aboutsummaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
Diffstat (limited to 'etc')
-rw-r--r--etc/0ad.profile4
-rw-r--r--etc/7z.profile4
-rw-r--r--etc/Cryptocat.profile6
-rw-r--r--etc/Cyberfox.profile4
-rw-r--r--etc/FossaMail.profile6
-rw-r--r--etc/Mathematica.profile4
-rw-r--r--etc/Telegram.profile4
-rw-r--r--etc/Thunar.profile23
-rw-r--r--etc/VirtualBox.profile4
-rw-r--r--etc/Wire.profile4
-rw-r--r--etc/abrowser.profile5
-rw-r--r--etc/amarok.profile4
-rw-r--r--etc/ark.profile4
-rw-r--r--etc/atom-beta.profile4
-rw-r--r--etc/atom.profile4
-rw-r--r--etc/atool.profile4
-rw-r--r--etc/atril.profile4
-rw-r--r--etc/audacious.profile5
-rw-r--r--etc/audacity.profile4
-rw-r--r--etc/aweather.profile4
-rw-r--r--etc/bitlbee.profile4
-rw-r--r--etc/bleachbit.profile4
-rw-r--r--etc/bless.profile4
-rw-r--r--etc/brasero.profile4
-rw-r--r--etc/brave.profile4
-rw-r--r--etc/cherrytree.profile4
-rw-r--r--etc/chromium-browser.profile4
-rw-r--r--etc/chromium.profile5
-rw-r--r--etc/claws-mail.profile4
-rw-r--r--etc/clementine.profile4
-rw-r--r--etc/cmus.profile4
-rw-r--r--etc/conkeror.profile4
-rw-r--r--etc/corebird.profile4
-rw-r--r--etc/cpio.profile4
-rw-r--r--etc/cryptocat.profile4
-rw-r--r--etc/cyberfox.profile5
-rw-r--r--etc/deadbeef.profile4
-rw-r--r--etc/default.profile4
-rw-r--r--etc/deluge.profile4
-rw-r--r--etc/dillo.profile4
-rw-r--r--etc/disable-common.inc30
-rw-r--r--etc/disable-devel.inc4
-rw-r--r--etc/disable-passwdmgr.inc4
-rw-r--r--etc/disable-programs.inc9
-rw-r--r--etc/display.profile4
-rw-r--r--etc/dnscrypt-proxy.profile4
-rw-r--r--etc/dnsmasq.profile4
-rw-r--r--etc/dolphin.profile4
-rw-r--r--etc/dosbox.profile4
-rw-r--r--etc/dragon.profile4
-rw-r--r--etc/dropbox.profile4
-rw-r--r--etc/elinks.profile4
-rw-r--r--etc/emacs.profile4
-rw-r--r--etc/empathy.profile4
-rw-r--r--etc/enchant.profile4
-rw-r--r--etc/eog.profile4
-rw-r--r--etc/eom.profile4
-rw-r--r--etc/epiphany.profile4
-rw-r--r--etc/evince.profile4
-rw-r--r--etc/evolution.profile7
-rw-r--r--etc/exiftool.profile4
-rw-r--r--etc/fbreader.profile4
-rw-r--r--etc/feh.profile4
-rw-r--r--etc/file-roller.profile4
-rw-r--r--etc/file.profile4
-rw-r--r--etc/filezilla.profile4
-rw-r--r--etc/firefox-esr.profile4
-rw-r--r--etc/firefox.profile6
-rw-r--r--etc/firejail.config8
-rw-r--r--etc/flashpeak-slimjet.profile5
-rw-r--r--etc/flowblade.profile4
-rw-r--r--etc/fossamail.profile19
-rw-r--r--etc/franz.profile5
-rw-r--r--etc/gajim.profile4
-rw-r--r--etc/gedit.profile4
-rw-r--r--etc/gimp.profile4
-rw-r--r--etc/git.profile4
-rw-r--r--etc/gitter.profile4
-rw-r--r--etc/gjs.profile4
-rw-r--r--etc/gnome-2048.profile4
-rw-r--r--etc/gnome-books.profile4
-rw-r--r--etc/gnome-calculator.profile4
-rw-r--r--etc/gnome-chess.profile4
-rw-r--r--etc/gnome-clocks.profile4
-rw-r--r--etc/gnome-contacts.profile4
-rw-r--r--etc/gnome-documents.profile4
-rw-r--r--etc/gnome-maps.profile4
-rw-r--r--etc/gnome-mplayer.profile6
-rw-r--r--etc/gnome-music.profile4
-rw-r--r--etc/gnome-photos.profile4
-rw-r--r--etc/gnome-weather.profile4
-rw-r--r--etc/goobox.profile4
-rw-r--r--etc/google-chrome-beta.profile5
-rw-r--r--etc/google-chrome-stable.profile4
-rw-r--r--etc/google-chrome-unstable.profile5
-rw-r--r--etc/google-chrome.profile5
-rw-r--r--etc/google-play-music-desktop-player.profile4
-rw-r--r--etc/gpa.profile6
-rw-r--r--etc/gpg-agent.profile8
-rw-r--r--etc/gpg.profile9
-rw-r--r--etc/gpredict.profile4
-rw-r--r--etc/gtar.profile4
-rw-r--r--etc/gthumb.profile4
-rw-r--r--etc/guayadeque.profile4
-rw-r--r--etc/gwenview.profile4
-rw-r--r--etc/gzip.profile4
-rw-r--r--etc/hedgewars.profile4
-rw-r--r--etc/hexchat.profile4
-rw-r--r--etc/highlight.profile4
-rw-r--r--etc/icecat.profile5
-rw-r--r--etc/icedove.profile4
-rw-r--r--etc/iceweasel.profile4
-rw-r--r--etc/img2txt.profile4
-rw-r--r--etc/inkscape.profile4
-rw-r--r--etc/inox.profile5
-rw-r--r--etc/iridium-browser.profile6
-rw-r--r--etc/iridium.profile33
-rw-r--r--etc/jd-gui.profile4
-rw-r--r--etc/jitsi.profile4
-rw-r--r--etc/k3b.profile4
-rw-r--r--etc/kate.profile4
-rw-r--r--etc/keepass.profile4
-rw-r--r--etc/keepass2.profile4
-rw-r--r--etc/keepassx.profile11
-rw-r--r--etc/keepassx2.profile10
-rw-r--r--etc/kino.profile30
-rw-r--r--etc/kmail.profile4
-rw-r--r--etc/konversation.profile4
-rw-r--r--etc/less.profile4
-rw-r--r--etc/libreoffice.profile4
-rw-r--r--etc/localc.profile4
-rw-r--r--etc/lodraw.profile4
-rw-r--r--etc/loffice.profile4
-rw-r--r--etc/lofromtemplate.profile4
-rw-r--r--etc/login.users6
-rw-r--r--etc/loimpress.profile4
-rw-r--r--etc/lollypop.profile4
-rw-r--r--etc/lomath.profile4
-rw-r--r--etc/loweb.profile4
-rw-r--r--etc/lowriter.profile4
-rw-r--r--etc/luminance-hdr.profile4
-rw-r--r--etc/lxterminal.profile4
-rw-r--r--etc/lynx.profile4
-rw-r--r--etc/mathematica.profile4
-rw-r--r--etc/mcabber.profile4
-rw-r--r--etc/mediainfo.profile4
-rw-r--r--etc/midori.profile4
-rw-r--r--etc/mpv.profile4
-rw-r--r--etc/multimc5.profile4
-rw-r--r--etc/mumble.profile4
-rw-r--r--etc/mupdf.profile4
-rw-r--r--etc/mupen64plus.profile4
-rw-r--r--etc/mutt.profile4
-rw-r--r--etc/nautilus.profile4
-rw-r--r--etc/netsurf.profile4
-rw-r--r--etc/odt2txt.profile4
-rw-r--r--etc/okular.profile4
-rw-r--r--etc/openbox.profile4
-rw-r--r--etc/openshot.profile4
-rw-r--r--etc/opera-beta.profile5
-rw-r--r--etc/opera.profile5
-rw-r--r--etc/palemoon.profile5
-rw-r--r--etc/parole.profile4
-rw-r--r--etc/pdfsam.profile4
-rw-r--r--etc/pdftotext.profile4
-rw-r--r--etc/pidgin.profile4
-rw-r--r--etc/pithos.profile4
-rw-r--r--etc/pix.profile4
-rw-r--r--etc/pluma.profile4
-rw-r--r--etc/polari.profile4
-rw-r--r--etc/psi-plus.profile4
-rw-r--r--etc/qbittorrent.profile5
-rw-r--r--etc/qemu-launcher.profile4
-rw-r--r--etc/qemu-system-x86_64.profile4
-rw-r--r--etc/qpdfview.profile4
-rw-r--r--etc/qtox.profile4
-rw-r--r--etc/quassel.profile4
-rw-r--r--etc/quiterss.profile4
-rw-r--r--etc/qupzilla.profile4
-rw-r--r--etc/qutebrowser.profile4
-rw-r--r--etc/ranger.profile4
-rw-r--r--etc/rhythmbox.profile4
-rw-r--r--etc/rtorrent.profile4
-rw-r--r--etc/seamonkey-bin.profile4
-rw-r--r--etc/seamonkey.profile5
-rw-r--r--etc/server.profile4
-rw-r--r--etc/simple-scan.profile4
-rw-r--r--etc/skanlite.profile4
-rw-r--r--etc/skype.profile4
-rw-r--r--etc/skypeforlinux.profile4
-rw-r--r--etc/slack.profile4
-rw-r--r--etc/snap.profile4
-rw-r--r--etc/soffice.profile4
-rw-r--r--etc/spotify.profile4
-rw-r--r--etc/ssh-agent.profile4
-rw-r--r--etc/ssh.profile4
-rw-r--r--etc/start-tor-browser.profile6
-rw-r--r--etc/steam.profile4
-rw-r--r--etc/stellarium.profile4
-rw-r--r--etc/strings.profile4
-rw-r--r--etc/synfigstudio.profile4
-rw-r--r--etc/tar.profile4
-rw-r--r--etc/telegram.profile4
-rw-r--r--etc/thunar.profile1
-rw-r--r--etc/thunderbird.profile4
-rw-r--r--etc/totem.profile4
-rw-r--r--etc/tracker.profile4
-rw-r--r--etc/transmission-cli.profile4
-rw-r--r--etc/transmission-gtk.profile4
-rw-r--r--etc/transmission-qt.profile4
-rw-r--r--etc/transmission-show.profile4
-rw-r--r--etc/uget-gtk.profile4
-rw-r--r--etc/unbound.profile5
-rw-r--r--etc/unrar.profile4
-rw-r--r--etc/unzip.profile4
-rw-r--r--etc/uudeview.profile6
-rw-r--r--etc/uzbl-browser.profile33
-rw-r--r--etc/vim.profile4
-rw-r--r--etc/virtualbox.profile4
-rw-r--r--etc/vivaldi-beta.profile4
-rw-r--r--etc/vivaldi.profile4
-rw-r--r--etc/vlc.profile6
-rw-r--r--etc/w3m.profile4
-rw-r--r--etc/warzone2100.profile4
-rw-r--r--etc/weechat-curses.profile4
-rw-r--r--etc/weechat.profile4
-rw-r--r--etc/wesnoth.profile4
-rw-r--r--etc/wget.profile4
-rw-r--r--etc/whitelist-common.inc3
-rw-r--r--etc/wine.profile4
-rw-r--r--etc/wire.profile4
-rw-r--r--etc/wireshark.profile16
-rw-r--r--etc/xchat.profile4
-rw-r--r--etc/xed.profile4
-rw-r--r--etc/xfburn.profile4
-rw-r--r--etc/xiphos.profile4
-rw-r--r--etc/xmms.profile23
-rw-r--r--etc/xonotic-glx.profile4
-rw-r--r--etc/xonotic-sdl.profile4
-rw-r--r--etc/xonotic.profile4
-rw-r--r--etc/xpdf.profile4
-rw-r--r--etc/xplayer.profile4
-rw-r--r--etc/xpra.profile4
-rw-r--r--etc/xreader.profile4
-rw-r--r--etc/xviewer.profile4
-rw-r--r--etc/xz.profile4
-rw-r--r--etc/xzdec.profile4
-rw-r--r--etc/zathura.profile4
-rw-r--r--etc/zoom.profile4
249 files changed, 1210 insertions, 28 deletions
diff --git a/etc/0ad.profile b/etc/0ad.profile
index 1e7c06879..84addc229 100644
--- a/etc/0ad.profile
+++ b/etc/0ad.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/0ad.local
4
1# Firejail profile for 0ad. 5# Firejail profile for 0ad.
2noblacklist ~/.cache/0ad 6noblacklist ~/.cache/0ad
3noblacklist ~/.config/0ad 7noblacklist ~/.config/0ad
diff --git a/etc/7z.profile b/etc/7z.profile
index 319126540..102de44ee 100644
--- a/etc/7z.profile
+++ b/etc/7z.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/7z.local
4
1# 7zip crompression tool profile 5# 7zip crompression tool profile
2quiet 6quiet
3ignore noroot 7ignore noroot
diff --git a/etc/Cryptocat.profile b/etc/Cryptocat.profile
index 3db34c03c..da7f93791 100644
--- a/etc/Cryptocat.profile
+++ b/etc/Cryptocat.profile
@@ -1,4 +1,8 @@
1# Firejail profile for 1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/Cryptocat.local
4
5# Firejail profile for Cryptocat
2noblacklist ${HOME}/.config/Cryptocat 6noblacklist ${HOME}/.config/Cryptocat
3 7
4include /etc/firejail/disable-common.inc 8include /etc/firejail/disable-common.inc
diff --git a/etc/Cyberfox.profile b/etc/Cyberfox.profile
index 1f74606ce..bd2765bc7 100644
--- a/etc/Cyberfox.profile
+++ b/etc/Cyberfox.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/Cyberfox.local
4
1# Firejail profile for Cyberfox (based on Mozilla Firefox) 5# Firejail profile for Cyberfox (based on Mozilla Firefox)
2 6
3include /etc/firejail/cyberfox.profile 7include /etc/firejail/cyberfox.profile
diff --git a/etc/FossaMail.profile b/etc/FossaMail.profile
new file mode 100644
index 000000000..e0ba131ed
--- /dev/null
+++ b/etc/FossaMail.profile
@@ -0,0 +1,6 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/FossaMail.local
4
5# Firejail profile for FossaMail
6include /etc/firejail/fossamail.profile
diff --git a/etc/Mathematica.profile b/etc/Mathematica.profile
index e719f070f..2fe19c570 100644
--- a/etc/Mathematica.profile
+++ b/etc/Mathematica.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/Mathematica.local
4
1# Mathematica profile 5# Mathematica profile
2noblacklist ${HOME}/.Mathematica 6noblacklist ${HOME}/.Mathematica
3noblacklist ${HOME}/.Wolfram Research 7noblacklist ${HOME}/.Wolfram Research
diff --git a/etc/Telegram.profile b/etc/Telegram.profile
index 2e0f97821..6ccda7929 100644
--- a/etc/Telegram.profile
+++ b/etc/Telegram.profile
@@ -1,2 +1,6 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/Telegram.local
4
1# Telegram IRC profile 5# Telegram IRC profile
2include /etc/firejail/telegram.profile 6include /etc/firejail/telegram.profile
diff --git a/etc/Thunar.profile b/etc/Thunar.profile
new file mode 100644
index 000000000..5a27177e0
--- /dev/null
+++ b/etc/Thunar.profile
@@ -0,0 +1,23 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/Thunar.local
4
5# Firejail profile for thunar
6noblacklist ~/.config/Thunar
7noblacklist ~/.config/xfce4/xfconf/xfce-perchannel-xml/thunar.xml
8
9include /etc/firejail/disable-common.inc
10include /etc/firejail/disable-programs.inc
11include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-passwdmgr.inc
13
14caps.drop all
15netfilter
16nogroups
17nonewprivs
18noroot
19nosound
20protocol unix
21seccomp
22shell none
23tracelog
diff --git a/etc/VirtualBox.profile b/etc/VirtualBox.profile
index ff0a4b6ef..5e011b1fc 100644
--- a/etc/VirtualBox.profile
+++ b/etc/VirtualBox.profile
@@ -1 +1,5 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/VirtualBox.local
4
1include /etc/firejail/virtualbox.profile 5include /etc/firejail/virtualbox.profile
diff --git a/etc/Wire.profile b/etc/Wire.profile
index bd9645c7f..0895353d1 100644
--- a/etc/Wire.profile
+++ b/etc/Wire.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/Wire.local
4
1# wire messenger profile 5# wire messenger profile
2 6
3include /etc/firejail/wire.profile 7include /etc/firejail/wire.profile
diff --git a/etc/abrowser.profile b/etc/abrowser.profile
index f25bbd94d..bdd56e42f 100644
--- a/etc/abrowser.profile
+++ b/etc/abrowser.profile
@@ -1,6 +1,11 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/abrowser.local
4
1# Firejail profile for Abrowser 5# Firejail profile for Abrowser
2noblacklist ~/.mozilla 6noblacklist ~/.mozilla
3noblacklist ~/.cache/mozilla 7noblacklist ~/.cache/mozilla
8noblacklist ~/.pki
4include /etc/firejail/disable-common.inc 9include /etc/firejail/disable-common.inc
5include /etc/firejail/disable-programs.inc 10include /etc/firejail/disable-programs.inc
6include /etc/firejail/disable-devel.inc 11include /etc/firejail/disable-devel.inc
diff --git a/etc/amarok.profile b/etc/amarok.profile
index 8d5b35d47..c2a400fe4 100644
--- a/etc/amarok.profile
+++ b/etc/amarok.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/amarok.local
4
1# amarok profile 5# amarok profile
2include /etc/firejail/disable-common.inc 6include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 7include /etc/firejail/disable-programs.inc
diff --git a/etc/ark.profile b/etc/ark.profile
index 61b4c6f60..20a2d10e0 100644
--- a/etc/ark.profile
+++ b/etc/ark.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/ark.local
4
1# ark profile 5# ark profile
2noblacklist ~/.config/arkrc 6noblacklist ~/.config/arkrc
3 7
diff --git a/etc/atom-beta.profile b/etc/atom-beta.profile
index fa0b316bb..4c50687aa 100644
--- a/etc/atom-beta.profile
+++ b/etc/atom-beta.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/atom-beta.local
4
1# Firejail profile for Atom Beta. 5# Firejail profile for Atom Beta.
