Commit message (Collapse) | Author | Age | |
---|---|---|---|
* | add private-tmp to unbound profile | smitsohu | 2019-10-01 |
| | |||
* | Update evince | rusty-snake | 2019-09-28 |
| | | | | | | | private-lib: - Add note about possible two-page-view breaktage - add libgraphite2.so.* remove mdwe | ||
* | fixup! add missing blacklist paths | rusty-snake | 2019-09-28 |
| | |||
* | Fix sorting (caught by GitLab CI tests) | Fred Barclay | 2019-09-28 |
| | |||
* | fix ffprobe | rusty-snake | 2019-09-28 |
| | | | | | | | | | | | $ firejail ffprobe VIDEO execvp: No such file or directory $ firejail --noprofile --private-bin=ffprobe ffprobe VIDEO execvp: No such file or directory $ firejail --ignore=private-bin ffprobe VIDEO Works ffprobe is the only file in PATH that is touched (see --build). | ||
* | add missing blacklist paths | rusty-snake | 2019-09-28 |
| | |||
* | KeePassXC: Added a warning regarding tray icon | Timo Hardebusch | 2019-09-28 |
| | |||
* | profiles: fix audio playback with ffplay | Reiner Herrmann | 2019-09-28 |
| | | | | https://bugs.debian.org/941241 | ||
* | protect files that can execute commands | rusty-snake | 2019-09-22 |
| | |||
* | Inkscape: allow xcf export | rusty-snake | 2019-09-22 |
| | | | close #2967 | ||
* | add allow-debuggers to steam.profile (#2971) | corecontingency | 2019-09-21 |
| | |||
* | readd .config/dconf to whitelist-common because … | rusty-snake | 2019-09-21 |
| | | | | … it breaks feedreader and potential also other programs | ||
* | Create pngquant.profile | rusty-snake | 2019-09-21 |
| | |||
* | Create gnome-latex.profile | rusty-snake | 2019-09-20 |
| | |||
* | apparmor: permit writing to trace file | smitsohu | 2019-09-18 |
| | |||
* | Add allow-perl.inc to w3m.profile (#2965) | Ethan R | 2019-09-16 |
| | | | | | | * Removed disable-interpreters.inc from w3m.profile * disable-interpreters + allow-perl | ||
* | Fix #2899 | rusty-snake | 2019-09-15 |
| | |||
* | typos [skip ci] | rusty-snake | 2019-09-14 |
| | |||
* | "Net None" Option Breaks Functionality (#2962) | Barış Ekin Yıldırım | 2019-09-14 |
| | | | Netfilter is fine but "net none" option breaks functionality of marketplace. | ||
* | Fix #2945 (Signal 1.27 Fails to Start) | rusty-snake | 2019-09-13 |
| | |||
* | Update SkypeForLinux profile for latest version (#2960) | Denys Havrysh | 2019-09-13 |
| | | | Fixes #2933 | ||
* | Add ar profile (#2949) | glitsj16 | 2019-09-08 |
| | | | | | | * Add ar to firecfg * Create ar.profile | ||
* | Fix private-bin in tar.profile | glitsj16 | 2019-09-06 |
| | | | Fixes #2942. | ||
* | Fix gnome-schedule | glitsj16 | 2019-09-06 |
| | | | This fixes #2941. | ||
* | Update syscalls.txt | rusty-snake | 2019-09-05 |
| | |||
* | remove ~/.config/dconf from whitelist-common.inc | rusty-snake | 2019-09-05 |
| | | | | | - dconf database is read-only (fde6e04b) and accessed over dbus, there are no reasons to keep it in the sandbox | ||
* | explain removal of nodbus in qpdfview.profile | smitsohu | 2019-09-05 |
| | | | see previous commit, #2879 | ||
* | Merge pull request #2879 from Edu4rdSHL/patch-1 | smitsohu | 2019-09-05 |
|\ | | | | | qpdfview: Fix issue when opening a file from file manager | ||
| * | Fix issue when opening a file from file manager | Eduard Tolosa | 2019-07-29 |
| | | | | | | I can confirm https://github.com/netblue30/firejail/pull/2837#issuecomment-511334363 when opening a file from `pcmanfm`, it doesn't open if qpdfview contains `nodbus` | ||
* | | fixup! Use new seccomp syntax from #2926 in more profiles | rusty-snake | 2019-08-30 |
| | | |||
* | | fix #2669 | rusty-snake | 2019-08-30 |
| | | |||
* | | Use new seccomp syntax (#2926) in more profiles | rusty-snake | 2019-08-30 |
| | | | | | | | | | | | | | | | | | | | | Rules for redirecting profiles: - add exceptions: just add 'seccomp !SYSCALL' - remove exception: ``` seccomp ignore seccomp ``` | ||
* | | Use new seccomp syntax from #2926 in more profiles | rusty-snake | 2019-08-30 |
| | | |||
* | | Use new seccomp syntax from #2926 | rusty-snake | 2019-08-30 |
| | | |||
* | | Fix private-bin order in ghostwriter.profile | glitsj16 | 2019-08-26 |
| | | |||
* | | Fix order of private-cache in mpsyt.profile | glitsj16 | 2019-08-26 |
| | | |||
* | | Fic private-etc ordering for gnome-schedule | glitsj16 | 2019-08-26 |
| | | |||
* | | many profile fixes (1) | rusty-snake | 2019-08-26 |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | - add novideo to a lot of profiles (there are still more profiles where novideo can be added) - remove commente mdwe from some gnome applications - add descriptions to some profiles - blacklist ${HOME}/.cargo/credentials - move ${HOME}/.git-credentials and ${HOME}/.git-credential-cache to 'top secret' in disable-common.inc - some ordering in disable-programs.inc - merge tor browser blacklists to ${HOME}/.tor-browser* - qupzilla.profile redirect to falkon.profile - blacklist gnome-builder paths - fix transmission profiles inlude - much more | ||
* | | harden strings profile | smitsohu | 2019-08-25 |
| | | |||
* | | Merge pull request #2921 from rusty-snake/allow-common-devel.inc | rusty-snake | 2019-08-22 |
|\ \ | | | | | | | Introduce allow-common-devel.inc | ||
| * | | add allow-common-devel to more profiles | rusty-snake | 2019-08-22 |
| | | | |||
| * | | Introduce allow-common-devel.inc | rusty-snake | 2019-08-22 |
| | | | |||
* | | | update syscalls.txt | rusty-snake | 2019-08-22 |
| | | | |||
* | | | various fixes and improvements | rusty-snake | 2019-08-22 |
|/ / | | | | | | | | | | | | | | | | | | | | | | | - install contrib/syscalls.sh - add GitLab-CI status to README.md - read-only ${HOME}/.cargo/env - move blacklist ${HOME}/.cargo/registry, ${HOME}/.cargo/config to disable-programs - typo in man firejail firejail-profiles firecfg - better descriptions in man firejail-profiles - fixes in man firejail - template descriptions in firejail-profiles | ||
* | | Enable private-bin in transmission-daemon | glitsj16 | 2019-08-21 |
| | | |||
* | | Enable private-bin in transmission-cli | glitsj16 | 2019-08-21 |
| | | |||
* | | Fix private-etc order in i2prouter | glitsj16 | 2019-08-21 |
| | | |||
* | | Fix teamspeak3 | glitsj16 | 2019-08-21 |
| | | | | | | Fixes #2901. | ||
* | | Merge pull request #2919 from corecontingency/master | rusty-snake | 2019-08-21 |
|\ \ | | | | | | | Profiles: add I2P | ||
| * | | Applied further suggestions from code review | core_contingency | 2019-08-21 |
| | | |