aboutsummaryrefslogtreecommitdiffstats
path: root/etc
Commit message (Collapse)AuthorAge
* Prevent quiet option output leakage (#2913)Libravatar glitsj162019-08-14
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | * nano: add quiet option * ffmpegthumbnailer: fix quiet leakage * ffplay: fix quiet leakage * ffprobe: fix quiet leakage * rnano: fix quiet leakage * qt-faststart: fix quiet leakage * scp: fix quiet leakage * sftp: fix quiet leakage * transmission-create: fix quiet leakage * transmission-edit: fix quiet leakage * transmission-remote-cli: fix quiet leakage * transmission-remote-gtk: fix quiet leakage * dnscrypt-proxy: add quiet option * dnsmasq: add quiet option * seahorse-daemon: add quiet option * xpra: add quiet option * Xephyr: add quiet option * Xvfb: add quiet option
* Fix regular profile header for conplayLibravatar glitsj162019-08-14
|
* remove x11 xorgLibravatar Patrick Schleizer2019-08-14
| | | https://forums.whonix.org/t/automatically-firejailing-tor-browser/4767/29
* Fix quiet option in archiver redirect profiles (#2907)Libravatar glitsj162019-08-13
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | * Fix potential leakage of quiet option in 7za * Fix potential leakage in quiet option for 7zr * Fix potential leakage in quiet option for p7zip * Fix potential leakage in quiet option for acat * Fix potential leakage in quiet option for adiff * Fix potential leakage in quiet option for als * Fix potential leakage in quiet option for apack * Fix potential leakage in quiet option for arepack * Fix potential leakage in quiet option for aunpack * Fix potential leakage in quiet option for lrunzip * Fix potential leakage in quiet option for lrz * Fix potential leakage in quiet option for lrzcat * Fix potential leakage in quiet option for lrzip * Fix potential leakage in quiet option for lrztar * Fix potential leakage in quiet option for lrzuntar * Fix potential leakage in quiet option for zpaq
* whois: streamline quiet optionLibravatar glitsj162019-08-13
|
* dig: streamline quiet optionLibravatar glitsj162019-08-13
|
* virtualbox: sort capabilitiesLibravatar glitsj162019-08-13
|
* virtualbox: add required capabilitiesLibravatar Vincent432019-08-13
| | | | | VirtualBox has several setuid binaries which need cap_sys_admin, cap_net_raw and cap_sys_nice to work properly. Fixes https://github.com/netblue30/firejail/issues/2868
* Harden 7z.profileLibravatar glitsj162019-08-13
|
* Fix order of nodvd in bsdtar.profileLibravatar glitsj162019-08-12
|
* Place quiet option cfr. all other profiles (#2904)Libravatar glitsj162019-08-12
|
* Add unzstd profile (#2903)Libravatar glitsj162019-08-12
| | | | | | * Create unzstd.profile * Add unzstd to firecfg.config
* Add zstd (redirect) profile(s) (#2902)Libravatar glitsj162019-08-12
| | | | | | | | | | | | | | | | * Create zstd.profile * Create pzstd.profile * Create zstdcat.profile * Create zstdgrep.profile * Create zstdless.profile * Create zstdmt.profile * Add zstd and its redirect profiles to firecfg.config
* add bzcat profileLibravatar smitsohu2019-08-12
|
* fix file.profile (broken on Debian Buster)Libravatar smitsohu2019-08-12
|
* Fix QOwnNotes pathLibravatar František Polášek2019-08-11
| | | | Every time QOwnNotes was started, setup Wizard was shown. Log shown: `Warning: cannot create xxx.config directory`
* update and harden file.profileLibravatar smitsohu2019-08-11
|
* added 'noblacklist ${PICTURES}' to mpv.profile (#2898)Libravatar veloute2019-08-11
| | | | | | | | * added 'noblacklist ${PICTURES}' to mpv.profile * Update mpv.profile fix typo
* rewrite/partial revert of 8bff773d6a7bf70c97b3d5b751df9ec0dd6c8b5dLibravatar smitsohu2019-08-09
| | | | | | | the commit in question introduced an early check of Firejail configuration file, which broke "firejail in firejail" for some sandboxes. see issue #2877
* Fix printer detection in okular and gwenviewLibravatar Vincent432019-08-07
|
* Fix #2866 -- private-etc needed fedora-release (#2890)Libravatar Jiri2019-08-05
| | | | * Fix #2866 -- private-etc needed os-release,redhat-release,system-release,system-release-cpe
* Merge pull request #2871 from rusty-snake/add-rsync.profileLibravatar rusty-snake2019-08-05
|\ | | | | Create rsync.profile
