From bf3ba3e577a6d7e58b55f88d3ab363aa75337ba8 Mon Sep 17 00:00:00 2001 From: avoidr Date: Sat, 14 May 2016 17:28:25 +0200 Subject: add mcabber.profile --- etc/mcabber.profile | 19 +++++++++++++++++++ 1 file changed, 19 insertions(+) create mode 100644 etc/mcabber.profile diff --git a/etc/mcabber.profile b/etc/mcabber.profile new file mode 100644 index 000000000..553672406 --- /dev/null +++ b/etc/mcabber.profile @@ -0,0 +1,19 @@ +# mcabber profile +noblacklist ${HOME}/.mcabber +noblacklist ${HOME}/.mcabberrc + +include /etc/firejail/disable-common.inc +include /etc/firejail/disable-programs.inc +include /etc/firejail/disable-devel.inc +include /etc/firejail/disable-passwdmgr.inc + +caps.drop all +seccomp +protocol inet,inet6 +netfilter +noroot + +private-bin mcabber +private-etc group +private-dev +shell none -- cgit v1.2.3-70-g09d2 From d32b616e41b8216e2573d80813d719ed6b714467 Mon Sep 17 00:00:00 2001 From: avoidr Date: Sat, 14 May 2016 17:29:35 +0200 Subject: noblacklist mcabber --- etc/disable-programs.inc | 1 + 1 file changed, 1 insertion(+) diff --git a/etc/disable-programs.inc b/etc/disable-programs.inc index a3fd0fe73..307ccaf6c 100644 --- a/etc/disable-programs.inc +++ b/etc/disable-programs.inc @@ -55,6 +55,7 @@ blacklist ${HOME}/.8pecxstudios # Instant Messaging blacklist ${HOME}/.config/hexchat blacklist ${HOME}/.mcabber +blacklist ${HOME}/.mcabberrc blacklist ${HOME}/.purple blacklist ${HOME}/.config/psi+ blacklist ${HOME}/.retroshare -- cgit v1.2.3-70-g09d2 From 86fa3a51d76bbb62f7676dee106a5bd8c5c4fcc7 Mon Sep 17 00:00:00 2001 From: avoidr Date: Sat, 14 May 2016 17:34:13 +0200 Subject: edit Makefile.in, conffiles, README{.md,} --- Makefile.in | 1 + README | 3 ++- README.md | 2 +- platform/debian/conffiles | 1 + 4 files changed, 5 insertions(+), 2 deletions(-) diff --git a/Makefile.in b/Makefile.in index 2d49f88e1..34daed387 100644 --- a/Makefile.in +++ b/Makefile.in @@ -183,6 +183,7 @@ realinstall: install -c -m 0644 .etc/xplayer.profile $(DESTDIR)/$(sysconfdir)/firejail/. install -c -m 0644 .etc/xreader.profile $(DESTDIR)/$(sysconfdir)/firejail/. install -c -m 0644 .etc/xviewer.profile $(DESTDIR)/$(sysconfdir)/firejail/. + install -c -m 0644 .etc/mcabber.profile $(DESTDIR)/$(sysconfdir)/firejail/. sh -c "if [ ! -f $(DESTDIR)/$(sysconfdir)/firejail/login.users ]; then install -c -m 0644 etc/login.users $(DESTDIR)/$(sysconfdir)/firejail/.; fi;" sh -c "if [ ! -f $(DESTDIR)/$(sysconfdir)/firejail/firejail.config ]; then install -c -m 0644 etc/firejail.config $(DESTDIR)/$(sysconfdir)/firejail/.; fi;" rm -fr .etc diff --git a/README b/README index fcd1c54cd..dd0c5a5b1 100644 --- a/README +++ b/README @@ -29,7 +29,7 @@ avoidr (https://github.com/avoidr) - whitelist fix - recently-used.xbel fix - added parole profile - - blacklist ncat, manpage fixes, + - blacklist ncat - hostname support in profile file - Google Chrome profile rework - added cmus profile @@ -37,6 +37,7 @@ avoidr (https://github.com/avoidr) - add net iface support in profile files - paths fix - lots of profile fixes + - added mcabber profile Ruan (https://github.com/ruany) - fixed hexchat profile Vasya Novikov (https://github.com/vn971) diff --git a/README.md b/README.md index eb4b1af81..4fa79d9f2 100644 --- a/README.md +++ b/README.md @@ -283,6 +283,6 @@ $ man firejail-profile lxterminal, Epiphany, cherrytree, Polari, Vivaldi, Atril, qutebrowser, SlimJet, Battle for Wesnoth, Hedgewars, qTox, OpenSSH client, OpenBox window manager, Dillo, cmus, dnsmasq, PaleMoon, Icedove, abrowser, 0ad, netsurf, Warzone2100, okular, gwenview, Gpredict, Aweather, Stellarium, Google-Play-Music-Desktop-Player, quiterss, -cyberfox, generic Ubuntu snap application profile, xplayer, xreader, xviewer +cyberfox, generic Ubuntu snap application profile, xplayer, xreader, xviewer, mcabber diff --git a/platform/debian/conffiles b/platform/debian/conffiles index 4f118d571..8cf8f165c 100644 --- a/platform/debian/conffiles +++ b/platform/debian/conffiles @@ -97,3 +97,4 @@ /etc/firejail/xplayer.profile /etc/firejail/xreader.profile /etc/firejail/xviewer.profile +/etc/firejail/mcabber.profile -- cgit v1.2.3-70-g09d2 From 6cc91e438a5be38168b599529f046c35929d9c10 Mon Sep 17 00:00:00 2001 From: avoidr Date: Sat, 14 May 2016 17:34:58 +0200 Subject: edit RELNOTES --- RELNOTES | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/RELNOTES b/RELNOTES index 9c6aeac24..be1612acf 100644 --- a/RELNOTES +++ b/RELNOTES @@ -24,7 +24,7 @@ firejail (0.9.40-rc1) baseline; urgency=low * new profiles: okular, gwenview, Google-Play-Music-Desktop-Player * new profiles: Aweather, Stellarium, gpredict, quiterss, cyberfox * new profiles: generic Ubuntu snap application profile, xplayer - * new profiles: xreader, xviewer + * new profiles: xreader, xviewer, mcabber * generic.profile renamed default.profile * build rpm packages using "make rpms" * bugfixes -- cgit v1.2.3-70-g09d2