summaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
authorLibravatar Tad <tad@spotco.us>2017-09-22 08:42:52 -0400
committerLibravatar Tad <tad@spotco.us>2017-09-22 08:42:52 -0400
commit04adc450151cc5107098ef2f555ad526ac9f632e (patch)
treece43807c66368539ffba1630ccedb0819cbc12dc /etc
parentFixup merge of #1565 (diff)
downloadfirejail-04adc450151cc5107098ef2f555ad526ac9f632e.tar.gz
firejail-04adc450151cc5107098ef2f555ad526ac9f632e.tar.zst
firejail-04adc450151cc5107098ef2f555ad526ac9f632e.zip
Further fixup #1565 and add a profile for uefitool
Diffstat (limited to 'etc')
-rw-r--r--etc/bluefish.profile4
-rw-r--r--etc/cliqz.profile4
-rw-r--r--etc/disable-programs.inc3
-rw-r--r--etc/pinta.profile12
-rw-r--r--etc/uefitool.profile33
5 files changed, 47 insertions, 9 deletions
diff --git a/etc/bluefish.profile b/etc/bluefish.profile
index a0bceabbe..f18dea296 100644
--- a/etc/bluefish.profile
+++ b/etc/bluefish.profile
@@ -1,11 +1,10 @@
1# Firejail profile for pluma 1# Firejail profile for bluefish
2# This file is overwritten after every install/update 2# This file is overwritten after every install/update
3# Persistent local customizations 3# Persistent local customizations
4include /etc/firejail/pluma.local 4include /etc/firejail/pluma.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ${HOME}/.config/pluma
9 8
10include /etc/firejail/disable-common.inc 9include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-devel.inc 10include /etc/firejail/disable-devel.inc
@@ -29,7 +28,6 @@ tracelog
29 28
30private-bin bluefish 29private-bin bluefish
31private-dev 30private-dev
32# private-etc fonts
33private-tmp 31private-tmp
34 32
35noexec ${HOME} 33noexec ${HOME}
diff --git a/etc/cliqz.profile b/etc/cliqz.profile
index 9c0f44e97..a7c791a02 100644
--- a/etc/cliqz.profile
+++ b/etc/cliqz.profile
@@ -1,7 +1,7 @@
1# Firejail profile for firefox 1# Firejail profile for cliqz
2# This file is overwritten after every install/update 2# This file is overwritten after every install/update
3# Persistent local customizations 3# Persistent local customizations
4include /etc/firejail/firefox.local 4include /etc/firejail/cliqz.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
diff --git a/etc/disable-programs.inc b/etc/disable-programs.inc
index 615e28172..ad589890c 100644
--- a/etc/disable-programs.inc
+++ b/etc/disable-programs.inc
@@ -81,6 +81,7 @@ blacklist ${HOME}/.config/chromium
81blacklist ${HOME}/.config/chromium-dev 81blacklist ${HOME}/.config/chromium-dev
82blacklist ${HOME}/.config/chromium-flags.conf 82blacklist ${HOME}/.config/chromium-flags.conf
83blacklist ${HOME}/.config/clipit 83blacklist ${HOME}/.config/clipit
84blacklist ${HOME}/.config/cliqz
84blacklist ${HOME}/.config/cmus 85blacklist ${HOME}/.config/cmus
85blacklist ${HOME}/.config/corebird 86blacklist ${HOME}/.config/corebird
86blacklist ${HOME}/.config/darktable 87blacklist ${HOME}/.config/darktable
@@ -142,6 +143,7 @@ blacklist ${HOME}/.config/opera-beta
142blacklist ${HOME}/.config/orage 143blacklist ${HOME}/.config/orage
143blacklist ${HOME}/.config/org.kde.gwenviewrc 144blacklist ${HOME}/.config/org.kde.gwenviewrc
144blacklist ${HOME}/.config/pcmanfm 145blacklist ${HOME}/.config/pcmanfm
146blacklist ${HOME}/.config/Pinta
145blacklist ${HOME}/.config/pix 147blacklist ${HOME}/.config/pix
146blacklist ${HOME}/.config/pluma 148blacklist ${HOME}/.config/pluma
147blacklist ${HOME}/.config/psi+ 149blacklist ${HOME}/.config/psi+
@@ -408,6 +410,7 @@ blacklist ${HOME}/.cache/calibre
408blacklist ${HOME}/.cache/champlain 410blacklist ${HOME}/.cache/champlain
409blacklist ${HOME}/.cache/chromium 411blacklist ${HOME}/.cache/chromium
410blacklist ${HOME}/.cache/chromium-dev 412blacklist ${HOME}/.cache/chromium-dev
413blacklist ${HOME}/.cache/cliqz
411blacklist ${HOME}/.cache/darktable 414blacklist ${HOME}/.cache/darktable
412blacklist ${HOME}/.cache/epiphany 415blacklist ${HOME}/.cache/epiphany
413blacklist ${HOME}/.cache/evolution 416blacklist ${HOME}/.cache/evolution
diff --git a/etc/pinta.profile b/etc/pinta.profile
index 2562e1b80..4228e5880 100644
--- a/etc/pinta.profile
+++ b/etc/pinta.profile
@@ -1,15 +1,21 @@
1# Firejail profile for krita 1# Firejail profile for pinta
2# This file is overwritten after every install/update 2# This file is overwritten after every install/update
3# Persistent local customizations 3# Persistent local customizations
4include /etc/firejail/krita.local 4include /etc/firejail/pinta.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8
9noblacklist ${HOME}/.config/Pinta
10
8include /etc/firejail/disable-common.inc 11include /etc/firejail/disable-common.inc
9include /etc/firejail/disable-devel.inc 12include /etc/firejail/disable-devel.inc
10include /etc/firejail/disable-passwdmgr.inc 13include /etc/firejail/disable-passwdmgr.inc
11include /etc/firejail/disable-programs.inc 14include /etc/firejail/disable-programs.inc
12 15
16whitelist ${HOME}/.config/Pinta
17include /etc/firejail/whitelist-common.inc
18
13caps.drop all 19caps.drop all
14ipc-namespace 20ipc-namespace
15net none 21net none
@@ -27,7 +33,5 @@ shell none
27private-dev 33private-dev
28private-tmp 34private-tmp
29 35
30
31whitelist ~/.config/Pinta
32noexec ${HOME} 36noexec ${HOME}
33noexec /tmp 37noexec /tmp
diff --git a/etc/uefitool.profile b/etc/uefitool.profile
new file mode 100644
index 000000000..138f69aa8
--- /dev/null
+++ b/etc/uefitool.profile
@@ -0,0 +1,33 @@
1# Firejail profile for uefitool
2# This file is overwritten after every install/update
3# Persistent local customizations
4include /etc/firejail/uefitool.local
5# Persistent global definitions
6include /etc/firejail/globals.local
7
8
9include /etc/firejail/disable-common.inc
10include /etc/firejail/disable-devel.inc
11include /etc/firejail/disable-passwdmgr.inc
12include /etc/firejail/disable-programs.inc
13
14caps.drop all
15ipc-namespace
16net none
17no3d
18nodvd
19nogroups
20nonewprivs
21noroot
22nosound
23notv
24novideo
25protocol unix
26seccomp
27shell none
28
29private-dev
30private-tmp
31
32noexec ${HOME}
33noexec /tmp