aboutsummaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
authorLibravatar smitsohu <smitsohu@gmail.com>2017-10-29 20:18:36 +0100
committerLibravatar smitsohu <smitsohu@gmail.com>2017-10-29 20:18:36 +0100
commit44adaf47214a6d1c290fca390c73fc0b9560f660 (patch)
tree8a84d003c346014523edeeff8ea39bce3977f607 /etc
parentfix and harden various profiles (diff)
downloadfirejail-44adaf47214a6d1c290fca390c73fc0b9560f660.tar.gz
firejail-44adaf47214a6d1c290fca390c73fc0b9560f660.tar.zst
firejail-44adaf47214a6d1c290fca390c73fc0b9560f660.zip
add kopete profile
Diffstat (limited to 'etc')
-rw-r--r--etc/disable-programs.inc20
-rw-r--r--etc/kopete.profile34
2 files changed, 46 insertions, 8 deletions
diff --git a/etc/disable-programs.inc b/etc/disable-programs.inc
index 0e5400dd6..9bfef1f5e 100644
--- a/etc/disable-programs.inc
+++ b/etc/disable-programs.inc
@@ -233,6 +233,7 @@ blacklist ${HOME}/.kde/share/apps/kcookiejar
233blacklist ${HOME}/.kde/share/apps/khtml 233blacklist ${HOME}/.kde/share/apps/khtml
234blacklist ${HOME}/.kde/share/apps/konqsidebartng 234blacklist ${HOME}/.kde/share/apps/konqsidebartng
235blacklist ${HOME}/.kde/share/apps/konqueror 235blacklist ${HOME}/.kde/share/apps/konqueror
236blacklist ${HOME}/.kde/share/apps/kopete
236blacklist ${HOME}/.kde/share/apps/okular 237blacklist ${HOME}/.kde/share/apps/okular
237blacklist ${HOME}/.kde/share/config/baloofilerc 238blacklist ${HOME}/.kde/share/config/baloofilerc
238blacklist ${HOME}/.kde/share/config/baloorc 239blacklist ${HOME}/.kde/share/config/baloorc
@@ -244,28 +245,31 @@ blacklist ${HOME}/.kde/share/config/khtmlrc
244blacklist ${HOME}/.kde/share/config/konq_history 245blacklist ${HOME}/.kde/share/config/konq_history
245blacklist ${HOME}/.kde/share/config/konqsidebartngrc 246blacklist ${HOME}/.kde/share/config/konqsidebartngrc
246blacklist ${HOME}/.kde/share/config/konquerorrc 247blacklist ${HOME}/.kde/share/config/konquerorrc
248blacklist ${HOME}/.kde/share/config/kopeterc
247blacklist ${HOME}/.kde/share/config/ktorrentrc 249blacklist ${HOME}/.kde/share/config/ktorrentrc
248blacklist ${HOME}/.kde/share/config/okularpartrc 250blacklist ${HOME}/.kde/share/config/okularpartrc
249blacklist ${HOME}/.kde/share/config/okularrc 251blacklist ${HOME}/.kde/share/config/okularrc
250blacklist ${HOME}/.kde4/share/config/baloorc 252blacklist ${HOME}/.kde4/share/apps/gwenview
251blacklist ${HOME}/.kde4/share/config/baloofilerc 253blacklist ${HOME}/.kde4/share/apps/kcookiejar
252blacklist ${HOME}/.kde4/share/apps/okular 254blacklist ${HOME}/.kde4/share/apps/khtml
253blacklist ${HOME}/.kde4/share/apps/konqueror 255blacklist ${HOME}/.kde4/share/apps/konqueror
254blacklist ${HOME}/.kde4/share/apps/konqsidebartng 256blacklist ${HOME}/.kde4/share/apps/konqsidebartng
255blacklist ${HOME}/.kde4/share/apps/khtml 257blacklist ${HOME}/.kde4/share/apps/kopete
256blacklist ${HOME}/.kde4/share/apps/kcookiejar 258blacklist ${HOME}/.kde4/share/apps/okular
259blacklist ${HOME}/.kde4/share/config/baloorc
260blacklist ${HOME}/.kde4/share/config/baloofilerc
257blacklist ${HOME}/.kde4/share/config/digikam 261blacklist ${HOME}/.kde4/share/config/digikam
258blacklist ${HOME}/.kde4/share/apps/gwenview 262blacklist ${HOME}/.kde4/share/config/gwenviewrc
263blacklist ${HOME}/.kde4/share/config/k3brc
259blacklist ${HOME}/.kde4/share/config/kcookiejarrc 264blacklist ${HOME}/.kde4/share/config/kcookiejarrc
260blacklist ${HOME}/.kde4/share/config/khtmlrc 265blacklist ${HOME}/.kde4/share/config/khtmlrc
261blacklist ${HOME}/.kde4/share/config/konq_history 266blacklist ${HOME}/.kde4/share/config/konq_history
262blacklist ${HOME}/.kde4/share/config/konqsidebartngrc 267blacklist ${HOME}/.kde4/share/config/konqsidebartngrc
263blacklist ${HOME}/.kde4/share/config/konquerorrc 268blacklist ${HOME}/.kde4/share/config/konquerorrc
269blacklist ${HOME}/.kde4/share/config/kopeterc
264blacklist ${HOME}/.kde4/share/config/okularpartrc 270blacklist ${HOME}/.kde4/share/config/okularpartrc
265blacklist ${HOME}/.kde4/share/config/okularrc 271blacklist ${HOME}/.kde4/share/config/okularrc
266blacklist ${HOME}/.kde4/share/config/ktorrentrc 272blacklist ${HOME}/.kde4/share/config/ktorrentrc
267blacklist ${HOME}/.kde4/share/config/gwenviewrc
268blacklist ${HOME}/.kde4/share/config/k3brc
269blacklist ${HOME}/.killingfloor 273blacklist ${HOME}/.killingfloor
270blacklist ${HOME}/.kino-history 274blacklist ${HOME}/.kino-history
271blacklist ${HOME}/.kinorc 275blacklist ${HOME}/.kinorc
diff --git a/etc/kopete.profile b/etc/kopete.profile
new file mode 100644
index 000000000..3e943c162
--- /dev/null
+++ b/etc/kopete.profile
@@ -0,0 +1,34 @@
1# Firejail profile for kopete
2# This file is overwritten after every install/update
3# Persistent local customizations
4include /etc/firejail/kopete.local
5# Persistent global definitions
6include /etc/firejail/globals.local
7
8noblacklist ~/.kde/share/apps/kopete
9noblacklist ~/.kde/share/config/kopeterc
10noblacklist ~/.kde4/share/apps/kopete
11noblacklist ~/.kde4/share/config/kopeterc
12
13include /etc/firejail/disable-common.inc
14include /etc/firejail/disable-devel.inc
15include /etc/firejail/disable-passwdmgr.inc
16include /etc/firejail/disable-programs.inc
17
18include /etc/firejail/whitelist-var-common.inc
19
20caps.drop all
21netfilter
22nodvd
23nogroups
24nonewprivs
25noroot
26notv
27protocol unix,inet,inet6,netlink
28seccomp
29
30private-dev
31private-tmp
32
33noexec ${HOME}
34noexec /tmp