aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLibravatar rusty-snake <print_hello_world+Public@protonmail.com>2019-05-25 10:24:28 +0200
committerLibravatar rusty-snake <print_hello_world+Public@protonmail.com>2019-05-25 10:24:28 +0200
commit74b71ae2f1cada1295826a24fd636d23683d343e (patch)
treef74b2e47093d46f007edb82e27ff73c1ff2d0f93
parentsmall private-cwd adjustments (diff)
downloadfirejail-74b71ae2f1cada1295826a24fd636d23683d343e.tar.gz
firejail-74b71ae2f1cada1295826a24fd636d23683d343e.tar.zst
firejail-74b71ae2f1cada1295826a24fd636d23683d343e.zip
Add ktouch.profile
-rw-r--r--README2
-rw-r--r--README.md2
-rw-r--r--RELNOTES2
-rw-r--r--etc/disable-programs.inc2
-rw-r--r--etc/ktouch.profile50
5 files changed, 56 insertions, 2 deletions
diff --git a/README b/README
index 61b21ac6d..b2123aba2 100644
--- a/README
+++ b/README
@@ -559,6 +559,7 @@ rusty-snake (https://github.com/rusty-snake)
559 - added profiles: gajim-history-manager, freemind, nomacs, kid3 559 - added profiles: gajim-history-manager, freemind, nomacs, kid3
560 - added profiles: kid3-qt, kid3-cli, anki, utox, mp3splt, mp3wrap 560 - added profiles: kid3-qt, kid3-cli, anki, utox, mp3splt, mp3wrap
561 - added profiles: oggsplt, flacsplt, cheese, inkview, mp3splt-gtk 561 - added profiles: oggsplt, flacsplt, cheese, inkview, mp3splt-gtk
562 - added profiles: ktouch
562 - fixed profiles: kdenlive, bibletime, rhythmbox, gajim, seahorse 563 - fixed profiles: kdenlive, bibletime, rhythmbox, gajim, seahorse
563 - fixed profiles: libreoffice, gnome-maps, wget, seahorse-tool 564 - fixed profiles: libreoffice, gnome-maps, wget, seahorse-tool
564 - fixed profiles: gnome-logs, atom, brackets, gnome-builder, geany 565 - fixed profiles: gnome-logs, atom, brackets, gnome-builder, geany
@@ -573,6 +574,7 @@ rusty-snake (https://github.com/rusty-snake)
573 - hardened profiles: gajim, evince, ffmpeg, feh-network.inc, qtox 574 - hardened profiles: gajim, evince, ffmpeg, feh-network.inc, qtox
574 - hardened profiles: gnome-clocks, meld, minetest, youtube-dl 575 - hardened profiles: gnome-clocks, meld, minetest, youtube-dl
575 - hardened profiles: bibletime, whois, etr, display, feh, mpv, xiphos 576 - hardened profiles: bibletime, whois, etr, display, feh, mpv, xiphos
577 - hardened profiles: gnome-chess
576 - gnome-mpv was renamed to celluloid 578 - gnome-mpv was renamed to celluloid
577 - some typo fixes 579 - some typo fixes
578Salvo 'LtWorf' Tomaselli (https://github.com/ltworf) 580Salvo 'LtWorf' Tomaselli (https://github.com/ltworf)
diff --git a/README.md b/README.md
index c11402386..68caf2f13 100644
--- a/README.md
+++ b/README.md
@@ -112,7 +112,7 @@ We also keep a list of profile fixes for previous released versions in [etc-fixe
112## New profiles: 112## New profiles:
113anki, assogiate, autokey-gtk, autokey-qt, autokey-run, autokey-shell, bzflag, celluoid, cheese, code-oss, crawl, crawl-tiles, crow, d-feet, dconf, 113anki, assogiate, autokey-gtk, autokey-qt, autokey-run, autokey-shell, bzflag, celluoid, cheese, code-oss, crawl, crawl-tiles, crow, d-feet, dconf,
114dconf-editor, devhelp, exfalso, font-manager, freeciv, freecol, freeoffice-planmaker, freeoffice-presentations, freeoffice-textmaker, freemind, 114dconf-editor, devhelp, exfalso, font-manager, freeciv, freecol, freeoffice-planmaker, freeoffice-presentations, freeoffice-textmaker, freemind,
115gconf-editor, geekbench, gnome-keyring, gnome-nettool, gnome-system-log, gramps, gsettings, inkview kid3, kid3-cli, kid3-qt, lincity-ng, lugaru, 115gconf-editor, geekbench, gnome-keyring, gnome-nettool, gnome-system-log, gramps, gsettings, inkview, kid3, kid3-cli, kid3-qt, ktouch, lincity-ng, lugaru,
116Maelstrom, manaplus, megaglest, meteo-qt, mp3splt-gtk, mpdris2, mypaint, nano, netactview, newsboat, nomacs, nyx, opencity, openclonk, openttd, ostrichriders, pavucontrol, 116Maelstrom, manaplus, megaglest, meteo-qt, mp3splt-gtk, mpdris2, mypaint, nano, netactview, newsboat, nomacs, nyx, opencity, openclonk, openttd, ostrichriders, pavucontrol,
