aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLibravatar netblue30 <netblue30@yahoo.com>2020-03-19 15:30:08 -0400
committerLibravatar netblue30 <netblue30@yahoo.com>2020-03-19 15:30:08 -0400
commit5dbdf657bdaafbb1dd1643b2115232a02b328286 (patch)
tree582534c0550f084e8148d3489e9433f456f92ac6
parentvarious profile fixes (diff)
downloadfirejail-5dbdf657bdaafbb1dd1643b2115232a02b328286.tar.gz
firejail-5dbdf657bdaafbb1dd1643b2115232a02b328286.tar.zst
firejail-5dbdf657bdaafbb1dd1643b2115232a02b328286.zip
new profiles: ripperx, sound-juicer
-rw-r--r--README.md3
-rw-r--r--etc/asunder.profile4
-rw-r--r--etc/disable-programs.inc2
-rw-r--r--etc/ripperx.profile41
-rw-r--r--etc/sound-juicer.profile41
-rw-r--r--src/firecfg/firecfg.config2
6 files changed, 92 insertions, 1 deletions
diff --git a/README.md b/README.md
index e333df314..374d6f456 100644
--- a/README.md
+++ b/README.md
@@ -175,4 +175,5 @@ Run ./profstats -h for help.
175 175
176### New profiles: 176### New profiles:
177 177
178gfeeds, firefox-x11, tvbrowser, rtv, clipgrab, gnome-passwordsafe, bibtex, gummi, latex, pdflatex, tex, wpp, wpspdf, wps, et, multimc, gnome-hexgl, com.github.johnfactotum.Foliate, desktopeditors, impressive, mupdf-gl, mupdf-x11, mupdf-x11-curl, muraster, mutool, planmaker18, planmaker18free, presentations18, presentations18free, textmaker18, textmaker18free, teams, xournal, gnome-screenshot 178gfeeds, firefox-x11, tvbrowser, rtv, clipgrab, gnome-passwordsafe, bibtex, gummi, latex, pdflatex, tex, wpp, wpspdf, wps, et, multimc, gnome-hexgl, com.github.johnfactotum.Foliate, desktopeditors, impressive, mupdf-gl, mupdf-x11, mupdf-x11-curl, muraster, mutool, planmaker18, planmaker18free, presentations18, presentations18free, textmaker18, textmaker18free, teams, xournal,
179gnome-screenshot, ripperX, sound-juicer
diff --git a/etc/asunder.profile b/etc/asunder.profile
index 1f3acd735..fceac7cf9 100644
--- a/etc/asunder.profile
+++ b/etc/asunder.profile
@@ -20,21 +20,25 @@ include disable-passwdmgr.inc
20include disable-programs.inc 20include disable-programs.inc
21include disable-xdg.inc 21include disable-xdg.inc
22 22
23include whitelist-usr-share-common.inc
23include whitelist-var-common.inc 24include whitelist-var-common.inc
24 25
25apparmor 26apparmor
26caps.drop all 27caps.drop all
27netfilter 28netfilter
29no3d
28nodbus 30nodbus
29# nogroups 31# nogroups
30nonewprivs 32nonewprivs
31noroot 33noroot
32nou2f 34nou2f
35notv
33novideo 36novideo
34protocol unix,inet,inet6 37protocol unix,inet,inet6
35seccomp 38seccomp
36shell none 39shell none
37 40
41private-cache
38private-dev 42private-dev
39private-tmp 43private-tmp
40 44
diff --git a/etc/disable-programs.inc b/etc/disable-programs.inc
index 0786ba7d2..b54c1cce3 100644
--- a/etc/disable-programs.inc
+++ b/etc/disable-programs.inc
@@ -305,6 +305,7 @@ blacklist ${HOME}/.config/slimjet
305blacklist ${HOME}/.config/smplayer 305blacklist ${HOME}/.config/smplayer
306blacklist ${HOME}/.config/smtube 306blacklist ${HOME}/.config/smtube
307blacklist ${HOME}/.config/snox 307blacklist ${HOME}/.config/snox
308blacklist ${HOME}/.config/sound-juicer
308blacklist ${HOME}/.config/specialmailcollectionsrc 309blacklist ${HOME}/.config/specialmailcollectionsrc
