aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLibravatar glitsj16 <glitsj16@users.noreply.github.com>2024-03-14 18:48:02 +0000
committerLibravatar GitHub <noreply@github.com>2024-03-14 18:48:02 +0000
commita97d53383f89bf88053e7dd3eeaf1a20d94c23fb (patch)
tree6d526b6e8a00e14037c48f540dfe85a543b5c3d6
parentNew profile: lyriek.profile (#6245) (diff)
downloadfirejail-a97d53383f89bf88053e7dd3eeaf1a20d94c23fb.tar.gz
firejail-a97d53383f89bf88053e7dd3eeaf1a20d94c23fb.tar.zst
firejail-a97d53383f89bf88053e7dd3eeaf1a20d94c23fb.zip
New profile: statusof.profile (#6253)
Description: Python script to check the status of a list of URLs. https://github.com/Arthurdw/statusof
-rw-r--r--etc/profile-m-z/statusof.profile68
-rw-r--r--src/firecfg/firecfg.config1
2 files changed, 69 insertions, 0 deletions
diff --git a/etc/profile-m-z/statusof.profile b/etc/profile-m-z/statusof.profile
new file mode 100644
index 000000000..7463b90f5
--- /dev/null
+++ b/etc/profile-m-z/statusof.profile
@@ -0,0 +1,68 @@
1# Firejail profile for statusof
2# Description: Small python script to check the status of a list of urls
3# This file is overwritten after every install/update
4quiet
5# Persistent local customizations
6include statusof.local
7# Persistent global definitions
8include globals.local
9
10blacklist /tmp/.X11-unix
11blacklist /usr/libexec
12blacklist ${RUNUSER}
13
14# Allow python (blacklisted by disable-interpreters.inc)
15include allow-python3.inc
16
17include disable-common.inc
18include disable-devel.inc
19include disable-exec.inc
20include disable-interpreters.inc
21include disable-proc.inc
22include disable-programs.inc
23include disable-shell.inc
24include disable-xdg.inc
25
26include whitelist-common.inc
27include whitelist-run-common.inc
28include whitelist-runuser-common.inc
29include whitelist-usr-share-common.inc
30include whitelist-var-common.inc
31
32apparmor
33caps.drop all
34ipc-namespace
35machine-id
36netfilter
37no3d
38nodvd
39nogroups
40noinput
41nonewprivs
42noprinters
43noroot
44nosound
45notv
46nou2f
47novideo
48protocol inet
49seccomp
50seccomp.block-secondary
51tracelog
52x11 none
53
54disable-mnt
55private
56private-bin python*,statusof
57private-cache
58private-dev
59private-etc @network,@tls-ca,httpd
60private-lib engines*,libcrypto.so.*,libssl.so.*,libz.so.*,python*
61private-tmp
62
63dbus-user none
64dbus-system none
65
66memory-deny-write-execute
67read-only ${HOME}
68restrict-namespaces
diff --git a/src/firecfg/firecfg.config b/src/firecfg/firecfg.config
index 916ff3ba5..9b949cf90 100644
--- a/src/firecfg/firecfg.config
+++ b/src/firecfg/firecfg.config
@@ -812,6 +812,7 @@ ssh
812#ssh-agent # problems on Arch with Fish shell (#1568) 812#ssh-agent # problems on Arch with Fish shell (#1568)
813standardnotes-desktop 813standardnotes-desktop
814start-tor-browser 814start-tor-browser
815statusof
815steam 816steam
816steam-native 817steam-native
817steam-runtime 818steam-runtime