aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLibravatar netblue30 <netblue30@yahoo.com>2016-10-30 16:01:49 -0400
committerLibravatar GitHub <noreply@github.com>2016-10-30 16:01:49 -0400
commit8ad201fe9dd40c7743c2362065166a959c660edf (patch)
tree7e8e51daa0ae54b6a38454165d8ca4123866ee15
parentmajor cleanup (diff)
parentMerge remote-tracking branch 'upstream/master' (diff)
downloadfirejail-8ad201fe9dd40c7743c2362065166a959c660edf.tar.gz
firejail-8ad201fe9dd40c7743c2362065166a959c660edf.tar.zst
firejail-8ad201fe9dd40c7743c2362065166a959c660edf.zip
Merge pull request #881 from valoq/master
Added profiles for display (imagemagick) and wire
-rw-r--r--etc/Wire.profile22
-rw-r--r--etc/disable-programs.inc1
-rw-r--r--etc/display.profile23
3 files changed, 46 insertions, 0 deletions
diff --git a/etc/Wire.profile b/etc/Wire.profile
new file mode 100644
index 000000000..b488d75e4
--- /dev/null
+++ b/etc/Wire.profile
@@ -0,0 +1,22 @@
1# wire messenger profile
2
3noblacklist ~/.config/Wire
4
5include /etc/firejail/disable-common.inc
6include /etc/firejail/disable-programs.inc
7include /etc/firejail/disable-devel.inc
8include /etc/firejail/disable-passwdmgr.inc
9
10caps.drop all
11netfilter
12nonewprivs
13nogroups
14noroot
15protocol unix,inet,inet6,netlink
16seccomp
17shell none
18
19private-tmp
20private-dev
21
22# please note: the wire binary is currently identified with a capital W. This might change in future versions
diff --git a/etc/disable-programs.inc b/etc/disable-programs.inc
index 6e22fe04d..0d9bd1bb4 100644
--- a/etc/disable-programs.inc
+++ b/etc/disable-programs.inc
@@ -106,6 +106,7 @@ blacklist ${HOME}/.config/Slack
106blacklist ${HOME}/.cache/gajim 106blacklist ${HOME}/.cache/gajim
107blacklist ${HOME}/.local/share/gajim 107blacklist ${HOME}/.local/share/gajim
108blacklist ${HOME}/.config/gajim 108blacklist ${HOME}/.config/gajim
109blacklist ${HOME}/.config/Wire
109 110
110# Games 111# Games
111blacklist ${HOME}/.hedgewars 112blacklist ${HOME}/.hedgewars
diff --git a/etc/display.profile b/etc/display.profile
new file mode 100644
index 000000000..ec041bff7
--- /dev/null
+++ b/etc/display.profile
@@ -0,0 +1,23 @@
1# display (ImageMagick tool) image viewer profile
2include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc
4include /etc/firejail/disable-devel.inc
5include /etc/firejail/disable-passwdmgr.inc
6
7caps.drop all
8seccomp
9protocol unix
10netfilter
11net none
12nonewprivs
13noroot
14nogroups
15nosound
16shell none
17x11 xorg
18
19private-bin display
20private-tmp
21private-dev
22private-etc none
23