aboutsummaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
Diffstat (limited to 'etc')
-rw-r--r--etc/apktool.profile1
-rw-r--r--etc/arm.profile2
-rw-r--r--etc/baobab.profile1
-rw-r--r--etc/bless.profile1
-rw-r--r--etc/chromium.profile4
-rw-r--r--etc/dex2jar.profile1
-rw-r--r--etc/flashpeak-slimjet.profile3
-rw-r--r--etc/gitg.profile1
-rw-r--r--etc/google-chrome-beta.profile3
-rw-r--r--etc/google-chrome-unstable.profile3
-rw-r--r--etc/google-chrome.profile3
-rw-r--r--etc/hashcat.profile3
-rw-r--r--etc/jd-gui.profile1
-rw-r--r--etc/meld.profile1
-rw-r--r--etc/multimc5.profile2
-rw-r--r--etc/obs.profile1
-rw-r--r--etc/pdfsam.profile1
-rw-r--r--etc/peek.profile1
-rw-r--r--etc/pithos.profile1
-rw-r--r--etc/sdat2img.profile1
-rw-r--r--etc/strings.profile2
21 files changed, 26 insertions, 11 deletions
diff --git a/etc/apktool.profile b/etc/apktool.profile
index b4ff45c7c..bdd711964 100644
--- a/etc/apktool.profile
+++ b/etc/apktool.profile
@@ -25,6 +25,7 @@ protocol unix
25seccomp 25seccomp
26shell none 26shell none
27 27
28private-bin apktool,bash,java,dirname,basename,expr
28private-dev 29private-dev
29 30
30noexec ${HOME} 31noexec ${HOME}
diff --git a/etc/arm.profile b/etc/arm.profile
index 5845958fa..53d290b49 100644
--- a/etc/arm.profile
+++ b/etc/arm.profile
@@ -33,7 +33,7 @@ shell none
33tracelog 33tracelog
34 34
35disable-mnt 35disable-mnt
36# private-bin arm,tor,sh,python2,python2.7,ps,lsof,ldconfig 36# private-bin arm,tor,sh,bash,python2,python2.7,ps,lsof,ldconfig
37private-dev 37private-dev
38private-etc tor,passwd 38private-etc tor,passwd
39private-tmp 39private-tmp
diff --git a/etc/baobab.profile b/etc/baobab.profile
index 014f8869c..ef733632d 100644
--- a/etc/baobab.profile
+++ b/etc/baobab.profile
@@ -25,6 +25,7 @@ protocol unix
25seccomp 25seccomp
26shell none 26shell none
27 27
28private-bin baobab
28private-dev 29private-dev
29private-tmp 30private-tmp
30 31
diff --git a/etc/bless.profile b/etc/bless.profile
index 8285e4473..e4d2f0730 100644
--- a/etc/bless.profile
+++ b/etc/bless.profile
@@ -26,6 +26,7 @@ protocol unix
26seccomp 26seccomp
27shell none 27shell none
28 28
29# private-bin bless,sh,bash,mono
29private-dev 30private-dev
30private-etc fonts,mono 31private-etc fonts,mono
31private-tmp 32private-tmp
diff --git a/etc/chromium.profile b/etc/chromium.profile
index 37b2e51a6..9be99e68a 100644
--- a/etc/chromium.profile
+++ b/etc/chromium.profile
@@ -11,8 +11,7 @@ noblacklist ~/.config/chromium-flags.conf
11noblacklist ~/.pki 11noblacklist ~/.pki
12 12
13include /etc/firejail/disable-common.inc 13include /etc/firejail/disable-common.inc
14# chromium is distributed with a perl script on Arch 14include /etc/firejail/disable-devel.inc
15# include /etc/firejail/disable-devel.inc
16include /etc/firejail/disable-programs.inc 15include /etc/firejail/disable-programs.inc
17 16
18mkdir ~/.cache/chromium 17mkdir ~/.cache/chromium
@@ -32,6 +31,7 @@ nogroups
32notv 31notv
33shell none 32shell none
34 33
34# private-bin chromium,chromium-browser,chromedriver
35private-dev 35private-dev
36# private-tmp - problems with multiple browser sessions 36# private-tmp - problems with multiple browser sessions
37 37
diff --git a/etc/dex2jar.profile b/etc/dex2jar.profile
index 858baba6d..5261bb865 100644
--- a/etc/dex2jar.profile
+++ b/etc/dex2jar.profile
@@ -26,6 +26,7 @@ protocol unix
26seccomp 26seccomp
27shell none 27shell none
28 28
29private-bin dex2jar,java,sh,bash,expr,dirname,ls,uname,grep
29private-dev 30private-dev
30 31
