aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
-rw-r--r--README.md2
-rw-r--r--RELNOTES2
-rw-r--r--etc/blender-2.8.profile30
-rw-r--r--etc/thunderbird-beta.profile33
-rw-r--r--src/firecfg/firecfg.config2
5 files changed, 10 insertions, 59 deletions
diff --git a/README.md b/README.md
index d3f5db872..73d9390d9 100644
--- a/README.md
+++ b/README.md
@@ -293,4 +293,4 @@ firefox-common-addons.inc in firefox-common.profile.
293Basilisk browser, Tor Browser language packs, PlayOnLinux, sylpheed, discord-canary, 293Basilisk browser, Tor Browser language packs, PlayOnLinux, sylpheed, discord-canary,
294pycharm-community, pycharm-professional, Pitivi, OnionShare, Fritzing, Kaffeine, pdfchain, 294pycharm-community, pycharm-professional, Pitivi, OnionShare, Fritzing, Kaffeine, pdfchain,
295tilp, vivaldi-snapshot, bitcoin-qt, VS Code, falkon, gnome-builder, lobase, asunder, 295tilp, vivaldi-snapshot, bitcoin-qt, VS Code, falkon, gnome-builder, lobase, asunder,
296gnome-recipes, akonadi_control 296gnome-recipes, akonadi_control, blender-2.8, thunderbird-beta
diff --git a/RELNOTES b/RELNOTES
index 681e2a865..18a4bf346 100644
--- a/RELNOTES
+++ b/RELNOTES
@@ -29,7 +29,7 @@ firejail (0.9.53) baseline; urgency=low
29 * new profiles: discord-canary, pycharm-community, pycharm-professional, 29 * new profiles: discord-canary, pycharm-community, pycharm-professional,
30 * new profiles: pdfchain, tilp, vivaldi-snapshot, bitcoin-qt, kaffeine, 30 * new profiles: pdfchain, tilp, vivaldi-snapshot, bitcoin-qt, kaffeine,
31 * new profiles: falkon, gnome-builder, asunder, VS Code, gnome-recipes 31 * new profiles: falkon, gnome-builder, asunder, VS Code, gnome-recipes
32 * new profiles: akonadi_control 32 * new profiles: akonadi_control, blender-2.8, thunderbird-beta
33 -- netblue30 <netblue30@yahoo.com> Thu, 1 Mar 2018 08:00:00 -0500 33 -- netblue30 <netblue30@yahoo.com> Thu, 1 Mar 2018 08:00:00 -0500
34 34
35firejail (0.9.52) baseline; urgency=low 35firejail (0.9.52) baseline; urgency=low
diff --git a/etc/blender-2.8.profile b/etc/blender-2.8.profile
index 29df27759..4b907018e 100644
--- a/etc/blender-2.8.profile
+++ b/etc/blender-2.8.profile
@@ -1,30 +1,6 @@
1# Firejail profile for blender 1# Firejail profile alias for blender
2# This file is overwritten after every install/update 2# This file is overwritten after every install/update
3# Persistent local customizations
4include /etc/firejail/blender.local
5# Persistent global definitions
6include /etc/firejail/globals.local
7 3
8noblacklist ${HOME}/.config/blender
9 4
10include /etc/firejail/disable-common.inc 5# Redirect
11include /etc/firejail/disable-devel.inc 6include /etc/firejail/blender.profile
12include /etc/firejail/disable-passwdmgr.inc
13include /etc/firejail/disable-programs.inc
14
15caps.drop all
16netfilter
17nodvd
18nogroups
19nonewprivs
20noroot
21notv
22protocol unix,inet,inet6,netlink
23seccomp
24shell none
25
26private-dev
27private-tmp
28
29noexec ${HOME}
30noexec /tmp
diff --git a/etc/thunderbird-beta.profile b/etc/thunderbird-beta.profile
index fb1ee46e2..73d2419da 100644
--- a/etc/thunderbird-beta.profile
+++ b/etc/thunderbird-beta.profile
@@ -1,35 +1,8 @@
1# Firejail profile for thunderbird 1# Firejail profile alias for thunderbird-beta
2# This file is overwritten after every install/update 2# This file is overwritten after every install/update
3# Persistent local customizations
4include /etc/firejail/thunderbird.local
5# Persistent global definitions
6include /etc/firejail/globals.local
7 3
8# Users have thunderbird set to open a browser by clicking a link in an email
9# We are not allowed to blacklist browser-specific directories
10whitelist /opt/thunderbird-beta
11noblacklist ${HOME}/.cache/thunderbird
12noblacklist ${HOME}/.gnupg
13# noblacklist ${HOME}/.icedove
14noblacklist ${HOME}/.thunderbird
15
16mkdir ${HOME}/.cache/thunderbird
17mkdir ${HOME}/.gnupg
18# mkdir ${HOME}/.icedove
19mkdir ${HOME}/.thunderbird
20whitelist ${HOME}/.cache/thunderbird
21whitelist ${HOME}/.gnupg
22# whitelist ${HOME}/.icedove
23whitelist ${HOME}/.thunderbird
24 4
25# We need the real /tmp for data exchange when xdg-open handles email attachments on KDE 5whitelist /opt/thunderbird-beta
26ignore private-tmp
27# machine-id breaks audio in browsers; enable it when sound is not required
28# machine-id
29read-only ${HOME}/.config/mimeapps.list
30# writable-run-user is needed for signing and encrypting emails
31writable-run-user
32 6
33# allow browsers
34# Redirect 7# Redirect
35include /etc/firejail/firefox.profile 8include /etc/firejail/thunderbird.profile
diff --git a/src/firecfg/firecfg.config b/src/firecfg/firecfg.config
index 2ffaa8b98..fafbc83d9 100644
--- a/src/firecfg/firecfg.config
+++ b/src/firecfg/firecfg.config
@@ -44,6 +44,7 @@ bibletime
44bitlbee 44bitlbee
45bleachbit 45bleachbit
46blender 46blender
47blender-2.8
47bless 48bless
48bluefish 49bluefish
49bnox 50bnox
@@ -350,6 +351,7 @@ telegram
350telegram-desktop 351telegram-desktop
351terasology 352terasology
352thunderbird 353thunderbird
354thunderbird-beta
353tilp 355tilp
354tor-browser-ar 356tor-browser-ar
355tor-browser-en 357tor-browser-en