aboutsummaryrefslogtreecommitdiffstats
path: root/etc
Commit message (Collapse)AuthorAge
...
* Update disable-common.inc (#3499)Libravatar rusty-snake2020-07-09
| | | | | | | * Update disable-common.inc * Update disable-common.inc [skip ci]
* Okular profile fixes (#3489)Libravatar Kishore96in2020-07-07
| | | | | | | | | | | | | | | | | * Whitelist some config files used by Okular. These files are used to store the toolbar configurations. * Whitelist files required for okular in firefox-common-addons.inc Without this, okular does not follow the user configuration for toolbars and keyboard shortcuts when launched inside the firefox sandbox (for eg., while opening a downloaded PDF). * Alphabetical sort * Remove noblacklist for files which are not actually blacklisted. I have blacklisted them in a separate pull request.
* Fixed Blender profile being unable to import numpy (#3497)Libravatar neirenoir2020-07-06
| | | Co-authored-by: noir <noir@neire.dev>
* Whitelist /usr/share/hplip for simple-scan (#3496)Libravatar Carlo Abelli2020-07-05
| | | hplip is required for scanning using HP printer/scanners.
* typoLibravatar rusty-snake2020-07-05
|
* fix com.github.dahenson.agenda.profileLibravatar rusty-snake2020-07-05
|
* fixup! Don't blacklist file used to save konversation notifications ↵Libravatar rusty-snake2020-07-04
| | | | configuration. (#3490)
* Don't blacklist file used to save konversation notifications configuration. ↵Libravatar Kishore96in2020-07-04
| | | | | | (#3490) Without this, konversation doesn't remember the settings for notifications.
* drop private-tmp from blender.profileLibravatar glitsj162020-07-04
| | | Blender autosaves to /tmp.
* update comment for apparmor in thunderbird.profileLibravatar glitsj162020-07-04
| | | This should clarify how to configure for reading local mail after https://github.com/netblue30/firejail/commit/dfaf7a7660689c055ba45a935e42b1b548669c57.
* clarify writing to /var/mail and /var/spool/mail in apparmor (#3487)Libravatar glitsj162020-07-04
| | | | | | | * clarify writing to /var/mail and /var/spool/mail in apparmor Thunderbird seems to be our only mail client profile that enables the `apparmor` option. Users need this when they follow instructions on how to allow reading local mail. * fix mail clients rule in firejail-default
* allow running kernel config check in zgrep.profileLibravatar glitsj162020-07-03
|
* allow running kernel config check in zcat.profileLibravatar glitsj162020-07-03
|
* new profile: gapplicationLibravatar rusty-snake2020-07-03
|
* fixes for /var/mail in mail clients (#3486)Libravatar glitsj162020-07-03
| | | | | | | | | * fix comment in email-common * add writable-var to evolution.profile * add writable-var to mutt.profile * remove newline above writable-var in evolution.profile
* Fix #3481 - pandoc needs access to /etc/texmfLibravatar Fred Barclay2020-06-28
|
* akonadi: update seccomp blacklistLibravatar smitsohu2020-06-26
|
* harden gradio.profileLibravatar rusty-snake2020-06-25
|
* new profilesLibravatar rusty-snake2020-06-25
|
* fix apostropheLibravatar rusty-snake2020-06-21
|
* add ${HOME}/.config/user-dirs.locale to whitelist-common.incLibravatar glitsj162020-06-19
|
* harden totem.profileLibravatar glitsj162020-06-18
| | | Totem saves screenshots of video to ${PICTURES}. Also adding tracelog to slightly harden things a bit.
* clean private-bin in gummi.profileLibravatar glitsj162020-06-18
|
* Allow python3 in totem profile (#3470)Libravatar Christian Pinedo2020-06-18
|
* Fix #3464Libravatar Fred Barclay2020-06-12
| | | | | | | Atom 1.48 requires a looser sandbox and no longer works with noroot, nonewprivs, protocol, and seccomp caps filter needed adjusting to keep sys_admin and sys_chroot
* mmapfail.sh fixLibravatar rusty-snake2020-06-11
| | | | https://github.com/hannob/mmapfail
* New profiles: apostrophe & quadrapasselLibravatar rusty-snake2020-06-11
|
* Add strawberry profile (#3459)Libravatar Amin Vakil2020-06-11
| | | | | | | | | | | | | | | | | | | | | | | * Add strawberry profile * Fix comment * Add to disable-programs.inc & firecfg.config * Add /home/amin/.local/share/strawberry to profile and disable-programs * Various hardening for strawberry profile Signed-off-by: Amin Vakil <info@aminvakil.com> * Change nodbus to dbus-system none in strawberry profile * Add dbus-user none to strawberry profile * Add whitelist-var-common, sort private-etc * Sort, Add wruc, Add netlink to protocol in strawberry profile * Remove dbus-user none to allow using gnome functions for various usage in strawberry profile
* Fix qt5ct colour schemes and QSS (#3463)Libravatar DiGitHubCap2020-06-10
| | | Applications using Qt5 need this to be whitelisted if the user is using a qt5ct colour scheme (such as "darker") or custom QSS.
