aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLibravatar Janik Rabe <jrabe@openmailbox.org>2016-03-23 11:14:12 +0200
committerLibravatar Janik Rabe <jrabe@openmailbox.org>2016-03-23 11:14:12 +0200
commita8503fb9a3919b674e4a31d960e043a59b236bff (patch)
tree5f8810b3633621d86b2cf3e83c57ed19409bdfd7
parent--private-etc fix (diff)
downloadfirejail-a8503fb9a3919b674e4a31d960e043a59b236bff.tar.gz
firejail-a8503fb9a3919b674e4a31d960e043a59b236bff.tar.zst
firejail-a8503fb9a3919b674e4a31d960e043a59b236bff.zip
Add qTox profile
-rw-r--r--Makefile.in1
-rw-r--r--README1
-rw-r--r--README.md2
-rw-r--r--etc/qtox.profile15
-rw-r--r--platform/debian/conffiles1
5 files changed, 19 insertions, 1 deletions
diff --git a/Makefile.in b/Makefile.in
index 29d8004f3..90b238752 100644
--- a/Makefile.in
+++ b/Makefile.in
@@ -78,6 +78,7 @@ realinstall:
78 install -c -m 0644 .etc/audacious.profile $(DESTDIR)/$(sysconfdir)/firejail/. 78 install -c -m 0644 .etc/audacious.profile $(DESTDIR)/$(sysconfdir)/firejail/.
79 install -c -m 0644 .etc/clementine.profile $(DESTDIR)/$(sysconfdir)/firejail/. 79 install -c -m 0644 .etc/clementine.profile $(DESTDIR)/$(sysconfdir)/firejail/.
80 install -c -m 0644 .etc/epiphany.profile $(DESTDIR)/$(sysconfdir)/firejail/. 80 install -c -m 0644 .etc/epiphany.profile $(DESTDIR)/$(sysconfdir)/firejail/.
81 install -c -m 0644 .etc/qtox.profile $(DESTDIR)/$(sysconfdir)/firejail/.
81 install -c -m 0644 .etc/polari.profile $(DESTDIR)/$(sysconfdir)/firejail/. 82 install -c -m 0644 .etc/polari.profile $(DESTDIR)/$(sysconfdir)/firejail/.
82 install -c -m 0644 .etc/gnome-mplayer.profile $(DESTDIR)/$(sysconfdir)/firejail/. 83 install -c -m 0644 .etc/gnome-mplayer.profile $(DESTDIR)/$(sysconfdir)/firejail/.
83 install -c -m 0644 .etc/rhythmbox.profile $(DESTDIR)/$(sysconfdir)/firejail/. 84 install -c -m 0644 .etc/rhythmbox.profile $(DESTDIR)/$(sysconfdir)/firejail/.
diff --git a/README b/README
index bfbbc5c6b..07b73232e 100644
--- a/README
+++ b/README
@@ -41,6 +41,7 @@ jrabe (https://github.com/jrabe)
41 - disallow access to kdbx files 41 - disallow access to kdbx files
42 - Epiphany profile 42 - Epiphany profile
43 - Polari profile 43 - Polari profile
44 - qTox profile
44jgriffiths (https://github.com/jgriffiths) 45jgriffiths (https://github.com/jgriffiths)
45 - make rpm packages support 46 - make rpm packages support
46Tom Mellor (https://github.com/kalegrill) 47Tom Mellor (https://github.com/kalegrill)
diff --git a/README.md b/README.md
index 2406cfc49..9b045d50c 100644
--- a/README.md
+++ b/README.md
@@ -189,5 +189,5 @@ $ man firejail-profile
189 189
190## New security profiles 190## New security profiles
191 191
192lxterminal, Epiphany, cherrytree, Battle for Wesnoth, Hedgewars, qutebrowser, SlimJet 192lxterminal, Epiphany, cherrytree, Battle for Wesnoth, Hedgewars, qutebrowser, SlimJet, qTox
193 193
diff --git a/etc/qtox.profile b/etc/qtox.profile
new file mode 100644
index 000000000..8e75f01e6
--- /dev/null
+++ b/etc/qtox.profile
@@ -0,0 +1,15 @@
1# qTox instant messaging profile
2noblacklist ${HOME}/.config/tox
3include /etc/firejail/disable-mgmt.inc
4include /etc/firejail/disable-secret.inc
5include /etc/firejail/disable-common.inc
6include /etc/firejail/disable-devel.inc
7include /etc/firejail/disable-terminals.inc
8mkdir ${HOME}/.config/tox
9whitelist ${HOME}/.config/tox
10whitelist ${DOWNLOADS}
11include /etc/firejail/whitelist-common.inc
12caps.drop all
13seccomp
14protocol unix,inet,inet6
15noroot
diff --git a/platform/debian/conffiles b/platform/debian/conffiles
index 9f324c59f..a40ca2fdf 100644
--- a/platform/debian/conffiles
+++ b/platform/debian/conffiles
@@ -22,6 +22,7 @@
22/etc/firejail/audacious.profile 22/etc/firejail/audacious.profile
23/etc/firejail/clementine.profile 23/etc/firejail/clementine.profile
24/etc/firejail/epiphany.profile 24/etc/firejail/epiphany.profile
25/etc/firejail/qtox.profile
25/etc/firejail/polari.profile 26/etc/firejail/polari.profile
26/etc/firejail/gnome-mplayer.profile 27/etc/firejail/gnome-mplayer.profile
27/etc/firejail/rhythmbox.profile 28/etc/firejail/rhythmbox.profile