aboutsummaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
authorLibravatar netblue30 <netblue30@yahoo.com>2020-03-19 15:30:08 -0400
committerLibravatar netblue30 <netblue30@yahoo.com>2020-03-19 15:30:08 -0400
commit5dbdf657bdaafbb1dd1643b2115232a02b328286 (patch)
tree582534c0550f084e8148d3489e9433f456f92ac6 /etc
parentvarious profile fixes (diff)
downloadfirejail-5dbdf657bdaafbb1dd1643b2115232a02b328286.tar.gz
firejail-5dbdf657bdaafbb1dd1643b2115232a02b328286.tar.zst
firejail-5dbdf657bdaafbb1dd1643b2115232a02b328286.zip
new profiles: ripperx, sound-juicer
Diffstat (limited to 'etc')
-rw-r--r--etc/asunder.profile4
-rw-r--r--etc/disable-programs.inc2
-rw-r--r--etc/ripperx.profile41
-rw-r--r--etc/sound-juicer.profile41
4 files changed, 88 insertions, 0 deletions
diff --git a/etc/asunder.profile b/etc/asunder.profile
index 1f3acd735..fceac7cf9 100644
--- a/etc/asunder.profile
+++ b/etc/asunder.profile
@@ -20,21 +20,25 @@ include disable-passwdmgr.inc
20include disable-programs.inc 20include disable-programs.inc
21include disable-xdg.inc 21include disable-xdg.inc
22 22
23include whitelist-usr-share-common.inc
23include whitelist-var-common.inc 24include whitelist-var-common.inc
24 25
25apparmor 26apparmor
26caps.drop all 27caps.drop all
27netfilter 28netfilter
29no3d
28nodbus 30nodbus
29# nogroups 31# nogroups
30nonewprivs 32nonewprivs
31noroot 33noroot
32nou2f 34nou2f
35notv
33novideo 36novideo
34protocol unix,inet,inet6 37protocol unix,inet,inet6
35seccomp 38seccomp
36shell none 39shell none
37 40
41private-cache
38private-dev 42private-dev
39private-tmp 43private-tmp
40 44
diff --git a/etc/disable-programs.inc b/etc/disable-programs.inc
index 0786ba7d2..b54c1cce3 100644
--- a/etc/disable-programs.inc
+++ b/etc/disable-programs.inc
@@ -305,6 +305,7 @@ blacklist ${HOME}/.config/slimjet
305blacklist ${HOME}/.config/smplayer 305blacklist ${HOME}/.config/smplayer
306blacklist ${HOME}/.config/smtube 306blacklist ${HOME}/.config/smtube
307blacklist ${HOME}/.config/snox 307blacklist ${HOME}/.config/snox
308blacklist ${HOME}/.config/sound-juicer
308blacklist ${HOME}/.config/specialmailcollectionsrc 309blacklist ${HOME}/.config/specialmailcollectionsrc
309blacklist ${HOME}/.config/spotify 310blacklist ${HOME}/.config/spotify
310blacklist ${HOME}/.config/sqlitebrowser 311blacklist ${HOME}/.config/sqlitebrowser
@@ -650,6 +651,7 @@ blacklist ${HOME}/.remmina
650blacklist ${HOME}/.repo_.gitconfig.json 651blacklist ${HOME}/.repo_.gitconfig.json
651blacklist ${HOME}/.repoconfig 652blacklist ${HOME}/.repoconfig
652blacklist ${HOME}/.retroshare 653blacklist ${HOME}/.retroshare
654blacklist ${HOME}/.ripperXrc
653blacklist ${HOME}/.scorched3d 655blacklist ${HOME}/.scorched3d
654blacklist ${HOME}/.scribus 656blacklist ${HOME}/.scribus
655blacklist ${HOME}/.scribusrc 657blacklist ${HOME}/.scribusrc
diff --git a/etc/ripperx.profile b/etc/ripperx.profile
new file mode 100644
index 000000000..b572aa1b4
--- /dev/null
+++ b/etc/ripperx.profile
@@ -0,0 +1,41 @@
1# Firejail profile for mpv
2# Description: Graphical audio CD ripper and encoder
3# This file is overwritten after every install/update
4# Persistent local customizations
5include ripperx.local
6# Persistent global definitions
7include globals.local
8
9noblacklist ${HOME}/.ripperXrc
10noblacklist ${MUSIC}
11
12include disable-common.inc
13include disable-devel.inc
14include disable-exec.inc
15include disable-interpreters.inc
16include disable-passwdmgr.inc
17include disable-programs.inc
18include disable-xdg.inc
19
20include whitelist-usr-share-common.inc
21include whitelist-var-common.inc
22
23apparmor
24caps.drop all
25netfilter
26no3d
27nodbus
28nogroups
29nonewprivs
30noroot
31nou2f
32notv
33novideo
34protocol unix,inet,inet6
35seccomp
36shell none
37tracelog
38
39private-cache
40private-dev
41private-tmp
diff --git a/etc/sound-juicer.profile b/etc/sound-juicer.profile
new file mode 100644
index 000000000..ebd321573
--- /dev/null
+++ b/etc/sound-juicer.profile
@@ -0,0 +1,41 @@
1# Firejail profile for mpv
2# Description: Graphical audio CD ripper and encoder
3# This file is overwritten after every install/update
4# Persistent local customizations
5include sound-juicer.local
6# Persistent global definitions
7include globals.local
8
9noblacklist ${HOME}/.config/sound-juicer
10noblacklist ${MUSIC}
11
12include disable-common.inc
13include disable-devel.inc
14include disable-exec.inc
15include disable-interpreters.inc
16include disable-passwdmgr.inc
17include disable-programs.inc
18include disable-xdg.inc
19
20include whitelist-var-common.inc
21
22apparmor
23caps.drop all
24netfilter
25no3d
26#nodbus
27nogroups
28nonewprivs
29noroot
30nosound
31nou2f
32notv
33novideo
34protocol unix,inet,inet6,netlink
35seccomp
36shell none
37tracelog
38
39private-cache
40private-dev
41private-tmp