aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLibravatar netblue30 <netblue30@yahoo.com>2017-04-03 09:33:46 -0400
committerLibravatar netblue30 <netblue30@yahoo.com>2017-04-03 09:33:46 -0400
commitccc2ed781742057205e5df6aea296a12c2043ef2 (patch)
tree4798cd27253910530dbc278e104a7c25b6ef0ba4
parentupdated for Go, Rust, and OpenSSL blacklist: #1186 (diff)
downloadfirejail-ccc2ed781742057205e5df6aea296a12c2043ef2.tar.gz
firejail-ccc2ed781742057205e5df6aea296a12c2043ef2.tar.zst
firejail-ccc2ed781742057205e5df6aea296a12c2043ef2.zip
seccomp and brave profile merges
-rw-r--r--README2
-rw-r--r--etc/brave.profile24
-rw-r--r--src/man/firejail.txt4
3 files changed, 24 insertions, 6 deletions
diff --git a/README b/README
index 8d85fcd5a..fcde0c6b9 100644
--- a/README
+++ b/README
@@ -363,6 +363,8 @@ SYN-cook (https://github.com/SYN-cook)
363 - blacklist nautilus and nemo in ~/.local/share/ 363 - blacklist nautilus and nemo in ~/.local/share/
364startx2017 (https://github.com/startx2017) 364startx2017 (https://github.com/startx2017)
365 - syscall list update 365 - syscall list update
366 - updated default seccomp filters - added bpf, clock_settime, personality, process_vm_writev, query_module,
367 settimeofday, stime, umount, userfaultfd, ustat, vm86, and vm86old
366 - enable/disable join support in /etc/firejail/firejail.config 368 - enable/disable join support in /etc/firejail/firejail.config
367 - firecfg fix: create ~/.local/share/applications directory if it doesn't exist 369 - firecfg fix: create ~/.local/share/applications directory if it doesn't exist
368 - firejail.config cleanup 370 - firejail.config cleanup
diff --git a/etc/brave.profile b/etc/brave.profile
index d7678d5d5..a65a3adc8 100644
--- a/etc/brave.profile
+++ b/etc/brave.profile
@@ -4,18 +4,32 @@ include /etc/firejail/brave.local
4 4
5# Profile for Brave browser 5# Profile for Brave browser
6noblacklist ~/.config/brave 6noblacklist ~/.config/brave
7noblacklist ~/.pki
7include /etc/firejail/disable-common.inc 8include /etc/firejail/disable-common.inc
8include /etc/firejail/disable-programs.inc 9include /etc/firejail/disable-programs.inc
9include /etc/firejail/disable-devel.inc 10include /etc/firejail/disable-devel.inc
10 11
11caps.drop all 12#caps.drop all
12netfilter 13netfilter
13nonewprivs 14#nonewprivs
14noroot 15#noroot
15protocol unix,inet,inet6,netlink 16#protocol unix,inet,inet6,netlink
16seccomp 17#seccomp
17 18
18whitelist ${DOWNLOADS} 19whitelist ${DOWNLOADS}
19 20
20mkdir ~/.config/brave 21mkdir ~/.config/brave
21whitelist ~/.config/brave 22whitelist ~/.config/brave
23mkdir ~/.pki
24whitelist ~/.pki
25
26# lastpass, keepass
27# for keepass we additionally need to whitelist our .kdbx password database
28whitelist ~/.keepass
29whitelist ~/.config/keepass
30whitelist ~/.config/KeePass
31whitelist ~/.lastpass
32whitelist ~/.config/lastpass
33
34include /etc/firejail/whitelist-common.inc
35
diff --git a/src/man/firejail.txt b/src/man/firejail.txt
index f603daecb..3deeda960 100644
--- a/src/man/firejail.txt
+++ b/src/man/firejail.txt
@@ -1430,7 +1430,9 @@ add_key, request_key, keyctl, uselib, acct, modify_ldt, pivot_root, io_setup,
1430io_destroy, io_getevents, io_submit, io_cancel, 1430io_destroy, io_getevents, io_submit, io_cancel,
1431remap_file_pages, mbind, get_mempolicy, set_mempolicy, 1431remap_file_pages, mbind, get_mempolicy, set_mempolicy,
1432migrate_pages, move_pages, vmsplice, chroot, 1432migrate_pages, move_pages, vmsplice, chroot,
1433tuxcall, reboot, mfsservctl and get_kernel_syms. 1433tuxcall, reboot, mfsservctl, get_kernel_syms,
1434bpf, clock_settime, personality, process_vm_writev, query_module,
1435settimeofday, stime, umount, userfaultfd, ustat, vm86, and vm86old
1434.br 1436.br
1435 1437
1436.br 1438.br