diff options
-rw-r--r-- | README | 19 | ||||
-rw-r--r-- | README.md | 3 | ||||
-rw-r--r-- | RELNOTES | 8 | ||||
-rw-r--r-- | etc/profile-m-z/mate-color-select.profile | 1 | ||||
-rw-r--r-- | etc/profile-m-z/virtualbox.profile | 2 |
5 files changed, 29 insertions, 4 deletions
@@ -77,6 +77,9 @@ Aidan Gauland (https://github.com/aidalgol) | |||
77 | - whitelist Bohemia Interactive config dir for Steam | 77 | - whitelist Bohemia Interactive config dir for Steam |
78 | Akhil Hans Maulloo (https://github.com/kouul) | 78 | Akhil Hans Maulloo (https://github.com/kouul) |
79 | - xz profile | 79 | - xz profile |
80 | Albin Kauffmann (https://github.com/albinou) | ||
81 | - Firefox and Chromium profile fixes | ||
82 | - info to allow screen sharing in profiles | ||
80 | Alexey Kuznetsov (kuznet@ms2.inr.ac.ru) | 83 | Alexey Kuznetsov (kuznet@ms2.inr.ac.ru) |
81 | - src/lib/libnetlink.c extracted from iproute2 software package | 84 | - src/lib/libnetlink.c extracted from iproute2 software package |
82 | Aleksey Manevich (https://github.com/manevich) | 85 | Aleksey Manevich (https://github.com/manevich) |
@@ -166,9 +169,12 @@ Barış Ekin Yıldırım (https://github.com/circuitshaker) | |||
166 | - removing net none from code.profile | 169 | - removing net none from code.profile |
167 | bbhtt (https://github.com/bbhtt) | 170 | bbhtt (https://github.com/bbhtt) |
168 | - improvements to balsa,fractal,gajim,trojita profiles | 171 | - improvements to balsa,fractal,gajim,trojita profiles |
169 | - improvements to nheko, spectral, feh, links, lynx profiles | 172 | - improvements to nheko, spectral, feh, links, lynx, smplayer, profiles |
170 | - added alacartem com.github.bleakgrey.tootle, photoflare profiles | 173 | - added alacartem com.github.bleakgrey.tootle, photoflare profiles |
171 | - add profiles for MS Edge dev build for Linux and Librewolf | 174 | - add profiles for MS Edge dev build for Linux and Librewolf |
175 | - fixes to cheese, authneticator, liferea | ||
176 | - add profile for straw-viewer | ||
177 | - email clients whitelisting and fixes | ||
172 | Benjamin Kampmann (https://github.com/ligthyear) | 178 | Benjamin Kampmann (https://github.com/ligthyear) |
173 | - Forward exit code from child process | 179 | - Forward exit code from child process |
174 | bitfreak25 (https://github.com/bitfreak25) | 180 | bitfreak25 (https://github.com/bitfreak25) |
@@ -453,6 +459,8 @@ Impyy (https://github.com/Impyy) | |||
453 | - added mumble profile | 459 | - added mumble profile |
454 | intika (https://github.com/intika) | 460 | intika (https://github.com/intika) |
455 | - added musixmatch profile | 461 | - added musixmatch profile |
462 | irandms (https://github.com/irandms) | ||
463 | - man firecfg fixes | ||
456 | irregulator (https://github.com/irregulator) | 464 | irregulator (https://github.com/irregulator) |
457 | - thunderbird profile fixes for debian stretch | 465 | - thunderbird profile fixes for debian stretch |
458 | Irvine (https://github.com/Irvinehimself) | 466 | Irvine (https://github.com/Irvinehimself) |
@@ -799,7 +807,9 @@ Simon Peter (https://github.com/probonopd) | |||
799 | sinkuu (https://github.com/sinkuu) | 807 | sinkuu (https://github.com/sinkuu) |
800 | - blacklisting kwalletd | 808 | - blacklisting kwalletd |
801 | - fix symlink invocation for programs placing symlinks in $PATH | 809 | - fix symlink invocation for programs placing symlinks in $PATH |
802 | smithsohu (https://github.com/smitsohu) | 810 | Simo Piiroinen (https://github.com/spiiroin) |
811 | - Jolla/SailfishOS patches | ||
812 | smitsohu (https://github.com/smitsohu) | ||
803 | - read-only kde4 services directory | 813 | - read-only kde4 services directory |
804 | - enhanced mediathekview profile | 814 | - enhanced mediathekview profile |
805 | - added tuxguitar profile | 815 | - added tuxguitar profile |
@@ -914,6 +924,8 @@ Tom Mellor (https://github.com/kalegrill) | |||
914 | - mupen64plus profile | 924 | - mupen64plus profile |
915 | Tomasz Jan Góralczyk (https://github.com/tjg) | 925 | Tomasz Jan Góralczyk (https://github.com/tjg) |
