aboutsummaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
authorLibravatar Tad <tad@spotco.us>2019-03-07 16:48:53 -0500
committerLibravatar Tad <tad@spotco.us>2019-03-07 16:48:53 -0500
commit2dbbb92d936935f6edcd12345461d152ea7b5dc4 (patch)
treef9e0416a746fd0db134c239953e1989014479ec1 /etc
parentmerges (diff)
downloadfirejail-2dbbb92d936935f6edcd12345461d152ea7b5dc4.tar.gz
firejail-2dbbb92d936935f6edcd12345461d152ea7b5dc4.tar.zst
firejail-2dbbb92d936935f6edcd12345461d152ea7b5dc4.zip
Add a profile for pragha
+ add code-oss to firecfg + potential fix for https://github.com/netblue30/firejail/issues/2051#issuecomment-470665213
Diffstat (limited to 'etc')
-rw-r--r--etc/disable-programs.inc1
-rw-r--r--etc/pragha.profile39
-rw-r--r--etc/wire-desktop.profile2
3 files changed, 41 insertions, 1 deletions
diff --git a/etc/disable-programs.inc b/etc/disable-programs.inc
index 54b10acc4..971e00f18 100644
--- a/etc/disable-programs.inc
+++ b/etc/disable-programs.inc
@@ -239,6 +239,7 @@ blacklist ${HOME}/.config/pitivi
239blacklist ${HOME}/.config/pix 239blacklist ${HOME}/.config/pix
240blacklist ${HOME}/.config/pluma 240blacklist ${HOME}/.config/pluma
241blacklist ${HOME}/.config/ppsspp 241blacklist ${HOME}/.config/ppsspp
242blacklist ${HOME}/.config/pragha
242blacklist ${HOME}/.config/psi+ 243blacklist ${HOME}/.config/psi+
243blacklist ${HOME}/.config/qBittorrent 244blacklist ${HOME}/.config/qBittorrent
244blacklist ${HOME}/.config/qBittorrentrc 245blacklist ${HOME}/.config/qBittorrentrc
diff --git a/etc/pragha.profile b/etc/pragha.profile
new file mode 100644
index 000000000..a595caee9
--- /dev/null
+++ b/etc/pragha.profile
@@ -0,0 +1,39 @@
1# Firejail profile for pragha
2# Description: A lightweight GTK music player
3# This file is overwritten after every install/update
4# Persistent local customizations
5include pragha.local
6# Persistent global definitions
7include globals.local
8
9noblacklist ${HOME}/.config/pragha
10noblacklist ${MUSIC}
11
12include disable-common.inc
13include disable-devel.inc
14include disable-interpreters.inc
15include disable-passwdmgr.inc
16include disable-programs.inc
17include disable-xdg.inc
18
19include whitelist-var-common.inc
20
21caps.drop all
22netfilter
23no3d
24nogroups
25nonewprivs
26noroot
27notv
28nou2f
29novideo
30protocol unix,inet,inet6
31seccomp
32shell none
33
34private-dev
35private-etc alternatives,asound.conf,ca-certificates,fonts,host.conf,hostname,hosts,pulse,resolv.conf,ssl,pki,crypto-policies,gtk-3.0,xdg,machine-id
36private-tmp
37
38noexec ${HOME}
39noexec /tmp
diff --git a/etc/wire-desktop.profile b/etc/wire-desktop.profile
index e974e4304..3953de614 100644
--- a/etc/wire-desktop.profile
+++ b/etc/wire-desktop.profile
@@ -35,7 +35,7 @@ shell none
35# it is not in PATH. To use Wire with firejail, run "firejail /opt/wire-desktop/wire-desktop" 35# it is not in PATH. To use Wire with firejail, run "firejail /opt/wire-desktop/wire-desktop"
36 36
37disable-mnt 37disable-mnt
38private-bin wire-desktop 38private-bin wire-desktop,bash,sh,env,electron
39private-dev 39private-dev
40private-etc alternatives,fonts,machine-id,resolv.conf,ca-certificates,ssl,pki,crypto-policies 40private-etc alternatives,fonts,machine-id,resolv.conf,ca-certificates,ssl,pki,crypto-policies
41private-tmp 41private-tmp