aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
-rw-r--r--README.md5
-rw-r--r--RELNOTES1
-rw-r--r--etc/disable-programs.inc2
-rw-r--r--etc/mupdf.profile18
-rw-r--r--etc/qpdfview.profile22
-rw-r--r--platform/debian/conffiles3
-rw-r--r--src/firecfg/firecfg.config2
7 files changed, 53 insertions, 0 deletions
diff --git a/README.md b/README.md
index 64a67bf63..9db50d5ba 100644
--- a/README.md
+++ b/README.md
@@ -64,3 +64,8 @@ FAQ: https://firejail.wordpress.com/support/frequently-asked-questions/
64## New profile commands 64## New profile commands
65 65
66x11 xpra, x11 xephyr, x11 block, allusers, join-or-start 66x11 xpra, x11 xephyr, x11 block, allusers, join-or-start
67
68## New profiles
69
70qpdfview, mupdf
71
diff --git a/RELNOTES b/RELNOTES
index f0528b28c..492bd007a 100644
--- a/RELNOTES
+++ b/RELNOTES
@@ -10,6 +10,7 @@ firejail (0.9.43) baseline; urgency=low
10 * feature: add files to sandbox container (--put) 10 * feature: add files to sandbox container (--put)
11 * feature: blocking x11 (--x11=block) 11 * feature: blocking x11 (--x11=block)
12 * feature: x11 xpra, x11 xephyr, x11 block, allusers profile commands 12 * feature: x11 xpra, x11 xephyr, x11 block, allusers profile commands
13 * new profiles: qpdfview, mupdf
13 * bugfixes 14 * bugfixes
14 -- netblue30 <netblue30@yahoo.com> Fri, 9 Sept 2016 08:00:00 -0500 15 -- netblue30 <netblue30@yahoo.com> Fri, 9 Sept 2016 08:00:00 -0500
15 16
diff --git a/etc/disable-programs.inc b/etc/disable-programs.inc
index fb0f5a669..54c53e794 100644
--- a/etc/disable-programs.inc
+++ b/etc/disable-programs.inc
@@ -26,6 +26,7 @@ blacklist ${HOME}/.kde/share/config/okularrc
26blacklist ${HOME}/.kde/share/config/okularpartrc 26blacklist ${HOME}/.kde/share/config/okularpartrc
27blacklist ${HOME}/.kde/share/apps/gwenview 27blacklist ${HOME}/.kde/share/apps/gwenview
28blacklist ${HOME}/.kde/share/config/gwenviewrc 28blacklist ${HOME}/.kde/share/config/gwenviewrc
29blacklist ${HOME}/.config/qpdfview
29 30
30# Media players 31# Media players
31blacklist ${HOME}/.config/cmus 32blacklist ${HOME}/.config/cmus
@@ -135,6 +136,7 @@ blacklist ${HOME}/.local/share/totem
135blacklist ${HOME}/.local/share/psi+ 136blacklist ${HOME}/.local/share/psi+
136blacklist ${HOME}/.local/share/pix 137blacklist ${HOME}/.local/share/pix
137blacklist ${HOME}/.local/share/gnome-chess 138blacklist ${HOME}/.local/share/gnome-chess
139blacklist ${HOME}/.local/share/qpdfview
138 140
139# ssh 141# ssh
140blacklist /tmp/ssh-* 142blacklist /tmp/ssh-*
diff --git a/etc/mupdf.profile b/etc/mupdf.profile
new file mode 100644
index 000000000..6f2db511b
--- /dev/null
+++ b/etc/mupdf.profile
@@ -0,0 +1,18 @@
1# mupdf reader profile
2include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc
4include /etc/firejail/disable-devel.inc
5include /etc/firejail/disable-passwdmgr.inc
6
7caps.drop all
8nogroups
9nonewprivs
10noroot
11nosound
12protocol unix
13seccomp
14shell none
15tracelog
16
17private-tmp
18private-dev
diff --git a/etc/qpdfview.profile b/etc/qpdfview.profile
new file mode 100644
index 000000000..07ea173e6
--- /dev/null
+++ b/etc/qpdfview.profile
@@ -0,0 +1,22 @@
1# qpdfview profile
2noblacklist ${HOME}/.config/qpdfview
3noblacklist ${HOME}/.local/share/qpdfview
4
5include /etc/firejail/disable-common.inc
6include /etc/firejail/disable-programs.inc
7include /etc/firejail/disable-devel.inc
8include /etc/firejail/disable-passwdmgr.inc
9
10caps.drop all
11nogroups
12nonewprivs
13noroot
14nosound
15protocol unix
16seccomp
17shell none
18tracelog
19
20private-bin qpdfview
21private-tmp
22private-dev
diff --git a/platform/debian/conffiles b/platform/debian/conffiles
index 691c536df..0c494c042 100644
--- a/platform/debian/conffiles
+++ b/platform/debian/conffiles
@@ -143,3 +143,6 @@
143/etc/firejail/xzdec.profile 143/etc/firejail/xzdec.profile
144/etc/firejail/strings.profile 144/etc/firejail/strings.profile
145/etc/firejail/dosbox.profile 145/etc/firejail/dosbox.profile
146/etc/firejail/mupdf.profile
147/etc/firejail/qpdfview.profile
148
diff --git a/src/firecfg/firecfg.config b/src/firecfg/firecfg.config
index dd876c87c..ca28d025b 100644
--- a/src/firecfg/firecfg.config
+++ b/src/firecfg/firecfg.config
@@ -128,6 +128,8 @@ mathematica
128okular 128okular
129pix 129pix
130xreader 130xreader
131mupdf
132qpdfview
131 133
132# other 134# other
133ssh 135ssh