* Ignore read-only mount of emacs configuration in the emacs profile.Libravatar Lior Stern2020-06-06
| | | | solves #3454
* drop kcmp from steam.profileLibravatar glitsj162020-06-05
| | | See https://github.com/netblue30/firejail/issues/3219#issuecomment-638823377
* disable-shell.inc (#3411)Libravatar rusty-snake2020-06-04
| | | | | | | | | | | | * disable-shell.inc * add disable-shell.inc to all profiles with a … … private-bin line without bash/sh except profiles with redirect profiles. * add it to some more profiles * exclude aria2c.profile
* Set quiet in w3m profile (#3444)Libravatar Amin Vakil2020-06-02
| | | | | w3m is a text-based web browser as well as a pager like `more' or `less'. With w3m you can browse web pages through a terminal emulator window (xterm, rxvt or something like that). As it outputs I suppose setting quiet in its profile is appropriate.
* fix surf.profile, closes #3441Libravatar rusty-snake2020-06-01
|
* Avoid dbus-*=filter breakage (#3432)Libravatar curiosityseeker2020-06-01
|
* harden mpg123.profile (#3438)Libravatar glitsj162020-05-27
| | | | | * harden mpg123.profile * drop nodvd from mpg123.profile
* new profile: mocp (#3437)Libravatar glitsj162020-05-27
| | | | | | | | | | | | | * Create mocp.profile * add mocp support to disable-programs.inc * add mocp support in firecfg.config * update RELNOTES for mocp * fix configuration access for mocp Thanks to @rusty-snake for spotting this.
* ${RUNUSER} blacklisting + typoLibravatar rusty-snake2020-05-27
|
* Update dino-im.profile (#3433)Libravatar Karoshi422020-05-24
| | | | | | | | | * Update dino-im.profile comment out the globals.local so it's not included twice * Update dino-im.profile add comment
* Add profile for Ubuntu's renamed dino binaryLibravatar Karoshi422020-05-22
| | | Ubuntu named the dino instant messenger's binary ``dino-im``, so it needs to be present as profile and added to private-bin.
* cleanup wire-desktop.profileLibravatar glitsj162020-05-20
| | | After https://github.com/netblue30/firejail/commit/76127399a5811a0b5ae3fffbd999bf22fba032e1 the caps workaround is no longer needed.
* fix seccomp in wire-desktop.profileLibravatar glitsj162020-05-19
| | | Fixes #3423.
* better blacklist orderingLibravatar Reiner Herrmann2020-05-16
|
* Blacklist busybox by defaultLibravatar Reiner Herrmann2020-05-16
| | | | It's a collection of many tools, that might not be allowed individually. When it's needed, it can easily be allowed again.
* fix ordering in disable-programs.incLibravatar glitsj162020-05-16
|
* Allow google-chrome access to the custom flags files in ~/.config. (#3418)Libravatar Mace Muilman2020-05-16
| | | | | | | | | * Allow google-chrome access to the custom flags files in ~/.config. * Added noblacklist for the custom flag files for google-chrome-stable. * Allow read access to the custom flag files for both google-chrome-beta and google-chrome-unstable. * Added the custom flag files for google-chrome stable, beta and unstable to the disable-programs.inc list.
* Add quiet to secret-toolLibravatar Tad2020-05-15
|
* fix wusc in yelp.profileLibravatar glitsj162020-05-15
|
* add new profile: plv (#3410)Libravatar glitsj162020-05-11
| | | | | | | | | | | Also fixed a typo for new profiles: nicontine --> nicotine * add plv to firecfg * add plv to disable-programs.inc * Create plv.profile * Update plv.profile
* Add several games to steam and disable-programsLibravatar corecontingency2020-05-10
| | | | | | | | | | | | Add Faster Than Light, Into the Breach, Paradox Interactive, and mbwarband to disable-programs.inc. Also, add Faster Than Light and Into the Breach into steam.profile. This fixes saved games being lost when steam is closed, and also lets Steam cloud sync work properly. Lastly, remove a duplicate whitelist ${HOME}/.steampid from steam.profile.