aboutsummaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
authorLibravatar Fred-Barclay <Fred-Barclay@users.noreply.github.com>2016-10-23 23:23:09 -0500
committerLibravatar Fred-Barclay <Fred-Barclay@users.noreply.github.com>2016-10-24 15:33:54 -0500
commit88972056f4eb7919f41ca9412853725e80967240 (patch)
treed512e80df09c3b6e715099c3f44a6f7b939c197c /etc
parentappimage fixes (diff)
downloadfirejail-88972056f4eb7919f41ca9412853725e80967240.tar.gz
firejail-88972056f4eb7919f41ca9412853725e80967240.tar.zst
firejail-88972056f4eb7919f41ca9412853725e80967240.zip
squash attempt 2
Diffstat (limited to 'etc')
-rw-r--r--etc/atom-beta.profile2
-rw-r--r--etc/atom.profile2
-rw-r--r--etc/atril.profile2
-rw-r--r--etc/audacity.profile2
-rw-r--r--etc/aweather.profile2
-rw-r--r--etc/cherrytree.profile3
-rw-r--r--etc/eog.profile3
-rw-r--r--etc/evolution.profile2
-rw-r--r--etc/feh.profile6
-rw-r--r--etc/file.profile17
-rw-r--r--etc/filezilla.profile5
-rw-r--r--etc/flowblade.profile2
-rw-r--r--etc/franz.profile6
-rw-r--r--etc/gajim.profile2
-rw-r--r--etc/gimp.profile10
-rw-r--r--etc/git.profile4
-rw-r--r--etc/gpredict.profile2
-rw-r--r--etc/gwenview.profile5
-rw-r--r--etc/gzip.profile14
-rw-r--r--etc/inkscape.profile10
-rw-r--r--etc/jitsi.profile2
-rw-r--r--etc/kmail.profile2
-rw-r--r--etc/less.profile6
-rw-r--r--etc/luminance-hdr.profile14
-rw-r--r--etc/okular.profile5
-rw-r--r--etc/pidgin.profile2
-rw-r--r--etc/pix.profile3
-rw-r--r--etc/psi-plus.profile4
-rw-r--r--etc/qbittorrent.profile4
-rw-r--r--etc/qpdfview.profile2
-rw-r--r--etc/qtox.profile2
-rw-r--r--etc/quiterss.profile9
-rw-r--r--etc/ranger.profile3
-rw-r--r--etc/rhythmbox.profile2
-rw-r--r--etc/rtorrent.profile1
-rw-r--r--etc/server.profile11
-rw-r--r--etc/slack.profile29
-rw-r--r--etc/strings.profile9
-rw-r--r--etc/synfigstudio.profile6
-rw-r--r--etc/tar.profile14
-rw-r--r--etc/telegram.profile1
-rw-r--r--etc/transmission-gtk.profile2
-rw-r--r--etc/transmission-qt.profile5
-rw-r--r--etc/uget-gtk.profile13
-rw-r--r--etc/unrar.profile15
-rw-r--r--etc/unzip.profile16
-rw-r--r--etc/uudeview.profile14
-rw-r--r--etc/vim.profile3
-rw-r--r--etc/xpdf.profile9
-rw-r--r--etc/xplayer.profile2
-rw-r--r--etc/xzdec.profile14
-rw-r--r--etc/zathura.profile6
52 files changed, 171 insertions, 160 deletions
diff --git a/etc/atom-beta.profile b/etc/atom-beta.profile
index 9a8d93875..fa0b316bb 100644
--- a/etc/atom-beta.profile
+++ b/etc/atom-beta.profile
@@ -8,8 +8,8 @@ include /etc/firejail/disable-passwdmgr.inc
8 8
9caps.drop all 9caps.drop all
10netfilter 10netfilter
11nonewprivs
12nogroups 11nogroups
12nonewprivs
13noroot 13noroot
14nosound 14nosound
15protocol unix,inet,inet6,netlink 15protocol unix,inet,inet6,netlink
diff --git a/etc/atom.profile b/etc/atom.profile
index 3cb86847e..61930d5c1 100644
--- a/etc/atom.profile
+++ b/etc/atom.profile
@@ -8,8 +8,8 @@ include /etc/firejail/disable-passwdmgr.inc
8 8
9caps.drop all 9caps.drop all
10netfilter 10netfilter
11nonewprivs
12nogroups 11nogroups
12nonewprivs
13noroot 13noroot
14nosound 14nosound
15protocol unix,inet,inet6,netlink 15protocol unix,inet,inet6,netlink
diff --git a/etc/atril.profile b/etc/atril.profile
index d9e10b072..fbcca0c1b 100644
--- a/etc/atril.profile
+++ b/etc/atril.profile
@@ -7,8 +7,8 @@ include /etc/firejail/disable-devel.inc
7include /etc/firejail/disable-passwdmgr.inc 7include /etc/firejail/disable-passwdmgr.inc
8 8
9caps.drop all 9caps.drop all
10nonewprivs
11nogroups 10nogroups
11nonewprivs
12noroot 12noroot
13nosound 13nosound
14protocol unix 14protocol unix
diff --git a/etc/audacity.profile b/etc/audacity.profile
index be3fac9be..827fa4301 100644
--- a/etc/audacity.profile
