aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLibravatar smitsohu <smitsohu@gmail.com>2020-08-09 19:21:33 +0200
committerLibravatar smitsohu <smitsohu@gmail.com>2020-08-09 19:21:33 +0200
commit93a45e11495cc2652ac2e11bc1a2ac1c3ad9cde7 (patch)
tree326a37edcb6f1cf23246fb4cf6df6c074c72c559
parentmount sandbox lib directory ro,nosuid,nodev (diff)
parentprofile fixes (1) (diff)
downloadfirejail-93a45e11495cc2652ac2e11bc1a2ac1c3ad9cde7.tar.gz
firejail-93a45e11495cc2652ac2e11bc1a2ac1c3ad9cde7.tar.zst
firejail-93a45e11495cc2652ac2e11bc1a2ac1c3ad9cde7.zip
Merge branch 'release-0.9.62' of https://github.com/netblue30/firejail into release-0.9.62
-rw-r--r--etc/celluloid.profile2
-rw-r--r--etc/disable-common.inc1
-rw-r--r--etc/gedit.profile2
-rw-r--r--etc/gnome-builder.profile1
-rw-r--r--etc/gnome-maps.profile2
-rw-r--r--etc/whitelist-usr-share-common.inc1
6 files changed, 5 insertions, 4 deletions
diff --git a/etc/celluloid.profile b/etc/celluloid.profile
index 6b7db6b44..d06eb7a65 100644
--- a/etc/celluloid.profile
+++ b/etc/celluloid.profile
@@ -29,7 +29,7 @@ include whitelist-var-common.inc
29apparmor 29apparmor
30caps.drop all 30caps.drop all
31netfilter 31netfilter
32nodbus 32# nodbus -- uses dconf
33nogroups 33nogroups
34nonewprivs 34nonewprivs
35noroot 35noroot
diff --git a/etc/disable-common.inc b/etc/disable-common.inc
index 16f231108..f50e10a00 100644
--- a/etc/disable-common.inc
+++ b/etc/disable-common.inc
@@ -230,6 +230,7 @@ read-only ${HOME}/.bash_login
230read-only ${HOME}/.bash_logout 230read-only ${HOME}/.bash_logout
231read-only ${HOME}/.bash_profile 231read-only ${HOME}/.bash_profile
232read-only ${HOME}/.bashrc 232read-only ${HOME}/.bashrc
233read-only ${HOME}/.config/environment.d
233read-only ${HOME}/.config/fish 234read-only ${HOME}/.config/fish
234read-only ${HOME}/.csh_files 235read-only ${HOME}/.csh_files
235read-only ${HOME}/.cshrc 236read-only ${HOME}/.cshrc
diff --git a/etc/gedit.profile b/etc/gedit.profile
index 837396654..6d575e850 100644
--- a/etc/gedit.profile
+++ b/etc/gedit.profile
@@ -42,6 +42,6 @@ tracelog
42 42
43# private-bin gedit 43# private-bin gedit
44private-dev 44private-dev
45private-lib aspell,gconv,gedit,libgspell-1.so.*,libreadline.so.*,libtinfo.so.* 45private-lib aspell,gconv,gedit,libgspell-1.so.*,libgtksourceview-3.0.so.*,libpeas-gtk-1.0.so.*,libreadline.so.*,libtinfo.so.*
46private-tmp 46private-tmp
47 47
diff --git a/etc/gnome-builder.profile b/etc/gnome-builder.profile
index 726a74089..eaf48931d 100644
--- a/etc/gnome-builder.profile
+++ b/etc/gnome-builder.profile
@@ -31,5 +31,4 @@ protocol unix,inet,inet6
31seccomp 31seccomp
32shell none 32shell none
33 33
34private-cache
35private-dev 34private-dev
diff --git a/etc/gnome-maps.profile b/etc/gnome-maps.profile
index a625db948..78f5ddc3a 100644
--- a/etc/gnome-maps.profile
+++ b/etc/gnome-maps.profile
@@ -28,6 +28,7 @@ whitelist ${HOME}/.local/share/maps-places.json
28whitelist ${DOWNLOADS} 28whitelist ${DOWNLOADS}
29whitelist ${PICTURES} 29whitelist ${PICTURES}
30whitelist /usr/share/gnome-maps 30whitelist /usr/share/gnome-maps
31whitelist /usr/share/libgweather
31include whitelist-common.inc 32include whitelist-common.inc
32include whitelist-usr-share-common.inc 33include whitelist-usr-share-common.inc
33include whitelist-var-common.inc 34include whitelist-var-common.inc
@@ -55,4 +56,3 @@ private-bin gjs,gnome-maps
55private-dev 56private-dev
56private-etc alternatives,ca-certificates,clutter-1.0,crypto-policies,dconf,drirc,fonts,gconf,gcrypt,gtk-3.0,host.conf,hostname,hosts,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,locale,locale.alias,locale.conf,localtime,mime.types,nsswitch.conf,pango,pkcs11,pki,protocols,resolv.conf,rpc,services,ssl,X11,xdg 57private-etc alternatives,ca-certificates,clutter-1.0,crypto-policies,dconf,drirc,fonts,gconf,gcrypt,gtk-3.0,host.conf,hostname,hosts,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,locale,locale.alias,locale.conf,localtime,mime.types,nsswitch.conf,pango,pkcs11,pki,protocols,resolv.conf,rpc,services,ssl,X11,xdg
57private-tmp 58private-tmp
58
diff --git a/etc/whitelist-usr-share-common.inc b/etc/whitelist-usr-share-common.inc
index be0a29d94..78b947750 100644
--- a/etc/whitelist-usr-share-common.inc
+++ b/etc/whitelist-usr-share-common.inc
@@ -42,6 +42,7 @@ whitelist /usr/share/p11-kit
42whitelist /usr/share/pixmaps 42whitelist /usr/share/pixmaps
43whitelist /usr/share/pki 43whitelist /usr/share/pki
44whitelist /usr/share/plasma 44whitelist /usr/share/plasma
45whitelist /usr/share/publicsuffix
45whitelist /usr/share/qt 46whitelist /usr/share/qt
46whitelist /usr/share/qt4 47whitelist /usr/share/qt4
47whitelist /usr/share/qt5 48whitelist /usr/share/qt5