aboutsummaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
authorLibravatar netblue30 <netblue30@yahoo.com>2016-12-16 12:44:28 -0500
committerLibravatar GitHub <noreply@github.com>2016-12-16 12:44:28 -0500
commitcbfef7eea581e9c9a8c5c8b22154971043eddb1a (patch)
tree0050b1c43923e23c3329e1278147da36b7a6d97b /etc
parentMerge pull request #978 from Fred-Barclay/keepassx2 (diff)
parentUpdate disable-common.inc (diff)
downloadfirejail-cbfef7eea581e9c9a8c5c8b22154971043eddb1a.tar.gz
firejail-cbfef7eea581e9c9a8c5c8b22154971043eddb1a.tar.zst
firejail-cbfef7eea581e9c9a8c5c8b22154971043eddb1a.zip
Merge pull request #979 from curiosity-seeker/master
Correct skanlite.profile
Diffstat (limited to 'etc')
-rw-r--r--etc/VirtualBox.profile1
-rw-r--r--etc/disable-common.inc1
-rw-r--r--etc/skanlite.profile6
-rw-r--r--etc/virtualbox.profile14
4 files changed, 17 insertions, 5 deletions
diff --git a/etc/VirtualBox.profile b/etc/VirtualBox.profile
new file mode 100644
index 000000000..ff0a4b6ef
--- /dev/null
+++ b/etc/VirtualBox.profile
@@ -0,0 +1 @@
include /etc/firejail/virtualbox.profile
diff --git a/etc/disable-common.inc b/etc/disable-common.inc
index 07814a704..efe5c850d 100644
--- a/etc/disable-common.inc
+++ b/etc/disable-common.inc
@@ -191,6 +191,7 @@ blacklist ${PATH}/mount.ecryptfs_private
191 191
192# other SUID binaries 192# other SUID binaries
193blacklist /usr/lib/virtualbox 193blacklist /usr/lib/virtualbox
194blacklist /usr/lib64/virtualbox
194 195
195# prevent lxterminal connecting to an existing lxterminal session 196# prevent lxterminal connecting to an existing lxterminal session
196blacklist /tmp/.lxterminal-socket* 197blacklist /tmp/.lxterminal-socket*
diff --git a/etc/skanlite.profile b/etc/skanlite.profile
index 4dcfa64d9..667b775c8 100644
--- a/etc/skanlite.profile
+++ b/etc/skanlite.profile
@@ -11,10 +11,10 @@ nonewprivs
11noroot 11noroot
12nosound 12nosound
13shell none 13shell none
14#seccomp 14seccomp
15protocol unix,inet,inet6 15# protocol unix,inet,inet6
16 16
17private-bin skanlite 17# private-bin skanlite
18# private-dev 18# private-dev
19# private-tmp 19# private-tmp
20# private-etc 20# private-etc
diff --git a/etc/virtualbox.profile b/etc/virtualbox.profile
index 36a1e0704..1e765b89b 100644
--- a/etc/virtualbox.profile
+++ b/etc/virtualbox.profile
@@ -1,12 +1,22 @@
1# VirtualBox profile 1# virtualbox profile
2noblacklist ${HOME}/.VirtualBox 2noblacklist ${HOME}/.VirtualBox
3noblacklist ${HOME}/VirtualBox VMs 3noblacklist ${HOME}/VirtualBox VMs
4noblacklist ${HOME}/.config/VirtualBox 4noblacklist ${HOME}/.config/VirtualBox
5noblacklist /usr/bin/virtualbox 5
6mkdir ~/VirtualBox VMs
7whitelist ~/VirtualBox VMs
8mkdir ~/.config/VirtualBox
9whitelist ~/.config/VirtualBox
10
11# noblacklist /usr/bin/virtualbox
12noblacklist /usr/lib/virtualbox
13noblacklist /usr/lib64/virtualbox
6include /etc/firejail/disable-common.inc 14include /etc/firejail/disable-common.inc
7include /etc/firejail/disable-programs.inc 15include /etc/firejail/disable-programs.inc
8include /etc/firejail/disable-passwdmgr.inc 16include /etc/firejail/disable-passwdmgr.inc
17include /etc/firejail/whitelist-common.inc
9 18
10caps.drop all 19caps.drop all
20netfilter
11 21
12 22