aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
-rw-r--r--README.md3
-rw-r--r--RELNOTES2
-rw-r--r--etc/akregator.profile1
-rw-r--r--etc/audacity.profile2
-rw-r--r--etc/disable-common.inc7
-rw-r--r--etc/disable-programs.inc1
-rw-r--r--etc/libreoffice.profile2
-rw-r--r--etc/remmina.profile1
-rw-r--r--etc/soundconverter.profile2
-rw-r--r--etc/tilp.profile34
-rw-r--r--etc/whitelist-common.inc3
-rw-r--r--src/firecfg/firecfg.config1
12 files changed, 54 insertions, 5 deletions
diff --git a/README.md b/README.md
index 1bb9b2d98..bc4802138 100644
--- a/README.md
+++ b/README.md
@@ -101,4 +101,5 @@ Use this issue to request new profiles: [#1139](https://github.com/netblue30/fir
101## New profiles 101## New profiles
102 102
103Basilisk browser, Tor Browser language packs, PlayOnLinux, sylpheed, discord-canary, 103Basilisk browser, Tor Browser language packs, PlayOnLinux, sylpheed, discord-canary,
104pycharm-community, pycharm-professional, Pitivi, OnionShare, Fritzing, Kaffeine, pdfchain 104pycharm-community, pycharm-professional, Pitivi, OnionShare, Fritzing, Kaffeine, pdfchain,
105tilp
diff --git a/RELNOTES b/RELNOTES
index a924cd3d8..b0a873e38 100644
--- a/RELNOTES
+++ b/RELNOTES
@@ -7,7 +7,7 @@ firejail (0.9.53) baseline; urgency=low
7 * private-tmp support for overlay and chroot sandboxes 7 * private-tmp support for overlay and chroot sandboxes
8 * new profiles: basilisk, Tor Browser language packs, PlayOnLinux, sylpheed, 8 * new profiles: basilisk, Tor Browser language packs, PlayOnLinux, sylpheed,
9 * new profiles: discord-canary, pycharm-community, pycharm-professional, kaffeine, 9 * new profiles: discord-canary, pycharm-community, pycharm-professional, kaffeine,
10 * new profiles: pdfchain 10 * new profiles: pdfchain, tilp
11 -- netblue30 <netblue30@yahoo.com> Tue, 12 Dec 2017 08:00:00 -0500 11 -- netblue30 <netblue30@yahoo.com> Tue, 12 Dec 2017 08:00:00 -0500
12 12
13firejail (0.9.52) baseline; urgency=low 13firejail (0.9.52) baseline; urgency=low
diff --git a/etc/akregator.profile b/etc/akregator.profile
index f2e5ea341..2c49ef9f0 100644
--- a/etc/akregator.profile
+++ b/etc/akregator.profile
@@ -17,6 +17,7 @@ mkfile ${HOME}/.config/akregatorrc
17mkdir ${HOME}/.local/share/akregator 17mkdir ${HOME}/.local/share/akregator
18whitelist ${HOME}/.config/akregatorrc 18whitelist ${HOME}/.config/akregatorrc
19whitelist ${HOME}/.local/share/akregator 19whitelist ${HOME}/.local/share/akregator
20whitelist ${HOME}/.local/share/kssl
20include /etc/firejail/whitelist-common.inc 21include /etc/firejail/whitelist-common.inc
21 22
22include /etc/firejail/whitelist-var-common.inc 23include /etc/firejail/whitelist-var-common.inc
diff --git a/etc/audacity.profile b/etc/audacity.profile
index e173fa65a..ea1d38132 100644
--- a/etc/audacity.profile
+++ b/etc/audacity.profile
@@ -17,7 +17,7 @@ include /etc/firejail/disable-programs.inc
17include /etc/firejail/whitelist-var-common.inc 17include /etc/firejail/whitelist-var-common.inc
18 18
19caps.drop all 19caps.drop all
20net none 20#net none
21no3d 21no3d
22nodvd 22nodvd
23nogroups 23nogroups
diff --git a/etc/disable-common.inc b/etc/disable-common.inc
index ec700e24e..2a4905c04 100644
--- a/etc/disable-common.inc
+++ b/etc/disable-common.inc
@@ -83,15 +83,21 @@ read-only ${HOME}/.config/kdeglobals