117pioneer, pragha, redshift, regextester, seahorse, seahorse-tool, scorched3d, secret-tool, simplescreenrecorder, slashem, subdownloader, sysprof, 117pioneer, pragha, redshift, regextester, seahorse, seahorse-tool, scorched3d, secret-tool, simplescreenrecorder, slashem, subdownloader, sysprof,
118sysprof-cli, teeworlds, torcs, tremulous, transgui, utox, vulturesclaw, vultureseye, warsow, widelands, xfce4-mixer 118sysprof-cli, teeworlds, torcs, tremulous, transgui, utox, vulturesclaw, vultureseye, warsow, widelands, xfce4-mixer
diff --git a/RELNOTES b/RELNOTES
index 508511621..b9e5dd7db 100644
--- a/RELNOTES
+++ b/RELNOTES
@@ -15,7 +15,7 @@ firejail (0.9.60~rc2) baseline; urgency=low
15 * new profiles: oggsplt, flacsplt, gramps, newsboat, freeoffice-planmaker 15 * new profiles: oggsplt, flacsplt, gramps, newsboat, freeoffice-planmaker
16 * new profiles: autokey-gtk, autokey-qt, autokey-run, autokey-shell 16 * new profiles: autokey-gtk, autokey-qt, autokey-run, autokey-shell
17 * new profiles: freeoffice-presentations, freeoffice-textmaker, mp3wrap 17 * new profiles: freeoffice-presentations, freeoffice-textmaker, mp3wrap
18 * new profiles: inkview, meteo-qt, mp3splt-gtk 18 * new profiles: inkview, meteo-qt, mp3splt-gtk, ktouch
19 * memory-deny-write-execute now also blocks memfd_create 19 * memory-deny-write-execute now also blocks memfd_create
20 * drop support for flatpak/snap packages 20 * drop support for flatpak/snap packages
21 -- netblue30 <netblue30@yahoo.com> Sun, 21 Apr 2019 08:00:00 -0500 21 -- netblue30 <netblue30@yahoo.com> Sun, 21 Apr 2019 08:00:00 -0500
diff --git a/etc/disable-programs.inc b/etc/disable-programs.inc
index eb0f73ba2..43157c6c3 100644
--- a/etc/disable-programs.inc
+++ b/etc/disable-programs.inc
@@ -209,6 +209,7 @@ blacklist ${HOME}/.config/kdeconnect
209blacklist ${HOME}/.config/knotesrc 209blacklist ${HOME}/.config/knotesrc
210blacklist ${HOME}/.config/konversationrc 210blacklist ${HOME}/.config/konversationrc
211blacklist ${HOME}/.config/ktorrentrc 211blacklist ${HOME}/.config/ktorrentrc
212blacklist ${HOME}/.config/ktouch2rc
212blacklist ${HOME}/.config/leafpad 213blacklist ${HOME}/.config/leafpad
213blacklist ${HOME}/.config/libreoffice 214blacklist ${HOME}/.config/libreoffice
214blacklist ${HOME}/.config/liferea 215blacklist ${HOME}/.config/liferea
@@ -494,6 +495,7 @@ blacklist ${HOME}/.local/share/knotes
494blacklist ${HOME}/.local/share/krita 495blacklist ${HOME}/.local/share/krita
495blacklist ${HOME}/.local/share/ktorrentrc 496blacklist ${HOME}/.local/share/ktorrentrc
496blacklist ${HOME}/.local/share/ktorrent 497blacklist ${HOME}/.local/share/ktorrent
498blacklist ${HOME}/.local/share/ktouch
497blacklist ${HOME}/.local/share/kwrite 499blacklist ${HOME}/.local/share/kwrite
498blacklist ${HOME}/.local/share/liferea 500blacklist ${HOME}/.local/share/liferea
499blacklist ${HOME}/.local/share/local-mail 501blacklist ${HOME}/.local/share/local-mail
diff --git a/etc/ktouch.profile b/etc/ktouch.profile
new file mode 100644
index 000000000..446bc50ee
--- /dev/null
+++ b/etc/ktouch.profile
@@ -0,0 +1,50 @@
1# Firejail profile for KTouch
2# Description: a typing tutor by KDE
3# This file is overwritten after every install/update
4# Persistent local customizations
5include ktouch.local
6# Persistent global definitions
7include globals.local
8
9noblacklist ${HOME}/.config/ktouch2rc
10noblacklist ${HOME}/.local/share/ktouch
11
12include disable-common.inc
13include disable-devel.inc
14include disable-exec.inc
15include disable-interpreters.inc
16include disable-passwdmgr.inc
17include disable-programs.inc
18include disable-xdg.inc
19
20mkfile ${HOME}/.config/ktouch2rc
21mkdir ${HOME}/.local/share/ktouch
22whitelist ${HOME}/.config/ktouch2rc
23whitelist ${HOME}/.local/share/ktouch
24include whitelist-common.inc
25include whitelist-var-common.inc
26
27apparmor
28caps.drop all
29machine-id
30net none
31nodbus
32nodvd
33nogroups
34nonewprivs
35noroot
36nosound
37notv
38nou2f
39novideo
40protocol unix,netlink
41seccomp
42shell none
43tracelog
44
45disable-mnt
46private-bin ktouch
47private-cache
48private-dev
49private-etc alternatives,fonts,kde5rc,machine-id
50private-tmp