aboutsummaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
authorLibravatar valoq <valoq@mailbox.org>2016-12-01 12:09:19 +0100
committerLibravatar valoq <valoq@mailbox.org>2016-12-01 12:09:19 +0100
commitabc77414d8e1f864db6af55d46629f1e9f301f61 (patch)
treee02817be141457a3d2ef3d0c7053a71c32159f32 /etc
parentgajim fix (diff)
downloadfirejail-abc77414d8e1f864db6af55d46629f1e9f301f61.tar.gz
firejail-abc77414d8e1f864db6af55d46629f1e9f301f61.tar.zst
firejail-abc77414d8e1f864db6af55d46629f1e9f301f61.zip
blacklisted various program files
Diffstat (limited to 'etc')
-rw-r--r--etc/disable-common.inc1
-rw-r--r--etc/disable-passwdmgr.inc3
-rw-r--r--etc/disable-programs.inc34
-rw-r--r--etc/evince.profile2
-rw-r--r--etc/gnome-chess.profile2
5 files changed, 40 insertions, 2 deletions
diff --git a/etc/disable-common.inc b/etc/disable-common.inc
index bc2f6869d..8886a0bc3 100644
--- a/etc/disable-common.inc
+++ b/etc/disable-common.inc
@@ -194,6 +194,7 @@ blacklist ${PATH}/roxterm-config
194blacklist ${PATH}/terminix 194blacklist ${PATH}/terminix
195blacklist ${PATH}/urxvtc 195blacklist ${PATH}/urxvtc
196blacklist ${PATH}/urxvtcd 196blacklist ${PATH}/urxvtcd
197blacklist ${PATH}/konsole
197 198
198# kernel files 199# kernel files
199blacklist /vmlinuz* 200blacklist /vmlinuz*
diff --git a/etc/disable-passwdmgr.inc b/etc/disable-passwdmgr.inc
index 6db9073ab..045b4d92b 100644
--- a/etc/disable-passwdmgr.inc
+++ b/etc/disable-passwdmgr.inc
@@ -1,7 +1,10 @@
1blacklist ${HOME}/.pki/nssdb 1blacklist ${HOME}/.pki/nssdb
2blacklist ${HOME}/.lastpass 2blacklist ${HOME}/.lastpass
3blacklist ${HOME}/.keepassx 3blacklist ${HOME}/.keepassx
4blacklist ${HOME}/.keepass
4blacklist ${HOME}/.password-store 5blacklist ${HOME}/.password-store
5blacklist ${HOME}/keepassx.kdbx 6blacklist ${HOME}/keepassx.kdbx
6blacklist ${HOME}/.config/keepassx 7blacklist ${HOME}/.config/keepassx
8blacklist ${HOME}/.config/keepass
9blacklist ${HOME}/.config/KeePass
7 10
diff --git a/etc/disable-programs.inc b/etc/disable-programs.inc
index 76a4c4607..f87053b7c 100644
--- a/etc/disable-programs.inc
+++ b/etc/disable-programs.inc
@@ -44,7 +44,27 @@ blacklist ${HOME}/.openshot_qt
44blacklist ${HOME}/.flowblade 44blacklist ${HOME}/.flowblade
45blacklist ${HOME}/.config/flowblade 45blacklist ${HOME}/.config/flowblade
46blacklist ${HOME}/.config/eog 46blacklist ${HOME}/.config/eog
47 47blacklist ${HOME}/.config/arkrc
48blacklist ${HOME}/.config/atril
49blacklist ${HOME}/.config/aweather
50blacklist ${HOME}/.config/brasero
51blacklist ${HOME}/.config/enchant
52blacklist ${HOME}/.config/gedit
53blacklist ${HOME}/.config/Cryptocat
54blacklist ${HOME}/.config/dolphinrc
55blacklist ${HOME}/.config/katerc
56blacklist ${HOME}/.config/katepartrc
57blacklist ${HOME}/.config/kateschemarc
58blacklist ${HOME}/.config/katesyntaxhighlightingrc
59blacklist ${HOME}/.config/katevirc
60blacklist ${HOME}/.config/nautilus
61blacklist ${HOME}/.config/xfburn
62blacklist ${HOME}/.config/evince
63blacklist ${HOME}/.emacs
64blacklist ${HOME}/.emacs.d
65blacklist ${HOME}/.claws-mail
66blacklist ${HOME}/.config/ranger
67blacklist ${HOME}/.qemu-launcher
48 68
49# Media players 69# Media players
50blacklist ${HOME}/.config/cmus 70blacklist ${HOME}/.config/cmus
@@ -56,6 +76,7 @@ blacklist ${HOME}/.config/totem
56blacklist ${HOME}/.config/xplayer 76blacklist ${HOME}/.config/xplayer
57blacklist ${HOME}/.audacity-data 77blacklist ${HOME}/.audacity-data
58blacklist ${HOME}/.guayadeque 78blacklist ${HOME}/.guayadeque
