aboutsummaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
authorLibravatar netblue30 <netblue30@yahoo.com>2016-10-26 09:08:58 -0400
committerLibravatar GitHub <noreply@github.com>2016-10-26 09:08:58 -0400
commit33ee2da69f91d719f318a3c93cc3c2eaf5ce4e20 (patch)
tree2982f885d297ee3ea00b36bb1f6d67ed59ab0887 /etc
parentfixes (diff)
parenttypo #2 (diff)
downloadfirejail-33ee2da69f91d719f318a3c93cc3c2eaf5ce4e20.tar.gz
firejail-33ee2da69f91d719f318a3c93cc3c2eaf5ce4e20.tar.zst
firejail-33ee2da69f91d719f318a3c93cc3c2eaf5ce4e20.zip
Merge pull request #872 from Fred-Barclay/extra-profiles
Extra profiles
Diffstat (limited to 'etc')
-rw-r--r--etc/disable-programs.inc2
-rw-r--r--etc/gpredict.profile2
-rw-r--r--etc/start-tor-browser.profile20
-rw-r--r--etc/xiphos.profile30
4 files changed, 53 insertions, 1 deletions
diff --git a/etc/disable-programs.inc b/etc/disable-programs.inc
index edd4ee374..6e22fe04d 100644
--- a/etc/disable-programs.inc
+++ b/etc/disable-programs.inc
@@ -7,6 +7,8 @@ blacklist ${HOME}/.wine
7blacklist ${HOME}/.Mathematica 7blacklist ${HOME}/.Mathematica
8blacklist ${HOME}/.Wolfram Research 8blacklist ${HOME}/.Wolfram Research
9blacklist ${HOME}/.stellarium 9blacklist ${HOME}/.stellarium
10blacklist ${HOME}/.sword
11blacklist ${HOME}/.xiphos
10blacklist ${HOME}/.config/Atom 12blacklist ${HOME}/.config/Atom
11blacklist ${HOME}/.config/gthumb 13blacklist ${HOME}/.config/gthumb
12blacklist ${HOME}/.config/mupen64plus 14blacklist ${HOME}/.config/mupen64plus
diff --git a/etc/gpredict.profile b/etc/gpredict.profile
index 0cc6c416b..801304c18 100644
--- a/etc/gpredict.profile
+++ b/etc/gpredict.profile
@@ -6,7 +6,6 @@ include /etc/firejail/disable-passwdmgr.inc
6include /etc/firejail/disable-programs.inc 6include /etc/firejail/disable-programs.inc
7 7
8# Whitelist 8# Whitelist
9mkdir ~/.config/Gpredict
10whitelist ~/.config/Gpredict 9whitelist ~/.config/Gpredict
11 10
12caps.drop all 11caps.drop all
@@ -21,5 +20,6 @@ shell none
21tracelog 20tracelog
22 21
23private-bin gpredict 22private-bin gpredict
23private-etc fonts,resolv.conf
24private-dev 24private-dev
25private-tmp 25private-tmp
diff --git a/etc/start-tor-browser.profile b/etc/start-tor-browser.profile
new file mode 100644
index 000000000..ee19cee25
--- /dev/null
+++ b/etc/start-tor-browser.profile
@@ -0,0 +1,20 @@
1# Firejail profile for the Tor Brower Bundle
2include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-devel.inc
4include /etc/firejail/disable-passwdmgr.inc
5include /etc/firejail/disable-programs.inc
6
7caps.drop all
8netfilter
9nogroups
10nonewprivs
11noroot
12protocol unix,inet,inet6
13seccomp
14shell none
15tracelog
16
17private-bin bash,grep,sed,tail,env,gpg,id,readlink,dirname,test,mkdir,ln,sed,cp,rm,getconf
18private-etc fonts
19private-dev
20private-tmp
diff --git a/etc/xiphos.profile b/etc/xiphos.profile
new file mode 100644
index 000000000..b7fb6ecf3
--- /dev/null
+++ b/etc/xiphos.profile
@@ -0,0 +1,30 @@
1# Firejail profile for xiphos
2noblacklist ~/.sword
3noblacklist ~/.xiphos
4
5include /etc/firejail/disable-common.inc
6include /etc/firejail/disable-devel.inc
7include /etc/firejail/disable-passwdmgr.inc
8include /etc/firejail/disable-programs.inc
9
10blacklist ~/.bashrc
11blacklist ~/.Xauthority
12
13caps.drop all
14netfilter
15nogroups
16nonewprivs
17noroot
18nosound
19protocol unix,inet,inet6
20seccomp
21shell none
22tracelog
23
24private-bin xiphos
25private-etc fonts,resolv.conf,sword
26private-dev
27private-tmp
28
29whitelist ${HOME}/.sword
30whitelist ${HOME}/.xiphos