aboutsummaryrefslogtreecommitdiffstats
path: root/etc
Commit message (Collapse)AuthorAge
* fix tuxguitarLibravatar smitsohu2021-06-06
|
* tightening zathura profile (#4343)Libravatar pirate4867431862021-06-05
| | | | | * tightening zathura profile * sort
* minor fixLibravatar pirate4867431862021-06-05
|
* creating googler and ddgr profiles (#4333)Libravatar pirate4867431862021-06-04
| | | | | | | | | | | | | | | | | | | | | | | | | | | * Create googler-common.profile * Create googler.profile * Create ddgr.profile * Update firecfg.config * sort fix * space * space * tightening * comment * fix comment * fix private-etc and ${DOWNLOADS} * fix sort * redundant ${DOWNLOADS}
* Fix sort error in profile.template (#4334)Libravatar pirate4867431862021-06-04
|
* Merge pull request #4330 from smitsohu/fjconfigLibravatar netblue302021-06-04
|\ | | | | add firejail.config switch for private-{bin,etc,opt,srv}
| * add firejail.config switch for private-{bin,etc,opt,srv}Libravatar smitsohu2021-05-22
| |
* | Fix seahorse-adventures + CILibravatar rusty-snake2021-06-04
| |
* | some profile fixes for Debian 10Libravatar netblue302021-06-03
| |
* | Update profile.templateLibravatar rusty-snake2021-06-03
| | | | | | | | | | | | | | | | | | The header of profile.template define this order: IGNORES NOBLACKLISTS ALLOW INCLUDES BLACKLISTS DISABLE INCLUDES
* | kodi.profile: Add note for CEC AdaptersLibravatar rusty-snake2021-06-03
| | | | | | | | closes #4324
* | Fix slack.profile (fixes #4329)Libravatar rusty-snake2021-06-03
| |
* | Correct typo in telegram-desktop profileLibravatar Ivan Reshetnikov2021-06-03
| |
* | reorganizing links browsers (#4320)Libravatar pirate4867431862021-05-31
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | * Create links-common.profile * Update links.profile * Create links2.profile * Update links.profile * Update links2.profile * Update elinks.profile * Update elinks.profile * links2 * Update firecfg.config * Update xlinks.profile * .xlinks * add dbus and whitelist-usr-share-common * .xlinks doesn't exist * revert * Create xlinks2 * xlinks2 * Update xlinks2 * Update xlinks.profile * no wayland * no wayland * doesn't use /tmp/.X11-unix * doesn't use /tmp/.X11-unix * noblacklist /tmp/.X11-unix * noblacklist /tmp/.X11-unix
* | Merge pull request #4287 from rusty-snake/restrict-usr-libexecLibravatar netblue302021-05-29
|\ \ | | | | | | Restrict /usr/libexec
| * | Restrict /usr/libexecLibravatar rusty-snake2021-05-29
| | |
* | | Fix #3823 -- Unable to start hexchat with firejailLibravatar rusty-snake2021-05-29
| | |
* | | [minor] gunzip profile broken (#4317)Libravatar pirate4867431862021-05-29
|/ / | | | | | | | | * ignore include disable-shell.inc * allow-bin-sh.inc
* | reorganizing youtube-viewers (#4128)Libravatar pirate4867431862021-05-28
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | * Create youtube-viewers-common.profile * reorganising youtube viewers * rm globals * reorganise youtube viewers * adding pipe-viewer * adding gtk-pipe-viewer * xterm and youtube-dl cache * sort * Update youtube-viewers-common.profile * quiet * quiet * quiet * Update firecfg.config * rm vlc * rm invalid binary * noinput * rm whitelist-runuser-common.inc * rm whitelist-runuser-common.inc * rm whitelist-runuser-common.inc * whitelist-runuser-common.inc
* | deprecated follow-symlink-as-user from firejail.configLibravatar netblue302021-05-26
| |
* | add support for cargo toml/non-toml files (#4286)Libravatar glitsj162021-05-20
| | | | | | | | | | | | | | | | | | | | | | | | | | * add support for cargo toml/non-toml files * add support for cargo toml/non-toml files * use globbing to blacklist Rust files See https://github.com/netblue30/firejail/pull/4286#issuecomment-845318446. * use globbing to blacklist cargo/Rust files See https://github.com/netblue30/firejail/pull/4286#issuecomment-845318446.
* | fixes for eb30ce5 (new profiles) (#4291)Libravatar glitsj162021-05-20
| | | | | | | | | | | | | | | | | | | | | | * fix blobby * fix funnyboat * fix librecad * drop doubled netfilter entree in blobby * drop unneeded include in funnyboat
* | new profilesLibravatar netblue302021-05-20
| |
* | readme, etcLibravatar netblue302021-05-18
| |
* | Merge pull request #4283 from RandomVoid/fix_lutris_profileLibravatar netblue302021-05-18
|\ \ | | | | | | Fix Lutris profile
| * | Fix running games with enabled Feral GameMode in LutrisLibravatar RandomVoid2021-05-16
| | |
| * | Fix Lutris won't start without access to ldconfigLibravatar RandomVoid2021-05-16
| | |
* | | Merge pull request #4284 from rusty-snake/add-cargo.profileLibravatar netblue302021-05-18
|\ \ \ | | | | | | | | Add cargo.profile
| * | | Harden cargo.profileLibravatar rusty-snake2021-05-17
| | | |
| * | | Add cargo.profileLibravatar rusty-snake2021-05-16
| |/ /
* | | Merge pull request #4229 from smitsohu/whitelist2Libravatar netblue302021-05-18
|\ \ \ | |_|/ |/| | Whitelist2
| * | add support for arbitrary whitelist directoriesLibravatar smitsohu2021-05-03
| | |
* | | Fix #4282 -- Unable to open X display when running firejail chromium commandLibravatar rusty-snake2021-05-16
| |/ |/| | | | | | | | | | | | | | | | | | | Summary: SDDM uses $XDG_RUNTIME_DIR/<UUID> as Xauthority. In my tests (Fedora 32 KDE spin IIRC) it used /tmp/... so it was irrelevant for wruc. So the Xauthority file created by SDDM sems to depend on distro, version, config, …. Future alternatives to this long, ugly line would be a ${XAUTHORITY} macro or a private-run-user option.
