aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLibravatar rusty-snake <print_hello_world+Public@protonmail.com>2019-09-20 18:43:53 +0200
committerLibravatar rusty-snake <print_hello_world+Public@protonmail.com>2019-09-20 18:43:53 +0200
commit5c7f993216fbe2b0f31845fec86a636f93cc03ec (patch)
tree6720aab17eab4f0c479bfd09bc9b5dbd9d7fa7f6
parentapparmor: permit writing to trace file (diff)
downloadfirejail-5c7f993216fbe2b0f31845fec86a636f93cc03ec.tar.gz
firejail-5c7f993216fbe2b0f31845fec86a636f93cc03ec.tar.zst
firejail-5c7f993216fbe2b0f31845fec86a636f93cc03ec.zip
Create gnome-latex.profile
-rw-r--r--README.md2
-rw-r--r--RELNOTES2
-rw-r--r--etc/disable-programs.inc2
-rw-r--r--etc/gnome-latex.profile46
-rw-r--r--src/firecfg/firecfg.config1
5 files changed, 51 insertions, 2 deletions
diff --git a/README.md b/README.md
index b97d73e67..711a970fb 100644
--- a/README.md
+++ b/README.md
@@ -118,4 +118,4 @@ We also keep a list of profile fixes for previous released versions in [etc-fixe
118 118
119## New profiles: 119## New profiles:
120 120
121gnome-sound-recorder, godot, jerry, keepassxc-cli, keepassxc-proxy, klatexformula, klatexformula_cmdl, links, newsbeuter, OpenArena, pandoc, qgis, rhythmbox-client, tcpdump, teams-for-linux, tshark, xlinks, zeal, mpg123, conplay, mpg123.bin, mpg123-alsa, mpg123-id3dump, mpg123-jack, mpg123-nas, mpg123-openal, mpg123-oss, mpg123-portaudio, mpg123-pulse, mpg123-strip, out123, pavucontrol-qt, gnome-characters, gnome-character-map, rsync, Whalebird, tor-browser (AUR), Zulip, tb-starter-wrapper, bzcat, kiwix-desktop 121gnome-sound-recorder, godot, jerry, keepassxc-cli, keepassxc-proxy, klatexformula, klatexformula_cmdl, links, newsbeuter, OpenArena, pandoc, qgis, rhythmbox-client, tcpdump, teams-for-linux, tshark, xlinks, zeal, mpg123, conplay, mpg123.bin, mpg123-alsa, mpg123-id3dump, mpg123-jack, mpg123-nas, mpg123-openal, mpg123-oss, mpg123-portaudio, mpg123-pulse, mpg123-strip, out123, pavucontrol-qt, gnome-characters, gnome-character-map, rsync, Whalebird, tor-browser (AUR), Zulip, tb-starter-wrapper, bzcat, kiwix-desktop, ar, gnome-latex
diff --git a/RELNOTES b/RELNOTES
index 5c50195e0..14b454b87 100644
--- a/RELNOTES
+++ b/RELNOTES
@@ -16,7 +16,7 @@ firejail (0.9.61) baseline; urgency=low
16 * new profiles: gnome-characters, gnome-character-map, rsync, Whalebird, 16 * new profiles: gnome-characters, gnome-character-map, rsync, Whalebird,
17 * new profiles: tor-browser (AUR), Zulip, tb-starter-wrapper, bzcat, 17 * new profiles: tor-browser (AUR), Zulip, tb-starter-wrapper, bzcat,
18 * new profiles: kiwix-desktop, bzcat, zstd, pzstd, zstdcat, zstdgrep, zstdless 18 * new profiles: kiwix-desktop, bzcat, zstd, pzstd, zstdcat, zstdgrep, zstdless
19 * new profiles: zstdmt, unzstd, i2p 19 * new profiles: zstdmt, unzstd, i2p, ar, gnome-latex
20 -- netblue30 <netblue30@yahoo.com> Sat, 1 Jun 2019 08:00:00 -0500 20 -- netblue30 <netblue30@yahoo.com> Sat, 1 Jun 2019 08:00:00 -0500
21 21
22firejail (0.9.60) baseline; urgency=low 22firejail (0.9.60) baseline; urgency=low
