| Commit message (Collapse) | Author | Age |
|
|
|
| |
revert long-line split and fix bash-completion
|
|
|
|
|
|
| |
- remove -c, the manpage says it is ignored
- $(DESTDIR)/$(bindir)/. -> $(DESTDIR)$(bindir) and so on
- install contrib by file glob (*.py, *.sh)
- split long lines
|
|
|
|
|
| |
w3m is a text-based web browser as well as a pager like `more' or `less'. With w3m you can browse web pages through a terminal emulator window (xterm, rxvt or something like that).
As it outputs I suppose setting quiet in its profile is appropriate.
|
| |
|
|\
| |
| | |
DBus filtering enhancements
|
| | |
|
| | |
|
| |
| |
| |
| |
| |
| |
| |
| | |
D-Bus audit is now more in line with D-Bus filtering settings:
* Checks both the DBUS_SESSION_BUS_ADDRESS and DBUS_SYSTEM_BUS_ADDRESS
environment variables.
* Also checks common paths for fallback sockets in /run.
* Will report GOOD when D-Bus filtering is enabled.
|
| |
| |
| |
| |
| |
| |
| | |
--dbus-user.log and --dbus-system.log instruct xdg-dbus-proxy to log
interactions with the session and system buses, respectively.
--dbus-log= can specify the location of the log file. If no location is
specified, log output is written to stdout.
|
| |
| |
| |
| |
| | |
This allows setting per-member and per-object path policies for
xdg-dbus-proxy.
|
| |
| |
| |
| |
| |
| |
| | |
The SEE policy of xdg-dbus-proxy allows clients to see objects and bus
names, but not interact with them. The --call and --broadcast can allow
interactions with objects that have the SEE policy set. Profile support
for these proxy options will be added in a future commit.
|
| | |
|
| |
| |
| |
| |
| | |
* harden mpg123.profile
* drop nodvd from mpg123.profile
|
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| | |
* Create mocp.profile
* add mocp support to disable-programs.inc
* add mocp support in firecfg.config
* update RELNOTES for mocp
* fix configuration access for mocp
Thanks to @rusty-snake for spotting this.
|
| | |
|
| |
| |
| |
| |
| |
| |
| |
| |
| | |
* Update dino-im.profile
comment out the globals.local so it's not included twice
* Update dino-im.profile
add comment
|
| | |
|
| |
| |
| |
| |
| | |
See
87e7b313997b1d2be6553cfb22fef71b74c84ea6
|
| | |
|
| | |
|
|\ \
| | |
| | | |
Add Ubuntu's renamed version of dino
|
| | |
| | |
| | | |
Ubuntu packages dino as dino-im
|
|/ /
| |
| | |
Ubuntu named the dino instant messenger's binary ``dino-im``, so it needs to be present as profile and added to private-bin.
|
| |
| |
| | |
After https://github.com/netblue30/firejail/commit/76127399a5811a0b5ae3fffbd999bf22fba032e1 the caps workaround is no longer needed.
|
| | |
|
| |
| |
| | |
Fixes #3423.
|
| | |
|
| | |
|
| | |
|
| | |
|
| |
| |
| |
| | |
It's a collection of many tools, that might not be allowed individually.
When it's needed, it can easily be allowed again.
|
| | |
|
| | |
|
| |
| |
| |
| |
| |
| |
| |
| |
| | |
* Allow google-chrome access to the custom flags files in ~/.config.
* Added noblacklist for the custom flag files for google-chrome-stable.
* Allow read access to the custom flag files for both google-chrome-beta and google-chrome-unstable.
* Added the custom flag files for google-chrome stable, beta and unstable to the disable-programs.inc list.
|
| | |
|
| | |
|
| |
| |
| |
| |
| | |
Configure Debian package with AA and SELinux options if they are
enabled.
|
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| | |
Also fixed a typo for new profiles: nicontine --> nicotine
* add plv to firecfg
* add plv to disable-programs.inc
* Create plv.profile
* Update plv.profile
|
|\ \
| |/
|/| |
Add several games to steam and disable-programs
|
|/
|
|
|
|
|
|
|
|
|
|
| |
Add Faster Than Light, Into the Breach, Paradox Interactive, and mbwarband
to disable-programs.inc.
Also, add Faster Than Light and Into the Breach into steam.profile. This
fixes saved games being lost when steam is closed, and also lets Steam
cloud sync work properly.
Lastly, remove a duplicate whitelist ${HOME}/.steampid from
steam.profile.
|
|
|
| |
We seem to have forgotten 3 scripts from contrib. Let's add those too.
|
|
|
|
|
|
| |
Don't build all filters many times over but instead let them be built
in parallel.
Closes #3393
|
|
|
|
|
|
|
|
|
|
|
| |
* use the new dbus format in chromium-common.profile
* use new dbus format in firejail.config
Now that #3326 landed I think it might be less confusing to keep using the --nodbus wording. Couldn't come up with a better alternative (yet), so this might need future improvements.
* block dbus system bus
Blocking the system bus shouldn't affect password functionality etc, as that uses the session bus.
|
|\
| |
| | |
bug_template: more specific information
|
|/
|
|
| |
existence, lookup for installed profiles and user investigation on related problems
|
|
|
|
|
|
| |
- create vim directorys (#3396)
- fix #3400 (Eye of GNOME won't open)
- fix feedreader, it is broken without org.freedesktop.secrets access
|
| |
|
| |
|
|\
| |
| | |
Disable browser drm by default.
|
| |
| |
| |
| | |
Done to match whats stated in etc/firejail/firejail.config
|