summaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
authorLibravatar netblue30 <netblue30@yahoo.com>2016-03-28 12:05:15 -0400
committerLibravatar netblue30 <netblue30@yahoo.com>2016-03-28 12:05:15 -0400
commitec34ed78af30cba5b582ab7c06951d2632c7b3e8 (patch)
tree0597011bbe41e6ec7b0f67fdfa7deef6037e9340 /etc
parentfix atril.profile (diff)
downloadfirejail-ec34ed78af30cba5b582ab7c06951d2632c7b3e8.tar.gz
firejail-ec34ed78af30cba5b582ab7c06951d2632c7b3e8.tar.zst
firejail-ec34ed78af30cba5b582ab7c06951d2632c7b3e8.zip
introducing disable-passwdmgr.inc
Diffstat (limited to 'etc')
-rw-r--r--etc/Mathematica.profile1
-rw-r--r--etc/atril.profile8
-rw-r--r--etc/audacious.profile7
-rw-r--r--etc/bitlbee.profile1
-rw-r--r--etc/cherrytree.profile4
-rw-r--r--etc/chromium.profile1
-rw-r--r--etc/clementine.profile7
-rw-r--r--etc/conkeror.profile4
-rw-r--r--etc/deadbeef.profile7
-rw-r--r--etc/deluge.profile7
-rw-r--r--etc/disable-passwdmgr.inc6
-rw-r--r--etc/dnscrypt-proxy.profile2
-rw-r--r--etc/dropbox.profile7
-rw-r--r--etc/empathy.profile2
-rw-r--r--etc/evince.profile6
-rw-r--r--etc/fbreader.profile6
-rw-r--r--etc/filezilla.profile1
-rw-r--r--etc/firefox.profile1
-rw-r--r--etc/flashpeak-slimjet.profile1
-rw-r--r--etc/generic.profile7
-rw-r--r--etc/gnome-mplayer.profile6
-rw-r--r--etc/google-chrome-beta.profile1
-rw-r--r--etc/google-chrome-unstable.profile1
-rw-r--r--etc/google-chrome.profile1
-rw-r--r--etc/hedgewars.profile2
-rw-r--r--etc/kmail.profile5
-rw-r--r--etc/lxterminal.profile6
-rw-r--r--etc/mupen64plus.profile1
-rw-r--r--etc/opera-beta.profile1
-rw-r--r--etc/opera.profile1
-rw-r--r--etc/parole.profile6
-rw-r--r--etc/qbittorrent.profile5
-rw-r--r--etc/qutebrowser.profile1
-rw-r--r--etc/rhythmbox.profile5
-rw-r--r--etc/rtorrent.profile1
-rw-r--r--etc/seamonkey.profile1
-rw-r--r--etc/server.profile1
-rw-r--r--etc/spotify.profile1
-rw-r--r--etc/ssh.profile6
-rw-r--r--etc/steam.profile1
-rw-r--r--etc/totem.profile5
-rw-r--r--etc/transmission-gtk.profile5
-rw-r--r--etc/transmission-qt.profile5
-rw-r--r--etc/unbound.profile1
-rw-r--r--etc/vivaldi.profile1
-rw-r--r--etc/vlc.profile5
-rw-r--r--etc/wesnoth.profile2
-rw-r--r--etc/xchat.profile1
48 files changed, 67 insertions, 97 deletions
diff --git a/etc/Mathematica.profile b/etc/Mathematica.profile
index 1ee50b4d4..52fd62ada 100644
--- a/etc/Mathematica.profile
+++ b/etc/Mathematica.profile
@@ -9,6 +9,7 @@ include /etc/firejail/whitelist-common.inc
9include /etc/firejail/disable-common.inc 9include /etc/firejail/disable-common.inc
10include /etc/firejail/disable-programs.inc 10include /etc/firejail/disable-programs.inc
11include /etc/firejail/disable-devel.inc 11include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-passwdmgr.inc
12 13
13caps.drop all 14caps.drop all
14seccomp 15seccomp
diff --git a/etc/atril.profile b/etc/atril.profile
index d0df28ac2..f142f50bc 100644
--- a/etc/atril.profile
+++ b/etc/atril.profile
@@ -2,16 +2,14 @@
2include /etc/firejail/disable-common.inc 2include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 3include /etc/firejail/disable-programs.inc
4include /etc/firejail/disable-devel.inc 4include /etc/firejail/disable-devel.inc
5include /etc/firejail/disable-passwdmgr.inc
6
7blacklist ${HOME}/.wine
5 8
6blacklist ${HOME}/.pki/nssdb
7blacklist ${HOME}/.lastpass
8blacklist ${HOME}/.keepassx
9blacklist ${HOME}/.password-store
10caps.drop all 9caps.drop all
11seccomp 10seccomp
12protocol unix,inet,inet6 11protocol unix,inet,inet6
13netfilter 12netfilter
14noroot 13noroot
15
16tracelog 14tracelog
17 15
diff --git a/etc/audacious.profile b/etc/audacious.profile
index 690463a46..0c79d02ac 100644
--- a/etc/audacious.profile
+++ b/etc/audacious.profile
@@ -2,11 +2,10 @@
2include /etc/firejail/disable-common.inc 2include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 3include /etc/firejail/disable-programs.inc
4include /etc/firejail/disable-devel.inc 4include /etc/firejail/disable-devel.inc
5blacklist ${HOME}/.pki/nssdb 5include /etc/firejail/disable-passwdmgr.inc
6blacklist ${HOME}/.lastpass 6
7blacklist ${HOME}/.keepassx
8blacklist ${HOME}/.password-store
9blacklist ${HOME}/.wine 7blacklist ${HOME}/.wine
8
10caps.drop all 9caps.drop all
11seccomp 10seccomp
