aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLibravatar netblue30 <netblue30@yahoo.com>2017-06-15 20:53:29 -0400
committerLibravatar netblue30 <netblue30@yahoo.com>2017-06-15 20:53:29 -0400
commit19c2c137bf99210f4ba48af57b3c9ac0624debd0 (patch)
treeef2a45eac82eff02ca9c2afa0af118a275690a61
parenttest: add novideo to profiles (part 1) (diff)
downloadfirejail-19c2c137bf99210f4ba48af57b3c9ac0624debd0.tar.gz
firejail-19c2c137bf99210f4ba48af57b3c9ac0624debd0.tar.zst
firejail-19c2c137bf99210f4ba48af57b3c9ac0624debd0.zip
curl profile
-rw-r--r--README.md5
-rw-r--r--RELNOTES1
-rw-r--r--etc/curl.profile35
-rw-r--r--etc/disable-programs.inc2
-rw-r--r--etc/wget.profile1
-rw-r--r--platform/debian/conffiles1
6 files changed, 45 insertions, 0 deletions
diff --git a/README.md b/README.md
index fa5b9199f..bc0ba475a 100644
--- a/README.md
+++ b/README.md
@@ -63,3 +63,8 @@ Use this issue to request new profiles: https://github.com/netblue30/firejail/is
63 63
64````` 64`````
65# Current development version: 0.9.49 65# Current development version: 0.9.49
66
67## New profiles:
68
69curl
70
diff --git a/RELNOTES b/RELNOTES
index 684a0c731..b7a0c49e7 100644
--- a/RELNOTES
+++ b/RELNOTES
@@ -1,5 +1,6 @@
1firejail (0.9.49) baseline; urgency=low 1firejail (0.9.49) baseline; urgency=low
2 * work in progress! 2 * work in progress!
3 * new profiles: curl
3 * bugfixes 4 * bugfixes
4 -- netblue30 <netblue30@yahoo.com> Mon, 12 Jun 2017 20:00:00 -0500 5 -- netblue30 <netblue30@yahoo.com> Mon, 12 Jun 2017 20:00:00 -0500
5 6
diff --git a/etc/curl.profile b/etc/curl.profile
new file mode 100644
index 000000000..58b5f050a
--- /dev/null
+++ b/etc/curl.profile
@@ -0,0 +1,35 @@
1quiet
2# Persistent global definitions go here
3include /etc/firejail/globals.local
4
5# This file is overwritten during software install.
6# Persistent customizations should go in a .local file.
7include /etc/firejail/curl.local
8
9# curl profile
10noblacklist ~/.curlrc
11include /etc/firejail/disable-common.inc
12include /etc/firejail/disable-programs.inc
13include /etc/firejail/disable-passwdmgr.inc
14
15caps.drop all
16#ipc-namespace
17netfilter
18no3d
19nogroups
20nonewprivs
21noroot
22nosound
23protocol unix,inet,inet6
24seccomp
25shell none
26
27blacklist /tmp/.X11-unix
28
29# private-bin curl
30private-dev
31# private-etc resolv.conf
32private-tmp
33
34noexec ${HOME}
35noexec /tmp
diff --git a/etc/disable-programs.inc b/etc/disable-programs.inc
index 41889cc5f..4d77218de 100644
--- a/etc/disable-programs.inc
+++ b/etc/disable-programs.inc
@@ -170,6 +170,7 @@ blacklist ${HOME}/.config/xviewer
170blacklist ${HOME}/.config/zathura 170blacklist ${HOME}/.config/zathura
171blacklist ${HOME}/.config/zoomus.conf 171blacklist ${HOME}/.config/zoomus.conf
172blacklist ${HOME}/.conkeror.mozdev.org 172blacklist ${HOME}/.conkeror.mozdev.org
173blacklist ${HOME}/.curlrc
173blacklist ${HOME}/.dia 174blacklist ${HOME}/.dia
174blacklist ${HOME}/.dillo 175blacklist ${HOME}/.dillo
175blacklist ${HOME}/.dosbox 176blacklist ${HOME}/.dosbox
@@ -339,6 +340,7 @@ blacklist ${HOME}/.vst
339blacklist ${HOME}/.w3m 340blacklist ${HOME}/.w3m
340blacklist ${HOME}/.warzone2100-3.* 341blacklist ${HOME}/.warzone2100-3.*
341blacklist ${HOME}/.weechat 342blacklist ${HOME}/.weechat
343blacklist ${HOME}/.wgetrc
342blacklist ${HOME}/.wine 344blacklist ${HOME}/.wine
343blacklist ${HOME}/.wine64 345blacklist ${HOME}/.wine64
344blacklist ${HOME}/.xiphos 346blacklist ${HOME}/.xiphos
diff --git a/etc/wget.profile b/etc/wget.profile
index 306ec4417..801e034ea 100644
--- a/etc/wget.profile
+++ b/etc/wget.profile
@@ -7,6 +7,7 @@ include /etc/firejail/globals.local
7include /etc/firejail/wget.local 7include /etc/firejail/wget.local
8 8
9# wget profile 9# wget profile
10noblacklist ~/.wgetrc
10include /etc/firejail/disable-common.inc 11include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-programs.inc 12include /etc/firejail/disable-programs.inc
12include /etc/firejail/disable-passwdmgr.inc 13include /etc/firejail/disable-passwdmgr.inc
diff --git a/platform/debian/conffiles b/platform/debian/conffiles
index 7d36714c1..1fb8c86e7 100644
--- a/platform/debian/conffiles
+++ b/platform/debian/conffiles
@@ -307,3 +307,4 @@
307/etc/firejail/darktable.profile 307/etc/firejail/darktable.profile
308/etc/firejail/waterfox.profile 308/etc/firejail/waterfox.profile
309/etc/firejail/handbrake.profile 309/etc/firejail/handbrake.profile
310/etc/firejail/curl.profile