aboutsummaryrefslogtreecommitdiffstats
Commit message (Collapse)AuthorAge
...
* Create zless.profileLibravatar glitsj162019-12-21
|
* Create zgrep.profileLibravatar glitsj162019-12-21
|
* Create zforce.profileLibravatar glitsj162019-12-21
|
* Create zfgrep.profileLibravatar glitsj162019-12-21
|
* Create zegrep.profileLibravatar glitsj162019-12-21
|
* Create zdiff.profileLibravatar glitsj162019-12-21
|
* Create zcmp.profileLibravatar glitsj162019-12-21
|
* Create zcat.profileLibravatar glitsj162019-12-21
|
* Create uncompress.profileLibravatar glitsj162019-12-21
|
* Create gzexe.profileLibravatar glitsj162019-12-21
|
* fix seahorse-toolLibravatar rusty-snake2019-12-21
| | | | | squashed: Fix private-etc ordering in seahorse-tool Thanks to @glitsj16 for this fixup
* Fix Brave's native sandbox (#3087)Libravatar glitsj162019-12-21
| | | | | | | | | | * Allow user access to /proc/config.gz * Fix Brave's native sandbox * Move /proc/config.gz to disable-common.inc * Move /proc/config.gz to disable-common.inc
* small fixLibravatar netblue302019-12-21
|
* configure script, version, relnotesLibravatar netblue302019-12-14
|
* Fix --appimage on linux 5.4.x kernelLibravatar glitsj162019-12-14
| | | Fixes #3068.
* wine: enable allow-debuggers by default - #446Libravatar smitsohu2019-12-11
|
* little thingsLibravatar smitsohu2019-12-11
|
* gpg additions (#3077)Libravatar glitsj162019-12-10
| | | | | | | | * Add 'quiet' to gpg.profile * Add 'quiet' to gpg-agent.profile * Create gpg2.profile
* tentative fix for #3075Libravatar netblue302019-12-08
|
* Fix DeVeDe-NG exportLibravatar rusty-snake2019-12-06
| | | | It is better to comment wusc in ffmpeg?
* fix braseroLibravatar rusty-snake2019-12-06
|
* mainline moving to 0.9.63 for new development; release 0.9.62 is handled on ↵Libravatar netblue302019-12-06
| | | | release-0.9.62 branch
* mergesLibravatar smitsohu2019-12-03
|
* Merge pull request #3065 from the-antz/profile-thunderbird-waylandLibravatar smitsohu2019-12-03
|\ | | | | Minor profile tweaks.
| * Minor profile tweaks.Libravatar Antz2019-11-26
| | | | | | | | thunderbird-wayland profile did not include thunderbird-wayland.local
* | cleanupLibravatar smitsohu2019-12-03
| |
* | fix stack alignmentLibravatar smitsohu2019-11-30
| | | | | | | | apparently on x86 and on other platforms like aarch64 a 16 byte aligned stack is expected todo: replace this with a generic check
* | libreoffice aliasenLibravatar rusty-snake2019-11-28
| |
* | add private-tmp debug messageLibravatar smitsohu2019-11-28
| |
* | mask more private options runtime directories, just to be sureLibravatar smitsohu2019-11-28
| |
* | fix interaction between private options and allusers optionLibravatar smitsohu2019-11-28
| |
* | Fix profile: ffmpeg (#3064)Libravatar the-antz2019-11-27
|/ | | Fix broken libx265 encoding (needs the set_mempolicy syscall).
* blacklist /tmp/.X11-unix in gist.profileLibravatar glitsj162019-11-25
| | | Thanks to @rusty-snake for requesting this in https://github.com/netblue30/firejail/pull/3061.
* Update README.mdLibravatar glitsj162019-11-25
|
* Update RELNOTESLibravatar glitsj162019-11-25
|
* Add gist-paste to firecfg.configLibravatar glitsj162019-11-25
|
* Add redirect profile for gist-paste (#3062)Libravatar glitsj162019-11-25
|
* Add new profile: gist (#3061)Libravatar glitsj162019-11-25
| | | | | | | | | | | | * Create gist.profile * Add gist config to disable-programs.inc * Add gist to firecfg.config * Update RELNOTES * Update README.md
* blacklist gksu, gksudo, kdesudoLibravatar rusty-snake2019-11-25
|
* various fixupsLibravatar rusty-snake2019-11-25
|
* apparmor: misc fix for pcscdLibravatar Vincent432019-11-24
|
* apparmor: don't allow mounts and paths manipulationLibravatar Vincent432019-11-24
| | | | | | | | | | | | | AppArmor security relies on path based rules and rewriting paths may allow to bypass them. Those actions are priveliged so vast majority of apps shouldn't need them anyway. If some app need those rules then it's better to consider them as unsuitable for apparmor option rather than weaken generic profile for all apps. See related issue reported by apparmor usage in snap: https://bugs.launchpad.net/snapd/+bug/1791711
* apparmor: allow access to pcscd socket (smartcards)Libravatar Vincent432019-11-24
|
* Add new profile: unf (#3060)Libravatar glitsj162019-11-24
| | | | | | * Create unf.profile * Add unf to firecfg.config
* Add new profile: gmpc (#3059)Libravatar glitsj162019-11-24
| | | | | | | | * Create gmpc.profile * Add gmpc config to disable-programs.inc * Add gmpc to firecfg.config
* Add new profile: drawio (#3058)Libravatar glitsj162019-11-24
| | | | | | | | * Create drawio.profile * Add drawio config to disable-programs.inc * Add drawio to firecfg.config
* Add new profile: ddgtk (#3057)Libravatar glitsj162019-11-24
| | | | | | * Create ddgtk.profile * Add ddgtk to firecfg.config
* Add new profile: cameramonitor (#3056)Libravatar glitsj162019-11-24
| | | | | | * Create cameramonitor.profile * Add cameramonitor to firecfg.config
* New profile: audio-recorder (#3055)Libravatar glitsj162019-11-24
| | | | | | * Create audio-recorder.profile * Add audio-recorder to firecfg.config
* mergesLibravatar Tad2019-11-24
|