aboutsummaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
Diffstat (limited to 'etc')
-rw-r--r--etc/audacity.profile11
-rw-r--r--etc/aweather.profile19
-rw-r--r--etc/gitter.profile7
-rw-r--r--etc/gpredict.profile19
-rw-r--r--etc/palemoon.profile24
-rw-r--r--etc/rhythmbox.profile6
-rw-r--r--etc/spotify.profile5
-rw-r--r--etc/stellarium.profile23
-rw-r--r--etc/warzone2100.profile11
-rw-r--r--etc/xplayer.profile5
-rw-r--r--etc/xviewer.profile11
11 files changed, 89 insertions, 52 deletions
diff --git a/etc/audacity.profile b/etc/audacity.profile
index 8971ce1a2..162201cb8 100644
--- a/etc/audacity.profile
+++ b/etc/audacity.profile
@@ -7,10 +7,13 @@ include /etc/firejail/disable-passwdmgr.inc
7include /etc/firejail/disable-programs.inc 7include /etc/firejail/disable-programs.inc
8 8
9caps.drop all 9caps.drop all
10netfilter
11nonewprivs 10nonewprivs
12noroot
13nogroups 11nogroups
14#private-bin audacity 12noroot
15protocol unix,inet,inet6 13protocol unix
16seccomp 14seccomp
15shell none
16tracelog
17
18private-bin audacity
19private-dev
diff --git a/etc/aweather.profile b/etc/aweather.profile
index dd508e736..d617fb701 100644
--- a/etc/aweather.profile
+++ b/etc/aweather.profile
@@ -1,24 +1,25 @@
1# Firejail profile for aweather. 1# Firejail profile for aweather.
2
3# Noblacklist
4noblacklist ~/.config/aweather 2noblacklist ~/.config/aweather
5
6# Include
7include /etc/firejail/disable-common.inc 3include /etc/firejail/disable-common.inc
8include /etc/firejail/disable-devel.inc 4include /etc/firejail/disable-devel.inc
9include /etc/firejail/disable-passwdmgr.inc 5include /etc/firejail/disable-passwdmgr.inc
10include /etc/firejail/disable-programs.inc 6include /etc/firejail/disable-programs.inc
11 7
12# Call these options 8# Whitelist
9mkdir ~/.config
10mkdir ~/.config/aweather
11whitelist ~/.config/aweather
12
13caps.drop all 13caps.drop all
14netfilter 14netfilter
15nonewprivs 15nonewprivs
16nogroups
16noroot 17noroot
18nosound
17protocol unix,inet,inet6,netlink 19protocol unix,inet,inet6,netlink
18seccomp 20seccomp
21shell none
19tracelog 22tracelog
20 23
21# Whitelist 24private-bin aweather
22mkdir ~/.config 25private-dev
23mkdir ~/.config/aweather
24whitelist ~/.config/aweather
diff --git a/etc/gitter.profile b/etc/gitter.profile
index 0c2bd1353..2882c59a6 100644
--- a/etc/gitter.profile
+++ b/etc/gitter.profile
@@ -1,6 +1,5 @@
1# Firejail profile for Gitter 1# Firejail profile for Gitter
2noblacklist ~/.config/Gitter 2noblacklist ~/.config/Gitter
3
4include /etc/firejail/disable-common.inc 3include /etc/firejail/disable-common.inc
5include /etc/firejail/disable-passwdmgr.inc 4include /etc/firejail/disable-passwdmgr.inc
6include /etc/firejail/disable-programs.inc 5include /etc/firejail/disable-programs.inc
@@ -8,6 +7,12 @@ include /etc/firejail/disable-devel.inc
8 7
9caps.drop all 8caps.drop all
10netfilter 9netfilter
10nonewprivs
11nogroups
11noroot 12noroot
12protocol unix,inet,inet6,netlink 13protocol unix,inet,inet6,netlink
13seccomp 14seccomp
15shell none
16
17private-bin gitter
18private-dev
diff --git a/etc/gpredict.profile b/etc/gpredict.profile
index ba9fce37b..02bb4d24d 100644
--- a/etc/gpredict.profile
+++ b/etc/gpredict.profile
@@ -1,24 +1,25 @@
1# Firejail profile for gpredict. 1# Firejail profile for gpredict.
