aboutsummaryrefslogtreecommitdiffstats
Commit message (Collapse)AuthorAge
...
* | Add barrier profile (#3115)Libravatar Adrian L. Shaw2020-01-04
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | * Add barrier.profile * Add newline before special options * Modify description * Add disable mount to barrier.profile * Address feedback from rusty-snake * Remove stray carriage return * Add noexec for /home/user and /tmp * Don't blacklist openssl * Remove redundant rules
* | Gentoo fixes (#3120)Libravatar glitsj162020-01-04
| | | | | | | | | | | | | | | | * fix private-etc on gentoo * Fix private-etc on gentoo * Fix evince on gentoo
* | update pavucontrolLibravatar rusty-snake2020-01-03
| | | | | | | | see #3112
* | ${HOME} whitelisting breaks settings in arthaLibravatar glitsj162020-01-03
| | | | | | More background info in #3112.
* | typo (wget) & fix (baobab) [skip ci]Libravatar rusty-snake2020-01-03
| |
* | fix #3110Libravatar rusty-snake2020-01-03
| |
* | Get rid of #2302 (#3111)Libravatar rusty-snake2020-01-03
| |
* | fixup! Extra hardening for wgetLibravatar rusty-snake2020-01-03
| |
* | Update READMELibravatar glitsj162020-01-03
| |
* | Fix wusc in mpv (#3108)Libravatar Daniel M. Capella2020-01-03
| | | | | | Partly fixes #3107.
* | Fix wusc in exiftoolLibravatar glitsj162020-01-03
| | | | | | Arch puts files under /usr/share/perl-image-exiftool, whitelist that path for wusc.
* | Fix wusc in weechatLibravatar glitsj162020-01-03
| | | | | | Partly fixes #3107 (the weechat part).
* | Add artha log to disable-programs.incLibravatar glitsj162020-01-02
| |
* | Fix arthaLibravatar glitsj162020-01-02
| | | | | | I intentionally wanted to have this as a 'whitelist' profile. The only snag is that artha seems to generate ${HOME}/.config/artha.config.XXXXXX that I cannot whitelist upfront. Added notes to highlight this behaviour.
* | Extra hardening for wgetLibravatar glitsj162020-01-02
| |
* | Additional hardening for whoisLibravatar glitsj162020-01-02
| |
* | Harden artha.profileLibravatar glitsj162020-01-02
| |
* | Harden aria2c.profileLibravatar glitsj162020-01-02
| |
* | Future-proof private-lib in gedit.profileLibravatar glitsj162020-01-02
| | | | | | Better fix for #3104 .
* | tests: drop shm from whitelist-dev test as it can contain many filesLibravatar Reiner Herrmann2020-01-02
| |
* | Fix #3105 -- add allow-ruby.incLibravatar rusty-snake2020-01-02
| |
* | tests: use pid 1, which will also exist in containersLibravatar Reiner Herrmann2020-01-02
| |
* | tests: wait until sandbox is shutdown before running next commandLibravatar Reiner Herrmann2020-01-02
| |
* | gitlab-ci: it's actually the redhat test that was failingLibravatar Reiner Herrmann2020-01-02
| |
* | fix gnome-mapsLibravatar rusty-snake2020-01-02
| |
* | fix celluloidLibravatar rusty-snake2020-01-02
| |
* | harden whois.profileLibravatar rusty-snake2020-01-02
| |
* | Harden openshotLibravatar rusty-snake2020-01-02
| |
* | gnome-builder: fix build cacheLibravatar rusty-snake2020-01-02
| |
* | Harden wget.profileLibravatar rusty-snake2020-01-02
| |
* | gitlab-ci: disable continuously failing fedora testLibravatar Reiner Herrmann2020-01-01
| |
* | gitlab-ci: drop debian patches before building, as they might conflictLibravatar Reiner Herrmann2020-01-01
| |
* | Fix private-lib in gedit.profileLibravatar glitsj162020-01-01
| | | | | | Fixes #3104.
* | Make ${HOME}/.config/environment.d read-onlyLibravatar rusty-snake2019-12-30
| |
* | spelling fixLibravatar Reiner Herrmann2019-12-30
| |
* | include m4 directory in source archiveLibravatar Reiner Herrmann2019-12-30
|/
* Harden file-rollerLibravatar rusty-snake2019-12-29
|
* disable-devel: blacklist source-codeLibravatar rusty-snake2019-12-29
|
* Add appimage fix to electrum.profileLibravatar glitsj162019-12-29
|
* Merge pull request #3097 from glitsj16/firecfgLibravatar netblue302019-12-26
|\ | | | | Drop CLI archivers from firecfg
| * Drop CLI archivers from firecfgLibravatar glitsj162019-12-26
| | | | | | More research/testing is needed to make CLI-based archivers work on Arch (based distributions). See ongoing discussion in #3095.
* | Update private-bin in tar.profileLibravatar glitsj162019-12-26
| |
* | Add login.defs to private-etcLibravatar glitsj162019-12-26
|/
* Merge pull request #3093 from smitsohu/joinLibravatar smitsohu2019-12-25
|\ | | | | add join timeout and make it configurable
| * let is_ready_for_join() return a booleanLibravatar smitsohu2019-12-23
| |
| * simplify join timeoutLibravatar smitsohu2019-12-23
| |
| * cleanupLibravatar smitsohu2019-12-23
| |
| * make join timeout configurable in firejail.configLibravatar smitsohu2019-12-23
| |
| * let join wait if target sandbox is not ready yetLibravatar smitsohu2019-12-23
| | | | | | | | fixes #2139
| * move invalid_sandbox function to join moduleLibravatar smitsohu2019-12-22
| |