aboutsummaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
Diffstat (limited to 'etc')
-rw-r--r--etc/clamtk.profile28
-rw-r--r--etc/disable-passwdmgr.inc1
-rw-r--r--etc/keepassxc.profile6
-rw-r--r--etc/steam.profile2
4 files changed, 34 insertions, 3 deletions
diff --git a/etc/clamtk.profile b/etc/clamtk.profile
new file mode 100644
index 000000000..d916381b2
--- /dev/null
+++ b/etc/clamtk.profile
@@ -0,0 +1,28 @@
1# Firejail profile for clamtk
2# This file is overwritten after every install/update
3# Persistent local customizations
4include /etc/firejail/clamtk.local
5# Persistent global definitions
6include /etc/firejail/globals.local
7
8caps.drop all
9ipc-namespace
10net none
11no3d
12nodbus
13nodvd
14nogroups
15nonewprivs
16noroot
17nosound
18notv
19novideo
20protocol unix
21seccomp
22shell none
23
24private-dev
25
26memory-deny-write-execute
27noexec ${HOME}
28noexec /tmp
diff --git a/etc/disable-passwdmgr.inc b/etc/disable-passwdmgr.inc
index 6ef11780e..597fbd1fc 100644
--- a/etc/disable-passwdmgr.inc
+++ b/etc/disable-passwdmgr.inc
@@ -10,6 +10,7 @@ blacklist ${HOME}/.config/Sinew Software Systems
10blacklist ${HOME}/.keepass 10blacklist ${HOME}/.keepass
11blacklist ${HOME}/.keepassx 11blacklist ${HOME}/.keepassx
12blacklist ${HOME}/.keepassxc 12blacklist ${HOME}/.keepassxc
13blacklist ${HOME}/.keepassxc-socket
13blacklist ${HOME}/.lastpass 14blacklist ${HOME}/.lastpass
14blacklist ${HOME}/.local/share/KeePass 15blacklist ${HOME}/.local/share/KeePass
15blacklist ${HOME}/.local/share/keepass 16blacklist ${HOME}/.local/share/keepass
diff --git a/etc/keepassxc.profile b/etc/keepassxc.profile
index dcd652e55..2073feabb 100644
--- a/etc/keepassxc.profile
+++ b/etc/keepassxc.profile
@@ -10,6 +10,7 @@ noblacklist ${HOME}/*.kdb
10noblacklist ${HOME}/*.kdbx 10noblacklist ${HOME}/*.kdbx
11noblacklist ${HOME}/.config/keepassxc 11noblacklist ${HOME}/.config/keepassxc
12noblacklist ${HOME}/.keepassxc 12noblacklist ${HOME}/.keepassxc
13noblacklist ${HOME}/.keepassxc-socket
13# 2.2.4 needs this path when compiled with "Native messaging browser extension" 14# 2.2.4 needs this path when compiled with "Native messaging browser extension"
14noblacklist ${HOME}/.mozilla 15noblacklist ${HOME}/.mozilla
15noblacklist ${DOCUMENTS} 16noblacklist ${DOCUMENTS}
@@ -34,7 +35,7 @@ nonewprivs
34noroot 35noroot
35nosound 36nosound
36notv 37notv
37pnovideo 38novideo
38protocol unix 39protocol unix
39seccomp 40seccomp
40shell none 41shell none
@@ -49,6 +50,7 @@ private-tmp
49noexec ${HOME} 50noexec ${HOME}
50noexec /tmp 51noexec /tmp
51 52
53# Mutex is stored in /tmp by default, which is broken by private-tmp
54# Make a new directory and have it stored there. Fixes #2062
52mkdir ${HOME}/.keepassxc-socket 55mkdir ${HOME}/.keepassxc-socket
53
54env TMPDIR=${HOME}/.keepassxc-socket/ 56env TMPDIR=${HOME}/.keepassxc-socket/
diff --git a/etc/steam.profile b/etc/steam.profile
index 4ebd941dd..8dbe613f8 100644
--- a/etc/steam.profile
+++ b/etc/steam.profile
@@ -67,5 +67,5 @@ shell none
67# private-dev should be commented for controllers 67# private-dev should be commented for controllers
68private-dev 68private-dev
69# private-etc breaks a small selection of games on some systems, comment to support those 69# private-etc breaks a small selection of games on some systems, comment to support those
70private-etc asound.conf,ca-certificates,dbus-1,drirc,fonts,group,gtk-2.0,gtk-3.0,host.conf,hostname,hosts,ld.so.cache,ld.so.preload,ld.so.conf,ld.so.conf.d,localtime,lsb-release,machine-id,mime.types,passwd,pulse,resolv.conf,ssl,pki,services,crypto-policies,alternatives 70private-etc asound.conf,ca-certificates,dbus-1,drirc,fonts,group,gtk-2.0,gtk-3.0,host.conf,hostname,hosts,ld.so.cache,ld.so.preload,ld.so.conf,ld.so.conf.d,localtime,lsb-release,machine-id,mime.types,passwd,pulse,resolv.conf,ssl,pki,services,crypto-policies,alternatives,bumblebee,nvidia,os-release
71private-tmp 71private-tmp