diff options
-rw-r--r-- | etc/bibletime.profile | 3 | ||||
-rw-r--r-- | etc/disable-programs.inc | 3 | ||||
-rw-r--r-- | etc/supertuxkart.profile | 55 | ||||
-rw-r--r-- | src/firecfg/firecfg.config | 1 | ||||
-rw-r--r-- | src/man/firejail.txt | 2 |
5 files changed, 61 insertions, 3 deletions
diff --git a/etc/bibletime.profile b/etc/bibletime.profile index 0691b32c3..ca8ab09bb 100644 --- a/etc/bibletime.profile +++ b/etc/bibletime.profile | |||
@@ -34,9 +34,8 @@ notv | |||
34 | nou2f | 34 | nou2f |
35 | novideo | 35 | novideo |
36 | protocol unix,inet,inet6,netlink | 36 | protocol unix,inet,inet6,netlink |
37 | seccomp | 37 | seccomp.drop @clock,@cpu-emulation,@debug,@module,@obsolete,@raw-io,@reboot,@resources,@swap,acct,add_key,bpf,fanotify_init,io_cancel,io_destroy,io_getevents,io_setup,io_submit,ioprio_set,kcmp,keyctl,mount,name_to_handle_at,nfsservctl,ni_syscall,open_by_handle_at,personality,pivot_root,process_vm_readv,ptrace,remap_file_pages,request_key,setdomainname,sethostname,syslog,umount,umount2,userfaultfd,vhangup,vmsplice |
38 | shell none | 38 | shell none |
39 | tracelog | ||
40 | 39 | ||
41 | # private-bin bibletime,qt5ct | 40 | # private-bin bibletime,qt5ct |
42 | private-dev | 41 | private-dev |
diff --git a/etc/disable-programs.inc b/etc/disable-programs.inc index 7e9d7be80..774852c2f 100644 --- a/etc/disable-programs.inc +++ b/etc/disable-programs.inc | |||
@@ -233,6 +233,7 @@ blacklist ${HOME}/.config/smplayer | |||
233 | blacklist ${HOME}/.config/smtube | 233 | blacklist ${HOME}/.config/smtube |
234 | blacklist ${HOME}/.config/specialmailcollectionsrc | 234 | blacklist ${HOME}/.config/specialmailcollectionsrc |
235 | blacklist ${HOME}/.config/spotify | 235 | blacklist ${HOME}/.config/spotify |
236 | blacklist ${HOME}/.config/supertuxkart | ||
236 | blacklist ${HOME}/.config/sqlitebrowser | 237 | blacklist ${HOME}/.config/sqlitebrowser |
237 | blacklist ${HOME}/.config/stellarium | 238 | blacklist ${HOME}/.config/stellarium |
238 | blacklist ${HOME}/.config/synfig | 239 | blacklist ${HOME}/.config/synfig |
@@ -461,6 +462,7 @@ blacklist ${HOME}/.local/share/scribus | |||
461 | blacklist ${HOME}/.local/share/spotify | 462 | blacklist ${HOME}/.local/share/spotify |
462 | blacklist ${HOME}/.local/share/steam | 463 | blacklist ${HOME}/.local/share/steam |
463 | blacklist ${HOME}/.local/share/supertux2 | 464 | blacklist ${HOME}/.local/share/supertux2 |
465 | blacklist ${HOME}/.local/share/supertuxkart | ||
464 | blacklist ${HOME}/.local/share/telepathy | 466 | blacklist ${HOME}/.local/share/telepathy |
465 | blacklist ${HOME}/.local/share/terasology | 467 | blacklist ${HOME}/.local/share/terasology |
466 | blacklist ${HOME}/.local/share/torbrowser | 468 | blacklist ${HOME}/.local/share/torbrowser |
@@ -617,6 +619,7 @@ blacklist ${HOME}/.cache/qutebrowser | |||
617 | blacklist ${HOME}/.cache/simple-scan | 619 | blacklist ${HOME}/.cache/simple-scan |
618 | blacklist ${HOME}/.cache/slimjet | 620 | blacklist ${HOME}/.cache/slimjet |
619 | blacklist ${HOME}/.cache/spotify | 621 | blacklist ${HOME}/.cache/spotify |
622 | blacklist ${HOME}/.cache/supertuxkart | ||
620 | blacklist ${HOME}/.cache/systemsettings | 623 | blacklist ${HOME}/.cache/systemsettings |
