aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
-rw-r--r--etc/bibletime.profile3
-rw-r--r--etc/disable-programs.inc3
-rw-r--r--etc/supertuxkart.profile55
-rw-r--r--src/firecfg/firecfg.config1
-rw-r--r--src/man/firejail.txt2
5 files changed, 61 insertions, 3 deletions
diff --git a/etc/bibletime.profile b/etc/bibletime.profile
index 0691b32c3..ca8ab09bb 100644
--- a/etc/bibletime.profile
+++ b/etc/bibletime.profile
@@ -34,9 +34,8 @@ notv
34nou2f 34nou2f
35novideo 35novideo
36protocol unix,inet,inet6,netlink 36protocol unix,inet,inet6,netlink
37seccomp 37seccomp.drop @clock,@cpu-emulation,@debug,@module,@obsolete,@raw-io,@reboot,@resources,@swap,acct,add_key,bpf,fanotify_init,io_cancel,io_destroy,io_getevents,io_setup,io_submit,ioprio_set,kcmp,keyctl,mount,name_to_handle_at,nfsservctl,ni_syscall,open_by_handle_at,personality,pivot_root,process_vm_readv,ptrace,remap_file_pages,request_key,setdomainname,sethostname,syslog,umount,umount2,userfaultfd,vhangup,vmsplice
38shell none 38shell none
39tracelog
40 39
41# private-bin bibletime,qt5ct 40# private-bin bibletime,qt5ct
42private-dev 41private-dev
diff --git a/etc/disable-programs.inc b/etc/disable-programs.inc
index 7e9d7be80..774852c2f 100644
--- a/etc/disable-programs.inc
+++ b/etc/disable-programs.inc
@@ -233,6 +233,7 @@ blacklist ${HOME}/.config/smplayer
233blacklist ${HOME}/.config/smtube 233blacklist ${HOME}/.config/smtube
234blacklist ${HOME}/.config/specialmailcollectionsrc 234blacklist ${HOME}/.config/specialmailcollectionsrc
235blacklist ${HOME}/.config/spotify 235blacklist ${HOME}/.config/spotify
236blacklist ${HOME}/.config/supertuxkart
236blacklist ${HOME}/.config/sqlitebrowser 237blacklist ${HOME}/.config/sqlitebrowser
237blacklist ${HOME}/.config/stellarium 238blacklist ${HOME}/.config/stellarium
238blacklist ${HOME}/.config/synfig 239blacklist ${HOME}/.config/synfig
@@ -461,6 +462,7 @@ blacklist ${HOME}/.local/share/scribus
461blacklist ${HOME}/.local/share/spotify 462blacklist ${HOME}/.local/share/spotify
462blacklist ${HOME}/.local/share/steam 463blacklist ${HOME}/.local/share/steam
463blacklist ${HOME}/.local/share/supertux2 464blacklist ${HOME}/.local/share/supertux2
465blacklist ${HOME}/.local/share/supertuxkart
464blacklist ${HOME}/.local/share/telepathy 466blacklist ${HOME}/.local/share/telepathy
465blacklist ${HOME}/.local/share/terasology 467blacklist ${HOME}/.local/share/terasology
466blacklist ${HOME}/.local/share/torbrowser 468blacklist ${HOME}/.local/share/torbrowser
@@ -617,6 +619,7 @@ blacklist ${HOME}/.cache/qutebrowser
617blacklist ${HOME}/.cache/simple-scan 619blacklist ${HOME}/.cache/simple-scan
618blacklist ${HOME}/.cache/slimjet 620blacklist ${HOME}/.cache/slimjet
619blacklist ${HOME}/.cache/spotify 621blacklist ${HOME}/.cache/spotify
622blacklist ${HOME}/.cache/supertuxkart
620blacklist ${HOME}/.cache/systemsettings 623blacklist ${HOME}/.cache/systemsettings
621blacklist ${HOME}/.cache/telepathy 624blacklist ${HOME}/.cache/telepathy
622blacklist ${HOME}/.cache/thunderbird 625blacklist ${HOME}/.cache/thunderbird
diff --git a/etc/supertuxkart.profile b/etc/supertuxkart.profile
new file mode 100644
index 000000000..9f65a2fa1
--- /dev/null
+++ b/etc/supertuxkart.profile
@@ -0,0 +1,55 @@
1# Firejail profile for supertuxkart
2# Description: Free kart racing game.
3# This file is overwritten after every install/update
4# Persistent local customizations
5include supertuxkart.local
6# Persistent global definitions
7include globals.local
8
9noblacklist ${HOME}/.config/supertuxkart
10noblacklist ${HOME}/.cache/supertuxkart
11noblacklist ${HOME}/.local/share/supertuxkart
12
13include disable-common.inc
14include disable-devel.inc
15include disable-passwdmgr.inc
16include disable-programs.inc
17include disable-xdg.inc
18include disable-interpreters.inc
19
20mkdir ${HOME}/.config/supertuxkart
21mkdir ${HOME}/.cache/supertuxkart
22mkdir ${HOME}/.local/share/supertuxkart
23whitelist ${HOME}/.config/supertuxkart
24whitelist ${HOME}/.cache/supertuxkart
25whitelist ${HOME}/.local/share/supertuxkart
26include whitelist-common.inc
27include whitelist-var-common.inc
28
29apparmor
30caps.drop all
31netfilter
32nodbus
33nodvd
34nogroups
35nonewprivs
36noroot
37notv
38nou2f
39novideo
40protocol unix,inet,inet6
41seccomp
42shell none
43tracelog
44
45disable-mnt
46private-bin supertuxkart
47private-cache
48private-dev
49private-etc resolv.conf,ca-certificates,ssl,hosts,machine-id,xdg,openal,crypto-policies,pki,drirc,system-fips,selinux
50private-tmp
51private-opt none
52private-srv none
53
54noexec ${HOME}
55noexec /tmp
diff --git a/src/firecfg/firecfg.config b/src/firecfg/firecfg.config
index bfba93190..f36455c89 100644
--- a/src/firecfg/firecfg.config
+++ b/src/firecfg/firecfg.config
@@ -403,6 +403,7 @@ steam-native
403stellarium 403stellarium
404strings 404strings
405supertux2 405supertux2
406supertuxkart
406surf 407surf
407sylpheed 408sylpheed
408synfigstudio 409synfigstudio
diff --git a/src/man/firejail.txt b/src/man/firejail.txt
index 9c1133756..2d0bd26d0 100644
--- a/src/man/firejail.txt
+++ b/src/man/firejail.txt
@@ -2676,7 +2676,7 @@ Option \-\-netstats prints network statistics for active sandboxes installing ne
2676 2676
2677 2677
2678Listed below are the available fields (columns) in alphabetical 2678Listed below are the available fields (columns) in alphabetical
2679order for \-\-top and \-\-netstat options: 2679order for \-\-top and \-\-netstats options:
2680 2680
2681.TP 2681.TP
2682Command 2682Command