aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
-rw-r--r--Makefile.in1
-rw-r--r--README.md2
-rw-r--r--RELNOTES3
-rw-r--r--etc/flashpeak-slimjet.profile43
-rw-r--r--platform/debian/conffiles1
5 files changed, 48 insertions, 2 deletions
diff --git a/Makefile.in b/Makefile.in
index 8dc052352..20df3acf9 100644
--- a/Makefile.in
+++ b/Makefile.in
@@ -147,6 +147,7 @@ realinstall:
147 install -c -m 0644 .etc/vivaldi-beta.profile $(DESTDIR)/$(sysconfdir)/firejail/. 147 install -c -m 0644 .etc/vivaldi-beta.profile $(DESTDIR)/$(sysconfdir)/firejail/.
148 install -c -m 0644 .etc/atril.profile $(DESTDIR)/$(sysconfdir)/firejail/. 148 install -c -m 0644 .etc/atril.profile $(DESTDIR)/$(sysconfdir)/firejail/.
149 install -c -m 0644 .etc/qutebrowser.profile $(DESTDIR)/$(sysconfdir)/firejail/. 149 install -c -m 0644 .etc/qutebrowser.profile $(DESTDIR)/$(sysconfdir)/firejail/.
150 install -c -m 0644 .etc/flashpeak-slimjet.profile $(DESTDIR)/$(sysconfdir)/firejail/.
150 sh -c "if [ ! -f $(DESTDIR)/$(sysconfdir)/firejail/login.users ]; then install -c -m 0644 etc/login.users $(DESTDIR)/$(sysconfdir)/firejail/.; fi;" 151 sh -c "if [ ! -f $(DESTDIR)/$(sysconfdir)/firejail/login.users ]; then install -c -m 0644 etc/login.users $(DESTDIR)/$(sysconfdir)/firejail/.; fi;"
151 sh -c "if [ ! -f $(DESTDIR)/$(sysconfdir)/firejail/firejail.config ]; then install -c -m 0644 etc/firejail.config $(DESTDIR)/$(sysconfdir)/firejail/.; fi;" 152 sh -c "if [ ! -f $(DESTDIR)/$(sysconfdir)/firejail/firejail.config ]; then install -c -m 0644 etc/firejail.config $(DESTDIR)/$(sysconfdir)/firejail/.; fi;"
152 rm -fr .etc 153 rm -fr .etc
diff --git a/README.md b/README.md
index 0865bc966..0da0ec5ea 100644
--- a/README.md
+++ b/README.md
@@ -154,5 +154,5 @@ $ man firejail-profile
154 154
155## New security profiles 155## New security profiles
156 156
157lxterminal, Epiphany, cherrytree, Battle for Wesnoth, Hedgewars, qutebrowser 157lxterminal, Epiphany, cherrytree, Battle for Wesnoth, Hedgewars, qutebrowser, SlimJet
158 158
diff --git a/RELNOTES b/RELNOTES
index 1392bbaff..00695006e 100644
--- a/RELNOTES
+++ b/RELNOTES
@@ -9,8 +9,9 @@ firejail (0.9.39) baseline; urgency=low
9 * added compile-time option to restrict --net= to root only 9 * added compile-time option to restrict --net= to root only
10 * build rpm packages using "make rpms" 10 * build rpm packages using "make rpms"
11 * new profiles: lxterminal, Epiphany, cherrytree, Polari, Vivaldi, Atril 11 * new profiles: lxterminal, Epiphany, cherrytree, Polari, Vivaldi, Atril
12 * new profiles: qutebrowser, SlimJet
12 * bugfixes 13 * bugfixes
13 -- netblue30 <netblue30@yahoo.com> Wed, 3 Mar 2016 08:00:00 -0500 14 -- netblue30 <netblue30@yahoo.com> Wed, 16 Mar 2016 08:00:00 -0500
14 15
15firejail (0.9.38) baseline; urgency=low 16firejail (0.9.38) baseline; urgency=low
16 * IPv6 support (--ip6 and --netfilter6) 17 * IPv6 support (--ip6 and --netfilter6)
diff --git a/etc/flashpeak-slimjet.profile b/etc/flashpeak-slimjet.profile
new file mode 100644
index 000000000..2f5d7148c
--- /dev/null
+++ b/etc/flashpeak-slimjet.profile
@@ -0,0 +1,43 @@
1# SlimJet browser profile
2# This is a whitelisted profile, the internal browser sandbox
3# is disabled because it requires sudo password. The command
4# to run it is as follows:
5#
6# firejail flashpeak-slimjet --no-sandbox
7#
8noblacklist ~/.config/silmjet
9noblacklist ~/.cache/slimjet
10noblacklist ~/keepassx.kdbx
11include /etc/firejail/disable-mgmt.inc
12include /etc/firejail/disable-secret.inc
13include /etc/firejail/disable-common.inc
14include /etc/firejail/disable-terminals.inc
15
16# chromium is distributed with a perl script on Arch
17# include /etc/firejail/disable-devel.inc
18#
19
20caps.drop all
21seccomp
22protocol unix,inet,inet6,netlink
23netfilter
24noroot
25
26whitelist ${DOWNLOADS}
27mkdir ~/.config
28mkdir ~/.config/slimjet
29whitelist ~/.config/slimjet
30mkdir ~/.cache
31mkdir ~/.cache/slimjet
32whitelist ~/.cache/simjet
33mkdir ~/.pki
34whitelist ~/.pki
35
36# lastpass, keepassx
37whitelist ~/.keepassx
38whitelist ~/.config/keepassx
39whitelist ~/keepassx.kdbx
40whitelist ~/.lastpass
41whitelist ~/.config/lastpass
42
43include /etc/firejail/whitelist-common.inc
diff --git a/platform/debian/conffiles b/platform/debian/conffiles
index 5f552414f..9f324c59f 100644
--- a/platform/debian/conffiles
+++ b/platform/debian/conffiles
@@ -74,3 +74,4 @@
74/etc/firejail/atril.profile 74/etc/firejail/atril.profile
75/etc/firejail/firejail.config 75/etc/firejail/firejail.config
76/etc/firejail/qutebrowser.profile 76/etc/firejail/qutebrowser.profile
77/etc/firejail/flashpeak-slimjet.profile