summaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
authorLibravatar Fred-Barclay <Fred-Barclay@users.noreply.github.com>2016-05-07 14:20:03 +1000
committerLibravatar Fred-Barclay <Fred-Barclay@users.noreply.github.com>2016-05-07 14:20:03 +1000
commit78fbedbe1199ce7914c021c376bb5752439f8c62 (patch)
tree48967e3cec45f38d95075ec133d611c450f60b3b /etc
parenttest fixes (diff)
downloadfirejail-78fbedbe1199ce7914c021c376bb5752439f8c62.tar.gz
firejail-78fbedbe1199ce7914c021c376bb5752439f8c62.tar.zst
firejail-78fbedbe1199ce7914c021c376bb5752439f8c62.zip
added xapps && cleanup
Diffstat (limited to 'etc')
-rw-r--r--etc/disable-programs.inc17
-rw-r--r--etc/xplayer.profile15
-rw-r--r--etc/xreader.profile16
-rw-r--r--etc/xviewer.profile13
4 files changed, 56 insertions, 5 deletions
diff --git a/etc/disable-programs.inc b/etc/disable-programs.inc
index 297d25bf2..1f3768693 100644
--- a/etc/disable-programs.inc
+++ b/etc/disable-programs.inc
@@ -12,17 +12,22 @@ blacklist ${HOME}/.config/uGet
12blacklist ${HOME}/.config/Gpredict 12blacklist ${HOME}/.config/Gpredict
13blacklist ${HOME}/.config/aweather 13blacklist ${HOME}/.config/aweather
14blacklist ${HOME}/.config/stellarium 14blacklist ${HOME}/.config/stellarium
15blacklist ~/.kde/share/apps/okular 15blacklist ${HOME}/.config/atril
16blacklist ~/.kde/share/config/okularrc 16blacklist ${HOME}/.config/xreader
17blacklist ~/.kde/share/config/okularpartrc 17blacklist ${HOME}/.config/xviewer
18blacklist ~/.kde/share/apps/gwenview 18blacklist ${HOME}/.kde/share/apps/okular
19blacklist ~/.kde/share/config/gwenviewrc 19blacklist ${HOME}/.kde/share/config/okularrc
20blacklist ${HOME}/.kde/share/config/okularpartrc
21blacklist ${HOME}/.kde/share/apps/gwenview
22blacklist ${HOME}/.kde/share/config/gwenviewrc
20 23
21# Media players 24# Media players
22blacklist ${HOME}/.config/cmus 25blacklist ${HOME}/.config/cmus
23blacklist ${HOME}/.config/deadbeef 26blacklist ${HOME}/.config/deadbeef
24blacklist ${HOME}/.config/spotify 27blacklist ${HOME}/.config/spotify
25blacklist ${HOME}/.config/vlc 28blacklist ${HOME}/.config/vlc
29blacklist ${HOME}/.config/totem
30blacklist ${HOME}/.config/xplayer
26 31
27# HTTP / FTP / Mail 32# HTTP / FTP / Mail
28blacklist ${HOME}/.icedove 33blacklist ${HOME}/.icedove
@@ -95,6 +100,7 @@ blacklist ${HOME}/.cache/transmission
95blacklist ${HOME}/.cache/wesnoth 100blacklist ${HOME}/.cache/wesnoth
96blacklist ${HOME}/.cache/0ad 101blacklist ${HOME}/.cache/0ad
97blacklist ${HOME}/.cache/8pecxstudios 102blacklist ${HOME}/.cache/8pecxstudios
103blacklist ${HOME}/.cache/xreader
98 104
99# share 105# share
100blacklist ${HOME}/.local/share/epiphany 106blacklist ${HOME}/.local/share/epiphany
@@ -103,3 +109,4 @@ blacklist ${HOME}/.local/share/spotify
103blacklist ${HOME}/.local/share/steam 109blacklist ${HOME}/.local/share/steam
104blacklist ${HOME}/.local/share/wesnoth 110blacklist ${HOME}/.local/share/wesnoth
105blacklist ${HOME}/.local/share/0ad 111blacklist ${HOME}/.local/share/0ad
112blacklist ${HOME}/.local/share/xplayer
diff --git a/etc/xplayer.profile b/etc/xplayer.profile
new file mode 100644
index 000000000..67a46a7da
--- /dev/null
+++ b/etc/xplayer.profile
@@ -0,0 +1,15 @@
1# Xplayer profile
2noblacklist ~/.config/xplayer
3noblacklist ~/.local/share/xplayer
4
5include /etc/firejail/disable-common.inc
6include /etc/firejail/disable-programs.inc
7include /etc/firejail/disable-devel.inc
8include /etc/firejail/disable-passwdmgr.inc
9
10caps.drop all
11seccomp
12protocol unix,inet,inet6
13noroot
14tracelog
15netfilter
diff --git a/etc/xreader.profile b/etc/xreader.profile
new file mode 100644
index 000000000..7b72d41a6
--- /dev/null
+++ b/etc/xreader.profile
@@ -0,0 +1,16 @@
1# Xreader profile
2noblacklist ~/.config/xreader
3noblacklist ~/.cache/xreader
4noblacklist ~/.local/share
5
6include /etc/firejail/disable-common.inc
7include /etc/firejail/disable-programs.inc
8include /etc/firejail/disable-devel.inc
9include /etc/firejail/disable-passwdmgr.inc
10
11caps.drop all
12seccomp
13protocol unix,inet,inet6
14noroot
15tracelog
16netfilter
diff --git a/etc/xviewer.profile b/etc/xviewer.profile
new file mode 100644
index 000000000..33e1e3c68
--- /dev/null
+++ b/etc/xviewer.profile
@@ -0,0 +1,13 @@
1noblacklist ~/.config/xviewer
2
3include /etc/firejail/disable-common.inc
4include /etc/firejail/disable-programs.inc
5include /etc/firejail/disable-devel.inc
6include /etc/firejail/disable-passwdmgr.inc
7
8caps.drop all
9seccomp
10protocol unix,inet,inet6
11noroot
12tracelog
13netfilter