79blacklist ${HOME}/.config/dragonplayerrc
59 80
60# HTTP / FTP / Mail 81# HTTP / FTP / Mail
61blacklist ${HOME}/.icedove 82blacklist ${HOME}/.icedove
@@ -88,6 +109,8 @@ blacklist ${HOME}/.msmtprc
88blacklist ${HOME}/.config/evolution 109blacklist ${HOME}/.config/evolution
89blacklist ${HOME}/.local/share/evolution 110blacklist ${HOME}/.local/share/evolution
90blacklist ${HOME}/.cache/evolution 111blacklist ${HOME}/.cache/evolution
112blacklist ${HOME}/.elinks
113blacklist ${HOME}/.w3m
91 114
92# Instant Messaging 115# Instant Messaging
93blacklist ${HOME}/.config/hexchat 116blacklist ${HOME}/.config/hexchat
@@ -110,6 +133,7 @@ blacklist ${HOME}/.cache/gajim
110blacklist ${HOME}/.local/share/gajim 133blacklist ${HOME}/.local/share/gajim
111blacklist ${HOME}/.config/gajim 134blacklist ${HOME}/.config/gajim
112blacklist ${HOME}/.config/Wire 135blacklist ${HOME}/.config/Wire
136blacklist ${HOME}/.config/wire
113blacklist ${HOME}/.config/Cryptocat 137blacklist ${HOME}/.config/Cryptocat
114 138
115# Games 139# Games
@@ -119,6 +143,7 @@ blacklist ${HOME}/.config/wesnoth
119blacklist ${HOME}/.config/0ad 143blacklist ${HOME}/.config/0ad
120blacklist ${HOME}/.warzone2100-3.1 144blacklist ${HOME}/.warzone2100-3.1
121blacklist ${HOME}/.dosbox 145blacklist ${HOME}/.dosbox
146blacklist ${HOME}/.local/share/gnome-chess
122 147
123# Cryptocoins 148# Cryptocoins
124blacklist ${HOME}/.*coin 149blacklist ${HOME}/.*coin
@@ -151,6 +176,9 @@ blacklist ${HOME}/.cache/0ad
151blacklist ${HOME}/.cache/8pecxstudios 176blacklist ${HOME}/.cache/8pecxstudios
152blacklist ${HOME}/.cache/xreader 177blacklist ${HOME}/.cache/xreader
153blacklist ${HOME}/.cache/Franz 178blacklist ${HOME}/.cache/Franz
179blacklist ${HOME}/.cache/simple-scan
180blacklist ${HOME}/.cache/libgweather
181blacklist ${HOME}/.cache/org.gnome.Books
154 182
155# share 183# share
156blacklist ${HOME}/.local/share/epiphany 184blacklist ${HOME}/.local/share/epiphany
@@ -166,6 +194,10 @@ blacklist ${HOME}/.local/share/pix
166blacklist ${HOME}/.local/share/gnome-chess 194blacklist ${HOME}/.local/share/gnome-chess
167blacklist ${HOME}/.local/share/qpdfview 195blacklist ${HOME}/.local/share/qpdfview
168blacklist ${HOME}/.local/share/zathura 196blacklist ${HOME}/.local/share/zathura
197blacklist ${HOME}/.local/share/gnome-music
198blacklist ${HOME}/.local/share/gnome-photos
199blacklist ${HOME}/.local/share/kate
200blacklist ${HOME}/.local/share/dolphin
169 201
170# ssh 202# ssh
171blacklist /tmp/ssh-* 203blacklist /tmp/ssh-*
diff --git a/etc/evince.profile b/etc/evince.profile
index 12ea358be..1ec384947 100644
--- a/etc/evince.profile
+++ b/etc/evince.profile
@@ -1,4 +1,6 @@
1# evince pdf reader profile 1# evince pdf reader profile
2noblacklist ~/.config/evince
3
2include /etc/firejail/disable-common.inc 4include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 5include /etc/firejail/disable-programs.inc
4include /etc/firejail/disable-devel.inc 6include /etc/firejail/disable-devel.inc
diff --git a/etc/gnome-chess.profile b/etc/gnome-chess.profile
index 297f7e6a9..4db485ea7 100644
--- a/etc/gnome-chess.profile
+++ b/etc/gnome-chess.profile
@@ -1,5 +1,5 @@
1# Firejail profile for gnome-chess 1# Firejail profile for gnome-chess
2noblacklist /.local/share/gnome-chess 2noblacklist ~/.local/share/gnome-chess
3 3
4include /etc/firejail/disable-common.inc 4include /etc/firejail/disable-common.inc
5include /etc/firejail/disable-devel.inc 5include /etc/firejail/disable-devel.inc