31noexec ${HOME} 32noexec ${HOME}
diff --git a/etc/flashpeak-slimjet.profile b/etc/flashpeak-slimjet.profile
index 8a8337802..18db4c597 100644
--- a/etc/flashpeak-slimjet.profile
+++ b/etc/flashpeak-slimjet.profile
@@ -15,8 +15,7 @@ noblacklist ~/.config/slimjet
15noblacklist ~/.pki 15noblacklist ~/.pki
16 16
17include /etc/firejail/disable-common.inc 17include /etc/firejail/disable-common.inc
18# chromium is distributed with a perl script on Arch 18include /etc/firejail/disable-devel.inc
19# include /etc/firejail/disable-devel.inc
20include /etc/firejail/disable-programs.inc 19include /etc/firejail/disable-programs.inc
21 20
22mkdir ~/.cache/slimjet 21mkdir ~/.cache/slimjet
diff --git a/etc/gitg.profile b/etc/gitg.profile
index 869c4a6f5..1a731d507 100644
--- a/etc/gitg.profile
+++ b/etc/gitg.profile
@@ -27,6 +27,7 @@ protocol unix,inet,inet6
27seccomp 27seccomp
28shell none 28shell none
29 29
30private-bin gitg,git,ssh
30private-dev 31private-dev
31private-tmp 32private-tmp
32 33
diff --git a/etc/google-chrome-beta.profile b/etc/google-chrome-beta.profile
index a3fdb214a..ac457b92f 100644
--- a/etc/google-chrome-beta.profile
+++ b/etc/google-chrome-beta.profile
@@ -10,8 +10,7 @@ noblacklist ~/.config/google-chrome-beta
10noblacklist ~/.pki 10noblacklist ~/.pki
11 11
12include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
13# chromium is distributed with a perl script on Arch 13include /etc/firejail/disable-devel.inc
14# include /etc/firejail/disable-devel.inc
15include /etc/firejail/disable-programs.inc 14include /etc/firejail/disable-programs.inc
16 15
17mkdir ~/.cache/google-chrome-beta 16mkdir ~/.cache/google-chrome-beta
diff --git a/etc/google-chrome-unstable.profile b/etc/google-chrome-unstable.profile
index 8de3c5262..3d7a9a715 100644
--- a/etc/google-chrome-unstable.profile
+++ b/etc/google-chrome-unstable.profile
@@ -10,8 +10,7 @@ noblacklist ~/.config/google-chrome-unstable
10noblacklist ~/.pki 10noblacklist ~/.pki
11 11
12include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
13# chromium is distributed with a perl script on Arch 13include /etc/firejail/disable-devel.inc
14# include /etc/firejail/disable-devel.inc
15include /etc/firejail/disable-programs.inc 14include /etc/firejail/disable-programs.inc
16 15
17mkdir ~/.cache/google-chrome-unstable 16mkdir ~/.cache/google-chrome-unstable
diff --git a/etc/google-chrome.profile b/etc/google-chrome.profile
index 1a86c546e..a50e0e89d 100644
--- a/etc/google-chrome.profile
+++ b/etc/google-chrome.profile
@@ -10,8 +10,7 @@ noblacklist ~/.config/google-chrome
10noblacklist ~/.pki 10noblacklist ~/.pki
11 11
12include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
13# chromium is distributed with a perl script on Arch 13include /etc/firejail/disable-devel.inc
14# include /etc/firejail/disable-devel.inc
15include /etc/firejail/disable-programs.inc 14include /etc/firejail/disable-programs.inc
16 15
17mkdir ~/.cache/google-chrome 16mkdir ~/.cache/google-chrome
diff --git a/etc/hashcat.profile b/etc/hashcat.profile
index ae631054b..5f08d7cb8 100644
--- a/etc/hashcat.profile
+++ b/etc/hashcat.profile
@@ -7,8 +7,10 @@ include /etc/firejail/hashcat.local
7include /etc/firejail/globals.local 7include /etc/firejail/globals.local
8 8
9noblacklist ${HOME}/.hashcat 9noblacklist ${HOME}/.hashcat
10noblacklist /usr/include
10 11
11include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-passwdmgr.inc 14include /etc/firejail/disable-passwdmgr.inc
