aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLibravatar rusty-snake <print_hello_world+Public@protonmail.com>2019-07-31 18:30:30 +0000
committerLibravatar GitHub <noreply@github.com>2019-07-31 18:30:30 +0000
commit4e8addaaec1ecd5b32a98b5e3b45365334b16d28 (patch)
tree44c8cdc6aac491151f0bf02a0cc5842c29c4f9d1
parentAdd tb-starter-wrapper.profile (#2863) (diff)
parentCorrections (diff)
downloadfirejail-4e8addaaec1ecd5b32a98b5e3b45365334b16d28.tar.gz
firejail-4e8addaaec1ecd5b32a98b5e3b45365334b16d28.tar.zst
firejail-4e8addaaec1ecd5b32a98b5e3b45365334b16d28.zip
Merge pull request #2881 from flacks/profiles/zulip
Add Zulip profile
-rw-r--r--etc/disable-programs.inc1
-rw-r--r--etc/zulip.profile47
-rw-r--r--src/firecfg/firecfg.config1
3 files changed, 49 insertions, 0 deletions
diff --git a/etc/disable-programs.inc b/etc/disable-programs.inc
index cc6877693..9b66702fc 100644
--- a/etc/disable-programs.inc
+++ b/etc/disable-programs.inc
@@ -322,6 +322,7 @@ blacklist ${HOME}/.config/yelp
322blacklist ${HOME}/.config/youtube-dl 322blacklist ${HOME}/.config/youtube-dl
323blacklist ${HOME}/.config/zathura 323blacklist ${HOME}/.config/zathura
324blacklist ${HOME}/.config/zoomus.conf 324blacklist ${HOME}/.config/zoomus.conf
325blacklist ${HOME}/.config/Zulip
325blacklist ${HOME}/.conkeror.mozdev.org 326blacklist ${HOME}/.conkeror.mozdev.org
326blacklist ${HOME}/.crawl 327blacklist ${HOME}/.crawl
327blacklist ${HOME}/.curlrc 328blacklist ${HOME}/.curlrc
diff --git a/etc/zulip.profile b/etc/zulip.profile
new file mode 100644
index 000000000..999c2f77a
--- /dev/null
+++ b/etc/zulip.profile
@@ -0,0 +1,47 @@
1# Firejail profile for zulip
2# Description: Real-time team chat based on the email threading model
3# This file is overwritten after every install/update
4# Persistent local customizations
5include zulip.local
6# Persistent global definitions
7include globals.local
8
9ignore noexec /tmp
10
11noblacklist ${HOME}/.config/Zulip
12
13include disable-common.inc
14include disable-devel.inc
15include disable-exec.inc
16include disable-interpreters.inc
17include disable-passwdmgr.inc
18include disable-programs.inc
19include disable-xdg.inc
20
21mkdir ${HOME}/.config/Zulip
22whitelist ${HOME}/.config/Zulip
23whitelist ${DOWNLOADS}
24include whitelist-common.inc
25include whitelist-var-common.inc
26
27apparmor
28caps.drop all
29netfilter
30no3d
31nodvd
32nogroups
33nonewprivs
34noroot
35notv
36nou2f
37novideo
38protocol unix,inet,inet6
39seccomp
40shell none
41
42disable-mnt
43private-bin locale,zulip
44private-cache
45private-dev
46private-etc asound.conf,fonts,machine-id
47private-tmp
diff --git a/src/firecfg/firecfg.config b/src/firecfg/firecfg.config
index 9645215ef..daf7a5621 100644
--- a/src/firecfg/firecfg.config
+++ b/src/firecfg/firecfg.config
@@ -679,3 +679,4 @@ zathura
679zeal 679zeal
680zoom 680zoom
681zpaq 681zpaq
682zulip