12protocol unix,inet,inet6 11protocol unix,inet,inet6
diff --git a/etc/bitlbee.profile b/etc/bitlbee.profile
index 753e42480..fb84c260a 100644
--- a/etc/bitlbee.profile
+++ b/etc/bitlbee.profile
@@ -3,6 +3,7 @@ noblacklist /sbin
3noblacklist /usr/sbin 3noblacklist /usr/sbin
4include /etc/firejail/disable-common.inc 4include /etc/firejail/disable-common.inc
5include /etc/firejail/disable-programs.inc 5include /etc/firejail/disable-programs.inc
6
6protocol unix,inet,inet6 7protocol unix,inet,inet6
7private 8private
8private-dev 9private-dev
diff --git a/etc/cherrytree.profile b/etc/cherrytree.profile
index 349cc7acf..3cc384b37 100644
--- a/etc/cherrytree.profile
+++ b/etc/cherrytree.profile
@@ -2,6 +2,9 @@
2include /etc/firejail/disable-common.inc 2include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 3include /etc/firejail/disable-programs.inc
4include /etc/firejail/disable-devel.inc 4include /etc/firejail/disable-devel.inc
5include /etc/firejail/disable-passwdmgr.inc
6
7blacklist ${HOME}/.wine
5 8
6whitelist ${HOME}/cherrytree 9whitelist ${HOME}/cherrytree
7mkdir ~/.config 10mkdir ~/.config
@@ -10,6 +13,7 @@ whitelist ${HOME}/.config/cherrytree/
10mkdir ~/.local 13mkdir ~/.local
11mkdir ~/.local/share 14mkdir ~/.local/share
12whitelist ${HOME}/.local/share/ 15whitelist ${HOME}/.local/share/
16
13caps.drop all 17caps.drop all
14seccomp 18seccomp
15protocol unix,inet,inet6,netlink 19protocol unix,inet,inet6,netlink
diff --git a/etc/chromium.profile b/etc/chromium.profile
index 58f62daa2..7cf2853ca 100644
--- a/etc/chromium.profile
+++ b/etc/chromium.profile
@@ -1,7 +1,6 @@
1# Chromium browser profile 1# Chromium browser profile
2noblacklist ~/.config/chromium 2noblacklist ~/.config/chromium
3noblacklist ~/.cache/chromium 3noblacklist ~/.cache/chromium
4noblacklist ~/keepassx.kdbx
5include /etc/firejail/disable-common.inc 4include /etc/firejail/disable-common.inc
6include /etc/firejail/disable-programs.inc 5include /etc/firejail/disable-programs.inc
7 6
diff --git a/etc/clementine.profile b/etc/clementine.profile
index cc0614551..a02e05f9c 100644
--- a/etc/clementine.profile
+++ b/etc/clementine.profile
@@ -2,11 +2,10 @@
2include /etc/firejail/disable-common.inc 2include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 3include /etc/firejail/disable-programs.inc
4include /etc/firejail/disable-devel.inc 4include /etc/firejail/disable-devel.inc
5blacklist ${HOME}/.pki/nssdb 5include /etc/firejail/disable-passwdmgr.inc
6blacklist ${HOME}/.lastpass 6
7blacklist ${HOME}/.keepassx
8blacklist ${HOME}/.password-store
9blacklist ${HOME}/.wine 7blacklist ${HOME}/.wine
8
10caps.drop all 9caps.drop all
11seccomp 10seccomp
12protocol unix,inet,inet6 11protocol unix,inet,inet6
diff --git a/etc/conkeror.profile b/etc/conkeror.profile
index 67e529d0a..007eef663 100644
--- a/etc/conkeror.profile
+++ b/etc/conkeror.profile
@@ -2,11 +2,13 @@
2noblacklist ${HOME}/.conkeror.mozdev.org 2noblacklist ${HOME}/.conkeror.mozdev.org
3include /etc/firejail/disable-common.inc 3include /etc/firejail/disable-common.inc
4include /etc/firejail/disable-programs.inc 4include /etc/firejail/disable-programs.inc
5
5caps.drop all 6caps.drop all
6seccomp 7seccomp
7protocol unix,inet,inet6 8protocol unix,inet,inet6
8netfilter 9netfilter
9noroot 10noroot
11
10whitelist ~/.conkeror.mozdev.org 12whitelist ~/.conkeror.mozdev.org
11whitelist ~/Downloads 13whitelist ~/Downloads
12whitelist ~/dwhelper 14whitelist ~/dwhelper
@@ -18,6 +20,4 @@ whitelist ~/.vimperator
18whitelist ~/.pentadactylrc 20whitelist ~/.pentadactylrc
19whitelist ~/.pentadactyl 21whitelist ~/.pentadactyl
20whitelist ~/.conkerorrc 22whitelist ~/.conkerorrc
21
22# common
23include /etc/firejail/whitelist-common.inc 23include /etc/firejail/whitelist-common.inc
diff --git a/etc/deadbeef.profile b/etc/deadbeef.profile
index 89661d83c..dbf4531c4 100644
--- a/etc/deadbeef.profile
+++ b/etc/deadbeef.profile
@@ -2,11 +2,10 @@
2include /etc/firejail/disable-common.inc 2include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 3include /etc/firejail/disable-programs.inc
4include /etc/firejail/disable-devel.inc 4include /etc/firejail/disable-devel.inc
5blacklist ${HOME}/.pki/nssdb 5include /etc/firejail/disable-passwdmgr.inc
