aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLibravatar rusty-snake <print_hello_world+Public@protonmail.com>2019-10-12 17:48:24 +0200
committerLibravatar rusty-snake <print_hello_world+Public@protonmail.com>2019-10-12 17:48:24 +0200
commit79a3aefdbc098b85d9989852a4eb2598316f9964 (patch)
tree0bb9f1d1dda7adf981575da2483315cda7a47795
parentx11 xorg: blacklist non-default Xauthority file (diff)
downloadfirejail-79a3aefdbc098b85d9989852a4eb2598316f9964.tar.gz
firejail-79a3aefdbc098b85d9989852a4eb2598316f9964.tar.zst
firejail-79a3aefdbc098b85d9989852a4eb2598316f9964.zip
kalgebra.profile, kalgebramobile.profile
-rw-r--r--README.md2
-rw-r--r--RELNOTES5
-rw-r--r--etc/disable-programs.inc2
-rw-r--r--etc/kalgebra.profile47
-rw-r--r--etc/kalgebramobile.profile5
-rw-r--r--src/firecfg/firecfg.config2
6 files changed, 61 insertions, 2 deletions
diff --git a/README.md b/README.md
index bd6ba406a..f73168986 100644
--- a/README.md
+++ b/README.md
@@ -118,4 +118,4 @@ We also keep a list of profile fixes for previous released versions in [etc-fixe
118 118
119## New profiles: 119## New profiles:
120 120
121gnome-sound-recorder, godot, jerry, keepassxc-cli, keepassxc-proxy, klatexformula, klatexformula_cmdl, links, newsbeuter, OpenArena, pandoc, qgis, rhythmbox-client, tcpdump, teams-for-linux, tshark, xlinks, zeal, mpg123, conplay, mpg123.bin, mpg123-alsa, mpg123-id3dump, mpg123-jack, mpg123-nas, mpg123-openal, mpg123-oss, mpg123-portaudio, mpg123-pulse, mpg123-strip, out123, pavucontrol-qt, gnome-characters, gnome-character-map, rsync, Whalebird, tor-browser (AUR), Zulip, tb-starter-wrapper, bzcat, kiwix-desktop, ar, gnome-latex, pngquant 121gnome-sound-recorder, godot, jerry, keepassxc-cli, keepassxc-proxy, klatexformula, klatexformula_cmdl, links, newsbeuter, OpenArena, pandoc, qgis, rhythmbox-client, tcpdump, teams-for-linux, tshark, xlinks, zeal, mpg123, conplay, mpg123.bin, mpg123-alsa, mpg123-id3dump, mpg123-jack, mpg123-nas, mpg123-openal, mpg123-oss, mpg123-portaudio, mpg123-pulse, mpg123-strip, out123, pavucontrol-qt, gnome-characters, gnome-character-map, rsync, Whalebird, tor-browser (AUR), Zulip, tb-starter-wrapper, bzcat, kiwix-desktop, ar, gnome-latex, pngquant, kalgebra, kalgebramobile
diff --git a/RELNOTES b/RELNOTES
index cad0b974c..92208fba0 100644
--- a/RELNOTES
+++ b/RELNOTES
@@ -6,6 +6,8 @@ firejail (0.9.61) baseline; urgency=low
6 * several seccomp enhancements 6 * several seccomp enhancements
7 * compiler flags autodetection 7 * compiler flags autodetection
8 * new scripts in conrib: gdb-firejail.sh and sort.py 8 * new scripts in conrib: gdb-firejail.sh and sort.py
9 * enhancement: whitelist /usr/share in some profiles
10 * new condition: HAS_X11
9 * new profiles: qgis, klatexformula, klatexformula_cmdl, links, xlinks 11 * new profiles: qgis, klatexformula, klatexformula_cmdl, links, xlinks
10 * new profiles: pandoc, teams-for-linux, OpenArena, gnome-sound-recorder 12 * new profiles: pandoc, teams-for-linux, OpenArena, gnome-sound-recorder
11 * new profiles: godot, tcpdump, tshark, newsbeuter, keepassxc-cli 13 * new profiles: godot, tcpdump, tshark, newsbeuter, keepassxc-cli
@@ -16,7 +18,8 @@ firejail (0.9.61) baseline; urgency=low
16 * new profiles: gnome-characters, gnome-character-map, rsync, Whalebird, 18 * new profiles: gnome-characters, gnome-character-map, rsync, Whalebird,
17 * new profiles: tor-browser (AUR), Zulip, tb-starter-wrapper, bzcat, 19 * new profiles: tor-browser (AUR), Zulip, tb-starter-wrapper, bzcat,
18 * new profiles: kiwix-desktop, bzcat, zstd, pzstd, zstdcat, zstdgrep, zstdless 20 * new profiles: kiwix-desktop, bzcat, zstd, pzstd, zstdcat, zstdgrep, zstdless
