aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLibravatar Vincent43 <31109921+Vincent43@users.noreply.github.com>2019-02-03 13:18:07 +0100
committerLibravatar Vincent43 <31109921+Vincent43@users.noreply.github.com>2019-02-03 13:18:07 +0100
commit63c35052b7e76f40591f709571e19fbcb7cd8f48 (patch)
treefe5819efcbba2f637f3c75933a1cd829f6869823
parentrelnotes (diff)
downloadfirejail-63c35052b7e76f40591f709571e19fbcb7cd8f48.tar.gz
firejail-63c35052b7e76f40591f709571e19fbcb7cd8f48.tar.zst
firejail-63c35052b7e76f40591f709571e19fbcb7cd8f48.zip
Add '$HOME/.local/share/pki' to blacklist
Since nss 3.42, '$HOME/.local/share/pki' is supported dir for storing certs https://hg.mozilla.org/projects/nss/rev/da45424cb9a0b4d8e45e5040e2e3b574d994e254
-rw-r--r--etc-fixes/0.9.52/firefox.profile3
-rw-r--r--etc/chromium-common.profile3
-rw-r--r--etc/disable-common.inc1
-rw-r--r--etc/evolution.profile1
-rw-r--r--etc/firefox-common.profile3
-rw-r--r--etc/franz.profile3
-rw-r--r--etc/mendeleydesktop.profile3
-rw-r--r--etc/midori.profile3
-rw-r--r--etc/min.profile3
-rw-r--r--etc/rambox.profile3
-rw-r--r--etc/seamonkey.profile2
11 files changed, 27 insertions, 1 deletions
diff --git a/etc-fixes/0.9.52/firefox.profile b/etc-fixes/0.9.52/firefox.profile
index 6b19b14df..e3efada2c 100644
--- a/etc-fixes/0.9.52/firefox.profile
+++ b/etc-fixes/0.9.52/firefox.profile
@@ -24,6 +24,7 @@ noblacklist ${HOME}/.local/share/okular
24noblacklist ${HOME}/.local/share/qpdfview 24noblacklist ${HOME}/.local/share/qpdfview
25noblacklist ${HOME}/.mozilla 25noblacklist ${HOME}/.mozilla
26noblacklist ${HOME}/.pki 26noblacklist ${HOME}/.pki
27noblacklist ${HOME}/.local/share/pki
27 28
28include /etc/firejail/disable-common.inc 29include /etc/firejail/disable-common.inc
29include /etc/firejail/disable-devel.inc 30include /etc/firejail/disable-devel.inc
@@ -32,6 +33,7 @@ include /etc/firejail/disable-programs.inc
32mkdir ${HOME}/.cache/mozilla/firefox 33mkdir ${HOME}/.cache/mozilla/firefox
33mkdir ${HOME}/.mozilla 34mkdir ${HOME}/.mozilla
34mkdir ${HOME}/.pki 35mkdir ${HOME}/.pki
36mkdir ${HOME}/.local/share/pki
35whitelist ${DOWNLOADS} 37whitelist ${DOWNLOADS}
36whitelist ${HOME}/.cache/gnome-mplayer/plugin 38whitelist ${HOME}/.cache/gnome-mplayer/plugin
37whitelist ${HOME}/.cache/mozilla/firefox 39whitelist ${HOME}/.cache/mozilla/firefox
@@ -60,6 +62,7 @@ whitelist ${HOME}/.mozilla
60whitelist ${HOME}/.pentadactyl 62whitelist ${HOME}/.pentadactyl
61whitelist ${HOME}/.pentadactylrc 63whitelist ${HOME}/.pentadactylrc
62whitelist ${HOME}/.pki 64whitelist ${HOME}/.pki
65whitelist ${HOME}/.local/share/pki
63whitelist ${HOME}/.vimperator 66whitelist ${HOME}/.vimperator
64whitelist ${HOME}/.vimperatorrc 67whitelist ${HOME}/.vimperatorrc
65whitelist ${HOME}/.wine-pipelight 68whitelist ${HOME}/.wine-pipelight
diff --git a/etc/chromium-common.profile b/etc/chromium-common.profile
index 7d8bc15ba..a182e5d20 100644
--- a/etc/chromium-common.profile
+++ b/etc/chromium-common.profile
@@ -7,6 +7,7 @@ include chromium-common.local