13include /etc/firejail/disable-programs.inc 15include /etc/firejail/disable-programs.inc
14 16
@@ -26,6 +28,7 @@ seccomp
26shell none 28shell none
27 29
28disable-mnt 30disable-mnt
31private-bin hashcat
29private-dev 32private-dev
30private-tmp 33private-tmp
31 34
diff --git a/etc/jd-gui.profile b/etc/jd-gui.profile
index c9af51596..5cb1e1828 100644
--- a/etc/jd-gui.profile
+++ b/etc/jd-gui.profile
@@ -27,6 +27,7 @@ protocol unix
27seccomp 27seccomp
28shell none 28shell none
29 29
30private-bin jd-gui,sh,bash
30private-dev 31private-dev
31private-tmp 32private-tmp
32 33
diff --git a/etc/meld.profile b/etc/meld.profile
index 488b2e365..f1910d0f4 100644
--- a/etc/meld.profile
+++ b/etc/meld.profile
@@ -26,6 +26,7 @@ protocol unix
26seccomp 26seccomp
27shell none 27shell none
28 28
29# private-bin meld,python2,python2.7
29private-dev 30private-dev
30private-tmp 31private-tmp
31 32
diff --git a/etc/multimc5.profile b/etc/multimc5.profile
index fcb351b4d..91a269ffb 100644
--- a/etc/multimc5.profile
+++ b/etc/multimc5.profile
@@ -33,6 +33,8 @@ protocol unix,inet,inet6
33shell none 33shell none
34 34
35disable-mnt 35disable-mnt
36# private-bin works, but causes weirdness
37# private-bin multimc5,bash,mkdir,which,zenity,kdialog,ldd,chmod,valgrind,apt-file,pkgfile,dnf,yum,zypper,pfl,java,grep,sort,awk,readlink,dirname
36private-dev 38private-dev
37private-tmp 39private-tmp
38 40
diff --git a/etc/obs.profile b/etc/obs.profile
index 101d5c28a..187862752 100644
--- a/etc/obs.profile
+++ b/etc/obs.profile
@@ -23,6 +23,7 @@ seccomp
23shell none 23shell none
24tracelog 24tracelog
25 25
26private-bin obs
26private-dev 27private-dev
27private-tmp 28private-tmp
28 29
diff --git a/etc/pdfsam.profile b/etc/pdfsam.profile
index b156513dc..fd52fb9ee 100644
--- a/etc/pdfsam.profile
+++ b/etc/pdfsam.profile
@@ -26,6 +26,7 @@ protocol unix
26seccomp 26seccomp
27shell none 27shell none
28 28
29private-bin pdfsam,sh,bash,java,archlinux-java,grep,awk,dirname,uname,which,sort,find,readlink,expr,ls,java-config
29private-dev 30private-dev
30private-tmp 31private-tmp
31 32
diff --git a/etc/peek.profile b/etc/peek.profile
index a7ad9865c..13c0c72e0 100644
--- a/etc/peek.profile
+++ b/etc/peek.profile
@@ -26,6 +26,7 @@ protocol unix
26seccomp 26seccomp
27shell none 27shell none
28 28
29# private-bin breaks gif mode, mp4 and webm mode work fine however
29# private-bin peek,convert,ffmpeg 30# private-bin peek,convert,ffmpeg
30private-dev 31private-dev
31private-tmp 32private-tmp
diff --git a/etc/pithos.profile b/etc/pithos.profile
index e7c316a39..b81e0b634 100644
--- a/etc/pithos.profile
+++ b/etc/pithos.profile
@@ -26,6 +26,7 @@ seccomp
26shell none 26shell none
27 27
28disable-mnt 28disable-mnt
29# private-bin pithos,python,python3,python3.6
29private-dev 30private-dev
30private-tmp 31private-tmp
31 32
diff --git a/etc/sdat2img.profile b/etc/sdat2img.profile
index 30c2509eb..ce4c4d416 100644
--- a/etc/sdat2img.profile
+++ b/etc/sdat2img.profile
@@ -26,6 +26,7 @@ protocol unix
26seccomp 26seccomp
27shell none 27shell none
28 28
29# private-bin sdat2img,env,python,python3,python3.6
29private-dev 30private-dev
30 31
31noexec ${HOME} 32noexec ${HOME}
diff --git a/etc/strings.profile b/etc/strings.profile
index f203b963c..83561cae5 100644
--- a/etc/strings.profile
+++ b/etc/strings.profile
@@ -18,7 +18,9 @@ novideo
18shell none 18shell none
19tracelog 19tracelog
20 20
21private-bin strings
21private-dev 22private-dev
23private-lib
22 24
23memory-deny-write-execute 25memory-deny-write-execute
24 26