswitch.conf,resolv.conf,gtk-2.0,pango,fonts,iceweasel,firefox,adobe,mime.types,mailcap,asound.conf,pulse 51#private-etc passwd,group,hostname,hosts,localtime,nsswitch.conf,resolv.conf,gtk-2.0,pango,fonts,iceweasel,firefox,adobe,mime.types,mailcap,asound.conf,pulse
55 52
diff --git a/etc/skype.profile b/etc/skype.profile
index 77f10e644..26feac1a4 100644
--- a/etc/skype.profile
+++ b/etc/skype.profile
@@ -3,7 +3,7 @@ noblacklist ${HOME}/.Skype
3include /etc/firejail/disable-common.inc 3include /etc/firejail/disable-common.inc
4include /etc/firejail/disable-programs.inc 4include /etc/firejail/disable-programs.inc
5include /etc/firejail/disable-devel.inc 5include /etc/firejail/disable-devel.inc
6include /etc/firejail/disable-terminals.inc 6
7caps.drop all 7caps.drop all
8netfilter 8netfilter
9noroot 9noroot
diff --git a/etc/ssh.profile b/etc/ssh.profile
index f0e33540a..32536c0a7 100644
--- a/etc/ssh.profile
+++ b/etc/ssh.profile
@@ -2,11 +2,12 @@
2noblacklist ~/.ssh 2noblacklist ~/.ssh
3include /etc/firejail/disable-common.inc 3include /etc/firejail/disable-common.inc
4include /etc/firejail/disable-programs.inc 4include /etc/firejail/disable-programs.inc
5include /etc/firejail/disable-terminals.inc 5
6blacklist ${HOME}/.pki/nssdb 6blacklist ${HOME}/.pki/nssdb
7blacklist ${HOME}/.lastpass 7blacklist ${HOME}/.lastpass
8blacklist ${HOME}/.keepassx 8blacklist ${HOME}/.keepassx
9blacklist ${HOME}/.password-store 9blacklist ${HOME}/.password-store
10
10caps.drop all 11caps.drop all
11seccomp 12seccomp
12protocol unix,inet,inet6 13protocol unix,inet,inet6
diff --git a/etc/steam.profile b/etc/steam.profile
index 7cfa21028..31ebf543e 100644
--- a/etc/steam.profile
+++ b/etc/steam.profile
@@ -4,7 +4,7 @@ noblacklist ${HOME}/.local/share/steam
4include /etc/firejail/disable-common.inc 4include /etc/firejail/disable-common.inc
5include /etc/firejail/disable-programs.inc 5include /etc/firejail/disable-programs.inc
6include /etc/firejail/disable-devel.inc 6include /etc/firejail/disable-devel.inc
7include /etc/firejail/disable-terminals.inc 7
8caps.drop all 8caps.drop all
9netfilter 9netfilter
10noroot 10noroot
diff --git a/etc/telegram.profile b/etc/telegram.profile
index acafdda00..df6b6a270 100644
--- a/etc/telegram.profile
+++ b/etc/telegram.profile
@@ -3,7 +3,6 @@ noblacklist ${HOME}/.TelegramDesktop
3include /etc/firejail/disable-common.inc 3include /etc/firejail/disable-common.inc
4include /etc/firejail/disable-programs.inc 4include /etc/firejail/disable-programs.inc
5include /etc/firejail/disable-devel.inc 5include /etc/firejail/disable-devel.inc
6include /etc/firejail/disable-terminals.inc
7 6
8caps.drop all 7caps.drop all
9seccomp 8seccomp
diff --git a/etc/totem.profile b/etc/totem.profile
index 2cff319a7..ad55e320a 100644
--- a/etc/totem.profile
+++ b/etc/totem.profile
@@ -2,12 +2,13 @@
2include /etc/firejail/disable-common.inc 2include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 3include /etc/firejail/disable-programs.inc
4include /etc/firejail/disable-devel.inc 4include /etc/firejail/disable-devel.inc
5include /etc/firejail/disable-terminals.inc 5
6blacklist ${HOME}/.pki/nssdb 6blacklist ${HOME}/.pki/nssdb
7blacklist ${HOME}/.lastpass 7blacklist ${HOME}/.lastpass
8blacklist ${HOME}/.keepassx 8blacklist ${HOME}/.keepassx
9blacklist ${HOME}/.password-store 9blacklist ${HOME}/.password-store
10blacklist ${HOME}/.wine 10blacklist ${HOME}/.wine
11
11caps.drop all 12caps.drop all
12seccomp 13seccomp
13protocol unix,inet,inet6 14protocol unix,inet,inet6
diff --git a/etc/transmission-gtk.profile b/etc/transmission-gtk.profile
index 269686fa1..ac685aee4 100644
--- a/etc/transmission-gtk.profile
+++ b/etc/transmission-gtk.profile
@@ -2,12 +2,13 @@
2include /etc/firejail/disable-common.inc 2include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 3include /etc/firejail/disable-programs.inc
