| Commit message (Collapse) | Author | Age |
|
|
|
|
| |
* Add profile for straw-viewer
* Remove blacklist, fixes
|
|\
| |
| | |
from my overrides
|
| |
| |
| |
| |
| |
| |
| |
| | |
- add seccomp.block-secondary to a lot profiles
- add wruc to firefox-common and ignore it in TB and
firefox-common-addons
- harden dia, gnome-keyring, libreoffice, megaglest, pngquant,
ghostwriter, rhythmbox, sqlitebrowser
|
|/
|
|
|
| |
* add dbus comment
* disable dbus
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
- .github/ISSUE_TEMPLATE/bug_report.md: get ride off spanish,
french, ... error messages
- etc/inc/firefox-common-addons.inc: support ff2mpv
- etc/profile-a-l/gimp.profile: note about xsane
- etc/profile-m-z/min.profile: prettify
- etc/profile-m-z/mpsyt.profile: fix, add lua
- etc/profile-m-z/qbittorrent.profile: add note for tray-icons; this
will get a better note once I investigated and audited all the D-Bus
tray stuff.
- etc/profile-m-z/transmission-daemon.profile: fix, add protocol packet
close #3686 - mps-youtube needs lua
close #3701 - Firefox native messaging regression in 0.9.62.4 -> 0.9.64rc1
close #3636 - transmission-daemon fills log with error
close #3640 - Gimp - add note how to enable scanning (xsane)
close #3707 - qBittorrent tray icon missing from notification panel when running it with firejail
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
* rework chromium
+ 516d0811 has removed fundamental security features.
(remove caps.drop=all, nonewprivs, noroot, seccomp, protocol; add
caps.keep)
Though this is only necessary if running under a kernel which
disallow
unprivileged userns clones. Arch's linux-hardened and debian kernel
are
patched accordingly. Arch's linux and linux-lts kernels support this
restriction via sysctk (kernel.unprivileged_userns_clone=0) as users
opt-in.
Other kernels such as mainline or fedora/redhat always support
unprivileged
userns clone and have no sysctl parameter to disable it. Debian and
Arch
users can enable it with 'sysctl kernel.unprivileged_userns_clone=1'.
This commit adds a chromium-common-hardened.inc which can be included
in
chromium-common to enhance security of chromium-based programs.
+ chromium-common.profile: add private-cache
+ chromium-common.profile: add wruc and wusc, but disable it for the
following
profiles until tested. tests welcome.
- [ ] bnox, dnox, enox, inox, snox
- [ ] brave
- [ ] flashpeak-slimjet
- [ ] google-chrome, google-chrome-beta, google-chrome-unstable
- [ ] iridium
- [ ] min
- [ ] opera, opera-beta
+ move vivaldi-snapshot paths from vivaldi-snapshot.profile to vivaldi.
/usr/bin/vivaldi is a symlink to /etc/alternatives/vivaldi which can
be
vivaldi-stable, vivaldi-beta or vivaldi-snapshot.
vivaldi-snapshot.profile
missed also some features from vivaldi.profile, solve this by making
it
redirect to vivaldi.profile. TODO: exist new paths such as
.local/lib/vivaldi
also for vivaldi-snapshot?
+ create chromium-browser-privacy.profile (closes #3633)
* update 1
+ add missing 'ignore whitelist /usr/share/chromium'
+ revert 'Move drm-relaktions in vivaldi.profile behind
BROWSER_ALLOW_DRM.'. This breaks not just DRM, it break things such
as AAC too. In addition vivaldi shows a something is broken pop-up,
we would have a lot of 'does not work with firejail' issues.
