aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLibravatar netblue30 <netblue30@yahoo.com>2017-08-18 17:32:59 -0400
committerLibravatar netblue30 <netblue30@yahoo.com>2017-08-18 17:32:59 -0400
commit085027f6fdf967b3f53c1b1ef5d8be1cbbb54993 (patch)
treee000a0fa15bf5532b8519c052ab9967c404d34b0
parentseccomp testing (diff)
parentMerge pull request #1475 from smitsohu/patch-2 (diff)
downloadfirejail-085027f6fdf967b3f53c1b1ef5d8be1cbbb54993.tar.gz
firejail-085027f6fdf967b3f53c1b1ef5d8be1cbbb54993.tar.zst
firejail-085027f6fdf967b3f53c1b1ef5d8be1cbbb54993.zip
Merge branch 'master' of https://github.com/netblue30/firejail
-rw-r--r--README.md3
-rw-r--r--RELNOTES2
-rw-r--r--etc/cvlc.profile2
-rw-r--r--etc/disable-programs.inc4
-rw-r--r--etc/konversation.profile3
-rw-r--r--etc/musescore.profile30
-rw-r--r--etc/skanlite.profile9
-rw-r--r--etc/tracker.profile1
-rw-r--r--etc/tuxguitar.profile1
-rw-r--r--platform/debian/conffiles1
-rw-r--r--src/firecfg/firecfg.config1
11 files changed, 50 insertions, 7 deletions
diff --git a/README.md b/README.md
index d12b9ee4e..8372841a5 100644
--- a/README.md
+++ b/README.md
@@ -207,4 +207,5 @@ curl, mplayer2, SMPlayer, Calibre, ebook-viewer, KWrite, Geary, Liferea, peek, s
207IntelliJ IDEA, Android Studio, electron, riot-web, 207IntelliJ IDEA, Android Studio, electron, riot-web,
208Extreme Tux Racer, Frozen Bubble, Open Invaders, Pingus, Simutrans, SuperTux, 208Extreme Tux Racer, Frozen Bubble, Open Invaders, Pingus, Simutrans, SuperTux,
209telegram-desktop, arm, rambox, apktool, baobab, dex2jar, gitg, hashcat, obs, picard, 209telegram-desktop, arm, rambox, apktool, baobab, dex2jar, gitg, hashcat, obs, picard,
210remmina, sdat2img, soundconverter, sqlitebrowse, truecraft, gnome-twitch 210remmina, sdat2img, soundconverter, sqlitebrowse, truecraft, gnome-twitch, tuxguitar,
211musescore
diff --git a/RELNOTES b/RELNOTES
index 36dd39686..0e61019d9 100644
--- a/RELNOTES
+++ b/RELNOTES
@@ -19,7 +19,7 @@ firejail (0.9.49) baseline; urgency=low
19 * new profiles: Frozen Bubble, Open Invaders, Pingus, Simutrans, SuperTux 19 * new profiles: Frozen Bubble, Open Invaders, Pingus, Simutrans, SuperTux
20 * new profiles: telegram-desktop, arm, rambox, apktool, baobab, dex2jar, gitg, 20 * new profiles: telegram-desktop, arm, rambox, apktool, baobab, dex2jar, gitg,
21 * new profiles: hashcat, obs, picard, remmina, sdat2img, soundconverter, sqlitebrowse, 21 * new profiles: hashcat, obs, picard, remmina, sdat2img, soundconverter, sqlitebrowse,
22 * new profiles: truecraft, gnome-twitch 22 * new profiles: truecraft, gnome-twitch, tuxguitar, musescore
23 * bugfixes 23 * bugfixes
24 -- netblue30 <netblue30@yahoo.com> Mon, 12 Jun 2017 20:00:00 -0500 24 -- netblue30 <netblue30@yahoo.com> Mon, 12 Jun 2017 20:00:00 -0500
25 25
diff --git a/etc/cvlc.profile b/etc/cvlc.profile
index ee1346617..460966321 100644
--- a/etc/cvlc.profile
+++ b/etc/cvlc.profile
@@ -14,11 +14,9 @@ include /etc/firejail/disable-programs.inc
14 14
15caps.drop all 15caps.drop all
16netfilter 16netfilter
17nodvd
18nogroups 17nogroups
19nonewprivs 18nonewprivs
20noroot 19noroot
21notv
22protocol unix,inet,inet6,netlink 20protocol unix,inet,inet6,netlink
23seccomp 21seccomp
24shell none 22shell none