6blacklist ${HOME}/.lastpass 6
7blacklist ${HOME}/.keepassx
8blacklist ${HOME}/.password-store
9blacklist ${HOME}/.wine 7blacklist ${HOME}/.wine
8
10caps.drop all 9caps.drop all
11seccomp 10seccomp
12protocol unix,inet,inet6 11protocol unix,inet,inet6
diff --git a/etc/deluge.profile b/etc/deluge.profile
index eef2a42ee..9b2c65656 100644
--- a/etc/deluge.profile
+++ b/etc/deluge.profile
@@ -2,11 +2,10 @@
2include /etc/firejail/disable-common.inc 2include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 3include /etc/firejail/disable-programs.inc
4include /etc/firejail/disable-devel.inc 4include /etc/firejail/disable-devel.inc
5blacklist ${HOME}/.pki/nssdb 5include /etc/firejail/disable-passwdmgr.inc
6blacklist ${HOME}/.lastpass 6
7blacklist ${HOME}/.keepassx
8blacklist ${HOME}/.password-store
9blacklist ${HOME}/.wine 7blacklist ${HOME}/.wine
8
10caps.drop all 9caps.drop all
11seccomp 10seccomp
12protocol unix,inet,inet6 11protocol unix,inet,inet6
diff --git a/etc/disable-passwdmgr.inc b/etc/disable-passwdmgr.inc
new file mode 100644
index 000000000..c1e68d1ec
--- /dev/null
+++ b/etc/disable-passwdmgr.inc
@@ -0,0 +1,6 @@
1blacklist ${HOME}/.pki/nssdb
2blacklist ${HOME}/.lastpass
3blacklist ${HOME}/.keepassx
4blacklist ${HOME}/.password-store
5blacklist ${HOME}/keepassx.kdbx
6
diff --git a/etc/dnscrypt-proxy.profile b/etc/dnscrypt-proxy.profile
index dc6b783ee..bd7e19dc2 100644
--- a/etc/dnscrypt-proxy.profile
+++ b/etc/dnscrypt-proxy.profile
@@ -4,6 +4,8 @@ noblacklist /usr/sbin
4include /etc/firejail/disable-common.inc 4include /etc/firejail/disable-common.inc
5include /etc/firejail/disable-programs.inc 5include /etc/firejail/disable-programs.inc
6include /etc/firejail/disable-devel.inc 6include /etc/firejail/disable-devel.inc
7include /etc/firejail/disable-passwdmgr.inc
8
7private 9private
8private-dev 10private-dev
9seccomp.drop mount,umount2,ptrace,kexec_load,kexec_file_load,open_by_handle_at,init_module,finit_module,delete_module,iopl,ioperm,swapon,swapoff,syslog,process_vm_readv,process_vm_writev,sysfs,_sysctl,adjtimex,clock_adjtime,lookup_dcookie,perf_event_open,fanotify_init,kcmp,add_key,request_key,keyctl,uselib,acct,modify_ldt,pivot_root,io_setup,io_destroy,io_getevents,io_submit,io_cancel,remap_file_pages,mbind,get_mempolicy,set_mempolicy,migrate_pages,move_pages,vmsplice,perf_event_open 11seccomp.drop mount,umount2,ptrace,kexec_load,kexec_file_load,open_by_handle_at,init_module,finit_module,delete_module,iopl,ioperm,swapon,swapoff,syslog,process_vm_readv,process_vm_writev,sysfs,_sysctl,adjtimex,clock_adjtime,lookup_dcookie,perf_event_open,fanotify_init,kcmp,add_key,request_key,keyctl,uselib,acct,modify_ldt,pivot_root,io_setup,io_destroy,io_getevents,io_submit,io_cancel,remap_file_pages,mbind,get_mempolicy,set_mempolicy,migrate_pages,move_pages,vmsplice,perf_event_open
diff --git a/etc/dropbox.profile b/etc/dropbox.profile
index 3b48f0d49..ea0dc1fcb 100644
--- a/etc/dropbox.profile
+++ b/etc/dropbox.profile
@@ -1,11 +1,10 @@
1# dropbox profile 1# dropbox profile
2include /etc/firejail/disable-common.inc 2include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 3include /etc/firejail/disable-programs.inc
4blacklist ${HOME}/.pki/nssdb 4include /etc/firejail/disable-passwdmgr.inc
5blacklist ${HOME}/.lastpass 5
6blacklist ${HOME}/.keepassx
7blacklist ${HOME}/.password-store
8blacklist ${HOME}/.wine 6blacklist ${HOME}/.wine
7
9caps 8caps
10seccomp 9seccomp
11protocol unix,inet,inet6 10protocol unix,inet,inet6
diff --git a/etc/empathy.profile b/etc/empathy.profile
index 1c46f8b3e..37277e3d1 100644
--- a/etc/empathy.profile
+++ b/etc/empathy.profile
@@ -2,7 +2,9 @@
2include /etc/firejail/disable-common.inc 2include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 3include /etc/firejail/disable-programs.inc
4include /etc/firejail/disable-devel.inc 4include /etc/firejail/disable-devel.inc
5
5blacklist ${HOME}/.wine 6blacklist ${HOME}/.wine
7
6caps.drop all 8caps.drop all
7seccomp 9seccomp
8protocol unix,inet,inet6 10protocol unix,inet,inet6
diff --git a/etc/evince.profile b/etc/evince.profile
index 13b342f06..693593713 100644
--- a/etc/evince.profile
+++ b/etc/evince.profile
