aboutsummaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
authorLibravatar smitsohu <smitsohu@gmail.com>2022-03-11 15:44:00 +0100
committerLibravatar smitsohu <smitsohu@gmail.com>2022-03-11 15:44:00 +0100
commit255fdb1c7f75f00f0560c614bd986f086a5253cb (patch)
tree50a4b8a7ed6daa8c67006b5498ed86d1788c83aa /etc
parentmerge (diff)
parentMerge pull request #5013 from rusty-snake/scala (diff)
downloadfirejail-255fdb1c7f75f00f0560c614bd986f086a5253cb.tar.gz
firejail-255fdb1c7f75f00f0560c614bd986f086a5253cb.tar.zst
firejail-255fdb1c7f75f00f0560c614bd986f086a5253cb.zip
Merge branch 'master' of https://github.com/netblue30/firejail
Diffstat (limited to 'etc')
-rw-r--r--etc/inc/disable-common.inc3
-rw-r--r--etc/inc/disable-devel.inc7
-rw-r--r--etc/inc/disable-programs.inc5
-rw-r--r--etc/profile-m-z/steam.profile6
4 files changed, 20 insertions, 1 deletions
diff --git a/etc/inc/disable-common.inc b/etc/inc/disable-common.inc
index 43332b4d0..2e2f6c429 100644
--- a/etc/inc/disable-common.inc
+++ b/etc/inc/disable-common.inc
@@ -9,7 +9,9 @@ blacklist ${HOME}/.local/share/Trash
9 9
10# History files in $HOME and clipboard managers 10# History files in $HOME and clipboard managers
11blacklist-nolog ${HOME}/.*_history 11blacklist-nolog ${HOME}/.*_history
12blacklist-nolog ${HOME}/.*_history_*
12blacklist-nolog ${HOME}/.adobe 13blacklist-nolog ${HOME}/.adobe
14blacklist-nolog ${HOME}/.ammonite/history
13blacklist-nolog ${HOME}/.cache/greenclip* 15blacklist-nolog ${HOME}/.cache/greenclip*
14blacklist-nolog ${HOME}/.histfile 16blacklist-nolog ${HOME}/.histfile
15blacklist-nolog ${HOME}/.history 17blacklist-nolog ${HOME}/.history
@@ -360,6 +362,7 @@ read-only ${HOME}/.bin
360read-only ${HOME}/.cargo/bin 362read-only ${HOME}/.cargo/bin
361read-only ${HOME}/.gem 363read-only ${HOME}/.gem
362read-only ${HOME}/.local/bin 364read-only ${HOME}/.local/bin
365read-only ${HOME}/.local/share/coursier/bin
363read-only ${HOME}/.luarocks 366read-only ${HOME}/.luarocks
364read-only ${HOME}/.npm-packages 367read-only ${HOME}/.npm-packages
365read-only ${HOME}/.nvm 368read-only ${HOME}/.nvm
diff --git a/etc/inc/disable-devel.inc b/etc/inc/disable-devel.inc
index 98bf5ecc8..360077936 100644
--- a/etc/inc/disable-devel.inc
+++ b/etc/inc/disable-devel.inc
@@ -41,6 +41,13 @@ blacklist /etc/java
41blacklist /usr/lib/java 41blacklist /usr/lib/java
42blacklist /usr/share/java 42blacklist /usr/share/java
43 43
44# Scala
45blacklist ${PATH}/scala
46blacklist ${PATH}/scala3
47blacklist ${PATH}/scala3-compiler
48blacklist ${PATH}/scala3-repl
49blacklist ${PATH}/scalac
50
44#OpenSSL 51#OpenSSL
45blacklist ${PATH}/openssl 52blacklist ${PATH}/openssl
46blacklist ${PATH}/openssl-1.0 53blacklist ${PATH}/openssl-1.0
diff --git a/etc/inc/disable-programs.inc b/etc/inc/disable-programs.inc
index 3d74b8866..f5de98450 100644
--- a/etc/inc/disable-programs.inc
+++ b/etc/inc/disable-programs.inc
@@ -30,6 +30,7 @@ blacklist ${HOME}/.aMule
30blacklist ${HOME}/.abook 30blacklist ${HOME}/.abook
31blacklist ${HOME}/.addressbook 31blacklist ${HOME}/.addressbook
32blacklist ${HOME}/.alpine-smime 32blacklist ${HOME}/.alpine-smime
33blacklist ${HOME}/.ammonite
33blacklist ${HOME}/.android 34blacklist ${HOME}/.android
34blacklist ${HOME}/.anydesk 35blacklist ${HOME}/.anydesk
35blacklist ${HOME}/.arduino15 36blacklist ${HOME}/.arduino15
@@ -466,6 +467,7 @@ blacklist ${HOME}/.config/iridium
466blacklist ${HOME}/.config/itch 467blacklist ${HOME}/.config/itch
467blacklist ${HOME}/.config/jami 468blacklist ${HOME}/.config/jami
468blacklist ${HOME}/.config/jd-gui.cfg 469blacklist ${HOME}/.config/jd-gui.cfg
470blacklist ${HOME}/.config/jgit
469blacklist ${HOME}/.config/k3brc 471blacklist ${HOME}/.config/k3brc
470blacklist ${HOME}/.config/kaffeinerc 472blacklist ${HOME}/.config/kaffeinerc