+++ b/etc/audacity.profile
@@ -8,8 +8,8 @@ include /etc/firejail/disable-programs.inc
8 8
9caps.drop all 9caps.drop all
10netfilter 10netfilter
11nonewprivs
12nogroups 11nogroups
12nonewprivs
13noroot 13noroot
14protocol unix 14protocol unix
15seccomp 15seccomp
diff --git a/etc/aweather.profile b/etc/aweather.profile
index 4e5c36f50..fa8654f1e 100644
--- a/etc/aweather.profile
+++ b/etc/aweather.profile
@@ -11,8 +11,8 @@ whitelist ~/.config/aweather
11 11
12caps.drop all 12caps.drop all
13netfilter 13netfilter
14nonewprivs
15nogroups 14nogroups
15nonewprivs
16noroot 16noroot
17nosound 17nosound
18protocol unix,inet,inet6 18protocol unix,inet,inet6
diff --git a/etc/cherrytree.profile b/etc/cherrytree.profile
index ec6d0d69d..139dec8ec 100644
--- a/etc/cherrytree.profile
+++ b/etc/cherrytree.profile
@@ -9,11 +9,10 @@ include /etc/firejail/disable-passwdmgr.inc
9 9
10caps.drop all 10caps.drop all
11netfilter 11netfilter
12nogroups
12nonewprivs 13nonewprivs
13noroot 14noroot
14nosound 15nosound
15seccomp 16seccomp
16protocol unix,inet,inet6,netlink 17protocol unix,inet,inet6,netlink
17tracelog 18tracelog
18
19
diff --git a/etc/eog.profile b/etc/eog.profile
index 32b54a042..7eb7fd127 100644
--- a/etc/eog.profile
+++ b/etc/eog.profile
@@ -9,9 +9,9 @@ include /etc/firejail/disable-passwdmgr.inc
9 9
10caps.drop all 10caps.drop all
11netfilter 11netfilter
12nogroups
12nonewprivs 13nonewprivs
13noroot 14noroot
14nogroups
15protocol unix 15protocol unix
16seccomp 16seccomp
17shell none 17shell none
@@ -20,4 +20,3 @@ private-bin eog
20private-dev 20private-dev
21private-etc fonts 21private-etc fonts
22private-tmp 22private-tmp
23
diff --git a/etc/evolution.profile b/etc/evolution.profile
index cf581643d..d097c0f34 100644
--- a/etc/evolution.profile
+++ b/etc/evolution.profile
@@ -14,9 +14,9 @@ include /etc/firejail/disable-passwdmgr.inc
14 14
15caps.drop all 15caps.drop all
16netfilter 16netfilter
17nogroups
17nonewprivs 18nonewprivs
18noroot 19noroot
19nogroups
20protocol unix,inet,inet6 20protocol unix,inet,inet6
21seccomp 21seccomp
22shell none 22shell none
diff --git a/etc/feh.profile b/etc/feh.profile
index 5fcb6bf25..e3b1ec528 100644
--- a/etc/feh.profile
+++ b/etc/feh.profile
@@ -5,14 +5,14 @@ include /etc/firejail/disable-devel.inc
5include /etc/firejail/disable-passwdmgr.inc 5include /etc/firejail/disable-passwdmgr.inc
6 6
7caps.drop all 7caps.drop all
8seccomp
9protocol unix
10netfilter 8netfilter
11net none 9net none
10nogroups
12nonewprivs 11nonewprivs
13noroot 12noroot
14nogroups
15nosound 13nosound
14protocol unix
15seccomp
16shell none 16shell none
17 17
18private-bin feh 18private-bin feh
diff --git a/etc/file.profile b/etc/file.profile
index 2e54030b1..199a97fad 100644
--- a/etc/file.profile
+++ b/etc/file.profile
@@ -1,16 +1,17 @@
1# file profile 1# file profile
2quiet
3ignore noroot 2ignore noroot
4include /etc/firejail/default.profile 3include /etc/firejail/default.profile
5 4
6tracelog 5blacklist /tmp/.X11-unix
6
7hostname file
7net none 8net none
9no3d
10nosound
11quiet
8shell none 12shell none
13tracelog
14
15private-dev
9private-bin file 16private-bin file
10private-etc magic.mgc,magic,localtime 17private-etc magic.mgc,magic,localtime
11hostname file
12private-dev
13nosound
14no3d
15blacklist /tmp/.X11-unix
16
diff --git a/etc/filezilla.profile b/etc/filezilla.profile
index 551c17a78..fe1d9d20d 100644
--- a/etc/filezilla.profile
+++ b/etc/filezilla.profile
@@ -13,10 +13,9 @@ noroot
13nosound 13nosound
14protocol unix,inet,inet6 14protocol unix,inet,inet6
15seccomp 15seccomp
16
17shell none 16shell none
17
18private-bin filezilla,uname,sh,python,lsb_release,fzputtygen,fzsftp 18private-bin filezilla,uname,sh,python,lsb_release,fzputtygen,fzsftp