@@ -2,12 +2,10 @@
2include /etc/firejail/disable-common.inc 2include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 3include /etc/firejail/disable-programs.inc
4include /etc/firejail/disable-devel.inc 4include /etc/firejail/disable-devel.inc
5include /etc/firejail/disable-passwdmgr.inc
5 6
6blacklist ${HOME}/.pki/nssdb
7blacklist ${HOME}/.lastpass
8blacklist ${HOME}/.keepassx
9blacklist ${HOME}/.password-store
10blacklist ${HOME}/.wine 7blacklist ${HOME}/.wine
8
11caps.drop all 9caps.drop all
12seccomp 10seccomp
13protocol unix,inet,inet6 11protocol unix,inet,inet6
diff --git a/etc/fbreader.profile b/etc/fbreader.profile
index 4b45208d7..c45acc901 100644
--- a/etc/fbreader.profile
+++ b/etc/fbreader.profile
@@ -3,12 +3,10 @@ noblacklist ${HOME}/.FBReader
3include /etc/firejail/disable-common.inc 3include /etc/firejail/disable-common.inc
4include /etc/firejail/disable-programs.inc 4include /etc/firejail/disable-programs.inc
5include /etc/firejail/disable-devel.inc 5include /etc/firejail/disable-devel.inc
6include /etc/firejail/disable-passwdmgr.inc
6 7
7blacklist ${HOME}/.pki/nssdb
8blacklist ${HOME}/.lastpass
9blacklist ${HOME}/.keepassx
10blacklist ${HOME}/.password-store
11blacklist ${HOME}/.wine 8blacklist ${HOME}/.wine
9
12caps.drop all 10caps.drop all
13seccomp 11seccomp
14protocol unix,inet,inet6 12protocol unix,inet,inet6
diff --git a/etc/filezilla.profile b/etc/filezilla.profile
index 09e56b1ce..dc677542f 100644
--- a/etc/filezilla.profile
+++ b/etc/filezilla.profile
@@ -6,6 +6,7 @@ include /etc/firejail/disable-programs.inc
6include /etc/firejail/disable-devel.inc 6include /etc/firejail/disable-devel.inc
7 7
8blacklist ${HOME}/.wine 8blacklist ${HOME}/.wine
9
9caps.drop all 10caps.drop all
10seccomp 11seccomp
11protocol unix,inet,inet6 12protocol unix,inet,inet6
diff --git a/etc/firefox.profile b/etc/firefox.profile
index 2d2716256..1ea94a2c7 100644
--- a/etc/firefox.profile
+++ b/etc/firefox.profile
@@ -2,7 +2,6 @@
2 2
3noblacklist ~/.mozilla 3noblacklist ~/.mozilla
4noblacklist ~/.cache/mozilla 4noblacklist ~/.cache/mozilla
5noblacklist ~/keepassx.kdbx
6include /etc/firejail/disable-common.inc 5include /etc/firejail/disable-common.inc
7include /etc/firejail/disable-programs.inc 6include /etc/firejail/disable-programs.inc
8include /etc/firejail/disable-devel.inc 7include /etc/firejail/disable-devel.inc
diff --git a/etc/flashpeak-slimjet.profile b/etc/flashpeak-slimjet.profile
index 3f6af42b1..94c672acf 100644
--- a/etc/flashpeak-slimjet.profile
+++ b/etc/flashpeak-slimjet.profile
@@ -7,7 +7,6 @@
7# 7#
8noblacklist ~/.config/slimjet 8noblacklist ~/.config/slimjet
9noblacklist ~/.cache/slimjet 9noblacklist ~/.cache/slimjet
10noblacklist ~/keepassx.kdbx
11include /etc/firejail/disable-common.inc 10include /etc/firejail/disable-common.inc
12include /etc/firejail/disable-programs.inc 11include /etc/firejail/disable-programs.inc
13 12
diff --git a/etc/generic.profile b/etc/generic.profile
index 2bf7a0703..f2c7d4114 100644
--- a/etc/generic.profile
+++ b/etc/generic.profile
@@ -3,11 +3,10 @@
3################################ 3################################
4include /etc/firejail/disable-common.inc 4include /etc/firejail/disable-common.inc
5include /etc/firejail/disable-programs.inc 5include /etc/firejail/disable-programs.inc
6include /etc/firejail/disable-passwdmgr.inc
7
8#blacklist ${HOME}/.wine
6 9
7blacklist ${HOME}/.pki/nssdb
8blacklist ${HOME}/.lastpass
9blacklist ${HOME}/.keepassx
10blacklist ${HOME}/.password-store
11caps.drop all 10caps.drop all
12seccomp 11seccomp
13protocol unix,inet,inet6 12protocol unix,inet,inet6
diff --git a/etc/gnome-mplayer.profile b/etc/gnome-mplayer.profile
index 1138a73bd..a96b19ec3 100644
--- a/etc/gnome-mplayer.profile
+++ b/etc/gnome-mplayer.profile
@@ -2,12 +2,10 @@
2include /etc/firejail/disable-common.inc 2include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 3include /etc/firejail/disable-programs.inc
4include /etc/firejail/disable-devel.inc 4include /etc/firejail/disable-devel.inc
5include /etc/firejail/disable-passwdmgr.inc
5 6
6blacklist ${HOME}/.pki/nssdb
7blacklist ${HOME}/.lastpass
8blacklist ${HOME}/.keepassx
9blacklist ${HOME}/.password-store
