summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLibravatar Your Name <you@example.com>2018-03-24 19:59:50 -0400
committerLibravatar Your Name <you@example.com>2018-03-24 19:59:50 -0400
commit5ae3e801d91f386ab36dbe8fc3d8b50cd30004db (patch)
tree2379164b209d33056b4ae0aadfe9fa72ba25e7fc
parentfix akonadi_control, enable it in firecfg for a better default (diff)
downloadfirejail-5ae3e801d91f386ab36dbe8fc3d8b50cd30004db.tar.gz
firejail-5ae3e801d91f386ab36dbe8fc3d8b50cd30004db.tar.zst
firejail-5ae3e801d91f386ab36dbe8fc3d8b50cd30004db.zip
fix
-rw-r--r--etc/blender-2.8.profile30
-rw-r--r--etc/thunderbird-beta.profile35
2 files changed, 65 insertions, 0 deletions
diff --git a/etc/blender-2.8.profile b/etc/blender-2.8.profile
new file mode 100644
index 000000000..29df27759
--- /dev/null
+++ b/etc/blender-2.8.profile
@@ -0,0 +1,30 @@
1# Firejail profile for blender
2# This file is overwritten after every install/update
3# Persistent local customizations
4include /etc/firejail/blender.local
5# Persistent global definitions
6include /etc/firejail/globals.local
7
8noblacklist ${HOME}/.config/blender
9
10include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-passwdmgr.inc
13include /etc/firejail/disable-programs.inc
14
15caps.drop all
16netfilter
17nodvd
18nogroups
19nonewprivs
20noroot
21notv
22protocol unix,inet,inet6,netlink
23seccomp
24shell none
25
26private-dev
27private-tmp
28
29noexec ${HOME}
30noexec /tmp
diff --git a/etc/thunderbird-beta.profile b/etc/thunderbird-beta.profile
new file mode 100644
index 000000000..fb1ee46e2
--- /dev/null
+++ b/etc/thunderbird-beta.profile
@@ -0,0 +1,35 @@
1# Firejail profile for thunderbird
2# This file is overwritten after every install/update
3# Persistent local customizations
4include /etc/firejail/thunderbird.local
5# Persistent global definitions
6include /etc/firejail/globals.local
7
8# Users have thunderbird set to open a browser by clicking a link in an email
9# We are not allowed to blacklist browser-specific directories
10whitelist /opt/thunderbird-beta
11noblacklist ${HOME}/.cache/thunderbird
12noblacklist ${HOME}/.gnupg
13# noblacklist ${HOME}/.icedove
14noblacklist ${HOME}/.thunderbird
15
16mkdir ${HOME}/.cache/thunderbird
17mkdir ${HOME}/.gnupg
18# mkdir ${HOME}/.icedove
19mkdir ${HOME}/.thunderbird
20whitelist ${HOME}/.cache/thunderbird
21whitelist ${HOME}/.gnupg
22# whitelist ${HOME}/.icedove
23whitelist ${HOME}/.thunderbird
24
25# We need the real /tmp for data exchange when xdg-open handles email attachments on KDE
26ignore private-tmp
27# machine-id breaks audio in browsers; enable it when sound is not required
28# machine-id
29read-only ${HOME}/.config/mimeapps.list
30# writable-run-user is needed for signing and encrypting emails
31writable-run-user
32
33# allow browsers
34# Redirect
35include /etc/firejail/firefox.profile