aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
-rw-r--r--README.md2
-rw-r--r--RELNOTES1
-rw-r--r--etc/profile-m-z/org.gnome.NautilusPreviewer.profile10
-rw-r--r--etc/profile-m-z/sushi.profile48
-rw-r--r--src/firecfg/firecfg.config1
5 files changed, 61 insertions, 1 deletions
diff --git a/README.md b/README.md
index c370368d7..1cbe84a62 100644
--- a/README.md
+++ b/README.md
@@ -196,4 +196,4 @@ gnome-screenshot, ripperX, sound-juicer, iagno, com.github.dahenson.agenda, gnom
196penguin-command, x2goclient, frogatto, gnome-mines, gnome-nibbles, lightsoff, ts3client_runscript.sh, warmux, ferdi, abiword, 196penguin-command, x2goclient, frogatto, gnome-mines, gnome-nibbles, lightsoff, ts3client_runscript.sh, warmux, ferdi, abiword,
197four-in-a-row, gnome-mahjongg, gnome-robots, gnome-sudoku, gnome-taquin, gnome-tetravex, blobwars, gravity-beams-and-evaporating-stars, 197four-in-a-row, gnome-mahjongg, gnome-robots, gnome-sudoku, gnome-taquin, gnome-tetravex, blobwars, gravity-beams-and-evaporating-stars,
198hyperrogue, jumpnbump-menu, jumpnbump, magicor, mindless, mirrormagic, mrrescue, scorched3d-wrapper, scorchwentbonkers, 198hyperrogue, jumpnbump-menu, jumpnbump, magicor, mindless, mirrormagic, mrrescue, scorched3d-wrapper, scorchwentbonkers,
199seahorse-adventures, wordwarvi, xbill, gnome-klotski, five-or-more, swell-foop, fdns, jitsi-meet-desktop, nicontine, steam-runtime, apostrophe, quadrapassel, dino-im, strawberry, hitori, bijiben, gnote, gnubik, ZeGrapher, gapplication, xonotic-sdl-wrapper, openarena_ded, cawbird, freetube, homebank, mattermost-desktop, newsflash, com.gitlab.newsflash, element-desktop 199seahorse-adventures, wordwarvi, xbill, gnome-klotski, five-or-more, swell-foop, fdns, jitsi-meet-desktop, nicontine, steam-runtime, apostrophe, quadrapassel, dino-im, strawberry, hitori, bijiben, gnote, gnubik, ZeGrapher, gapplication, xonotic-sdl-wrapper, openarena_ded, cawbird, freetube, homebank, mattermost-desktop, newsflash, com.gitlab.newsflash, element-desktop, sushi, xfce4-screenshooter, org.gnome.NautilusPreviewer
diff --git a/RELNOTES b/RELNOTES
index d0cf88d4d..e77db8cf8 100644
--- a/RELNOTES
+++ b/RELNOTES
@@ -39,6 +39,7 @@ firejail (0.9.63) baseline; urgency=low
39 * new profiles: hitori, bijiben, gnote, gnubik, ZeGrapher, xonotic-sdl-wrapper 39 * new profiles: hitori, bijiben, gnote, gnubik, ZeGrapher, xonotic-sdl-wrapper
40 * new profiles: gapplication, openarena_ded, element-desktop, cawbird, freetube 40 * new profiles: gapplication, openarena_ded, element-desktop, cawbird, freetube
41 * new profiles: homebank, mattermost-desktop, newsflash, com.gitlab.newsflash 41 * new profiles: homebank, mattermost-desktop, newsflash, com.gitlab.newsflash
42 * new profiles: sushi, xfce4-screenshooter, org.gnome.NautilusPreviewer
42 -- netblue30 <netblue30@yahoo.com> Tue, 21 Apr 2020 08:00:00 -0500 43 -- netblue30 <netblue30@yahoo.com> Tue, 21 Apr 2020 08:00:00 -0500
43 44
44firejail (0.9.62) baseline; urgency=low 45firejail (0.9.62) baseline; urgency=low
diff --git a/etc/profile-m-z/org.gnome.NautilusPreviewer.profile b/etc/profile-m-z/org.gnome.NautilusPreviewer.profile
new file mode 100644
index 000000000..eb75add58
--- /dev/null
+++ b/etc/profile-m-z/org.gnome.NautilusPreviewer.profile
@@ -0,0 +1,10 @@
1# Firejail profile alias for sushi
2# This file is overwritten after every install/update
3# Persistent local customizations
4include org.gnome.NautilusPreviewer.local
5# Persistent global definitions
6# added by included profile
7#include globals.local
8
9# Redirect
10include sushi.profile
diff --git a/etc/profile-m-z/sushi.profile b/etc/profile-m-z/sushi.profile
new file mode 100644
index 000000000..68abd8c94
--- /dev/null
+++ b/etc/profile-m-z/sushi.profile
@@ -0,0 +1,48 @@
1# Firejail profile for sushi
2# Description: A quick previewer for Nautilus
3# This file is overwritten after every install/update
4# Persistent local customizations
5include sushi.local
6# Persistent global definitions
7include globals.local
8
9# Allow gjs (blacklisted by disable-interpreters.inc)
10include allow-gjs.inc
11
12include disable-common.inc
13include disable-devel.inc
14include disable-exec.inc
15include disable-interpreters.inc
16include disable-passwdmgr.inc
17# include disable-programs.inc
18include disable-shell.inc
19
20include whitelist-runuser-common.inc
21
22apparmor
23caps.drop all
24net none
25nodvd
26nogroups
27nonewprivs
28noroot
29notv
30nou2f
31novideo
32protocol unix
33seccomp
34shell none
35tracelog
36
37private-bin gjs,sushi
38private-dev
39private-tmp
40
41dbus-system none
42
43read-only /
44read-only /mnt
45read-only /media
46read-only /run/mount
47read-only /run/media
48read-only ${HOME}
diff --git a/src/firecfg/firecfg.config b/src/firecfg/firecfg.config
index ee0def5aa..77b0596e9 100644
--- a/src/firecfg/firecfg.config
+++ b/src/firecfg/firecfg.config
@@ -663,6 +663,7 @@ subdownloader
663supertux2 663supertux2
664supertuxkart 664supertuxkart
665surf 665surf
666sushi
666swell-foop 667swell-foop
667sylpheed 668sylpheed
668synfigstudio 669synfigstudio