aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLibravatar glitsj16 <glitsj16@users.noreply.github.com>2024-03-16 20:26:12 +0000
committerLibravatar GitHub <noreply@github.com>2024-03-16 20:26:12 +0000
commit8636d326649c7be838048d0b89fda32db74092b4 (patch)
tree71ab4b9748d25f1d598641199ad15f311de494e0
parentfirejail-local: be less restrictive with torbrowser-launcher (diff)
downloadfirejail-8636d326649c7be838048d0b89fda32db74092b4.tar.gz
firejail-8636d326649c7be838048d0b89fda32db74092b4.tar.zst
firejail-8636d326649c7be838048d0b89fda32db74092b4.zip
New profile: dexios.profile (#6234)
Description: CLI encryption tool https://github.com/brxken128/dexios https://aur.archlinux.org/packages/dexios-bin
-rw-r--r--etc/profile-a-l/dexios.profile63
-rw-r--r--src/firecfg/firecfg.config1
2 files changed, 64 insertions, 0 deletions
diff --git a/etc/profile-a-l/dexios.profile b/etc/profile-a-l/dexios.profile
new file mode 100644
index 000000000..4dfccd685
--- /dev/null
+++ b/etc/profile-a-l/dexios.profile
@@ -0,0 +1,63 @@
1# Firejail profile for dexios
2# Description: CLI encryption tool
3quiet
4# This file is overwritten after every install/update
5# Persistent local customizations
6include dexios.local
7# Persistent global definitions
8include globals.local
9
10blacklist /tmp/.X11-unix
11blacklist /usr/libexec
12blacklist ${RUNUSER}
13
14include disable-common.inc
15include disable-devel.inc
16include disable-exec.inc
17include disable-interpreters.inc
18include disable-proc.inc
19include disable-programs.inc
20include disable-shell.inc
21include disable-xdg.inc
22
23whitelist ${DOWNLOADS}
24include whitelist-run-common.inc
25include whitelist-usr-share-common.inc
26include whitelist-var-common.inc
27
28apparmor
29caps.drop all
30ipc-namespace
31machine-id
32netfilter
33no3d
34nodvd
35nogroups
36noinput
37nonewprivs
38noprinters
39noroot
40nosound
41notv
42nou2f
43novideo
44seccomp.drop socket
45seccomp.block-secondary
46tracelog
47x11 none
48
49disable-mnt
50private-bin dexios
51private-cache
52private-dev
53private-etc
54private-lib
55private-tmp
56
57dbus-user none
58dbus-system none
59
60memory-deny-write-execute
61read-only ${HOME}
62read-write ${DOWNLOADS}
63restrict-namespaces
diff --git a/src/firecfg/firecfg.config b/src/firecfg/firecfg.config
index 1a65d3b5d..275385690 100644
--- a/src/firecfg/firecfg.config
+++ b/src/firecfg/firecfg.config
@@ -200,6 +200,7 @@ deluge
200desktopeditors 200desktopeditors
201devhelp 201devhelp
202dex2jar 202dex2jar
203dexios
203dia 204dia
204dig 205dig
205digikam 206digikam