| * add usage to rsync-download_only.profileLibravatar rusty-snake2019-08-05
| |
| * rename rsync.profile to rsync-download_only.profileLibravatar rusty-snake2019-08-01
| |
| * update commentLibravatar rusty-snake2019-07-30
| |
| * Create rsync.profileLibravatar rusty-snake2019-07-25
| |
* | Fix #2866 -- private-etc needed debian_versionLibravatar Fred Barclay2019-08-04
| |
* | blacklist kwalletrcLibravatar smitsohu2019-08-01
| |
* | misc profile fixes (Debian 10 related)Libravatar smitsohu2019-08-01
| |
* | some profile fixups (followup)Libravatar rusty-snake2019-08-01
| | | | | | | | | | - fix sorting and private-etc, thanks to @glitsj16 for catching this - add some missing to private-bin in firefox (still need more testing)
* | some profile fixupsLibravatar rusty-snake2019-08-01
| | | | | | | | | | | | - add a private-bin to firefox for fedora (still need testing) - add a temporary workaround for #2877 ghostwriter sience this break export and preview with pandoc - remove 'name slack' from slack.profile sience this is the only profile with name
* | Merge pull request #2883 from flacks/profiles/whalebirdLibravatar SkewedZeppelin2019-08-01
|\ \ | | | | | | Add Whalebird profile
| * | Add Whalebird profileLibravatar Jean Lucas2019-07-31
| | |
* | | profiles: misc fixesLibravatar Tad2019-08-01
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | - pluma: sync private-lib from gedit to fix crashes 5e220b2da502bdcaf0f6188779e8bb0e37c9c414 - checkbashisms: fix missing library needed under CentOS 7 of note: - yelp complains about /etc/pki but lacks network access anyway under openSUSE Tumbleweed - gedit is broken, see #2207 - onionshare-gui is broken, unrelated to firejail under CentOS 7 - chromium-common is broken, commenting private-dev fixes, potentially related to firejail, there are SELinux denials for /dev/urandom under Fedora and CentOS 7 - gnome-system-log is broken, as it is a script that calls logview using pkexec, consider commenting in firecfg?
* | | Merge pull request #2885 from flacks/profiles/tor-browserLibravatar SkewedZeppelin2019-08-01
|\ \ \ | | | | | | | | Add new Tor Browser alias
| * | | Add new Tor Browser aliasLibravatar Jean Lucas2019-07-31
| |/ / | | | | | | | | | | | | | | | | | | | | | | | | - tor-browser in the AUR is an international package; all other individual language variants have been removed, so, add new alias - Add 'tor-browser' and 'mv' to private-bin in launcher profile ('mv' is required when upgrading tor-browser versions) - Add 'tor-browser' to firecfg.config - Add config dir to disable-programs.inc
* / / Update itch profileLibravatar Jean Lucas2019-07-31
|/ / | | | | | | itch now also uses ~/.itch for application updates
* | CorrectionsLibravatar Jean Lucas2019-07-31
| | | | | | | | | | | | - Add Zulip config dir to disable-programs.inc - Add disable-xdg.inc to Zulip profile - Add Zulip to firecfg.config
* | Add Zulip profileLibravatar Jean Lucas2019-07-31
| |
* | Add tb-starter-wrapper.profile (#2863)Libravatar rusty-snake2019-07-28
| |
* | fix ghostwriterLibravatar rusty-snake2019-07-28
| |
* | Remove private-cache from unzipLibravatar glitsj162019-07-26
|/ | | The `private-cache` option breaks electron related builds (see [this](https://github.com/minbrowser/min/issues/793) for an example).
* fix file-roller.profileLibravatar rusty-snake2019-07-25
|
* update private-bin for tbbLibravatar rusty-snake2019-07-25
|
* Merge branch 'master' of https://github.com/netblue30/firejailLibravatar smitsohu2019-07-25
|\
| * Update syscalls.txtLibravatar rusty-snake2019-07-22
| | | | | | | | | | | | * remove mincore * add @default without chroot * add @default-nodebuggers without chroot
* | fix verbosity for non-authorized userLibravatar smitsohu2019-07-22
|/ | | | | | users not in firejail.users should only see the error, not the symlink warning. Also exposes less code to non- authorized users.
* fix gucharmap & add gnome-characters, gnome-character-mapLibravatar rusty-snake2019-07-18
|
* use allow-debuggers in spectre-meltdown-checkerLibravatar rusty-snake2019-07-18
|
* Harden gnome-scheduleLibravatar glitsj162019-07-18
| | | Let's disable using a terminal for cron job testing by default and make this a whitelist profile.