* | Update disable-common.incLibravatar rusty-snake2021-05-16
| | | | | | | | Make ${HOME}/.rustup read-only and blacklist ${HOME}/.cargo/credentials.toml
* | Add read-write to profile.templateLibravatar rusty-snake2021-05-16
| |
* | fix: discord logout on opening twiceLibravatar sak962021-05-14
| |
* | Harden device access in default.profileLibravatar rusty-snake2021-05-14
| |
* | Follow-up for #4165 (#4271)Libravatar glitsj162021-05-13
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | * Follow-up for #4165 * Follow-up for #4165 * Follow-up for #4165 * Follow-up for #4165 * Follow-up for #4165 * Follow-up for #4165 * Follow-up for #4165 * Follow-up for #4165 * Follow-up for #4165 * Follow-up for #4165 * Follow-up for #4165 * Follow-up for #4165 * Follow-up for #4165 * fix noroot comment As suggested [here](https://github.com/netblue30/firejail/pull/4271#discussion_r630981737). * fix dbus-user comment As suggested [here](https://github.com/netblue30/firejail/pull/4271#discussion_r630982527). * fix private-dev comment As suggested [here](https://github.com/netblue30/firejail/pull/4271#discussion_r630980029). * fix private-etc comment As suggested [here](https://github.com/netblue30/firejail/pull/4271#discussion_r630979698). * move writable-var comment cfr. profile.template
* | Update profile.templateLibravatar rusty-snake2021-05-13
| | | | | | | | Clarify some options that supersede others.
* | Add noinput to browsers as wellLibravatar rusty-snake2021-05-13
| | | | | | | | Profiles with private-dev behind BROWSER_DISABLE_U2F were missed by 0cee0ba5.
* | Update dino.profileLibravatar Tad2021-05-11
| | | | | | | | It now features audio/video calling.
* | drop noautopulse from agetpkgLibravatar glitsj162021-05-11
| | | | | | It's a workaround option, not to be used in any profile by default. Thanks to @rusty-snake for pointing that out.
* | Fix bijibenLibravatar rusty-snake2021-05-08
| | | | | | | | | | | | | | | | bijiben crashes without access to /usr/share/tracker3 in Fedora 34 with: ** (bijiben:14): WARNING **: 21:48:08.394: Unable to connect to Tracker: 'file:///usr/share/tracker3/ontologies/nepomuk' is not a ontology location ** (bijiben:14): WARNING **: 21:48:08.394: Cannot initialize BijiManager: 'file:///usr/share/tracker3/ontologies/nepomuk' is not a ontology location
* | Node.js stack refactoring (#4255)Libravatar glitsj162021-05-08
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | * Create node.profile * Create node-gyp.profile * refactor npm as redirect * Create npx.profile * Create nvm.profile * Create semver.profile * refactor yarn as redirect * collect node.js stack configuration in common profile * add ~/.nvm to node section * account for node-gyp python dependency * read-only ~/.nvm for node.js stack * blacklist ~/.nvm for node.js stack * move env var comment cfr. profile.template * Delete node-gyp.profile node-gyp is a shell script with a node shebang. We've got that covered via node.profile. * Delete npx.profile npx is a shell script with a node shebang. We've got that covered via node.profile. * Delete semver.profile semver is a shell script that calls node. We've got that covered via node.profile. * add node and nvm to new profiles section
* | revert comment changes from #4257 (#4258)Libravatar glitsj162021-05-07
| | | | | | | | | | | | | | | | | | * revert comment changes from #4257 * revert comment changes from #4257 * revert comment changes from #4257 * revert comment changes from #4257
* | read-write fixes (#4257)Libravatar glitsj162021-05-07
| | | | | | | | | | | | | | | | | | * [comment] use 'read-write' instead of 'ignore read-only' * [comment] use 'read-write' instead of 'ignore read-only' * [comment] use 'read-write' instead of 'ignore read-only' * [comment] use 'read-write' instead of 'ignore read-only'
* | Merge pull request #4251 from pirate486743186/patch-2Libravatar glitsj162021-05-07
|\ \ | | | | | | whitelist /var/lib/aspell in whitelist-var-common.inc
| * | whitelist /var/lib/aspellLibravatar pirate4867431862021-05-06
| | |
* | | pluma broken with memory-deny-write-executeLibravatar pirate4867431862021-05-07
|/ /
* | some wireshark hardening (#4245)Libravatar glitsj162021-05-05
| | | | | | | | | | * restrict D-Bus access in wireshark * add private-cache to wireshark