2noblacklist ~/.atom 6noblacklist ~/.atom
3noblacklist ~/.config/Atom 7noblacklist ~/.config/Atom
diff --git a/etc/atom.profile b/etc/atom.profile
index 61930d5c1..fc0e1b69c 100644
--- a/etc/atom.profile
+++ b/etc/atom.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/atom.local
4
1# Firejail profile for Atom. 5# Firejail profile for Atom.
2noblacklist ~/.atom 6noblacklist ~/.atom
3noblacklist ~/.config/Atom 7noblacklist ~/.config/Atom
diff --git a/etc/atool.profile b/etc/atool.profile
index 578a88fc7..37a2e09e4 100644
--- a/etc/atool.profile
+++ b/etc/atool.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/atool.local
4
1# atool profile 5# atool profile
2include /etc/firejail/disable-common.inc 6include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 7include /etc/firejail/disable-programs.inc
diff --git a/etc/atril.profile b/etc/atril.profile
index fbcca0c1b..1125f4f3c 100644
--- a/etc/atril.profile
+++ b/etc/atril.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/atril.local
4
1# Atril profile 5# Atril profile
2noblacklist ~/.config/atril 6noblacklist ~/.config/atril
3noblacklist ~/.local/share 7noblacklist ~/.local/share
diff --git a/etc/audacious.profile b/etc/audacious.profile
index e5275213c..63ba9af9c 100644
--- a/etc/audacious.profile
+++ b/etc/audacious.profile
@@ -1,4 +1,9 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/audacious.local
4
1# Audacious media player profile 5# Audacious media player profile
6noblacklist ~/.config/audacious
2include /etc/firejail/disable-common.inc 7include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 8include /etc/firejail/disable-programs.inc
4include /etc/firejail/disable-devel.inc 9include /etc/firejail/disable-devel.inc
diff --git a/etc/audacity.profile b/etc/audacity.profile
index 827fa4301..4394416ff 100644
--- a/etc/audacity.profile
+++ b/etc/audacity.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/audacity.local
4
1# Audacity profile 5# Audacity profile
2noblacklist ~/.audacity-data 6noblacklist ~/.audacity-data
3 7
diff --git a/etc/aweather.profile b/etc/aweather.profile
index fa8654f1e..b6ed0de51 100644
--- a/etc/aweather.profile
+++ b/etc/aweather.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/aweather.local
4
1# Firejail profile for aweather. 5# Firejail profile for aweather.
2noblacklist ~/.config/aweather 6noblacklist ~/.config/aweather
3include /etc/firejail/disable-common.inc 7include /etc/firejail/disable-common.inc
diff --git a/etc/bitlbee.profile b/etc/bitlbee.profile
index 87d2e843a..b056a54e3 100644
--- a/etc/bitlbee.profile
+++ b/etc/bitlbee.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/bitlbee.local
4
1# BitlBee instant messaging profile 5# BitlBee instant messaging profile
2noblacklist /sbin 6noblacklist /sbin
3noblacklist /usr/sbin 7noblacklist /usr/sbin
diff --git a/etc/bleachbit.profile b/etc/bleachbit.profile
index 0a71db9f0..b406b9985 100644
--- a/etc/bleachbit.profile
+++ b/etc/bleachbit.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/bleachbit.local
4
1# bleachbit profile 5# bleachbit profile
2include /etc/firejail/disable-common.inc 6include /etc/firejail/disable-common.inc
3# include /etc/firejail/disable-programs.inc 7# include /etc/firejail/disable-programs.inc
diff --git a/etc/bless.profile b/etc/bless.profile
index 752edadf7..b8325de39 100644
--- a/etc/bless.profile
+++ b/etc/bless.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/bless.local
4
1# 5#
2#Profile for bless 6#Profile for bless
3# 7#
diff --git a/etc/brasero.profile b/etc/brasero.profile
index 66de6fa50..6d84b0ca5 100644
--- a/etc/brasero.profile
+++ b/etc/brasero.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/brasero.local
4
1# brasero profile 5# brasero profile
2noblacklist ~/.config/brasero 6noblacklist ~/.config/brasero
3 7
diff --git a/etc/brave.profile b/etc/brave.profile
index 21ea7f908..d7678d5d5 100644
--- a/etc/brave.profile
+++ b/etc/brave.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/brave.local
4
1# Profile for Brave browser 5# Profile for Brave browser
2noblacklist ~/.config/brave 6noblacklist ~/.config/brave
3include /etc/firejail/disable-common.inc 7include /etc/firejail/disable-common.inc
diff --git a/etc/cherrytree.profile b/etc/cherrytree.profile
index 139dec8ec..8d7585fb9 100644
--- a/etc/cherrytree.profile
+++ b/etc/cherrytree.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/cherrytree.local
4
1# cherrytree note taking application 5# cherrytree note taking application
2noblacklist /usr/bin/python2* 6noblacklist /usr/bin/python2*
3noblacklist /usr/lib/python3* 7noblacklist /usr/lib/python3*
diff --git a/etc/chromium-browser.profile b/etc/chromium-browser.profile
index d989b736b..e7dd5afe3 100644
--- a/etc/chromium-browser.profile
+++ b/etc/chromium-browser.profile
@@ -1,2 +1,6 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/chromium-browser.local
4
1# Chromium browser profile 5# Chromium browser profile
2include /etc/firejail/chromium.profile 6include /etc/firejail/chromium.profile
diff --git a/etc/chromium.profile b/etc/chromium.profile
index 7610d9b26..531f9156c 100644
--- a/etc/chromium.profile
+++ b/etc/chromium.profile
@@ -1,6 +1,11 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/chromium.local
4
1# Chromium browser profile 5# Chromium browser profile
2noblacklist ~/.config/chromium 6noblacklist ~/.config/chromium
3noblacklist ~/.cache/chromium 7noblacklist ~/.cache/chromium
8noblacklist ~/.pki
4include /etc/firejail/disable-common.inc 9include /etc/firejail/disable-common.inc
5include /etc/firejail/disable-programs.inc 10include /etc/firejail/disable-programs.inc
6 11
diff --git a/etc/claws-mail.profile b/etc/claws-mail.profile
index 8921bb25e..3bffb9b0a 100644
--- a/etc/claws-mail.profile
+++ b/etc/claws-mail.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/claws-mail.local
4
1# claws-mail profile 5# claws-mail profile
2noblacklist ~/.claws-mail 6noblacklist ~/.claws-mail
3noblacklist ~/.signature 7noblacklist ~/.signature
diff --git a/etc/clementine.profile b/etc/clementine.profile
index 5ce085358..f92413a36 100644
--- a/etc/clementine.profile
+++ b/etc/clementine.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/clementine.local
4
1# Clementine media player profile 5# Clementine media player profile
2include /etc/firejail/disable-common.inc 6include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 7include /etc/firejail/disable-programs.inc
diff --git a/etc/cmus.profile b/etc/cmus.profile
index 2e2a6940c..50bfbf7c8 100644
--- a/etc/cmus.profile
+++ b/etc/cmus.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/cmus.local
4
1# cmus profile 5# cmus profile
2noblacklist ${HOME}/.config/cmus 6noblacklist ${HOME}/.config/cmus
3 7
diff --git a/etc/conkeror.profile b/etc/conkeror.profile
index e82eeec4c..b87aa835d 100644
--- a/etc/conkeror.profile
+++ b/etc/conkeror.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/conkeror.local
4
1# Firejail profile for Conkeror web browser profile 5# Firejail profile for Conkeror web browser profile
2noblacklist ${HOME}/.conkeror.mozdev.org 6noblacklist ${HOME}/.conkeror.mozdev.org
3include /etc/firejail/disable-common.inc 7include /etc/firejail/disable-common.inc
diff --git a/etc/corebird.profile b/etc/corebird.profile
index 6fb8219e8..a6514af5a 100644
--- a/etc/corebird.profile
+++ b/etc/corebird.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/corebird.local
4
1# Firejail corebird profile 5# Firejail corebird profile
2include /etc/firejail/disable-common.inc 6include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 7include /etc/firejail/disable-programs.inc
diff --git a/etc/cpio.profile b/etc/cpio.profile
index cf89acdac..d4b0e6d2d 100644
--- a/etc/cpio.profile
+++ b/etc/cpio.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/cpio.local
4
1# cpio profile 5# cpio profile
2# /sbin and /usr/sbin are visible inside the sandbox 6# /sbin and /usr/sbin are visible inside the sandbox
3# /boot is not visible and /var is heavily modified 7# /boot is not visible and /var is heavily modified
diff --git a/etc/cryptocat.profile b/etc/cryptocat.profile
index 0d392b272..ea5c5c69b 100644
--- a/etc/cryptocat.profile
+++ b/etc/cryptocat.profile
@@ -1 +1,5 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/cryptocat.local
4
1include /etc/Cryptocat.profile 5include /etc/Cryptocat.profile
diff --git a/etc/cyberfox.profile b/etc/cyberfox.profile
index f722915f0..3dffe187c 100644
--- a/etc/cyberfox.profile
+++ b/etc/cyberfox.profile
@@ -1,6 +1,11 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/cyberfox.local
4
1# Firejail profile for Cyberfox (based on Mozilla Firefox) 5# Firejail profile for Cyberfox (based on Mozilla Firefox)
2noblacklist ~/.8pecxstudios 6noblacklist ~/.8pecxstudios
3noblacklist ~/.cache/8pecxstudios 7noblacklist ~/.cache/8pecxstudios
8noblacklist ~/.pki
4include /etc/firejail/disable-common.inc 9include /etc/firejail/disable-common.inc
5include /etc/firejail/disable-programs.inc 10include /etc/firejail/disable-programs.inc
6include /etc/firejail/disable-devel.inc 11include /etc/firejail/disable-devel.inc
diff --git a/etc/deadbeef.profile b/etc/deadbeef.profile
index 04abd0a92..603d6345c 100644
--- a/etc/deadbeef.profile
+++ b/etc/deadbeef.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/deadbeef.local
4
1# DeaDBeeF media player profile 5# DeaDBeeF media player profile
2noblacklist ${HOME}/.config/deadbeef 6noblacklist ${HOME}/.config/deadbeef
3 7
diff --git a/etc/default.profile b/etc/default.profile
index 603321316..66b04896f 100644
--- a/etc/default.profile
+++ b/etc/default.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/default.local
4
1################################ 5################################
2# Generic GUI application profile 6# Generic GUI application profile
3################################ 7################################
diff --git a/etc/deluge.profile b/etc/deluge.profile
index c6ddec3ec..7b4a49db5 100644
--- a/etc/deluge.profile
+++ b/etc/deluge.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/deluge.local
4
1# deluge bittorrernt client profile 5# deluge bittorrernt client profile
2include /etc/firejail/disable-common.inc 6include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 7include /etc/firejail/disable-programs.inc
diff --git a/etc/dillo.profile b/etc/dillo.profile
index 108787920..f8a3e5252 100644
--- a/etc/dillo.profile
+++ b/etc/dillo.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/dillo.local
4
1# Firejail profile for Dillo web browser 5# Firejail profile for Dillo web browser
2noblacklist ~/.dillo 6noblacklist ~/.dillo
3include /etc/firejail/disable-common.inc 7include /etc/firejail/disable-common.inc
diff --git a/etc/disable-common.inc b/etc/disable-common.inc
index 22f54604a..79732b197 100644
--- a/etc/disable-common.inc
+++ b/etc/disable-common.inc
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/disable-common.local
4
1# History files in $HOME 5# History files in $HOME
2blacklist-nolog ${HOME}/.history 6blacklist-nolog ${HOME}/.history
3blacklist-nolog ${HOME}/.*_history 7blacklist-nolog ${HOME}/.*_history
@@ -72,12 +76,9 @@ blacklist /etc/profile.d
72blacklist /etc/rc.local 76blacklist /etc/rc.local
73blacklist /etc/anacrontab 77blacklist /etc/anacrontab
74 78
75# General startup files 79# Startup files
76read-only ${HOME}/.xinitrc 80read-only ${HOME}/.xinitrc
77read-only ${HOME}/.xserverrc 81read-only ${HOME}/.xserverrc
78read-only ${HOME}/.profile
79
80# Shell startup files
81read-only ${HOME}/.antigen 82read-only ${HOME}/.antigen
82read-only ${HOME}/.bash_login 83read-only ${HOME}/.bash_login
83read-only ${HOME}/.bashrc 84read-only ${HOME}/.bashrc
@@ -96,12 +97,21 @@ read-only ${HOME}/.tcshrc
96read-only ${HOME}/.cshrc 97read-only ${HOME}/.cshrc
97read-only ${HOME}/.csh_files 98read-only ${HOME}/.csh_files
98read-only ${HOME}/.profile 99read-only ${HOME}/.profile
100read-only ${HOME}/.forward
101read-only ${HOME}/.login
102read-only ${HOME}/.logout
103read-only ${HOME}/.pgpkey
104read-only ${HOME}/.plan
105read-only ${HOME}/.project
99 106
100# Initialization files that allow arbitrary command execution 107# Initialization files that allow arbitrary command execution
101read-only ${HOME}/.caffrc 108read-only ${HOME}/.caffrc
102read-only ${HOME}/.dotfiles 109read-only ${HOME}/.dotfiles
103read-only ${HOME}/dotfiles 110read-only ${HOME}/dotfiles
104read-only ${HOME}/.mailcap 111read-only ${HOME}/.mailcap
112read-only ${HOME}/.muttrc
113read-only ${HOME}/.mutt/muttrc
114read-only ${HOME}/.msmtprc
105read-only ${HOME}/.exrc 115read-only ${HOME}/.exrc
106read-only ${HOME}/_exrc 116read-only ${HOME}/_exrc
107read-only ${HOME}/.vimrc 117read-only ${HOME}/.vimrc
@@ -118,8 +128,16 @@ read-only ${HOME}/.reportbugrc
118read-only ${HOME}/.xmonad 128read-only ${HOME}/.xmonad
119read-only ${HOME}/.xscreensaver 129read-only ${HOME}/.xscreensaver
120 130
121# The user ~/bin directory can override commands such as ls 131# Make directories commonly found in $PATH read-only
122read-only ${HOME}/bin 132read-only ${HOME}/bin
133read-only ${HOME}/.gem
134read-only ${HOME}/.luarocks
135read-only ${HOME}/.npm-packages
136
137# Make the contents of ~/.local read-only,
138# except the commonly-used ~/.local/share
139read-only ${HOME}/.local
140read-write ${HOME}/.local/share
123 141
124# top secret 142# top secret
125blacklist ${HOME}/.ecryptfs 143blacklist ${HOME}/.ecryptfs
@@ -197,6 +215,8 @@ blacklist /usr/lib64/virtualbox
197 215
198# prevent lxterminal connecting to an existing lxterminal session 216# prevent lxterminal connecting to an existing lxterminal session
199blacklist /tmp/.lxterminal-socket* 217blacklist /tmp/.lxterminal-socket*
218# prevent tmux connecting to an existing session
219blacklist /tmp/tmux-*
200 220
201# disable terminals running as server resulting in sandbox escape 221# disable terminals running as server resulting in sandbox escape
202blacklist ${PATH}/gnome-terminal 222blacklist ${PATH}/gnome-terminal
diff --git a/etc/disable-devel.inc b/etc/disable-devel.inc
index 2ac367f37..24c739b5b 100644
--- a/etc/disable-devel.inc
+++ b/etc/disable-devel.inc
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/disable-devel.local
4
1# development tools 5# development tools
2 6
3# GCC 7# GCC
