summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLibravatar Tad <tad@spotco.us>2017-10-10 12:39:26 -0400
committerLibravatar Tad <tad@spotco.us>2017-10-10 12:39:26 -0400
commit9627229b6ffe1566ffd26f9d3a8be2938784cc21 (patch)
treea08f0866e11f07fe239982957d5e03250a2b57e6
parentprivate-lib (diff)
downloadfirejail-9627229b6ffe1566ffd26f9d3a8be2938784cc21.tar.gz
firejail-9627229b6ffe1566ffd26f9d3a8be2938784cc21.tar.zst
firejail-9627229b6ffe1566ffd26f9d3a8be2938784cc21.zip
Add a profile for ZAProxy
-rw-r--r--README.md2
-rw-r--r--etc/disable-programs.inc1
-rw-r--r--etc/zaproxy.profile42
-rw-r--r--src/firecfg/firecfg.config2
4 files changed, 46 insertions, 1 deletions
diff --git a/README.md b/README.md
index 578ae10e9..549d3fdc4 100644
--- a/README.md
+++ b/README.md
@@ -181,4 +181,4 @@ calligrawords, cin, dooble, dooble-qt4, fetchmail, freecad, freecadcmd, google-e
181imagej, karbon, kdenlive, krita, linphone, lmms, macrofusion, mpd, natron, Natron, 181imagej, karbon, kdenlive, krita, linphone, lmms, macrofusion, mpd, natron, Natron,
182ricochet, shotcut, teamspeak3, tor, tor-browser-en, Viber, x-terminal-emulator, zart, 182ricochet, shotcut, teamspeak3, tor, tor-browser-en, Viber, x-terminal-emulator, zart,
183conky, arch-audit, ffmpeg, bluefish, cliqz, cinelerra, openshot-qt, pinta, uefitool, 183conky, arch-audit, ffmpeg, bluefish, cliqz, cinelerra, openshot-qt, pinta, uefitool,
184aosp, pdfmod, gnome-ring, signal-dekstop, xcalc 184aosp, pdfmod, gnome-ring, signal-dekstop, xcalc, zaproxy
diff --git a/etc/disable-programs.inc b/etc/disable-programs.inc
index 064e60294..0e5400dd6 100644
--- a/etc/disable-programs.inc
+++ b/etc/disable-programs.inc
@@ -20,6 +20,7 @@ blacklist ${HOME}/.TelegramDesktop
20blacklist ${HOME}/.ViberPC 20blacklist ${HOME}/.ViberPC
21blacklist ${HOME}/.VirtualBox 21blacklist ${HOME}/.VirtualBox
22blacklist ${HOME}/.Wolfram Research 22blacklist ${HOME}/.Wolfram Research
23blacklist ${HOME}/.ZAP
23blacklist ${HOME}/.aMule 24blacklist ${HOME}/.aMule
24blacklist ${HOME}/.android 25blacklist ${HOME}/.android
25blacklist ${HOME}/.arduino15 26blacklist ${HOME}/.arduino15
diff --git a/etc/zaproxy.profile b/etc/zaproxy.profile
new file mode 100644
index 000000000..3cce79a2e
--- /dev/null
+++ b/etc/zaproxy.profile
@@ -0,0 +1,42 @@
1# Firejail profile for zaproxy
2# This file is overwritten after every install/update
3# Persistent local customizations
4include /etc/firejail/zaproxy.local
5# Persistent global definitions
6include /etc/firejail/globals.local
7
8noblacklist ${HOME}/.java
9noblacklist ${HOME}/.ZAP
10
11include /etc/firejail/disable-common.inc
12include /etc/firejail/disable-devel.inc
13include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc
15
16mkdir ${HOME}/.ZAP
17whitelist ${HOME}/.java
18whitelist ${HOME}/.ZAP
19include /etc/firejail/whitelist-common.inc
20include /etc/firejail/whitelist-var-common.inc
21
22caps.drop all
23ipc-namespace
24netfilter
25no3d
26nodvd
27nogroups
28nonewprivs
29noroot
30nosound
31notv
32novideo
33protocol unix,inet,inet6
34seccomp
35shell none
36
37disable-mnt
38private-dev
39private-tmp
40
41noexec ${HOME}
42noexec /tmp
diff --git a/src/firecfg/firecfg.config b/src/firecfg/firecfg.config
index 3d7d23fe7..600bd8841 100644
--- a/src/firecfg/firecfg.config
+++ b/src/firecfg/firecfg.config
@@ -286,6 +286,7 @@ sdat2img
286seamonkey 286seamonkey
287seamonkey-bin 287seamonkey-bin
288shotcut 288shotcut
289signal-desktop
289silentarmy 290silentarmy
290simple-scan 291simple-scan
291simutrans 292simutrans
@@ -365,6 +366,7 @@ xreader
365xviewer 366xviewer
366yandex-browser 367yandex-browser
367youtube-dl 368youtube-dl
369zaproxy
368zart 370zart
369zathura 371zathura
370zoom 372zoom