83read-only ${HOME}/.config/kio_httprc 83read-only ${HOME}/.config/kio_httprc
84read-only ${HOME}/.config/kiorc 84read-only ${HOME}/.config/kiorc
85read-only ${HOME}/.config/kioslaverc 85read-only ${HOME}/.config/kioslaverc
86read-only ${HOME}/.config/ksslcablacklist
87read-only ${HOME}/.kde/share/apps/kssl
86read-only ${HOME}/.kde/share/config/kdeglobals 88read-only ${HOME}/.kde/share/config/kdeglobals
87read-only ${HOME}/.kde/share/config/kio_httprc 89read-only ${HOME}/.kde/share/config/kio_httprc
88read-only ${HOME}/.kde/share/config/kioslaverc 90read-only ${HOME}/.kde/share/config/kioslaverc
91read-only ${HOME}/.kde/share/config/ksslcablacklist
89read-only ${HOME}/.kde/share/kde4/services 92read-only ${HOME}/.kde/share/kde4/services
93read-only ${HOME}/.kde4/share/apps/kssl
90read-only ${HOME}/.kde4/share/config/kdeglobals 94read-only ${HOME}/.kde4/share/config/kdeglobals
91read-only ${HOME}/.kde4/share/config/kio_httprc 95read-only ${HOME}/.kde4/share/config/kio_httprc
92read-only ${HOME}/.kde4/share/config/kioslaverc 96read-only ${HOME}/.kde4/share/config/kioslaverc
97read-only ${HOME}/.kde4/share/config/ksslcablacklist
93read-only ${HOME}/.kde4/share/kde4/services 98read-only ${HOME}/.kde4/share/kde4/services
94read-only ${HOME}/.local/share/kservices5 99read-only ${HOME}/.local/share/kservices5
100read-only ${HOME}/.local/share/kssl
95 101
96# kdeinit socket 102# kdeinit socket
97blacklist /run/user/*/kdeinit5__* 103blacklist /run/user/*/kdeinit5__*
@@ -245,6 +251,7 @@ read-only ${HOME}/bin
245blacklist ${HOME}/.local/share/Trash 251blacklist ${HOME}/.local/share/Trash
246 252
247# Write-protection for desktop entries 253# Write-protection for desktop entries
254read-only ${HOME}/.config/menus
248read-only ${HOME}/.local/share/applications 255read-only ${HOME}/.local/share/applications
249 256
250# top secret 257# top secret
diff --git a/etc/disable-programs.inc b/etc/disable-programs.inc
index 660bb9ffd..a93f50a8d 100644
--- a/etc/disable-programs.inc
+++ b/etc/disable-programs.inc
@@ -445,6 +445,7 @@ blacklist ${HOME}/.sylpheed-2.0
445blacklist ${HOME}/.synfig 445blacklist ${HOME}/.synfig
446blacklist ${HOME}/.tconn 446blacklist ${HOME}/.tconn
447blacklist ${HOME}/.thunderbird 447blacklist ${HOME}/.thunderbird
448blacklist ${HOME}/.tilp
448blacklist ${HOME}/.tooling 449blacklist ${HOME}/.tooling
449blacklist ${HOME}/.tor-browser-* 450blacklist ${HOME}/.tor-browser-*
450blacklist ${HOME}/.ts3client 451blacklist ${HOME}/.ts3client
diff --git a/etc/libreoffice.profile b/etc/libreoffice.profile
index 3548a75ad..220e0f02c 100644
--- a/etc/libreoffice.profile
+++ b/etc/libreoffice.profile
@@ -34,3 +34,5 @@ private-tmp
34 34
35noexec ${HOME} 35noexec ${HOME}
36noexec /tmp 36noexec /tmp
37
38join-or-start libreoffice
diff --git a/etc/remmina.profile b/etc/remmina.profile
index bef6376c6..cc209b84a 100644
--- a/etc/remmina.profile
+++ b/etc/remmina.profile
@@ -5,6 +5,7 @@ include /etc/firejail/remmina.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ${HOME}/.remmina
8noblacklist ${HOME}/.config/remmina 9noblacklist ${HOME}/.config/remmina
9noblacklist ${HOME}/.local/share/remmina 10noblacklist ${HOME}/.local/share/remmina
10noblacklist ${HOME}/.ssh 11noblacklist ${HOME}/.ssh
diff --git a/etc/soundconverter.profile b/etc/soundconverter.profile
index c27fb3819..1f64567ef 100644
