summaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
Diffstat (limited to 'etc')
-rw-r--r--etc/cherrytree.profile10
-rw-r--r--etc/evince.profile1
-rw-r--r--etc/firejail-default3
-rw-r--r--etc/keepass.profile2
-rw-r--r--etc/libreoffice.profile5
-rw-r--r--etc/vlc.profile1
6 files changed, 8 insertions, 14 deletions
diff --git a/etc/cherrytree.profile b/etc/cherrytree.profile
index 7c324a34b..d16e7c067 100644
--- a/etc/cherrytree.profile
+++ b/etc/cherrytree.profile
@@ -1,6 +1,7 @@
1# cherrytree note taking application 1# cherrytree note taking application
2noblacklist /usr/bin/python2* 2noblacklist /usr/bin/python2*
3noblacklist /usr/lib/python3* 3noblacklist /usr/lib/python3*
4noblacklist ${HOME}/.config/cherrytree/
4include /etc/firejail/disable-common.inc 5include /etc/firejail/disable-common.inc
5include /etc/firejail/disable-programs.inc 6include /etc/firejail/disable-programs.inc
6include /etc/firejail/disable-devel.inc 7include /etc/firejail/disable-devel.inc
@@ -15,13 +16,4 @@ seccomp
15protocol unix,inet,inet6,netlink 16protocol unix,inet,inet6,netlink
16tracelog 17tracelog
17 18
18include /etc/firejail/whitelist-common.inc
19 19
20# no private-bin support for various reasons:
21#10:25:34 exec 11249 (root) NEW SANDBOX: /usr/bin/firejail /usr/bin/cherrytree
22#10:25:34 exec 11252 (netblue) /bin/bash -c "/usr/bin/cherrytree"
23#10:25:34 exec 11252 (netblue) /usr/bin/python /usr/bin/cherrytree
24#10:25:34 exec 11253 (netblue) sh -c /sbin/ldconfig -p 2>/dev/null
25#10:25:34 exec 11255 (netblue) sh -c if type gcc >/dev/null 2>&1; then CC=gcc; elif type cc >/dev/null 2>&1; then CC=cc;else exit 10; fi;LANG=C LC_ALL=C $CC -Wl,-t -o /tmp/tmpiYr44S 2>&1 -llibc
26# it requires acces to browser to show the online help
27# it doesn't play nicely with expect
diff --git a/etc/evince.profile b/etc/evince.profile
index 374fa4aaa..894c7c70d 100644
--- a/etc/evince.profile
+++ b/etc/evince.profile
@@ -15,5 +15,4 @@ shell none
15tracelog 15tracelog
16 16
17private-bin evince,evince-previewer,evince-thumbnailer 17private-bin evince,evince-previewer,evince-thumbnailer
18whitelist /tmp/.X11-unix
19private-dev 18private-dev
diff --git a/etc/firejail-default b/etc/firejail-default
index 0b771f834..1b0eb7658 100644
--- a/etc/firejail-default
+++ b/etc/firejail-default
@@ -31,6 +31,9 @@ profile firejail-default {
31/{,var/}run/user/**/pulse/ rw, 31/{,var/}run/user/**/pulse/ rw,
32/{,var/}run/user/**/pulse/** rw, 32/{,var/}run/user/**/pulse/** rw,
33/{,var/}run/firejail/mnt/fslogger r, 33/{,var/}run/firejail/mnt/fslogger r,
34/{,var/}run/firejail/appimage r,
35/{,var/}run/firejail/appimage/** r,
36/{,var/}run/firejail/appimage/** ix,
34/{run,dev}/shm/ r, 37/{run,dev}/shm/ r,
35/{run,dev}/shm/** rmwk, 38/{run,dev}/shm/** rmwk,
36 39
diff --git a/etc/keepass.profile b/etc/keepass.profile
index b2085f53d..23f9a7b40 100644
--- a/etc/keepass.profile
+++ b/etc/keepass.profile
@@ -13,7 +13,7 @@ nogroups
13nonewprivs 13nonewprivs
14noroot 14noroot
15nosound 15nosound
16protocol unix 16protocol unix,inet,inet6
17seccomp 17seccomp
18netfilter 18netfilter
19shell none 19shell none
diff --git a/etc/libreoffice.profile b/etc/libreoffice.profile
index 75a52e9ff..d6aceb7a8 100644
--- a/etc/libreoffice.profile
+++ b/etc/libreoffice.profile
@@ -1,5 +1,6 @@
1# Firejail profile for LibreOffice 1# Firejail profile for LibreOffice
2noblacklist ~/.config/libreoffice 2noblacklist ~/.config/libreoffice
3noblacklist /usr/local/sbin
3include /etc/firejail/disable-common.inc 4include /etc/firejail/disable-common.inc
4include /etc/firejail/disable-programs.inc 5include /etc/firejail/disable-programs.inc
5include /etc/firejail/disable-devel.inc 6include /etc/firejail/disable-devel.inc
@@ -10,9 +11,9 @@ netfilter
10nogroups 11nogroups
11nonewprivs 12nonewprivs
12noroot 13noroot
13protocol unix,inet,inet6,netlink 14protocol unix,inet,inet6
14seccomp 15seccomp
15tracelog 16tracelog
16 17
17private-dev 18private-dev
18whitelist /tmp/.X11-unix/ 19# whitelist /tmp/.X11-unix/
diff --git a/etc/vlc.profile b/etc/vlc.profile
index cdd098dd5..446e47864 100644
--- a/etc/vlc.profile
+++ b/etc/vlc.profile
@@ -14,7 +14,6 @@ noroot
14protocol unix,inet,inet6 14protocol unix,inet,inet6
15seccomp 15seccomp
16shell none 16shell none
17tracelog
18 17
19private-bin vlc,cvlc,nvlc,rvlc,qvlc,svlc 18private-bin vlc,cvlc,nvlc,rvlc,qvlc,svlc
20private-dev 19private-dev