summaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
authorLibravatar Fred-Barclay <Fred-Barclay@users.noreply.github.com>2016-10-25 12:23:23 -0500
committerLibravatar Fred-Barclay <Fred-Barclay@users.noreply.github.com>2016-10-25 12:23:23 -0500
commit7e20af49b10d716154b21d5b19abf3a312a31c7e (patch)
tree4bab1a86b12fd8429ca503fd324276447a82ced2 /etc
parentfixes (diff)
downloadfirejail-7e20af49b10d716154b21d5b19abf3a312a31c7e.tar.gz
firejail-7e20af49b10d716154b21d5b19abf3a312a31c7e.tar.zst
firejail-7e20af49b10d716154b21d5b19abf3a312a31c7e.zip
Added gpredict, TBB, and xiphos
Diffstat (limited to 'etc')
-rw-r--r--etc/gpredict.profile8
-rw-r--r--etc/start-tor-browser.profile20
-rw-r--r--etc/xiphos.profile30
3 files changed, 54 insertions, 4 deletions
diff --git a/etc/gpredict.profile b/etc/gpredict.profile
index 0cc6c416b..f62bf11aa 100644
--- a/etc/gpredict.profile
+++ b/etc/gpredict.profile
@@ -6,20 +6,20 @@ include /etc/firejail/disable-passwdmgr.inc
6include /etc/firejail/disable-programs.inc 6include /etc/firejail/disable-programs.inc
7 7
8# Whitelist 8# Whitelist
9mkdir ~/.config/Gpredict
10whitelist ~/.config/Gpredict 9whitelist ~/.config/Gpredict
11 10
12caps.drop all 11caps.drop all
13netfilter 12netfilter
14nogroups
15nonewprivs 13nonewprivs
14nogroups
16noroot 15noroot
17nosound 16nosound
18protocol unix,inet,inet6 17protocol unix,inet,inet6
19seccomp 18seccomp
20shell none 19#shell none
21tracelog 20tracelog
22 21
23private-bin gpredict 22#private-bin gpredict
23private-etc fonts,resolv.conf
24private-dev 24private-dev
25private-tmp 25private-tmp
diff --git a/etc/start-tor-browser.profile b/etc/start-tor-browser.profile
new file mode 100644
index 000000000..ee19cee25
--- /dev/null
+++ b/etc/start-tor-browser.profile
@@ -0,0 +1,20 @@
1# Firejail profile for the Tor Brower Bundle
2include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-devel.inc
4include /etc/firejail/disable-passwdmgr.inc
5include /etc/firejail/disable-programs.inc
6
7caps.drop all
8netfilter
9nogroups
10nonewprivs
11noroot
12protocol unix,inet,inet6
13seccomp
14shell none
15tracelog
16
17private-bin bash,grep,sed,tail,env,gpg,id,readlink,dirname,test,mkdir,ln,sed,cp,rm,getconf
18private-etc fonts
19private-dev
20private-tmp
diff --git a/etc/xiphos.profile b/etc/xiphos.profile
new file mode 100644
index 000000000..b7fb6ecf3
--- /dev/null
+++ b/etc/xiphos.profile
@@ -0,0 +1,30 @@
1# Firejail profile for xiphos
2noblacklist ~/.sword
3noblacklist ~/.xiphos
4
5include /etc/firejail/disable-common.inc
6include /etc/firejail/disable-devel.inc
7include /etc/firejail/disable-passwdmgr.inc
8include /etc/firejail/disable-programs.inc
9
10blacklist ~/.bashrc
11blacklist ~/.Xauthority
12
13caps.drop all
14netfilter
15nogroups
16nonewprivs
17noroot
18nosound
19protocol unix,inet,inet6
20seccomp
21shell none
22tracelog
23
24private-bin xiphos
25private-etc fonts,resolv.conf,sword
26private-dev
27private-tmp
28
29whitelist ${HOME}/.sword
30whitelist ${HOME}/.xiphos