19whitelist /tmp/.X11-unix
20private-dev 19private-dev
21nosound
22 20
21whitelist /tmp/.X11-unix
diff --git a/etc/flowblade.profile b/etc/flowblade.profile
index e1ec291bd..12afdb0aa 100644
--- a/etc/flowblade.profile
+++ b/etc/flowblade.profile
@@ -1,4 +1,4 @@
1# OpenShot profile 1# FlowBlade profile
2noblacklist ${HOME}/.flowblade 2noblacklist ${HOME}/.flowblade
3noblacklist ${HOME}/.config/flowblade 3noblacklist ${HOME}/.config/flowblade
4include /etc/firejail/disable-common.inc 4include /etc/firejail/disable-common.inc
diff --git a/etc/franz.profile b/etc/franz.profile
index 3cb7942ab..0b3be551b 100644
--- a/etc/franz.profile
+++ b/etc/franz.profile
@@ -6,12 +6,12 @@ include /etc/firejail/disable-programs.inc
6include /etc/firejail/disable-devel.inc 6include /etc/firejail/disable-devel.inc
7 7
8caps.drop all 8caps.drop all
9seccomp
10protocol unix,inet,inet6,netlink
11netfilter 9netfilter
12#tracelog
13nonewprivs 10nonewprivs
14noroot 11noroot
12protocol unix,inet,inet6,netlink
13seccomp
14#tracelog
15 15
16whitelist ${DOWNLOADS} 16whitelist ${DOWNLOADS}
17mkdir ~/.config/Franz 17mkdir ~/.config/Franz
diff --git a/etc/gajim.profile b/etc/gajim.profile
index 04902a734..809378ef9 100644
--- a/etc/gajim.profile
+++ b/etc/gajim.profile
@@ -22,8 +22,8 @@ include /etc/firejail/disable-devel.inc
22 22
23caps.drop all 23caps.drop all
24netfilter 24netfilter
25nonewprivs
26nogroups 25nogroups
26nonewprivs
27noroot 27noroot
28protocol unix,inet,inet6 28protocol unix,inet,inet6
29seccomp 29seccomp
diff --git a/etc/gimp.profile b/etc/gimp.profile
index 23361b771..cb441fc9d 100644
--- a/etc/gimp.profile
+++ b/etc/gimp.profile
@@ -6,13 +6,15 @@ include /etc/firejail/disable-passwdmgr.inc
6 6
7caps.drop all 7caps.drop all
8netfilter 8netfilter
9nogroups
9nonewprivs 10nonewprivs
10noroot 11noroot
12nosound
11protocol unix 13protocol unix
12seccomp 14seccomp
13private-dev 15
14private-tmp
15noexec ${HOME} 16noexec ${HOME}
16noexec /tmp 17noexec /tmp
17nogroups 18
18nosound 19private-dev
20private-tmp
diff --git a/etc/git.profile b/etc/git.profile
index 2fb55377d..73122d347 100644
--- a/etc/git.profile
+++ b/etc/git.profile
@@ -12,15 +12,15 @@ include /etc/firejail/disable-common.inc
12include /etc/firejail/disable-programs.inc 12include /etc/firejail/disable-programs.inc
13include /etc/firejail/disable-passwdmgr.inc 13include /etc/firejail/disable-passwdmgr.inc
14 14
15quiet
16 15
17caps.drop all 16caps.drop all
18netfilter 17netfilter
18nogroups
19nonewprivs 19nonewprivs
20noroot 20noroot
21nogroups
22nosound 21nosound
23protocol unix,inet,inet6 22protocol unix,inet,inet6
23quiet
24seccomp 24seccomp
25shell none 25shell none
26 26
diff --git a/etc/gpredict.profile b/etc/gpredict.profile
index 353ecceae..0cc6c416b 100644
--- a/etc/gpredict.profile
+++ b/etc/gpredict.profile
@@ -11,8 +11,8 @@ whitelist ~/.config/Gpredict
11 11
12caps.drop all 12caps.drop all
13netfilter 13netfilter
14nonewprivs
15nogroups 14nogroups
15nonewprivs
16noroot 16noroot
17nosound 17nosound
18protocol unix,inet,inet6 18protocol unix,inet,inet6
diff --git a/etc/gwenview.profile b/etc/gwenview.profile
index 67f10c4e1..c866c9e63 100644
--- a/etc/gwenview.profile
+++ b/etc/gwenview.profile
@@ -7,14 +7,15 @@ include /etc/firejail/disable-devel.inc
7include /etc/firejail/disable-passwdmgr.inc 7include /etc/firejail/disable-passwdmgr.inc
8 8
9caps.drop all 9caps.drop all
10nogroups
10nonewprivs 11nonewprivs
11noroot 12noroot
12nogroups
13private-dev
14protocol unix 13protocol unix
15seccomp 14seccomp
16nosound 15nosound
17 16
17private-dev
18
18#Experimental: 19#Experimental:
19#shell none 20#shell none
20#private-bin gwenview 21#private-bin gwenview
diff --git a/etc/gzip.profile b/etc/gzip.profile
index 5e73969c4..d51b9a951 100644
--- a/etc/gzip.profile
+++ b/etc/gzip.profile
@@ -1,12 +1,14 @@
1# gzip profile 1# gzip profile
2quiet
3ignore noroot 2ignore noroot
4include /etc/firejail/default.profile 3include /etc/firejail/default.profile
5tracelog 4
6net none
7shell none
8blacklist /tmp/.X11-unix 5blacklist /tmp/.X11-unix
9private-dev 6
10nosound 7net none
11no3d 8no3d
9nosound
10quiet
11shell none
12tracelog
12 13
14private-dev
diff --git a/etc/inkscape.profile b/etc/inkscape.profile
index cf885fba2..a0e86b6c9 100644
--- a/etc/inkscape.profile
+++ b/etc/inkscape.profile
@@ -6,13 +6,15 @@ include /etc/firejail/disable-passwdmgr.inc
6 6
7caps.drop all 7caps.drop all
8netfilter 8netfilter
9nogroups
9nonewprivs 10nonewprivs
10noroot 11noroot
12nosound
11protocol unix 13protocol unix
12seccomp 14seccomp
13private-dev 15
14private-tmp
15noexec ${HOME} 16noexec ${HOME}
16noexec /tmp 17noexec /tmp
17nogroups 18
18nosound 19private-dev
20private-tmp
diff --git a/etc/jitsi.profile b/etc/jitsi.profile
index c61158f8b..046499abe 100644
--- a/etc/jitsi.profile
+++ b/etc/jitsi.profile
@@ -6,8 +6,8 @@ include /etc/firejail/disable-passwdmgr.inc
6include /etc/firejail/disable-programs.inc 6include /etc/firejail/disable-programs.inc
7 7
8caps.drop all 8caps.drop all
9nonewprivs
10nogroups 9nogroups
10nonewprivs
11noroot 11noroot
12protocol unix,inet,inet6 12protocol unix,inet,inet6
13seccomp 13seccomp
diff --git a/etc/kmail.profile b/etc/kmail.profile
index 8c8fd18c4..bc21ba604 100644
--- a/etc/kmail.profile
+++ b/etc/kmail.profile
@@ -8,8 +8,8 @@ include /etc/firejail/disable-passwdmgr.inc
8 8
9caps.drop all 9caps.drop all
10netfilter 10netfilter
11nonewprivs
12nogroups 11nogroups
12nonewprivs
13noroot 13noroot
14protocol unix,inet,inet6,netlink 14protocol unix,inet,inet6,netlink
15seccomp 15seccomp
diff --git a/etc/less.profile b/etc/less.profile
index 6dfae027e..08758aead 100644
--- a/etc/less.profile
+++ b/etc/less.profile
@@ -2,8 +2,10 @@
2quiet 2quiet
3ignore noroot 3ignore noroot
4include /etc/firejail/default.profile 4include /etc/firejail/default.profile
5tracelog 5
6net none 6net none
7nosound
7shell none 8shell none
9tracelog
10
8private-dev 11private-dev
9nosound
diff --git a/etc/luminance-hdr.profile b/etc/luminance-hdr.profile
index 6e059ea52..76e864e0c 100644
--- a/etc/luminance-hdr.profile
+++ b/etc/luminance-hdr.profile
@@ -5,17 +5,19 @@ include /etc/firejail/disable-programs.inc
5include /etc/firejail/disable-passwdmgr.inc 5include /etc/firejail/disable-passwdmgr.inc
6 6
7caps.drop all 7caps.drop all
8ipc-namespace
8netfilter 9netfilter
9protocol unix 10nogroups
10nonewprivs 11nonewprivs
11noroot 12noroot
13nosound
14protocol unix
12seccomp 15seccomp
13shell none 16shell none
14tracelog 17tracelog
15private-tmp 18
16private-dev
17noexec ${HOME} 19noexec ${HOME}
18noexec /tmp 20noexec /tmp
19nogroups 21
20nosound 22private-tmp
21ipc-namespace 23private-dev
diff --git a/etc/okular.profile b/etc/okular.profile
index df142ccfc..b43a5fbea 100644
--- a/etc/okular.profile
+++ b/etc/okular.profile
@@ -9,14 +9,15 @@ include /etc/firejail/disable-devel.inc
9include /etc/firejail/disable-passwdmgr.inc 9include /etc/firejail/disable-passwdmgr.inc
10 10
11caps.drop all 11caps.drop all
12nonewprivs
13nogroups 12nogroups
13nonewprivs
14noroot 14noroot
15private-dev
16protocol unix 15protocol unix
17seccomp 16seccomp
18nosound 17nosound
19 18
19private-dev
20
20#Experimental: 21#Experimental:
21#net none 22#net none
22#shell none 23#shell none
