aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLibravatar netblue30 <netblue30@protonmail.com>2021-01-25 09:05:54 -0500
committerLibravatar GitHub <noreply@github.com>2021-01-25 09:05:54 -0500
commitf45534d17d6262a00aac6c631b7dcd7542f7eeae (patch)
tree015c5a2d270091b9606ce50f985590826581c752
parentMerge pull request #3899 from rootalc/nolocal6 (diff)
parentAdded additional whitelists (diff)
downloadfirejail-f45534d17d6262a00aac6c631b7dcd7542f7eeae.tar.gz
firejail-f45534d17d6262a00aac6c631b7dcd7542f7eeae.tar.zst
firejail-f45534d17d6262a00aac6c631b7dcd7542f7eeae.zip
Merge pull request #3853 from botherder/master
New profile for CoyIM
-rw-r--r--etc/inc/disable-programs.inc1
-rw-r--r--etc/profile-a-l/coyim.profile49
-rw-r--r--src/firecfg/firecfg.config1
3 files changed, 51 insertions, 0 deletions
diff --git a/etc/inc/disable-programs.inc b/etc/inc/disable-programs.inc
index d24713fe5..72b1c86fb 100644
--- a/etc/inc/disable-programs.inc
+++ b/etc/inc/disable-programs.inc
@@ -191,6 +191,7 @@ blacklist ${HOME}/.config/cmus
191blacklist ${HOME}/.config/com.github.bleakgrey.tootle 191blacklist ${HOME}/.config/com.github.bleakgrey.tootle
192blacklist ${HOME}/.config/corebird 192blacklist ${HOME}/.config/corebird
193blacklist ${HOME}/.config/cower 193blacklist ${HOME}/.config/cower
194blacklist ${HOME}/.config/coyim
194blacklist ${HOME}/.config/darktable 195blacklist ${HOME}/.config/darktable
195blacklist ${HOME}/.config/deadbeef 196blacklist ${HOME}/.config/deadbeef
196blacklist ${HOME}/.config/deluge 197blacklist ${HOME}/.config/deluge
diff --git a/etc/profile-a-l/coyim.profile b/etc/profile-a-l/coyim.profile
new file mode 100644
index 000000000..75813c494
--- /dev/null
+++ b/etc/profile-a-l/coyim.profile
@@ -0,0 +1,49 @@
1# Firejail profile for coyim
2# Description: GTK Jabber client written in Go
3# This file is overwritten after every install/update
4# Persistent local customizations
5include coyim.local
6# Persistent global definitions
7include globals.local
8
9noblacklist ${HOME}/.config/coyim
10
11include disable-common.inc
12include disable-devel.inc
13include disable-exec.inc
14include disable-interpreters.inc
15include disable-passwdmgr.inc
16include disable-programs.inc
17include disable-shell.inc
18include disable-xdg.inc
19
20mkdir ${HOME}/.config/coyim
21whitelist ${HOME}/.config/coyim
22include whitelist-common.inc
23include whitelist-usr-share-common.inc
24include whitelist-runuser-common.inc
25include whitelist-var-common.inc
26
27caps.drop all
28netfilter
29nodvd
30nogroups
31nonewprivs
32noroot
33notv
34nou2f
35protocol unix,inet,inet6
36seccomp
37shell none
38tracelog
39
40disable-mnt
41private-cache
42private-dev
43private-etc alternatives,ca-certificates,crypto-policies,fonts,machine-id,pki,ssl
44private-tmp
45
46dbus-user none
47dbus-system none
48
49#memory-deny-write-execute
diff --git a/src/firecfg/firecfg.config b/src/firecfg/firecfg.config
index d6fcdb38f..e924ef2ec 100644
--- a/src/firecfg/firecfg.config
+++ b/src/firecfg/firecfg.config
@@ -149,6 +149,7 @@ conkeror
149conky 149conky
150conplay 150conplay
151corebird 151corebird
152coyim
152crawl 153crawl
153crawl-tiles 154crawl-tiles
154crow 155crow