aboutsummaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
authorLibravatar netblue30 <netblue30@yahoo.com>2016-09-27 11:32:59 -0400
committerLibravatar netblue30 <netblue30@yahoo.com>2016-09-27 11:32:59 -0400
commited31d2238915749730856f877fceae3579b320da (patch)
tree9993d1a3f3dacc369a7cd237d5dcc58cf963c7cf /etc
parentCVE-2016-7545 (diff)
downloadfirejail-ed31d2238915749730856f877fceae3579b320da.tar.gz
firejail-ed31d2238915749730856f877fceae3579b320da.tar.zst
firejail-ed31d2238915749730856f877fceae3579b320da.zip
mupdf and qpdfview profiles
Diffstat (limited to 'etc')
-rw-r--r--etc/disable-programs.inc2
-rw-r--r--etc/mupdf.profile18
-rw-r--r--etc/qpdfview.profile22
3 files changed, 42 insertions, 0 deletions
diff --git a/etc/disable-programs.inc b/etc/disable-programs.inc
index fb0f5a669..54c53e794 100644
--- a/etc/disable-programs.inc
+++ b/etc/disable-programs.inc
@@ -26,6 +26,7 @@ blacklist ${HOME}/.kde/share/config/okularrc
26blacklist ${HOME}/.kde/share/config/okularpartrc 26blacklist ${HOME}/.kde/share/config/okularpartrc
27blacklist ${HOME}/.kde/share/apps/gwenview 27blacklist ${HOME}/.kde/share/apps/gwenview
28blacklist ${HOME}/.kde/share/config/gwenviewrc 28blacklist ${HOME}/.kde/share/config/gwenviewrc
29blacklist ${HOME}/.config/qpdfview
29 30
30# Media players 31# Media players
31blacklist ${HOME}/.config/cmus 32blacklist ${HOME}/.config/cmus
@@ -135,6 +136,7 @@ blacklist ${HOME}/.local/share/totem
135blacklist ${HOME}/.local/share/psi+ 136blacklist ${HOME}/.local/share/psi+
136blacklist ${HOME}/.local/share/pix 137blacklist ${HOME}/.local/share/pix
137blacklist ${HOME}/.local/share/gnome-chess 138blacklist ${HOME}/.local/share/gnome-chess
139blacklist ${HOME}/.local/share/qpdfview
138 140
139# ssh 141# ssh
140blacklist /tmp/ssh-* 142blacklist /tmp/ssh-*
diff --git a/etc/mupdf.profile b/etc/mupdf.profile
new file mode 100644
index 000000000..6f2db511b
--- /dev/null
+++ b/etc/mupdf.profile
@@ -0,0 +1,18 @@
1# mupdf reader profile
2include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc
4include /etc/firejail/disable-devel.inc
5include /etc/firejail/disable-passwdmgr.inc
6
7caps.drop all
8nogroups
9nonewprivs
10noroot
11nosound
12protocol unix
13seccomp
14shell none
15tracelog
16
17private-tmp
18private-dev
diff --git a/etc/qpdfview.profile b/etc/qpdfview.profile
new file mode 100644
index 000000000..07ea173e6
--- /dev/null
+++ b/etc/qpdfview.profile
@@ -0,0 +1,22 @@
1# qpdfview profile
2noblacklist ${HOME}/.config/qpdfview
3noblacklist ${HOME}/.local/share/qpdfview
4
5include /etc/firejail/disable-common.inc
6include /etc/firejail/disable-programs.inc
7include /etc/firejail/disable-devel.inc
8include /etc/firejail/disable-passwdmgr.inc
9
10caps.drop all
11nogroups
12nonewprivs
13noroot
14nosound
15protocol unix
16seccomp
17shell none
18tracelog
19
20private-bin qpdfview
21private-tmp
22private-dev