309blacklist ${HOME}/.config/spotify 310blacklist ${HOME}/.config/spotify
310blacklist ${HOME}/.config/sqlitebrowser 311blacklist ${HOME}/.config/sqlitebrowser
@@ -650,6 +651,7 @@ blacklist ${HOME}/.remmina
650blacklist ${HOME}/.repo_.gitconfig.json 651blacklist ${HOME}/.repo_.gitconfig.json
651blacklist ${HOME}/.repoconfig 652blacklist ${HOME}/.repoconfig
652blacklist ${HOME}/.retroshare 653blacklist ${HOME}/.retroshare
654blacklist ${HOME}/.ripperXrc
653blacklist ${HOME}/.scorched3d 655blacklist ${HOME}/.scorched3d
654blacklist ${HOME}/.scribus 656blacklist ${HOME}/.scribus
655blacklist ${HOME}/.scribusrc 657blacklist ${HOME}/.scribusrc
diff --git a/etc/ripperx.profile b/etc/ripperx.profile
new file mode 100644
index 000000000..b572aa1b4
--- /dev/null
+++ b/etc/ripperx.profile
@@ -0,0 +1,41 @@
1# Firejail profile for mpv
2# Description: Graphical audio CD ripper and encoder
3# This file is overwritten after every install/update
4# Persistent local customizations
5include ripperx.local
6# Persistent global definitions
7include globals.local
8
9noblacklist ${HOME}/.ripperXrc
10noblacklist ${MUSIC}
11
12include disable-common.inc
13include disable-devel.inc
14include disable-exec.inc
15include disable-interpreters.inc
16include disable-passwdmgr.inc
17include disable-programs.inc
18include disable-xdg.inc
19
20include whitelist-usr-share-common.inc
21include whitelist-var-common.inc
22
23apparmor
24caps.drop all
25netfilter
26no3d
27nodbus
28nogroups
29nonewprivs
30noroot
31nou2f
32notv
33novideo
34protocol unix,inet,inet6
35seccomp
36shell none
37tracelog
38
39private-cache
40private-dev
41private-tmp
diff --git a/etc/sound-juicer.profile b/etc/sound-juicer.profile
new file mode 100644
index 000000000..ebd321573
--- /dev/null
+++ b/etc/sound-juicer.profile
@@ -0,0 +1,41 @@
1# Firejail profile for mpv
2# Description: Graphical audio CD ripper and encoder
3# This file is overwritten after every install/update
4# Persistent local customizations
5include sound-juicer.local
6# Persistent global definitions
7include globals.local
8
9noblacklist ${HOME}/.config/sound-juicer
10noblacklist ${MUSIC}
11
12include disable-common.inc
13include disable-devel.inc
14include disable-exec.inc
15include disable-interpreters.inc
16include disable-passwdmgr.inc
17include disable-programs.inc
18include disable-xdg.inc
19
20include whitelist-var-common.inc
21
22apparmor
23caps.drop all
24netfilter
25no3d
26#nodbus
27nogroups
28nonewprivs
29noroot
30nosound
31nou2f
32notv
33novideo
34protocol unix,inet,inet6,netlink
35seccomp
36shell none
37tracelog
38
39private-cache
40private-dev
41private-tmp
diff --git a/src/firecfg/firecfg.config b/src/firecfg/firecfg.config
index c2401ee32..2798605d5 100644
--- a/src/firecfg/firecfg.config
+++ b/src/firecfg/firecfg.config
@@ -552,6 +552,7 @@ rhythmbox-client
552ricochet 552ricochet
553riot-desktop 553riot-desktop
554riot-web 554riot-web
555ripperx
555ristretto 556ristretto
556rocketchat 557rocketchat
557rtorrent 558rtorrent
@@ -584,6 +585,7 @@ smtube
584snox 585snox
585soffice 586soffice
586sol 587sol
588sound-juicer
587soundconverter 589soundconverter
588spotify 590spotify
589sqlitebrowser 591sqlitebrowser