aboutsummaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
authorLibravatar netblue30 <netblue30@yahoo.com>2017-07-29 07:52:17 -0400
committerLibravatar netblue30 <netblue30@yahoo.com>2017-07-29 07:52:17 -0400
commit348b875f3025988a336e365a3127f6d6b25bec18 (patch)
tree112a1247f397348633a4a95b247d030df0255446 /etc
parentarp rework (diff)
downloadfirejail-348b875f3025988a336e365a3127f6d6b25bec18.tar.gz
firejail-348b875f3025988a336e365a3127f6d6b25bec18.tar.zst
firejail-348b875f3025988a336e365a3127f6d6b25bec18.zip
new profiles
Diffstat (limited to 'etc')
-rw-r--r--etc/disable-programs.inc8
-rw-r--r--etc/etr.profile41
-rw-r--r--etc/frozen-bubble.profile38
-rw-r--r--etc/open-invaders.profile41
-rw-r--r--etc/pingus.profile41
-rw-r--r--etc/simutrans.profile41
-rw-r--r--etc/supertux2.profile41
-rw-r--r--etc/unknown-horizons.profile40
8 files changed, 291 insertions, 0 deletions
diff --git a/etc/disable-programs.inc b/etc/disable-programs.inc
index 0a4d4c4cb..95d9b04a0 100644
--- a/etc/disable-programs.inc
+++ b/etc/disable-programs.inc
@@ -186,9 +186,12 @@ blacklist ${HOME}/.elinks
186blacklist ${HOME}/.emacs 186blacklist ${HOME}/.emacs
187blacklist ${HOME}/.emacs.d 187blacklist ${HOME}/.emacs.d
188blacklist ${HOME}/.filezilla 188blacklist ${HOME}/.filezilla
189blacklist ${HOME}/.emacs
190blacklist ${HOME}/.etr
189blacklist ${HOME}/.flowblade 191blacklist ${HOME}/.flowblade
190blacklist ${HOME}/.fltk 192blacklist ${HOME}/.fltk
191blacklist ${HOME}/.FontForge 193blacklist ${HOME}/.FontForge
194blacklist ${HOME}/.frozen-bubble
192blacklist ${HOME}/.gimp* 195blacklist ${HOME}/.gimp*
193blacklist ${HOME}/.git-credential-cache 196blacklist ${HOME}/.git-credential-cache
194blacklist ${HOME}/.gitconfig 197blacklist ${HOME}/.gitconfig
@@ -301,6 +304,7 @@ blacklist ${HOME}/.local/share/qpdfview
301blacklist ${HOME}/.local/share/scribus 304blacklist ${HOME}/.local/share/scribus
302blacklist ${HOME}/.local/share/spotify 305blacklist ${HOME}/.local/share/spotify
303blacklist ${HOME}/.local/share/steam 306blacklist ${HOME}/.local/share/steam
307blacklist ${HOME}/.local/share/supertux2
304blacklist ${HOME}/.local/share/telepathy 308blacklist ${HOME}/.local/share/telepathy
305blacklist ${HOME}/.local/share/torbrowser 309blacklist ${HOME}/.local/share/torbrowser
306blacklist ${HOME}/.local/share/totem 310blacklist ${HOME}/.local/share/totem
@@ -325,16 +329,19 @@ blacklist ${HOME}/.mutt/muttrc
325blacklist ${HOME}/.muttrc 329blacklist ${HOME}/.muttrc
326blacklist ${HOME}/.nv 330blacklist ${HOME}/.nv
327blacklist ${HOME}/.nylas-mail 331blacklist ${HOME}/.nylas-mail
332blacklist ${HOME}/.openinvaders
328blacklist ${HOME}/.openshot 333blacklist ${HOME}/.openshot
329blacklist ${HOME}/.openshot_qt 334blacklist ${HOME}/.openshot_qt
330blacklist ${HOME}/.opera 335blacklist ${HOME}/.opera
331blacklist ${HOME}/.opera-beta 336blacklist ${HOME}/.opera-beta
337blacklist ${HOME}/.pingus
332blacklist ${HOME}/.purple 338blacklist ${HOME}/.purple
333blacklist ${HOME}/.qemu-launcher 339blacklist ${HOME}/.qemu-launcher
334blacklist ${HOME}/.remmina 340blacklist ${HOME}/.remmina
335blacklist ${HOME}/.retroshare 341blacklist ${HOME}/.retroshare
336blacklist ${HOME}/.scribus 342blacklist ${HOME}/.scribus
337blacklist ${HOME}/.scribusrc 343blacklist ${HOME}/.scribusrc
344blacklist ${HOME}/.simutrans
338blacklist ${HOME}/.steam 345blacklist ${HOME}/.steam
339blacklist ${HOME}/.steampath 346blacklist ${HOME}/.steampath
340blacklist ${HOME}/.steampid 347blacklist ${HOME}/.steampid
@@ -347,6 +354,7 @@ blacklist ${HOME}/.tconn
347blacklist ${HOME}/.thunderbird 354blacklist ${HOME}/.thunderbird
348blacklist ${HOME}/.tooling 355blacklist ${HOME}/.tooling
