| Commit message (Collapse) | Author | Age |
|
|
|
|
| |
Signal is adding support for video calls on desktop, see
https://signal.org/blog/desktop-calling-beta/
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
* Use whitelisting for video players
See https://github.com/netblue30/firejail/pull/3469
* Update media player whitelists
See reviews at https://github.com/netblue30/firejail/pull/3472
Block $DOCUMENTS
Make $DESKTOP read-only
* Review fixes: include read-only Desktop in whitelist
|
|\
| |
| | |
Fix nomacs
|
| |
| |
| |
| |
| |
| |
| |
| |
| |
| | |
```
Aug 11 16:32:32 korte audit[29004]: SECCOMP auid=1000 uid=1000 gid=1000
ses=2 subj==firejail-default (enforce) pid=29004 comm="nomacs"
exe="/usr/bin/nomacs" sig=31 arch=c000003e syscall=9 compat=0
ip=0x7fa2a1cc98c6 code=0x0
```
|
|/
|
|
|
| |
Initial,amend: wrong dir,delete gtk-*,added new files
Co-authored-by: kortewegdevries <k0rtic_dv@aol.com>
|
|
|
|
|
|
|
| |
* Add profile for otter-browser
Initial
* private-bin,sorting
|
| |
|
| |
|
| |
|
|
|
|
|
|
|
|
|
| |
* Added minitube profile
Initial
* Second
Removed no3d,added novideo
|
|
|
| |
Initial
|
|
|
|
|
|
|
|
|
| |
* Added mtpaint profile
Initial
* Second
Remove IPC-namespace,netfilter
|
|
|
| |
Fixes for #3554.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
* Added minecraft-launcher-profile
Initial
* Changed minecraft-launcher profile
Added space,tracelog,nodvd
* Third
Fixed private-etc,added notes about path,java
* Sorting
|
| |
|
|\
| |
| | |
Added xfce4-screenshooter profile
|
| |
| |
| |
| | |
Initial,removed common blaclist,add netfilter,private-etc
|
|/ |
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
* Update virtualbox.profile
* Update virtualbox.profile
* Update virtualbox.profile
* Update virtualbox.profile
* Update virtualbox.profile
* Update virtualbox.profile
|
|\
| |
| | |
Hardend Zoom profile
|
| | |
|
|\ \
| | |
| | | |
Add Mattermost desktop profile
|
| |/ |
|
| |
| |
| |
| |
| |
| |
| | |
* Update telegram.profile
* Update telegram.profile
* Update telegram.profile
|
| |
| |
| |
| |
| | |
* fix #3404
* Update teams.profile
|
|/ |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
use it. (#3493)
* blacklist .local/share/kxmlgui5
KDE programs use this to store their toolbar config.
* noblacklist .local/share/kxmlgui5 in the relevant KDE applications.
* Whitelist kxmlgui file for okular.
* Use a glob to blacklist subfolders instead of the parent folder.
noblacklisting individual subdirectories works only if we do it this way
(tested by launching bash in the kate profile).
* Make directory, not file.
* noblacklist relevant subdirs for more KDE applications
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
* hardening some profiles
- harden and fix flameshot
- wruc: frogatto, ghostwriter
- harden gnome-latex
- add whitelist opt-in note to keepassxc
- add comment to minetest
- harden openarena, tremulous, xonotic
- add profile for xonotic-sdl-wrapper
* followup
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
* Whitelist some config files used by Okular.
These files are used to store the toolbar configurations.
* Whitelist files required for okular in firefox-common-addons.inc
Without this, okular does not follow the user configuration for toolbars
and keyboard shortcuts when launched inside the firefox sandbox (for
eg., while opening a downloaded PDF).
* Alphabetical sort
* Remove noblacklist for files which are not actually blacklisted.
I have blacklisted them in a separate pull request.
|
|
|
| |
hplip is required for scanning using HP printer/scanners.
|
| |
|
|
|
| |
This should clarify how to configure for reading local mail after https://github.com/netblue30/firejail/commit/dfaf7a7660689c055ba45a935e42b1b548669c57.
|
| |
|
| |
|
|
|
|
|
|
|
|
|
| |
* fix comment in email-common
* add writable-var to evolution.profile
* add writable-var to mutt.profile
* remove newline above writable-var in evolution.profile
|
| |
|
| |
|
|
|
| |
Totem saves screenshots of video to ${PICTURES}. Also adding tracelog to slightly harden things a bit.
|
| |
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
* Add strawberry profile
* Fix comment
* Add to disable-programs.inc & firecfg.config
* Add /home/amin/.local/share/strawberry to profile and disable-programs
* Various hardening for strawberry profile
Signed-off-by: Amin Vakil <info@aminvakil.com>
* Change nodbus to dbus-system none in strawberry profile
* Add dbus-user none to strawberry profile
* Add whitelist-var-common, sort private-etc
* Sort, Add wruc, Add netlink to protocol in strawberry profile
* Remove dbus-user none to allow using gnome functions for various usage in strawberry profile
|
|
|
| |
See https://github.com/netblue30/firejail/issues/3219#issuecomment-638823377
|
|
|
|
|
|
|
|
|
|
|
|
| |
* disable-shell.inc
* add disable-shell.inc to all profiles with a …
… private-bin line without bash/sh except profiles with redirect
profiles.
* add it to some more profiles
* exclude aria2c.profile
|
|
|
|
|
| |
w3m is a text-based web browser as well as a pager like `more' or `less'. With w3m you can browse web pages through a terminal emulator window (xterm, rxvt or something like that).
As it outputs I suppose setting quiet in its profile is appropriate.
|
| |
|
|
|
|
|
| |
* harden mpg123.profile
* drop nodvd from mpg123.profile
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
* Create mocp.profile
* add mocp support to disable-programs.inc
* add mocp support in firecfg.config
* update RELNOTES for mocp
* fix configuration access for mocp
Thanks to @rusty-snake for spotting this.
|
|
|
| |
After https://github.com/netblue30/firejail/commit/76127399a5811a0b5ae3fffbd999bf22fba032e1 the caps workaround is no longer needed.
|