summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLibravatar rusty-snake <print_hello_world+Public@protonmail.com>2019-06-14 10:22:34 +0200
committerLibravatar rusty-snake <print_hello_world+Public@protonmail.com>2019-06-14 10:22:34 +0200
commit7319615509e41a28aadb1316f3a4f06cffbb7b81 (patch)
tree32bc0c4590e5407be4fcd9febeff4da341cd2c05
parentMerge branch 'master' of http://github.com/netblue30/firejail (diff)
downloadfirejail-7319615509e41a28aadb1316f3a4f06cffbb7b81.tar.gz
firejail-7319615509e41a28aadb1316f3a4f06cffbb7b81.tar.zst
firejail-7319615509e41a28aadb1316f3a4f06cffbb7b81.zip
New profiles: newsbeuter, keepassxc-{cli,proxy}
-rw-r--r--README3
-rw-r--r--README.md2
-rw-r--r--RELNOTES3
-rw-r--r--etc/disable-programs.inc2
-rw-r--r--etc/keepassxc-cli.profile12
-rw-r--r--etc/keepassxc-proxy.profile11
-rw-r--r--etc/keepassxc.profile4
-rw-r--r--etc/newsbeuter.profile21
-rw-r--r--src/firecfg/firecfg.config4
9 files changed, 57 insertions, 5 deletions
diff --git a/README b/README
index 22ae557db..a4bc6363e 100644
--- a/README
+++ b/README
@@ -571,7 +571,8 @@ rusty-snake (https://github.com/rusty-snake)
571 - added profiles: kid3-qt, kid3-cli, anki, utox, mp3splt, mp3wrap 571 - added profiles: kid3-qt, kid3-cli, anki, utox, mp3splt, mp3wrap
572 - added profiles: oggsplt, flacsplt, cheese, inkview, mp3splt-gtk 572 - added profiles: oggsplt, flacsplt, cheese, inkview, mp3splt-gtk
573 - added profiles: ktouch, yelp, klatexformula, klatexformula_cmdl 573 - added profiles: ktouch, yelp, klatexformula, klatexformula_cmdl
574 - added profiles: pandoc, gnome-sound-recorder, godot 574 - added profiles: pandoc, gnome-sound-recorder, godot, newsbeuter
575 - added profiles: keepassxc-cli, keepassxc-proxy
575 - many profile fixing and hardening 576 - many profile fixing and hardening
576 - some typo fixes 577 - some typo fixes
577 - added profile templates 578 - added profile templates
diff --git a/README.md b/README.md
index 879a2eeed..fea4e9c97 100644
--- a/README.md
+++ b/README.md
@@ -111,4 +111,4 @@ We also keep a list of profile fixes for previous released versions in [etc-fixe
111 111
112## New profiles: 112## New profiles:
113 113
114klatexformula, klatexformula_cmdl, links, pandoc, qgis, teams-for-linux, xlinks, OpenArena, gnome-sound-recorder, godot, tcpdump, tshark 114klatexformula, klatexformula_cmdl, links, pandoc, qgis, teams-for-linux, xlinks, OpenArena, gnome-sound-recorder, godot, tcpdump, tshark, keepassxc-cli, keepassxc-proxy, newsbeuter
diff --git a/RELNOTES b/RELNOTES
index 0ecb40688..eec446dfe 100644
--- a/RELNOTES
+++ b/RELNOTES
@@ -3,7 +3,8 @@ firejail (0.9.61) baseline; urgency=low
3 * profile templates 3 * profile templates
4 * new profiles: qgis, klatexformula, klatexformula_cmdl, links, xlinks 4 * new profiles: qgis, klatexformula, klatexformula_cmdl, links, xlinks
5 * new profiles: pandoc, teams-for-linux, OpenArena, gnome-sound-recorder 5 * new profiles: pandoc, teams-for-linux, OpenArena, gnome-sound-recorder
6 * new profiles: godot, tcpdump, tshark 6 * new profiles: godot, tcpdump, tshark, newsbeuter, keepassxc-cli
7 * new profiles: keepassxc-proxy
7 -- netblue30 <netblue30@yahoo.com> Sat, 1 Jun 2019 08:00:00 -0500 8 -- netblue30 <netblue30@yahoo.com> Sat, 1 Jun 2019 08:00:00 -0500
8 9
9firejail (0.9.60) baseline; urgency=low 10firejail (0.9.60) baseline; urgency=low
diff --git a/etc/disable-programs.inc b/etc/disable-programs.inc
index 356c8209c..fb7e02d0b 100644
--- a/etc/disable-programs.inc
+++ b/etc/disable-programs.inc
@@ -239,6 +239,7 @@ blacklist ${HOME}/.config/nano
239blacklist ${HOME}/.config/nautilus 239blacklist ${HOME}/.config/nautilus
240blacklist ${HOME}/.config/nemo 240blacklist ${HOME}/.config/nemo
241blacklist ${HOME}/.config/netsurf 241blacklist ${HOME}/.config/netsurf