--- a/etc/soundconverter.profile
+++ b/etc/soundconverter.profile
@@ -5,8 +5,6 @@ include /etc/firejail/soundconverter.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8blacklist /run/user/*/bus
9
10include /etc/firejail/disable-common.inc 8include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-devel.inc 9include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-passwdmgr.inc 10include /etc/firejail/disable-passwdmgr.inc
diff --git a/etc/tilp.profile b/etc/tilp.profile
new file mode 100644
index 000000000..a6165fbfe
--- /dev/null
+++ b/etc/tilp.profile
@@ -0,0 +1,34 @@
1# Firejail profile for tilp
2# This file is overwritten after every install/update
3# Persistent local customizations
4include /etc/firejail/tilp.local
5# Persistent global definitions
6include /etc/firejail/globals.local
7
8noblacklist ${HOME}/.tilp
9
10include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-passwdmgr.inc
13include /etc/firejail/disable-programs.inc
14
15caps.drop all
16net none
17nodvd
18nogroups
19nonewprivs
20noroot
21notv
22novideo
23protocol unix,netlink
24seccomp
25shell none
26tracelog
27
28disable-mnt
29private-bin tilp
30private-etc fonts
31private-tmp
32
33noexec ${HOME}
34noexec /tmp
diff --git a/etc/whitelist-common.inc b/etc/whitelist-common.inc
index 97846b4a3..c664d5a53 100644
--- a/etc/whitelist-common.inc
+++ b/etc/whitelist-common.inc
@@ -57,15 +57,18 @@ whitelist ${HOME}/.config/Trolltech.conf
57whitelist ${HOME}/.config/kdeglobals 57whitelist ${HOME}/.config/kdeglobals
58whitelist ${HOME}/.config/kio_httprc 58whitelist ${HOME}/.config/kio_httprc
59whitelist ${HOME}/.config/kioslaverc 59whitelist ${HOME}/.config/kioslaverc
60whitelist ${HOME}/.config/ksslcablacklist
60whitelist ${HOME}/.config/qt5ct 61whitelist ${HOME}/.config/qt5ct
61whitelist ${HOME}/.kde/share/config/kdeglobals 62whitelist ${HOME}/.kde/share/config/kdeglobals
62whitelist ${HOME}/.kde/share/config/kio_httprc 63whitelist ${HOME}/.kde/share/config/kio_httprc
63whitelist ${HOME}/.kde/share/config/kioslaverc 64whitelist ${HOME}/.kde/share/config/kioslaverc
65whitelist ${HOME}/.kde/share/config/ksslcablacklist
64whitelist ${HOME}/.kde/share/config/oxygenrc 66whitelist ${HOME}/.kde/share/config/oxygenrc
65whitelist ${HOME}/.kde/share/icons 67whitelist ${HOME}/.kde/share/icons
66whitelist ${HOME}/.kde4/share/config/kdeglobals 68whitelist ${HOME}/.kde4/share/config/kdeglobals
67whitelist ${HOME}/.kde4/share/config/kio_httprc 69whitelist ${HOME}/.kde4/share/config/kio_httprc
68whitelist ${HOME}/.kde4/share/config/kioslaverc 70whitelist ${HOME}/.kde4/share/config/kioslaverc
71whitelist ${HOME}/.kde4/share/config/ksslcablacklist
69whitelist ${HOME}/.kde4/share/config/oxygenrc 72whitelist ${HOME}/.kde4/share/config/oxygenrc
70whitelist ${HOME}/.kde4/share/icons 73whitelist ${HOME}/.kde4/share/icons
71whitelist ${HOME}/.local/share/qt5ct 74whitelist ${HOME}/.local/share/qt5ct
diff --git a/src/firecfg/firecfg.config b/src/firecfg/firecfg.config
index 90bbc8bb5..9bd60171b 100644
--- a/src/firecfg/firecfg.config
+++ b/src/firecfg/firecfg.config
@@ -338,6 +338,7 @@ telegram
338telegram-desktop 338telegram-desktop
339terasology 339terasology
340thunderbird 340thunderbird
341tilp
341tor-browser-ar 342tor-browser-ar
342tor-browser-en 343tor-browser-en
343tor-browser-en-us 344tor-browser-en-us