aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
-rw-r--r--README.md2
-rw-r--r--RELNOTES2
-rw-r--r--etc/default.profile2
-rw-r--r--etc/dia.profile26
-rw-r--r--etc/disable-programs.inc4
-rw-r--r--etc/fontforge.profile26
-rw-r--r--etc/geany.profile26
-rw-r--r--etc/hugin.profile27
-rw-r--r--platform/debian/conffiles4
-rw-r--r--src/firecfg/firecfg.config4
10 files changed, 120 insertions, 3 deletions
diff --git a/README.md b/README.md
index 67beef83b..9457da983 100644
--- a/README.md
+++ b/README.md
@@ -217,4 +217,4 @@ xed, pluma, Cryptocat, Bless, Gnome 2048, Gnome Calculator, Gnome Contacts, JD-G
217PDFSam, Pithos, Xonotic, wireshark, keepassx2, QupZilla, FossaMail, Uzbl browser, xmms, iridium browser, 217PDFSam, Pithos, Xonotic, wireshark, keepassx2, QupZilla, FossaMail, Uzbl browser, xmms, iridium browser,
218Kino, Thunar, Geeqie, Engrampa, Scribus, mousepad, gpicview, keepassxc, cvlc, MediathekView, baloo_file, 218Kino, Thunar, Geeqie, Engrampa, Scribus, mousepad, gpicview, keepassxc, cvlc, MediathekView, baloo_file,
219Nylas, dino, BibleTime, viewnior, Kodi, viking, youtube-dl, meld, Arduino, Akregator, KCalc, KTorrent, 219Nylas, dino, BibleTime, viewnior, Kodi, viking, youtube-dl, meld, Arduino, Akregator, KCalc, KTorrent,
220Orage Globaltime, Orage Clendar, xfce4-notes, xfce4-dict, Ristretto, PCManFM 220Orage Globaltime, Orage Clendar, xfce4-notes, xfce4-dict, Ristretto, PCManFM, Dia, FontForge, Geany, Hugin
diff --git a/RELNOTES b/RELNOTES
index a4615b240..7e92deed2 100644
--- a/RELNOTES
+++ b/RELNOTES
@@ -39,7 +39,7 @@ firejail (0.9.46-rc1) baseline; urgency=low
39 * new profiles: baloo_file, Nylas, dino, BibleTime, viewnior, Kodi, viking, 39 * new profiles: baloo_file, Nylas, dino, BibleTime, viewnior, Kodi, viking,
40 * new profiles: youtube-dl, meld, Arduino, Akregator, KCalc, KTorrent, 40 * new profiles: youtube-dl, meld, Arduino, Akregator, KCalc, KTorrent,
41 * new profiles: Orage Globaltime, Orage Clendar, xfce4-notes, xfce4-dict, 41 * new profiles: Orage Globaltime, Orage Clendar, xfce4-notes, xfce4-dict,
42 * new profiles: Ristretto, PCManFM 42 * new profiles: Ristretto, PCManFM, Dia, FontForge, Geany, Hugin
43 * bugfixes 43 * bugfixes
44 -- netblue30 <netblue30@yahoo.com> Fri, 7 Apr 2017 08:00:00 -0500 44 -- netblue30 <netblue30@yahoo.com> Fri, 7 Apr 2017 08:00:00 -0500
45 45
diff --git a/etc/default.profile b/etc/default.profile
index 66b04896f..484c1cd8e 100644
--- a/etc/default.profile
+++ b/etc/default.profile
@@ -25,4 +25,4 @@ seccomp
25# private-etc none 25# private-etc none
26# private-dev 26# private-dev
27# private-tmp 27# private-tmp
28 28# nosound
diff --git a/etc/dia.profile b/etc/dia.profile
new file mode 100644
index 000000000..3c01e9a0b
--- /dev/null
+++ b/etc/dia.profile
@@ -0,0 +1,26 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/dia.local
4
5noblacklist ~/.dia
6include /etc/firejail/disable-common.inc
7include /etc/firejail/disable-programs.inc
8include /etc/firejail/disable-passwdmgr.inc
9
10caps.drop all
11netfilter
12nonewprivs
13noroot
14protocol unix,inet,inet6
15seccomp
16
17#
18# depending on you usage, you can enable some of the commands below:
19#
20nogroups
21shell none
22# private-bin program
23# private-etc none
24private-dev
25private-tmp
26
diff --git a/etc/disable-programs.inc b/etc/disable-programs.inc
index 18b644987..285a7f7e3 100644
--- a/etc/disable-programs.inc
+++ b/etc/disable-programs.inc
@@ -74,6 +74,7 @@ blacklist ${HOME}/.config/evolution
74blacklist ${HOME}/.config/filezilla 74blacklist ${HOME}/.config/filezilla
75blacklist ${HOME}/.config/flowblade 75blacklist ${HOME}/.config/flowblade
76blacklist ${HOME}/.config/gajim 76blacklist ${HOME}/.config/gajim
77blacklist ${HOME}/.config/geany
77blacklist ${HOME}/.config/geeqie 78blacklist ${HOME}/.config/geeqie
78blacklist ${HOME}/.config/gedit 79blacklist ${HOME}/.config/gedit
79blacklist ${HOME}/.config/globaltime 80blacklist ${HOME}/.config/globaltime
@@ -148,6 +149,7 @@ blacklist ${HOME}/.config/xviewer
148blacklist ${HOME}/.config/zathura 149blacklist ${HOME}/.config/zathura
149blacklist ${HOME}/.config/zoomus.conf 150blacklist ${HOME}/.config/zoomus.conf
150blacklist ${HOME}/.conkeror.mozdev.org 151blacklist ${HOME}/.conkeror.mozdev.org
152blacklist ${HOME}/.dia
151blacklist ${HOME}/.dillo 153blacklist ${HOME}/.dillo
