summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
-rw-r--r--etc/7z.profile1
-rw-r--r--etc/atom.profile6
-rw-r--r--etc/calligra.profile2
-rw-r--r--etc/cinelerra.profile31
-rw-r--r--etc/dia.profile3
-rw-r--r--etc/evince.profile1
-rw-r--r--etc/hugin.profile3
-rw-r--r--etc/inox.profile4
-rw-r--r--etc/libreoffice.profile1
-rw-r--r--etc/openshot-qt.profile31
-rw-r--r--etc/scribus.profile2
-rw-r--r--etc/synfigstudio.profile3
-rw-r--r--etc/tar.profile1
-rw-r--r--etc/unrar.profile1
-rw-r--r--etc/unzip.profile1
15 files changed, 16 insertions, 75 deletions
diff --git a/etc/7z.profile b/etc/7z.profile
index 53900bae6..ea67bbe19 100644
--- a/etc/7z.profile
+++ b/etc/7z.profile
@@ -17,7 +17,6 @@ notv
17novideo 17novideo
18shell none 18shell none
19tracelog 19tracelog
20caps.drop all
21 20
22private-dev 21private-dev
23 22
diff --git a/etc/atom.profile b/etc/atom.profile
index 6fb6048b6..34fb3a9b1 100644
--- a/etc/atom.profile
+++ b/etc/atom.profile
@@ -5,8 +5,6 @@ include /etc/firejail/atom.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noexec ${HOME}
9noexec /tmp
10noblacklist ~/.atom 8noblacklist ~/.atom
11noblacklist ~/.config/Atom 9noblacklist ~/.config/Atom
12 10
@@ -25,8 +23,10 @@ notv
25novideo 23novideo
26protocol unix,inet,inet6,netlink 24protocol unix,inet,inet6,netlink
27seccomp 25seccomp
28net none
29shell none 26shell none
30 27
31private-dev 28private-dev
32private-tmp 29private-tmp
30
31noexec ${HOME}
32noexec /tmp
diff --git a/etc/calligra.profile b/etc/calligra.profile
index 8c7e49121..d2b76d22c 100644
--- a/etc/calligra.profile
+++ b/etc/calligra.profile
@@ -12,6 +12,7 @@ include /etc/firejail/disable-programs.inc
12 12
13caps.drop all 13caps.drop all
14ipc-namespace 14ipc-namespace
15net none
15nodvd 16nodvd
16nogroups 17nogroups
17nonewprivs 18nonewprivs
@@ -21,7 +22,6 @@ novideo
21protocol unix 22protocol unix
22seccomp 23seccomp
23shell none 24shell none
24net none
25 25
26private-bin calligra,calligraauthor,calligraconverter,calligraflow,calligraplan,calligraplanwork,calligrasheets,calligrastage,calligrawords,dbus-launch 26private-bin calligra,calligraauthor,calligraconverter,calligraflow,calligraplan,calligraplanwork,calligrasheets,calligrastage,calligrawords,dbus-launch
27private-dev 27private-dev
diff --git a/etc/cinelerra.profile b/etc/cinelerra.profile
index bd75a66a9..e6a1941b5 100644
--- a/etc/cinelerra.profile
+++ b/etc/cinelerra.profile
@@ -1,31 +1,6 @@
1# Firejail profile for cin 1# Firejail profile alias for cin
2# This file is overwritten after every install/update 2# This file is overwritten after every install/update
3# Persistent local customizations
4include /etc/firejail/cin.local
5# Persistent global definitions
6include /etc/firejail/globals.local
7 3
8noblacklist ${HOME}/.bcast
9 4
10include /etc/firejail/disable-common.inc 5# Redirect
11include /etc/firejail/disable-devel.inc 6include /etc/firejail/cin.profile
12include /etc/firejail/disable-passwdmgr.inc
13include /etc/firejail/disable-programs.inc
14
15caps.drop all
16ipc-namespace
17net none
18nodvd
19nogroups
20nonewprivs
21notv
22noroot
23protocol unix
24seccomp
25shell none
26
27private-bin cinelerra
28private-dev
29
30noexec ${HOME}
31noexec /tmp
