aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLibravatar rusty-snake <41237666+rusty-snake@users.noreply.github.com>2020-10-23 14:06:37 +0200
committerLibravatar rusty-snake <41237666+rusty-snake@users.noreply.github.com>2020-10-23 14:06:37 +0200
commit582ae38e811a7a768d2cfbcf93e711ebbc984e07 (patch)
treef290de320d79ced20ee3e194e91e12cab0d0baea
parentMerge pull request #3683 from jmetrius/vlc-aacs-fix (diff)
downloadfirejail-582ae38e811a7a768d2cfbcf93e711ebbc984e07.tar.gz
firejail-582ae38e811a7a768d2cfbcf93e711ebbc984e07.tar.zst
firejail-582ae38e811a7a768d2cfbcf93e711ebbc984e07.zip
harden peek; update README.md; add gnome-sound-…
…recorder to firecfg.config
-rw-r--r--README.md13
-rw-r--r--etc/inc/disable-programs.inc2
-rw-r--r--etc/profile-m-z/peek.profile24
-rw-r--r--src/firecfg/firecfg.config1
4 files changed, 25 insertions, 15 deletions
diff --git a/README.md b/README.md
index 2bb05a872..6bc24cfbb 100644
--- a/README.md
+++ b/README.md
@@ -154,9 +154,9 @@ We also keep a list of profile fixes for previous released versions in [etc-fixe
154````` 154`````
155 155
156````` 156`````
157## Latest released version: 0.9.62 157## Latest released version: 0.9.64
158 158
159## Current development version: 0.9.63 159## Current development version: 0.9.65
160 160
161### Profile Statistics 161### Profile Statistics
162 162
@@ -191,12 +191,3 @@ Stats:
191 191
192### New profiles: 192### New profiles:
193 193
194gfeeds, firefox-x11, tvbrowser, rtv, clipgrab, gnome-passwordsafe, bibtex, gummi, latex, pdflatex, tex, wpp, wpspdf, wps, et,
195multimc, gnome-hexgl, com.github.johnfactotum.Foliate, desktopeditors, impressive, mupdf-gl, mupdf-x11, mupdf-x11-curl,
196muraster, mutool, planmaker18, planmaker18free, presentations18, presentations18free, textmaker18, textmaker18free, teams, xournal,
197gnome-screenshot, ripperX, sound-juicer, iagno, com.github.dahenson.agenda, gnome-pomodoro, gnome-todo, kmplayer,
198penguin-command, x2goclient, frogatto, gnome-mines, gnome-nibbles, lightsoff, ts3client_runscript.sh, warmux, ferdi, abiword,
199four-in-a-row, gnome-mahjongg, gnome-robots, gnome-sudoku, gnome-taquin, gnome-tetravex, blobwars, gravity-beams-and-evaporating-stars,
200hyperrogue, jumpnbump-menu, jumpnbump, magicor, mindless, mirrormagic, mrrescue, scorched3d-wrapper, scorchwentbonkers,
201seahorse-adventures, wordwarvi, xbill, gnome-klotski, five-or-more, swell-foop, fdns, jitsi-meet-desktop, nicontine, steam-runtime, apostrophe, quadrapassel, dino-im, strawberry, hitori, bijiben, gnote, gnubik, ZeGrapher, gapplication, xonotic-sdl-wrapper, openarena_ded, cawbird, freetube, homebank, mattermost-desktop, newsflash, com.gitlab.newsflash, element-desktop, sushi, xfce4-screenshooter, org.gnome.NautilusPreviewer, lyx, minitube, nuclear, mtpaint, minecraft-launcher, gnome-calendar, vmware, git-cola, otter-browser, kazam, menulibre, musictube, onboard, fractal, mirage, quaternion, spectral, man, psi, smuxi-frontend-gnome, balsa, kube, trojita, cola, twitch, youtube, youtubemusic-nativefier, ytmdesktop, dbus-send, notify-send, qrencode,
202xournalpp, chromium-freeworld, equalx
