aboutsummaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
authorLibravatar netblue30 <netblue30@yahoo.com>2018-09-26 09:22:01 -0400
committerLibravatar netblue30 <netblue30@yahoo.com>2018-09-26 09:22:01 -0400
commit52c9602ce6d0c8942cdb0200558bb91bec00ee65 (patch)
tree7b54171190c182bd072c4e3520d73ad9b76af41c /etc
parenttesting (diff)
downloadfirejail-52c9602ce6d0c8942cdb0200558bb91bec00ee65.tar.gz
firejail-52c9602ce6d0c8942cdb0200558bb91bec00ee65.tar.zst
firejail-52c9602ce6d0c8942cdb0200558bb91bec00ee65.zip
mainline merge: profiles
Diffstat (limited to 'etc')
-rw-r--r--etc/android-studio.profile2
-rw-r--r--etc/apktool.profile2
-rw-r--r--etc/bless.profile2
-rw-r--r--etc/dex2jar.profile2
-rw-r--r--etc/gitg.profile2
-rw-r--r--etc/gnome-music.profile4
-rw-r--r--etc/jd-gui.profile2
-rw-r--r--etc/liferea.profile1
-rw-r--r--etc/lollypop.profile2
-rw-r--r--etc/meld.profile2
-rw-r--r--etc/minetest.profile2
-rw-r--r--etc/mumble.profile1
-rw-r--r--etc/patch.profile2
-rw-r--r--etc/picard.profile2
-rw-r--r--etc/pithos.profile1
-rw-r--r--etc/remmina.profile2
-rw-r--r--etc/sdat2img.profile2
-rw-r--r--etc/shellcheck.profile2
-rw-r--r--etc/soundconverter.profile2
-rw-r--r--etc/spectre-meltdown-checker.profile53
-rw-r--r--etc/sqlitebrowser.profile2
-rw-r--r--etc/start-tor-browser.desktop.profile66
-rw-r--r--etc/vlc.profile2
-rw-r--r--etc/xonotic.profile1
24 files changed, 158 insertions, 3 deletions
diff --git a/etc/android-studio.profile b/etc/android-studio.profile
index d845bd4b9..8f5cd56cc 100644
--- a/etc/android-studio.profile
+++ b/etc/android-studio.profile
@@ -20,6 +20,8 @@ include /etc/firejail/disable-common.inc
20include /etc/firejail/disable-passwdmgr.inc 20include /etc/firejail/disable-passwdmgr.inc
21include /etc/firejail/disable-programs.inc 21include /etc/firejail/disable-programs.inc
22 22
23include /etc/firejail/whitelist-var-common.inc
24
23caps.drop all 25caps.drop all
24netfilter 26netfilter
25nodvd 27nodvd
diff --git a/etc/apktool.profile b/etc/apktool.profile
index 2043cf5af..d157b1478 100644
--- a/etc/apktool.profile
+++ b/etc/apktool.profile
@@ -12,6 +12,8 @@ include /etc/firejail/disable-passwdmgr.inc
12include /etc/firejail/disable-programs.inc 12include /etc/firejail/disable-programs.inc
13include /etc/firejail/disable-xdg.inc 13include /etc/firejail/disable-xdg.inc
14 14
15include /etc/firejail/whitelist-var-common.inc
16
15caps.drop all 17caps.drop all
16net none 18net none
17no3d 19no3d
diff --git a/etc/bless.profile b/etc/bless.profile
index 01f75b00d..0da3436e8 100644
--- a/etc/bless.profile
+++ b/etc/bless.profile
@@ -14,6 +14,8 @@ include /etc/firejail/disable-interpreters.inc
14include /etc/firejail/disable-passwdmgr.inc 14include /etc/firejail/disable-passwdmgr.inc
15include /etc/firejail/disable-programs.inc 15include /etc/firejail/disable-programs.inc
16 16
17include /etc/firejail/whitelist-var-common.inc
18
17caps.drop all 19caps.drop all
18net none 20net none
19no3d 21no3d
diff --git a/etc/dex2jar.profile b/etc/dex2jar.profile
index b61d68e06..da59fc71a 100644
--- a/etc/dex2jar.profile
+++ b/etc/dex2jar.profile
@@ -19,6 +19,8 @@ include /etc/firejail/disable-passwdmgr.inc
19include /etc/firejail/disable-programs.inc 19include /etc/firejail/disable-programs.inc
