aboutsummaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
Diffstat (limited to 'etc')
-rw-r--r--etc/audacity.profile16
-rw-r--r--etc/cpio.profile8
-rw-r--r--etc/disable-programs.inc1
-rw-r--r--etc/gzip.profile19
-rw-r--r--etc/xzdec.profile13
5 files changed, 57 insertions, 0 deletions
diff --git a/etc/audacity.profile b/etc/audacity.profile
new file mode 100644
index 000000000..8971ce1a2
--- /dev/null
+++ b/etc/audacity.profile
@@ -0,0 +1,16 @@
1# Audacity profile
2noblacklist ~/.audacity-data
3
4include /etc/firejail/disable-common.inc
5include /etc/firejail/disable-devel.inc
6include /etc/firejail/disable-passwdmgr.inc
7include /etc/firejail/disable-programs.inc
8
9caps.drop all
10netfilter
11nonewprivs
12noroot
13nogroups
14#private-bin audacity
15protocol unix,inet,inet6
16seccomp
diff --git a/etc/cpio.profile b/etc/cpio.profile
new file mode 100644
index 000000000..811d657f2
--- /dev/null
+++ b/etc/cpio.profile
@@ -0,0 +1,8 @@
1include /usr/local/etc/firejail/server.profile
2include /usr/local/etc/firejail/disable-common.inc
3include /usr/local/etc/firejail/disable-programs.inc
4include /usr/local/etc/firejail/disable-passwdmgr.inc
5caps.drop all
6net none
7shell none
8seccomp
diff --git a/etc/disable-programs.inc b/etc/disable-programs.inc
index 70deb2b0c..e9dd331aa 100644
--- a/etc/disable-programs.inc
+++ b/etc/disable-programs.inc
@@ -32,6 +32,7 @@ blacklist ${HOME}/.config/vlc
32blacklist ${HOME}/.config/mpv 32blacklist ${HOME}/.config/mpv
33blacklist ${HOME}/.config/totem 33blacklist ${HOME}/.config/totem
34blacklist ${HOME}/.config/xplayer 34blacklist ${HOME}/.config/xplayer
35blacklist ${HOME}/.audacity-data
35 36
36# HTTP / FTP / Mail 37# HTTP / FTP / Mail
37blacklist ${HOME}/.icedove 38blacklist ${HOME}/.icedove
diff --git a/etc/gzip.profile b/etc/gzip.profile
new file mode 100644
index 000000000..f231c3780
--- /dev/null
+++ b/etc/gzip.profile
@@ -0,0 +1,19 @@
1################################
2# Gzip profile
3################################
4include /etc/firejail/disable-common.inc
5include /etc/firejail/disable-programs.inc
6include /etc/firejail/disable-passwdmgr.inc
7
8blacklist ${HOME}/.wine
9blacklist ${HOME}/.ssh
10
11tracelog
12caps.drop all
13seccomp
14net none
15noroot
16nosound
17nogroups
18nonewprivs
19
diff --git a/etc/xzdec.profile b/etc/xzdec.profile
new file mode 100644
index 000000000..f29f7360c
--- /dev/null
+++ b/etc/xzdec.profile
@@ -0,0 +1,13 @@
1# Firejail profile for XZ decompressor
2# xzdec.profile
3
4include /etc/firejail/disable-mgmt.inc
5include /etc/firejail/disable-secret.inc
6include /etc/firejail/disable-common.inc
7include /etc/firejail/disable-devel.inc
8
9caps.drop all
10seccomp
11tracelog
12noroot
13shell none