10blacklist ${HOME}/.wine 7blacklist ${HOME}/.wine
8
11caps.drop all 9caps.drop all
12seccomp 10seccomp
13protocol unix,inet,inet6 11protocol unix,inet,inet6
diff --git a/etc/google-chrome-beta.profile b/etc/google-chrome-beta.profile
index 8ca049778..11f9f9e33 100644
--- a/etc/google-chrome-beta.profile
+++ b/etc/google-chrome-beta.profile
@@ -1,7 +1,6 @@
1# Google Chrome beta browser profile 1# Google Chrome beta browser profile
2noblacklist ~/.config/google-chrome-beta 2noblacklist ~/.config/google-chrome-beta
3noblacklist ~/.cache/google-chrome-beta 3noblacklist ~/.cache/google-chrome-beta
4noblacklist ~/keepassx.kdbx
5include /etc/firejail/disable-common.inc 4include /etc/firejail/disable-common.inc
6include /etc/firejail/disable-programs.inc 5include /etc/firejail/disable-programs.inc
7 6
diff --git a/etc/google-chrome-unstable.profile b/etc/google-chrome-unstable.profile
index 3e238d8f8..f253e5a90 100644
--- a/etc/google-chrome-unstable.profile
+++ b/etc/google-chrome-unstable.profile
@@ -1,7 +1,6 @@
1# Google Chrome unstable browser profile 1# Google Chrome unstable browser profile
2noblacklist ~/.config/google-chrome-unstable 2noblacklist ~/.config/google-chrome-unstable
3noblacklist ~/.cache/google-chrome-unstable 3noblacklist ~/.cache/google-chrome-unstable
4noblacklist ~/keepassx.kdbx
5include /etc/firejail/disable-common.inc 4include /etc/firejail/disable-common.inc
6include /etc/firejail/disable-programs.inc 5include /etc/firejail/disable-programs.inc
7 6
diff --git a/etc/google-chrome.profile b/etc/google-chrome.profile
index afc57f948..5e168aae5 100644
--- a/etc/google-chrome.profile
+++ b/etc/google-chrome.profile
@@ -1,7 +1,6 @@
1# Google Chrome browser profile 1# Google Chrome browser profile
2noblacklist ~/.config/google-chrome 2noblacklist ~/.config/google-chrome
3noblacklist ~/.cache/google-chrome 3noblacklist ~/.cache/google-chrome
4noblacklist ~/keepassx.kdbx
5include /etc/firejail/disable-common.inc 4include /etc/firejail/disable-common.inc
6include /etc/firejail/disable-programs.inc 5include /etc/firejail/disable-programs.inc
7 6
diff --git a/etc/hedgewars.profile b/etc/hedgewars.profile
index 13a311070..53d0c2eaf 100644
--- a/etc/hedgewars.profile
+++ b/etc/hedgewars.profile
@@ -3,6 +3,7 @@
3include /etc/firejail/disable-common.inc 3include /etc/firejail/disable-common.inc
4include /etc/firejail/disable-programs.inc 4include /etc/firejail/disable-programs.inc
5include /etc/firejail/disable-devel.inc 5include /etc/firejail/disable-devel.inc
6include /etc/firejail/disable-passwdmgr.inc
6 7
7caps.drop all 8caps.drop all
8noroot 9noroot
@@ -12,3 +13,4 @@ tracelog
12 13
13mkdir ~/.hedgewars 14mkdir ~/.hedgewars
14whitelist ~/.hedgewars 15whitelist ~/.hedgewars
16include /etc/firejail/whitelist-common.inc
diff --git a/etc/kmail.profile b/etc/kmail.profile
index 78e72a7a7..67a7b4eb1 100644
--- a/etc/kmail.profile
+++ b/etc/kmail.profile
@@ -3,11 +3,8 @@ noblacklist ${HOME}/.gnupg
3include /etc/firejail/disable-common.inc 3include /etc/firejail/disable-common.inc
4include /etc/firejail/disable-programs.inc 4include /etc/firejail/disable-programs.inc
5include /etc/firejail/disable-devel.inc 5include /etc/firejail/disable-devel.inc
6include /etc/firejail/disable-passwdmgr.inc
6 7
7blacklist ${HOME}/.pki/nssdb
8blacklist ${HOME}/.lastpass
9blacklist ${HOME}/.keepassx
10blacklist ${HOME}/.password-store
11blacklist ${HOME}/.wine 8blacklist ${HOME}/.wine
12 9
13caps.drop all 10caps.drop all
diff --git a/etc/lxterminal.profile b/etc/lxterminal.profile
index 88a7a8c7a..b6acf2587 100644
--- a/etc/lxterminal.profile
+++ b/etc/lxterminal.profile
@@ -2,11 +2,7 @@
2 2
3include /etc/firejail/disable-common.inc 3include /etc/firejail/disable-common.inc
4include /etc/firejail/disable-programs.inc 4include /etc/firejail/disable-programs.inc
5 5include /etc/firejail/disable-passwdmgr.inc
6blacklist ${HOME}/.pki/nssdb
7blacklist ${HOME}/.lastpass
8blacklist ${HOME}/.keepassx
9blacklist ${HOME}/.password-store
10 6
11caps.drop all 7caps.drop all
12seccomp 8seccomp
diff --git a/etc/mupen64plus.profile b/etc/mupen64plus.profile
index 45dc4757f..101074c24 100644
--- a/etc/mupen64plus.profile
+++ b/etc/mupen64plus.profile
@@ -3,6 +3,7 @@