4include /etc/firejail/disable-devel.inc 4include /etc/firejail/disable-devel.inc
5include /etc/firejail/disable-terminals.inc 5
6blacklist ${HOME}/.pki/nssdb 6blacklist ${HOME}/.pki/nssdb
7blacklist ${HOME}/.lastpass 7blacklist ${HOME}/.lastpass
8blacklist ${HOME}/.keepassx 8blacklist ${HOME}/.keepassx
9blacklist ${HOME}/.password-store 9blacklist ${HOME}/.password-store
10blacklist ${HOME}/.wine 10blacklist ${HOME}/.wine
11
11caps.drop all 12caps.drop all
12seccomp 13seccomp
13protocol unix,inet,inet6 14protocol unix,inet,inet6
diff --git a/etc/transmission-qt.profile b/etc/transmission-qt.profile
index d032752b4..b8dffbece 100644
--- a/etc/transmission-qt.profile
+++ b/etc/transmission-qt.profile
@@ -2,12 +2,13 @@
2include /etc/firejail/disable-common.inc 2include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 3include /etc/firejail/disable-programs.inc
4include /etc/firejail/disable-devel.inc 4include /etc/firejail/disable-devel.inc
5include /etc/firejail/disable-terminals.inc 5
6blacklist ${HOME}/.pki/nssdb 6blacklist ${HOME}/.pki/nssdb
7blacklist ${HOME}/.lastpass 7blacklist ${HOME}/.lastpass
8blacklist ${HOME}/.keepassx 8blacklist ${HOME}/.keepassx
9blacklist ${HOME}/.password-store 9blacklist ${HOME}/.password-store
10blacklist ${HOME}/.wine 10blacklist ${HOME}/.wine
11
11caps.drop all 12caps.drop all
12seccomp 13seccomp
13protocol unix,inet,inet6 14protocol unix,inet,inet6
diff --git a/etc/uget-gtk.profile b/etc/uget-gtk.profile
index 4a6544a12..6593075c8 100644
--- a/etc/uget-gtk.profile
+++ b/etc/uget-gtk.profile
@@ -2,12 +2,13 @@
2include /etc/firejail/disable-common.inc 2include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 3include /etc/firejail/disable-programs.inc
4include /etc/firejail/disable-devel.inc 4include /etc/firejail/disable-devel.inc
5include /etc/firejail/disable-terminals.inc 5
6caps.drop all 6caps.drop all
7seccomp 7seccomp
8protocol unix,inet,inet6 8protocol unix,inet,inet6
9netfilter 9netfilter
10noroot 10noroot
11
11whitelist ${DOWNLOADS} 12whitelist ${DOWNLOADS}
12mkdir ~/.config 13mkdir ~/.config
13mkdir ~/.config/uGet 14mkdir ~/.config/uGet
diff --git a/etc/unbound.profile b/etc/unbound.profile
index 594d67cf9..24ca88b03 100644
--- a/etc/unbound.profile
+++ b/etc/unbound.profile
@@ -4,7 +4,7 @@ noblacklist /usr/sbin
4include /etc/firejail/disable-common.inc 4include /etc/firejail/disable-common.inc
5include /etc/firejail/disable-programs.inc 5include /etc/firejail/disable-programs.inc
6include /etc/firejail/disable-devel.inc 6include /etc/firejail/disable-devel.inc
7include /etc/firejail/disable-terminals.inc 7
8private 8private
9private-dev 9private-dev
10seccomp.drop mount,umount2,ptrace,kexec_load,kexec_file_load,open_by_handle_at,init_module,finit_module,delete_module,iopl,ioperm,swapon,swapoff,syslog,process_vm_readv,process_vm_writev,sysfs,_sysctl,adjtimex,clock_adjtime,lookup_dcookie,perf_event_open,fanotify_init,kcmp,add_key,request_key,keyctl,uselib,acct,modify_ldt,pivot_root,io_setup,io_destroy,io_getevents,io_submit,io_cancel,remap_file_pages,mbind,get_mempolicy,set_mempolicy,migrate_pages,move_pages,vmsplice,perf_event_open 10seccomp.drop mount,umount2,ptrace,kexec_load,kexec_file_load,open_by_handle_at,init_module,finit_module,delete_module,iopl,ioperm,swapon,swapoff,syslog,process_vm_readv,process_vm_writev,sysfs,_sysctl,adjtimex,clock_adjtime,lookup_dcookie,perf_event_open,fanotify_init,kcmp,add_key,request_key,keyctl,uselib,acct,modify_ldt,pivot_root,io_setup,io_destroy,io_getevents,io_submit,io_cancel,remap_file_pages,mbind,get_mempolicy,set_mempolicy,migrate_pages,move_pages,vmsplice,perf_event_open
diff --git a/etc/vivaldi.profile b/etc/vivaldi.profile
index e039c4676..a4ab60e6c 100644
--- a/etc/vivaldi.profile
+++ b/etc/vivaldi.profile
@@ -5,7 +5,6 @@ noblacklist ~/keepassx.kdbx
5include /etc/firejail/disable-common.inc 5include /etc/firejail/disable-common.inc