* update 2
* update 3
fixes #3709
|
|
|
|
| |
linphone 4.0 changed the location of config and database files
to respect freedesktop standards.
|
|
|
|
|
|
|
|
| |
- update README.md and RELNOTES
- add 'blacklist ${RUNUSER}/.flatpak-cache' to disable-common.inc
- fix #3728, fonts in openSUSE KDE with wc / wusc
- fix gnome-todo
- fix xournalpp MathTeX whitelist
|
|
|
| |
This fixes #3722.
|
| |
|
| |
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
* remove read-only item redundancy
'read-only ${HOME}/.config/mimeapps.list' is already part of disable-common.inc
* remove read-only item redundancy
'read-only ${HOME}/.config/mimeapps.list' is already part of disable-common.inc, which is included in the redirect profile
* remove read-only item redundancy
'read-only ${HOME}/.config/mimeapps.list' is already part of disable-common.inc, which is included in the redirect profile
|
|
|
| |
The user mime database needs to be writable.
|
|\
| |
| | |
fix #3699 -- Firefox can't inhibit screensavers/screen blanking
|
| | |
|
| | |
|
|/
|
| |
liblua is needed for celluloid & otherwise at least on arch it's showing this error - "celluloid: error while loading shared libraries: liblua5.2.so.5.2: cannot open shared object file: Permission denied"
|
| |
|
|\
| |
| | |
Switch mails to whitelisting
|
| | |
|
| | |
|
| | |
|
| | |
|
| | |
|
| | |
|
| |
| |
| |
| | |
closes #3643
|
| | |
|
| | |
|
| | |
|
| | |
|
| | |
|
| |
| |
| |
| |
| |
| |
| |
| | |
- blacklist ~/.rustup in disable-devel.inc
- add note to mpv (See #3628)
- harden warsow
- update relnotes
- new profile qrencode, dbus-send, notify-send
|
| | |
|
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| | |
* New disable include: disable-write-mnt.inc
It is for profiles which have a reasonable mnt access (we can not add
disable-mnt), but no edit function (e.g. any kind of viewer).
Added to
- profile.template
- default.profile
- eo-common.profile
* Update default.profile
|
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| | |
* README.md & RELNOTES
* Allow gnome-build do read and write .bash_history, it has a build-in
terminal
* D-Bus filter for gnome-passwordsafe
* wruc for supertuxkart
* wruc+wusc for totem
* dbus-system none for totem
* remove src/man/preproc.c it is replaced by preproc.awk
* remove dead-code form preproc.awk
|
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| | |
* Add profile for twitch,youtube wrappers
* Fix git-cola, add Youtube music wrapper profiles
* Fixes for git-cola again
* Add profile for alternative name for git-cola
* Fixes
* Fix
|
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| | |
* Added minecraft-launcher-profile
Initial
* Changed minecraft-launcher profile
Added space,tracelog,nodvd
* New profiles for balsa,trojita,kube
* Switch to whitelisting
* Enable gpg,firefox uniformity between other clients
* Hyperlinks
* Fix
Co-authored-by: kortewegdevries <k0rtic_dv@aol.com>
|
| | |
|
| |
| |
| |
| |
| |
| |
| |
| |
| | |
* Fix private-etc of electron-mail
* Fix dbus of geary
* Fix geary again, remove GPG
* Fix seccomp on Arch
|
| |
| |
| |
| |
| |
| |
| |
| |
| | |
* Matrix clients
Initial
* Add profile for fractal, # 1139
* Fixes
|
|/
|
|
|
|
|
|
|
| |
* Various profiles
Initial
* Various fixes # 1
Removed blacklist,no3d; added icon flatpak paths;sorting;added space
|
|
|
|
|
|
|
| |
This commit removes it from profile which have it.
/usr/share/perl* is still inaccessible for profiles with wusc and
disable-interpreters.inc w/o allow-perl.inc.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
* Use whitelisting for video players
See https://github.com/netblue30/firejail/pull/3469
* Update media player whitelists
See reviews at https://github.com/netblue30/firejail/pull/3472
Block $DOCUMENTS
Make $DESKTOP read-only
* Review fixes: include read-only Desktop in whitelist
|
|
|
|
|
| |
Initial,amend: wrong dir,delete gtk-*,added new files
Co-authored-by: kortewegdevries <k0rtic_dv@aol.com>
|
|
|
|
|
|
|
|
|
|
|
| |
* Added git-cola profile
Initial
* Edit private-etc
Add alternatives,pki
* Add disable-xdg
|
| |
|
|
|
|
|
|
|
|
|
| |
* Added lyx profile
Initial
* Rmoved whitelists
Make home directory more accessible
|
| |
|
|
|
|
| |
Add chroot
|