aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
-rw-r--r--README.md2
-rw-r--r--RELNOTES3
-rw-r--r--etc/gnome-hexgl.profile49
-rw-r--r--src/firecfg/firecfg.config1
4 files changed, 53 insertions, 2 deletions
diff --git a/README.md b/README.md
index f6ce3b68f..8d2fb534b 100644
--- a/README.md
+++ b/README.md
@@ -151,4 +151,4 @@ We also keep a list of profile fixes for previous released versions in [etc-fixe
151 151
152### New profiles: 152### New profiles:
153 153
154gfeeds, firefox-x11, tvbrowser, rtv, clipgrab, gnome-passwordsafe, bibtex, gummi, latex, pdflatex, tex, wpp, wpspdf, wps, et 154gfeeds, firefox-x11, tvbrowser, rtv, clipgrab, gnome-passwordsafe, bibtex, gummi, latex, pdflatex, tex, wpp, wpspdf, wps, et, multimc, gnome-hexgl
diff --git a/RELNOTES b/RELNOTES
index 9541cef74..09e43e090 100644
--- a/RELNOTES
+++ b/RELNOTES
@@ -3,7 +3,8 @@ firejail (0.9.63) baseline; urgency=low
3 * DHCP client support 3 * DHCP client support
4 * new profiles: gfeeds, firefox-x11, tvbrowser, rtv, clipgrab 4 * new profiles: gfeeds, firefox-x11, tvbrowser, rtv, clipgrab
5 * new profiles: gnome-passwordsafe, bibtex, gummi, latex 5 * new profiles: gnome-passwordsafe, bibtex, gummi, latex
6 * new profiles: pdflatex, tex, wpp, wpspdf, wps, et 6 * new profiles: pdflatex, tex, wpp, wpspdf, wps, et, multimc
7 * new profiles: gnome-hexgl
7 8
8firejail (0.9.62) baseline; urgency=low 9firejail (0.9.62) baseline; urgency=low
9 * added file-copy-limit in /etc/firejail/firejail.config 10 * added file-copy-limit in /etc/firejail/firejail.config
diff --git a/etc/gnome-hexgl.profile b/etc/gnome-hexgl.profile
new file mode 100644
index 000000000..386c33d7f
--- /dev/null
+++ b/etc/gnome-hexgl.profile
@@ -0,0 +1,49 @@
1# Firejail profile for gnome-hexgl
2# Description: Gthree port of HexGL
3# This file is overwritten after every install/update
4# Persistent local customizations
5include gnome-hexgl.local
6# Persistent global definitions
7include globals.local
8
9include disable-common.inc
10include disable-devel.inc
11include disable-exec.inc
12include disable-interpreters.inc
13include disable-passwdmgr.inc
14include disable-programs.inc
15include disable-xdg.inc
16
17mkdir ${HOME}/.cache/mesa_shader_cache
18whitelist ${RUNUSER}/pulse
19whitelist ${RUNUSER}/wayland-0
20whitelist /usr/share/gnome-hexgl
21include whitelist-usr-share-common.inc
22include whitelist-var-common.inc
23
24apparmor
25caps.drop all
26net none
27nodbus
28nodvd
29nogroups
30nonewprivs
31noroot
32notv
33nou2f
34novideo
35protocol unix
36seccomp
37shell none
38tracelog
39
40disable-mnt
41private
42private-bin gnome-hexgl
43private-cache
44private-dev
45private-etc machine-id
46private-tmp
47
48read-only ${HOME}
49read-write ${HOME}/.cache/mesa_shader_cache
diff --git a/src/firecfg/firecfg.config b/src/firecfg/firecfg.config
index 040ad3827..51ec06402 100644
--- a/src/firecfg/firecfg.config
+++ b/src/firecfg/firecfg.config
@@ -261,6 +261,7 @@ gnome-clocks
261gnome-contacts 261gnome-contacts
262gnome-documents 262gnome-documents
263gnome-font-viewer 263gnome-font-viewer
264gnome-hexgl
264gnome-latex 265gnome-latex
265gnome-logs 266gnome-logs
266gnome-maps 267gnome-maps