From b553272fac9b205bf5a3192b799a4d79e6fedcee Mon Sep 17 00:00:00 2001 From: Tad Date: Sat, 29 Jul 2017 10:08:56 -0400 Subject: Add a profile for arm --- etc/arm.profile | 42 ++++++++++++++++++++++++++++++++++++++++++ src/firecfg/firecfg.config | 1 + 2 files changed, 43 insertions(+) create mode 100644 etc/arm.profile diff --git a/etc/arm.profile b/etc/arm.profile new file mode 100644 index 000000000..3000c35d7 --- /dev/null +++ b/etc/arm.profile @@ -0,0 +1,42 @@ +# Persistent global definitions go here +include /etc/firejail/globals.local + +# This file is overwritten during software install. +# Persistent customizations should go in a .local file. +include /etc/firejail/arm.local + +# Firejail profile for arm + +noblacklist ${HOME}/.arm + +include /etc/firejail/disable-common.inc +include /etc/firejail/disable-devel.inc +include /etc/firejail/disable-passwdmgr.inc +include /etc/firejail/disable-programs.inc + +mkdir ${HOME}/.arm +whitelist ${HOME}/.arm +include /etc/firejail/whitelist-common.inc + +caps.drop all +ipc-namespace +netfilter +no3d +nogroups +nonewprivs +noroot +nosound +novideo +protocol unix,inet,inet6 +seccomp +shell none +tracelog + +disable-mnt +#private-bin arm,tor,sh,python2,python2.7,ps,lsof,ldconfig +private-dev +private-etc tor,passwd +private-tmp + +noexec ${HOME} +noexec /tmp diff --git a/src/firecfg/firecfg.config b/src/firecfg/firecfg.config index b3614bf64..eb611034f 100644 --- a/src/firecfg/firecfg.config +++ b/src/firecfg/firecfg.config @@ -9,6 +9,7 @@ amarok android-studio arduino ark +arm atom atom-beta atool -- cgit v1.2.3-70-g09d2 From 059ea07a98f508bb99f15e3e434c7c3169a013dd Mon Sep 17 00:00:00 2001 From: Fred-Barclay Date: Sat, 29 Jul 2017 09:11:22 -0500 Subject: merges --- platform/debian/conffiles | 3 +++ 1 file changed, 3 insertions(+) diff --git a/platform/debian/conffiles b/platform/debian/conffiles index a2e02dd6a..a60bf92c3 100644 --- a/platform/debian/conffiles +++ b/platform/debian/conffiles @@ -66,6 +66,7 @@ /etc/firejail/dragon.profile /etc/firejail/dropbox.profile /etc/firejail/elinks.profile +/etc/firejail/electron.profile /etc/firejail/emacs.profile /etc/firejail/empathy.profile /etc/firejail/enchant.profile @@ -230,6 +231,7 @@ /etc/firejail/qutebrowser.profile /etc/firejail/ranger.profile /etc/firejail/rhythmbox.profile +/etc/firejail/riot-web.profile /etc/firejail/ristretto.profile /etc/firejail/rtorrent.profile /etc/firejail/scribus.profile @@ -264,6 +266,7 @@ /etc/firejail/transmission-show.profile /etc/firejail/uget-gtk.profile /etc/firejail/unbound.profile +/etc/firejail/unknown-horizons.profile /etc/firejail/unrar.profile /etc/firejail/unzip.profile /etc/firejail/uudeview.profile -- cgit v1.2.3-70-g09d2