3include /etc/firejail/disable-common.inc 3include /etc/firejail/disable-common.inc
4include /etc/firejail/disable-programs.inc 4include /etc/firejail/disable-programs.inc
5include /etc/firejail/disable-devel.inc 5include /etc/firejail/disable-devel.inc
6include /etc/firejail/disable-passwdmgr.inc
6 7
7mkdir ${HOME}/.local 8mkdir ${HOME}/.local
8mkdir ${HOME}/.local/share 9mkdir ${HOME}/.local/share
diff --git a/etc/opera-beta.profile b/etc/opera-beta.profile
index 7b74d6dd1..3d6edb286 100644
--- a/etc/opera-beta.profile
+++ b/etc/opera-beta.profile
@@ -1,7 +1,6 @@
1# Opera-beta browser profile 1# Opera-beta browser profile
2noblacklist ~/.config/opera-beta 2noblacklist ~/.config/opera-beta
3noblacklist ~/.cache/opera-beta 3noblacklist ~/.cache/opera-beta
4noblacklist ~/keepassx.kdbx
5include /etc/firejail/disable-common.inc 4include /etc/firejail/disable-common.inc
6include /etc/firejail/disable-programs.inc 5include /etc/firejail/disable-programs.inc
7include /etc/firejail/disable-devel.inc 6include /etc/firejail/disable-devel.inc
diff --git a/etc/opera.profile b/etc/opera.profile
index 2d7a9ca06..11e6e2a6e 100644
--- a/etc/opera.profile
+++ b/etc/opera.profile
@@ -1,7 +1,6 @@
1# Opera browser profile 1# Opera browser profile
2noblacklist ~/.config/opera 2noblacklist ~/.config/opera
3noblacklist ~/.cache/opera 3noblacklist ~/.cache/opera
4noblacklist ~/keepassx.kdbx
5include /etc/firejail/disable-common.inc 4include /etc/firejail/disable-common.inc
6include /etc/firejail/disable-programs.inc 5include /etc/firejail/disable-programs.inc
7include /etc/firejail/disable-devel.inc 6include /etc/firejail/disable-devel.inc
diff --git a/etc/parole.profile b/etc/parole.profile
index 9f63e5b16..0c9a72143 100644
--- a/etc/parole.profile
+++ b/etc/parole.profile
@@ -2,15 +2,11 @@
2include /etc/firejail/disable-common.inc 2include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 3include /etc/firejail/disable-programs.inc
4include /etc/firejail/disable-devel.inc 4include /etc/firejail/disable-devel.inc
5include /etc/firejail/disable-passwdmgr.inc
5 6
6private-etc passwd,group,fonts 7private-etc passwd,group,fonts
7private-bin parole,dbus-launch 8private-bin parole,dbus-launch
8 9
9blacklist ${HOME}/.pki/nssdb
10blacklist ${HOME}/.lastpass
11blacklist ${HOME}/.keepassx
12blacklist ${HOME}/.password-store
13
14caps.drop all 10caps.drop all
15seccomp 11seccomp
16protocol unix,inet,inet6 12protocol unix,inet,inet6
diff --git a/etc/qbittorrent.profile b/etc/qbittorrent.profile
index 9ad073b05..121d08a13 100644
--- a/etc/qbittorrent.profile
+++ b/etc/qbittorrent.profile
@@ -2,11 +2,8 @@
2include /etc/firejail/disable-common.inc 2include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 3include /etc/firejail/disable-programs.inc
4include /etc/firejail/disable-devel.inc 4include /etc/firejail/disable-devel.inc
5include /etc/firejail/disable-passwdmgr.inc
5 6
6blacklist ${HOME}/.pki/nssdb
7blacklist ${HOME}/.lastpass
8blacklist ${HOME}/.keepassx
9blacklist ${HOME}/.password-store
10blacklist ${HOME}/.wine 7blacklist ${HOME}/.wine
11 8
12caps.drop all 9caps.drop all
diff --git a/etc/qutebrowser.profile b/etc/qutebrowser.profile
index 3b7bf2d55..934a374de 100644
--- a/etc/qutebrowser.profile
+++ b/etc/qutebrowser.profile
@@ -19,5 +19,4 @@ whitelist ~/.config/qutebrowser
19mkdir ~/.cache 19mkdir ~/.cache
20mkdir ~/.cache/qutebrowser 20mkdir ~/.cache/qutebrowser
21whitelist ~/.cache/qutebrowser 21whitelist ~/.cache/qutebrowser
22
23include /etc/firejail/whitelist-common.inc 22include /etc/firejail/whitelist-common.inc
diff --git a/etc/rhythmbox.profile b/etc/rhythmbox.profile
index 50838a15b..a3204c5f9 100644
--- a/etc/rhythmbox.profile
+++ b/etc/rhythmbox.profile
@@ -2,11 +2,8 @@
2include /etc/firejail/disable-common.inc 2include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 3include /etc/firejail/disable-programs.inc
4include /etc/firejail/disable-devel.inc 4include /etc/firejail/disable-devel.inc
5include /etc/firejail/disable-passwdmgr.inc
5 6
6blacklist ${HOME}/.pki/nssdb
7blacklist ${HOME}/.lastpass
8blacklist ${HOME}/.keepassx
9blacklist ${HOME}/.password-store
10blacklist ${HOME}/.wine 7blacklist ${HOME}/.wine
11 8
12caps.drop all 9caps.drop all