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.pki 9noblacklist ${HOME}/.pki
10noblacklist ${HOME}/.local/share/pki
10 11
11include disable-common.inc 12include disable-common.inc
12include disable-devel.inc 13include disable-devel.inc
@@ -14,8 +15,10 @@ include disable-interpreters.inc
14include disable-programs.inc 15include disable-programs.inc
15 16
16mkdir ${HOME}/.pki 17mkdir ${HOME}/.pki
18mkdir ${HOME}/.local/share/pki
17whitelist ${DOWNLOADS} 19whitelist ${DOWNLOADS}
18whitelist ${HOME}/.pki 20whitelist ${HOME}/.pki
21whitelist ${HOME}/.local/share/pki
19include whitelist-common.inc 22include whitelist-common.inc
20include whitelist-var-common.inc 23include whitelist-var-common.inc
21 24
diff --git a/etc/disable-common.inc b/etc/disable-common.inc
index 985d658e0..f98f247d5 100644
--- a/etc/disable-common.inc
+++ b/etc/disable-common.inc
@@ -306,6 +306,7 @@ blacklist ${HOME}/.mutt
306blacklist ${HOME}/.muttrc 306blacklist ${HOME}/.muttrc
307blacklist ${HOME}/.netrc 307blacklist ${HOME}/.netrc
308blacklist ${HOME}/.pki 308blacklist ${HOME}/.pki
309blacklist ${HOME}/.local/share/pki
309blacklist ${HOME}/.smbcredentials 310blacklist ${HOME}/.smbcredentials
310blacklist ${HOME}/.ssh 311blacklist ${HOME}/.ssh
311blacklist ${HOME}/.vaults 312blacklist ${HOME}/.vaults
diff --git a/etc/evolution.profile b/etc/evolution.profile
index 1cce0656c..96f7e0eb5 100644
--- a/etc/evolution.profile
+++ b/etc/evolution.profile
@@ -14,6 +14,7 @@ noblacklist ${HOME}/.config/evolution
14noblacklist ${HOME}/.gnupg 14noblacklist ${HOME}/.gnupg
15noblacklist ${HOME}/.local/share/evolution 15noblacklist ${HOME}/.local/share/evolution
16noblacklist ${HOME}/.pki 16noblacklist ${HOME}/.pki
17noblacklist ${HOME}/.local/share/pki
17 18
18include disable-common.inc 19include disable-common.inc
19include disable-devel.inc 20include disable-devel.inc
diff --git a/etc/firefox-common.profile b/etc/firefox-common.profile
index 644dc89b1..7c65be7cb 100644
--- a/etc/firefox-common.profile
+++ b/etc/firefox-common.profile
@@ -10,6 +10,7 @@ include firefox-common.local
10#include firefox-common-addons.inc 10#include firefox-common-addons.inc
11 11
12noblacklist ${HOME}/.pki 12noblacklist ${HOME}/.pki
13noblacklist ${HOME}/.local/share/pki
13 14
14include disable-common.inc 15include disable-common.inc
15include disable-devel.inc 16include disable-devel.inc
@@ -17,8 +18,10 @@ include disable-interpreters.inc
17include disable-programs.inc 18include disable-programs.inc
18 19
19mkdir ${HOME}/.pki 20mkdir ${HOME}/.pki
21mkdir ${HOME}/.local/share/pki
20whitelist ${DOWNLOADS} 22whitelist ${DOWNLOADS}
21whitelist ${HOME}/.pki 23whitelist ${HOME}/.pki
24whitelist ${HOME}/.local/share/pki
22include whitelist-common.inc 25include whitelist-common.inc
23include whitelist-var-common.inc 26include whitelist-var-common.inc
24 27
diff --git a/etc/franz.profile b/etc/franz.profile
index 5ce8954c4..d6445ff8e 100644
--- a/etc/franz.profile
+++ b/etc/franz.profile
@@ -8,6 +8,7 @@ include globals.local
8noblacklist ${HOME}/.cache/Franz 8noblacklist ${HOME}/.cache/Franz
