aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLibravatar rusty-snake <41237666+rusty-snake@users.noreply.github.com>2020-04-17 15:47:56 +0000
committerLibravatar GitHub <noreply@github.com>2020-04-17 15:47:56 +0000
commite467bf5be33c8543cc20e9297ef09f878a68bb3a (patch)
tree20751ac844683592aed7e8136049cfde2cce55d0
parentRevert https://github.com/netblue30/firejail/commit/ca6eec7dcf388c3d0bf52f54c... (diff)
parentAdd nicotine to firecfg.config (diff)
downloadfirejail-e467bf5be33c8543cc20e9297ef09f878a68bb3a.tar.gz
firejail-e467bf5be33c8543cc20e9297ef09f878a68bb3a.tar.zst
firejail-e467bf5be33c8543cc20e9297ef09f878a68bb3a.zip
Merge pull request #3348 from chrpinedo/profile-nicotine
Add new profile: nicotine
-rw-r--r--etc/disable-programs.inc1
-rw-r--r--etc/nicotine.profile55
-rw-r--r--src/firecfg/firecfg.config1
3 files changed, 57 insertions, 0 deletions
diff --git a/etc/disable-programs.inc b/etc/disable-programs.inc
index 6a50f8561..ffe60e283 100644
--- a/etc/disable-programs.inc
+++ b/etc/disable-programs.inc
@@ -654,6 +654,7 @@ blacklist ${HOME}/.netactview
654blacklist ${HOME}/.neverball 654blacklist ${HOME}/.neverball
655blacklist ${HOME}/.newsbeuter 655blacklist ${HOME}/.newsbeuter
656blacklist ${HOME}/.newsboat 656blacklist ${HOME}/.newsboat
657blacklist ${HOME}/.nicotine
657blacklist ${HOME}/.nv 658blacklist ${HOME}/.nv
658blacklist ${HOME}/.nylas-mail 659blacklist ${HOME}/.nylas-mail
659blacklist ${HOME}/.openarena 660blacklist ${HOME}/.openarena
diff --git a/etc/nicotine.profile b/etc/nicotine.profile
new file mode 100644
index 000000000..7764edffb
--- /dev/null
+++ b/etc/nicotine.profile
@@ -0,0 +1,55 @@
1# Firejail profile for Nicotine Plus
2# Description: Soulseek music-sharing client
3# This file is overwritten after every install/update
4# Persistent local customizations
5include nicotine.local
6# Persistent global definitions
7include globals.local
8
9noblacklist ${HOME}/.nicotine
10
11include allow-python2.inc
12
13include disable-common.inc
14include disable-devel.inc
15include disable-exec.inc
16include disable-interpreters.inc
17include disable-passwdmgr.inc
18include disable-programs.inc
19include disable-xdg.inc
20
21mkdir ${HOME}/.nicotine
22whitelist ${DOWNLOADS}
23whitelist ${HOME}/.nicotine
24whitelist /usr/share/GeoIP
25include whitelist-common.inc
26include whitelist-runuser-common.inc
27include whitelist-usr-share-common.inc
28include whitelist-var-common.inc
29
30apparmor
31caps.drop all
32#ipc-namespace
33netfilter
34no3d
35nodvd
36nogroups
37nonewprivs
38noroot
39nosound
40notv
41nou2f
42novideo
43protocol unix,inet,inet6
44seccomp
45shell none
46tracelog
47
48disable-mnt
49private-bin nicotine,python2*
50private-cache
51private-dev
52private-tmp
53
54dbus-user none
55dbus-system none
diff --git a/src/firecfg/firecfg.config b/src/firecfg/firecfg.config
index a19819552..809ab3129 100644
--- a/src/firecfg/firecfg.config
+++ b/src/firecfg/firecfg.config
@@ -492,6 +492,7 @@ neverputt
492newsbeuter 492newsbeuter
493newsboat 493newsboat
494nheko 494nheko
495nicotine
495nitroshare 496nitroshare
496nitroshare-cli 497nitroshare-cli
497nitroshare-nmh 498nitroshare-nmh