2
3# Noblacklist
4noblacklist ~/.config/Gpredict 2noblacklist ~/.config/Gpredict
5
6# Include
7include /etc/firejail/disable-common.inc 3include /etc/firejail/disable-common.inc
8include /etc/firejail/disable-devel.inc 4include /etc/firejail/disable-devel.inc
9include /etc/firejail/disable-passwdmgr.inc 5include /etc/firejail/disable-passwdmgr.inc
10include /etc/firejail/disable-programs.inc 6include /etc/firejail/disable-programs.inc
11 7
12# Call these options 8# Whitelist
9mkdir ~/.config
10mkdir ~/.config/Gpredict
11whitelist ~/.config/Gpredict
12
13caps.drop all 13caps.drop all
14netfilter 14netfilter
15nonewprivs 15nonewprivs
16nogroups
16noroot 17noroot
18nosound
17protocol unix,inet,inet6,netlink 19protocol unix,inet,inet6,netlink
18seccomp 20seccomp
21shell none
19tracelog 22tracelog
20 23
21# Whitelist 24private-bin gpredict
22mkdir ~/.config 25private-dev
23mkdir ~/.config/Gpredict
24whitelist ~/.config/Gpredict
diff --git a/etc/palemoon.profile b/etc/palemoon.profile
index a74954ddb..302c20d7d 100644
--- a/etc/palemoon.profile
+++ b/etc/palemoon.profile
@@ -1,31 +1,30 @@
1# Firejail profile for Pale Moon 1# Firejail profile for Pale Moon
2
3# Noblacklists
4noblacklist ~/.moonchild productions/pale moon 2noblacklist ~/.moonchild productions/pale moon
5noblacklist ~/.cache/moonchild productions/pale moon 3noblacklist ~/.cache/moonchild productions/pale moon
6
7# Included profiles
8include /etc/firejail/disable-common.inc 4include /etc/firejail/disable-common.inc
9include /etc/firejail/disable-programs.inc 5include /etc/firejail/disable-programs.inc
10include /etc/firejail/disable-devel.inc 6include /etc/firejail/disable-devel.inc
11include /etc/firejail/whitelist-common.inc 7include /etc/firejail/whitelist-common.inc
12 8
13# Options 9whitelist ${DOWNLOADS}
10mkdir ~/.moonchild productions
11whitelist ~/.moonchild productions
12mkdir ~/.cache
13mkdir ~/.cache/moonchild productions
14mkdir ~/.cache/moonchild productions/pale moon
15whitelist ~/.cache/moonchild productions/pale moon
16
14caps.drop all 17caps.drop all
15netfilter 18netfilter
19nogroups
16nonewprivs 20nonewprivs
17noroot 21noroot
18protocol unix,inet,inet6,netlink 22protocol unix,inet,inet6,netlink
19seccomp 23seccomp
24shell none
20tracelog 25tracelog
21 26
22whitelist ${DOWNLOADS} 27private-bin palemoon
23mkdir ~/.moonchild productions
24whitelist ~/.moonchild productions
25mkdir ~/.cache
26mkdir ~/.cache/moonchild productions
27mkdir ~/.cache/moonchild productions/pale moon
28whitelist ~/.cache/moonchild productions/pale moon
29 28
30# These are uncommented in the Firefox profile. If you run into trouble you may 29# These are uncommented in the Firefox profile. If you run into trouble you may
31# want to uncomment (some of) them. 30# want to uncomment (some of) them.
@@ -56,3 +55,4 @@ whitelist ~/.config/lastpass
56 55
57# experimental features 56# experimental features
58#private-etc passwd,group,hostname,hosts,localtime,nsswitch.conf,resolv.conf,gtk-2.0,pango,fonts,iceweasel,firefox,adobe,mime.types,mailcap,asound.conf,pulse 57#private-etc passwd,group,hostname,hosts,localtime,nsswitch.conf,resolv.conf,gtk-2.0,pango,fonts,iceweasel,firefox,adobe,mime.types,mailcap,asound.conf,pulse
58#private-dev (disabled for now as it will interfere with webcam use in palemoon)
diff --git a/etc/rhythmbox.profile b/etc/rhythmbox.profile
index 0782a653d..9f087ea1d 100644
--- a/etc/rhythmbox.profile
+++ b/etc/rhythmbox.profile
@@ -5,8 +5,14 @@ include /etc/firejail/disable-devel.inc
5include /etc/firejail/disable-passwdmgr.inc 5include /etc/firejail/disable-passwdmgr.inc
6 6
7caps.drop all 7caps.drop all
8nogroups
8netfilter 9netfilter
9nonewprivs 10nonewprivs
10noroot 11noroot
11protocol unix,inet,inet6 12protocol unix,inet,inet6
12seccomp 13seccomp
14shell none
15tracelog
16
17private-bin rhythmbox
18private-dev
diff --git a/etc/spotify.profile b/etc/spotify.profile
index 9ba25b818..ca575970b 100644
--- a/etc/spotify.profile
+++ b/etc/spotify.profile
@@ -24,7 +24,12 @@ include /etc/firejail/whitelist-common.inc
24 24
25caps.drop all 25caps.drop all
26netfilter 26netfilter
27nogroups
27nonewprivs 28nonewprivs
28noroot 29noroot
29protocol unix,inet,inet6,netlink 30protocol unix,inet,inet6,netlink
30seccomp 31seccomp
32shell none
33
34private-bin spotify
35private-dev
diff --git a/etc/stellarium.profile b/etc/stellarium.profile
index 148ec949d..d0c1326b3 100644
--- a/etc/stellarium.profile
+++ b/etc/stellarium.profile
@@ -1,28 +1,29 @@
1# Firejail profile for Stellarium. 1# Firejail profile for Stellarium.