19 * new profiles: zstdmt, unzstd, i2p, ar, gnome-latex, pngquant 21 * new profiles: zstdmt, unzstd, i2p, ar, gnome-latex, pngquant, kalgebra
22 * new profiles: kalgebramobile
20 -- netblue30 <netblue30@yahoo.com> Sat, 1 Jun 2019 08:00:00 -0500 23 -- netblue30 <netblue30@yahoo.com> Sat, 1 Jun 2019 08:00:00 -0500
21 24
22firejail (0.9.60) baseline; urgency=low 25firejail (0.9.60) baseline; urgency=low
diff --git a/etc/disable-programs.inc b/etc/disable-programs.inc
index 9098d38c8..a546f05e3 100644
--- a/etc/disable-programs.inc
+++ b/etc/disable-programs.inc
@@ -203,6 +203,7 @@ blacklist ${HOME}/.config/itch
203blacklist ${HOME}/.config/jd-gui.cfg 203blacklist ${HOME}/.config/jd-gui.cfg
204blacklist ${HOME}/.config/k3brc 204blacklist ${HOME}/.config/k3brc
205blacklist ${HOME}/.config/kaffeinerc 205blacklist ${HOME}/.config/kaffeinerc
206blacklist ${HOME}/.config/kalgebrarc
206blacklist ${HOME}/.config/katemetainfos 207blacklist ${HOME}/.config/katemetainfos
207blacklist ${HOME}/.config/katepartrc 208blacklist ${HOME}/.config/katepartrc
208blacklist ${HOME}/.config/katerc 209blacklist ${HOME}/.config/katerc
@@ -516,6 +517,7 @@ blacklist ${HOME}/.local/share/gradio
516blacklist ${HOME}/.local/share/gwenview 517blacklist ${HOME}/.local/share/gwenview
517blacklist ${HOME}/.local/share/i2p 518blacklist ${HOME}/.local/share/i2p
518blacklist ${HOME}/.local/share/kaffeine 519blacklist ${HOME}/.local/share/kaffeine
520blacklist ${HOME}/.local/share/kalgebra
519blacklist ${HOME}/.local/share/kate 521blacklist ${HOME}/.local/share/kate
520blacklist ${HOME}/.local/share/kdenlive 522blacklist ${HOME}/.local/share/kdenlive
521blacklist ${HOME}/.local/share/kget 523blacklist ${HOME}/.local/share/kget
diff --git a/etc/kalgebra.profile b/etc/kalgebra.profile
new file mode 100644
index 000000000..2dc90b9b9
--- /dev/null
+++ b/etc/kalgebra.profile
@@ -0,0 +1,47 @@
1# Firejail profile for kalgebra
2# Description: 2D and 3D Graph Calculator
3# This file is overwritten after every install/update
4# Persistent local customizations
5include kalgebra.local
6# Persistent global definitions
7include globals.local
8
9noblacklist ${HOME}/.config/kalgebrarc
10noblacklist ${HOME}/.local/share/kalgebra
11
12include disable-common.inc
13include disable-devel.inc
14include disable-exec.inc
15include disable-interpreters.inc
16include disable-passwdmgr.inc
17include disable-programs.inc
18include disable-xdg.inc
19
20whitelist /usr/share/kalgebramobile
21include whitelist-usr-share-common.inc
22include whitelist-var-common.inc
23
24apparmor
25caps.drop all
26machine-id
27net none
28nodbus
29nodvd
30nogroups
31nonewprivs
32noroot
33nosound
34notv
35nou2f
36novideo
37protocol unix,netlink
38seccomp !chroot
39shell none
40# tracelog
41
42disable-mnt
43private-bin kalgebra,kalgebramobile
44private-cache
45private-dev
46private-etc fonts,machine-id
47private-tmp
diff --git a/etc/kalgebramobile.profile b/etc/kalgebramobile.profile
new file mode 100644
index 000000000..d2394fe20
--- /dev/null
+++ b/etc/kalgebramobile.profile
@@ -0,0 +1,5 @@
1# Firejail profile for kalgebramobile
2# This file is overwritten after every install/update
3
4# Redirect
5include kalgebra.profile
diff --git a/src/firecfg/firecfg.config b/src/firecfg/firecfg.config
index f90d6c6bc..1ab3efdd1 100644
--- a/src/firecfg/firecfg.config
+++ b/src/firecfg/firecfg.config
@@ -300,6 +300,8 @@ jerry
300jitsi 300jitsi
301k3b 301k3b
302kaffeine 302kaffeine
303kalgebra
304kalgebramobile
303karbon 305karbon
304kate 306kate
305kcalc 307kcalc