aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
-rw-r--r--README.md2
-rw-r--r--RELNOTES3
-rw-r--r--etc/archaudit-report.profile41
-rw-r--r--etc/cower.profile47
4 files changed, 91 insertions, 2 deletions
diff --git a/README.md b/README.md
index fc809a7c2..643839b1d 100644
--- a/README.md
+++ b/README.md
@@ -236,7 +236,7 @@ imagej, karbon, kdenlive, krita, linphone, lmms, macrofusion, mpd, natron, Natro
236ricochet, shotcut, teamspeak3, tor, tor-browser-en, Viber, x-terminal-emulator, zart, 236ricochet, shotcut, teamspeak3, tor, tor-browser-en, Viber, x-terminal-emulator, zart,
237conky, arch-audit, ffmpeg, bluefish, cliqz, cinelerra, openshot-qt, pinta, uefitool, 237conky, arch-audit, ffmpeg, bluefish, cliqz, cinelerra, openshot-qt, pinta, uefitool,
238aosp, pdfmod, gnome-ring, signal-desktop, xcalc, zaproxy, kopete, kget, nheko, Enpass, 238aosp, pdfmod, gnome-ring, signal-desktop, xcalc, zaproxy, kopete, kget, nheko, Enpass,
239kwin_x11, krunner, ping, bsdtar, makepkg (Arch), 239kwin_x11, krunner, ping, bsdtar, makepkg (Arch), archaudit-report, cower (Arch)
240 240
241Upstreamed many profiles from the following sources: https://github.com/chiraag-nataraj/firejail-profiles, 241Upstreamed many profiles from the following sources: https://github.com/chiraag-nataraj/firejail-profiles,
242https://github.com/nyancat18/fe, and https://aur.archlinux.org/packages/firejail-profiles. 242https://github.com/nyancat18/fe, and https://aur.archlinux.org/packages/firejail-profiles.
diff --git a/RELNOTES b/RELNOTES
index 8010c0bfc..3c878520d 100644
--- a/RELNOTES
+++ b/RELNOTES
@@ -41,7 +41,8 @@ firejail (0.9.51) baseline; urgency=low
41 Viber, x-terminal-emulator, zart, conky, arch-audit, ffmpeg, bluefish, 41 Viber, x-terminal-emulator, zart, conky, arch-audit, ffmpeg, bluefish,
42 cinelerra, openshot-qt, pinta, uefitool, aosp, pdfmod, gnome-ring, 42 cinelerra, openshot-qt, pinta, uefitool, aosp, pdfmod, gnome-ring,
43 xcalc, zaproxy, kopete, cliqz, signal-desktop, kget, nheko, Enpass, 43 xcalc, zaproxy, kopete, cliqz, signal-desktop, kget, nheko, Enpass,
44 kwin_x11, krunner, ping, bsdtar, makepkg (Arch) 44 kwin_x11, krunner, ping, bsdtar, makepkg (Arch), archaudit-report
45 cower (Arch)
45 46
46 -- netblue30 <netblue30@yahoo.com> Thu, 9 Nov 2017 08:00:00 -0500 47 -- netblue30 <netblue30@yahoo.com> Thu, 9 Nov 2017 08:00:00 -0500
47 48
diff --git a/etc/archaudit-report.profile b/etc/archaudit-report.profile
new file mode 100644
index 000000000..3d0d1d356
--- /dev/null
+++ b/etc/archaudit-report.profile
@@ -0,0 +1,41 @@
1# Firejail profile for archaudit-report
2# This file is overwritten after every install/update
3quiet
4# Persistent local customizations
5include /etc/firejail/archaudit-report.local
6# Persistent global definitions
7include /etc/firejail/globals.local
8
9
10noblacklist /var/lib/pacman
11
12include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-devel.inc
14include /etc/firejail/disable-passwdmgr.inc
15include /etc/firejail/disable-programs.inc
16include /etc/firejail/whitelist-common.inc
17
18caps.drop all
19ipc-namespace
20netfilter
21no3d
22nodvd
23nogroups
24nonewprivs
25noroot
26nosound
27notv
28novideo
29protocol unix,inet,inet6
30seccomp
31shell none
32
33disable-mnt
34private
35private-bin archaudit-report,arch-audit,bash,cat,comm,cut,date,fold,grep,pacman,pactree,rm,sed,sort,whoneeds
36#private-dev
37private-tmp
38
39memory-deny-write-execute
40noexec ${HOME}
41noexec /tmp
diff --git a/etc/cower.profile b/etc/cower.profile
new file mode 100644
index 000000000..5e5c367c4
--- /dev/null
+++ b/etc/cower.profile
@@ -0,0 +1,47 @@
1# Firejail profile for cower
2# This file is overwritten after every install/update
3
4# This profile could be significantly strengthened by adding the following to cower.local
5# whitelist ~/<Your Build Folder>
6# whitelist ~/.config/cower/
7
8quiet
9
10# Persistent local customizations
11include /etc/firejail/cower.local
12# Persistent global definitions
13include /etc/firejail/globals.local
14
15noblacklist ~/.config/cower/config
16read-only ~/.config/cower/config
17
18noblacklist /var/lib/pacman
19
20include /etc/firejail/disable-common.inc
21include /etc/firejail/disable-devel.inc
22include /etc/firejail/disable-passwdmgr.inc
23include /etc/firejail/disable-programs.inc
24
25caps.drop all
26ipc-namespace
27netfilter
28no3d
29nodvd
30nogroups
31nonewprivs
32noroot
33nosound
34notv
35novideo
36protocol unix,inet,inet6
37seccomp
38shell none
39
40disable-mnt
41private-bin cower
42private-dev
43private-tmp
44
45memory-deny-write-execute
46noexec ${HOME}
47noexec /tmp