From ca09dafadcf00cf419e23fc13adf9874fc905fb5 Mon Sep 17 00:00:00 2001 From: netblue30 Date: Sat, 30 Jun 2018 07:48:24 -0400 Subject: merged Amend Wire profiles #1998 form @flacks --- etc/Wire.profile | 6 ------ etc/disable-programs.inc | 1 - etc/wire-desktop.profile | 40 ++++++++++++++++++++++++++++++++++++++++ etc/wire.profile | 34 ---------------------------------- 4 files changed, 40 insertions(+), 41 deletions(-) delete mode 100644 etc/Wire.profile create mode 100644 etc/wire-desktop.profile delete mode 100644 etc/wire.profile (limited to 'etc') diff --git a/etc/Wire.profile b/etc/Wire.profile deleted file mode 100644 index 26b683f84..000000000 --- a/etc/Wire.profile +++ /dev/null @@ -1,6 +0,0 @@ -# Firejail profile alias for wire -# This file is overwritten after every install/update - - -# Redirect -include /etc/firejail/wire.profile diff --git a/etc/disable-programs.inc b/etc/disable-programs.inc index ce27116ba..f72b5a5c3 100644 --- a/etc/disable-programs.inc +++ b/etc/disable-programs.inc @@ -229,7 +229,6 @@ blacklist ${HOME}/.config/vivaldi blacklist ${HOME}/.config/vivaldi-snapshot blacklist ${HOME}/.config/vlc blacklist ${HOME}/.config/wesnoth -blacklist ${HOME}/.config/wire blacklist ${HOME}/.config/wireshark blacklist ${HOME}/.config/xchat blacklist ${HOME}/.config/xed diff --git a/etc/wire-desktop.profile b/etc/wire-desktop.profile new file mode 100644 index 000000000..74d44efe3 --- /dev/null +++ b/etc/wire-desktop.profile @@ -0,0 +1,40 @@ +# Firejail profile for wire-desktop +# This file is overwritten after every install/update +# Persistent local customizations +include /etc/firejail/wire-desktop.local +# Persistent global definitions +include /etc/firejail/globals.local + +noblacklist ${HOME}/.config/Wire + +include /etc/firejail/disable-common.inc +include /etc/firejail/disable-devel.inc +include /etc/firejail/disable-interpreters.inc +include /etc/firejail/disable-passwdmgr.inc +include /etc/firejail/disable-programs.inc + +mkdir ${HOME}/.config/Wire +whitelist ${HOME}/.config/Wire +whitelist ${DOWNLOADS} + +include /etc/firejail/whitelist-common.inc + +caps.drop all +netfilter +nodvd +nogroups +nonewprivs +noroot +notv +protocol unix,inet,inet6,netlink +seccomp +shell none + +# Note: The current version of Wire is located in /opt/wire-desktop/wire-desktop, and therefore +# it is not in PATH. To use Wire with firejail, run "firejail /opt/wire-desktop/wire-desktop" + +private-bin wire-desktop +private-dev +private-etc fonts,machine-id +disable-mnt +private-tmp diff --git a/etc/wire.profile b/etc/wire.profile deleted file mode 100644 index 86ebca33d..000000000 --- a/etc/wire.profile +++ /dev/null @@ -1,34 +0,0 @@ -# Firejail profile for wire -# This file is overwritten after every install/update -# Persistent local customizations -include /etc/firejail/wire.local -# Persistent global definitions -include /etc/firejail/globals.local - -# Note: the current beta version of wire is located in /opt/Wire/wire and therefore not in PATH. -# To use wire with firejail run "firejail /opt/Wire/wire" - -noblacklist ${HOME}/.config/Wire -noblacklist ${HOME}/.config/wire - -include /etc/firejail/disable-common.inc -include /etc/firejail/disable-devel.inc -include /etc/firejail/disable-interpreters.inc -include /etc/firejail/disable-passwdmgr.inc -include /etc/firejail/disable-programs.inc - -caps.drop all -netfilter -nodvd -nogroups -nonewprivs -noroot -notv -protocol unix,inet,inet6,netlink -seccomp -shell none - -disable-mnt -private-cache -private-dev -private-tmp -- cgit v1.2.3-54-g00ecf