| Commit message (Collapse) | Author | Age |
| |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
* Create allow-INTERPETER.inc
* allow-lua.inc
* allow-perl.inc
* allow-python2.inc
* allow-python3.inc
* Create allow-java.inc
* Update profiles to use new allow-INTERPRETER.inc includes
* Update profiles to use new allow-INTERPRETER.inc includes 2/x
* Fix order of allow-INTERPRETER.inc includes
* Update profiles to use new allow-INTERPRETER.inc includes 3/x
* Fixup comment about allow-java.inc
https://github.com/netblue30/firejail/pull/2736#discussion_r289597997
* Add Arch Linux specific paths to allow-perl.inc
|
|
|
| |
Everything in Notes is now in profile.template (#2735)
|
| |
|
|\
| |
| | |
Fix typo in template
|
| | |
|
|\ \
| |/
|/| |
Whitespace fix
|
| | |
|
| |
| |
| |
| | |
* private-bin and ipc-namespace break starting app in Ubuntu 18.04 LTS for me
* no3d causes warning about unable to access mesa (this is typical for QT apps)
|
| |
| |
| | |
... is needed by old versions
|
| | |
|
| |
| |
| |
| |
| |
| |
| |
| | |
Create etc/templates
* profile.template
* redirect_alias-profile.template
* syscalls.txt
* Notes
|
| | |
|
| | |
|
| | |
|
| | |
|
| | |
|
| | |
|
| |
| |
| |
| |
| |
| |
| |
| | |
* Harden gnome-chess
* Update gnome-chess.profile
remove whitelisting
|
| | |
|
| |
| |
| |
| |
| |
| | |
* Re-add 'shell none' to gpg.profile
* Update seahorse.profile
|
| | |
|
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| | |
* Create eo-common.profile
* Refactor eog.profile
* Refactor eom.profile
* Keep private-bin in eog.profile
* Keep private-bin in eom.profile
* Place private-bin back in eog/eom profiles
|
| |
| |
| |
| | |
same fixes as in 091e12a for eog
|
| | |
|
| | |
|
| | |
|
| | |
|
| | |
|
| |
| |
| | |
Missed the fact that for dynamic playlists perl is needed. Deactivating apparmor is also necessary for this.
|
| | |
|
| |
| |
| | |
The private-etc entries were added by firejail --build but are not complete.
|
| | |
|
|/
|
| |
Adding `keepassxc-proxy` to `private-bin`as without it there is a related error message in Settings->Browser Integration (via the Keepassxc-Browser add-on).
|
|
|
|
|
|
| |
Since Mumble 1.3, client data was moved from
$HOME/.local/share/data/Mumble to $HOME/.local/share/Mumble.
See https://wiki.mumble.info/wiki/Client_Settings
|
| |
|
| |
|
| |
|
|
|
|
|
|
|
|
|
|
| |
* Add bitwarden to firecfg
* Add support for bitwarden in disable-programs.inc
* Create bitwarden.profile
* Fix whitelisting and no3d in bitwarden
|
|
|
|
|
|
|
|
|
|
| |
* Refactor enpass profile
Upstream enpass version 6 needs profile adjustments. These are integrated into the refactored profile without dropping support for older versions.
* Support newer Enpass in disable-programs.inc
* Re-add no3d and move whitelist lines in enpass.profile
|
|
|
|
|
|
|
|
|
|
| |
* Fix comments in eom.profile
* Fix comments in eog.profile
* Fix comments in gnome-system-log.profile
* Fix comments in gnome-logs.profile
|
|
|
| |
typo
|
| |
|
|
|
|
|
| |
This reverts commit 0d42e12f11825f84d6bf6f9c667cd16272a3700c, reversing
changes made to 63efb454a4af0ee5d4905f7cfae193138aef3e15.
|
|\ |
|
| |
| |
| |
| |
| | |
and noblacklist they in all profiles with
noblacklist .gitconfig
|
|/
|
|
|
| |
and noblacklist they in all profiles with
noblacklist .gitconfig
|
| |
|
|
|
| |
Commit https://github.com/netblue30/firejail/commit/7fe1da929cb0a4391970ca40e64a6462e7b460ab made whole /var empty in sandbox which accidentally fixed issue even if it worked differently than its description. This commit fixes the issue in similar way but makes clear the way it's done. It also prevents potential regressions by allowing access to some common dirs under /var.
|
|
|
|
| |
Gajim will not start without being able to read this file, even if it
doesn't exist.
|