From 1f83479b6a5f8d372091fe73aa6c05d2721bf87f Mon Sep 17 00:00:00 2001 From: Fred-Barclay Date: Thu, 7 Jul 2016 05:43:27 +1000 Subject: Fixed typo --- etc/pix.profile | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) (limited to 'etc') diff --git a/etc/pix.profile b/etc/pix.profile index 4e53de00b..87056e32c 100644 --- a/etc/pix.profile +++ b/etc/pix.profile @@ -1,4 +1,4 @@ -# gthumb profile +# Firejail profile for pix noblacklist ${HOME}/.config/pix noblacklist ${HOME}/.local/share/pix -- cgit v1.2.3-54-g00ecf From 6175c869299b89bd5f9742d404ed5cd7a85a581f Mon Sep 17 00:00:00 2001 From: Fred-Barclay Date: Thu, 7 Jul 2016 05:45:24 +1000 Subject: added Atom Beta profile --- etc/atom-beta.profile | 17 +++++++++++++++++ 1 file changed, 17 insertions(+) create mode 100644 etc/atom-beta.profile (limited to 'etc') diff --git a/etc/atom-beta.profile b/etc/atom-beta.profile new file mode 100644 index 000000000..e2c3000c9 --- /dev/null +++ b/etc/atom-beta.profile @@ -0,0 +1,17 @@ +# Firjail profile for Atom Beta. +noblacklist ~/.atom +noblacklist ~/.config/Atom + +include /etc/firejail/disable-common.inc +include /etc/firejail/disable-programs.inc +include /etc/firejail/disable-passwdmgr.inc + +caps.drop all +netfilter +nonewprivs +nogroups +noroot +seccomp +shell none + +private-dev -- cgit v1.2.3-54-g00ecf From 49968ea2702263b038a675e10f667d18ae030ee0 Mon Sep 17 00:00:00 2001 From: Fred-Barclay Date: Thu, 7 Jul 2016 05:53:22 +1000 Subject: additional atom-beta files --- Makefile.in | 1 + README | 1 + README.md | 2 +- RELNOTES | 1 + etc/disable-programs.inc | 2 ++ platform/debian/conffiles | 2 ++ src/firecfg/firecfg.config | 1 + 7 files changed, 9 insertions(+), 1 deletion(-) (limited to 'etc') diff --git a/Makefile.in b/Makefile.in index 9ee65c975..85e81fada 100644 --- a/Makefile.in +++ b/Makefile.in @@ -220,6 +220,7 @@ realinstall: install -c -m 0644 .etc/xz.profile $(DESTDIR)/$(sysconfdir)/firejail/. install -c -m 0644 .etc/less.profile $(DESTDIR)/$(sysconfdir)/firejail/. install -c -m 0644 .etc/Telegram.profile $(DESTDIR)/$(sysconfdir)/firejail/. + install -c -m 0644 .etc/atom-beta.profile $(DESTDIR)/$(sysconfdir)/firejail/. sh -c "if [ ! -f $(DESTDIR)/$(sysconfdir)/firejail/login.users ]; then install -c -m 0644 etc/login.users $(DESTDIR)/$(sysconfdir)/firejail/.; fi;" install -c -m 0644 etc/firejail.config $(DESTDIR)/$(sysconfdir)/firejail/. rm -fr .etc diff --git a/README b/README index 6cab5bd7a..9bde4793f 100644 --- a/README +++ b/README @@ -52,6 +52,7 @@ Fred-Barclay (https://github.com/Fred-Barclay) - added pix profile - added audacity profile - fixed Telegram and qtox profiles + - added Atom Beta profile Jaykishan Mutkawoa (https://github.com/jmutkawoa) - cpio profile Paupiah Yash (https://github.com/CaffeinatedStud) diff --git a/README.md b/README.md index bec1a2716..e6757c6f1 100644 --- a/README.md +++ b/README.md @@ -102,5 +102,5 @@ Office: evince, gthumb, fbreader, pix ## New security profiles -Gitter, gThumb, mpv, Franz messenger, LibreOffice, pix, audacity, strings, xz, xzdec, gzip, cpio, less +Gitter, gThumb, mpv, Franz messenger, LibreOffice, pix, audacity, strings, xz, xzdec, gzip, cpio, less, Atom Beta diff --git a/RELNOTES b/RELNOTES index 96a5f0a7f..e48f7dc29 100644 --- a/RELNOTES +++ b/RELNOTES @@ -8,6 +8,7 @@ firejail (0.9.41) baseline; urgency=low * some profiles have been converted to private-bin * new profiles: Gitter, gThumb, mpv, Franz messenger, LibreOffice * new profiles: pix, audacity, strings, xz, xzdec, gzip, cpio, less + * new profiles: Atom Beta -- netblue30 Tue, 31 May 2016 08:00:00 -0500 firejail (0.9.40) baseline; urgency=low diff --git a/etc/disable-programs.inc b/etc/disable-programs.inc index e9dd331aa..81c97ca2d 100644 --- a/etc/disable-programs.inc +++ b/etc/disable-programs.inc @@ -1,4 +1,5 @@ # various programs +blacklist ${HOME}/.Atom blacklist ${HOME}/.remmina blacklist ${HOME}/.tconn blacklist ${HOME}/.FBReader @@ -6,6 +7,7 @@ blacklist ${HOME}/.wine blacklist ${HOME}/.Mathematica blacklist ${HOME}/.Wolfram Research blacklist ${HOME}/.stellarium +blacklist ${HOME}/.config/Atom blacklist ${HOME}/.config/gthumb blacklist ${HOME}/.config/mupen64plus blacklist ${HOME}/.config/transmission diff --git a/platform/debian/conffiles b/platform/debian/conffiles index 9ef2f1b26..20a68146c 100644 --- a/platform/debian/conffiles +++ b/platform/debian/conffiles @@ -126,4 +126,6 @@ /etc/firejail/xz.profile /etc/firejail/less.profile /etc/firejail/Telegram.profile +/etc/firejail/atom-beta.profile + diff --git a/src/firecfg/firecfg.config b/src/firecfg/firecfg.config index 35338d427..55b61df7d 100644 --- a/src/firecfg/firecfg.config +++ b/src/firecfg/firecfg.config @@ -126,6 +126,7 @@ xreader # other snap ssh +atom-beta # weather/climate aweather -- cgit v1.2.3-54-g00ecf