From b68bded6f46265666c842e29041b5a67d0b23a35 Mon Sep 17 00:00:00 2001 From: Fred-Barclay Date: Mon, 12 Mar 2018 12:40:26 -0500 Subject: Remove mdwe from viewnior - fix #1808 --- etc/viewnior.profile | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/etc/viewnior.profile b/etc/viewnior.profile index 4df71f728..39bf3f7ce 100644 --- a/etc/viewnior.profile +++ b/etc/viewnior.profile @@ -37,6 +37,7 @@ private-dev private-etc fonts private-tmp -memory-deny-write-execute +# memory-deny-write-executes breaks on Arch - see issue #1808 +#memory-deny-write-execute noexec ${HOME} noexec /tmp -- cgit v1.2.3-54-g00ecf From 66f9edf9bb5fbef9d2299b84bf8ffe85248e0cd1 Mon Sep 17 00:00:00 2001 From: Tad Date: Mon, 12 Mar 2018 14:43:11 -0400 Subject: Add a profile for gnome-builder --- README.md | 2 +- RELNOTES | 2 +- etc/gnome-builder.profile | 25 +++++++++++++++++++++++++ src/firecfg/firecfg.config | 1 + 4 files changed, 28 insertions(+), 2 deletions(-) create mode 100644 etc/gnome-builder.profile diff --git a/README.md b/README.md index fd3518c27..8ff75b46a 100644 --- a/README.md +++ b/README.md @@ -244,4 +244,4 @@ firefox-common-addons.inc in firefox-common.profile. Basilisk browser, Tor Browser language packs, PlayOnLinux, sylpheed, discord-canary, pycharm-community, pycharm-professional, Pitivi, OnionShare, Fritzing, Kaffeine, pdfchain, -tilp, vivaldi-snapshot, bitcoin-qt, VS Code, falkon +tilp, vivaldi-snapshot, bitcoin-qt, VS Code, falkon, gnome-builder diff --git a/RELNOTES b/RELNOTES index 682e40d0e..8e9f65501 100644 --- a/RELNOTES +++ b/RELNOTES @@ -26,7 +26,7 @@ firejail (0.9.53) baseline; urgency=low * new profiles: basilisk, Tor Browser language packs, PlayOnLinux, sylpheed, * new profiles: discord-canary, pycharm-community, pycharm-professional, * new profiles: pdfchain, tilp, vivaldi-snapshot, bitcoin-qt, kaffeine, VS Code, - * new profiles: falkon + * new profiles: falkon, gnome-builder -- netblue30 Thu, 1 Mar 2018 08:00:00 -0500 firejail (0.9.52) baseline; urgency=low diff --git a/etc/gnome-builder.profile b/etc/gnome-builder.profile new file mode 100644 index 000000000..a5a48e97a --- /dev/null +++ b/etc/gnome-builder.profile @@ -0,0 +1,25 @@ +# Firejail profile for gnome-builder +# This file is overwritten after every install/update +# Persistent local customizations +include /etc/firejail/gnome-builder.local +# Persistent global definitions +include /etc/firejail/globals.local + +include /etc/firejail/disable-common.inc +include /etc/firejail/disable-passwdmgr.inc +include /etc/firejail/disable-programs.inc + +caps.drop all +ipc-namespace +netfilter +nodvd +nogroups +nonewprivs +noroot +notv +novideo +protocol unix,inet,inet6 +seccomp +shell none + +private-dev diff --git a/src/firecfg/firecfg.config b/src/firecfg/firecfg.config index 4eb01c5b5..3cf5df1c1 100644 --- a/src/firecfg/firecfg.config +++ b/src/firecfg/firecfg.config @@ -141,6 +141,7 @@ gitter gjs globaltime gnome-2048 +gnome-builder gnome-books gnome-calculator gnome-chess -- cgit v1.2.3-54-g00ecf