242blacklist ${HOME}/.config/newsbeuter
242blacklist ${HOME}/.config/nheko 243blacklist ${HOME}/.config/nheko
243blacklist ${HOME}/.config/NitroShare 244blacklist ${HOME}/.config/NitroShare
244blacklist ${HOME}/.config/nomacs 245blacklist ${HOME}/.config/nomacs
@@ -574,6 +575,7 @@ blacklist ${HOME}/.multimc5
574blacklist ${HOME}/.nanorc 575blacklist ${HOME}/.nanorc
575blacklist ${HOME}/.netactview 576blacklist ${HOME}/.netactview
576blacklist ${HOME}/.neverball 577blacklist ${HOME}/.neverball
578blacklist ${HOME}/.newsbeuter
577blacklist ${HOME}/.newsboat 579blacklist ${HOME}/.newsboat
578blacklist ${HOME}/.nv 580blacklist ${HOME}/.nv
579blacklist ${HOME}/.nylas-mail 581blacklist ${HOME}/.nylas-mail
diff --git a/etc/keepassxc-cli.profile b/etc/keepassxc-cli.profile
new file mode 100644
index 000000000..6f657e7de
--- /dev/null
+++ b/etc/keepassxc-cli.profile
@@ -0,0 +1,12 @@
1# Firejail profile for keepassxc-cli
2# Description: command line interface for KeePassXC
3# This file is overwritten after every install/update
4# Persistent local customizations
5include keepassxc-cli.local
6# Persistent global definitions
7# added by included profile
8#include globals.local
9
10
11# Redirect
12include keepassxc.profile
diff --git a/etc/keepassxc-proxy.profile b/etc/keepassxc-proxy.profile
new file mode 100644
index 000000000..79666aee2
--- /dev/null
+++ b/etc/keepassxc-proxy.profile
@@ -0,0 +1,11 @@
1# Firejail profile for keepassxc-cli
2# This file is overwritten after every install/update
3# Persistent local customizations
4include keepassxc-proxy.local
5# Persistent global definitions
6# added by included profile
7#include globals.local
8
9
10# Redirect
11include keepassxc.profile
diff --git a/etc/keepassxc.profile b/etc/keepassxc.profile
index c1adfd516..6ef02ad47 100644
--- a/etc/keepassxc.profile
+++ b/etc/keepassxc.profile
@@ -37,11 +37,11 @@ nosound
37notv 37notv
38nou2f 38nou2f
39novideo 39novideo
40protocol netlink,unix 40protocol unix,netlink
41seccomp 41seccomp
42shell none 42shell none
43 43
44private-bin keepassxc,keepassxc-proxy 44private-bin keepassxc,keepassxc-cli,keepassxc-proxy
45private-dev 45private-dev
46private-etc alternatives,fonts,ld.so.cache,machine-id 46private-etc alternatives,fonts,ld.so.cache,machine-id
47private-tmp 47private-tmp
diff --git a/etc/newsbeuter.profile b/etc/newsbeuter.profile
new file mode 100644
index 000000000..059c2156d
--- /dev/null
+++ b/etc/newsbeuter.profile
@@ -0,0 +1,21 @@
1# Firejail profile for Newsboat
2# Description: Text based Atom/RSS feed reader
3# This file is overwritten after every install/update
4# Persistent local customizations
5include newsbeuter.local
6# Persistent global definitions
7# added by included profile
8#include globals.local
9
10noblacklist ${HOME}/.config/newsbeuter
11noblacklist ${HOME}/.newsbeuter
12
13mkdir ${HOME}/.config/newsbeuter
14mkdir ${HOME}/.newsbeuter
15whitelist ${HOME}/.config/newsbeuter
16whitelist ${HOME}/.newsbeuter
17
18private-bin newsbeuter
19
20# Redirect
21include newsboat.profile
diff --git a/src/firecfg/firecfg.config b/src/firecfg/firecfg.config
index d1855d6f7..0f00ca275 100644
--- a/src/firecfg/firecfg.config
+++ b/src/firecfg/firecfg.config
@@ -301,6 +301,8 @@ keepass2
301keepassx 301keepassx
302keepassx2 302keepassx2
303keepassxc 303keepassxc
304keepassxc-cli
305keepassxc-proxy
304kget 306kget
305kid3 307kid3
306kid3-cli 308kid3-cli
@@ -400,6 +402,7 @@ netactview
400nethack 402nethack
401netsurf 403netsurf
402neverball 404neverball
405newsbeuter
403newsboat 406newsboat
404nheko 407nheko
405nitroshare 408nitroshare
@@ -585,6 +588,7 @@ transmission-remote-gtk
585transmission-show 588transmission-show
586tremulous 589tremulous
587truecraft 590truecraft
591tshark
588tuxguitar 592tuxguitar
589uefitool 593uefitool
590uget-gtk 594uget-gtk