diff --git a/etc/disable-passwdmgr.inc b/etc/disable-passwdmgr.inc
index 8f8aa1c2c..c4112d4d5 100644
--- a/etc/disable-passwdmgr.inc
+++ b/etc/disable-passwdmgr.inc
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/disable-passwdmgr.local
4
1blacklist ${HOME}/.pki/nssdb 5blacklist ${HOME}/.pki/nssdb
2blacklist ${HOME}/.lastpass 6blacklist ${HOME}/.lastpass
3blacklist ${HOME}/.keepassx 7blacklist ${HOME}/.keepassx
diff --git a/etc/disable-programs.inc b/etc/disable-programs.inc
index 69f0a2e1b..c59285e85 100644
--- a/etc/disable-programs.inc
+++ b/etc/disable-programs.inc
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/disable-programs.local
4
1blacklist ${HOME}/.*coin 5blacklist ${HOME}/.*coin
2blacklist ${HOME}/.8pecxstudios 6blacklist ${HOME}/.8pecxstudios
3blacklist ${HOME}/.Atom 7blacklist ${HOME}/.Atom
@@ -66,12 +70,14 @@ blacklist ${HOME}/.config/Mumble
66blacklist ${HOME}/.config/QuiteRss 70blacklist ${HOME}/.config/QuiteRss
67blacklist ${HOME}/.config/QuiteRssrc 71blacklist ${HOME}/.config/QuiteRssrc
68blacklist ${HOME}/.config/Slack 72blacklist ${HOME}/.config/Slack
73blacklist ${HOME}/.config/Thunar
69blacklist ${HOME}/.config/VirtualBox 74blacklist ${HOME}/.config/VirtualBox
70blacklist ${HOME}/.config/Wire 75blacklist ${HOME}/.config/Wire
71blacklist ${HOME}/.config/ardour4 76blacklist ${HOME}/.config/ardour4
72blacklist ${HOME}/.config/ardour5 77blacklist ${HOME}/.config/ardour5
73blacklist ${HOME}/.config/arkrc 78blacklist ${HOME}/.config/arkrc
74blacklist ${HOME}/.config/atril 79blacklist ${HOME}/.config/atril
80blacklist ${HOME}/.config/audacious
75blacklist ${HOME}/.config/autostart 81blacklist ${HOME}/.config/autostart
76blacklist ${HOME}/.config/autostart/dropbox.desktop 82blacklist ${HOME}/.config/autostart/dropbox.desktop
77blacklist ${HOME}/.config/aweather 83blacklist ${HOME}/.config/aweather
@@ -145,6 +151,7 @@ blacklist ${HOME}/.config/wireshark
145blacklist ${HOME}/.config/xchat 151blacklist ${HOME}/.config/xchat
146blacklist ${HOME}/.config/xed 152blacklist ${HOME}/.config/xed
147blacklist ${HOME}/.config/xfburn 153blacklist ${HOME}/.config/xfburn
154blacklist ${HOME}/.config/xfce4/xfconf/xfce-perchannel-xml/thunar.xml
148blacklist ${HOME}/.config/xplayer 155blacklist ${HOME}/.config/xplayer
149blacklist ${HOME}/.config/xreader 156blacklist ${HOME}/.config/xreader
150blacklist ${HOME}/.config/xviewer 157blacklist ${HOME}/.config/xviewer
@@ -278,3 +285,5 @@ blacklist ${HOME}/.xpdfrc
278blacklist ${HOME}/.zoom 285blacklist ${HOME}/.zoom
279blacklist ${HOME}/wallet.dat 286blacklist ${HOME}/wallet.dat
280blacklist /tmp/ssh-* 287blacklist /tmp/ssh-*
288blacklist ${HOME}/.kinorc
289blacklist ${HOME}/.kino-history
diff --git a/etc/display.profile b/etc/display.profile
index ec041bff7..83fbc965a 100644
--- a/etc/display.profile
+++ b/etc/display.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/display.local
4
1# display (ImageMagick tool) image viewer profile 5# display (ImageMagick tool) image viewer profile
2include /etc/firejail/disable-common.inc 6include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 7include /etc/firejail/disable-programs.inc
diff --git a/etc/dnscrypt-proxy.profile b/etc/dnscrypt-proxy.profile
index 926b8bfcc..c69707181 100644
--- a/etc/dnscrypt-proxy.profile
+++ b/etc/dnscrypt-proxy.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/dnscrypt-proxy.local
4
1# security profile for dnscrypt-proxy 5# security profile for dnscrypt-proxy
2noblacklist /sbin 6noblacklist /sbin
3noblacklist /usr/sbin 7noblacklist /usr/sbin
diff --git a/etc/dnsmasq.profile b/etc/dnsmasq.profile
index 3bd43f144..0af4a3f62 100644
--- a/etc/dnsmasq.profile
+++ b/etc/dnsmasq.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/dnsmasq.local
4
1# dnsmasq profile 5# dnsmasq profile
2noblacklist /sbin 6noblacklist /sbin
3noblacklist /usr/sbin 7noblacklist /usr/sbin
diff --git a/etc/dolphin.profile b/etc/dolphin.profile
index 09a86f811..2b7919083 100644
--- a/etc/dolphin.profile
+++ b/etc/dolphin.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/dolphin.local
4
1# dolphin profile 5# dolphin profile
2 6
3# warning: firejail is currently not effectively constraining dolphin since used services are started by kdeinit5 7# warning: firejail is currently not effectively constraining dolphin since used services are started by kdeinit5
diff --git a/etc/dosbox.profile b/etc/dosbox.profile
index 45fbb712a..3ef6931fc 100644
--- a/etc/dosbox.profile
+++ b/etc/dosbox.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/dosbox.local
4
1# Firejail profile for dosbox 5# Firejail profile for dosbox
2noblacklist ~/.dosbox 6noblacklist ~/.dosbox
3 7
diff --git a/etc/dragon.profile b/etc/dragon.profile
index 09cb73802..b6228fd41 100644
--- a/etc/dragon.profile
+++ b/etc/dragon.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/dragon.local
4
1# dragon player profile 5# dragon player profile
2noblacklist ~/.config/dragonplayerrc 6noblacklist ~/.config/dragonplayerrc
3 7
diff --git a/etc/dropbox.profile b/etc/dropbox.profile
index 40efd62b2..b58fa0ed1 100644
--- a/etc/dropbox.profile
+++ b/etc/dropbox.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/dropbox.local
4
1# dropbox profile 5# dropbox profile
2noblacklist ~/.config/autostart 6noblacklist ~/.config/autostart
3include /etc/firejail/disable-common.inc 7include /etc/firejail/disable-common.inc
diff --git a/etc/elinks.profile b/etc/elinks.profile
index ade15f203..1fad33d54 100644
--- a/etc/elinks.profile
+++ b/etc/elinks.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/elinks.local
4
1# elinks profile 5# elinks profile
2noblacklist ~/.elinks 6noblacklist ~/.elinks
3 7
diff --git a/etc/emacs.profile b/etc/emacs.profile
index 2b9c5805c..21767402f 100644
--- a/etc/emacs.profile
+++ b/etc/emacs.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/emacs.local
4
1# emacs profile 5# emacs profile
2noblacklist ~/.emacs 6noblacklist ~/.emacs
3noblacklist ~/.emacs.d 7noblacklist ~/.emacs.d
diff --git a/etc/empathy.profile b/etc/empathy.profile
index 2a0a6389c..4cf90908f 100644
--- a/etc/empathy.profile
+++ b/etc/empathy.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/empathy.local
4
1# Empathy instant messaging profile 5# Empathy instant messaging profile
2include /etc/firejail/disable-common.inc 6include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 7include /etc/firejail/disable-programs.inc
diff --git a/etc/enchant.profile b/etc/enchant.profile
index cf8288919..8b1995a95 100644
--- a/etc/enchant.profile
+++ b/etc/enchant.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/enchant.local
4
1# enchant profile 5# enchant profile
2noblacklist ~/.config/enchant 6noblacklist ~/.config/enchant
3 7
diff --git a/etc/eog.profile b/etc/eog.profile
index d463f3a97..c5afec7fa 100644
--- a/etc/eog.profile
+++ b/etc/eog.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/eog.local
4
1# eog (gnome image viewer) profile 5# eog (gnome image viewer) profile
2noblacklist ~/.config/eog 6noblacklist ~/.config/eog
3 7
diff --git a/etc/eom.profile b/etc/eom.profile
index dfcea82c1..a7e10ba9e 100644
--- a/etc/eom.profile
+++ b/etc/eom.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/eom.local
4
1# Firejail profile for Eye of Mate (eom) 5# Firejail profile for Eye of Mate (eom)
2noblacklist ~/.config/mate/eom 6noblacklist ~/.config/mate/eom
3 7
diff --git a/etc/epiphany.profile b/etc/epiphany.profile
index 0e898f02b..1bf259440 100644
--- a/etc/epiphany.profile
+++ b/etc/epiphany.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/epiphany.local
4
1# Epiphany browser profile 5# Epiphany browser profile
2noblacklist ${HOME}/.config/epiphany 6noblacklist ${HOME}/.config/epiphany
3noblacklist ${HOME}/.cache/epiphany 7noblacklist ${HOME}/.cache/epiphany
diff --git a/etc/evince.profile b/etc/evince.profile
index 1ec384947..94cefdd8b 100644
--- a/etc/evince.profile
+++ b/etc/evince.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/evince.local
4
1# evince pdf reader profile 5# evince pdf reader profile
2noblacklist ~/.config/evince 6noblacklist ~/.config/evince
3 7
diff --git a/etc/evolution.profile b/etc/evolution.profile
index ab6dd7a4a..cb6615716 100644
--- a/etc/evolution.profile
+++ b/etc/evolution.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/evolution.local
4
1# evolution profile 5# evolution profile
2noblacklist ~/.config/evolution 6noblacklist ~/.config/evolution
3noblacklist ~/.local/share/evolution 7noblacklist ~/.local/share/evolution
@@ -6,6 +10,9 @@ noblacklist ~/.pki
6noblacklist ~/.pki/nssdb 10noblacklist ~/.pki/nssdb
7noblacklist ~/.gnupg 11noblacklist ~/.gnupg
8 12
13noblacklist /var/spool/mail
14noblacklist /var/mail
15
9include /etc/firejail/disable-common.inc 16include /etc/firejail/disable-common.inc
10include /etc/firejail/disable-programs.inc 17include /etc/firejail/disable-programs.inc
11include /etc/firejail/disable-devel.inc 18include /etc/firejail/disable-devel.inc
diff --git a/etc/exiftool.profile b/etc/exiftool.profile
index 1cae8c093..356735421 100644
--- a/etc/exiftool.profile
+++ b/etc/exiftool.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/exiftool.local
4
1# exiftool profile 5# exiftool profile
2noblacklist /usr/bin/perl 6noblacklist /usr/bin/perl
3noblacklist /usr/share/perl* 7noblacklist /usr/share/perl*
diff --git a/etc/fbreader.profile b/etc/fbreader.profile
index ec098d5fe..77bf89f35 100644
--- a/etc/fbreader.profile
+++ b/etc/fbreader.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/fbreader.local
4
1# fbreader ebook reader profile 5# fbreader ebook reader profile
2noblacklist ${HOME}/.FBReader 6noblacklist ${HOME}/.FBReader
3 7
diff --git a/etc/feh.profile b/etc/feh.profile
index 2812effc9..e00b6a821 100644
--- a/etc/feh.profile
+++ b/etc/feh.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/feh.local
4
1# feh image viewer profile 5# feh image viewer profile
2include /etc/firejail/disable-common.inc 6include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 7include /etc/firejail/disable-programs.inc
diff --git a/etc/file-roller.profile b/etc/file-roller.profile
index 6116389db..804d20ce1 100644
--- a/etc/file-roller.profile
+++ b/etc/file-roller.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/file-roller.local
4
1# file-roller profile 5# file-roller profile
2include /etc/firejail/disable-common.inc 6include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 7include /etc/firejail/disable-programs.inc
diff --git a/etc/file.profile b/etc/file.profile
index d145fe12a..2f972212e 100644
--- a/etc/file.profile
+++ b/etc/file.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/file.local
4
1# file profile 5# file profile
2quiet 6quiet
3include /etc/firejail/disable-common.inc 7include /etc/firejail/disable-common.inc
diff --git a/etc/filezilla.profile b/etc/filezilla.profile
index a40fceec1..5f2636bf5 100644
--- a/etc/filezilla.profile
+++ b/etc/filezilla.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/filezilla.local
4
1# FileZilla ftp profile 5# FileZilla ftp profile
2noblacklist ${HOME}/.filezilla 6noblacklist ${HOME}/.filezilla
3noblacklist ${HOME}/.config/filezilla 7noblacklist ${HOME}/.config/filezilla
diff --git a/etc/firefox-esr.profile b/etc/firefox-esr.profile
index d2fde9a3f..753f64526 100644
--- a/etc/firefox-esr.profile
+++ b/etc/firefox-esr.profile
@@ -1,2 +1,6 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/firefox-esr.local
4
1# Firejail profile for Mozilla Firefox ESR 5# Firejail profile for Mozilla Firefox ESR
2include /etc/firejail/firefox.profile 6include /etc/firejail/firefox.profile
diff --git a/etc/firefox.profile b/etc/firefox.profile
index c3a9b2a62..5f891ea3c 100644
--- a/etc/firefox.profile
+++ b/etc/firefox.profile
@@ -1,9 +1,14 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/firefox.local
4
1# Firejail profile for Mozilla Firefox (Iceweasel in Debian) 5# Firejail profile for Mozilla Firefox (Iceweasel in Debian)
2noblacklist ~/.mozilla 6noblacklist ~/.mozilla
3noblacklist ~/.cache/mozilla 7noblacklist ~/.cache/mozilla
4noblacklist ~/.config/qpdfview 8noblacklist ~/.config/qpdfview
5noblacklist ~/.local/share/qpdfview 9noblacklist ~/.local/share/qpdfview
6noblacklist ~/.kde/share/apps/okular 10noblacklist ~/.kde/share/apps/okular
11noblacklist ~/.pki
7include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
8include /etc/firejail/disable-programs.inc 13include /etc/firejail/disable-programs.inc
9include /etc/firejail/disable-devel.inc 14include /etc/firejail/disable-devel.inc
@@ -30,6 +35,7 @@ whitelist ~/.pentadactyl
30whitelist ~/.keysnail.js 35whitelist ~/.keysnail.js
31whitelist ~/.config/gnome-mplayer 36whitelist ~/.config/gnome-mplayer
32whitelist ~/.cache/gnome-mplayer/plugin 37whitelist ~/.cache/gnome-mplayer/plugin
38mkdir ~/.pki
33whitelist ~/.pki 39whitelist ~/.pki
34whitelist ~/.config/qpdfview 40whitelist ~/.config/qpdfview
35whitelist ~/.local/share/qpdfview 41whitelist ~/.local/share/qpdfview
diff --git a/etc/firejail.config b/etc/firejail.config
index 824e3f503..766802a7d 100644
--- a/etc/firejail.config
+++ b/etc/firejail.config
@@ -20,6 +20,12 @@
20# Enable Firejail green prompt in terminal, default disabled 20# Enable Firejail green prompt in terminal, default disabled
21# firejail-prompt no 21# firejail-prompt no
22 22
23# Follow symlink as user. While using --whitelist feature,
24# symlinks pointing outside home directory are followed only
25# if both the link and the real file are owned by the user.
26# Enabled by default
27# follow-symlink-as-user yes
28
23# Force use of nonewprivs. This mitigates the possibility of 29# Force use of nonewprivs. This mitigates the possibility of
24# a user abusing firejail's features to trick a privileged (suid 30# a user abusing firejail's features to trick a privileged (suid
25# or file capabilities) process into loading code or configuration 31# or file capabilities) process into loading code or configuration
@@ -79,6 +85,6 @@
79# Firejail window title in Xephyr, default enabled. 85# Firejail window title in Xephyr, default enabled.
80# xephyr-window-title yes 86# xephyr-window-title yes
81 87
82# Xephyr command extra parameters. None by default, and the declaration is commented out. 88# Xephyr command extra parameters. None by default; these are examples.
