aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
-rw-r--r--README.md2
-rw-r--r--RELNOTES2
-rw-r--r--etc/clipgrab.profile45
-rw-r--r--etc/disable-programs.inc1
-rw-r--r--etc/whitelist-usr-share-common.inc2
5 files changed, 49 insertions, 3 deletions
diff --git a/README.md b/README.md
index 6a0ddd822..2bf935e6f 100644
--- a/README.md
+++ b/README.md
@@ -151,4 +151,4 @@ We also keep a list of profile fixes for previous released versions in [etc-fixe
151 151
152### New profiles: 152### New profiles:
153 153
154firefox-x11, tvbrowser, rtv 154gfeeds, firefox-x11, tvbrowser, rtv, clipgrab
diff --git a/RELNOTES b/RELNOTES
index ccc3d766d..708f5b297 100644
--- a/RELNOTES
+++ b/RELNOTES
@@ -1,7 +1,7 @@
1firejail (0.9.63) baseline; urgency=low 1firejail (0.9.63) baseline; urgency=low
2 * work in progress 2 * work in progress
3 * DHCP client support 3 * DHCP client support
4 * new profiles: firefox-x11, tvbrowser, rtv 4 * new profiles: gfeeds, firefox-x11, tvbrowser, rtv, clipgrab
5 5
6firejail (0.9.62) baseline; urgency=low 6firejail (0.9.62) baseline; urgency=low
7 * added file-copy-limit in /etc/firejail/firejail.config 7 * added file-copy-limit in /etc/firejail/firejail.config
diff --git a/etc/clipgrab.profile b/etc/clipgrab.profile
new file mode 100644
index 000000000..786d1c866
--- /dev/null
+++ b/etc/clipgrab.profile
@@ -0,0 +1,45 @@
1# Firejail profile for clipgrab
2# Description: A free video downloader and converter
3# This file is overwritten after every install/update
4# Persistent local customizations
5include clipgrab.local
6# Persistent global definitions
7include globals.local
8
9noblacklist ${HOME}/.config/Philipp Schmieder
10noblacklist ${HOME}/.pki
11noblacklist ${VIDEOS}
12
13include disable-common.inc
14include disable-devel.inc
15include disable-exec.inc
16include disable-interpreters.inc
17include disable-passwdmgr.inc
18include disable-programs.inc
19include disable-xdg.inc
20
21include whitelist-usr-share-common.inc
22include whitelist-var-common.inc
23
24apparmor
25caps.drop all
26machine-id
27netfilter
28# Breaks tray-icon, uncommend or add to clipgrab.local if you don't need it.
29#nodbus
30nodvd
31nogroups
32nonewprivs
33noroot
34nosound
35notv
36nou2f
37novideo
38protocol unix,inet,inet6,netlink
39seccomp !chroot
40shell none
41
42disable-mnt
43private-cache
44private-dev
45private-tmp
diff --git a/etc/disable-programs.inc b/etc/disable-programs.inc
index f46294a25..2eac1338e 100644
--- a/etc/disable-programs.inc
+++ b/etc/disable-programs.inc
@@ -97,6 +97,7 @@ blacklist ${HOME}/.config/MusicBrainz
97blacklist ${HOME}/.config/Nathan Osman 97blacklist ${HOME}/.config/Nathan Osman
98blacklist ${HOME}/.config/Nylas Mail 98blacklist ${HOME}/.config/Nylas Mail
99blacklist ${HOME}/.config/PBE 99blacklist ${HOME}/.config/PBE
100blacklist ${HOME}/.config/Philipp Schmieder
100blacklist ${HOME}/.config/QGIS 101blacklist ${HOME}/.config/QGIS
101blacklist ${HOME}/.config/QMediathekView 102blacklist ${HOME}/.config/QMediathekView
102blacklist ${HOME}/.config/Qlipper 103blacklist ${HOME}/.config/Qlipper
diff --git a/etc/whitelist-usr-share-common.inc b/etc/whitelist-usr-share-common.inc
index 78b947750..4115dbfeb 100644
--- a/etc/whitelist-usr-share-common.inc
+++ b/etc/whitelist-usr-share-common.inc
@@ -26,8 +26,8 @@ whitelist /usr/share/gtksourceview-4
26whitelist /usr/share/hunspell 26whitelist /usr/share/hunspell
27whitelist /usr/share/hwdata 27whitelist /usr/share/hwdata
28whitelist /usr/share/icons 28whitelist /usr/share/icons
29whitelist /usr/share/knotifications5
30whitelist /usr/share/icu 29whitelist /usr/share/icu
30whitelist /usr/share/knotifications5
31whitelist /usr/share/kservices5 31whitelist /usr/share/kservices5
32whitelist /usr/share/Kvantum 32whitelist /usr/share/Kvantum
33whitelist /usr/share/kxmlgui5 33whitelist /usr/share/kxmlgui5