| Commit message (Collapse) | Author | Age |
| |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
* Add strawberry profile
* Fix comment
* Add to disable-programs.inc & firecfg.config
* Add /home/amin/.local/share/strawberry to profile and disable-programs
* Various hardening for strawberry profile
Signed-off-by: Amin Vakil <info@aminvakil.com>
* Change nodbus to dbus-system none in strawberry profile
* Add dbus-user none to strawberry profile
* Add whitelist-var-common, sort private-etc
* Sort, Add wruc, Add netlink to protocol in strawberry profile
* Remove dbus-user none to allow using gnome functions for various usage in strawberry profile
|
|
|
| |
Applications using Qt5 need this to be whitelisted if the user is using a qt5ct colour scheme (such as "darker") or custom QSS.
|
|
|
|
| |
solves #3454
|
|
|
| |
See https://github.com/netblue30/firejail/issues/3219#issuecomment-638823377
|
|
|
|
|
|
|
|
|
|
|
|
| |
* disable-shell.inc
* add disable-shell.inc to all profiles with a …
… private-bin line without bash/sh except profiles with redirect
profiles.
* add it to some more profiles
* exclude aria2c.profile
|
|
|
|
|
| |
w3m is a text-based web browser as well as a pager like `more' or `less'. With w3m you can browse web pages through a terminal emulator window (xterm, rxvt or something like that).
As it outputs I suppose setting quiet in its profile is appropriate.
|
| |
|
| |
|
|
|
|
|
| |
* harden mpg123.profile
* drop nodvd from mpg123.profile
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
* Create mocp.profile
* add mocp support to disable-programs.inc
* add mocp support in firecfg.config
* update RELNOTES for mocp
* fix configuration access for mocp
Thanks to @rusty-snake for spotting this.
|
| |
|
|
|
|
|
|
|
|
|
| |
* Update dino-im.profile
comment out the globals.local so it's not included twice
* Update dino-im.profile
add comment
|
|
|
| |
Ubuntu named the dino instant messenger's binary ``dino-im``, so it needs to be present as profile and added to private-bin.
|
|
|
| |
After https://github.com/netblue30/firejail/commit/76127399a5811a0b5ae3fffbd999bf22fba032e1 the caps workaround is no longer needed.
|
|
|
| |
Fixes #3423.
|
| |
|
|
|
|
| |
It's a collection of many tools, that might not be allowed individually.
When it's needed, it can easily be allowed again.
|
| |
|
|
|
|
|
|
|
|
|
| |
* Allow google-chrome access to the custom flags files in ~/.config.
* Added noblacklist for the custom flag files for google-chrome-stable.
* Allow read access to the custom flag files for both google-chrome-beta and google-chrome-unstable.
* Added the custom flag files for google-chrome stable, beta and unstable to the disable-programs.inc list.
|
| |
|
| |
|
|
|
|
|
|
|
|
|
|
|
| |
Also fixed a typo for new profiles: nicontine --> nicotine
* add plv to firecfg
* add plv to disable-programs.inc
* Create plv.profile
* Update plv.profile
|
|
|
|
|
|
|
|
|
|
|
|
| |
Add Faster Than Light, Into the Breach, Paradox Interactive, and mbwarband
to disable-programs.inc.
Also, add Faster Than Light and Into the Breach into steam.profile. This
fixes saved games being lost when steam is closed, and also lets Steam
cloud sync work properly.
Lastly, remove a duplicate whitelist ${HOME}/.steampid from
steam.profile.
|
|
|
|
|
|
|
|
|
|
|
| |
* use the new dbus format in chromium-common.profile
* use new dbus format in firejail.config
Now that #3326 landed I think it might be less confusing to keep using the --nodbus wording. Couldn't come up with a better alternative (yet), so this might need future improvements.
* block dbus system bus
Blocking the system bus shouldn't affect password functionality etc, as that uses the session bus.
|
|
|
|
|
|
| |
- create vim directorys (#3396)
- fix #3400 (Eye of GNOME won't open)
- fix feedreader, it is broken without org.freedesktop.secrets access
|
| |
|
|
|
|
|
|
|
| |
* dbus filter (1)
* dbus-filter: firefox
* drop org.gtk.vfs and com.canonical.AppMenu.Registrar
|
| |
|
|
|
| |
Preliminary fixes tested/confirmed on Arch regarding #3389 (in-progress).
|
|
|
| |
Fix for #3385.
|
| |
|
| |
|
| |
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
* refactor caja.profile
* refactor dolphin.profile
* Create file-manager-common.profile
* refactor nautilus.profile
* refactor nemo.profile
* refactor pcmanfm.profile
* refactor ranger.profile
* refactor Thunar.profile
|
| |
|
| |
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
* Profile for Jitsi Meet desktop app (electron)
* Update description.
* Correctly include global definitions.
* Add jitsi-meet-desktop to firecfg.
* blacklist Jitsi-meet config directory in disable-programs.inc
* Disable more things.
disable-exec.inc not included, as the application shows some error if I
include it.
* Disable more stuff.
* No need to whitelist Downloads directory.
I don't think this application has any file sharing / downloading
feature.
* Use private-bin
I needed to allow the bash executable as well for this to work.
* Add some whitelist rules.
* Use private-cache option
* include disable-exec.inc
Apparently one needs to allow execution in /tmp for the program to work.
* Redirect to electron.profile.
* Use private-etc.
* Do not whitelist Downloads directory.
electron.profile does this, but I do not think this program needs it.
* Rearrange whitelisted files to alphabetical order.
* Move nonwhitelist to appropriate section.
* Newlines as section separators.
|
|
|
| |
Fixes #3363.
|
|\
| |
| | |
Add new profile: nicotine
|
| | |
|
| | |
|
| |
| |
| |
| |
| | |
https://github.com/netblue30/firejail/commit/ca6eec7dcf388c3d0bf52f54c56f7c957b8b777b
As per discussion in #3333, thanks to @rusty-snake for coming up with an alternative.
|
| |
| |
| |
| | |
…g.config (#3333).
|
|/
|
|
|
|
| |
- Makefile.in: loops are slow
- Makefile.in: firecfg.config wasn't installed
- allow-gjs.inc: gjs uses libmozjs, forgotten to commit
|
|
|
| |
This fixes #3333.
|
|
|
|
|
|
|
|
|
|
|
| |
- disable-interpreters: blacklist /usr/lib64/libmozjs-*
- fdns:
- fix .local name
- remove server.profile comment (do we need /sbin and /usr/sbin?)
- add wusc and wvc (commented because untested)
- minimize caps.keep (based on fdns.service)
- fix protocol position
- add private-etc (based on fdns.service)
|
| |
|