83# xephyr-extra-params -keybd ephyr,,,xkbmodel=evdev 89# xephyr-extra-params -keybd ephyr,,,xkbmodel=evdev
84# xephyr-extra-params -grayscale 90# xephyr-extra-params -grayscale
diff --git a/etc/flashpeak-slimjet.profile b/etc/flashpeak-slimjet.profile
index 3c23ff6f6..56437ba06 100644
--- a/etc/flashpeak-slimjet.profile
+++ b/etc/flashpeak-slimjet.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/flashpeak-slimjet.local
4
1# SlimJet browser profile 5# SlimJet browser profile
2# This is a whitelisted profile, the internal browser sandbox 6# This is a whitelisted profile, the internal browser sandbox
3# is disabled because it requires sudo password. The command 7# is disabled because it requires sudo password. The command
@@ -7,6 +11,7 @@
7# 11#
8noblacklist ~/.config/slimjet 12noblacklist ~/.config/slimjet
9noblacklist ~/.cache/slimjet 13noblacklist ~/.cache/slimjet
14noblacklist ~/.pki
10include /etc/firejail/disable-common.inc 15include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-programs.inc 16include /etc/firejail/disable-programs.inc
12 17
diff --git a/etc/flowblade.profile b/etc/flowblade.profile
index 12afdb0aa..e60417081 100644
--- a/etc/flowblade.profile
+++ b/etc/flowblade.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/flowblade.local
4
1# FlowBlade profile 5# FlowBlade profile
2noblacklist ${HOME}/.flowblade 6noblacklist ${HOME}/.flowblade
3noblacklist ${HOME}/.config/flowblade 7noblacklist ${HOME}/.config/flowblade
diff --git a/etc/fossamail.profile b/etc/fossamail.profile
new file mode 100644
index 000000000..3caaad71c
--- /dev/null
+++ b/etc/fossamail.profile
@@ -0,0 +1,19 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/fossamail.local
4
5# Firejail profile for FossaMail
6
7noblacklist ~/.gnupg
8mkdir ~/.gnupg
9whitelist ~/.gnupg
10
11noblacklist ~/.fossamail
12mkdir ~/.fossamail
13whitelist ~/.fossamail
14
15noblacklist ~/.cache/fossamail
16mkdir ~/.cache/fossamail
17whitelist ~/.cache/fossamail
18
19include /etc/firejail/firefox.profile
diff --git a/etc/franz.profile b/etc/franz.profile
index 0b3be551b..05ff72a47 100644
--- a/etc/franz.profile
+++ b/etc/franz.profile
@@ -1,6 +1,11 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/franz.local
4
1# Franz profile 5# Franz profile
2noblacklist ~/.config/Franz 6noblacklist ~/.config/Franz
3noblacklist ~/.cache/Franz 7noblacklist ~/.cache/Franz
8noblacklist ~/.pki
4include /etc/firejail/disable-common.inc 9include /etc/firejail/disable-common.inc
5include /etc/firejail/disable-programs.inc 10include /etc/firejail/disable-programs.inc
6include /etc/firejail/disable-devel.inc 11include /etc/firejail/disable-devel.inc
diff --git a/etc/gajim.profile b/etc/gajim.profile
index eb60f858b..bac6cc466 100644
--- a/etc/gajim.profile
+++ b/etc/gajim.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/gajim.local
4
1# Firejail profile for Gajim 5# Firejail profile for Gajim
2noblacklist ${HOME}/.cache/gajim 6noblacklist ${HOME}/.cache/gajim
3noblacklist ${HOME}/.local/share/gajim 7noblacklist ${HOME}/.local/share/gajim
diff --git a/etc/gedit.profile b/etc/gedit.profile
index a25286bfa..9f4eee9b3 100644
--- a/etc/gedit.profile
+++ b/etc/gedit.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/gedit.local
4
1# gedit profile 5# gedit profile
2 6
3# when gedit is started via gnome-shell, firejail is not applied because systemd will start it 7# when gedit is started via gnome-shell, firejail is not applied because systemd will start it
diff --git a/etc/gimp.profile b/etc/gimp.profile
index cb441fc9d..d07398a41 100644
--- a/etc/gimp.profile
+++ b/etc/gimp.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/gimp.local
4
1# gimp 5# gimp
2noblacklist ${HOME}/.gimp* 6noblacklist ${HOME}/.gimp*
3include /etc/firejail/disable-common.inc 7include /etc/firejail/disable-common.inc
diff --git a/etc/git.profile b/etc/git.profile
index 80e534e20..5fbacd7fa 100644
--- a/etc/git.profile
+++ b/etc/git.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/git.local
4
1# git profile 5# git profile
2quiet 6quiet
3noblacklist ~/.gitconfig 7noblacklist ~/.gitconfig
diff --git a/etc/gitter.profile b/etc/gitter.profile
index f43f5f199..054d859f8 100644
--- a/etc/gitter.profile
+++ b/etc/gitter.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/gitter.local
4
1# Firejail profile for Gitter 5# Firejail profile for Gitter
2noblacklist ~/.config/Gitter 6noblacklist ~/.config/Gitter
3include /etc/firejail/disable-common.inc 7include /etc/firejail/disable-common.inc
diff --git a/etc/gjs.profile b/etc/gjs.profile
index 8d71728a2..24ec70e86 100644
--- a/etc/gjs.profile
+++ b/etc/gjs.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/gjs.local
4
1# gjs (gnome javascript bindings) profile 5# gjs (gnome javascript bindings) profile
2 6
3# when gjs apps are started via gnome-shell, firejail is not applied because systemd will start them 7# when gjs apps are started via gnome-shell, firejail is not applied because systemd will start them
diff --git a/etc/gnome-2048.profile b/etc/gnome-2048.profile
index f9982da61..95c0daccd 100644
--- a/etc/gnome-2048.profile
+++ b/etc/gnome-2048.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/gnome-2048.local
4
1# 5#
2#Profile for gnome-2048 6#Profile for gnome-2048
3# 7#
diff --git a/etc/gnome-books.profile b/etc/gnome-books.profile
index 10b06e173..692e32896 100644
--- a/etc/gnome-books.profile
+++ b/etc/gnome-books.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/gnome-books.local
4
1# gnome-books profile 5# gnome-books profile
2 6
3# when gjs apps are started via gnome-shell, firejail is not applied because systemd will start them 7# when gjs apps are started via gnome-shell, firejail is not applied because systemd will start them
diff --git a/etc/gnome-calculator.profile b/etc/gnome-calculator.profile
index 49e068171..714a97650 100644
--- a/etc/gnome-calculator.profile
+++ b/etc/gnome-calculator.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/gnome-calculator.local
4
1# 5#
2#Profile for gnome-calculator 6#Profile for gnome-calculator
3# 7#
diff --git a/etc/gnome-chess.profile b/etc/gnome-chess.profile
index 4db485ea7..3dcc98b72 100644
--- a/etc/gnome-chess.profile
+++ b/etc/gnome-chess.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/gnome-chess.local
4
1# Firejail profile for gnome-chess 5# Firejail profile for gnome-chess
2noblacklist ~/.local/share/gnome-chess 6noblacklist ~/.local/share/gnome-chess
3 7
diff --git a/etc/gnome-clocks.profile b/etc/gnome-clocks.profile
index 6cccf9d32..30598f348 100644
--- a/etc/gnome-clocks.profile
+++ b/etc/gnome-clocks.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/gnome-clocks.local
4
1# gnome-clocks profile 5# gnome-clocks profile
2include /etc/firejail/disable-common.inc 6include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 7include /etc/firejail/disable-programs.inc
diff --git a/etc/gnome-contacts.profile b/etc/gnome-contacts.profile
index 9dc25b26c..b61cd3c74 100644
--- a/etc/gnome-contacts.profile
+++ b/etc/gnome-contacts.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/gnome-contacts.local
4
1# 5#
2#Profile for gnome-contacts 6#Profile for gnome-contacts
3# 7#
diff --git a/etc/gnome-documents.profile b/etc/gnome-documents.profile
index c5def7aff..9d3b8172b 100644
--- a/etc/gnome-documents.profile
+++ b/etc/gnome-documents.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/gnome-documents.local
4
1# gnome-documents profile 5# gnome-documents profile
2 6
3# when gjs apps are started via gnome-shell, firejail is not applied because systemd will start them 7# when gjs apps are started via gnome-shell, firejail is not applied because systemd will start them
diff --git a/etc/gnome-maps.profile b/etc/gnome-maps.profile
index f1451506e..54c0eb99c 100644
--- a/etc/gnome-maps.profile
+++ b/etc/gnome-maps.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/gnome-maps.local
4
1# gnome-maps profile 5# gnome-maps profile
2 6
3# when gjs apps are started via gnome-shell, firejail is not applied because systemd will start them 7# when gjs apps are started via gnome-shell, firejail is not applied because systemd will start them
diff --git a/etc/gnome-mplayer.profile b/etc/gnome-mplayer.profile
index 488c7e0b8..cd268aed7 100644
--- a/etc/gnome-mplayer.profile
+++ b/etc/gnome-mplayer.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/gnome-mplayer.local
4
1# GNOME MPlayer profile 5# GNOME MPlayer profile
2include /etc/firejail/disable-common.inc 6include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 7include /etc/firejail/disable-programs.inc
@@ -12,6 +16,6 @@ protocol unix,inet,inet6
12seccomp 16seccomp
13shell none 17shell none
14 18
15private-bin gnome-mplayer,mplayer 19# private-bin gnome-mplayer,mplayer
16private-dev 20private-dev
17private-tmp 21private-tmp
diff --git a/etc/gnome-music.profile b/etc/gnome-music.profile
index 4a8adeb22..9136015e9 100644
--- a/etc/gnome-music.profile
+++ b/etc/gnome-music.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/gnome-music.local
4
1# gnome-music profile 5# gnome-music profile
2noblacklist ~/.local/share/gnome-music 6noblacklist ~/.local/share/gnome-music
3 7
diff --git a/etc/gnome-photos.profile b/etc/gnome-photos.profile
index 8f9d60cb5..d1636e02e 100644
--- a/etc/gnome-photos.profile
+++ b/etc/gnome-photos.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/gnome-photos.local
4
1# gnome-photos profile 5# gnome-photos profile
2 6
3# when gjs apps are started via gnome-shell, firejail is not applied because systemd will start them 7# when gjs apps are started via gnome-shell, firejail is not applied because systemd will start them
diff --git a/etc/gnome-weather.profile b/etc/gnome-weather.profile
index 9f93b8f15..925420a5a 100644
--- a/etc/gnome-weather.profile
+++ b/etc/gnome-weather.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/gnome-weather.local
4
1# gnome-weather profile 5# gnome-weather profile
2 6
3# when gjs apps are started via gnome-shell, firejail is not applied because systemd will start them 7# when gjs apps are started via gnome-shell, firejail is not applied because systemd will start them
diff --git a/etc/goobox.profile b/etc/goobox.profile
index 8990943fc..6aaec1354 100644
--- a/etc/goobox.profile
+++ b/etc/goobox.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/goobox.local
4
1# goobox profile 5# goobox profile
2include /etc/firejail/disable-common.inc 6include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 7include /etc/firejail/disable-programs.inc
diff --git a/etc/google-chrome-beta.profile b/etc/google-chrome-beta.profile
index 3d483967c..2f09edb7a 100644
--- a/etc/google-chrome-beta.profile
+++ b/etc/google-chrome-beta.profile
@@ -1,6 +1,11 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/google-chrome-beta.local
4
1# Google Chrome beta browser profile 5# Google Chrome beta browser profile
2noblacklist ~/.config/google-chrome-beta 6noblacklist ~/.config/google-chrome-beta
3noblacklist ~/.cache/google-chrome-beta 7noblacklist ~/.cache/google-chrome-beta
8noblacklist ~/.pki
4include /etc/firejail/disable-common.inc 9include /etc/firejail/disable-common.inc
5include /etc/firejail/disable-programs.inc 10include /etc/firejail/disable-programs.inc
6 11
diff --git a/etc/google-chrome-stable.profile b/etc/google-chrome-stable.profile
index 78c8ca6e5..b8d9d6917 100644
--- a/etc/google-chrome-stable.profile
+++ b/etc/google-chrome-stable.profile
@@ -1,2 +1,6 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/google-chrome-stable.local
4
1# Google Chrome browser profile 5# Google Chrome browser profile
2include /etc/firejail/google-chrome.profile 6include /etc/firejail/google-chrome.profile
diff --git a/etc/google-chrome-unstable.profile b/etc/google-chrome-unstable.profile
index 0189ce40b..e0dc37034 100644
--- a/etc/google-chrome-unstable.profile
+++ b/etc/google-chrome-unstable.profile
@@ -1,6 +1,11 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/google-chrome-unstable.local
4
1# Google Chrome unstable browser profile 5# Google Chrome unstable browser profile
2noblacklist ~/.config/google-chrome-unstable 6noblacklist ~/.config/google-chrome-unstable
3noblacklist ~/.cache/google-chrome-unstable 7noblacklist ~/.cache/google-chrome-unstable
8noblacklist ~/.pki
4include /etc/firejail/disable-common.inc 9include /etc/firejail/disable-common.inc
5include /etc/firejail/disable-programs.inc 10include /etc/firejail/disable-programs.inc
6 11
diff --git a/etc/google-chrome.profile b/etc/google-chrome.profile
index 3083c2afd..dfb30dc7e 100644
--- a/etc/google-chrome.profile
+++ b/etc/google-chrome.profile
@@ -1,6 +1,11 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/google-chrome.local
4
1# Google Chrome browser profile 5# Google Chrome browser profile
2noblacklist ~/.config/google-chrome 6noblacklist ~/.config/google-chrome
3noblacklist ~/.cache/google-chrome 7noblacklist ~/.cache/google-chrome
8noblacklist ~/.pki
4include /etc/firejail/disable-common.inc 9include /etc/firejail/disable-common.inc
5include /etc/firejail/disable-programs.inc 10include /etc/firejail/disable-programs.inc
6 11
diff --git a/etc/google-play-music-desktop-player.profile b/etc/google-play-music-desktop-player.profile
index b4cf8d9ac..dbe07cfee 100644
--- a/etc/google-play-music-desktop-player.profile
+++ b/etc/google-play-music-desktop-player.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/google-play-music-desktop-player.local
4
1# Google Play Music desktop player profile 5# Google Play Music desktop player profile
2noblacklist ~/.config/Google Play Music Desktop Player 6noblacklist ~/.config/Google Play Music Desktop Player
3 7
diff --git a/etc/gpa.profile b/etc/gpa.profile
index 7d7277190..7618fdd41 100644
--- a/etc/gpa.profile
+++ b/etc/gpa.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/gpa.local
4
1# gpa profile 5# gpa profile
2noblacklist ~/.gnupg 6noblacklist ~/.gnupg
3 7
@@ -18,6 +22,4 @@ shell none
18tracelog 22tracelog
19 23
20# private-bin gpa,gpg 24# private-bin gpa,gpg
21private-tmp
22private-dev 25private-dev
23# private-etc none
diff --git a/etc/gpg-agent.profile b/etc/gpg-agent.profile
index 59c7383d7..7beaca6f2 100644
--- a/etc/gpg-agent.profile
+++ b/etc/gpg-agent.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/gpg-agent.local
4
1# gpg-agent profile 5# gpg-agent profile
2noblacklist ~/.gnupg 6noblacklist ~/.gnupg
3 7
@@ -11,7 +15,7 @@ nogroups
11nonewprivs 15nonewprivs
12noroot 16noroot
13nosound 17nosound
14protocol unix 18protocol unix,inet,inet6
15seccomp 19seccomp
16netfilter 20netfilter
17no3d 21no3d
@@ -21,6 +25,4 @@ tracelog
21blacklist /tmp/.X11-unix 25blacklist /tmp/.X11-unix
22 26
23# private-bin gpg-agent,gpg 27# private-bin gpg-agent,gpg
24private-tmp
25private-dev 28private-dev
26# private-etc none
diff --git a/etc/gpg.profile b/etc/gpg.profile
index d711c6f3e..92e42cc4b 100644
--- a/etc/gpg.profile
+++ b/etc/gpg.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/gpg.local
4
1# gpg profile 5# gpg profile
2noblacklist ~/.gnupg 6noblacklist ~/.gnupg
3 7
@@ -11,10 +15,9 @@ nogroups
11nonewprivs 15nonewprivs
12noroot 16noroot
13nosound 17nosound
14protocol unix 18protocol unix,inet,inet6
15seccomp 19seccomp
16netfilter 20netfilter
17net none
18no3d 21no3d
19shell none 22shell none
20tracelog 23tracelog
@@ -22,6 +25,4 @@ tracelog
22blacklist /tmp/.X11-unix 25blacklist /tmp/.X11-unix
23 26
24# private-bin gpg,gpg-agent 27# private-bin gpg,gpg-agent
25private-tmp
26private-dev 28private-dev
27# private-etc none
diff --git a/etc/gpredict.profile b/etc/gpredict.profile
index 801304c18..9e8af2016 100644
--- a/etc/gpredict.profile
+++ b/etc/gpredict.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/gpredict.local
4
1# Firejail profile for gpredict. 5# Firejail profile for gpredict.