diff --git a/etc/disable-programs.inc b/etc/disable-programs.inc
index a54d2a739..7b0e6e9eb 100644
--- a/etc/disable-programs.inc
+++ b/etc/disable-programs.inc
@@ -44,6 +44,8 @@ blacklist ${HOME}/.config/Luminance
44blacklist ${HOME}/.config/Meltytech 44blacklist ${HOME}/.config/Meltytech
45blacklist ${HOME}/.config/Mousepad 45blacklist ${HOME}/.config/Mousepad
46blacklist ${HOME}/.config/Mumble 46blacklist ${HOME}/.config/Mumble
47blacklist ${HOME}/.config/MusE
48blacklist ${HOME}/.config/MuseScore
47blacklist ${HOME}/.config/Nylas Mail 49blacklist ${HOME}/.config/Nylas Mail
48blacklist ${HOME}/.config/Qlipper 50blacklist ${HOME}/.config/Qlipper
49blacklist ${HOME}/.config/QuiteRss 51blacklist ${HOME}/.config/QuiteRss
@@ -274,6 +276,8 @@ blacklist ${HOME}/.local/share/caja-python
274blacklist ${HOME}/.local/share/cdprojektred 276blacklist ${HOME}/.local/share/cdprojektred
275blacklist ${HOME}/.local/share/clipit 277blacklist ${HOME}/.local/share/clipit
276blacklist ${HOME}/.local/share/data/Mumble 278blacklist ${HOME}/.local/share/data/Mumble
279blacklist ${HOME}/.local/share/data/MusE
280blacklist ${HOME}/.local/share/data/MuseScore
277blacklist ${HOME}/.local/share/dino 281blacklist ${HOME}/.local/share/dino
278blacklist ${HOME}/.local/share/dolphin 282blacklist ${HOME}/.local/share/dolphin
279blacklist ${HOME}/.local/share/epiphany 283blacklist ${HOME}/.local/share/epiphany
diff --git a/etc/konversation.profile b/etc/konversation.profile
index 8bc263d4d..212aa8817 100644
--- a/etc/konversation.profile
+++ b/etc/konversation.profile
@@ -15,9 +15,12 @@ caps.drop all
15netfilter 15netfilter
16nodvd 16nodvd
17nogroups 17nogroups
18nonewprivs
18noroot 19noroot
19notv 20notv
21novideo
20protocol unix,inet,inet6 22protocol unix,inet,inet6
21seccomp 23seccomp
24tracelog
22 25
23private-tmp 26private-tmp
diff --git a/etc/musescore.profile b/etc/musescore.profile
new file mode 100644
index 000000000..bd00bea69
--- /dev/null
+++ b/etc/musescore.profile
@@ -0,0 +1,30 @@
1# Firejail profile for musescore
2# This file is overwritten after every install/update
3# Persistent local customizations
4include /etc/firejail/musescore.local
5# Persistent global definitions
6include /etc/firejail/globals.local
7
8noblacklist ~/.config/MusE
9noblacklist ~/.config/MuseScore
10noblacklist ~/.local/share/data/MusE
11noblacklist ~/.local/share/data/MuseScore
12
13caps.drop all
14netfilter
15no3d
16nodvd
17nonewprivs
18noroot
19notv
20novideo
21protocol unix,inet,inet6
22seccomp
23shell none
24tracelog
25
26# private-bin musescore,mscore
27private-tmp
28
29noexec ${HOME}
30noexec /tmp
diff --git a/etc/skanlite.profile b/etc/skanlite.profile
index 0338bc452..1d590a142 100644
--- a/etc/skanlite.profile
+++ b/etc/skanlite.profile
@@ -12,6 +12,7 @@ include /etc/firejail/disable-passwdmgr.inc
12include /etc/firejail/disable-programs.inc 12include /etc/firejail/disable-programs.inc
13 13
14caps.drop all 14caps.drop all
15# net none
15netfilter 16netfilter
16nodvd 17nodvd
17nogroups 18nogroups
@@ -19,11 +20,13 @@ nonewprivs
19noroot 20noroot
20nosound 21nosound
21notv 22notv
22# protocol unix,inet,inet6 23novideo
23seccomp 24protocol unix,netlink
25# skanlite makes ioperm system calls, which are blacklisted by default.
