aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLibravatar glitsj16 <glitsj16@users.noreply.github.com>2024-03-15 00:04:13 +0000
committerLibravatar GitHub <noreply@github.com>2024-03-15 00:04:13 +0000
commit259062d952b82a7290de4c44136885bc08be3edc (patch)
tree447fdf8988d2f7e11c67d3782447c543ff70d176
parentNew profile: statusof.profile (#6253) (diff)
downloadfirejail-259062d952b82a7290de4c44136885bc08be3edc.tar.gz
firejail-259062d952b82a7290de4c44136885bc08be3edc.tar.zst
firejail-259062d952b82a7290de4c44136885bc08be3edc.zip
New profile: cloneit (#6232)
Description: A CLI tool to download specific GitHub directories or files. https://github.com/alok8bb/cloneit https://aur.archlinux.org/packages/cloneit-git
-rw-r--r--etc/profile-a-l/cloneit.profile61
-rw-r--r--src/firecfg/firecfg.config1
2 files changed, 62 insertions, 0 deletions
diff --git a/etc/profile-a-l/cloneit.profile b/etc/profile-a-l/cloneit.profile
new file mode 100644
index 000000000..b5328a807
--- /dev/null
+++ b/etc/profile-a-l/cloneit.profile
@@ -0,0 +1,61 @@
1# Firejail profile for cloneit
2# Description: A CLI tool to download specific GitHub directories or files
3# This file is overwritten after every install/update
4quiet
5# Persistent local customizations
6include cloneit.local
7# Persistent global definitions
8include globals.local
9
10blacklist /tmp/.X11-unix
11blacklist /usr/libexec
12blacklist ${RUNUSER}
13
14include disable-common.inc
15include disable-devel.inc
16include disable-exec.inc
17include disable-interpreters.inc
18include disable-proc.inc
19include disable-programs.inc
20include disable-shell.inc
21include disable-xdg.inc
22
23include whitelist-run-common.inc
24include whitelist-runuser-common.inc
25include whitelist-usr-share-common.inc
26include whitelist-var-common.inc
27
28apparmor
29caps.drop all
30ipc-namespace
31machine-id
32netfilter
33no3d
34nodvd
35nogroups
36noinput
37nonewprivs
38noprinters
39noroot
40nosound
41notv
42nou2f
43novideo
44protocol unix,inet,inet6
45seccomp
46seccomp.block-secondary
47tracelog
48x11 none
49
50disable-mnt
51private-bin cloneit
52private-cache
53private-dev
54private-etc @network,@tls-ca,rpc,services
55private-tmp
56
57dbus-user none
58dbus-system none
59
60memory-deny-write-execute
61restrict-namespaces
diff --git a/src/firecfg/firecfg.config b/src/firecfg/firecfg.config
index 9b949cf90..e56e55479 100644
--- a/src/firecfg/firecfg.config
+++ b/src/firecfg/firecfg.config
@@ -163,6 +163,7 @@ clipgrab
163clipit 163clipit
164cliqz 164cliqz
165clocks 165clocks
166cloneit
166cmus 167cmus
167code 168code
168code-oss 169code-oss