aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLibravatar netblue30 <netblue30@protonmail.com>2022-01-24 12:52:16 -0500
committerLibravatar GitHub <noreply@github.com>2022-01-24 12:52:16 -0500
commitcb90b43467eec3675e9fbeaed52055544d6e7829 (patch)
tree5584e48579bf4e743f1e6d447610d7cda04b9609
parentmerges (diff)
parentadd seafile-applet (diff)
downloadfirejail-cb90b43467eec3675e9fbeaed52055544d6e7829.tar.gz
firejail-cb90b43467eec3675e9fbeaed52055544d6e7829.tar.zst
firejail-cb90b43467eec3675e9fbeaed52055544d6e7829.zip
Merge pull request #4829 from CaseOf/seafile
Seafile
-rw-r--r--etc/inc/disable-programs.inc2
-rw-r--r--etc/profile-m-z/seafile-applet.profile62
-rw-r--r--src/firecfg/firecfg.config1
3 files changed, 65 insertions, 0 deletions
diff --git a/etc/inc/disable-programs.inc b/etc/inc/disable-programs.inc
index 890c831d6..458565ab3 100644
--- a/etc/inc/disable-programs.inc
+++ b/etc/inc/disable-programs.inc
@@ -16,6 +16,7 @@ blacklist ${HOME}/.Natron
16blacklist ${HOME}/.PlayOnLinux 16blacklist ${HOME}/.PlayOnLinux
17blacklist ${HOME}/.PyCharm* 17blacklist ${HOME}/.PyCharm*
18blacklist ${HOME}/.Sayonara 18blacklist ${HOME}/.Sayonara
19blacklist ${HOME}/Seafile/.seafile-data
19blacklist ${HOME}/.Steam 20blacklist ${HOME}/.Steam
20blacklist ${HOME}/.Steampath 21blacklist ${HOME}/.Steampath
21blacklist ${HOME}/.Steampid 22blacklist ${HOME}/.Steampid
@@ -317,6 +318,7 @@ blacklist ${HOME}/.config/Riot
317blacklist ${HOME}/.config/Rocket.Chat 318blacklist ${HOME}/.config/Rocket.Chat
318blacklist ${HOME}/.config/RogueLegacy 319blacklist ${HOME}/.config/RogueLegacy
319blacklist ${HOME}/.config/RogueLegacyStorageContainer 320blacklist ${HOME}/.config/RogueLegacyStorageContainer
321blacklist ${HOME}/.config/Seafile
320blacklist ${HOME}/.config/Signal 322blacklist ${HOME}/.config/Signal
321blacklist ${HOME}/.config/Sinew Software Systems 323blacklist ${HOME}/.config/Sinew Software Systems
322blacklist ${HOME}/.config/Slack 324blacklist ${HOME}/.config/Slack
diff --git a/etc/profile-m-z/seafile-applet.profile b/etc/profile-m-z/seafile-applet.profile
new file mode 100644
index 000000000..79e072475
--- /dev/null
+++ b/etc/profile-m-z/seafile-applet.profile
@@ -0,0 +1,62 @@
1# Firejail profile for Seafile
2# Description: Seafile desktop client.
3# This file is overwritten after every install/update
4# Persistent local customizations
5include seafile-applet.local
6# Persistent global definitions
7include globals.local
8
9noblacklist ${HOME}/.config/Seafile
10noblacklist ${HOME}/Seafile/.seafile-data
11
12blacklist /usr/libexec
13
14include disable-common.inc
15include disable-devel.inc
16include disable-exec.inc
17include disable-interpreters.inc
18include disable-programs.inc
19include disable-xdg.inc
20
21mkdir ${HOME}/.ccnet
22mkdir ${HOME}/.config/Seafile
23mkdir ${HOME}/Seafile
24whitelist ${HOME}/.ccnet
25whitelist ${HOME}/.config/Seafile
26whitelist ${HOME}/Seafile
27
28include whitelist-common.inc
29include whitelist-run-common.inc
30include whitelist-runuser-common.inc
31include whitelist-usr-share-common.inc
32include whitelist-var-common.inc
33
34apparmor
35caps.drop all
36netfilter
37nodvd
38nogroups
39noinput
40nonewprivs
41noprinters
42noroot
43nosound
44notv
45nou2f
46novideo
47protocol unix,inet,inet6
48seccomp
49seccomp.block-secondary
50shell none
51tracelog
52
53disable-mnt
54private-bin seaf-cli,seaf-daemon,seafile-applet
55private-cache
56private-dev
57private-etc alternatives,ca-certificates,crypto-policies,host.conf,hostname,hosts,ld.so.cache,ld.so.preload,nsswitch.conf,pki,protocols,resolv.conf,rpc,services,ssl
58#private-opt none
59private-tmp
60
61dbus-user none
62dbus-system none
diff --git a/src/firecfg/firecfg.config b/src/firecfg/firecfg.config
index edf46ef4a..77f233bce 100644
--- a/src/firecfg/firecfg.config
+++ b/src/firecfg/firecfg.config
@@ -714,6 +714,7 @@ scorched3d
714scorchwentbonkers 714scorchwentbonkers
715scribus 715scribus
716sdat2img 716sdat2img
717seafile-applet
717seahorse 718seahorse
718seahorse-adventures 719seahorse-adventures
719seahorse-daemon 720seahorse-daemon