349blacklist ${HOME}/.ts3client 356blacklist ${HOME}/.ts3client
357blacklist ${HOME}/.unknow-horizons
350blacklist ${HOME}/.viking 358blacklist ${HOME}/.viking
351blacklist ${HOME}/.viking-maps 359blacklist ${HOME}/.viking-maps
352blacklist ${HOME}/.vst 360blacklist ${HOME}/.vst
diff --git a/etc/etr.profile b/etc/etr.profile
new file mode 100644
index 000000000..d7b747995
--- /dev/null
+++ b/etc/etr.profile
@@ -0,0 +1,41 @@
1# Persistent global definitions go here
2include /etc/firejail/globals.local
3
4# This file is overwritten during software install.
5# Persistent customizations should go in a .local file.
6include /etc/firejail/etr.local
7
8################################
9# Extreme Tux Racer profile
10################################
11
12noblacklist ~/.etr
13mkdir ~/.etr
14whitelist ~/.etr
15include /etc/firejail/whitelist-common.inc
16
17include /etc/firejail/disable-common.inc
18include /etc/firejail/disable-programs.inc
19include /etc/firejail/disable-passwdmgr.inc
20
21caps.drop all
22nonewprivs
23noroot
24protocol unix,netlink
25seccomp
26
27#
28# depending on your usage, you can enable some of the commands below:
29#
30net none
31nogroups
32shell none
33#private-bin etr
34# private-etc none
35private-dev
36private-tmp
37# nosound
38
39
40
41
diff --git a/etc/frozen-bubble.profile b/etc/frozen-bubble.profile
new file mode 100644
index 000000000..52f8e5b3e
--- /dev/null
+++ b/etc/frozen-bubble.profile
@@ -0,0 +1,38 @@
1# Persistent global definitions go here
2include /etc/firejail/globals.local
3
4# This file is overwritten during software install.
5# Persistent customizations should go in a .local file.
6include /etc/firejail/frozen-bubble.local
7
8################################
9# Frozen Bubble profile
10################################
11
12noblacklist ~/.frozen-bubble
13mkdir ~/.frozen-bubble
14whitelist ~/.frozen-bubble
15include /etc/firejail/whitelist-common.inc
16
17include /etc/firejail/disable-common.inc
18include /etc/firejail/disable-programs.inc
19include /etc/firejail/disable-passwdmgr.inc
20
21caps.drop all
22nonewprivs
23noroot
24protocol unix,netlink
25seccomp
26
27#
28# depending on your usage, you can enable some of the commands below:
29#
30net none
31nogroups
32shell none
33#private-bin frozen-bubble
34# private-etc none
35private-dev
36private-tmp
37# nosound
38
diff --git a/etc/open-invaders.profile b/etc/open-invaders.profile
new file mode 100644
index 000000000..f95b0f5a2
--- /dev/null
+++ b/etc/open-invaders.profile
@@ -0,0 +1,41 @@
1# Persistent global definitions go here
2include /etc/firejail/globals.local
3
4# This file is overwritten during software install.
5# Persistent customizations should go in a .local file.
6include /etc/firejail/open-invaders.local
7
8################################
9# open-invaders profile
10################################
11
12noblacklist ~/.openinvaders
13mkdir ~/.openinvaders
14whitelist ~/.openinvaders
15include /etc/firejail/whitelist-common.inc
16
17include /etc/firejail/disable-common.inc
18include /etc/firejail/disable-programs.inc
19include /etc/firejail/disable-passwdmgr.inc
20
21caps.drop all
22nonewprivs
23noroot
24protocol unix,netlink
25seccomp
26
27#
28# depending on your usage, you can enable some of the commands below:
29#
30net none
31nogroups
32shell none
33#private-bin open-invaders
34# private-etc none
35private-dev
36private-tmp
37# nosound
38
39
40
41
diff --git a/etc/pingus.profile b/etc/pingus.profile
new file mode 100644
index 000000000..b3b479046
--- /dev/null
+++ b/etc/pingus.profile
@@ -0,0 +1,41 @@
1# Persistent global definitions go here
2include /etc/firejail/globals.local
3
4# This file is overwritten during software install.