20include /etc/firejail/disable-xdg.inc 20include /etc/firejail/disable-xdg.inc
21 21
22include /etc/firejail/whitelist-var-common.inc
23
22caps.drop all 24caps.drop all
23net none 25net none
24no3d 26no3d
diff --git a/etc/gitg.profile b/etc/gitg.profile
index 5a7349eb1..87d8c0a1f 100644
--- a/etc/gitg.profile
+++ b/etc/gitg.profile
@@ -16,6 +16,8 @@ include /etc/firejail/disable-interpreters.inc
16include /etc/firejail/disable-passwdmgr.inc 16include /etc/firejail/disable-passwdmgr.inc
17include /etc/firejail/disable-programs.inc 17include /etc/firejail/disable-programs.inc
18 18
19include /etc/firejail/whitelist-var-common.inc
20
19caps.drop all 21caps.drop all
20no3d 22no3d
21nodvd 23nodvd
diff --git a/etc/gnome-music.profile b/etc/gnome-music.profile
index eaec627c6..819c40c98 100644
--- a/etc/gnome-music.profile
+++ b/etc/gnome-music.profile
@@ -37,9 +37,9 @@ seccomp
37shell none 37shell none
38tracelog 38tracelog
39 39
40private-bin gnome-music,python* 40private-bin gnome-music,python*,env,gio-launch-desktop,yelp
41private-dev 41private-dev
42# private-etc fonts,machine-id,pulse,asound.conf 42private-etc fonts,machine-id,pulse,asound.conf
43private-tmp 43private-tmp
44 44
45noexec ${HOME} 45noexec ${HOME}
diff --git a/etc/jd-gui.profile b/etc/jd-gui.profile
index 81e538153..3a280dab7 100644
--- a/etc/jd-gui.profile
+++ b/etc/jd-gui.profile
@@ -21,6 +21,8 @@ include /etc/firejail/disable-passwdmgr.inc
21include /etc/firejail/disable-programs.inc 21include /etc/firejail/disable-programs.inc
22include /etc/firejail/disable-xdg.inc 22include /etc/firejail/disable-xdg.inc
23 23
24include /etc/firejail/whitelist-var-common.inc
25
24caps.drop all 26caps.drop all
25net none 27net none
26no3d 28no3d
diff --git a/etc/liferea.profile b/etc/liferea.profile
index 673182c10..04c649121 100644
--- a/etc/liferea.profile
+++ b/etc/liferea.profile
@@ -29,6 +29,7 @@ whitelist ${HOME}/.cache/liferea
29whitelist ${HOME}/.config/liferea 29whitelist ${HOME}/.config/liferea
30whitelist ${HOME}/.local/share/liferea 30whitelist ${HOME}/.local/share/liferea
31include /etc/firejail/whitelist-common.inc 31include /etc/firejail/whitelist-common.inc
32include /etc/firejail/whitelist-var-common.inc
32 33
33caps.drop all 34caps.drop all
34netfilter 35netfilter
diff --git a/etc/lollypop.profile b/etc/lollypop.profile
index 0f8f49488..efd40e899 100644
--- a/etc/lollypop.profile
+++ b/etc/lollypop.profile
@@ -22,6 +22,8 @@ include /etc/firejail/disable-passwdmgr.inc
22include /etc/firejail/disable-programs.inc 22include /etc/firejail/disable-programs.inc
23include /etc/firejail/disable-xdg.inc 23include /etc/firejail/disable-xdg.inc
24 24
25include /etc/firejail/whitelist-var-common.inc
26
25caps.drop all 27caps.drop all
26netfilter 28netfilter
27no3d 29no3d
diff --git a/etc/meld.profile b/etc/meld.profile
index 00d5c6caa..1a7935800 100644
--- a/etc/meld.profile
+++ b/etc/meld.profile
@@ -13,6 +13,8 @@ include /etc/firejail/disable-devel.inc
13include /etc/firejail/disable-passwdmgr.inc 13include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc 14include /etc/firejail/disable-programs.inc
15 15
16include /etc/firejail/whitelist-var-common.inc
17
16caps.drop all 18caps.drop all
17net none 19net none
18no3d 20no3d
diff --git a/etc/minetest.profile b/etc/minetest.profile