2noblacklist ~/.config/Gpredict 6noblacklist ~/.config/Gpredict
3include /etc/firejail/disable-common.inc 7include /etc/firejail/disable-common.inc
diff --git a/etc/gtar.profile b/etc/gtar.profile
index 2f675cd9d..2fcdbaa83 100644
--- a/etc/gtar.profile
+++ b/etc/gtar.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/gtar.local
4
1# gtar profile 5# gtar profile
2quiet 6quiet
3include /etc/firejail/tar.profile 7include /etc/firejail/tar.profile
diff --git a/etc/gthumb.profile b/etc/gthumb.profile
index 055d78935..d8c438181 100644
--- a/etc/gthumb.profile
+++ b/etc/gthumb.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/gthumb.local
4
1# gthumb profile 5# gthumb profile
2noblacklist ${HOME}/.config/gthumb 6noblacklist ${HOME}/.config/gthumb
3 7
diff --git a/etc/guayadeque.profile b/etc/guayadeque.profile
index 0c6ad00be..3c8da9e46 100644
--- a/etc/guayadeque.profile
+++ b/etc/guayadeque.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/guayadeque.local
4
1noblacklist ${HOME}/.guayadeque 5noblacklist ${HOME}/.guayadeque
2 6
3include /etc/firejail/disable-common.inc 7include /etc/firejail/disable-common.inc
diff --git a/etc/gwenview.profile b/etc/gwenview.profile
index c866c9e63..f636792f0 100644
--- a/etc/gwenview.profile
+++ b/etc/gwenview.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/gwenview.local
4
1# KDE gwenview profile 5# KDE gwenview profile
2noblacklist ~/.kde/share/apps/gwenview 6noblacklist ~/.kde/share/apps/gwenview
3noblacklist ~/.kde/share/config/gwenviewrc 7noblacklist ~/.kde/share/config/gwenviewrc
diff --git a/etc/gzip.profile b/etc/gzip.profile
index feb27c150..2eca4d8b6 100644
--- a/etc/gzip.profile
+++ b/etc/gzip.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/gzip.local
4
1# gzip profile 5# gzip profile
2quiet 6quiet
3ignore noroot 7ignore noroot
diff --git a/etc/hedgewars.profile b/etc/hedgewars.profile
index 7910b7eb0..4e469bd42 100644
--- a/etc/hedgewars.profile
+++ b/etc/hedgewars.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/hedgewars.local
4
1# whitelist profile for Hedgewars (game) 5# whitelist profile for Hedgewars (game)
2noblacklist ${HOME}/.hedgewars 6noblacklist ${HOME}/.hedgewars
3 7
diff --git a/etc/hexchat.profile b/etc/hexchat.profile
index 5cefe45b5..53f447f7e 100644
--- a/etc/hexchat.profile
+++ b/etc/hexchat.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/hexchat.local
4
1# HexChat instant messaging profile 5# HexChat instant messaging profile
2# Currently in testing (may not work for all users) 6# Currently in testing (may not work for all users)
3noblacklist ${HOME}/.config/hexchat 7noblacklist ${HOME}/.config/hexchat
diff --git a/etc/highlight.profile b/etc/highlight.profile
index 4bab18349..446a3fbb7 100644
--- a/etc/highlight.profile
+++ b/etc/highlight.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/highlight.local
4
1# highlight profile 5# highlight profile
2include /etc/firejail/disable-common.inc 6include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 7include /etc/firejail/disable-programs.inc
diff --git a/etc/icecat.profile b/etc/icecat.profile
index 038afc876..144f5c4eb 100644
--- a/etc/icecat.profile
+++ b/etc/icecat.profile
@@ -1,6 +1,11 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/icecat.local
4
1# Firejail profile for GNU Icecat 5# Firejail profile for GNU Icecat
2noblacklist ~/.mozilla 6noblacklist ~/.mozilla
3noblacklist ~/.cache/mozilla 7noblacklist ~/.cache/mozilla
8noblacklist ~/.pki
4include /etc/firejail/disable-common.inc 9include /etc/firejail/disable-common.inc
5include /etc/firejail/disable-programs.inc 10include /etc/firejail/disable-programs.inc
6include /etc/firejail/disable-devel.inc 11include /etc/firejail/disable-devel.inc
diff --git a/etc/icedove.profile b/etc/icedove.profile
index 310684bdb..b5265e992 100644
--- a/etc/icedove.profile
+++ b/etc/icedove.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/icedove.local
4
1# Firejail profile for Mozilla Thunderbird (Icedove in Debian Stable) 5# Firejail profile for Mozilla Thunderbird (Icedove in Debian Stable)
2# Users have icedove set to open a browser by clicking a link in an email 6# Users have icedove set to open a browser by clicking a link in an email
3# We are not allowed to blacklist browser-specific directories 7# We are not allowed to blacklist browser-specific directories
diff --git a/etc/iceweasel.profile b/etc/iceweasel.profile
index e9b32846a..d5c29a5ce 100644
--- a/etc/iceweasel.profile
+++ b/etc/iceweasel.profile
@@ -1,2 +1,6 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/iceweasel.local
4
1# Firejail profile for Mozilla Firefox (Iceweasel in Debian) 5# Firejail profile for Mozilla Firefox (Iceweasel in Debian)
2include /etc/firejail/firefox.profile 6include /etc/firejail/firefox.profile
diff --git a/etc/img2txt.profile b/etc/img2txt.profile
index d55a31cd0..15692b2b0 100644
--- a/etc/img2txt.profile
+++ b/etc/img2txt.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/img2txt.local
4
1# img2txt profile 5# img2txt profile
2include /etc/firejail/disable-common.inc 6include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 7include /etc/firejail/disable-programs.inc
diff --git a/etc/inkscape.profile b/etc/inkscape.profile
index a0e86b6c9..000a35fd9 100644
--- a/etc/inkscape.profile
+++ b/etc/inkscape.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/inkscape.local
4
1# inkscape 5# inkscape
2noblacklist ${HOME}/.inkscape 6noblacklist ${HOME}/.inkscape
3include /etc/firejail/disable-common.inc 7include /etc/firejail/disable-common.inc
diff --git a/etc/inox.profile b/etc/inox.profile
index 6f6d140e2..8e95208ab 100644
--- a/etc/inox.profile
+++ b/etc/inox.profile
@@ -1,6 +1,11 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/inox.local
4
1# Inox browser profile 5# Inox browser profile
2noblacklist ~/.config/inox 6noblacklist ~/.config/inox
3noblacklist ~/.cache/inox 7noblacklist ~/.cache/inox
8noblacklist ~/.pki
4include /etc/firejail/disable-common.inc 9include /etc/firejail/disable-common.inc
5include /etc/firejail/disable-programs.inc 10include /etc/firejail/disable-programs.inc
6 11
diff --git a/etc/iridium-browser.profile b/etc/iridium-browser.profile
new file mode 100644
index 000000000..7a2f889dc
--- /dev/null
+++ b/etc/iridium-browser.profile
@@ -0,0 +1,6 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/iridium-browser.local
4
5include /etc/firejail/iridium.profile
6
diff --git a/etc/iridium.profile b/etc/iridium.profile
new file mode 100644
index 000000000..69ea483aa
--- /dev/null
+++ b/etc/iridium.profile
@@ -0,0 +1,33 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/iridium.local
4
5# Iridium browser profile
6noblacklist ~/.config/iridium
7noblacklist ~/.cache/iridium
8include /etc/firejail/disable-common.inc
9include /etc/firejail/disable-programs.inc
10
11# chromium/iridium is distributed with a perl script on Arch
12# include /etc/firejail/disable-devel.inc
13#
14
15netfilter
16
17whitelist ${DOWNLOADS}
18mkdir ~/.config/iridium
19whitelist ~/.config/iridium
20mkdir ~/.cache/iridium
21whitelist ~/.cache/iridium
22mkdir ~/.pki
23whitelist ~/.pki
24
25# lastpass, keepass
26# for keepass we additionally need to whitelist our .kdbx password database
27whitelist ~/.keepass
28whitelist ~/.config/keepass
29whitelist ~/.config/KeePass
30whitelist ~/.lastpass
31whitelist ~/.config/lastpass
32
33include /etc/firejail/whitelist-common.inc
diff --git a/etc/jd-gui.profile b/etc/jd-gui.profile
index 1d6eb41f8..2ba1a4380 100644
--- a/etc/jd-gui.profile
+++ b/etc/jd-gui.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/jd-gui.local
4
1# 5#
2#Profile for jd-gui 6#Profile for jd-gui
3# 7#
diff --git a/etc/jitsi.profile b/etc/jitsi.profile
index 046499abe..5d502fffe 100644
--- a/etc/jitsi.profile
+++ b/etc/jitsi.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/jitsi.local
4
1# Firejail profile for jitsi 5# Firejail profile for jitsi
2noblacklist ~/.jitsi 6noblacklist ~/.jitsi
3include /etc/firejail/disable-common.inc 7include /etc/firejail/disable-common.inc
diff --git a/etc/k3b.profile b/etc/k3b.profile
index 8a5fff0c6..68b825c5e 100644
--- a/etc/k3b.profile
+++ b/etc/k3b.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/k3b.local
4
1# k3b profile 5# k3b profile
2include /etc/firejail/disable-common.inc 6include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 7include /etc/firejail/disable-programs.inc
diff --git a/etc/kate.profile b/etc/kate.profile
index 4b07ea6cb..466786e61 100644
--- a/etc/kate.profile
+++ b/etc/kate.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/kate.local
4
1# kate profile 5# kate profile
2noblacklist ~/.local/share/kate 6noblacklist ~/.local/share/kate
3noblacklist ~/.config/katerc 7noblacklist ~/.config/katerc
diff --git a/etc/keepass.profile b/etc/keepass.profile
index eb7d92a7c..d269c3e8a 100644
--- a/etc/keepass.profile
+++ b/etc/keepass.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/keepass.local
4
1# keepass password manager profile 5# keepass password manager profile
2noblacklist ${HOME}/.keepass 6noblacklist ${HOME}/.keepass
3noblacklist ${HOME}/.config/keepass 7noblacklist ${HOME}/.config/keepass
diff --git a/etc/keepass2.profile b/etc/keepass2.profile
index 1ee2644d5..dbf7a4180 100644
--- a/etc/keepass2.profile
+++ b/etc/keepass2.profile
@@ -1,2 +1,6 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/keepass2.local
4
1# keepass password manager profile 5# keepass password manager profile
2include /etc/firejail/keepass.profile 6include /etc/firejail/keepass.profile
diff --git a/etc/keepassx.profile b/etc/keepassx.profile
index bb74bb629..379b8a668 100644
--- a/etc/keepassx.profile
+++ b/etc/keepassx.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/keepassx.local
4
1# keepassx password manager profile 5# keepassx password manager profile
2noblacklist ${HOME}/.config/keepassx 6noblacklist ${HOME}/.config/keepassx
3noblacklist ${HOME}/.keepassx 7noblacklist ${HOME}/.keepassx
@@ -10,14 +14,17 @@ include /etc/firejail/disable-devel.inc
10include /etc/firejail/disable-passwdmgr.inc 14include /etc/firejail/disable-passwdmgr.inc
11 15
12caps.drop all 16caps.drop all
17net none
13nogroups 18nogroups
14nonewprivs 19nonewprivs
15noroot 20noroot
16nosound 21nosound
17protocol unix 22protocol unix
18seccomp 23seccomp
19netfilter
20shell none 24shell none
25tracelog
21 26
27private-bin keepassx
28private-etc fonts
29private-dev
22private-tmp 30private-tmp
23private-dev
diff --git a/etc/keepassx2.profile b/etc/keepassx2.profile
index bb74bb629..a21caf3f1 100644
--- a/etc/keepassx2.profile
+++ b/etc/keepassx2.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/keepassx2.local
4
1# keepassx password manager profile 5# keepassx password manager profile
2noblacklist ${HOME}/.config/keepassx 6noblacklist ${HOME}/.config/keepassx
3noblacklist ${HOME}/.keepassx 7noblacklist ${HOME}/.keepassx
@@ -10,14 +14,16 @@ include /etc/firejail/disable-devel.inc
10include /etc/firejail/disable-passwdmgr.inc 14include /etc/firejail/disable-passwdmgr.inc
11 15
12caps.drop all 16caps.drop all
17net none
13nogroups 18nogroups
14nonewprivs 19nonewprivs
15noroot 20noroot
16nosound 21nosound
17protocol unix 22protocol unix
18seccomp 23seccomp
19netfilter
20shell none 24shell none
21 25
26private-bin keepassx2
27private-etc fonts
28private-dev
22private-tmp 29private-tmp
23private-dev
diff --git a/etc/kino.profile b/etc/kino.profile
new file mode 100644
index 000000000..70269e75a
--- /dev/null
+++ b/etc/kino.profile
@@ -0,0 +1,30 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/kino.local
4
5################################
6# Generic GUI application profile
7################################
8noblacklist ~/.kinorc
9noblacklist ~/.kino-history
10include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-programs.inc
12include /etc/firejail/disable-passwdmgr.inc
13
14caps.drop all
15netfilter
16nonewprivs
17noroot
18protocol unix,inet,inet6
19seccomp
20
21#
22# depending on you usage, you can enable some of the commands below:
23#
24# nogroups
25# shell none
26# private-bin program
27# private-etc none
28# private-dev
29# private-tmp
30
diff --git a/etc/kmail.profile b/etc/kmail.profile
index 410ff36c6..b930f6e48 100644
--- a/etc/kmail.profile
+++ b/etc/kmail.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/kmail.local
4
1# kmail profile 5# kmail profile
2noblacklist ${HOME}/.gnupg 6noblacklist ${HOME}/.gnupg
3 7
diff --git a/etc/konversation.profile b/etc/konversation.profile
index c00b91c18..0b920bd6a 100644
--- a/etc/konversation.profile
+++ b/etc/konversation.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/konversation.local
4
1# Firejail konversation profile 5# Firejail konversation profile
2include /etc/firejail/disable-common.inc 6include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 7include /etc/firejail/disable-programs.inc
diff --git a/etc/less.profile b/etc/less.profile
index c01dfc466..23fbc4ba2 100644
--- a/etc/less.profile
+++ b/etc/less.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/less.local
4
1# less profile 5# less profile
2quiet 6quiet
3ignore noroot 7ignore noroot
diff --git a/etc/libreoffice.profile b/etc/libreoffice.profile
index d6aceb7a8..685073e7c 100644
--- a/etc/libreoffice.profile
+++ b/etc/libreoffice.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/libreoffice.local
4
1# Firejail profile for LibreOffice 5# Firejail profile for LibreOffice
2noblacklist ~/.config/libreoffice 6noblacklist ~/.config/libreoffice
3noblacklist /usr/local/sbin 7noblacklist /usr/local/sbin
diff --git a/etc/localc.profile b/etc/localc.profile
index fecd08822..14c34c722 100644
--- a/etc/localc.profile
+++ b/etc/localc.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/localc.local
4
1################################ 5################################
2# LibreOffice profile 6# LibreOffice profile
3################################ 7################################
diff --git a/etc/lodraw.profile b/etc/lodraw.profile
index fecd08822..5be66c5de 100644
--- a/etc/lodraw.profile
+++ b/etc/lodraw.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/lodraw.local
4
1################################ 5################################
2# LibreOffice profile 6# LibreOffice profile
3################################ 7################################
diff --git a/etc/loffice.profile b/etc/loffice.profile
index fecd08822..5f931502c 100644
--- a/etc/loffice.profile
+++ b/etc/loffice.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/loffice.local
4
1################################ 5################################
2# LibreOffice profile 6# LibreOffice profile
3################################ 7################################
diff --git a/etc/lofromtemplate.profile b/etc/lofromtemplate.profile
index fecd08822..9899ddf58 100644
--- a/etc/lofromtemplate.profile
+++ b/etc/lofromtemplate.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/lofromtemplate.local
4
1################################ 5################################
2# LibreOffice profile 6# LibreOffice profile
3################################ 7################################
diff --git a/etc/login.users b/etc/login.users
index bc6ac4b09..81f12c6b1 100644
--- a/etc/login.users
+++ b/etc/login.users
@@ -9,6 +9,12 @@
9# 9#
10# netblue:--net=none --protocol=unix 10# netblue:--net=none --protocol=unix
11# 11#
12# Wildcard patterns are accepted in the user name field:
13#
14# user*: --private
15#
16# The example will do --private for user1, user2, and so on.
17#
12# The extra arguments are inserted into program command line if firejail 18# The extra arguments are inserted into program command line if firejail
13# was started as a login shell. 19# was started as a login shell.