9noblacklist ${HOME}/.config/Franz 9noblacklist ${HOME}/.config/Franz
10noblacklist ${HOME}/.pki 10noblacklist ${HOME}/.pki
11noblacklist ${HOME}/.local/share/pki
11 12
12include disable-common.inc 13include disable-common.inc
13include disable-devel.inc 14include disable-devel.inc
@@ -17,10 +18,12 @@ include disable-programs.inc
17mkdir ${HOME}/.cache/Franz 18mkdir ${HOME}/.cache/Franz
18mkdir ${HOME}/.config/Franz 19mkdir ${HOME}/.config/Franz
19mkdir ${HOME}/.pki 20mkdir ${HOME}/.pki
21mkdir ${HOME}/.local/share/pki
20whitelist ${DOWNLOADS} 22whitelist ${DOWNLOADS}
21whitelist ${HOME}/.cache/Franz 23whitelist ${HOME}/.cache/Franz
22whitelist ${HOME}/.config/Franz 24whitelist ${HOME}/.config/Franz
23whitelist ${HOME}/.pki 25whitelist ${HOME}/.pki
26whitelist ${HOME}/.local/share/pki
24include whitelist-common.inc 27include whitelist-common.inc
25 28
26caps.drop all 29caps.drop all
diff --git a/etc/mendeleydesktop.profile b/etc/mendeleydesktop.profile
index 280baebdc..3a5edc364 100644
--- a/etc/mendeleydesktop.profile
+++ b/etc/mendeleydesktop.profile
@@ -12,7 +12,8 @@ noblacklist ${HOME}/.cache/Mendeley Ltd.
12noblacklist ${HOME}/.config/Mendeley Ltd. 12noblacklist ${HOME}/.config/Mendeley Ltd.
13noblacklist ${HOME}/.local/share/Mendeley Ltd. 13noblacklist ${HOME}/.local/share/Mendeley Ltd.
14noblacklist ${HOME}/.local/share/data/Mendeley Ltd. 14noblacklist ${HOME}/.local/share/data/Mendeley Ltd.
15noblacklist ${HOME}/.pki/nssdb 15noblacklist ${HOME}/.pki
16noblacklist ${HOME}/.local/share/pki
16 17
17# Allow python (blacklisted by disable-interpreters.inc) 18# Allow python (blacklisted by disable-interpreters.inc)
18noblacklist ${PATH}/python2* 19noblacklist ${PATH}/python2*
diff --git a/etc/midori.profile b/etc/midori.profile
index 6a69f2282..4e9a6c63d 100644
--- a/etc/midori.profile
+++ b/etc/midori.profile
@@ -11,6 +11,7 @@ noblacklist ${HOME}/.local/share/midori
11# noblacklist ${HOME}/.local/share/webkit 11# noblacklist ${HOME}/.local/share/webkit
12# noblacklist ${HOME}/.local/share/webkitgtk 12# noblacklist ${HOME}/.local/share/webkitgtk
13noblacklist ${HOME}/.pki 13noblacklist ${HOME}/.pki
14noblacklist ${HOME}/.local/share/pki
14 15
15include disable-common.inc 16include disable-common.inc
16include disable-devel.inc 17include disable-devel.inc
@@ -23,6 +24,7 @@ mkdir ${HOME}/.local/share/midori
23mkdir ${HOME}/.local/share/webkit 24mkdir ${HOME}/.local/share/webkit
24mkdir ${HOME}/.local/share/webkitgtk 25mkdir ${HOME}/.local/share/webkitgtk
25mkdir ${HOME}/.pki 26mkdir ${HOME}/.pki
27mkdir ${HOME}/.local/share/pki
26whitelist ${DOWNLOADS} 28whitelist ${DOWNLOADS}
27whitelist ${HOME}/.cache/gnome-mplayer/plugin 29whitelist ${HOME}/.cache/gnome-mplayer/plugin
28whitelist ${HOME}/.cache/midori 30whitelist ${HOME}/.cache/midori
@@ -33,6 +35,7 @@ whitelist ${HOME}/.local/share/midori
33whitelist ${HOME}/.local/share/webkit 35whitelist ${HOME}/.local/share/webkit
34whitelist ${HOME}/.local/share/webkitgtk 36whitelist ${HOME}/.local/share/webkitgtk