index 7de546791..3e06b6d30 100644
--- a/etc/minetest.profile
+++ b/etc/minetest.profile
@@ -17,10 +17,12 @@ include /etc/firejail/disable-programs.inc
17mkdir ${HOME}/.minetest 17mkdir ${HOME}/.minetest
18whitelist ${HOME}/.minetest 18whitelist ${HOME}/.minetest
19include /etc/firejail/whitelist-common.inc 19include /etc/firejail/whitelist-common.inc
20include /etc/firejail/whitelist-var-common.inc
20 21
21caps.drop all 22caps.drop all
22ipc-namespace 23ipc-namespace
23netfilter 24netfilter
25nodbus
24nodvd 26nodvd
25nogroups 27nogroups
26nonewprivs 28nonewprivs
diff --git a/etc/mumble.profile b/etc/mumble.profile
index f894acb57..c5af9aa42 100644
--- a/etc/mumble.profile
+++ b/etc/mumble.profile
@@ -20,6 +20,7 @@ mkdir ${HOME}/.local/share/data/Mumble
20whitelist ${HOME}/.config/Mumble 20whitelist ${HOME}/.config/Mumble
21whitelist ${HOME}/.local/share/data/Mumble 21whitelist ${HOME}/.local/share/data/Mumble
22include /etc/firejail/whitelist-common.inc 22include /etc/firejail/whitelist-common.inc
23include /etc/firejail/whitelist-var-common.inc
23 24
24caps.drop all 25caps.drop all
25netfilter 26netfilter
diff --git a/etc/patch.profile b/etc/patch.profile
index d4058d6e7..8fa6ac966 100644
--- a/etc/patch.profile
+++ b/etc/patch.profile
@@ -15,6 +15,8 @@ include /etc/firejail/disable-interpreters.inc
15include /etc/firejail/disable-passwdmgr.inc 15include /etc/firejail/disable-passwdmgr.inc
16include /etc/firejail/disable-xdg.inc 16include /etc/firejail/disable-xdg.inc
17 17
18include /etc/firejail/whitelist-var-common.inc
19
18caps.drop all 20caps.drop all
19ipc-namespace 21ipc-namespace
20net none 22net none
diff --git a/etc/picard.profile b/etc/picard.profile
index 2cc0b5c68..8474eeda6 100644
--- a/etc/picard.profile
+++ b/etc/picard.profile
@@ -23,6 +23,8 @@ include /etc/firejail/disable-passwdmgr.inc
23include /etc/firejail/disable-programs.inc 23include /etc/firejail/disable-programs.inc
24include /etc/firejail/disable-xdg.inc 24include /etc/firejail/disable-xdg.inc
25 25
26include /etc/firejail/whitelist-var-common.inc
27
26caps.drop all 28caps.drop all
27no3d 29no3d
28nodvd 30nodvd
diff --git a/etc/pithos.profile b/etc/pithos.profile
index e5af9c973..cbe7ac9c6 100644
--- a/etc/pithos.profile
+++ b/etc/pithos.profile
@@ -20,6 +20,7 @@ include /etc/firejail/disable-programs.inc
20include /etc/firejail/disable-xdg.inc 20include /etc/firejail/disable-xdg.inc
21 21
22include /etc/firejail/whitelist-common.inc 22include /etc/firejail/whitelist-common.inc
23include /etc/firejail/whitelist-var-common.inc
23 24
24caps.drop all 25caps.drop all
25netfilter 26netfilter
diff --git a/etc/remmina.profile b/etc/remmina.profile
index 5078000bb..51c0f2d17 100644
--- a/etc/remmina.profile
+++ b/etc/remmina.profile
@@ -18,6 +18,8 @@ include /etc/firejail/disable-passwdmgr.inc
18include /etc/firejail/disable-programs.inc 18include /etc/firejail/disable-programs.inc
19include /etc/firejail/disable-xdg.inc 19include /etc/firejail/disable-xdg.inc
20 20
21include /etc/firejail/whitelist-var-common.inc
22
21caps.drop all 23caps.drop all
22nodvd 24nodvd
23nogroups 25nogroups
diff --git a/etc/sdat2img.profile b/etc/sdat2img.profile
index e318dd568..a2a54f838 100644
--- a/etc/sdat2img.profile
+++ b/etc/sdat2img.profile