6include /etc/firejail/disable-programs.inc 6include /etc/firejail/disable-programs.inc
7include /etc/firejail/disable-devel.inc 7include /etc/firejail/disable-devel.inc
8include /etc/firejail/disable-terminals.inc
9 8
10netfilter 9netfilter
11 10
diff --git a/etc/vlc.profile b/etc/vlc.profile
index 980d2816f..7cd913040 100644
--- a/etc/vlc.profile
+++ b/etc/vlc.profile
@@ -3,12 +3,13 @@ noblacklist ${HOME}/.config/vlc
3include /etc/firejail/disable-common.inc 3include /etc/firejail/disable-common.inc
4include /etc/firejail/disable-programs.inc 4include /etc/firejail/disable-programs.inc
5include /etc/firejail/disable-devel.inc 5include /etc/firejail/disable-devel.inc
6include /etc/firejail/disable-terminals.inc 6
7blacklist ${HOME}/.pki/nssdb 7blacklist ${HOME}/.pki/nssdb
8blacklist ${HOME}/.lastpass 8blacklist ${HOME}/.lastpass
9blacklist ${HOME}/.keepassx 9blacklist ${HOME}/.keepassx
10blacklist ${HOME}/.password-store 10blacklist ${HOME}/.password-store
11blacklist ${HOME}/.wine 11blacklist ${HOME}/.wine
12
12caps.drop all 13caps.drop all
13seccomp 14seccomp
14protocol unix,inet,inet6 15protocol unix,inet,inet6
diff --git a/etc/weechat.profile b/etc/weechat.profile
index ec305b45b..280a5f9d8 100644
--- a/etc/weechat.profile
+++ b/etc/weechat.profile
@@ -2,7 +2,7 @@
2noblacklist ${HOME}/.weechat 2noblacklist ${HOME}/.weechat
3include /etc/firejail/disable-common.inc 3include /etc/firejail/disable-common.inc
4include /etc/firejail/disable-programs.inc 4include /etc/firejail/disable-programs.inc
5include /etc/firejail/disable-terminals.inc 5
6caps.drop all 6caps.drop all
7seccomp 7seccomp
8protocol unix,inet,inet6 8protocol unix,inet,inet6
diff --git a/etc/wesnoth.profile b/etc/wesnoth.profile
index 7a2ade1fe..4075232d2 100644
--- a/etc/wesnoth.profile
+++ b/etc/wesnoth.profile
@@ -3,7 +3,6 @@
3include /etc/firejail/disable-common.inc 3include /etc/firejail/disable-common.inc
4include /etc/firejail/disable-programs.inc 4include /etc/firejail/disable-programs.inc
5include /etc/firejail/disable-devel.inc 5include /etc/firejail/disable-devel.inc
6include /etc/firejail/disable-terminals.inc
7 6
8caps.drop all 7caps.drop all
9seccomp 8seccomp
diff --git a/etc/wine.profile b/etc/wine.profile
index 993037794..f93fa6dc2 100644
--- a/etc/wine.profile
+++ b/etc/wine.profile
@@ -5,7 +5,7 @@ noblacklist ${HOME}/.wine
5include /etc/firejail/disable-common.inc 5include /etc/firejail/disable-common.inc
6include /etc/firejail/disable-programs.inc 6include /etc/firejail/disable-programs.inc
7include /etc/firejail/disable-devel.inc 7include /etc/firejail/disable-devel.inc
8include /etc/firejail/disable-terminals.inc 8
9caps.drop all 9caps.drop all
10netfilter 10netfilter
11noroot 11noroot
diff --git a/etc/xchat.profile b/etc/xchat.profile
index 552918750..ae1a6de53 100644
--- a/etc/xchat.profile
+++ b/etc/xchat.profile
@@ -3,7 +3,7 @@ noblacklist ${HOME}/.config/xchat
3include /etc/firejail/disable-common.inc 3include /etc/firejail/disable-common.inc
4include /etc/firejail/disable-programs.inc 4include /etc/firejail/disable-programs.inc
5include /etc/firejail/disable-devel.inc 5include /etc/firejail/disable-devel.inc
6include /etc/firejail/disable-terminals.inc 6
7blacklist ${HOME}/.wine 7blacklist ${HOME}/.wine
8caps.drop all 8caps.drop all
9seccomp 9seccomp
diff --git a/platform/debian/conffiles b/platform/debian/conffiles
index 0d37a464b..64a7006a3 100644
--- a/platform/debian/conffiles
+++ b/platform/debian/conffiles
@@ -63,7 +63,6 @@
63/etc/firejail/Mathematica.profile 63/etc/firejail/Mathematica.profile
64/etc/firejail/uget-gtk.profile 64/etc/firejail/uget-gtk.profile
65/etc/firejail/mupen64plus.profile 65/etc/firejail/mupen64plus.profile
66/etc/firejail/disable-terminals.inc
67/etc/firejail/lxterminal.profile 66/etc/firejail/lxterminal.profile
68/etc/firejail/cherrytree.profile 67/etc/firejail/cherrytree.profile
69/etc/firejail/wesnoth.profile 68/etc/firejail/wesnoth.profile