diff --git a/etc/pidgin.profile b/etc/pidgin.profile
index 47be2b6ea..850706145 100644
--- a/etc/pidgin.profile
+++ b/etc/pidgin.profile
@@ -8,8 +8,8 @@ include /etc/firejail/disable-programs.inc
8 8
9caps.drop all 9caps.drop all
10netfilter 10netfilter
11nonewprivs
12nogroups 11nogroups
12nonewprivs
13noroot 13noroot
14protocol unix,inet,inet6 14protocol unix,inet,inet6
15seccomp 15seccomp
diff --git a/etc/pix.profile b/etc/pix.profile
index 80c05fd09..e21ddadc6 100644
--- a/etc/pix.profile
+++ b/etc/pix.profile
@@ -8,8 +8,8 @@ include /etc/firejail/disable-devel.inc
8include /etc/firejail/disable-passwdmgr.inc 8include /etc/firejail/disable-passwdmgr.inc
9 9
10caps.drop all 10caps.drop all
11nonewprivs
12nogroups 11nogroups
12nonewprivs
13noroot 13noroot
14nosound 14nosound
15protocol unix 15protocol unix
@@ -20,4 +20,3 @@ tracelog
20private-bin pix 20private-bin pix
21whitelist /tmp/.X11-unix 21whitelist /tmp/.X11-unix
22private-dev 22private-dev
23
diff --git a/etc/psi-plus.profile b/etc/psi-plus.profile
index 22c5bafc5..a9323448b 100644
--- a/etc/psi-plus.profile
+++ b/etc/psi-plus.profile
@@ -14,10 +14,10 @@ whitelist ~/.local/share/psi+
14mkdir ~/.cache/psi+ 14mkdir ~/.cache/psi+
15whitelist ~/.cache/psi+ 15whitelist ~/.cache/psi+
16 16
17include /etc/firejail/whitelist-common.inc
18
19caps.drop all 17caps.drop all
20netfilter 18netfilter
21noroot 19noroot
22protocol unix,inet,inet6 20protocol unix,inet,inet6
23seccomp 21seccomp
22
23include /etc/firejail/whitelist-common.inc
diff --git a/etc/qbittorrent.profile b/etc/qbittorrent.profile
index 138b6db55..67829c9ca 100644
--- a/etc/qbittorrent.profile
+++ b/etc/qbittorrent.profile
@@ -15,6 +15,6 @@ seccomp
15# there are some problems with "Open destination folder", see bug #536 15# there are some problems with "Open destination folder", see bug #536
16#shell none 16#shell none
17#private-bin qbittorrent 17#private-bin qbittorrent
18whitelist /tmp/.X11-unix
19private-dev 18private-dev
20nosound 19
20whitelist /tmp/.X11-unix
diff --git a/etc/qpdfview.profile b/etc/qpdfview.profile
index 07ea173e6..06c0db206 100644
--- a/etc/qpdfview.profile
+++ b/etc/qpdfview.profile
@@ -18,5 +18,5 @@ shell none
18tracelog 18tracelog
19 19
20private-bin qpdfview 20private-bin qpdfview
21private-tmp
22private-dev 21private-dev
22private-tmp
diff --git a/etc/qtox.profile b/etc/qtox.profile
index 927487037..81d8aa10e 100644
--- a/etc/qtox.profile
+++ b/etc/qtox.profile
@@ -11,8 +11,8 @@ whitelist ${DOWNLOADS}
11 11
12caps.drop all 12caps.drop all
13netfilter 13netfilter
14nonewprivs
15nogroups 14nogroups
15nonewprivs
16noroot 16noroot
17protocol unix,inet,inet6 17protocol unix,inet,inet6
18seccomp 18seccomp
diff --git a/etc/quiterss.profile b/etc/quiterss.profile
index 2ab5d8a8e..2b28fce73 100644
--- a/etc/quiterss.profile
+++ b/etc/quiterss.profile
@@ -14,16 +14,17 @@ whitelist ${HOME}/.cache/QuiteRss
14 14
15caps.drop all 15caps.drop all
16netfilter 16netfilter
17nonewprivs
18nogroups 17nogroups
18nonewprivs
19noroot 19noroot
20private-bin quiterss
21private-dev
22nosound 20nosound
23#private-etc X11,ssl
24protocol unix,inet,inet6 21protocol unix,inet,inet6
25seccomp 22seccomp
26shell none 23shell none
27tracelog 24tracelog
28 25
26private-bin quiterss
27private-dev
28#private-etc X11,ssl
29
29include /etc/firejail/whitelist-common.inc 30include /etc/firejail/whitelist-common.inc
diff --git a/etc/ranger.profile b/etc/ranger.profile
index a040cd6bc..323e64dee 100644
--- a/etc/ranger.profile
+++ b/etc/ranger.profile
@@ -12,13 +12,12 @@ include /etc/firejail/disable-passwdmgr.inc
12caps.drop all 12caps.drop all
13netfilter 13netfilter
14net none 14net none
15nogroups
