aboutsummaryrefslogtreecommitdiffstats
path: root/etc/profile-m-z
diff options
context:
space:
mode:
authorLibravatar netblue30 <netblue30@protonmail.com>2021-11-13 12:19:09 +0000
committerLibravatar GitHub <noreply@github.com>2021-11-13 12:19:09 +0000
commit92307735bd07ad3d677429aa04795209204102ec (patch)
treee908ed688db35e0cdade9c5fd4cb5add48d7ddf7 /etc/profile-m-z
parentMerge pull request #4679 from pirate486743186/patch-3 (diff)
parentimplement review suggestions (diff)
downloadfirejail-92307735bd07ad3d677429aa04795209204102ec.tar.gz
firejail-92307735bd07ad3d677429aa04795209204102ec.tar.zst
firejail-92307735bd07ad3d677429aa04795209204102ec.zip
Merge pull request #4681 from jmetrius/openstego-profile
Add OpenStego profile
Diffstat (limited to 'etc/profile-m-z')
-rw-r--r--etc/profile-m-z/openstego.profile58
1 files changed, 58 insertions, 0 deletions
diff --git a/etc/profile-m-z/openstego.profile b/etc/profile-m-z/openstego.profile
new file mode 100644
index 000000000..f6622b38d
--- /dev/null
+++ b/etc/profile-m-z/openstego.profile
@@ -0,0 +1,58 @@
1# Firejail profile for OpenStego
2# Description: Steganography application that provides data hiding and watermarking functionality
3# This file is overwritten after every install/update
4# Persistent local customizations
5include openstego.local
6# Persistent global definitions
7include globals.local
8
9noblacklist ${HOME}/openstego.ini
10
11# Allow java (blacklisted by disable-devel.inc)
12include allow-java.inc
13
14include disable-common.inc
15include disable-devel.inc
16include disable-exec.inc
17include disable-interpreters.inc
18include disable-proc.inc
19include disable-programs.inc
20
21mkfile ${HOME}/openstego.ini
22whitelist ${HOME}/openstego.ini
23whitelist ${HOME}/.java
24whitelist ${PICTURES}
25whitelist ${DOCUMENTS}
26whitelist ${DESKTOP}
27whitelist /usr/share/java
28include whitelist-common.inc
29include whitelist-run-common.inc
30include whitelist-runuser-common.inc
31include whitelist-usr-share-common.inc
32include whitelist-var-common.inc
33
34caps.drop all
35machine-id
36net none
37no3d
38nogroups
39noinput
40nonewprivs
41noroot
42nosound
43notv
44nou2f
45novideo
46seccomp
47seccomp.block-secondary
48shell none
49tracelog
50
51disable-mnt
52private-bin bash,dirname,openstego,readlink,sh
53private-cache
54private-dev
55private-tmp
56
57dbus-user none
58dbus-system none