aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
-rw-r--r--README.md2
-rw-r--r--RELNOTES2
-rw-r--r--etc/disable-programs.inc1
-rw-r--r--etc/minetest.profile39
-rw-r--r--platform/debian/conffiles1
-rw-r--r--src/firecfg/firecfg.config1
6 files changed, 44 insertions, 2 deletions
diff --git a/README.md b/README.md
index 5c193ce77..26b76361e 100644
--- a/README.md
+++ b/README.md
@@ -223,4 +223,4 @@ IntelliJ IDEA, Android Studio, electron, riot-web,
223Extreme Tux Racer, Frozen Bubble, Open Invaders, Pingus, Simutrans, SuperTux, 223Extreme Tux Racer, Frozen Bubble, Open Invaders, Pingus, Simutrans, SuperTux,
224telegram-desktop, arm, rambox, apktool, baobab, dex2jar, gitg, hashcat, obs, picard, 224telegram-desktop, arm, rambox, apktool, baobab, dex2jar, gitg, hashcat, obs, picard,
225remmina, sdat2img, soundconverter, sqlitebrowse, truecraft, gnome-twitch, tuxguitar, 225remmina, sdat2img, soundconverter, sqlitebrowse, truecraft, gnome-twitch, tuxguitar,
226musescore, neverball, Yandex Browser 226musescore, neverball, Yandex Browser, minetest
diff --git a/RELNOTES b/RELNOTES
index 68b8a6bbd..47b337c2f 100644
--- a/RELNOTES
+++ b/RELNOTES
@@ -28,7 +28,7 @@ firejail (0.9.50~rc1) baseline; urgency=low
28 * new profiles: telegram-desktop, arm, rambox, apktool, baobab, dex2jar, gitg, 28 * new profiles: telegram-desktop, arm, rambox, apktool, baobab, dex2jar, gitg,
29 * new profiles: hashcat, obs, picard, remmina, sdat2img, soundconverter 29 * new profiles: hashcat, obs, picard, remmina, sdat2img, soundconverter
30 * new profiles: truecraft, gnome-twitch, tuxguitar, musescore, neverball 30 * new profiles: truecraft, gnome-twitch, tuxguitar, musescore, neverball
31 * new profiles: sqlitebrowse, Yandex Browser 31 * new profiles: sqlitebrowse, Yandex Browser, minetest
32 * bugfixes 32 * bugfixes
33 -- netblue30 <netblue30@yahoo.com> Mon, 12 Jun 2017 20:00:00 -0500 33 -- netblue30 <netblue30@yahoo.com> Mon, 12 Jun 2017 20:00:00 -0500
34 34
diff --git a/etc/disable-programs.inc b/etc/disable-programs.inc
index 13ed3f212..7e44d582e 100644
--- a/etc/disable-programs.inc
+++ b/etc/disable-programs.inc
@@ -330,6 +330,7 @@ blacklist ${HOME}/.lv2
330blacklist ${HOME}/.mcabber 330blacklist ${HOME}/.mcabber
331blacklist ${HOME}/.mcabberrc 331blacklist ${HOME}/.mcabberrc
332blacklist ${HOME}/.mediathek3 332blacklist ${HOME}/.mediathek3
333blacklist ${HOME}/.minetest
333blacklist ${HOME}/.mozilla 334blacklist ${HOME}/.mozilla
334blacklist ${HOME}/.mpdconf 335blacklist ${HOME}/.mpdconf
335blacklist ${HOME}/.mplayer 336blacklist ${HOME}/.mplayer
diff --git a/etc/minetest.profile b/etc/minetest.profile
new file mode 100644
index 000000000..147328616
--- /dev/null
+++ b/etc/minetest.profile
@@ -0,0 +1,39 @@
1# Firejail profile for minetest
2# This file is overwritten after every install/update
3# Persistent local customizations
4include /etc/firejail/minetest.local
5# Persistent global definitions
6include /etc/firejail/globals.local
7
8noblacklist ${HOME}/.minetest
9
10include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-passwdmgr.inc
13include /etc/firejail/disable-programs.inc
14
15mkdir ${HOME}/.minetest
16whitelist ${HOME}/.minetest
17include /etc/firejail/whitelist-common.inc
18
19caps.drop all
20ipc-namespace
21netfilter
22nodvd
23nogroups
24nonewprivs
25noroot
26notv
27novideo
28protocol unix,inet,inet6
29seccomp
30shell none
31
32disable-mnt
33private-bin minetest
34private-dev
35private-etc asound.conf,ca-certificates,drirc,fonts,group,host.conf,hostname,hosts,ld.so.cache,ld.so.preload,localtime,nsswitch.conf,passwd,pulse,resolv.conf,ssl
36private-tmp
37
38noexec ${HOME}
39noexec /tmp
diff --git a/platform/debian/conffiles b/platform/debian/conffiles
index cf1c50ec6..d87d1fc08 100644
--- a/platform/debian/conffiles
+++ b/platform/debian/conffiles
@@ -209,6 +209,7 @@
209/etc/firejail/mediathekview.profile 209/etc/firejail/mediathekview.profile
210/etc/firejail/meld.profile 210/etc/firejail/meld.profile
211/etc/firejail/midori.profile 211/etc/firejail/midori.profile
212/etc/firejail/minetest.profile
212/etc/firejail/mousepad.profile 213/etc/firejail/mousepad.profile
213/etc/firejail/mplayer.profile 214/etc/firejail/mplayer.profile
214/etc/firejail/mpv.profile 215/etc/firejail/mpv.profile
diff --git a/src/firecfg/firecfg.config b/src/firecfg/firecfg.config
index 10a0cfd98..79b263823 100644
--- a/src/firecfg/firecfg.config
+++ b/src/firecfg/firecfg.config
@@ -186,6 +186,7 @@ mediainfo
186mediathekview 186mediathekview
187meld 187meld
188midori 188midori
189minetest
189mousepad 190mousepad
190mplayer 191mplayer
191mpv 192mpv