summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
-rw-r--r--README.md2
-rw-r--r--RELNOTES8
-rw-r--r--etc/disable-passwdmgr.inc1
-rw-r--r--etc/enpass.profile39
-rw-r--r--etc/runenpass.sh.profile6
-rw-r--r--src/firecfg/firecfg.config1
6 files changed, 52 insertions, 5 deletions
diff --git a/README.md b/README.md
index c65e7f1fe..b1e3cbbca 100644
--- a/README.md
+++ b/README.md
@@ -221,7 +221,7 @@ calligrawords, cin, dooble, dooble-qt4, fetchmail, freecad, freecadcmd, google-e
221imagej, karbon, kdenlive, krita, linphone, lmms, macrofusion, mpd, natron, Natron, 221imagej, karbon, kdenlive, krita, linphone, lmms, macrofusion, mpd, natron, Natron,
222ricochet, shotcut, teamspeak3, tor, tor-browser-en, Viber, x-terminal-emulator, zart, 222ricochet, shotcut, teamspeak3, tor, tor-browser-en, Viber, x-terminal-emulator, zart,
223conky, arch-audit, ffmpeg, bluefish, cliqz, cinelerra, openshot-qt, pinta, uefitool, 223conky, arch-audit, ffmpeg, bluefish, cliqz, cinelerra, openshot-qt, pinta, uefitool,
224aosp, pdfmod, gnome-ring, signal-desktop, xcalc, zaproxy, kopete, kget, nheko 224aosp, pdfmod, gnome-ring, signal-desktop, xcalc, zaproxy, kopete, kget, nheko, Enpass
225 225
226Upstreamed many profiles from the following sources: https://github.com/chiraag-nataraj/firejail-profiles, 226Upstreamed many profiles from the following sources: https://github.com/chiraag-nataraj/firejail-profiles,
227https://github.com/nyancat18/fe, and https://aur.archlinux.org/packages/firejail-profiles. 227https://github.com/nyancat18/fe, and https://aur.archlinux.org/packages/firejail-profiles.
diff --git a/RELNOTES b/RELNOTES
index e5adc0fa5..2f9206518 100644
--- a/RELNOTES
+++ b/RELNOTES
@@ -30,15 +30,15 @@ firejail (0.9.51) baseline; urgency=low
30 https://aur.archlinux.org/packages/firejail-profiles. 30 https://aur.archlinux.org/packages/firejail-profiles.
31 * new profiles: terasology, surf, rocketchat, clamscan, clamdscan, 31 * new profiles: terasology, surf, rocketchat, clamscan, clamdscan,
32 clamdtop, freshclam, xmr-stak-cpu, amule, ardour4, ardour5, 32 clamdtop, freshclam, xmr-stak-cpu, amule, ardour4, ardour5,
33 brackets, calligra, calligraauthor, calligraconverter, calligraflow, 33 brackets, calligra, calligraauthor, calligraconverter, calligraflow,
34 calligraplan, calligraplanwork, calligrasheets, calligrastage, 34 calligraplan, calligraplanwork, calligrasheets, calligrastage,
35 calligrawords, cin, dooble, dooble-qt4, fetchmail, freecad, freecadcmd, 35 calligrawords, cin, dooble, dooble-qt4, fetchmail, freecad, freecadcmd,
36 google-earth,imagej, karbon, kdenlive, krita, linphone, lmms, macrofusion, 36 google-earth,imagej, karbon, kdenlive, krita, linphone, lmms, macrofusion,
37 mpd, natron, Natron, ricochet, shotcut, teamspeak3, tor, tor-browser-en, 37 mpd, natron, Natron, ricochet, shotcut, teamspeak3, tor, tor-browser-en,
38 Viber, x-terminal-emulator, zart, conky, arch-audit, ffmpeg, bluefish, 38 Viber, x-terminal-emulator, zart, conky, arch-audit, ffmpeg, bluefish,
39 cinelerra, openshot-qt, pinta, uefitool, aosp, pdfmod, gnome-ring, 39 cinelerra, openshot-qt, pinta, uefitool, aosp, pdfmod, gnome-ring,
40 xcalc, zaproxy, kopete, cliqz, signal-desktop, kget, nheko 40 xcalc, zaproxy, kopete, cliqz, signal-desktop, kget, nheko, Enpass
41 41
42 -- netblue30 <netblue30@yahoo.com> Thu, 14 Sep 2017 20:00:00 -0500 42 -- netblue30 <netblue30@yahoo.com> Thu, 14 Sep 2017 20:00:00 -0500
43 43
44firejail (0.9.50~rc1) baseline; urgency=low 44firejail (0.9.50~rc1) baseline; urgency=low
diff --git a/etc/disable-passwdmgr.inc b/etc/disable-passwdmgr.inc
index 9507d3feb..8ed87eefb 100644
--- a/etc/disable-passwdmgr.inc
+++ b/etc/disable-passwdmgr.inc
@@ -6,6 +6,7 @@ blacklist ${HOME}/.config/KeePass
6blacklist ${HOME}/.config/keepass 6blacklist ${HOME}/.config/keepass
7blacklist ${HOME}/.config/keepassx 7blacklist ${HOME}/.config/keepassx
8blacklist ${HOME}/.config/keepassxc 8blacklist ${HOME}/.config/keepassxc
9blacklist ${HOME}/.config/Sinew Software Systems
9blacklist ${HOME}/.keepass 10blacklist ${HOME}/.keepass
10blacklist ${HOME}/.keepassx 11blacklist ${HOME}/.keepassx
11blacklist ${HOME}/.keepassxc 12blacklist ${HOME}/.keepassxc
diff --git a/etc/enpass.profile b/etc/enpass.profile
new file mode 100644
index 000000000..4c19d5825
--- /dev/null
+++ b/etc/enpass.profile
@@ -0,0 +1,39 @@
1# This file is overwritten after every install/update.
2# Persistent local customisations
3include /etc/firejail/enpass.local
4# Persistent global definitions
5include /etc/firejail/globals.local
6
7include /etc/firejail/disable-common.inc
8include /etc/firejail/disable-devel.inc
9include /etc/firejail/disable-passwdmgr.inc
10include /etc/firejail/disable-programs.inc
11
12noblacklist ${HOME}/.config/Sinew Software Systems
13
14include /etc/firejail/whitelist-var-common.inc
15
16caps.drop all
17machine-id
18net none
19no3d
20nodvd
21nogroups
22nonewprivs
23noroot
24nosound
25notv
26novideo
27protocol unix
28seccomp
29shell none
30tracelog
31
32private-bin sh,readlink,dirname
33private-dev
34private-opt Enpass
35private-tmp
36
37memory-deny-write-execute
38noexec ${HOME}
39noexec /tmp
diff --git a/etc/runenpass.sh.profile b/etc/runenpass.sh.profile
new file mode 100644
index 000000000..05ffbfe20
--- /dev/null
+++ b/etc/runenpass.sh.profile
@@ -0,0 +1,6 @@
1# Firejail alias profile for enpass
2# This file is overwritten after every install/update
3
4
5# Redirect
6include /etc/firejail/enpass.profile
diff --git a/src/firecfg/firecfg.config b/src/firecfg/firecfg.config
index 56ff9a15b..28d3aab67 100644
--- a/src/firecfg/firecfg.config
+++ b/src/firecfg/firecfg.config
@@ -284,6 +284,7 @@ riot-web
284ristretto 284ristretto
285rocketchat 285rocketchat
286rtorrent 286rtorrent
287runenpass.sh
287scribus 288scribus
288sdat2img 289sdat2img
289seamonkey 290seamonkey