26seccomp.drop @clock,@cpu-emulation,@debug,@module,@obsolete,@reboot,@resources,@swap,acct,add_key,bpf,chroot,fanotify_init,io_cancel,io_destroy,io_getevents,io_setup,io_submit,iopl,ioprio_set,kcmp,keyctl,mount,name_to_handle_at,nfsservctl,ni_syscall,open_by_handle_at,pciconfig_iobase,pciconfig_read,pciconfig_write,personality,pivot_root,process_vm_readv,ptrace,remap_file_pages,request_key,s390_mmio_read,s390_mmio_write,setdomainname,sethostname,syslog,umount,umount2,userfaultfd,vhangup,vmsplice
24shell none 27shell none
25 28
26# private-bin skanlite 29# private-bin skanlite,kbuildsycoca4
27# private-dev 30# private-dev
28# private-etc 31# private-etc
29# private-tmp 32# private-tmp
diff --git a/etc/tracker.profile b/etc/tracker.profile
index ded2ae2e5..f3dfb2d4e 100644
--- a/etc/tracker.profile
+++ b/etc/tracker.profile
@@ -23,6 +23,7 @@ nonewprivs
23noroot 23noroot
24nosound 24nosound
25notv 25notv
26novideo
26protocol unix 27protocol unix
27seccomp 28seccomp
28shell none 29shell none
diff --git a/etc/tuxguitar.profile b/etc/tuxguitar.profile
index ddbcce3f6..5b6a257f6 100644
--- a/etc/tuxguitar.profile
+++ b/etc/tuxguitar.profile
@@ -14,6 +14,7 @@ include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc 14include /etc/firejail/disable-programs.inc
15 15
16caps.drop all 16caps.drop all
17netfilter
17no3d 18no3d
18nodvd 19nodvd
19nonewprivs 20nonewprivs
diff --git a/platform/debian/conffiles b/platform/debian/conffiles
index d11f473ed..6473c6fef 100644
--- a/platform/debian/conffiles
+++ b/platform/debian/conffiles
@@ -216,6 +216,7 @@
216/etc/firejail/mumble.profile 216/etc/firejail/mumble.profile
217/etc/firejail/mupdf.profile 217/etc/firejail/mupdf.profile
218/etc/firejail/mupen64plus.profile 218/etc/firejail/mupen64plus.profile
219/etc/firejail/musescore.profile
219/etc/firejail/mutt.profile 220/etc/firejail/mutt.profile
220/etc/firejail/nautilus.profile 221/etc/firejail/nautilus.profile
221/etc/firejail/nemo.profile 222/etc/firejail/nemo.profile
diff --git a/src/firecfg/firecfg.config b/src/firecfg/firecfg.config
index d66b026b0..15e95b9a7 100644
--- a/src/firecfg/firecfg.config
+++ b/src/firecfg/firecfg.config
@@ -193,6 +193,7 @@ multimc5
193mumble 193mumble
194mupdf 194mupdf
195mupen64plus 195mupen64plus
196musescore
196mutt 197mutt
197nautilus 198nautilus
198netsurf 199netsurf