2
3# Noblacklist
4noblacklist ~/.stellarium 2noblacklist ~/.stellarium
5noblacklist ~/.config/stellarium 3noblacklist ~/.config/stellarium
6
7# Include
8include /etc/firejail/disable-common.inc 4include /etc/firejail/disable-common.inc
9include /etc/firejail/disable-devel.inc 5include /etc/firejail/disable-devel.inc
10include /etc/firejail/disable-passwdmgr.inc 6include /etc/firejail/disable-passwdmgr.inc
11include /etc/firejail/disable-programs.inc 7include /etc/firejail/disable-programs.inc
12 8
13# Call these options 9# Whitelist
10mkdir ~/.stellarium
11whitelist ~/.stellarium
12mkdir ~/.config
13mkdir ~/.config/stellarium
14whitelist ~/.config/stellarium
15
14caps.drop all 16caps.drop all
15netfilter 17netfilter
18nogroups
16nonewprivs 19nonewprivs
17noroot 20noroot
21nosound
18protocol unix,inet,inet6,netlink 22protocol unix,inet,inet6,netlink
19seccomp 23seccomp
24shell none
20tracelog 25tracelog
21 26
22# Whitelist 27private-bin stellarium
23mkdir ~/.stellarium 28private-dev
24whitelist ~/.stellarium
25 29
26mkdir ~/.config
27mkdir ~/.config/stellarium
28whitelist ~/.config/stellarium
diff --git a/etc/warzone2100.profile b/etc/warzone2100.profile
index ceeaca012..ff37e2800 100644
--- a/etc/warzone2100.profile
+++ b/etc/warzone2100.profile
@@ -6,15 +6,20 @@ include /etc/firejail/disable-devel.inc
6include /etc/firejail/disable-passwdmgr.inc 6include /etc/firejail/disable-passwdmgr.inc
7include /etc/firejail/disable-programs.inc 7include /etc/firejail/disable-programs.inc
8 8
9# Whitelist
10mkdir ~/.warzone2100-3.1
11whitelist ~/.warzone2100-3.1
12
9# Call these options 13# Call these options
10caps.drop all 14caps.drop all
11netfilter 15netfilter
16nogroups
12nonewprivs 17nonewprivs
13noroot 18noroot
14protocol unix,inet,inet6,netlink 19protocol unix,inet,inet6,netlink
15seccomp 20seccomp
21shell none
16tracelog 22tracelog
17 23
18# Whitelist 24private-bin warzone2100
19mkdir ~/.warzone2100-3.1 25private-dev
20whitelist ~/.warzone2100-3.1
diff --git a/etc/xplayer.profile b/etc/xplayer.profile
index cd9cbed45..a46b2fa06 100644
--- a/etc/xplayer.profile
+++ b/etc/xplayer.profile
@@ -10,7 +10,12 @@ include /etc/firejail/disable-passwdmgr.inc
10caps.drop all 10caps.drop all
11netfilter 11netfilter
12nonewprivs 12nonewprivs
13nogroups
13noroot 14noroot
14protocol unix,inet,inet6 15protocol unix,inet,inet6
15seccomp 16seccomp
17shell none
16tracelog 18tracelog
19
20private-bin xplayer,xplayer-audio-preview,xplayer-video-thumbnailer
21private-dev
diff --git a/etc/xviewer.profile b/etc/xviewer.profile
index 51949526d..7a4ae4858 100644
--- a/etc/xviewer.profile
+++ b/etc/xviewer.profile
@@ -6,9 +6,14 @@ include /etc/firejail/disable-devel.inc
6include /etc/firejail/disable-passwdmgr.inc 6include /etc/firejail/disable-passwdmgr.inc
7 7
8caps.drop all 8caps.drop all
9netfilter
10noroot
11nonewprivs 9nonewprivs
12protocol unix,inet,inet6 10nogroups
11noroot
12nosound
13protocol unix
13seccomp 14seccomp
15shell none
14tracelog 16tracelog
17
18private-dev
19private-bin xviewer