diff --git a/etc/inc/disable-programs.inc b/etc/inc/disable-programs.inc
index a7ce7ed8a..42d690c94 100644
--- a/etc/inc/disable-programs.inc
+++ b/etc/inc/disable-programs.inc
@@ -68,7 +68,6 @@ blacklist ${HOME}/.cliqz
68blacklist ${HOME}/.clonk 68blacklist ${HOME}/.clonk
69blacklist ${HOME}/.config/0ad 69blacklist ${HOME}/.config/0ad
70blacklist ${HOME}/.config/2048-qt 70blacklist ${HOME}/.config/2048-qt
71blacklist ${HOME}/.config/aacs
72blacklist ${HOME}/.config/Atom 71blacklist ${HOME}/.config/Atom
73blacklist ${HOME}/.config/Audaciousrc 72blacklist ${HOME}/.config/Audaciousrc
74blacklist ${HOME}/.config/Authenticator 73blacklist ${HOME}/.config/Authenticator
@@ -143,6 +142,7 @@ blacklist ${HOME}/.config/Wire
143blacklist ${HOME}/.config/Youtube 142blacklist ${HOME}/.config/Youtube
144blacklist ${HOME}/.config/Zeal 143blacklist ${HOME}/.config/Zeal
145blacklist ${HOME}/.config/ZeGrapher Project 144blacklist ${HOME}/.config/ZeGrapher Project
145blacklist ${HOME}/.config/aacs
146blacklist ${HOME}/.config/abiword 146blacklist ${HOME}/.config/abiword
147blacklist ${HOME}/.config/agenda 147blacklist ${HOME}/.config/agenda
148blacklist ${HOME}/.config/akonadi* 148blacklist ${HOME}/.config/akonadi*
diff --git a/etc/profile-m-z/peek.profile b/etc/profile-m-z/peek.profile
index 66fdd6496..28a7da404 100644
--- a/etc/profile-m-z/peek.profile
+++ b/etc/profile-m-z/peek.profile
@@ -17,7 +17,18 @@ include disable-passwdmgr.inc
17include disable-programs.inc 17include disable-programs.inc
18include disable-xdg.inc 18include disable-xdg.inc
19 19
20#mkdir ${HOME}/.cache/peek
21#whitelist ${HOME}/.cache/peek
22#whitelist ${PICTURES}
23#whitelist ${VIDEOS}
24#include whitelist-common.inc
25include whitelist-runuser-common.inc
26include whitelist-usr-share-common.inc
27include whitelist-var-common.inc
28
29apparmor
20caps.drop all 30caps.drop all
31machine-id
21net none 32net none
22no3d 33no3d
23nodvd 34nodvd
@@ -31,13 +42,20 @@ novideo
31protocol unix 42protocol unix
32seccomp 43seccomp
33shell none 44shell none
45tracelog
34 46
35# private-bin breaks gif mode, mp4 and webm mode work fine however 47disable-mnt
36# private-bin convert,ffmpeg,peek 48private-bin bash,convert,ffmpeg,firejail,fish,peek,sh,which,zsh
37private-dev 49private-dev
50private-etc dconf,firejail,fonts,gtk-3.0,login.defs,pango,passwd,X11
38private-tmp 51private-tmp
39 52
40dbus-user none 53dbus-user filter
54dbus-user.own com.uploadedlobster.peek
55dbus-user.talk ca.desrt.dconf
56dbus-user.talk org.freedesktop.FileManager1
57dbus-user.talk org.freedesktop.Notifications
58dbus-user.talk org.gnome.Shell.Screencast
41dbus-system none 59dbus-system none
42 60
43memory-deny-write-execute 61memory-deny-write-execute
diff --git a/src/firecfg/firecfg.config b/src/firecfg/firecfg.config
index d16aa2ee9..906d86484 100644
--- a/src/firecfg/firecfg.config
+++ b/src/firecfg/firecfg.config
@@ -307,6 +307,7 @@ gnome-recipes
307gnome-robots 307gnome-robots
308gnome-schedule 308gnome-schedule
309gnome-screenshot 309gnome-screenshot
310gnome-sound-recorder
310gnome-sudoku 311gnome-sudoku
311gnome-system-log 312gnome-system-log
312gnome-taquin 313gnome-taquin