diff --git a/etc/rtorrent.profile b/etc/rtorrent.profile
index 67477dad6..ae0430830 100644
--- a/etc/rtorrent.profile
+++ b/etc/rtorrent.profile
@@ -2,6 +2,7 @@
2include /etc/firejail/disable-common.inc 2include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 3include /etc/firejail/disable-programs.inc
4include /etc/firejail/disable-devel.inc 4include /etc/firejail/disable-devel.inc
5include /etc/firejail/disable-passwdmgr.inc
5 6
6caps.drop all 7caps.drop all
7seccomp 8seccomp
diff --git a/etc/seamonkey.profile b/etc/seamonkey.profile
index 71a52b3bb..a10d5b0ec 100644
--- a/etc/seamonkey.profile
+++ b/etc/seamonkey.profile
@@ -1,7 +1,6 @@
1# Firejail profile for Seamoneky based off Mozilla Firefox 1# Firejail profile for Seamoneky based off Mozilla Firefox
2noblacklist ~/.mozilla 2noblacklist ~/.mozilla
3noblacklist ~/.cache/mozilla 3noblacklist ~/.cache/mozilla
4noblacklist ~/keepassx.kdbx
5include /etc/firejail/disable-common.inc 4include /etc/firejail/disable-common.inc
6include /etc/firejail/disable-programs.inc 5include /etc/firejail/disable-programs.inc
7include /etc/firejail/disable-devel.inc 6include /etc/firejail/disable-devel.inc
diff --git a/etc/server.profile b/etc/server.profile
index 61d10ba64..1b3cb7207 100644
--- a/etc/server.profile
+++ b/etc/server.profile
@@ -4,6 +4,7 @@ noblacklist /sbin
4noblacklist /usr/sbin 4noblacklist /usr/sbin
5include /etc/firejail/disable-common.inc 5include /etc/firejail/disable-common.inc
6include /etc/firejail/disable-programs.inc 6include /etc/firejail/disable-programs.inc
7include /etc/firejail/disable-passwdmgr.inc
7 8
8private 9private
9private-dev 10private-dev
diff --git a/etc/spotify.profile b/etc/spotify.profile
index 326d5d93e..dfe298e1d 100644
--- a/etc/spotify.profile
+++ b/etc/spotify.profile
@@ -2,6 +2,7 @@
2include /etc/firejail/disable-common.inc 2include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 3include /etc/firejail/disable-programs.inc
4include /etc/firejail/disable-devel.inc 4include /etc/firejail/disable-devel.inc
5include /etc/firejail/disable-passwdmgr.inc
5 6
6# Whitelist the folders needed by Spotify - This is more restrictive 7# Whitelist the folders needed by Spotify - This is more restrictive
7# than a blacklist though, but this is all spotify requires for 8# than a blacklist though, but this is all spotify requires for
diff --git a/etc/ssh.profile b/etc/ssh.profile
index 32536c0a7..7e105724e 100644
--- a/etc/ssh.profile
+++ b/etc/ssh.profile
@@ -2,11 +2,9 @@
2noblacklist ~/.ssh 2noblacklist ~/.ssh
3include /etc/firejail/disable-common.inc 3include /etc/firejail/disable-common.inc
4include /etc/firejail/disable-programs.inc 4include /etc/firejail/disable-programs.inc
5include /etc/firejail/disable-passwdmgr.inc
5 6
6blacklist ${HOME}/.pki/nssdb 7blacklist ${HOME}/.wine
7blacklist ${HOME}/.lastpass
8blacklist ${HOME}/.keepassx
9blacklist ${HOME}/.password-store
10 8
11caps.drop all 9caps.drop all
12seccomp 10seccomp
diff --git a/etc/steam.profile b/etc/steam.profile
index 31ebf543e..4c96e8258 100644
--- a/etc/steam.profile
+++ b/etc/steam.profile
@@ -4,6 +4,7 @@ noblacklist ${HOME}/.local/share/steam
4include /etc/firejail/disable-common.inc 4include /etc/firejail/disable-common.inc
5include /etc/firejail/disable-programs.inc 5include /etc/firejail/disable-programs.inc
6include /etc/firejail/disable-devel.inc 6include /etc/firejail/disable-devel.inc
7include /etc/firejail/disable-passwdmgr.inc
7 8
8caps.drop all 9caps.drop all
9netfilter 10netfilter
diff --git a/etc/totem.profile b/etc/totem.profile
index ad55e320a..5eeeb4402 100644
--- a/etc/totem.profile
+++ b/etc/totem.profile
@@ -2,11 +2,8 @@
2include /etc/firejail/disable-common.inc 2include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 3include /etc/firejail/disable-programs.inc
4include /etc/firejail/disable-devel.inc 4include /etc/firejail/disable-devel.inc
5include /etc/firejail/disable-passwdmgr.inc
5 6
6blacklist ${HOME}/.pki/nssdb
7blacklist ${HOME}/.lastpass
8blacklist ${HOME}/.keepassx
9blacklist ${HOME}/.password-store
10blacklist ${HOME}/.wine 7blacklist ${HOME}/.wine
11 8
12caps.drop all 9caps.drop all
diff --git a/etc/transmission-gtk.profile b/etc/transmission-gtk.profile