@@ -19,6 +19,8 @@ include /etc/firejail/disable-passwdmgr.inc
19include /etc/firejail/disable-programs.inc 19include /etc/firejail/disable-programs.inc
20include /etc/firejail/disable-xdg.inc 20include /etc/firejail/disable-xdg.inc
21 21
22include /etc/firejail/whitelist-var-common.inc
23
22caps.drop all 24caps.drop all
23net none 25net none
24no3d 26no3d
diff --git a/etc/shellcheck.profile b/etc/shellcheck.profile
index f6c154183..90fc9cb8c 100644
--- a/etc/shellcheck.profile
+++ b/etc/shellcheck.profile
@@ -16,6 +16,8 @@ include /etc/firejail/disable-passwdmgr.inc
16include /etc/firejail/disable-programs.inc 16include /etc/firejail/disable-programs.inc
17include /etc/firejail/disable-xdg.inc 17include /etc/firejail/disable-xdg.inc
18 18
19include /etc/firejail/whitelist-var-common.inc
20
19caps.drop all 21caps.drop all
20ipc-namespace 22ipc-namespace
21net none 23net none
diff --git a/etc/soundconverter.profile b/etc/soundconverter.profile
index ee4d90265..69efe5244 100644
--- a/etc/soundconverter.profile
+++ b/etc/soundconverter.profile
@@ -21,6 +21,8 @@ include /etc/firejail/disable-passwdmgr.inc
21include /etc/firejail/disable-programs.inc 21include /etc/firejail/disable-programs.inc
22include /etc/firejail/disable-xdg.inc 22include /etc/firejail/disable-xdg.inc
23 23
24include /etc/firejail/whitelist-var-common.inc
25
24caps.drop all 26caps.drop all
25net none 27net none
26no3d 28no3d
diff --git a/etc/spectre-meltdown-checker.profile b/etc/spectre-meltdown-checker.profile
new file mode 100644
index 000000000..18d3a0575
--- /dev/null
+++ b/etc/spectre-meltdown-checker.profile
@@ -0,0 +1,53 @@
1# Firejail profile for spectre-meltdown-checker
2# This file is overwritten after every install/update
3quiet
4# Persistent local customizations
5include /etc/firejail/spectre-meltdown-checker.local
6# Persistent global definitions
7include /etc/firejail/globals.local
8
9# sudo firejail --allow-debuggers spectre-meltdown-checker
10
11noblacklist ${PATH}/mount
12noblacklist ${PATH}/umount
13
14# Allow access to perl
15noblacklist ${PATH}/cpan*
16noblacklist ${PATH}/core_perl
17noblacklist ${PATH}/perl
18noblacklist /usr/lib/perl*
19noblacklist /usr/share/perl*
20
21include /etc/firejail/disable-common.inc
22include /etc/firejail/disable-devel.inc
23include /etc/firejail/disable-interpreters.inc
24include /etc/firejail/disable-passwdmgr.inc
25include /etc/firejail/disable-programs.inc
26include /etc/firejail/disable-xdg.inc
27
28include /etc/firejail/whitelist-var-common.inc
29
30caps.keep sys_rawio
31ipc-namespace
32net none
33no3d
34nodbus
35nodvd
36nogroups
37nonewprivs
38nosound
39notv
40novideo
41protocol unix
42seccomp.drop @clock,@cpu-emulation,@module,@obsolete,@reboot,@resources,@swap
43shell none
44
45disable-mnt
46private
47private-bin awk,bzip2,cat,coreos-install,cpucontrol,cut,dd,dmesg,dnf,echo,grep,gunzip,gz,gzip,head,id,kldload,kldstat,liblz4-tool,lzop,mktemp,modinfo,modprobe,mount,nm,objdump,od,perl,printf,readelf,rm,sed,seq,sh,sort,spectre-meltdown-checker,spectre-meltdown-checker.sh,stat,strings,sysctl,tail,test,toolbox,tr,uname,which,xz-utils
48private-cache
49private-tmp
50
51memory-deny-write-execute
52noexec ${HOME}
53noexec /tmp
diff --git a/etc/sqlitebrowser.profile b/etc/sqlitebrowser.profile
index 75e8ed5c0..0f030d559 100644