152blacklist ${HOME}/.dosbox 154blacklist ${HOME}/.dosbox
153blacklist ${HOME}/.dropbox-dist 155blacklist ${HOME}/.dropbox-dist
@@ -158,6 +160,7 @@ blacklist ${HOME}/.emacs.d
158blacklist ${HOME}/.filezilla 160blacklist ${HOME}/.filezilla
159blacklist ${HOME}/.flowblade 161blacklist ${HOME}/.flowblade
160blacklist ${HOME}/.fltk 162blacklist ${HOME}/.fltk
163blacklist ${HOME}/.FontForge
161blacklist ${HOME}/.gimp* 164blacklist ${HOME}/.gimp*
162blacklist ${HOME}/.git-credential-cache 165blacklist ${HOME}/.git-credential-cache
163blacklist ${HOME}/.gitconfig 166blacklist ${HOME}/.gitconfig
@@ -167,6 +170,7 @@ blacklist ${HOME}/.googleearth/myplaces.backup.kml
167blacklist ${HOME}/.googleearth/myplaces.kml 170blacklist ${HOME}/.googleearth/myplaces.kml
168blacklist ${HOME}/.guayadeque 171blacklist ${HOME}/.guayadeque
169blacklist ${HOME}/.hedgewars 172blacklist ${HOME}/.hedgewars
173blacklist ${HOME}/.hugin
170blacklist ${HOME}/.icedove 174blacklist ${HOME}/.icedove
171blacklist ${HOME}/.inkscape 175blacklist ${HOME}/.inkscape
172blacklist ${HOME}/.jitsi 176blacklist ${HOME}/.jitsi
diff --git a/etc/fontforge.profile b/etc/fontforge.profile
new file mode 100644
index 000000000..014d15650
--- /dev/null
+++ b/etc/fontforge.profile
@@ -0,0 +1,26 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/fontforge.local
4
5noblacklist ${HOME}/.FontForge
6include /etc/firejail/disable-common.inc
7include /etc/firejail/disable-programs.inc
8include /etc/firejail/disable-passwdmgr.inc
9
10caps.drop all
11netfilter
12nonewprivs
13noroot
14protocol unix,inet,inet6
15seccomp
16
17#
18# depending on you usage, you can enable some of the commands below:
19#
20nogroups
21shell none
22# private-bin program
23# private-etc none
24private-dev
25private-tmp
26
diff --git a/etc/geany.profile b/etc/geany.profile
new file mode 100644
index 000000000..8ccc44dc1
--- /dev/null
+++ b/etc/geany.profile
@@ -0,0 +1,26 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/geany.local
4
5noblacklist ${HOME}/.config/geany
6include /etc/firejail/disable-common.inc
7include /etc/firejail/disable-programs.inc
8include /etc/firejail/disable-passwdmgr.inc
9
10caps.drop all
11netfilter
12nonewprivs
13noroot
14protocol unix,inet,inet6
15seccomp
16
17#
18# depending on you usage, you can enable some of the commands below:
19#
20nogroups
21shell none
22# private-bin program
23# private-etc none
24private-dev
25private-tmp
26
diff --git a/etc/hugin.profile b/etc/hugin.profile
new file mode 100644
index 000000000..d2ad16c0e
--- /dev/null
+++ b/etc/hugin.profile
@@ -0,0 +1,27 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/hugin.local
4
5noblacklist ${HOME}/.hugin
6include /etc/firejail/disable-common.inc
7include /etc/firejail/disable-programs.inc
8include /etc/firejail/disable-passwdmgr.inc
9
10caps.drop all
11netfilter
12nonewprivs
13noroot
14protocol unix,inet,inet6
15seccomp
16
17#
18# depending on you usage, you can enable some of the commands below:
19#
20nogroups
21shell none
22# private-bin program
23# private-etc none
24private-dev
25private-tmp
26nosound
27
diff --git a/platform/debian/conffiles b/platform/debian/conffiles
index 2f0da51ce..fa910f957 100644
--- a/platform/debian/conffiles
+++ b/platform/debian/conffiles
@@ -277,3 +277,7 @@
277/etc/firejail/xfce4-dict.profile 277/etc/firejail/xfce4-dict.profile
278/etc/firejail/xfce4-notes.profile 278/etc/firejail/xfce4-notes.profile
279/etc/firejail/pcmanfm.profile 279/etc/firejail/pcmanfm.profile
280/etc/firejail/dia.profile
281/etc/firejail/fontforge.profile
282/etc/firejail/geany.profile
283/etc/firejail/hugin.profile
diff --git a/src/firecfg/firecfg.config b/src/firecfg/firecfg.config
index 93744f671..db3b525ff 100644
--- a/src/firecfg/firecfg.config
+++ b/src/firecfg/firecfg.config
@@ -34,6 +34,7 @@ cvlc
34cyberfox 34cyberfox
35deadbeef 35deadbeef
36deluge 36deluge
37dia
37dillo 38dillo
38dino 39dino
39display 40display
@@ -59,7 +60,9 @@ firefox
59firefox-esr 60firefox-esr
60flashpeak-slimjet 61flashpeak-slimjet
61flowblade 62flowblade
63fontforge
62gajim 64gajim
65geany
63gedit 66gedit
64geeqie 67geeqie
65gimp 68gimp
@@ -90,6 +93,7 @@ gwenview
90hedgewars 93hedgewars
91hexchat 94hexchat
92highlight 95highlight
96hugin
93icecat 97icecat
94icedove 98icedove
95iceweasel 99iceweasel