index ac685aee4..9e64c6d59 100644
--- a/etc/transmission-gtk.profile
+++ b/etc/transmission-gtk.profile
@@ -2,11 +2,8 @@
2include /etc/firejail/disable-common.inc 2include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 3include /etc/firejail/disable-programs.inc
4include /etc/firejail/disable-devel.inc 4include /etc/firejail/disable-devel.inc
5include /etc/firejail/disable-passwdmgr.inc
5 6
6blacklist ${HOME}/.pki/nssdb
7blacklist ${HOME}/.lastpass
8blacklist ${HOME}/.keepassx
9blacklist ${HOME}/.password-store
10blacklist ${HOME}/.wine 7blacklist ${HOME}/.wine
11 8
12caps.drop all 9caps.drop all
diff --git a/etc/transmission-qt.profile b/etc/transmission-qt.profile
index b8dffbece..1059ad3ee 100644
--- a/etc/transmission-qt.profile
+++ b/etc/transmission-qt.profile
@@ -2,11 +2,8 @@
2include /etc/firejail/disable-common.inc 2include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 3include /etc/firejail/disable-programs.inc
4include /etc/firejail/disable-devel.inc 4include /etc/firejail/disable-devel.inc
5include /etc/firejail/disable-passwdmgr.inc
5 6
6blacklist ${HOME}/.pki/nssdb
7blacklist ${HOME}/.lastpass
8blacklist ${HOME}/.keepassx
9blacklist ${HOME}/.password-store
10blacklist ${HOME}/.wine 7blacklist ${HOME}/.wine
11 8
12caps.drop all 9caps.drop all
diff --git a/etc/unbound.profile b/etc/unbound.profile
index 24ca88b03..4365e4fee 100644
--- a/etc/unbound.profile
+++ b/etc/unbound.profile
@@ -4,6 +4,7 @@ noblacklist /usr/sbin
4include /etc/firejail/disable-common.inc 4include /etc/firejail/disable-common.inc
5include /etc/firejail/disable-programs.inc 5include /etc/firejail/disable-programs.inc
6include /etc/firejail/disable-devel.inc 6include /etc/firejail/disable-devel.inc
7include /etc/firejail/disable-passwdmgr.inc
7 8
8private 9private
9private-dev 10private-dev
diff --git a/etc/vivaldi.profile b/etc/vivaldi.profile
index a4ab60e6c..449d9a168 100644
--- a/etc/vivaldi.profile
+++ b/etc/vivaldi.profile
@@ -1,7 +1,6 @@
1# Vivaldi browser profile 1# Vivaldi browser profile
2noblacklist ~/.config/vivaldi 2noblacklist ~/.config/vivaldi
3noblacklist ~/.cache/vivaldi 3noblacklist ~/.cache/vivaldi
4noblacklist ~/keepassx.kdbx
5include /etc/firejail/disable-common.inc 4include /etc/firejail/disable-common.inc
6include /etc/firejail/disable-programs.inc 5include /etc/firejail/disable-programs.inc
7include /etc/firejail/disable-devel.inc 6include /etc/firejail/disable-devel.inc
diff --git a/etc/vlc.profile b/etc/vlc.profile
index 7cd913040..0a7469339 100644
--- a/etc/vlc.profile
+++ b/etc/vlc.profile
@@ -3,11 +3,8 @@ noblacklist ${HOME}/.config/vlc
3include /etc/firejail/disable-common.inc 3include /etc/firejail/disable-common.inc
4include /etc/firejail/disable-programs.inc 4include /etc/firejail/disable-programs.inc
5include /etc/firejail/disable-devel.inc 5include /etc/firejail/disable-devel.inc
6include /etc/firejail/disable-passwdmgr.inc
6 7
7blacklist ${HOME}/.pki/nssdb
8blacklist ${HOME}/.lastpass
9blacklist ${HOME}/.keepassx
10blacklist ${HOME}/.password-store
11blacklist ${HOME}/.wine 8blacklist ${HOME}/.wine
12 9
13caps.drop all 10caps.drop all
diff --git a/etc/wesnoth.profile b/etc/wesnoth.profile
index 4075232d2..24b245b6c 100644
--- a/etc/wesnoth.profile
+++ b/etc/wesnoth.profile
@@ -1,8 +1,8 @@
1# Whitelist-based profile for "Battle for Wesnoth" (game). 1# Whitelist-based profile for "Battle for Wesnoth" (game).
2
3include /etc/firejail/disable-common.inc 2include /etc/firejail/disable-common.inc
4include /etc/firejail/disable-programs.inc 3include /etc/firejail/disable-programs.inc
5include /etc/firejail/disable-devel.inc 4include /etc/firejail/disable-devel.inc
5include /etc/firejail/disable-passwdmgr.inc
6 6
7caps.drop all 7caps.drop all
8seccomp 8seccomp
diff --git a/etc/xchat.profile b/etc/xchat.profile
index ae1a6de53..7c11ba76c 100644
--- a/etc/xchat.profile
+++ b/etc/xchat.profile
@@ -5,6 +5,7 @@ include /etc/firejail/disable-programs.inc
5include /etc/firejail/disable-devel.inc 5include /etc/firejail/disable-devel.inc
6 6
7blacklist ${HOME}/.wine 7blacklist ${HOME}/.wine
8
8caps.drop all 9caps.drop all
9seccomp 10seccomp
10protocol unix,inet,inet6 11protocol unix,inet,inet6