5# Persistent customizations should go in a .local file.
6include /etc/firejail/pingus.local
7
8################################
9# Pinugs profile
10################################
11
12noblacklist ~/.pingus
13mkdir ~/.pingus
14whitelist ~/.pingus
15include /etc/firejail/whitelist-common.inc
16
17include /etc/firejail/disable-common.inc
18include /etc/firejail/disable-programs.inc
19include /etc/firejail/disable-passwdmgr.inc
20
21caps.drop all
22nonewprivs
23noroot
24protocol unix,netlink
25seccomp
26
27#
28# depending on your usage, you can enable some of the commands below:
29#
30net none
31nogroups
32shell none
33#private-bin pingus
34# private-etc none
35private-dev
36private-tmp
37# nosound
38
39
40
41
diff --git a/etc/simutrans.profile b/etc/simutrans.profile
new file mode 100644
index 000000000..b1df0ba28
--- /dev/null
+++ b/etc/simutrans.profile
@@ -0,0 +1,41 @@
1# Persistent global definitions go here
2include /etc/firejail/globals.local
3
4# This file is overwritten during software install.
5# Persistent customizations should go in a .local file.
6include /etc/firejail/simutrans.local
7
8################################
9# simutrans profile
10################################
11
12noblacklist ~/.simutrans
13mkdir ~/.simutrans
14whitelist ~/.simutrans
15include /etc/firejail/whitelist-common.inc
16
17include /etc/firejail/disable-common.inc
18include /etc/firejail/disable-programs.inc
19include /etc/firejail/disable-passwdmgr.inc
20
21caps.drop all
22nonewprivs
23noroot
24protocol unix
25seccomp
26
27#
28# depending on your usage, you can enable some of the commands below:
29#
30net none
31nogroups
32shell none
33#private-bin simutrans
34# private-etc none
35private-dev
36private-tmp
37# nosound
38
39
40
41
diff --git a/etc/supertux2.profile b/etc/supertux2.profile
new file mode 100644
index 000000000..276e91b05
--- /dev/null
+++ b/etc/supertux2.profile
@@ -0,0 +1,41 @@
1# Persistent global definitions go here
2include /etc/firejail/globals.local
3
4# This file is overwritten during software install.
5# Persistent customizations should go in a .local file.
6include /etc/firejail/supertux2.local
7
8################################
9# SuperTux profile
10################################
11
12noblacklist ~/.local/share/supertux2
13mkdir ~/.local/share/supertux2
14whitelist ~/.local/share/supertux2
15include /etc/firejail/whitelist-common.inc
16
17include /etc/firejail/disable-common.inc
18include /etc/firejail/disable-programs.inc
19include /etc/firejail/disable-passwdmgr.inc
20
21caps.drop all
22nonewprivs
23noroot
24protocol unix,netlink
25seccomp
26
27#
28# depending on your usage, you can enable some of the commands below:
29#
30net none
31nogroups
32shell none
33#private-bin supertux2
34# private-etc none
35private-dev
36private-tmp
37# nosound
38
39
40
41
diff --git a/etc/unknown-horizons.profile b/etc/unknown-horizons.profile
new file mode 100644
index 000000000..c4e535070
--- /dev/null
+++ b/etc/unknown-horizons.profile
@@ -0,0 +1,40 @@
1# Persistent global definitions go here
2include /etc/firejail/globals.local
3
4# This file is overwritten during software install.
5# Persistent customizations should go in a .local file.
6include /etc/firejail/unknown-horizons.local
7
8################################
9# Extreme Tux Racer profile
10################################
11
12noblacklist ~/.unknown-horizons
13mkdir ~/.unknown-horizons
14whitelist ~/.unknown-horizons
15include /etc/firejail/whitelist-common.inc
16
17include /etc/firejail/disable-common.inc
18include /etc/firejail/disable-programs.inc
19include /etc/firejail/disable-passwdmgr.inc
20
21caps.drop all
22nonewprivs
23noroot
24protocol unix,netlink,inet,inet6
25seccomp
26
27#
28# depending on your usage, you can enable some of the commands below:
29#
30nogroups
31shell none
32#private-bin unknown-horizons
33# private-etc none
34private-dev
35private-tmp
36# nosound
37
38
39
40