aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLibravatar netblue30 <netblue30@yahoo.com>2018-10-11 08:37:04 -0500
committerLibravatar GitHub <noreply@github.com>2018-10-11 08:37:04 -0500
commitc67588ec3626254c56398deb0741baa012ef2c85 (patch)
tree1e6345a1e01441e5f29a38582f907ae57adea6f0
parentMerge pull request #2171 from glitsj16/desktop (diff)
parentUpdate for min (diff)
downloadfirejail-c67588ec3626254c56398deb0741baa012ef2c85.tar.gz
firejail-c67588ec3626254c56398deb0741baa012ef2c85.tar.zst
firejail-c67588ec3626254c56398deb0741baa012ef2c85.zip
Merge pull request #2172 from glitsj16/min
New profile min
-rw-r--r--etc/disable-programs.inc1
-rw-r--r--etc/min.profile50
-rw-r--r--src/firecfg/firecfg.config1
3 files changed, 52 insertions, 0 deletions
diff --git a/etc/disable-programs.inc b/etc/disable-programs.inc
index fe6b04ed0..6fa0eed26 100644
--- a/etc/disable-programs.inc
+++ b/etc/disable-programs.inc
@@ -66,6 +66,7 @@ blacklist ${HOME}/.config/INRIA
66blacklist ${HOME}/.config/InSilmaril 66blacklist ${HOME}/.config/InSilmaril
67blacklist ${HOME}/.config/Luminance 67blacklist ${HOME}/.config/Luminance
68blacklist ${HOME}/.config/Meltytech 68blacklist ${HOME}/.config/Meltytech
69blacklist ${HOME}/.config/Min
69blacklist ${HOME}/.config/Mousepad 70blacklist ${HOME}/.config/Mousepad
70blacklist ${HOME}/.config/Mumble 71blacklist ${HOME}/.config/Mumble
71blacklist ${HOME}/.config/MusE 72blacklist ${HOME}/.config/MusE
diff --git a/etc/min.profile b/etc/min.profile
new file mode 100644
index 000000000..91c6fce3c
--- /dev/null
+++ b/etc/min.profile
@@ -0,0 +1,50 @@
1# Firejail profile for min
2# Description: A faster, smarter web browser.
3# This file is overwritten after every install/update
4# Persistent local customizations
5include /etc/firejail/min.local
6# Persistent global definitions
7include /etc/firejail/globals.local
8
9noblacklist ${HOME}/.config/Min
10
11noblacklist ${HOME}/.pki
12
13include /etc/firejail/disable-common.inc
14include /etc/firejail/disable-devel.inc
15include /etc/firejail/disable-interpreters.inc
16include /etc/firejail/disable-programs.inc
17
18mkdir ${HOME}/.pki
19whitelist ${DOWNLOADS}
20whitelist ${HOME}/.pki
21include /etc/firejail/whitelist-common.inc
22include /etc/firejail/whitelist-var-common.inc
23
24caps.drop all
25# ipc-namespace
26# machine-id breaks pulse audio; it should work fine in setups where sound is not required
27#machine-id
28netfilter
29# no3d
30nodbus
31nodvd
32nogroups
33nonewprivs
34noroot
35notv
36protocol unix,inet,inet6
37seccomp
38shell none
39
40disable-mnt
41# private-bin min
42private-cache
43private-dev
44# private-etc below works fine on most distributions. There are some problems on CentOS.
45private-etc ca-certificates,ssl,machine-id,dconf,selinux,passwd,group,hostname,hosts,localtime,nsswitch.conf,resolv.conf,xdg,gtk-2.0,gtk-3.0,X11,pango,fonts,mime.types,mailcap,asound.conf,pulse,pki,crypto-policies,ld.so.cache
46private-tmp
47
48# memory-deny-write-execute
49noexec ${HOME}
50noexec /tmp
diff --git a/src/firecfg/firecfg.config b/src/firecfg/firecfg.config
index 542812624..2190f133d 100644
--- a/src/firecfg/firecfg.config
+++ b/src/firecfg/firecfg.config
@@ -280,6 +280,7 @@ mediainfo
280mediathekview 280mediathekview
281meld 281meld
282midori 282midori
283min
283minetest 284minetest
284mousepad 285mousepad
285mplayer 286mplayer