diff --git a/etc/dia.profile b/etc/dia.profile
index 6915318c0..800c3bbf1 100644
--- a/etc/dia.profile
+++ b/etc/dia.profile
@@ -13,7 +13,7 @@ include /etc/firejail/disable-passwdmgr.inc
13include /etc/firejail/disable-programs.inc 13include /etc/firejail/disable-programs.inc
14 14
15caps.drop all 15caps.drop all
16netfilter 16net none
17no3d 17no3d
18nodvd 18nodvd
19nogroups 19nogroups
@@ -25,7 +25,6 @@ novideo
25protocol unix 25protocol unix
26seccomp 26seccomp
27shell none 27shell none
28net none
29 28
30disable-mnt 29disable-mnt
31#private-bin dia 30#private-bin dia
diff --git a/etc/evince.profile b/etc/evince.profile
index 5e7596352..f503b9a8e 100644
--- a/etc/evince.profile
+++ b/etc/evince.profile
@@ -28,7 +28,6 @@ protocol unix
28seccomp 28seccomp
29shell none 29shell none
30tracelog 30tracelog
31net none
32 31
33private-bin evince,evince-previewer,evince-thumbnailer 32private-bin evince,evince-previewer,evince-thumbnailer
34private-dev 33private-dev
diff --git a/etc/hugin.profile b/etc/hugin.profile
index dd7e326c6..64b6e0c69 100644
--- a/etc/hugin.profile
+++ b/etc/hugin.profile
@@ -13,7 +13,7 @@ include /etc/firejail/disable-passwdmgr.inc
13include /etc/firejail/disable-programs.inc 13include /etc/firejail/disable-programs.inc
14 14
15caps.drop all 15caps.drop all
16netfilter 16net none
17nodvd 17nodvd
18nogroups 18nogroups
19nonewprivs 19nonewprivs
@@ -24,7 +24,6 @@ novideo
24protocol unix 24protocol unix
25seccomp 25seccomp
26shell none 26shell none
27net none
28 27
29private-bin PTBatcherGUI,calibrate_lens_gui,hugin,hugin_stitch_project,align_image_stack,autooptimiser,celeste_standalone,checkpto,cpclean,cpfind,deghosting_mask,fulla,geocpset,hugin_executor,hugin_hdrmerge,hugin_lensdb,icpfind,linefind,nona,pano_modify,pano_trafo,pto_gen,pto_lensstack,pto_mask,pto_merge,pto_move,pto_template,pto_var,tca_correct,verdandi,vig_optimize,enblend 28private-bin PTBatcherGUI,calibrate_lens_gui,hugin,hugin_stitch_project,align_image_stack,autooptimiser,celeste_standalone,checkpto,cpclean,cpfind,deghosting_mask,fulla,geocpset,hugin_executor,hugin_hdrmerge,hugin_lensdb,icpfind,linefind,nona,pano_modify,pano_trafo,pto_gen,pto_lensstack,pto_mask,pto_merge,pto_move,pto_template,pto_var,tca_correct,verdandi,vig_optimize,enblend
30private-dev 29private-dev
diff --git a/etc/inox.profile b/etc/inox.profile
index ec8d12387..de4d6205b 100644
--- a/etc/inox.profile
+++ b/etc/inox.profile
@@ -21,10 +21,10 @@ whitelist ~/.config/inox
21whitelist ~/.pki 21whitelist ~/.pki
22include /etc/firejail/whitelist-common.inc 22include /etc/firejail/whitelist-common.inc
23 23
24caps.keep sys_chroot,sys_admin
24netfilter 25netfilter
25nodvd 26nodvd
26notv
27nogroups 27nogroups
28noroot 28noroot
29notv
29shell none 30shell none
30caps.keep sys_chroot,sys_admin \ No newline at end of file
diff --git a/etc/libreoffice.profile b/etc/libreoffice.profile
index 9acdc3789..8d05a557c 100644
--- a/etc/libreoffice.profile
+++ b/etc/libreoffice.profile
@@ -27,7 +27,6 @@ protocol unix,inet,inet6
27seccomp 27seccomp
28shell none 28shell none
29tracelog 29tracelog
30net none
31 30
32private-dev 31private-dev
33 32
diff --git a/etc/openshot-qt.profile b/etc/openshot-qt.profile
index 02f4665d6..cbd1f8fe8 100644