15nonewprivs 16nonewprivs
16noroot 17noroot
17nogroups
18protocol unix 18protocol unix
19seccomp 19seccomp
20nosound 20nosound
21 21
22private-tmp 22private-tmp
23private-dev 23private-dev
24
diff --git a/etc/rhythmbox.profile b/etc/rhythmbox.profile
index 0e8527ae7..e5e192486 100644
--- a/etc/rhythmbox.profile
+++ b/etc/rhythmbox.profile
@@ -5,8 +5,8 @@ include /etc/firejail/disable-devel.inc
5include /etc/firejail/disable-passwdmgr.inc 5include /etc/firejail/disable-passwdmgr.inc
6 6
7caps.drop all 7caps.drop all
8nogroups
9netfilter 8netfilter
9nogroups
10nonewprivs 10nonewprivs
11noroot 11noroot
12protocol unix,inet,inet6 12protocol unix,inet,inet6
diff --git a/etc/rtorrent.profile b/etc/rtorrent.profile
index 15df2c374..1226a51cd 100644
--- a/etc/rtorrent.profile
+++ b/etc/rtorrent.profile
@@ -16,4 +16,3 @@ shell none
16private-bin rtorrent 16private-bin rtorrent
17whitelist /tmp/.X11-unix 17whitelist /tmp/.X11-unix
18private-dev 18private-dev
19nosound
diff --git a/etc/server.profile b/etc/server.profile
index 22cef0a3c..b8a34feb2 100644
--- a/etc/server.profile
+++ b/etc/server.profile
@@ -6,11 +6,12 @@ include /etc/firejail/disable-common.inc
6include /etc/firejail/disable-programs.inc 6include /etc/firejail/disable-programs.inc
7include /etc/firejail/disable-passwdmgr.inc 7include /etc/firejail/disable-passwdmgr.inc
8 8
9private
10private-dev
11nosound
12no3d
13private-tmp
14blacklist /tmp/.X11-unix 9blacklist /tmp/.X11-unix
10
11no3d
12nosound
15seccomp 13seccomp
16 14
15private
16private-dev
17private-tmp
diff --git a/etc/slack.profile b/etc/slack.profile
index 1009f7ee0..a85a28f03 100644
--- a/etc/slack.profile
+++ b/etc/slack.profile
@@ -1,3 +1,4 @@
1# Firejail profile for Slack
1noblacklist ${HOME}/.config/Slack 2noblacklist ${HOME}/.config/Slack
2noblacklist ${HOME}/Downloads 3noblacklist ${HOME}/Downloads
3 4
@@ -6,25 +7,25 @@ include /etc/firejail/disable-programs.inc
6include /etc/firejail/disable-devel.inc 7include /etc/firejail/disable-devel.inc
7include /etc/firejail/disable-passwdmgr.inc 8include /etc/firejail/disable-passwdmgr.inc
8 9
9mkdir ${HOME}/.config
10mkdir ${HOME}/.config/Slack
11whitelist ${HOME}/.config/Slack
12whitelist ${HOME}/Downloads
13
14protocol unix,inet,inet6,netlink
15private-dev
16private-tmp
17private-etc fonts,resolv.conf,ld.so.conf,ld.so.cache,localtime
18name slack
19blacklist /var 10blacklist /var
20 11
21include /etc/firejail/whitelist-common.inc
22
23caps.drop all 12caps.drop all
24seccomp 13name slack
25netfilter 14netfilter
26nonewprivs
27nogroups 15nogroups
16nonewprivs
28noroot 17noroot
18protocol unix,inet,inet6,netlink
19seccomp
29shell none 20shell none
21
30private-bin slack 22private-bin slack
23private-dev
24private-etc fonts,resolv.conf,ld.so.conf,ld.so.cache,localtime
25private-tmp
26
27mkdir ${HOME}/.config
28mkdir ${HOME}/.config/Slack
29whitelist ${HOME}/.config/Slack
30whitelist ${HOME}/Downloads
31include /etc/firejail/whitelist-common.inc
diff --git a/etc/strings.profile b/etc/strings.profile
index f99a65009..7c464bf88 100644
--- a/etc/strings.profile
+++ b/etc/strings.profile
@@ -1,10 +1,11 @@
1# strings profile 1# strings profile
2quiet
3ignore noroot 2ignore noroot
4include /etc/firejail/default.profile 3include /etc/firejail/default.profile
5tracelog 4
6net none 5net none
7shell none
8private-dev
9nosound 6nosound
7quiet
8shell none
9tracelog
10 10
11private-dev
diff --git a/etc/synfigstudio.profile b/etc/synfigstudio.profile
index d46467b99..69b2a0db2 100644
--- a/etc/synfigstudio.profile
+++ b/etc/synfigstudio.profile
@@ -11,7 +11,9 @@ nonewprivs
11noroot 11noroot
12protocol unix 12protocol unix
13seccomp 13seccomp
14private-dev 14