diff --git a/etc/disable-programs.inc b/etc/disable-programs.inc
index e54b651a6..7dbe535fe 100644
--- a/etc/disable-programs.inc
+++ b/etc/disable-programs.inc
@@ -183,6 +183,7 @@ blacklist ${HOME}/.config/ghostwriter
183blacklist ${HOME}/.config/git 183blacklist ${HOME}/.config/git
184blacklist ${HOME}/.config/globaltime 184blacklist ${HOME}/.config/globaltime
185blacklist ${HOME}/.config/gnome-builder 185blacklist ${HOME}/.config/gnome-builder
186blacklist ${HOME}/.config/gnome-latex
186blacklist ${HOME}/.config/gnome-mplayer 187blacklist ${HOME}/.config/gnome-mplayer
187blacklist ${HOME}/.config/gnome-mpv 188blacklist ${HOME}/.config/gnome-mpv
188blacklist ${HOME}/.config/gnome-pie 189blacklist ${HOME}/.config/gnome-pie
@@ -502,6 +503,7 @@ blacklist ${HOME}/.local/share/gitg
502blacklist ${HOME}/.local/share/gnome-2048 503blacklist ${HOME}/.local/share/gnome-2048
503blacklist ${HOME}/.local/share/gnome-chess 504blacklist ${HOME}/.local/share/gnome-chess
504blacklist ${HOME}/.local/share/gnome-builder 505blacklist ${HOME}/.local/share/gnome-builder
506blacklist ${HOME}/.local/share/gnome-latex
505blacklist ${HOME}/.local/share/gnome-music 507blacklist ${HOME}/.local/share/gnome-music
506blacklist ${HOME}/.local/share/gnome-photos 508blacklist ${HOME}/.local/share/gnome-photos
507blacklist ${HOME}/.local/share/gnome-recipes 509blacklist ${HOME}/.local/share/gnome-recipes
diff --git a/etc/gnome-latex.profile b/etc/gnome-latex.profile
new file mode 100644
index 000000000..9cef9072c
--- /dev/null
+++ b/etc/gnome-latex.profile
@@ -0,0 +1,46 @@
1# Firejail profile for gnome-latex
2# Description: LaTeX editor for the GNOME desktop
3# This file is overwritten after every install/update
4# Persistent local customizations
5include gnome-latex.local
6# Persistent global definitions
7include globals.local
8
9noblacklist ${HOME}/.config/gnome-latex
10noblacklist ${HOME}/.local/share/gnome-latex
11
12# Allow perl (blacklisted by disable-interpreters.inc)
13include allow-perl.inc
14
15include disable-common.inc
16include disable-devel.inc
17include disable-exec.inc
18include disable-interpreters.inc
19include disable-passwdmgr.inc
20include disable-programs.inc
21
22# May cause issues.
23#include whitelist-var-common.inc
24
25apparmor
26caps.drop all
27machine-id
28net none
29no3d
30nodvd
31nogroups
32nonewprivs
33noroot
34nosound
35notv
36nou2f
37novideo
38protocol unix
39seccomp
40shell none
41tracelog
42
43private-cache
44private-dev
45# passwd,login.defs,firejail are a temporary workaround for #2877 and can be removed once it is fixed
46private-etc alternatives,dconf,fonts,gtk-3.0,latexmk.conf,login.defs,passwd,texlive
diff --git a/src/firecfg/firecfg.config b/src/firecfg/firecfg.config
index 502449839..9c7fd1e4e 100644
--- a/src/firecfg/firecfg.config
+++ b/src/firecfg/firecfg.config
@@ -242,6 +242,7 @@ gnome-clocks
242gnome-contacts 242gnome-contacts
243gnome-documents 243gnome-documents
244gnome-font-viewer 244gnome-font-viewer
245gnome-latex
245gnome-logs 246gnome-logs
246gnome-maps 247gnome-maps
247gnome-mplayer 248gnome-mplayer