14 20
diff --git a/etc/loimpress.profile b/etc/loimpress.profile
index fecd08822..4de330d67 100644
--- a/etc/loimpress.profile
+++ b/etc/loimpress.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/loimpress.local
4
1################################ 5################################
2# LibreOffice profile 6# LibreOffice profile
3################################ 7################################
diff --git a/etc/lollypop.profile b/etc/lollypop.profile
index 41a662bca..06ed415d6 100644
--- a/etc/lollypop.profile
+++ b/etc/lollypop.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/lollypop.local
4
1# 5#
2#Profile for lollypop 6#Profile for lollypop
3# 7#
diff --git a/etc/lomath.profile b/etc/lomath.profile
index fecd08822..cbe13f474 100644
--- a/etc/lomath.profile
+++ b/etc/lomath.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/lomath.local
4
1################################ 5################################
2# LibreOffice profile 6# LibreOffice profile
3################################ 7################################
diff --git a/etc/loweb.profile b/etc/loweb.profile
index fecd08822..f5e13db02 100644
--- a/etc/loweb.profile
+++ b/etc/loweb.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/loweb.local
4
1################################ 5################################
2# LibreOffice profile 6# LibreOffice profile
3################################ 7################################
diff --git a/etc/lowriter.profile b/etc/lowriter.profile
index fecd08822..b6c6ed407 100644
--- a/etc/lowriter.profile
+++ b/etc/lowriter.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/lowriter.local
4
1################################ 5################################
2# LibreOffice profile 6# LibreOffice profile
3################################ 7################################
diff --git a/etc/luminance-hdr.profile b/etc/luminance-hdr.profile
index 76e864e0c..1b06b27c3 100644
--- a/etc/luminance-hdr.profile
+++ b/etc/luminance-hdr.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/luminance-hdr.local
4
1# luminance-hdr 5# luminance-hdr
2noblacklist ${HOME}/.config/Luminance 6noblacklist ${HOME}/.config/Luminance
3include /etc/firejail/disable-common.inc 7include /etc/firejail/disable-common.inc
diff --git a/etc/lxterminal.profile b/etc/lxterminal.profile
index 12765c299..5d76adf4c 100644
--- a/etc/lxterminal.profile
+++ b/etc/lxterminal.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/lxterminal.local
4
1# lxterminal (LXDE) profile 5# lxterminal (LXDE) profile
2include /etc/firejail/disable-common.inc 6include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 7include /etc/firejail/disable-programs.inc
diff --git a/etc/lynx.profile b/etc/lynx.profile
index 3e8d72103..de428c214 100644
--- a/etc/lynx.profile
+++ b/etc/lynx.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/lynx.local
4
1# lynx profile 5# lynx profile
2include /etc/firejail/disable-common.inc 6include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 7include /etc/firejail/disable-programs.inc
diff --git a/etc/mathematica.profile b/etc/mathematica.profile
index 9410054ae..c880b1daa 100644
--- a/etc/mathematica.profile
+++ b/etc/mathematica.profile
@@ -1,2 +1,6 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/mathematica.local
4
1# Mathematica profile 5# Mathematica profile
2include /etc/firejail/Mathematica.profile 6include /etc/firejail/Mathematica.profile
diff --git a/etc/mcabber.profile b/etc/mcabber.profile
index 48b46dba0..87e672501 100644
--- a/etc/mcabber.profile
+++ b/etc/mcabber.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/mcabber.local
4
1# mcabber profile 5# mcabber profile
2noblacklist ${HOME}/.mcabber 6noblacklist ${HOME}/.mcabber
3noblacklist ${HOME}/.mcabberrc 7noblacklist ${HOME}/.mcabberrc
diff --git a/etc/mediainfo.profile b/etc/mediainfo.profile
index 65d12c49e..9b4adc26f 100644
--- a/etc/mediainfo.profile
+++ b/etc/mediainfo.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/mediainfo.local
4
1# mediainfo profile 5# mediainfo profile
2include /etc/firejail/disable-common.inc 6include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 7include /etc/firejail/disable-programs.inc
diff --git a/etc/midori.profile b/etc/midori.profile
index 046c45d94..44e5e7417 100644
--- a/etc/midori.profile
+++ b/etc/midori.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/midori.local
4
1# Midori browser profile 5# Midori browser profile
2noblacklist ${HOME}/.config/midori 6noblacklist ${HOME}/.config/midori
3include /etc/firejail/disable-common.inc 7include /etc/firejail/disable-common.inc
diff --git a/etc/mpv.profile b/etc/mpv.profile
index 80f8de54a..d7a8d37e8 100644
--- a/etc/mpv.profile
+++ b/etc/mpv.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/mpv.local
4
1# mpv media player profile 5# mpv media player profile
2noblacklist ${HOME}/.config/mpv 6noblacklist ${HOME}/.config/mpv
3 7
diff --git a/etc/multimc5.profile b/etc/multimc5.profile
index cc310f294..6b8946be3 100644
--- a/etc/multimc5.profile
+++ b/etc/multimc5.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/multimc5.local
4
1# 5#
2#Profile for multimc5 6#Profile for multimc5
3# 7#
diff --git a/etc/mumble.profile b/etc/mumble.profile
index ddd70822d..d5405a6ae 100644
--- a/etc/mumble.profile
+++ b/etc/mumble.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/mumble.local
4
1# mumble profile 5# mumble profile
2noblacklist ${HOME}/.config/Mumble 6noblacklist ${HOME}/.config/Mumble
3noblacklist ${HOME}/.local/share/data/Mumble 7noblacklist ${HOME}/.local/share/data/Mumble
diff --git a/etc/mupdf.profile b/etc/mupdf.profile
index 7f9261d8b..712552965 100644
--- a/etc/mupdf.profile
+++ b/etc/mupdf.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/mupdf.local
4
1# mupdf reader profile 5# mupdf reader profile
2include /etc/firejail/disable-common.inc 6include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 7include /etc/firejail/disable-programs.inc
diff --git a/etc/mupen64plus.profile b/etc/mupen64plus.profile
index acb13e6b9..80e75e836 100644
--- a/etc/mupen64plus.profile
+++ b/etc/mupen64plus.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/mupen64plus.local
4
1# mupen64plus profile 5# mupen64plus profile
2# manually whitelist ROM files 6# manually whitelist ROM files
3noblacklist ${HOME}/.config/mupen64plus 7noblacklist ${HOME}/.config/mupen64plus
diff --git a/etc/mutt.profile b/etc/mutt.profile
index 5a714de4a..2f0809f02 100644
--- a/etc/mutt.profile
+++ b/etc/mutt.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/mutt.local
4
1# mutt email client profile 5# mutt email client profile
2noblacklist ~/.muttrc 6noblacklist ~/.muttrc
3noblacklist ~/.mutt 7noblacklist ~/.mutt
diff --git a/etc/nautilus.profile b/etc/nautilus.profile
index 264ee0b9d..85f9ab7d7 100644
--- a/etc/nautilus.profile
+++ b/etc/nautilus.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/nautilus.local
4
1# nautilus profile 5# nautilus profile
2 6
3# Nautilus is started by systemd on most systems. Therefore it is not firejailed by default. Since there is already a nautilus process running on gnome desktops firejail will have no effect. 7# Nautilus is started by systemd on most systems. Therefore it is not firejailed by default. Since there is already a nautilus process running on gnome desktops firejail will have no effect.
diff --git a/etc/netsurf.profile b/etc/netsurf.profile
index 644a1605b..4c10a3e98 100644
--- a/etc/netsurf.profile
+++ b/etc/netsurf.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/netsurf.local
4
1# Firejail profile for Mozilla Firefox (Iceweasel in Debian) 5# Firejail profile for Mozilla Firefox (Iceweasel in Debian)
2noblacklist ~/.config/netsurf 6noblacklist ~/.config/netsurf
3noblacklist ~/.cache/netsurf 7noblacklist ~/.cache/netsurf
diff --git a/etc/odt2txt.profile b/etc/odt2txt.profile
index c4e28f70e..3880895f3 100644
--- a/etc/odt2txt.profile
+++ b/etc/odt2txt.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/odt2txt.local
4
1# odt2txt profile 5# odt2txt profile
2include /etc/firejail/disable-common.inc 6include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 7include /etc/firejail/disable-programs.inc
diff --git a/etc/okular.profile b/etc/okular.profile
index 22e223cea..2875d2ef5 100644
--- a/etc/okular.profile
+++ b/etc/okular.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/okular.local
4
1# KDE okular profile 5# KDE okular profile
2noblacklist ~/.kde/share/apps/okular 6noblacklist ~/.kde/share/apps/okular
3noblacklist ~/.kde/share/config/okularrc 7noblacklist ~/.kde/share/config/okularrc
diff --git a/etc/openbox.profile b/etc/openbox.profile
index f812768a1..7e074f5b5 100644
--- a/etc/openbox.profile
+++ b/etc/openbox.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/openbox.local
4
1####################################### 5#######################################
2# OpenBox window manager profile 6# OpenBox window manager profile
3# - all applications started in OpenBox will run in this profile 7# - all applications started in OpenBox will run in this profile
diff --git a/etc/openshot.profile b/etc/openshot.profile
index f12bd7d11..25e9a4066 100644
--- a/etc/openshot.profile
+++ b/etc/openshot.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/openshot.local
4
1# OpenShot profile 5# OpenShot profile
2noblacklist ${HOME}/.openshot 6noblacklist ${HOME}/.openshot
3noblacklist ${HOME}/.openshot_qt 7noblacklist ${HOME}/.openshot_qt
diff --git a/etc/opera-beta.profile b/etc/opera-beta.profile
index 4cdb0a9eb..dba7cf68c 100644
--- a/etc/opera-beta.profile
+++ b/etc/opera-beta.profile
@@ -1,6 +1,11 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/opera-beta.local
4
1# Opera-beta browser profile 5# Opera-beta browser profile
2noblacklist ~/.config/opera-beta 6noblacklist ~/.config/opera-beta
3noblacklist ~/.cache/opera-beta 7noblacklist ~/.cache/opera-beta
8noblacklist ~/.pki
4include /etc/firejail/disable-common.inc 9include /etc/firejail/disable-common.inc
5include /etc/firejail/disable-programs.inc 10include /etc/firejail/disable-programs.inc
6include /etc/firejail/disable-devel.inc 11include /etc/firejail/disable-devel.inc
diff --git a/etc/opera.profile b/etc/opera.profile
index a337ccc5b..57395ea72 100644
--- a/etc/opera.profile
+++ b/etc/opera.profile
@@ -1,7 +1,12 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/opera.local
4
1# Opera browser profile 5# Opera browser profile
2noblacklist ~/.config/opera 6noblacklist ~/.config/opera
3noblacklist ~/.cache/opera 7noblacklist ~/.cache/opera
4noblacklist ~/.opera 8noblacklist ~/.opera
9noblacklist ~/.pki
5include /etc/firejail/disable-common.inc 10include /etc/firejail/disable-common.inc
6include /etc/firejail/disable-programs.inc 11include /etc/firejail/disable-programs.inc
7include /etc/firejail/disable-devel.inc 12include /etc/firejail/disable-devel.inc
diff --git a/etc/palemoon.profile b/etc/palemoon.profile
index 1476369a1..41eef8d91 100644
--- a/etc/palemoon.profile
+++ b/etc/palemoon.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/palemoon.local
4
1# Firejail profile for Pale Moon 5# Firejail profile for Pale Moon
2noblacklist ~/.moonchild productions/pale moon 6noblacklist ~/.moonchild productions/pale moon
3noblacklist ~/.cache/moonchild productions/pale moon 7noblacklist ~/.cache/moonchild productions/pale moon
@@ -23,6 +27,7 @@ shell none
23tracelog 27tracelog
24 28
25private-bin palemoon 29private-bin palemoon
30private-opt palemoon
26private-tmp 31private-tmp
27 32
28# These are uncommented in the Firefox profile. If you run into trouble you may 33# These are uncommented in the Firefox profile. If you run into trouble you may
diff --git a/etc/parole.profile b/etc/parole.profile
index 1440a9ef7..58a9f2c6c 100644
--- a/etc/parole.profile
+++ b/etc/parole.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/parole.local
4
1# Profile for Parole, the default XFCE4 media player 5# Profile for Parole, the default XFCE4 media player
2include /etc/firejail/disable-common.inc 6include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 7include /etc/firejail/disable-programs.inc
diff --git a/etc/pdfsam.profile b/etc/pdfsam.profile
index 6e50f37cf..37adabb39 100644
--- a/etc/pdfsam.profile
+++ b/etc/pdfsam.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/pdfsam.local
4
1# 5#
2#Profile for pdfsam 6#Profile for pdfsam
3# 7#
diff --git a/etc/pdftotext.profile b/etc/pdftotext.profile
index fe9e9e3cd..ce19f1760 100644
--- a/etc/pdftotext.profile
+++ b/etc/pdftotext.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/pdftotext.local
4
1# pdftotext profile 5# pdftotext profile
2include /etc/firejail/disable-common.inc 6include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 7include /etc/firejail/disable-programs.inc
diff --git a/etc/pidgin.profile b/etc/pidgin.profile
index 850706145..5c5cb0a5b 100644
--- a/etc/pidgin.profile
+++ b/etc/pidgin.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/pidgin.local
4
1# Pidgin profile 5# Pidgin profile
2noblacklist ${HOME}/.purple 6noblacklist ${HOME}/.purple
3 7
diff --git a/etc/pithos.profile b/etc/pithos.profile
index 8270b8bee..500e35989 100644
--- a/etc/pithos.profile
+++ b/etc/pithos.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/pithos.local
4
1# 5#
2#Profile for pithos 6#Profile for pithos
3# 7#
diff --git a/etc/pix.profile b/etc/pix.profile
index dc8192b01..c36a5f96e 100644
--- a/etc/pix.profile
+++ b/etc/pix.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/pix.local
4
1# Firejail profile for pix 5# Firejail profile for pix
2noblacklist ${HOME}/.config/pix 6noblacklist ${HOME}/.config/pix
3noblacklist ${HOME}/.local/share/pix 7noblacklist ${HOME}/.local/share/pix
diff --git a/etc/pluma.profile b/etc/pluma.profile
index 895cc2369..719a26928 100644
--- a/etc/pluma.profile
+++ b/etc/pluma.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/pluma.local
4
1# Firejail profile for Xed 5# Firejail profile for Xed
2noblacklist ${HOME}/.config/pluma 6noblacklist ${HOME}/.config/pluma
3 7
diff --git a/etc/polari.profile b/etc/polari.profile
index ac9530c40..834a8b3d6 100644
--- a/etc/polari.profile
+++ b/etc/polari.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/polari.local
4
1# Polari IRC profile 5# Polari IRC profile
2include /etc/firejail/disable-common.inc 6include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 7include /etc/firejail/disable-programs.inc
diff --git a/etc/psi-plus.profile b/etc/psi-plus.profile
index e4e69b9f6..45cb22ee4 100644
--- a/etc/psi-plus.profile
+++ b/etc/psi-plus.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/psi-plus.local
4
1# Firejail profile for Psi+ 5# Firejail profile for Psi+
2noblacklist ${HOME}/.config/psi+ 6noblacklist ${HOME}/.config/psi+
3noblacklist ${HOME}/.local/share/psi+ 7noblacklist ${HOME}/.local/share/psi+
diff --git a/etc/qbittorrent.profile b/etc/qbittorrent.profile
index 89e0e4c78..4a454d2f6 100644
--- a/etc/qbittorrent.profile
+++ b/etc/qbittorrent.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/qbittorrent.local
4
1# qbittorrent bittorrent profile 5# qbittorrent bittorrent profile
2include /etc/firejail/disable-common.inc 6include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 7include /etc/firejail/disable-programs.inc
@@ -6,6 +10,7 @@ include /etc/firejail/disable-passwdmgr.inc
6 10
7caps.drop all 11caps.drop all
8netfilter 12netfilter
13nogroups
9nonewprivs 14nonewprivs
10noroot 15noroot
11nosound 16nosound
diff --git a/etc/qemu-launcher.profile b/etc/qemu-launcher.profile
index f9c8e6345..328f1a30d 100644
--- a/etc/qemu-launcher.profile
+++ b/etc/qemu-launcher.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/qemu-launcher.local
4
1# qemu-launcher profile 5# qemu-launcher profile
2noblacklist ~/.qemu-launcher 6noblacklist ~/.qemu-launcher
3 7
diff --git a/etc/qemu-system-x86_64.profile b/etc/qemu-system-x86_64.profile
index 65e1e44ea..16e822901 100644
--- a/etc/qemu-system-x86_64.profile
+++ b/etc/qemu-system-x86_64.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/qemu-system-x86_64.local