--- a/etc/sqlitebrowser.profile
+++ b/etc/sqlitebrowser.profile
@@ -16,6 +16,8 @@ include /etc/firejail/disable-passwdmgr.inc
16include /etc/firejail/disable-programs.inc 16include /etc/firejail/disable-programs.inc
17include /etc/firejail/disable-xdg.inc 17include /etc/firejail/disable-xdg.inc
18 18
19include /etc/firejail/whitelist-var-common.inc
20
19caps.drop all 21caps.drop all
20net none 22net none
21no3d 23no3d
diff --git a/etc/start-tor-browser.desktop.profile b/etc/start-tor-browser.desktop.profile
new file mode 100644
index 000000000..c17815969
--- /dev/null
+++ b/etc/start-tor-browser.desktop.profile
@@ -0,0 +1,66 @@
1# Firejail profile alias for torbrowser-launcher
2# This file is overwritten after every install/update
3
4
5noblacklist ${HOME}/.tor-browser-ar:
6mkdir ${HOME}/.tor-browser-ar:
7whitelist ${HOME}/.tor-browser-ar:
8
9noblacklist ${HOME}/.tor-browser-en:
10mkdir ${HOME}/.tor-browser-en:
11whitelist ${HOME}/.tor-browser-en:
12
13noblacklist ${HOME}/.tor-browser-en-us:
14mkdir ${HOME}/.tor-browser-en-us:
15whitelist ${HOME}/.tor-browser-en-us:
16
17noblacklist ${HOME}/.tor-browser-es:
18mkdir ${HOME}/.tor-browser-es:
19whitelist ${HOME}/.tor-browser-es:
20
21noblacklist ${HOME}/.tor-browser-es-es:
22mkdir ${HOME}/.tor-browser-es-es:
23whitelist ${HOME}/.tor-browser-es-es:
24
25noblacklist ${HOME}/.tor-browser-fa:
26mkdir ${HOME}/.tor-browser-fa:
27whitelist ${HOME}/.tor-browser-fa:
28
29noblacklist ${HOME}/.tor-browser-fr:
30mkdir ${HOME}/.tor-browser-fr:
31whitelist ${HOME}/.tor-browser-fr:
32
33noblacklist ${HOME}/.tor-browser-it:
34mkdir ${HOME}/.tor-browser-it:
35whitelist ${HOME}/.tor-browser-it:
36
37noblacklist ${HOME}/.tor-browser-ja:
38mkdir ${HOME}/.tor-browser-ja:
39whitelist ${HOME}/.tor-browser-ja:
40
41noblacklist ${HOME}/.tor-browser-ko:
42mkdir ${HOME}/.tor-browser-ko:
43whitelist ${HOME}/.tor-browser-ko:
44
45noblacklist ${HOME}/.tor-browser-pl:
46mkdir ${HOME}/.tor-browser-pl:
47whitelist ${HOME}/.tor-browser-pl:
48
49noblacklist ${HOME}/.tor-browser-pt-br:
50mkdir ${HOME}/.tor-browser-pt-br:
51whitelist ${HOME}/.tor-browser-pt-br:
52
53noblacklist ${HOME}/.tor-browser-ru:
54mkdir ${HOME}/.tor-browser-ru:
55whitelist ${HOME}/.tor-browser-ru:
56
57noblacklist ${HOME}/.tor-browser-vi:
58mkdir ${HOME}/.tor-browser-vi:
59whitelist ${HOME}/.tor-browser-vi:
60
61noblacklist ${HOME}/.tor-browser-zh-cn:
62mkdir ${HOME}/.tor-browser-zh-cn:
63whitelist ${HOME}/.tor-browser-zh-cn:
64
65# Redirect
66include /etc/firejail/torbrowser-launcher.profile
diff --git a/etc/vlc.profile b/etc/vlc.profile
index 20dafba25..594a5944b 100644
--- a/etc/vlc.profile
+++ b/etc/vlc.profile
@@ -25,7 +25,7 @@ include /etc/firejail/whitelist-var-common.inc
25caps.drop all 25caps.drop all
26netfilter 26netfilter
27#nodbus 27#nodbus
28#nogroups 28nogroups
29nonewprivs 29nonewprivs
30noroot 30noroot
31protocol unix,inet,inet6,netlink 31protocol unix,inet,inet6,netlink
diff --git a/etc/xonotic.profile b/etc/xonotic.profile
index 29b2bb382..a7e8edc0f 100644
--- a/etc/xonotic.profile
+++ b/etc/xonotic.profile
@@ -21,6 +21,7 @@ include /etc/firejail/whitelist-var-common.inc
21 21
22caps.drop all 22caps.drop all
23netfilter 23netfilter
24nodbus
24nodvd 25nodvd
25nogroups 26nogroups
26nonewprivs 27nonewprivs