aboutsummaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
authorLibravatar juan <gatitocurioso@cock.lu>2017-09-16 13:20:36 -0400
committerLibravatar Tad <tad@spotco.us>2017-09-18 18:24:13 -0400
commitc435504a3eb66dee9a2964658bce8e17627e9c68 (patch)
tree492037d3f1cec726000e966d1be598d30148f335 /etc
parentAdd 31 profiles (diff)
downloadfirejail-c435504a3eb66dee9a2964658bce8e17627e9c68.tar.gz
firejail-c435504a3eb66dee9a2964658bce8e17627e9c68.tar.zst
firejail-c435504a3eb66dee9a2964658bce8e17627e9c68.zip
Add 5 profiles
Diffstat (limited to 'etc')
-rw-r--r--etc/ardour4.profile34
-rw-r--r--etc/dooble-qt4.profile33
-rw-r--r--etc/dooble.profile33
-rw-r--r--etc/karbon.profile37
-rw-r--r--etc/krita.profile37
5 files changed, 174 insertions, 0 deletions
diff --git a/etc/ardour4.profile b/etc/ardour4.profile
new file mode 100644
index 000000000..3a52edb66
--- /dev/null
+++ b/etc/ardour4.profile
@@ -0,0 +1,34 @@
1# Firejail profile for ardour4
2# This file is overwritten after every install/update
3# Persistent local customizations
4include /etc/firejail/ardour4.local
5# Persistent global definitions
6include /etc/firejail/globals.local
7
8noblacklist ~/.config/ardour4
9
10include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-passwdmgr.inc
13include /etc/firejail/disable-programs.inc
14
15mkdir ~/.config/ardour4
16whitelist ~/.config/ardour4
17whitelist ~/Music
18whitelist ~/Música
19include /etc/firejail/whitelist-common.inc
20
21caps.drop all
22netfilter
23nogroups
24nonewprivs
25noroot
26protocol unix
27seccomp
28shell none
29tracelog
30
31# private-bin ardour4
32private-dev
33# private-etc ardour4
34private-tmp
diff --git a/etc/dooble-qt4.profile b/etc/dooble-qt4.profile
new file mode 100644
index 000000000..ec85c7b58
--- /dev/null
+++ b/etc/dooble-qt4.profile
@@ -0,0 +1,33 @@
1# Firejail profile for dooble-qt4
2# This file is overwritten after every install/update
3# Persistent local customizations
4include /etc/firejail/dooble-qt4.local
5# Persistent global definitions
6include /etc/firejail/globals.local
7
8noblacklist ~/.dooble
9
10include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-programs.inc
13
14mkdir ~/.dooble
15mkdir ~/usr/lib/dooble-qt4
16whitelist ${DOWNLOADS}
17whitelist ~/.config/keepassx
18whitelist ~/.config/lastpass
19whitelist ~/.dooble
20whitelist ~/.keepassx
21whitelist ~/.lastpass
22whitelist ~/keepassx.kdbx
23whitelist ~/usr/lib/dooble
24whitelist ~/usr/lib/dooble-qt4
25include /etc/firejail/whitelist-common.inc
26
27caps.drop all
28netfilter
29nonewprivs
30noroot
31protocol unix,inet,inet6,netlink
32seccomp
33tracelog
diff --git a/etc/dooble.profile b/etc/dooble.profile
new file mode 100644
index 000000000..13e4ead96
--- /dev/null
+++ b/etc/dooble.profile
@@ -0,0 +1,33 @@
1# Firejail profile for dooble
2# This file is overwritten after every install/update
3# Persistent local customizations
4include /etc/firejail/dooble.local
5# Persistent global definitions
6include /etc/firejail/globals.local
7
8noblacklist ~/.dooble
9
10include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-programs.inc
13
14mkdir ~/.dooble
15mkdir ~/usr/lib/dooble-qt4
16whitelist ${DOWNLOADS}
17whitelist ~/.config/keepassx
18whitelist ~/.config/lastpass
19whitelist ~/.dooble
20whitelist ~/.keepassx
21whitelist ~/.lastpass
22whitelist ~/keepassx.kdbx
23whitelist ~/usr/lib/dooble
24whitelist ~/usr/lib/dooble-qt4
25include /etc/firejail/whitelist-common.inc
26
27caps.drop all
28netfilter
29nonewprivs
30noroot
31protocol unix,inet,inet6,netlink
32seccomp
33tracelog
diff --git a/etc/karbon.profile b/etc/karbon.profile
new file mode 100644
index 000000000..da72432f7
--- /dev/null
+++ b/etc/karbon.profile
@@ -0,0 +1,37 @@
1# Firejail profile for karbon
2# This file is overwritten after every install/update
3# Persistent local customizations
4include /etc/firejail/karbon.local
5# Persistent global definitions
6include /etc/firejail/globals.local
7
8blacklist /boot
9blacklist /media
10blacklist /mnt
11blacklist /opt
12
13whitelist ${DOWNLOADS}
14whitelist ${HOME}/.config/Trolltech.conf
15whitelist ${HOME}/.gtkrc-2.0
16whitelist ${HOME}/.kde4
17whitelist ${HOME}/.themes
18whitelist ${HOME}/Images
19whitelist /tmp/.X11-unix
20# DBus has been forced to use an ordinary unix socket
21whitelist /tmp/dbus_session_socket
22include /etc/firejail/whitelist-common.inc
23
24caps.drop all
25ipc-namespace
26net none
27nogroups
28noroot
29seccomp
30shell none
31
32# private-bin krita,dbus-launch
33private-dev
34# private-etc fonts,passwd,alternatives,X11
35
36noexec /home
37noexec /tmp
diff --git a/etc/krita.profile b/etc/krita.profile
new file mode 100644
index 000000000..f6e62e387
--- /dev/null
+++ b/etc/krita.profile
@@ -0,0 +1,37 @@
1# Firejail profile for krita
2# This file is overwritten after every install/update
3# Persistent local customizations
4include /etc/firejail/krita.local
5# Persistent global definitions
6include /etc/firejail/globals.local
7
8blacklist /boot
9blacklist /media
10blacklist /mnt
11blacklist /opt
12
13whitelist ${DOWNLOADS}
14whitelist ${HOME}/.config/Trolltech.conf
15whitelist ${HOME}/.gtkrc-2.0
16whitelist ${HOME}/.kde4
17whitelist ${HOME}/.themes
18whitelist ${HOME}/Images
19whitelist /tmp/.X11-unix
20# DBus has been forced to use an ordinary unix socket
21whitelist /tmp/dbus_session_socket
22include /etc/firejail/whitelist-common.inc
23
24caps.drop all
25ipc-namespace
26net none
27nogroups
28noroot
29seccomp
30shell none
31
32# private-bin krita,dbus-launch
33private-dev
34# private-etc fonts,passwd,alternatives,X11
35
36noexec /home
37noexec /tmp