471blacklist ${HOME}/.config/kalgebrarc 473blacklist ${HOME}/.config/kalgebrarc
@@ -692,6 +694,7 @@ blacklist ${HOME}/.freemind
692blacklist ${HOME}/.frogatto 694blacklist ${HOME}/.frogatto
693blacklist ${HOME}/.frozen-bubble 695blacklist ${HOME}/.frozen-bubble
694blacklist ${HOME}/.funnyboat 696blacklist ${HOME}/.funnyboat
697blacklist ${HOME}/.g8
695blacklist ${HOME}/.gallery-dl.conf 698blacklist ${HOME}/.gallery-dl.conf
696blacklist ${HOME}/.geekbench5 699blacklist ${HOME}/.geekbench5
697blacklist ${HOME}/.gimp* 700blacklist ${HOME}/.gimp*
@@ -714,6 +717,7 @@ blacklist ${HOME}/.icedove
714blacklist ${HOME}/.imagej 717blacklist ${HOME}/.imagej
715blacklist ${HOME}/.inkscape 718blacklist ${HOME}/.inkscape
716blacklist ${HOME}/.itch 719blacklist ${HOME}/.itch
720blacklist ${HOME}/.ivy2
717blacklist ${HOME}/.jack-server 721blacklist ${HOME}/.jack-server
718blacklist ${HOME}/.jack-settings 722blacklist ${HOME}/.jack-settings
719blacklist ${HOME}/.jak 723blacklist ${HOME}/.jak
@@ -1072,6 +1076,7 @@ blacklist ${HOME}/.repo_.gitconfig.json
1072blacklist ${HOME}/.repoconfig 1076blacklist ${HOME}/.repoconfig
1073blacklist ${HOME}/.retroshare 1077blacklist ${HOME}/.retroshare
1074blacklist ${HOME}/.ripperXrc 1078blacklist ${HOME}/.ripperXrc
1079blacklist ${HOME}/.sbt
1075blacklist ${HOME}/.scorched3d 1080blacklist ${HOME}/.scorched3d
1076blacklist ${HOME}/.scribus 1081blacklist ${HOME}/.scribus
1077blacklist ${HOME}/.scribusrc 1082blacklist ${HOME}/.scribusrc
diff --git a/etc/profile-m-z/steam.profile b/etc/profile-m-z/steam.profile
index b0be8a517..4137839f8 100644
--- a/etc/profile-m-z/steam.profile
+++ b/etc/profile-m-z/steam.profile
@@ -35,6 +35,7 @@ noblacklist ${HOME}/.local/share/vpltd
35noblacklist ${HOME}/.local/share/vulkan 35noblacklist ${HOME}/.local/share/vulkan
36noblacklist ${HOME}/.mbwarband 36noblacklist ${HOME}/.mbwarband
37noblacklist ${HOME}/.paradoxinteractive 37noblacklist ${HOME}/.paradoxinteractive
38noblacklist ${HOME}/.prey
38noblacklist ${HOME}/.steam 39noblacklist ${HOME}/.steam
39noblacklist ${HOME}/.steampath 40noblacklist ${HOME}/.steampath
40noblacklist ${HOME}/.steampid 41noblacklist ${HOME}/.steampid
@@ -82,6 +83,7 @@ mkdir ${HOME}/.local/share/vpltd
82mkdir ${HOME}/.local/share/vulkan 83mkdir ${HOME}/.local/share/vulkan
83mkdir ${HOME}/.mbwarband 84mkdir ${HOME}/.mbwarband
84mkdir ${HOME}/.paradoxinteractive 85mkdir ${HOME}/.paradoxinteractive
86mkdir ${HOME}/.prey
85mkdir ${HOME}/.steam 87mkdir ${HOME}/.steam
86mkfile ${HOME}/.steampath 88mkfile ${HOME}/.steampath
87mkfile ${HOME}/.steampid 89mkfile ${HOME}/.steampid
@@ -115,6 +117,7 @@ whitelist ${HOME}/.local/share/vpltd
115whitelist ${HOME}/.local/share/vulkan 117whitelist ${HOME}/.local/share/vulkan
116whitelist ${HOME}/.mbwarband 118whitelist ${HOME}/.mbwarband
117whitelist ${HOME}/.paradoxinteractive 119whitelist ${HOME}/.paradoxinteractive
120whitelist ${HOME}/.prey
118whitelist ${HOME}/.steam 121whitelist ${HOME}/.steam
119whitelist ${HOME}/.steampath 122whitelist ${HOME}/.steampath
120whitelist ${HOME}/.steampid 123whitelist ${HOME}/.steampid
@@ -143,7 +146,8 @@ novideo
143protocol unix,inet,inet6,netlink 146protocol unix,inet,inet6,netlink
144# seccomp sometimes causes issues (see #2951, #3267). 147# seccomp sometimes causes issues (see #2951, #3267).
145# Add 'ignore seccomp' to your steam.local if you experience this. 148# Add 'ignore seccomp' to your steam.local if you experience this.
146seccomp !ptrace 149# mount, name_to_handle_at, pivot_root and umount2 are used by Proton >= 5.13
150seccomp !chroot,!mount,!name_to_handle_at,!pivot_root,!ptrace,!umount2
147shell none 151shell none
148# tracelog breaks integrated browser 152# tracelog breaks integrated browser
149#tracelog 153#tracelog