aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLibravatar Tad <tad@spotco.us>2018-01-12 22:45:35 -0500
committerLibravatar Tad <tad@spotco.us>2018-01-12 22:45:35 -0500
commit4f72a60e1add916d36ea4f201a178c157882d7b5 (patch)
tree487814a8f322894fc2a43a52618a45bc0949f76d
parentfs_lib: don't ldd directories, part 2 (diff)
downloadfirejail-4f72a60e1add916d36ea4f201a178c157882d7b5.tar.gz
firejail-4f72a60e1add916d36ea4f201a178c157882d7b5.tar.zst
firejail-4f72a60e1add916d36ea4f201a178c157882d7b5.zip
Add a profile for Pitivi
-rw-r--r--etc/disable-programs.inc1
-rw-r--r--etc/pitivi.profile33
-rw-r--r--src/firecfg/firecfg.config1
3 files changed, 35 insertions, 0 deletions
diff --git a/etc/disable-programs.inc b/etc/disable-programs.inc
index 74e7e45a7..e6d425df2 100644
--- a/etc/disable-programs.inc
+++ b/etc/disable-programs.inc
@@ -162,6 +162,7 @@ blacklist ${HOME}/.config/org.kde.gwenviewrc
162blacklist ${HOME}/.config/pcmanfm 162blacklist ${HOME}/.config/pcmanfm
163blacklist ${HOME}/.config/pdfmod 163blacklist ${HOME}/.config/pdfmod
164blacklist ${HOME}/.config/Pinta 164blacklist ${HOME}/.config/Pinta
165blacklist ${HOME}/.config/pitivi
165blacklist ${HOME}/.config/pix 166blacklist ${HOME}/.config/pix
166blacklist ${HOME}/.config/pluma 167blacklist ${HOME}/.config/pluma
167blacklist ${HOME}/.config/psi+ 168blacklist ${HOME}/.config/psi+
diff --git a/etc/pitivi.profile b/etc/pitivi.profile
new file mode 100644
index 000000000..f2640ed66
--- /dev/null
+++ b/etc/pitivi.profile
@@ -0,0 +1,33 @@
1# Firejail profile for pitivi
2# This file is overwritten after every install/update
3# Persistent local customizations
4include /etc/firejail/pitivi.local
5# Persistent global definitions
6include /etc/firejail/globals.local
7
8
9noblacklist ${HOME}/.config/pitivi
10
11include /etc/firejail/disable-common.inc
12include /etc/firejail/disable-devel.inc
13include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc
15
16caps.drop all
17ipc-namespace
18netfilter
19nodvd
20nogroups
21nonewprivs
22noroot
23notv
24novideo
25protocol unix
26seccomp
27shell none
28
29private-dev
30private-tmp
31
32noexec ${HOME}
33noexec /tmp
diff --git a/src/firecfg/firecfg.config b/src/firecfg/firecfg.config
index 2871ce5b8..6f6dd3f06 100644
--- a/src/firecfg/firecfg.config
+++ b/src/firecfg/firecfg.config
@@ -268,6 +268,7 @@ ping
268pingus 268pingus
269pinta 269pinta
270pithos 270pithos
271pitivi
271pix 272pix
272pluma 273pluma
273polari 274polari