aboutsummaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
authorLibravatar netblue30 <netblue30@protonmail.com>2021-11-13 12:19:09 +0000
committerLibravatar GitHub <noreply@github.com>2021-11-13 12:19:09 +0000
commit92307735bd07ad3d677429aa04795209204102ec (patch)
treee908ed688db35e0cdade9c5fd4cb5add48d7ddf7 /etc
parentMerge pull request #4679 from pirate486743186/patch-3 (diff)
parentimplement review suggestions (diff)
downloadfirejail-92307735bd07ad3d677429aa04795209204102ec.tar.gz
firejail-92307735bd07ad3d677429aa04795209204102ec.tar.zst
firejail-92307735bd07ad3d677429aa04795209204102ec.zip
Merge pull request #4681 from jmetrius/openstego-profile
Add OpenStego profile
Diffstat (limited to 'etc')
-rw-r--r--etc/inc/disable-programs.inc1
-rw-r--r--etc/profile-m-z/openstego.profile58
2 files changed, 59 insertions, 0 deletions
diff --git a/etc/inc/disable-programs.inc b/etc/inc/disable-programs.inc
index e78f15e10..254d05e8e 100644
--- a/etc/inc/disable-programs.inc
+++ b/etc/inc/disable-programs.inc
@@ -1120,6 +1120,7 @@ blacklist ${HOME}/TeamSpeak3-Client-linux_x86
1120blacklist ${HOME}/hyperrogue.ini 1120blacklist ${HOME}/hyperrogue.ini
1121blacklist ${HOME}/i2p 1121blacklist ${HOME}/i2p
1122blacklist ${HOME}/mps 1122blacklist ${HOME}/mps
1123blacklist ${HOME}/openstego.ini
1123blacklist ${HOME}/wallet.dat 1124blacklist ${HOME}/wallet.dat
1124blacklist ${HOME}/yt-dlp.conf 1125blacklist ${HOME}/yt-dlp.conf
1125blacklist ${RUNUSER}/*firefox* 1126blacklist ${RUNUSER}/*firefox*
diff --git a/etc/profile-m-z/openstego.profile b/etc/profile-m-z/openstego.profile
new file mode 100644
index 000000000..f6622b38d
--- /dev/null
+++ b/etc/profile-m-z/openstego.profile
@@ -0,0 +1,58 @@
1# Firejail profile for OpenStego
2# Description: Steganography application that provides data hiding and watermarking functionality
3# This file is overwritten after every install/update
4# Persistent local customizations
5include openstego.local
6# Persistent global definitions
7include globals.local
8
9noblacklist ${HOME}/openstego.ini
10
11# Allow java (blacklisted by disable-devel.inc)
12include allow-java.inc
13
14include disable-common.inc
15include disable-devel.inc
16include disable-exec.inc
17include disable-interpreters.inc
18include disable-proc.inc
19include disable-programs.inc
20
21mkfile ${HOME}/openstego.ini
22whitelist ${HOME}/openstego.ini
23whitelist ${HOME}/.java
24whitelist ${PICTURES}
25whitelist ${DOCUMENTS}
26whitelist ${DESKTOP}
27whitelist /usr/share/java
28include whitelist-common.inc
29include whitelist-run-common.inc
30include whitelist-runuser-common.inc
31include whitelist-usr-share-common.inc
32include whitelist-var-common.inc
33
34caps.drop all
35machine-id
36net none
37no3d
38nogroups
39noinput
40nonewprivs
41noroot
42nosound
43notv
44nou2f
45novideo
46seccomp
47seccomp.block-secondary
48shell none
49tracelog
50
51disable-mnt
52private-bin bash,dirname,openstego,readlink,sh
53private-cache
54private-dev
55private-tmp
56
57dbus-user none
58dbus-system none