aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLibravatar Fred Barclay <Fred-Barclay@users.noreply.github.com>2019-06-26 21:59:01 -0500
committerLibravatar Fred Barclay <Fred-Barclay@users.noreply.github.com>2019-06-26 21:59:01 -0500
commit5bad67a48618ad8039ba93291948f0e2cf8808c6 (patch)
treebabcb1b36283eac7b79d6149a090b21021a57ad5
parentHardening a few profiles (#2800) (diff)
downloadfirejail-5bad67a48618ad8039ba93291948f0e2cf8808c6.tar.gz
firejail-5bad67a48618ad8039ba93291948f0e2cf8808c6.tar.zst
firejail-5bad67a48618ad8039ba93291948f0e2cf8808c6.zip
Add profile for jerry chess
-rw-r--r--README.md3
-rw-r--r--RELNOTES2
-rw-r--r--etc/disable-programs.inc1
-rw-r--r--etc/jerry.profile41
-rw-r--r--src/firecfg/firecfg.config1
5 files changed, 46 insertions, 2 deletions
diff --git a/README.md b/README.md
index f0cecd1e7..e1a79120a 100644
--- a/README.md
+++ b/README.md
@@ -115,4 +115,5 @@ We also keep a list of profile fixes for previous released versions in [etc-fixe
115 115
116## New profiles: 116## New profiles:
117 117
118klatexformula, klatexformula_cmdl, links, pandoc, qgis, teams-for-linux, xlinks, OpenArena, gnome-sound-recorder, godot, tcpdump, tshark, keepassxc-cli, keepassxc-proxy, newsbeuter, rhythmbox-client 118klatexformula, klatexformula_cmdl, links, pandoc, qgis, teams-for-linux, xlinks, OpenArena, gnome-sound-recorder, godot, tcpdump, tshark, keepassxc-cli, keepassxc-proxy, newsbeuter, rhythmbox-client,
119jerry
diff --git a/RELNOTES b/RELNOTES
index 0a3a0a011..a00a27b32 100644
--- a/RELNOTES
+++ b/RELNOTES
@@ -4,7 +4,7 @@ firejail (0.9.61) baseline; urgency=low
4 * new profiles: qgis, klatexformula, klatexformula_cmdl, links, xlinks 4 * new profiles: qgis, klatexformula, klatexformula_cmdl, links, xlinks
5 * new profiles: pandoc, teams-for-linux, OpenArena, gnome-sound-recorder 5 * new profiles: pandoc, teams-for-linux, OpenArena, gnome-sound-recorder
6 * new profiles: godot, tcpdump, tshark, newsbeuter, keepassxc-cli 6 * new profiles: godot, tcpdump, tshark, newsbeuter, keepassxc-cli
7 * new profiles: keepassxc-proxy, rhythmbox-client 7 * new profiles: keepassxc-proxy, rhythmbox-client, jerry
8 -- netblue30 <netblue30@yahoo.com> Sat, 1 Jun 2019 08:00:00 -0500 8 -- netblue30 <netblue30@yahoo.com> Sat, 1 Jun 2019 08:00:00 -0500
9 9
10firejail (0.9.60) baseline; urgency=low 10firejail (0.9.60) baseline; urgency=low
diff --git a/etc/disable-programs.inc b/etc/disable-programs.inc
index fb7e02d0b..679a8c0a0 100644
--- a/etc/disable-programs.inc
+++ b/etc/disable-programs.inc
@@ -151,6 +151,7 @@ blacklist ${HOME}/.config/digikam
151blacklist ${HOME}/.config/digikamrc 151blacklist ${HOME}/.config/digikamrc
152blacklist ${HOME}/.config/discord 152blacklist ${HOME}/.config/discord
153blacklist ${HOME}/.config/discordcanary 153blacklist ${HOME}/.config/discordcanary
154blacklist ${HOME}/.config/dkl
154blacklist ${HOME}/.config/dnox 155blacklist ${HOME}/.config/dnox
155blacklist ${HOME}/.config/dolphinrc 156blacklist ${HOME}/.config/dolphinrc
156blacklist ${HOME}/.config/dragonplayerrc 157blacklist ${HOME}/.config/dragonplayerrc
diff --git a/etc/jerry.profile b/etc/jerry.profile
new file mode 100644
index 000000000..28eb4d207
--- /dev/null
+++ b/etc/jerry.profile
@@ -0,0 +1,41 @@
1# Firejail profile for jerry
2# Description: Chess GUI
3# This file is overwritten after every install/update
4# Persistent local customizations
5include jerry.local
6# Persistent global definitions
7include globals.local
8
9noblacklist ${HOME}/.config/dkl
10
11include disable-common.inc
12include disable-devel.inc
13include disable-exec.inc
14include disable-interpreters.inc
15include disable-passwdmgr.inc
16include disable-programs.inc
17include disable-xdg.inc
18
19caps.drop all
20machine-id
21net none
22no3d
23nodbus
24nodvd
25nogroups
26nonewprivs
27noroot
28nosound
29notv
30novideo
31protocol unix
32seccomp
33shell none
34tracelog
35
36private-bin jerry,stockfish,sh,bash
37private-dev
38private-etc fonts,gtk-2.0,gtk-3.0
39private-tmp
40
41memory-deny-write-execute
diff --git a/src/firecfg/firecfg.config b/src/firecfg/firecfg.config
index b4efa3add..b9f493969 100644
--- a/src/firecfg/firecfg.config
+++ b/src/firecfg/firecfg.config
@@ -286,6 +286,7 @@ inkview
286inox 286inox
287iridium 287iridium
288iridium-browser 288iridium-browser
289jerry
289jd-gui 290jd-gui
290jdownloader 291jdownloader
291jitsi 292jitsi