35whitelist ${HOME}/.pki 37whitelist ${HOME}/.pki
38whitelist ${HOME}/.local/share/pki
36include whitelist-common.inc 39include whitelist-common.inc
37 40
38caps.drop all 41caps.drop all
diff --git a/etc/min.profile b/etc/min.profile
index 3029c2952..80baedff7 100644
--- a/etc/min.profile
+++ b/etc/min.profile
@@ -9,6 +9,7 @@ include globals.local
9noblacklist ${HOME}/.config/Min 9noblacklist ${HOME}/.config/Min
10 10
11noblacklist ${HOME}/.pki 11noblacklist ${HOME}/.pki
12noblacklist ${HOME}/.local/share/pki
12 13
13include disable-common.inc 14include disable-common.inc
14include disable-devel.inc 15include disable-devel.inc
@@ -16,8 +17,10 @@ include disable-interpreters.inc
16include disable-programs.inc 17include disable-programs.inc
17 18
18mkdir ${HOME}/.pki 19mkdir ${HOME}/.pki
20mkdir ${HOME}/.local/share/pki
19whitelist ${DOWNLOADS} 21whitelist ${DOWNLOADS}
20whitelist ${HOME}/.pki 22whitelist ${HOME}/.pki
23whitelist ${HOME}/.local/share/pki
21include whitelist-common.inc 24include whitelist-common.inc
22include whitelist-var-common.inc 25include whitelist-var-common.inc
23 26
diff --git a/etc/rambox.profile b/etc/rambox.profile
index 6c65f869b..6f7f37aaf 100644
--- a/etc/rambox.profile
+++ b/etc/rambox.profile
@@ -7,6 +7,7 @@ include globals.local
7 7
8noblacklist ${HOME}/.config/Rambox 8noblacklist ${HOME}/.config/Rambox
9noblacklist ${HOME}/.pki 9noblacklist ${HOME}/.pki
10noblacklist ${HOME}/.local/share/pki
10 11
11include disable-common.inc 12include disable-common.inc
12include disable-devel.inc 13include disable-devel.inc
@@ -15,9 +16,11 @@ include disable-programs.inc
15 16
16mkdir ${HOME}/.config/Rambox 17mkdir ${HOME}/.config/Rambox
17mkdir ${HOME}/.pki 18mkdir ${HOME}/.pki
19mkdir ${HOME}/.local/share/pki
18whitelist ${DOWNLOADS} 20whitelist ${DOWNLOADS}
19whitelist ${HOME}/.config/Rambox 21whitelist ${HOME}/.config/Rambox
20whitelist ${HOME}/.pki 22whitelist ${HOME}/.pki
23whitelist ${HOME}/.local/share/pki
21include whitelist-common.inc 24include whitelist-common.inc
22 25
23caps.drop all 26caps.drop all
diff --git a/etc/seamonkey.profile b/etc/seamonkey.profile
index 9c38414bb..8cb291ba6 100644
--- a/etc/seamonkey.profile
+++ b/etc/seamonkey.profile
@@ -9,6 +9,7 @@ include globals.local
9noblacklist ${HOME}/.cache/mozilla 9noblacklist ${HOME}/.cache/mozilla
10noblacklist ${HOME}/.mozilla 10noblacklist ${HOME}/.mozilla
11noblacklist ${HOME}/.pki 11noblacklist ${HOME}/.pki
12noblacklist ${HOME}/.local/share/pki
12 13
13include disable-common.inc 14include disable-common.inc
14include disable-devel.inc 15include disable-devel.inc
@@ -29,6 +30,7 @@ whitelist ${HOME}/.mozilla
29whitelist ${HOME}/.pentadactyl 30whitelist ${HOME}/.pentadactyl
30whitelist ${HOME}/.pentadactylrc 31whitelist ${HOME}/.pentadactylrc
31whitelist ${HOME}/.pki 32whitelist ${HOME}/.pki
33whitelist ${HOME}/.local/share/pki
32whitelist ${HOME}/.vimperator 34whitelist ${HOME}/.vimperator
33whitelist ${HOME}/.vimperatorrc 35whitelist ${HOME}/.vimperatorrc
34whitelist ${HOME}/.wine-pipelight 36whitelist ${HOME}/.wine-pipelight