Update profiles to use the new noblacklist command.

This commit is contained in:
sarneaud 2015-09-01 14:37:50 +10:00
parent 829d9e0c4c
commit 91e11d1554
6 changed files with 15 additions and 7 deletions

View file

@ -1,7 +1,8 @@
# Chromium browser profile # Chromium browser profile
noblacklist ${HOME}/.config/chromium
include /etc/firejail/disable-mgmt.inc include /etc/firejail/disable-mgmt.inc
include /etc/firejail/disable-secret.inc include /etc/firejail/disable-secret.inc
include /etc/firejail/disable-common.inc chromium include /etc/firejail/disable-common.inc
include /etc/firejail/disable-history.inc include /etc/firejail/disable-history.inc
netfilter netfilter

View file

@ -1,7 +1,9 @@
# FileZilla profile # FileZilla profile
noblacklist ${HOME}/.filezilla
noblacklist ${HOME}/.config/filezilla
include /etc/firejail/disable-mgmt.inc include /etc/firejail/disable-mgmt.inc
include /etc/firejail/disable-secret.inc include /etc/firejail/disable-secret.inc
include /etc/firejail/disable-common.inc .filezilla include /etc/firejail/disable-common.inc
include /etc/firejail/disable-history.inc include /etc/firejail/disable-history.inc
caps.drop all caps.drop all
seccomp seccomp

View file

@ -1,7 +1,8 @@
# Firejail profile for Mozilla Firefox (Iceweasel in Debian) # Firejail profile for Mozilla Firefox (Iceweasel in Debian)
noblacklist ${HOME}/.mozilla
include /etc/firejail/disable-mgmt.inc include /etc/firejail/disable-mgmt.inc
include /etc/firejail/disable-secret.inc include /etc/firejail/disable-secret.inc
include /etc/firejail/disable-common.inc .mozilla include /etc/firejail/disable-common.inc
include /etc/firejail/disable-history.inc include /etc/firejail/disable-history.inc
caps.drop all caps.drop all
seccomp seccomp

View file

@ -1,7 +1,8 @@
# Midory browser profile # Midori browser profile
noblacklist ${HOME}/.config/midori
include /etc/firejail/disable-mgmt.inc include /etc/firejail/disable-mgmt.inc
include /etc/firejail/disable-secret.inc include /etc/firejail/disable-secret.inc
include /etc/firejail/disable-common.inc midori include /etc/firejail/disable-common.inc
include /etc/firejail/disable-history.inc include /etc/firejail/disable-history.inc
caps.drop all caps.drop all
seccomp seccomp

View file

@ -1,7 +1,8 @@
# Chromium browser profile # Chromium browser profile
noblacklist ${HOME}/.config/opera
include /etc/firejail/disable-mgmt.inc include /etc/firejail/disable-mgmt.inc
include /etc/firejail/disable-secret.inc include /etc/firejail/disable-secret.inc
include /etc/firejail/disable-common.inc opera include /etc/firejail/disable-common.inc
include /etc/firejail/disable-history.inc include /etc/firejail/disable-history.inc
netfilter netfilter
noroot noroot

View file

@ -1,6 +1,8 @@
# generic server profile # generic server profile
# it allows /sbin and /usr/sbin directories - this is where servers are installed # it allows /sbin and /usr/sbin directories - this is where servers are installed
include /etc/firejail/disable-mgmt.inc sbin noblacklist /sbin
noblacklist /usr/sbin
include /etc/firejail/disable-mgmt.inc
private private
private-dev private-dev
seccomp seccomp