--- a/etc/openshot-qt.profile
+++ b/etc/openshot-qt.profile
@@ -1,31 +1,6 @@
1# Firejail profile for openshot 1# Firejail profile alias for openshot
2# This file is overwritten after every install/update 2# This file is overwritten after every install/update
3# Persistent local customizations
4include /etc/firejail/openshot.local
5# Persistent global definitions
6include /etc/firejail/globals.local
7 3
8noblacklist ${HOME}/.openshot
9noblacklist ${HOME}/.openshot_qt
10 4
11include /etc/firejail/disable-common.inc 5# Redirect
12include /etc/firejail/disable-devel.inc 6include /etc/firejail/openshot.profile
13include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc
15
16caps.drop all
17netfilter
18nodvd
19nogroups
20nonewprivs
21noroot
22notv
23protocol unix,inet,inet6,netlink
24seccomp
25shell none
26
27private-dev
28private-tmp
29
30noexec ${HOME}
31noexec /tmp
diff --git a/etc/scribus.profile b/etc/scribus.profile
index a6e86a7d6..38f1e5b3c 100644
--- a/etc/scribus.profile
+++ b/etc/scribus.profile
@@ -27,6 +27,7 @@ include /etc/firejail/disable-passwdmgr.inc
27include /etc/firejail/disable-programs.inc 27include /etc/firejail/disable-programs.inc
28 28
29caps.drop all 29caps.drop all
30net none
30nodvd 31nodvd
31nogroups 32nogroups
32nonewprivs 33nonewprivs
@@ -36,7 +37,6 @@ notv
36novideo 37novideo
37protocol unix 38protocol unix
38seccomp 39seccomp
39net none
40tracelog 40tracelog
41 41
42#private-bin scribus,gs 42#private-bin scribus,gs
diff --git a/etc/synfigstudio.profile b/etc/synfigstudio.profile
index 1758659f2..2617c0e51 100644
--- a/etc/synfigstudio.profile
+++ b/etc/synfigstudio.profile
@@ -14,7 +14,7 @@ include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc 14include /etc/firejail/disable-programs.inc
15 15
16caps.drop all 16caps.drop all
17netfilter 17net none
18nodvd 18nodvd
19nogroups 19nogroups
20nonewprivs 20nonewprivs
@@ -25,7 +25,6 @@ novideo
25protocol unix 25protocol unix
26seccomp 26seccomp
27shell none 27shell none
28net none
29 28
30#private-bin synfigstudio,synfig,ffmpeg 29#private-bin synfigstudio,synfig,ffmpeg
31private-dev 30private-dev
diff --git a/etc/tar.profile b/etc/tar.profile
index 6ac530b15..f14894c25 100644
--- a/etc/tar.profile
+++ b/etc/tar.profile
@@ -18,7 +18,6 @@ notv
18novideo 18novideo
19shell none 19shell none
20tracelog 20tracelog
21caps.drop all
22 21
23# support compressed archives 22# support compressed archives
24private-bin sh,bash,dash,tar,gtar,compress,gzip,lzma,xz,bzip2,lbzip2,lzip,lzop 23private-bin sh,bash,dash,tar,gtar,compress,gzip,lzma,xz,bzip2,lbzip2,lzip,lzop
diff --git a/etc/unrar.profile b/etc/unrar.profile
index 881572521..12559a721 100644
--- a/etc/unrar.profile
+++ b/etc/unrar.profile
@@ -18,7 +18,6 @@ notv
18novideo 18novideo
19shell none 19shell none
20tracelog 20tracelog
21caps.drop all
22 21
23private-bin unrar 22private-bin unrar
24private-dev 23private-dev
diff --git a/etc/unzip.profile b/etc/unzip.profile
index f913385fb..9828fa9b4 100644
--- a/etc/unzip.profile
+++ b/etc/unzip.profile
@@ -18,7 +18,6 @@ notv
18novideo 18novideo
19shell none 19shell none
20tracelog 20tracelog
21caps.drop all
22 21
23private-bin unzip 22private-bin unzip
24private-dev 23private-dev