aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLibravatar Nex <nex@nex.sx>2020-12-29 17:53:40 +0100
committerLibravatar Nex <nex@nex.sx>2020-12-29 17:53:40 +0100
commitd60281e009d13ca997a1b2e2483a6a52f5355370 (patch)
treef3235c6d2c30a7802199a6180b314a3f96b0be27
parentAdded some more restrictions to coyim profile (diff)
downloadfirejail-d60281e009d13ca997a1b2e2483a6a52f5355370.tar.gz
firejail-d60281e009d13ca997a1b2e2483a6a52f5355370.tar.zst
firejail-d60281e009d13ca997a1b2e2483a6a52f5355370.zip
Implementing some of the suggested changes from #3853
-rw-r--r--etc/inc/disable-programs.inc1
-rw-r--r--etc/profile-a-l/coyim.profile6
-rw-r--r--src/firecfg/firecfg.config1
3 files changed, 5 insertions, 3 deletions
diff --git a/etc/inc/disable-programs.inc b/etc/inc/disable-programs.inc
index 07fefec8c..a2d45a98d 100644
--- a/etc/inc/disable-programs.inc
+++ b/etc/inc/disable-programs.inc
@@ -191,6 +191,7 @@ blacklist ${HOME}/.config/cmus
191blacklist ${HOME}/.config/com.github.bleakgrey.tootle 191blacklist ${HOME}/.config/com.github.bleakgrey.tootle
192blacklist ${HOME}/.config/corebird 192blacklist ${HOME}/.config/corebird
193blacklist ${HOME}/.config/cower 193blacklist ${HOME}/.config/cower
194blacklist ${HOME}/.config/coyim
194blacklist ${HOME}/.config/darktable 195blacklist ${HOME}/.config/darktable
195blacklist ${HOME}/.config/deadbeef 196blacklist ${HOME}/.config/deadbeef
196blacklist ${HOME}/.config/deluge 197blacklist ${HOME}/.config/deluge
diff --git a/etc/profile-a-l/coyim.profile b/etc/profile-a-l/coyim.profile
index 2ca6c20f8..80aae097e 100644
--- a/etc/profile-a-l/coyim.profile
+++ b/etc/profile-a-l/coyim.profile
@@ -15,11 +15,11 @@ include disable-interpreters.inc
15include disable-passwdmgr.inc 15include disable-passwdmgr.inc
16include disable-programs.inc 16include disable-programs.inc
17include disable-shell.inc 17include disable-shell.inc
18include disable-write-mnt.inc
19include disable-xdg.inc 18include disable-xdg.inc
20 19
21mkdir ${HOME}/.config/coyim 20mkdir ${HOME}/.config/coyim
22whitelist ${HOME}/.config/coyim 21whitelist ${HOME}/.config/coyim
22include whitelist-common.inc
23 23
24caps.drop all 24caps.drop all
25netfilter 25netfilter
@@ -37,10 +37,10 @@ tracelog
37disable-mnt 37disable-mnt
38private-cache 38private-cache
39private-dev 39private-dev
40private-etc alternatives,ca-certificates,crypto-policies,fonts,ssl 40private-etc alternatives,ca-certificates,crypto-policies,fonts,machine-id,pki,ssl
41private-tmp 41private-tmp
42 42
43dbus-user none 43dbus-user none
44dbus-system none 44dbus-system none
45 45
46memory-deny-write-execute 46#memory-deny-write-execute
diff --git a/src/firecfg/firecfg.config b/src/firecfg/firecfg.config
index 3f1591cbd..4853e099b 100644
--- a/src/firecfg/firecfg.config
+++ b/src/firecfg/firecfg.config
@@ -149,6 +149,7 @@ conkeror
149conky 149conky
150conplay 150conplay
151corebird 151corebird
152coyim
152crawl 153crawl
153crawl-tiles 154crawl-tiles
154crow 155crow