Merge pull request #580 from Fred-Barclay/proposed

added libreoffice profile
This commit is contained in:
netblue30 2016-06-19 06:10:33 -04:00 committed by GitHub
commit 148ccdd991
8 changed files with 21 additions and 2 deletions

View file

@ -196,6 +196,7 @@ realinstall:
install -c -m 0644 .etc/gthumb.profile $(DESTDIR)/$(sysconfdir)/firejail/.
install -c -m 0644 .etc/mpv.profile $(DESTDIR)/$(sysconfdir)/firejail/.
install -c -m 0644 .etc/franz.profile $(DESTDIR)/$(sysconfdir)/firejail/.
install -c -m 0644 .etc/libreoffice.profile $(DESTDIR)/$(sysconfdir)/firejail/.
sh -c "if [ ! -f $(DESTDIR)/$(sysconfdir)/firejail/login.users ]; then install -c -m 0644 etc/login.users $(DESTDIR)/$(sysconfdir)/firejail/.; fi;"
install -c -m 0644 etc/firejail.config $(DESTDIR)/$(sysconfdir)/firejail/.
rm -fr .etc

1
README
View file

@ -87,6 +87,7 @@ Fred-Barclay (https://github.com/Fred-Barclay)
- added Brave profile
- added Gitter profile
- various organising
- added Libreoffice profile
Petter Reinholdtsen (pere@hungry.com)
- Opera profile patch
n1trux (https://github.com/n1trux)

View file

@ -77,4 +77,4 @@ Office: evince, gthumb, fbreader
## New security profiles
Gitter, gThumb, mpv, Franz messenger
Gitter, gThumb, mpv, Franz messenger, LibreOffice

View file

@ -3,7 +3,7 @@ firejail (0.9.41) baseline; urgency=low
* compile time and run time support to disable whitelists
* compile time support to disable global configuration file
* some profiles have been converted to private-bin
* new profiles: Gitter, gThumb, mpv, Franz messenger
* new profiles: Gitter, gThumb, mpv, Franz messenger, LibreOffice
-- netblue30 <netblue30@yahoo.com> Tue, 31 May 2016 08:00:00 -0500
firejail (0.9.40) baseline; urgency=low

View file

@ -16,6 +16,7 @@ blacklist ${HOME}/.config/stellarium
blacklist ${HOME}/.config/atril
blacklist ${HOME}/.config/xreader
blacklist ${HOME}/.config/xviewer
blacklist $(HOME)/.config/libreoffice
blacklist ${HOME}/.kde/share/apps/okular
blacklist ${HOME}/.kde/share/config/okularrc
blacklist ${HOME}/.kde/share/config/okularpartrc

14
etc/libreoffice.profile Normal file
View file

@ -0,0 +1,14 @@
# Firejail profile for LibreOffice
noblacklist ~/.config/libreoffice
include /etc/firejail/disable-common.inc
include /etc/firejail/disable-programs.inc
include /etc/firejail/disable-devel.inc
include /etc/firejail/disable-passwdmgr.inc
caps.drop all
netfilter
nonewprivs
noroot
protocol unix,inet,inet6,netlink
seccomp
tracelog

View file

@ -106,3 +106,4 @@
/etc/firejail/gthumb.profile
/etc/firejail/mpv.profile
/etc/firejail/franz.profile
/etc/firejail/libreoffice.profile

View file

@ -106,6 +106,7 @@ evince
fbreader
gwenview
gthumb
LibreOffice
Mathematica
mathematica
okular