15private-tmp
16noexec ${HOME} 15noexec ${HOME}
17noexec /tmp 16noexec /tmp
17
18private-dev
19private-tmp
diff --git a/etc/tar.profile b/etc/tar.profile
index 663ac3805..91fdaf48d 100644
--- a/etc/tar.profile
+++ b/etc/tar.profile
@@ -1,18 +1,18 @@
1# tar profile 1# tar profile
2quiet
3ignore noroot 2ignore noroot
4include /etc/firejail/default.profile 3include /etc/firejail/default.profile
5 4
6tracelog 5blacklist /tmp/.X11-unix
6
7hostname tar
7net none 8net none
9no3d
10nosound
11quiet
8shell none 12shell none
13tracelog
9 14
10# support compressed archives 15# support compressed archives
11private-bin sh,tar,gtar,compress,gzip,lzma,xz,bzip2,lbzip2,lzip,lzop 16private-bin sh,tar,gtar,compress,gzip,lzma,xz,bzip2,lbzip2,lzip,lzop
12private-dev 17private-dev
13nosound
14no3d
15private-etc passwd,group,localtime 18private-etc passwd,group,localtime
16hostname tar
17blacklist /tmp/.X11-unix
18
diff --git a/etc/telegram.profile b/etc/telegram.profile
index 8e91e426b..7615c8eef 100644
--- a/etc/telegram.profile
+++ b/etc/telegram.profile
@@ -10,4 +10,3 @@ nonewprivs
10noroot 10noroot
11protocol unix,inet,inet6 11protocol unix,inet,inet6
12seccomp 12seccomp
13
diff --git a/etc/transmission-gtk.profile b/etc/transmission-gtk.profile
index 0cfa4fcfc..316cdfec6 100644
--- a/etc/transmission-gtk.profile
+++ b/etc/transmission-gtk.profile
@@ -18,6 +18,6 @@ shell none
18tracelog 18tracelog
19 19
20private-bin transmission-gtk 20private-bin transmission-gtk
21whitelist /tmp/.X11-unix
22private-dev 21private-dev
23 22
23whitelist /tmp/.X11-unix
diff --git a/etc/transmission-qt.profile b/etc/transmission-qt.profile
index 754211a63..51c58e224 100644
--- a/etc/transmission-qt.profile
+++ b/etc/transmission-qt.profile
@@ -14,9 +14,10 @@ noroot
14nosound 14nosound
15protocol unix,inet,inet6 15protocol unix,inet,inet6
16seccomp 16seccomp
17shell none
17tracelog 18tracelog
18 19
19shell none
20private-bin transmission-qt 20private-bin transmission-qt
21whitelist /tmp/.X11-unix
22private-dev 21private-dev
22
23whitelist /tmp/.X11-unix
diff --git a/etc/uget-gtk.profile b/etc/uget-gtk.profile
index 522b4bd1e..f42e6c69a 100644
--- a/etc/uget-gtk.profile
+++ b/etc/uget-gtk.profile
@@ -9,17 +9,16 @@ caps.drop all
9netfilter 9netfilter
10nonewprivs 10nonewprivs
11noroot 11noroot
12nosound
12protocol unix,inet,inet6 13protocol unix,inet,inet6
13seccomp 14seccomp
15shell none
14 16
17private-bin uget-gtk
18private-dev
19
20whitelist /tmp/.X11-unix
15whitelist ${DOWNLOADS} 21whitelist ${DOWNLOADS}
16mkdir ~/.config/uGet 22mkdir ~/.config/uGet
17whitelist ~/.config/uGet 23whitelist ~/.config/uGet
18include /etc/firejail/whitelist-common.inc 24include /etc/firejail/whitelist-common.inc
19
20shell none
21private-bin uget-gtk
22whitelist /tmp/.X11-unix
23private-dev
24nosound
25
diff --git a/etc/unrar.profile b/etc/unrar.profile
index f29d1b51b..0700cafe9 100644
--- a/etc/unrar.profile
+++ b/etc/unrar.profile
@@ -1,17 +1,18 @@
1# unrar profile 1# unrar profile
2quiet
3ignore noroot 2ignore noroot
4include /etc/firejail/default.profile 3include /etc/firejail/default.profile
5 4
6tracelog 5blacklist /tmp/.X11-unix
6
7hostname unrar
7net none 8net none
9no3d
10nosound
11quiet
8shell none 12shell none
13tracelog
14
9private-bin unrar 15private-bin unrar
10private-dev 16private-dev
11nosound
12no3d
13private-etc passwd,group,localtime 17private-etc passwd,group,localtime
14hostname unrar
15private-tmp 18private-tmp
16blacklist /tmp/.X11-unix
17
diff --git a/etc/unzip.profile b/etc/unzip.profile
index 07224855f..a43785795 100644
--- a/etc/unzip.profile
+++ b/etc/unzip.profile
@@ -1,16 +1,16 @@
1# unzip profile 1# unzip profile