621 | blacklist ${HOME}/.cache/telepathy | 624 | blacklist ${HOME}/.cache/telepathy |
622 | blacklist ${HOME}/.cache/thunderbird | 625 | blacklist ${HOME}/.cache/thunderbird |
diff --git a/etc/supertuxkart.profile b/etc/supertuxkart.profile new file mode 100644 index 000000000..9f65a2fa1 --- /dev/null +++ b/etc/supertuxkart.profile | |||
@@ -0,0 +1,55 @@ | |||
1 | # Firejail profile for supertuxkart | ||
2 | # Description: Free kart racing game. | ||
3 | # This file is overwritten after every install/update | ||
4 | # Persistent local customizations | ||
5 | include supertuxkart.local | ||
6 | # Persistent global definitions | ||
7 | include globals.local | ||
8 | |||
9 | noblacklist ${HOME}/.config/supertuxkart | ||
10 | noblacklist ${HOME}/.cache/supertuxkart | ||
11 | noblacklist ${HOME}/.local/share/supertuxkart | ||
12 | |||
13 | include disable-common.inc | ||
14 | include disable-devel.inc | ||
15 | include disable-passwdmgr.inc | ||
16 | include disable-programs.inc | ||
17 | include disable-xdg.inc | ||
18 | include disable-interpreters.inc | ||
19 | |||
20 | mkdir ${HOME}/.config/supertuxkart | ||
21 | mkdir ${HOME}/.cache/supertuxkart | ||
22 | mkdir ${HOME}/.local/share/supertuxkart | ||
23 | whitelist ${HOME}/.config/supertuxkart | ||
24 | whitelist ${HOME}/.cache/supertuxkart | ||
25 | whitelist ${HOME}/.local/share/supertuxkart | ||
26 | include whitelist-common.inc | ||
27 | include whitelist-var-common.inc | ||
28 | |||
29 | apparmor | ||
30 | caps.drop all | ||
31 | netfilter | ||
32 | nodbus | ||
33 | nodvd | ||
34 | nogroups | ||
35 | nonewprivs | ||
36 | noroot | ||
37 | notv | ||
38 | nou2f | ||
39 | novideo | ||
40 | protocol unix,inet,inet6 | ||
41 | seccomp | ||
42 | shell none | ||
43 | tracelog | ||
44 | |||
45 | disable-mnt | ||
46 | private-bin supertuxkart | ||
47 | private-cache | ||
48 | private-dev | ||
49 | private-etc resolv.conf,ca-certificates,ssl,hosts,machine-id,xdg,openal,crypto-policies,pki,drirc,system-fips,selinux | ||
50 | private-tmp | ||
51 | private-opt none | ||
52 | private-srv none | ||
53 | |||
54 | noexec ${HOME} | ||
55 | noexec /tmp | ||
diff --git a/src/firecfg/firecfg.config b/src/firecfg/firecfg.config index bfba93190..f36455c89 100644 --- a/src/firecfg/firecfg.config +++ b/src/firecfg/firecfg.config | |||
@@ -403,6 +403,7 @@ steam-native | |||
403 | stellarium | 403 | stellarium |
404 | strings | 404 | strings |
405 | supertux2 | 405 | supertux2 |
406 | supertuxkart | ||
406 | surf | 407 | surf |
407 | sylpheed | 408 | sylpheed |
408 | synfigstudio | 409 | synfigstudio |
diff --git a/src/man/firejail.txt b/src/man/firejail.txt index 9c1133756..2d0bd26d0 100644 --- a/src/man/firejail.txt +++ b/src/man/firejail.txt | |||
@@ -2676,7 +2676,7 @@ Option \-\-netstats prints network statistics for active sandboxes installing ne | |||
2676 | 2676 | ||
2677 | 2677 | ||
2678 | Listed below are the available fields (columns) in alphabetical | 2678 | Listed below are the available fields (columns) in alphabetical |
2679 | order for \-\-top and \-\-netstat options: | 2679 | order for \-\-top and \-\-netstats options: |
2680 | 2680 | ||
2681 | .TP | 2681 | .TP |
2682 | Command | 2682 | Command |