4
1# qemu profile 5# qemu profile
2include /etc/firejail/disable-common.inc 6include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 7include /etc/firejail/disable-programs.inc
diff --git a/etc/qpdfview.profile b/etc/qpdfview.profile
index 06c0db206..97f06f848 100644
--- a/etc/qpdfview.profile
+++ b/etc/qpdfview.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/qpdfview.local
4
1# qpdfview profile 5# qpdfview profile
2noblacklist ${HOME}/.config/qpdfview 6noblacklist ${HOME}/.config/qpdfview
3noblacklist ${HOME}/.local/share/qpdfview 7noblacklist ${HOME}/.local/share/qpdfview
diff --git a/etc/qtox.profile b/etc/qtox.profile
index 81d8aa10e..40a959d05 100644
--- a/etc/qtox.profile
+++ b/etc/qtox.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/qtox.local
4
1# qTox instant messaging profile 5# qTox instant messaging profile
2noblacklist ${HOME}/.config/tox 6noblacklist ${HOME}/.config/tox
3include /etc/firejail/disable-common.inc 7include /etc/firejail/disable-common.inc
diff --git a/etc/quassel.profile b/etc/quassel.profile
index f92dfeb9f..6fd438073 100644
--- a/etc/quassel.profile
+++ b/etc/quassel.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/quassel.local
4
1# Quassel IRC profile 5# Quassel IRC profile
2include /etc/firejail/disable-common.inc 6include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 7include /etc/firejail/disable-programs.inc
diff --git a/etc/quiterss.profile b/etc/quiterss.profile
index 47ab77675..f4e4f96d3 100644
--- a/etc/quiterss.profile
+++ b/etc/quiterss.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/quiterss.local
4
1noblacklist ${HOME}/.cache/QuiteRss 5noblacklist ${HOME}/.cache/QuiteRss
2noblacklist ${HOME}/.config/QuiteRss 6noblacklist ${HOME}/.config/QuiteRss
3noblacklist ${HOME}/.config/QuiteRssrc 7noblacklist ${HOME}/.config/QuiteRssrc
diff --git a/etc/qupzilla.profile b/etc/qupzilla.profile
index 387ddeffa..3f5cb60c0 100644
--- a/etc/qupzilla.profile
+++ b/etc/qupzilla.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/qupzilla.local
4
1# Firejail profile for Qupzilla web browser 5# Firejail profile for Qupzilla web browser
2noblacklist ${HOME}/.config/qupzilla 6noblacklist ${HOME}/.config/qupzilla
3noblacklist ${HOME}/.cache/qupzilla 7noblacklist ${HOME}/.cache/qupzilla
diff --git a/etc/qutebrowser.profile b/etc/qutebrowser.profile
index dcacd4f29..f43307ef9 100644
--- a/etc/qutebrowser.profile
+++ b/etc/qutebrowser.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/qutebrowser.local
4
1# Firejail profile for Qutebrowser (Qt5-Webkit+Python) browser 5# Firejail profile for Qutebrowser (Qt5-Webkit+Python) browser
2noblacklist ~/.config/qutebrowser 6noblacklist ~/.config/qutebrowser
3noblacklist ~/.cache/qutebrowser 7noblacklist ~/.cache/qutebrowser
diff --git a/etc/ranger.profile b/etc/ranger.profile
index 3538f3eb2..0cabca11e 100644
--- a/etc/ranger.profile
+++ b/etc/ranger.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/ranger.local
4
1# ranger file manager profile 5# ranger file manager profile
2noblacklist /usr/bin/perl 6noblacklist /usr/bin/perl
3#noblacklist /usr/bin/cpan* 7#noblacklist /usr/bin/cpan*
diff --git a/etc/rhythmbox.profile b/etc/rhythmbox.profile
index e5e192486..0f7a3fa5b 100644
--- a/etc/rhythmbox.profile
+++ b/etc/rhythmbox.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/rhythmbox.local
4
1# Rhythmbox media player profile 5# Rhythmbox media player profile
2include /etc/firejail/disable-common.inc 6include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 7include /etc/firejail/disable-programs.inc
diff --git a/etc/rtorrent.profile b/etc/rtorrent.profile
index 55bfcd77f..2f8a527cc 100644
--- a/etc/rtorrent.profile
+++ b/etc/rtorrent.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/rtorrent.local
4
1# rtorrent bittorrent profile 5# rtorrent bittorrent profile
2include /etc/firejail/disable-common.inc 6include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 7include /etc/firejail/disable-programs.inc
diff --git a/etc/seamonkey-bin.profile b/etc/seamonkey-bin.profile
index fff8c1258..ff8936014 100644
--- a/etc/seamonkey-bin.profile
+++ b/etc/seamonkey-bin.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/seamonkey-bin.local
4
1# Firejail profile for Seamonkey based off Mozilla Firefox 5# Firejail profile for Seamonkey based off Mozilla Firefox
2include /etc/firejail/seamonkey.profile 6include /etc/firejail/seamonkey.profile
3 7
diff --git a/etc/seamonkey.profile b/etc/seamonkey.profile
index 5d817acce..bfcdf5873 100644
--- a/etc/seamonkey.profile
+++ b/etc/seamonkey.profile
@@ -1,6 +1,11 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/seamonkey.local
4
1# Firejail profile for Seamoneky based off Mozilla Firefox 5# Firejail profile for Seamoneky based off Mozilla Firefox
2noblacklist ~/.mozilla 6noblacklist ~/.mozilla
3noblacklist ~/.cache/mozilla 7noblacklist ~/.cache/mozilla
8noblacklist ~/.pki
4include /etc/firejail/disable-common.inc 9include /etc/firejail/disable-common.inc
5include /etc/firejail/disable-programs.inc 10include /etc/firejail/disable-programs.inc
6include /etc/firejail/disable-devel.inc 11include /etc/firejail/disable-devel.inc
diff --git a/etc/server.profile b/etc/server.profile
index b8a34feb2..d1d7dffa9 100644
--- a/etc/server.profile
+++ b/etc/server.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/server.local
4
1# generic server profile 5# generic server profile
2# it allows /sbin and /usr/sbin directories - this is where servers are installed 6# it allows /sbin and /usr/sbin directories - this is where servers are installed
3noblacklist /sbin 7noblacklist /sbin
diff --git a/etc/simple-scan.profile b/etc/simple-scan.profile
index 03089482b..ee7e50ba7 100644
--- a/etc/simple-scan.profile
+++ b/etc/simple-scan.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/simple-scan.local
4
1# simple-scan profile 5# simple-scan profile
2noblacklist ~/.cache/simple-scan 6noblacklist ~/.cache/simple-scan
3 7
diff --git a/etc/skanlite.profile b/etc/skanlite.profile
index 667b775c8..b1b4b5a96 100644
--- a/etc/skanlite.profile
+++ b/etc/skanlite.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/skanlite.local
4
1# skanlite profile 5# skanlite profile
2include /etc/firejail/disable-common.inc 6include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 7include /etc/firejail/disable-programs.inc
diff --git a/etc/skype.profile b/etc/skype.profile
index 9cbcd5117..169a1dd51 100644
--- a/etc/skype.profile
+++ b/etc/skype.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/skype.local
4
1# Skype profile 5# Skype profile
2noblacklist ${HOME}/.Skype 6noblacklist ${HOME}/.Skype
3include /etc/firejail/disable-common.inc 7include /etc/firejail/disable-common.inc
diff --git a/etc/skypeforlinux.profile b/etc/skypeforlinux.profile
index 3f0a274f9..d3bbf3e53 100644
--- a/etc/skypeforlinux.profile
+++ b/etc/skypeforlinux.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/skypeforlinux.local
4
1# skypeforlinux profile 5# skypeforlinux profile
2noblacklist ${HOME}/.config/skypeforlinux 6noblacklist ${HOME}/.config/skypeforlinux
3include /etc/firejail/disable-common.inc 7include /etc/firejail/disable-common.inc
diff --git a/etc/slack.profile b/etc/slack.profile
index a85a28f03..6a2dae253 100644
--- a/etc/slack.profile
+++ b/etc/slack.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/slack.local
4
1# Firejail profile for Slack 5# Firejail profile for Slack
2noblacklist ${HOME}/.config/Slack 6noblacklist ${HOME}/.config/Slack
3noblacklist ${HOME}/Downloads 7noblacklist ${HOME}/Downloads
diff --git a/etc/snap.profile b/etc/snap.profile
index e2ada3a99..085ce8e2a 100644
--- a/etc/snap.profile
+++ b/etc/snap.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/snap.local
4
1################################ 5################################
2# Generic Ubuntu snap application profile 6# Generic Ubuntu snap application profile
3################################ 7################################
diff --git a/etc/soffice.profile b/etc/soffice.profile
index fecd08822..737419a8f 100644
--- a/etc/soffice.profile
+++ b/etc/soffice.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/soffice.local
4
1################################ 5################################
2# LibreOffice profile 6# LibreOffice profile
3################################ 7################################
diff --git a/etc/spotify.profile b/etc/spotify.profile
index 6dbcc03ee..843038a2b 100644
--- a/etc/spotify.profile
+++ b/etc/spotify.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/spotify.local
4
1# Spotify media player profile 5# Spotify media player profile
2noblacklist ${HOME}/.config/spotify 6noblacklist ${HOME}/.config/spotify
3noblacklist ${HOME}/.cache/spotify 7noblacklist ${HOME}/.cache/spotify
diff --git a/etc/ssh-agent.profile b/etc/ssh-agent.profile
index bea3a6061..43d9f62fa 100644
--- a/etc/ssh-agent.profile
+++ b/etc/ssh-agent.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/ssh-agent.local
4
1# ssh-agent 5# ssh-agent
2quiet 6quiet
3noblacklist ~/.ssh 7noblacklist ~/.ssh
diff --git a/etc/ssh.profile b/etc/ssh.profile
index b7a8ed2b9..b1ef6b27e 100644
--- a/etc/ssh.profile
+++ b/etc/ssh.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/ssh.local
4
1# ssh client 5# ssh client
2quiet 6quiet
3noblacklist ~/.ssh 7noblacklist ~/.ssh
diff --git a/etc/start-tor-browser.profile b/etc/start-tor-browser.profile
index ee19cee25..c13f85a66 100644
--- a/etc/start-tor-browser.profile
+++ b/etc/start-tor-browser.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/start-tor-browser.local
4
1# Firejail profile for the Tor Brower Bundle 5# Firejail profile for the Tor Brower Bundle
2include /etc/firejail/disable-common.inc 6include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-devel.inc 7include /etc/firejail/disable-devel.inc
@@ -14,7 +18,7 @@ seccomp
14shell none 18shell none
15tracelog 19tracelog
16 20
17private-bin bash,grep,sed,tail,env,gpg,id,readlink,dirname,test,mkdir,ln,sed,cp,rm,getconf 21private-bin bash,grep,tail,env,gpg,id,readlink,dirname,test,mkdir,ln,sed,cp,rm,getconf
18private-etc fonts 22private-etc fonts
19private-dev 23private-dev
20private-tmp 24private-tmp
diff --git a/etc/steam.profile b/etc/steam.profile
index 5dc5e80ff..b527589de 100644
--- a/etc/steam.profile
+++ b/etc/steam.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/steam.local
4
1# Steam profile (applies to games/apps launched from Steam as well) 5# Steam profile (applies to games/apps launched from Steam as well)
2noblacklist ${HOME}/.steam 6noblacklist ${HOME}/.steam
3noblacklist ${HOME}/.local/share/steam 7noblacklist ${HOME}/.local/share/steam
diff --git a/etc/stellarium.profile b/etc/stellarium.profile
index d57c9e5f7..fc952be34 100644
--- a/etc/stellarium.profile
+++ b/etc/stellarium.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/stellarium.local
4
1# Firejail profile for Stellarium. 5# Firejail profile for Stellarium.
2noblacklist ~/.stellarium 6noblacklist ~/.stellarium
3noblacklist ~/.config/stellarium 7noblacklist ~/.config/stellarium
diff --git a/etc/strings.profile b/etc/strings.profile
index 2bbab1366..bfa089bd0 100644
--- a/etc/strings.profile
+++ b/etc/strings.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/strings.local
4
1# strings profile 5# strings profile
2quiet 6quiet
3ignore noroot 7ignore noroot
diff --git a/etc/synfigstudio.profile b/etc/synfigstudio.profile
index 69b2a0db2..636b09bd0 100644
--- a/etc/synfigstudio.profile
+++ b/etc/synfigstudio.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/synfigstudio.local
4
1# synfigstudio 5# synfigstudio
2noblacklist ${HOME}/.config/synfig 6noblacklist ${HOME}/.config/synfig
3noblacklist ${HOME}/.synfig 7noblacklist ${HOME}/.synfig
diff --git a/etc/tar.profile b/etc/tar.profile
index 3addb02fb..0162be718 100644
--- a/etc/tar.profile
+++ b/etc/tar.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/tar.local
4
1# tar profile 5# tar profile
2quiet 6quiet
3ignore noroot 7ignore noroot
diff --git a/etc/telegram.profile b/etc/telegram.profile
index 7615c8eef..c5e72fe76 100644
--- a/etc/telegram.profile
+++ b/etc/telegram.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/telegram.local
4
1# Telegram IRC profile 5# Telegram IRC profile
2noblacklist ${HOME}/.TelegramDesktop 6noblacklist ${HOME}/.TelegramDesktop
3include /etc/firejail/disable-common.inc 7include /etc/firejail/disable-common.inc
diff --git a/etc/thunar.profile b/etc/thunar.profile
new file mode 100644
index 000000000..868f80912
--- /dev/null
+++ b/etc/thunar.profile
@@ -0,0 +1 @@
include /etc/firejail/Thunar.profile
diff --git a/etc/thunderbird.profile b/etc/thunderbird.profile
index 568343ba6..88ab7501e 100644
--- a/etc/thunderbird.profile
+++ b/etc/thunderbird.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/thunderbird.local
4
1# Firejail profile for Mozilla Thunderbird 5# Firejail profile for Mozilla Thunderbird
2# Users have thunderbird set to open a browser by clicking a link in an email 6# Users have thunderbird set to open a browser by clicking a link in an email
3# We are not allowed to blacklist browser-specific directories 7# We are not allowed to blacklist browser-specific directories
diff --git a/etc/totem.profile b/etc/totem.profile
index 252b46979..0b3942cf0 100644
--- a/etc/totem.profile
+++ b/etc/totem.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/totem.local
4
1# Totem media player profile 5# Totem media player profile
2noblacklist ~/.config/totem 6noblacklist ~/.config/totem
3noblacklist ~/.local/share/totem 7noblacklist ~/.local/share/totem
diff --git a/etc/tracker.profile b/etc/tracker.profile
index 7f4f371eb..56528785a 100644
--- a/etc/tracker.profile
+++ b/etc/tracker.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/tracker.local
4
1# tracker profile 5# tracker profile
2 6
3# Tracker is started by systemd on most systems. Therefore it is not firejailed by default 7# Tracker is started by systemd on most systems. Therefore it is not firejailed by default
diff --git a/etc/transmission-cli.profile b/etc/transmission-cli.profile
index 6cbc3415c..dbcc8d041 100644
--- a/etc/transmission-cli.profile
+++ b/etc/transmission-cli.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/transmission-cli.local
4
1# transmission-cli bittorrent profile 5# transmission-cli bittorrent profile
2noblacklist ${HOME}/.config/transmission 6noblacklist ${HOME}/.config/transmission
3noblacklist ${HOME}/.cache/transmission 7noblacklist ${HOME}/.cache/transmission
diff --git a/etc/transmission-gtk.profile b/etc/transmission-gtk.profile
index fa54ea81b..dcd3317ef 100644
--- a/etc/transmission-gtk.profile
+++ b/etc/transmission-gtk.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/transmission-gtk.local
4
1# transmission-gtk bittorrent profile 5# transmission-gtk bittorrent profile
2noblacklist ${HOME}/.config/transmission 6noblacklist ${HOME}/.config/transmission
3noblacklist ${HOME}/.cache/transmission 7noblacklist ${HOME}/.cache/transmission
diff --git a/etc/transmission-qt.profile b/etc/transmission-qt.profile
index 100fadc27..ed63f7cff 100644
--- a/etc/transmission-qt.profile
+++ b/etc/transmission-qt.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/transmission-qt.local
4
1# transmission-qt bittorrent profile 5# transmission-qt bittorrent profile
2noblacklist ${HOME}/.config/transmission 6noblacklist ${HOME}/.config/transmission
3noblacklist ${HOME}/.cache/transmission 7noblacklist ${HOME}/.cache/transmission
diff --git a/etc/transmission-show.profile b/etc/transmission-show.profile
index 5e5284b34..0b88789b1 100644
--- a/etc/transmission-show.profile
+++ b/etc/transmission-show.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/transmission-show.local
4
1# transmission-show profile 5# transmission-show profile
2noblacklist ${HOME}/.config/transmission 6noblacklist ${HOME}/.config/transmission
3noblacklist ${HOME}/.cache/transmission 7noblacklist ${HOME}/.cache/transmission
diff --git a/etc/uget-gtk.profile b/etc/uget-gtk.profile
index 3ba28f772..cc5d4dda5 100644
