summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLibravatar startx2017 <vradu.startx@yandex.com>2018-01-15 08:28:47 -0500
committerLibravatar startx2017 <vradu.startx@yandex.com>2018-01-15 08:28:47 -0500
commit73d49c638fa51ba56b01605e7079c8e0556e755b (patch)
treecf02716c4ad722255d3e7987ab4e2c01143d92e9
parentmove copyright statement to 2018 (diff)
parentFix #1724, Tor browser not working on Ubuntu and Fedora (diff)
downloadfirejail-73d49c638fa51ba56b01605e7079c8e0556e755b.tar.gz
firejail-73d49c638fa51ba56b01605e7079c8e0556e755b.tar.zst
firejail-73d49c638fa51ba56b01605e7079c8e0556e755b.zip
Merge branch 'master' of https://github.com/netblue30/firejail
-rw-r--r--etc/disable-programs.inc1
-rw-r--r--etc/ideaIC.profile10
-rw-r--r--etc/onionshare-gui.profile35
-rw-r--r--etc/torbrowser-launcher.profile2
-rw-r--r--src/firecfg/firecfg.config24
5 files changed, 71 insertions, 1 deletions
diff --git a/etc/disable-programs.inc b/etc/disable-programs.inc
index e6d425df2..667c209ed 100644
--- a/etc/disable-programs.inc
+++ b/etc/disable-programs.inc
@@ -155,6 +155,7 @@ blacklist ${HOME}/.config/netsurf
155blacklist ${HOME}/.config/nheko 155blacklist ${HOME}/.config/nheko
156blacklist ${HOME}/.config/okularpartrc 156blacklist ${HOME}/.config/okularpartrc
157blacklist ${HOME}/.config/okularrc 157blacklist ${HOME}/.config/okularrc
158blacklist ${HOME}/.config/onionshare
158blacklist ${HOME}/.config/opera 159blacklist ${HOME}/.config/opera
159blacklist ${HOME}/.config/opera-beta 160blacklist ${HOME}/.config/opera-beta
160blacklist ${HOME}/.config/orage 161blacklist ${HOME}/.config/orage
diff --git a/etc/ideaIC.profile b/etc/ideaIC.profile
new file mode 100644
index 000000000..f7a69fa94
--- /dev/null
+++ b/etc/ideaIC.profile
@@ -0,0 +1,10 @@
1# Firejail profile for ideaIC
2# This file is overwritten after every install/update
3# Persistent local customizations
4include /etc/firejail/ideaIC.local
5# Persistent global definitions
6include /etc/firejail/globals.local
7
8
9# Redirect
10include /etc/firejail/idea.sh.profile
diff --git a/etc/onionshare-gui.profile b/etc/onionshare-gui.profile
new file mode 100644
index 000000000..7220f7e1c
--- /dev/null
+++ b/etc/onionshare-gui.profile
@@ -0,0 +1,35 @@
1# Firejail profile for onionshare-gui
2# This file is overwritten after every install/update
3# Persistent local customizations
4include /etc/firejail/onionshare-gui.local
5# Persistent global definitions
6include /etc/firejail/globals.local
7
8noblacklist ${HOME}/.config/onionshare
9
10include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-passwdmgr.inc
13include /etc/firejail/disable-programs.inc
14
15caps.drop all
16ipc-namespace
17netfilter
18no3d
19nodvd
20nogroups
21nonewprivs
22noroot
23nosound
24notv
25novideo
26protocol unix,inet,inet6
27seccomp
28shell none
29
30private-dev
31private-tmp
32
33memory-deny-write-execute
34noexec ${HOME}
35noexec /tmp
diff --git a/etc/torbrowser-launcher.profile b/etc/torbrowser-launcher.profile
index 51a5d7735..49b083919 100644
--- a/etc/torbrowser-launcher.profile
+++ b/etc/torbrowser-launcher.profile
@@ -33,7 +33,7 @@ tracelog
33disable-mnt 33disable-mnt
34private-bin bash,cp,dirname,env,expr,file,getconf,gpg,grep,id,ln,mkdir,python*,readlink,rm,sed,sh,tail,test,tor-browser-en,torbrowser-launcher 34private-bin bash,cp,dirname,env,expr,file,getconf,gpg,grep,id,ln,mkdir,python*,readlink,rm,sed,sh,tail,test,tor-browser-en,torbrowser-launcher
35private-dev 35private-dev
36private-etc fonts 36private-etc fonts,hostname,hosts,resolv.conf,pki,ssl,ca-certificates
37private-tmp 37private-tmp
38 38
39noexec /tmp 39noexec /tmp
diff --git a/src/firecfg/firecfg.config b/src/firecfg/firecfg.config
index 6f6dd3f06..3dbd8df1a 100644
--- a/src/firecfg/firecfg.config
+++ b/src/firecfg/firecfg.config
@@ -21,6 +21,7 @@ amule
21android-studio 21android-studio
22apktool 22apktool
23arch-audit 23arch-audit
24archaudit-report
24ardour4 25ardour4
25ardour5 26ardour5
26arduino 27arduino
@@ -42,6 +43,7 @@ bleachbit
42blender 43blender
43bless 44bless
44bluefish 45bluefish
46bnox
45brackets 47brackets
46brasero 48brasero
47brave 49brave
@@ -94,6 +96,7 @@ dropbox
94ebook-viewer 96ebook-viewer
95elinks 97elinks
96empathy 98empathy
99enpass
97eog 100eog
98eom 101eom
99epiphany 102epiphany
@@ -170,6 +173,7 @@ icecat
170icedove 173icedove
171iceweasel 174iceweasel
172idea.sh 175idea.sh
176ideaIC
173imagej 177imagej
174img2txt 178img2txt
175inkscape 179inkscape
@@ -250,6 +254,7 @@ nylas
250obs 254obs
251odt2txt 255odt2txt
252okular 256okular
257onionshare-gui
253open-invaders 258open-invaders
254openshot 259openshot
255openshot-qt 260openshot-qt
@@ -270,6 +275,7 @@ pinta
270pithos 275pithos
271pitivi 276pitivi
272pix 277pix
278playonlinux
273pluma 279pluma
274polari 280polari
275psi-plus 281psi-plus
@@ -306,6 +312,7 @@ skype
306skypeforlinux 312skypeforlinux
307slack 313slack
308smplayer 314smplayer
315smtube
309soffice 316soffice
310soundconverter 317soundconverter
311spotify 318spotify
@@ -317,13 +324,30 @@ steam
317stellarium 324stellarium
318strings 325strings
319supertux2 326supertux2
327surf
328sylpheed
320synfigstudio 329synfigstudio
321teamspeak3 330teamspeak3
322telegram 331telegram
323telegram-desktop 332telegram-desktop
324terasology 333terasology
325thunderbird 334thunderbird
335tor-browser-ar
326tor-browser-en 336tor-browser-en
337tor-browser-en-us
338tor-browser-es-es
339tor-browser-es
340tor-browser-fa
341tor-browser-fr
342tor-browser-it
343tor-browser-ja
344tor-browser-ko
345torbrowser-launcher
346tor-browser-pl
347tor-browser-pt-br
348tor-browser-ru
349tor-browser-vi
350tor-browser-zh-cn
327totem 351totem
328tracker 352tracker
329transmission-cli 353transmission-cli