aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLibravatar netblue30 <netblue30@yahoo.com>2016-09-30 09:33:45 -0400
committerLibravatar netblue30 <netblue30@yahoo.com>2016-09-30 09:33:45 -0400
commite90a8025a8173f3ce1fb0d22c3fc0b2ccb431ecc (patch)
tree46b9b3aed144e134aa42e8dfa0c048caad744476
parentMerge pull request #822 from manevich/xauthority-link (diff)
downloadfirejail-e90a8025a8173f3ce1fb0d22c3fc0b2ccb431ecc.tar.gz
firejail-e90a8025a8173f3ce1fb0d22c3fc0b2ccb431ecc.tar.zst
firejail-e90a8025a8173f3ce1fb0d22c3fc0b2ccb431ecc.zip
added luminance-hdr and synfigstudio profiles
-rw-r--r--README.md2
-rw-r--r--RELNOTES2
-rw-r--r--etc/disable-programs.inc3
-rw-r--r--etc/luminance-hdr.profile23
-rw-r--r--etc/synfigstudio.profile17
-rw-r--r--platform/debian/conffiles2
-rw-r--r--src/firecfg/firecfg.config2
7 files changed, 49 insertions, 2 deletions
diff --git a/README.md b/README.md
index 05cfd3b11..e98f8ad21 100644
--- a/README.md
+++ b/README.md
@@ -88,5 +88,5 @@ x11 xpra, x11 xephyr, x11 block, allusers, join-or-start
88 88
89## New profiles 89## New profiles
90 90
91qpdfview, mupdf 91qpdfview, mupdf, Luminance HDR, Synfig Studio
92 92
diff --git a/RELNOTES b/RELNOTES
index 9b746e229..f09c628e1 100644
--- a/RELNOTES
+++ b/RELNOTES
@@ -13,7 +13,7 @@ firejail (0.9.43) baseline; urgency=low
13 * feature: blocking x11 (--x11=block) 13 * feature: blocking x11 (--x11=block)
14 * feature: disable 3D hardware acceleration (--no3d) 14 * feature: disable 3D hardware acceleration (--no3d)
15 * feature: x11 xpra, x11 xephyr, x11 block, allusers, no3d profile commands 15 * feature: x11 xpra, x11 xephyr, x11 block, allusers, no3d profile commands
16 * new profiles: qpdfview, mupdf 16 * new profiles: qpdfview, mupdf, Luminance HDR, Synfig Studio
17 * bugfixes 17 * bugfixes
18 -- netblue30 <netblue30@yahoo.com> Fri, 9 Sept 2016 08:00:00 -0500 18 -- netblue30 <netblue30@yahoo.com> Fri, 9 Sept 2016 08:00:00 -0500
19 19
diff --git a/etc/disable-programs.inc b/etc/disable-programs.inc
index 54c53e794..8566ea0c5 100644
--- a/etc/disable-programs.inc
+++ b/etc/disable-programs.inc
@@ -27,6 +27,9 @@ blacklist ${HOME}/.kde/share/config/okularpartrc
27blacklist ${HOME}/.kde/share/apps/gwenview 27blacklist ${HOME}/.kde/share/apps/gwenview
28blacklist ${HOME}/.kde/share/config/gwenviewrc 28blacklist ${HOME}/.kde/share/config/gwenviewrc
29blacklist ${HOME}/.config/qpdfview 29blacklist ${HOME}/.config/qpdfview
30blacklist ${HOME}/.config/Luminance
31blacklist ${HOME}/.config/synfig
32blacklist ${HOME}/.synfig
30 33
31# Media players 34# Media players
32blacklist ${HOME}/.config/cmus 35blacklist ${HOME}/.config/cmus
diff --git a/etc/luminance-hdr.profile b/etc/luminance-hdr.profile
new file mode 100644
index 000000000..e9207fba3
--- /dev/null
+++ b/etc/luminance-hdr.profile
@@ -0,0 +1,23 @@
1# luminance-hdr
2noblacklist ${HOME}/.config/Luminance
3include /etc/firejail/disable-common.inc
4include /etc/firejail/disable-programs.inc
5include /etc/firejail/disable-passwdmgr.inc
6include /etc/firejail/disable-devel.inc
7
8
9caps.drop all
10netfilter
11protocol unix
12nonewprivs
13noroot
14seccomp
15shell none
16tracelog
17private-tmp
18private-dev
19noexec ${HOME}
20noexec /tmp
21nogroups
22nosound
23ipc-namespace
diff --git a/etc/synfigstudio.profile b/etc/synfigstudio.profile
new file mode 100644
index 000000000..d46467b99
--- /dev/null
+++ b/etc/synfigstudio.profile
@@ -0,0 +1,17 @@
1# synfigstudio
2noblacklist ${HOME}/.config/synfig
3noblacklist ${HOME}/.synfig
4include /etc/firejail/disable-common.inc
5include /etc/firejail/disable-programs.inc
6include /etc/firejail/disable-passwdmgr.inc
7
8caps.drop all
9netfilter
10nonewprivs
11noroot
12protocol unix
13seccomp
14private-dev
15private-tmp
16noexec ${HOME}
17noexec /tmp
diff --git a/platform/debian/conffiles b/platform/debian/conffiles
index 0c494c042..86f5564fd 100644
--- a/platform/debian/conffiles
+++ b/platform/debian/conffiles
@@ -145,4 +145,6 @@
145/etc/firejail/dosbox.profile 145/etc/firejail/dosbox.profile
146/etc/firejail/mupdf.profile 146/etc/firejail/mupdf.profile
147/etc/firejail/qpdfview.profile 147/etc/firejail/qpdfview.profile
148/etc/firejail/luminance-hdr.profile
149/etc/firejail/synfigstudio.profile
148 150
diff --git a/src/firecfg/firecfg.config b/src/firecfg/firecfg.config
index ca28d025b..2fec8ef90 100644
--- a/src/firecfg/firecfg.config
+++ b/src/firecfg/firecfg.config
@@ -130,6 +130,8 @@ pix
130xreader 130xreader
131mupdf 131mupdf
132qpdfview 132qpdfview
133luminance-hdr
134synfigstudio
133 135
134# other 136# other
135ssh 137ssh