--- a/etc/uget-gtk.profile
+++ b/etc/uget-gtk.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/uget-gtk.local
4
1# uGet profile 5# uGet profile
2noblacklist ${HOME}/.config/uGet 6noblacklist ${HOME}/.config/uGet
3 7
diff --git a/etc/unbound.profile b/etc/unbound.profile
index 5e2cb5f65..0bd46b7f4 100644
--- a/etc/unbound.profile
+++ b/etc/unbound.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/unbound.local
4
1# security profile for unbound (https://unbound.net) 5# security profile for unbound (https://unbound.net)
2noblacklist /sbin 6noblacklist /sbin
3noblacklist /usr/sbin 7noblacklist /usr/sbin
@@ -9,5 +13,6 @@ include /etc/firejail/disable-passwdmgr.inc
9private 13private
10private-dev 14private-dev
11nosound 15nosound
16no3d
12seccomp.drop mount,umount2,ptrace,kexec_load,kexec_file_load,open_by_handle_at,init_module,finit_module,delete_module,iopl,ioperm,swapon,swapoff,syslog,process_vm_readv,process_vm_writev,sysfs,_sysctl,adjtimex,clock_adjtime,lookup_dcookie,perf_event_open,fanotify_init,kcmp,add_key,request_key,keyctl,uselib,acct,modify_ldt,pivot_root,io_setup,io_destroy,io_getevents,io_submit,io_cancel,remap_file_pages,mbind,get_mempolicy,set_mempolicy,migrate_pages,move_pages,vmsplice,perf_event_open 17seccomp.drop mount,umount2,ptrace,kexec_load,kexec_file_load,open_by_handle_at,init_module,finit_module,delete_module,iopl,ioperm,swapon,swapoff,syslog,process_vm_readv,process_vm_writev,sysfs,_sysctl,adjtimex,clock_adjtime,lookup_dcookie,perf_event_open,fanotify_init,kcmp,add_key,request_key,keyctl,uselib,acct,modify_ldt,pivot_root,io_setup,io_destroy,io_getevents,io_submit,io_cancel,remap_file_pages,mbind,get_mempolicy,set_mempolicy,migrate_pages,move_pages,vmsplice,perf_event_open
13 18
diff --git a/etc/unrar.profile b/etc/unrar.profile
index bde6f4e22..da187bfef 100644
--- a/etc/unrar.profile
+++ b/etc/unrar.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/unrar.local
4
1# unrar profile 5# unrar profile
2quiet 6quiet
3ignore noroot 7ignore noroot
diff --git a/etc/unzip.profile b/etc/unzip.profile
index 8c10d11a0..24767c86f 100644
--- a/etc/unzip.profile
+++ b/etc/unzip.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/unzip.local
4
1# unzip profile 5# unzip profile
2quiet 6quiet
3ignore noroot 7ignore noroot
diff --git a/etc/uudeview.profile b/etc/uudeview.profile
index d5b750a13..5f41188af 100644
--- a/etc/uudeview.profile
+++ b/etc/uudeview.profile
@@ -1,9 +1,12 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/uudeview.local
4
1# uudeview profile 5# uudeview profile
2quiet 6quiet
3ignore noroot 7ignore noroot
4include /etc/firejail/default.profile 8include /etc/firejail/default.profile
5 9
6blacklist /etc
7 10
8hostname uudeview 11hostname uudeview
9net none 12net none
@@ -13,3 +16,4 @@ tracelog
13 16
14private-bin uudeview 17private-bin uudeview
15private-dev 18private-dev
19private-etc ld.so.preload
diff --git a/etc/uzbl-browser.profile b/etc/uzbl-browser.profile
new file mode 100644
index 000000000..ce0b0d0a5
--- /dev/null
+++ b/etc/uzbl-browser.profile
@@ -0,0 +1,33 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/uzbl-browser.local
4
5# Firejail profile for uzbl-browser
6
7noblacklist ~/.config/uzbl
8noblacklist ~/.gnupg
9include /etc/firejail/disable-common.inc
10include /etc/firejail/disable-programs.inc
11include /etc/firejail/disable-devel.inc
12
13caps.drop all
14netfilter
15nonewprivs
16noroot
17protocol unix,inet,inet6
18seccomp
19tracelog
20
21mkdir ~/.config/uzbl
22whitelist ~/.config/uzbl
23mkdir ~/.local/share/uzbl
24whitelist ~/.local/share/uzbl
25
26whitelist ${DOWNLOADS}
27
28mkdir ~/.gnupg
29whitelist ~/.gnupg
30mkdir ~/.password-store
31whitelist ~/.password-store
32
33include /etc/firejail/whitelist-common.inc
diff --git a/etc/vim.profile b/etc/vim.profile
index b161fcbb0..e89104e17 100644
--- a/etc/vim.profile
+++ b/etc/vim.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/vim.local
4
1# vim profile 5# vim profile
2noblacklist ~/.vim 6noblacklist ~/.vim
3noblacklist ~/.vimrc 7noblacklist ~/.vimrc
diff --git a/etc/virtualbox.profile b/etc/virtualbox.profile
index 1e765b89b..57ead818e 100644
--- a/etc/virtualbox.profile
+++ b/etc/virtualbox.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/virtualbox.local
4
1# virtualbox profile 5# virtualbox profile
2noblacklist ${HOME}/.VirtualBox 6noblacklist ${HOME}/.VirtualBox
3noblacklist ${HOME}/VirtualBox VMs 7noblacklist ${HOME}/VirtualBox VMs
diff --git a/etc/vivaldi-beta.profile b/etc/vivaldi-beta.profile
index 5426c4a2d..3b7c7d2b4 100644
--- a/etc/vivaldi-beta.profile
+++ b/etc/vivaldi-beta.profile
@@ -1,2 +1,6 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/vivaldi-beta.local
4
1# Vivaldi Beta browser profile 5# Vivaldi Beta browser profile
2include /etc/firejail/vivaldi.profile 6include /etc/firejail/vivaldi.profile
diff --git a/etc/vivaldi.profile b/etc/vivaldi.profile
index b3a096069..0667c4114 100644
--- a/etc/vivaldi.profile
+++ b/etc/vivaldi.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/vivaldi.local
4
1# Vivaldi browser profile 5# Vivaldi browser profile
2noblacklist ~/.config/vivaldi 6noblacklist ~/.config/vivaldi
3noblacklist ~/.cache/vivaldi 7noblacklist ~/.cache/vivaldi
diff --git a/etc/vlc.profile b/etc/vlc.profile
index 2fd763f25..9d1cdb4c8 100644
--- a/etc/vlc.profile
+++ b/etc/vlc.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/vlc.local
4
1# VLC media player profile 5# VLC media player profile
2noblacklist ${HOME}/.config/vlc 6noblacklist ${HOME}/.config/vlc
3 7
@@ -8,7 +12,7 @@ include /etc/firejail/disable-passwdmgr.inc
8 12
9caps.drop all 13caps.drop all
10netfilter 14netfilter
11nogroups 15# nogroups
12nonewprivs 16nonewprivs
13noroot 17noroot
14protocol unix,inet,inet6,netlink 18protocol unix,inet,inet6,netlink
diff --git a/etc/w3m.profile b/etc/w3m.profile
index 7ee91bb70..45546440a 100644
--- a/etc/w3m.profile
+++ b/etc/w3m.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/w3m.local
4
1# w3m profile 5# w3m profile
2noblacklist ~/.w3m 6noblacklist ~/.w3m
3 7
diff --git a/etc/warzone2100.profile b/etc/warzone2100.profile
index 7c7efade8..702097d98 100644
--- a/etc/warzone2100.profile
+++ b/etc/warzone2100.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/warzone2100.local
4
1# Firejail profile for warzone2100 5# Firejail profile for warzone2100
2# Currently supports warzone2100-3.1 6# Currently supports warzone2100-3.1
3noblacklist ~/.warzone2100-3.1 7noblacklist ~/.warzone2100-3.1
diff --git a/etc/weechat-curses.profile b/etc/weechat-curses.profile
index 4a92f0b34..345196dfb 100644
--- a/etc/weechat-curses.profile
+++ b/etc/weechat-curses.profile
@@ -1,2 +1,6 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/weechat-curses.local
4
1# Weechat IRC profile (Debian) 5# Weechat IRC profile (Debian)
2include /etc/firejail/weechat.profile 6include /etc/firejail/weechat.profile
diff --git a/etc/weechat.profile b/etc/weechat.profile
index 410061278..870e02677 100644
--- a/etc/weechat.profile
+++ b/etc/weechat.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/weechat.local
4
1# Weechat IRC profile 5# Weechat IRC profile
2noblacklist ${HOME}/.weechat 6noblacklist ${HOME}/.weechat
3include /etc/firejail/disable-common.inc 7include /etc/firejail/disable-common.inc
diff --git a/etc/wesnoth.profile b/etc/wesnoth.profile
index bb489ddeb..212466f5a 100644
--- a/etc/wesnoth.profile
+++ b/etc/wesnoth.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/wesnoth.local
4
1# Whitelist-based profile for "Battle for Wesnoth" (game). 5# Whitelist-based profile for "Battle for Wesnoth" (game).
2noblacklist ${HOME}/.config/wesnoth 6noblacklist ${HOME}/.config/wesnoth
3noblacklist ${HOME}/.cache/wesnoth 7noblacklist ${HOME}/.cache/wesnoth
diff --git a/etc/wget.profile b/etc/wget.profile
index ff4b92bae..cd156a376 100644
--- a/etc/wget.profile
+++ b/etc/wget.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/wget.local
4
1# wget profile 5# wget profile
2quiet 6quiet
3include /etc/firejail/disable-common.inc 7include /etc/firejail/disable-common.inc
diff --git a/etc/whitelist-common.inc b/etc/whitelist-common.inc
index d4e69948e..cf7797100 100644
--- a/etc/whitelist-common.inc
+++ b/etc/whitelist-common.inc
@@ -1,3 +1,6 @@
1# Local customizations come here
2include /etc/firejail/whitelist-common.local
3
1# common whitelist for all profiles 4# common whitelist for all profiles
2 5
3whitelist ~/.XCompose 6whitelist ~/.XCompose
diff --git a/etc/wine.profile b/etc/wine.profile
index 18e5346af..c732d6edf 100644
--- a/etc/wine.profile
+++ b/etc/wine.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/wine.local
4
1# wine profile 5# wine profile
2noblacklist ${HOME}/.steam 6noblacklist ${HOME}/.steam
3noblacklist ${HOME}/.local/share/steam 7noblacklist ${HOME}/.local/share/steam
diff --git a/etc/wire.profile b/etc/wire.profile
index ec8ed8771..79ac893a9 100644
--- a/etc/wire.profile
+++ b/etc/wire.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/wire.local
4
1# wire messenger profile 5# wire messenger profile
2noblacklist ~/.config/Wire 6noblacklist ~/.config/Wire
3noblacklist ~/.config/wire 7noblacklist ~/.config/wire
diff --git a/etc/wireshark.profile b/etc/wireshark.profile
index 898fc787e..90909edf1 100644
--- a/etc/wireshark.profile
+++ b/etc/wireshark.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/wireshark.local
4
1# Firejail profile for 5# Firejail profile for
2noblacklist ${HOME}/.config/wireshark 6noblacklist ${HOME}/.config/wireshark
3 7
@@ -6,17 +10,21 @@ include /etc/firejail/disable-programs.inc
6include /etc/firejail/disable-devel.inc 10include /etc/firejail/disable-devel.inc
7include /etc/firejail/disable-passwdmgr.inc 11include /etc/firejail/disable-passwdmgr.inc
8 12
9caps.drop all 13#
14# The profile allows users to run wireshark as root
15#
16#caps.drop all
17#noroot
18#protocol unix,inet,inet6,netlink
19
10netfilter 20netfilter
11nogroups 21nogroups
12nonewprivs 22nonewprivs
13noroot
14nosound 23nosound
15protocol unix,inet,inet6,netlink
16seccomp 24seccomp
17shell none 25shell none
18tracelog 26tracelog
19 27
20private-bin wireshark 28#private-bin wireshark
21private-dev 29private-dev
22private-tmp 30private-tmp
diff --git a/etc/xchat.profile b/etc/xchat.profile
index 1f2865cab..0571746b3 100644
--- a/etc/xchat.profile
+++ b/etc/xchat.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/xchat.local
4
1# XChat IRC profile 5# XChat IRC profile
2noblacklist ${HOME}/.config/xchat 6noblacklist ${HOME}/.config/xchat
3 7
diff --git a/etc/xed.profile b/etc/xed.profile
index 051710a70..c8076923a 100644
--- a/etc/xed.profile
+++ b/etc/xed.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/xed.local
4
1# Firejail profile for Xed 5# Firejail profile for Xed
2noblacklist ${HOME}/.config/xed 6noblacklist ${HOME}/.config/xed
3 7
diff --git a/etc/xfburn.profile b/etc/xfburn.profile
index 1dd24aa61..a05d844d0 100644
--- a/etc/xfburn.profile
+++ b/etc/xfburn.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/xfburn.local
4
1# xfburn profile 5# xfburn profile
2noblacklist ~/.config/xfburn 6noblacklist ~/.config/xfburn
3 7
diff --git a/etc/xiphos.profile b/etc/xiphos.profile
index b7fb6ecf3..7522c00d7 100644
--- a/etc/xiphos.profile
+++ b/etc/xiphos.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/xiphos.local
4
1# Firejail profile for xiphos 5# Firejail profile for xiphos
2noblacklist ~/.sword 6noblacklist ~/.sword
3noblacklist ~/.xiphos 7noblacklist ~/.xiphos
diff --git a/etc/xmms.profile b/etc/xmms.profile
new file mode 100644
index 000000000..b33727c2c
--- /dev/null
+++ b/etc/xmms.profile
@@ -0,0 +1,23 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/xmms.local
4
5# Firejail profile for XMMS
6noblacklist ${HOME}/.xmms
7
8include /etc/firejail/disable-common.inc
9include /etc/firejail/disable-programs.inc
10include /etc/firejail/disable-devel.inc
11include /etc/firejail/disable-passwdmgr.inc
12
13caps.drop all
14netfilter
15nonewprivs
16noroot
17protocol unix,inet,inet6
18seccomp
19shell none
20no3d
21
22private-bin xmms
23private-dev
diff --git a/etc/xonotic-glx.profile b/etc/xonotic-glx.profile
index b255ffdbb..2f57340de 100644
--- a/etc/xonotic-glx.profile
+++ b/etc/xonotic-glx.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/xonotic-glx.local
4
1# 5#
2#Profile for xonotic:xonotic-glx 6#Profile for xonotic:xonotic-glx
3# 7#
diff --git a/etc/xonotic-sdl.profile b/etc/xonotic-sdl.profile
index 783667304..9af845958 100644
--- a/etc/xonotic-sdl.profile
+++ b/etc/xonotic-sdl.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/xonotic-sdl.local
4
1# 5#
2#Profile for xonotic:xonotic-sdl 6#Profile for xonotic:xonotic-sdl
3# 7#
diff --git a/etc/xonotic.profile b/etc/xonotic.profile
index 75d649619..f2690c6c3 100644
--- a/etc/xonotic.profile
+++ b/etc/xonotic.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/xonotic.local
4
1# 5#
2#Profile for xonotic 6#Profile for xonotic
3# 7#
diff --git a/etc/xpdf.profile b/etc/xpdf.profile
index 7ea368bbe..b77bc76ac 100644
--- a/etc/xpdf.profile
+++ b/etc/xpdf.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/xpdf.local
4
1################################ 5################################
2# xpdf application profile 6# xpdf application profile
3################################ 7################################
diff --git a/etc/xplayer.profile b/etc/xplayer.profile
index 191d2f67f..d5b80fbc0 100644
--- a/etc/xplayer.profile
+++ b/etc/xplayer.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/xplayer.local
4
1# Xplayer profile 5# Xplayer profile
2noblacklist ~/.config/xplayer 6noblacklist ~/.config/xplayer
3noblacklist ~/.local/share/xplayer 7noblacklist ~/.local/share/xplayer
diff --git a/etc/xpra.profile b/etc/xpra.profile
index 32be90b19..d0fff2ebf 100644
--- a/etc/xpra.profile
+++ b/etc/xpra.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/xpra.local
4
1# xpra profile 5# xpra profile
2include /etc/firejail/disable-common.inc 6include /etc/firejail/disable-common.inc
3include /etc/firejail/disable-programs.inc 7include /etc/firejail/disable-programs.inc
diff --git a/etc/xreader.profile b/etc/xreader.profile
index d2a000bd0..2e6015aef 100644
--- a/etc/xreader.profile
+++ b/etc/xreader.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/xreader.local
4
1# Xreader profile 5# Xreader profile
2noblacklist ~/.config/xreader 6noblacklist ~/.config/xreader
3noblacklist ~/.cache/xreader 7noblacklist ~/.cache/xreader
diff --git a/etc/xviewer.profile b/etc/xviewer.profile
index ca380b4c7..d784ddfb3 100644
--- a/etc/xviewer.profile
+++ b/etc/xviewer.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/xviewer.local
4
1# xviewer profile 5# xviewer profile
2noblacklist ~/.config/xviewer 6noblacklist ~/.config/xviewer
3 7
diff --git a/etc/xz.profile b/etc/xz.profile
index 5b29f7338..2f7d9cae5 100644
--- a/etc/xz.profile
+++ b/etc/xz.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/xz.local
4
1# xz profile 5# xz profile
2quiet 6quiet
3include /etc/firejail/cpio.profile 7include /etc/firejail/cpio.profile
diff --git a/etc/xzdec.profile b/etc/xzdec.profile
index 6164e3200..e938b81ec 100644
--- a/etc/xzdec.profile
+++ b/etc/xzdec.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/xzdec.local
4
1# xzdec profile 5# xzdec profile
2quiet 6quiet
3ignore noroot 7ignore noroot
diff --git a/etc/zathura.profile b/etc/zathura.profile
index 6c93a2480..f75541dad 100644
--- a/etc/zathura.profile
+++ b/etc/zathura.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/zathura.local
4
1# zathura document viewer profile 5# zathura document viewer profile
2noblacklist ~/.config/zathura 6noblacklist ~/.config/zathura
3noblacklist ~/.local/share/zathura 7noblacklist ~/.local/share/zathura
diff --git a/etc/zoom.profile b/etc/zoom.profile
index 4c08868cf..809356d95 100644
--- a/etc/zoom.profile
+++ b/etc/zoom.profile
@@ -1,3 +1,7 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/zoom.local
4
1# Firejail profile for zoom.us 5# Firejail profile for zoom.us
2noblacklist ~/.config/zoomus.conf 6noblacklist ~/.config/zoomus.conf
3 7