916 | - fixed Steam profile | 926 | - fixed Steam profile |
927 | Tomi Leppänen (https://github.com/Tomin1) | ||
928 | - Jolla/SailfishOS patches | ||
917 | Topi Miettinen (https://github.com/topimiettinen) | 929 | Topi Miettinen (https://github.com/topimiettinen) |
918 | - improved seccomp printing | 930 | - improved seccomp printing |
919 | - improve mount handling, fix /run/user handling | 931 | - improve mount handling, fix /run/user handling |
@@ -1012,4 +1024,7 @@ Zack Weinberg (https://github.com/zackw) | |||
1012 | with firejail --x11 | 1024 | with firejail --x11 |
1013 | - support for xpra-extra-params in firejail.config | 1025 | - support for xpra-extra-params in firejail.config |
1014 | 1026 | ||
1027 | zupatisc (https://github.com/zupatisc) | ||
1028 | - patch-util fix | ||
1029 | |||
1015 | Copyright (C) 2014-2021 Firejail Authors | 1030 | Copyright (C) 2014-2021 Firejail Authors |
@@ -330,4 +330,5 @@ Stats: | |||
330 | 330 | ||
331 | ### New profiles: | 331 | ### New profiles: |
332 | 332 | ||
333 | vmware-view, display-im6.q16, ipcalc, ipcalc-ng, ebook-convert, ebook-edit, ebook-meta, ebook-polish, lzop, gget | 333 | vmware-view, display-im6.q16, ipcalc, ipcalc-ng, ebook-convert, ebook-edit, ebook-meta, ebook-polish, lzop. |
334 | avidemux, calligragemini, vmware-player, vmware-workstation, gget \ No newline at end of file | ||
@@ -2,8 +2,14 @@ firejail (0.9.65) baseline; urgency=low | |||
2 | * filtering environment variables | 2 | * filtering environment variables |
3 | * zsh completion | 3 | * zsh completion |
4 | * --mkdir, --mkfile | 4 | * --mkdir, --mkfile |
5 | * Jolla/SailfishOS patches | ||
6 | * privatelib rework | ||
7 | * jailtest | ||
8 | * capabilities list update | ||
9 | * faccessat2 syscall support | ||
5 | * new profiles: vmware-view, display-im6.q16, ipcalc, ipcalc-ng | 10 | * new profiles: vmware-view, display-im6.q16, ipcalc, ipcalc-ng |
6 | * ebook-convert, ebook-edit, ebook-meta, ebook-polish, lzop | 11 | * ebook-convert, ebook-edit, ebook-meta, ebook-polish, lzop, |
12 | * avidemux, calligragemini, vmware-player, vmware-workstation | ||
7 | * gget | 13 | * gget |
8 | -- netblue30 <netblue30@yahoo.com> Tue, 9 Feb 2021 09:00:00 -0500 | 14 | -- netblue30 <netblue30@yahoo.com> Tue, 9 Feb 2021 09:00:00 -0500 |
9 | 15 | ||
diff --git a/etc/profile-m-z/mate-color-select.profile b/etc/profile-m-z/mate-color-select.profile index b6dc643d4..d30965922 100644 --- a/etc/profile-m-z/mate-color-select.profile +++ b/etc/profile-m-z/mate-color-select.profile | |||
@@ -15,6 +15,7 @@ include disable-shell.inc | |||
15 | 15 | ||
16 | include whitelist-common.inc | 16 | include whitelist-common.inc |
17 | 17 | ||
18 | apparmor | ||
18 | caps.drop all | 19 | caps.drop all |
19 | netfilter | 20 | netfilter |
20 | no3d | 21 | no3d |
diff --git a/etc/profile-m-z/virtualbox.profile b/etc/profile-m-z/virtualbox.profile index 7a49ad88a..232ff8ae4 100644 --- a/etc/profile-m-z/virtualbox.profile +++ b/etc/profile-m-z/virtualbox.profile | |||
@@ -34,6 +34,7 @@ include whitelist-var-common.inc | |||
34 | 34 | ||
35 | # For host-only network sys_admin is needed. See https://github.com/netblue30/firejail/issues/2868#issuecomment-518647630 | 35 | # For host-only network sys_admin is needed. See https://github.com/netblue30/firejail/issues/2868#issuecomment-518647630 |
36 | 36 | ||
37 | apparmor | ||
37 | caps.keep net_raw,sys_nice | 38 | caps.keep net_raw,sys_nice |
38 | netfilter | 39 | netfilter |
39 | nodvd | 40 | nodvd |
@@ -45,6 +46,7 @@ tracelog | |||
45 | #disable-mnt | 46 | #disable-mnt |
46 | private-cache | 47 | private-cache |
47 | private-etc alsa,asound.conf,ca-certificates,conf.d,crypto-policies,dconf,fonts,hostname,hosts,ld.so.cache,localtime,machine-id,pki,pulse,resolv.conf,ssl | 48 | private-etc alsa,asound.conf,ca-certificates,conf.d,crypto-policies,dconf,fonts,hostname,hosts,ld.so.cache,localtime,machine-id,pki,pulse,resolv.conf,ssl |
49 | private-tmp | ||
48 | 50 | ||
49 | dbus-user none | 51 | dbus-user none |
50 | dbus-system none | 52 | dbus-system none |