summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLibravatar SkewedZeppelin <8296104+SkewedZeppelin@users.noreply.github.com>2019-05-13 11:07:21 +0000
committerLibravatar GitHub <noreply@github.com>2019-05-13 11:07:21 +0000
commite8e1eed08d9e405675a6d034559426f85a7400a1 (patch)
treecf33e043c11cbbd5a5c9a09f4966bbd0880ed052
parentharden & fix xiphos.profile (diff)
parentRemove trailing commas in cantata.profile (diff)
downloadfirejail-e8e1eed08d9e405675a6d034559426f85a7400a1.tar.gz
firejail-e8e1eed08d9e405675a6d034559426f85a7400a1.tar.zst
firejail-e8e1eed08d9e405675a6d034559426f85a7400a1.zip
Merge pull request #2691 from curiosity-seeker/master
cantata.profile
-rw-r--r--etc/cantata.profile40
-rw-r--r--etc/disable-programs.inc3
-rw-r--r--src/firecfg/firecfg.config1
3 files changed, 44 insertions, 0 deletions
diff --git a/etc/cantata.profile b/etc/cantata.profile
new file mode 100644
index 000000000..e4a4de9c1
--- /dev/null
+++ b/etc/cantata.profile
@@ -0,0 +1,40 @@
1# Firejail profile for Cantata
2# Description: Multimedia player - Qt5 client for the music Player daemon (MPD)
3# This file is overwritten during software install.
4# Persistent local customizations
5include cantata.local
6# Persistent global definitions
7include globals.local
8
9noblacklist ${HOME}/.cache/cantata
10noblacklist ${HOME}/.config/cantata
11noblacklist ${HOME}/.local/share/cantata
12noblacklist ${MUSIC}
13
14noblacklist ${PATH}/perl
15noblacklist /usr/lib/perl*
16noblacklist /usr/share/perl*
17
18include disable-common.inc
19include disable-devel.inc
20include disable-exec.inc
21include disable-interpreters.inc
22include disable-passwdmgr.inc
23include disable-programs.inc
24include disable-xdg.inc
25
26# apparmor
27caps.drop all
28ipc-namespace
29netfilter
30nonewprivs
31noroot
32nou2f
33novideo
34protocol unix,inet,inet6,netlink
35seccomp
36shell none
37
38# private-etc samba,gcrypt,drirc,fonts,mpd.conf,kde5rc,passwd,xdg,hosts,ssl
39private-bin cantata,mpd,perl
40private-dev
diff --git a/etc/disable-programs.inc b/etc/disable-programs.inc
index 7de2a620f..cd0cb1f2e 100644
--- a/etc/disable-programs.inc
+++ b/etc/disable-programs.inc
@@ -128,6 +128,7 @@ blacklist ${HOME}/.config/brasero
128blacklist ${HOME}/.config/brave 128blacklist ${HOME}/.config/brave
129blacklist ${HOME}/.config/caja 129blacklist ${HOME}/.config/caja
130blacklist ${HOME}/.config/calibre 130blacklist ${HOME}/.config/calibre
131blacklist ${HOME}/.config/cantata
131blacklist ${HOME}/.config/catfish 132blacklist ${HOME}/.config/catfish
132blacklist ${HOME}/.config/celluloid 133blacklist ${HOME}/.config/celluloid
133blacklist ${HOME}/.config/cherrytree 134blacklist ${HOME}/.config/cherrytree
@@ -451,6 +452,7 @@ blacklist ${HOME}/.local/share/aspyr-media
451blacklist ${HOME}/.local/share/baloo 452blacklist ${HOME}/.local/share/baloo
452blacklist ${HOME}/.local/share/bibletime 453blacklist ${HOME}/.local/share/bibletime
453blacklist ${HOME}/.local/share/caja-python 454blacklist ${HOME}/.local/share/caja-python
455blacklist ${HOME}/.local/share/cantata
454blacklist ${HOME}/.local/share/cdprojektred 456blacklist ${HOME}/.local/share/cdprojektred
455blacklist ${HOME}/.local/share/clipit 457blacklist ${HOME}/.local/share/clipit
456blacklist ${HOME}/.local/share/contacts 458blacklist ${HOME}/.local/share/contacts
@@ -648,6 +650,7 @@ blacklist ${HOME}/.cache/attic
648blacklist ${HOME}/.cache/bnox 650blacklist ${HOME}/.cache/bnox
649blacklist ${HOME}/.cache/borg 651blacklist ${HOME}/.cache/borg
650blacklist ${HOME}/.cache/calibre 652blacklist ${HOME}/.cache/calibre
653blacklist ${HOME}/.cache/cantata
651blacklist ${HOME}/.cache/champlain 654blacklist ${HOME}/.cache/champlain
652blacklist ${HOME}/.cache/chromium 655blacklist ${HOME}/.cache/chromium
653blacklist ${HOME}/.cache/chromium-dev 656blacklist ${HOME}/.cache/chromium-dev
diff --git a/src/firecfg/firecfg.config b/src/firecfg/firecfg.config
index 2d4902b91..aba0e9f60 100644
--- a/src/firecfg/firecfg.config
+++ b/src/firecfg/firecfg.config
@@ -92,6 +92,7 @@ calligraplanwork
92calligrasheets 92calligrasheets
93calligrastage 93calligrastage
94calligrawords 94calligrawords
95cantata
95catfish 96catfish
96celluloid 97celluloid
97checkbashisms 98checkbashisms