2quiet
3ignore noroot 2ignore noroot
4include /etc/firejail/default.profile 3include /etc/firejail/default.profile
4blacklist /tmp/.X11-unix
5 5
6tracelog 6hostname unzip
7net none 7net none
8no3d
9nosound
10quiet
8shell none 11shell none
12tracelog
13
9private-bin unzip 14private-bin unzip
10private-etc passwd,group,localtime
11hostname unzip
12private-dev 15private-dev
13nosound 16private-etc passwd,group,localtime
14no3d
15blacklist /tmp/.X11-unix
16
diff --git a/etc/uudeview.profile b/etc/uudeview.profile
index 8ea9d5163..5ba0896ab 100644
--- a/etc/uudeview.profile
+++ b/etc/uudeview.profile
@@ -1,15 +1,15 @@
1# uudeview profile 1# uudeview profile
2quiet
3ignore noroot 2ignore noroot
4include /etc/firejail/default.profile 3include /etc/firejail/default.profile
5 4
6tracelog 5blacklist /etc
6
7hostname uudeview
7net none 8net none
9nosound
10quiet
8shell none 11shell none
12tracelog
13
9private-bin uudeview 14private-bin uudeview
10private-dev 15private-dev
11private-etc nonexisting_fakefile_for_empty_etc
12hostname uudeview
13nosound
14uudeview
15
diff --git a/etc/vim.profile b/etc/vim.profile
index 3c1fefe41..b161fcbb0 100644
--- a/etc/vim.profile
+++ b/etc/vim.profile
@@ -1,5 +1,4 @@
1# vim profile 1# vim profile
2
3noblacklist ~/.vim 2noblacklist ~/.vim
4noblacklist ~/.vimrc 3noblacklist ~/.vimrc
5noblacklist ~/.viminfo 4noblacklist ~/.viminfo
@@ -10,8 +9,8 @@ include /etc/firejail/disable-passwdmgr.inc
10 9
11caps.drop all 10caps.drop all
12netfilter 11netfilter
12nogroups
13nonewprivs 13nonewprivs
14noroot 14noroot
15nogroups
16protocol unix,inet,inet6 15protocol unix,inet,inet6
17seccomp 16seccomp
diff --git a/etc/xpdf.profile b/etc/xpdf.profile
index e036fba21..7ea368bbe 100644
--- a/etc/xpdf.profile
+++ b/etc/xpdf.profile
@@ -7,15 +7,12 @@ include /etc/firejail/disable-programs.inc
7include /etc/firejail/disable-passwdmgr.inc 7include /etc/firejail/disable-passwdmgr.inc
8 8
9caps.drop all 9caps.drop all
10shell none 10net none
11nonewprivs 11nonewprivs
12noroot 12noroot
13protocol unix 13protocol unix
14shell none
14seccomp 15seccomp
16
15private-dev 17private-dev
16private-tmp 18private-tmp
17net none
18
19
20
21
diff --git a/etc/xplayer.profile b/etc/xplayer.profile
index 54d5ed89b..191d2f67f 100644
--- a/etc/xplayer.profile
+++ b/etc/xplayer.profile
@@ -9,8 +9,8 @@ include /etc/firejail/disable-passwdmgr.inc
9 9
10caps.drop all 10caps.drop all
11netfilter 11netfilter
12nonewprivs
13nogroups 12nogroups
13nonewprivs
14noroot 14noroot
15protocol unix,inet,inet6 15protocol unix,inet,inet6
16seccomp 16seccomp
diff --git a/etc/xzdec.profile b/etc/xzdec.profile
index a9d027c38..04f98cef6 100644
--- a/etc/xzdec.profile
+++ b/etc/xzdec.profile
@@ -1,12 +1,14 @@
1# xzdec profile 1# xzdec profile
2quiet
3ignore noroot 2ignore noroot
4include /etc/firejail/default.profile 3include /etc/firejail/default.profile
5tracelog 4
6net none
7shell none
8blacklist /tmp/.X11-unix 5blacklist /tmp/.X11-unix
9private-dev 6
10nosound 7net none
11no3d 8no3d
9nosound
10quiet
11shell none
12tracelog
12 13
14private-dev
diff --git a/etc/zathura.profile b/etc/zathura.profile
index 7093c52b2..ab2e99dbc 100644
--- a/etc/zathura.profile
+++ b/etc/zathura.profile
@@ -7,14 +7,14 @@ include /etc/firejail/disable-devel.inc
7include /etc/firejail/disable-passwdmgr.inc 7include /etc/firejail/disable-passwdmgr.inc
8 8
9caps.drop all 9caps.drop all
10seccomp
11protocol unix
12netfilter 10netfilter
11nogroups
13nonewprivs 12nonewprivs
14noroot 13noroot
15nogroups
16nosound 14nosound
17shell none 15shell none
16seccomp
17protocol unix
18 18
19private-bin zathura 19private-bin zathura
20private-dev 20private-dev