mirror of
https://github.com/netblue30/firejail.git
synced 2026-05-21 06:45:29 -06:00
commit
d222023bd1
32 changed files with 82 additions and 84 deletions
|
|
@ -1,4 +1,7 @@
|
|||
# Mathematica profile
|
||||
noblacklist ${HOME}/.Mathematica
|
||||
noblacklist ${HOME}/.Wolfram Research
|
||||
|
||||
mkdir ~/.Mathematica
|
||||
whitelist ~/.Mathematica
|
||||
mkdir ~/.Wolfram Research
|
||||
|
|
|
|||
|
|
@ -4,12 +4,9 @@ include /etc/firejail/disable-programs.inc
|
|||
include /etc/firejail/disable-devel.inc
|
||||
include /etc/firejail/disable-passwdmgr.inc
|
||||
|
||||
blacklist ${HOME}/.wine
|
||||
|
||||
caps.drop all
|
||||
seccomp
|
||||
protocol unix,inet,inet6
|
||||
netfilter
|
||||
noroot
|
||||
tracelog
|
||||
|
||||
|
|
|
|||
|
|
@ -4,10 +4,7 @@ include /etc/firejail/disable-programs.inc
|
|||
include /etc/firejail/disable-devel.inc
|
||||
include /etc/firejail/disable-passwdmgr.inc
|
||||
|
||||
blacklist ${HOME}/.wine
|
||||
|
||||
caps.drop all
|
||||
seccomp
|
||||
protocol unix,inet,inet6
|
||||
noroot
|
||||
|
||||
|
|
|
|||
|
|
@ -4,8 +4,6 @@ include /etc/firejail/disable-programs.inc
|
|||
include /etc/firejail/disable-devel.inc
|
||||
include /etc/firejail/disable-passwdmgr.inc
|
||||
|
||||
blacklist ${HOME}/.wine
|
||||
|
||||
whitelist ${HOME}/cherrytree
|
||||
mkdir ~/.config
|
||||
mkdir ~/.config/cherrytree
|
||||
|
|
|
|||
|
|
@ -4,8 +4,6 @@ include /etc/firejail/disable-programs.inc
|
|||
include /etc/firejail/disable-devel.inc
|
||||
include /etc/firejail/disable-passwdmgr.inc
|
||||
|
||||
blacklist ${HOME}/.wine
|
||||
|
||||
caps.drop all
|
||||
seccomp
|
||||
protocol unix,inet,inet6
|
||||
|
|
|
|||
|
|
@ -1,13 +1,12 @@
|
|||
# DeaDBeeF media player profile
|
||||
noblacklist ${HOME}/.config/deadbeef
|
||||
|
||||
include /etc/firejail/disable-common.inc
|
||||
include /etc/firejail/disable-programs.inc
|
||||
include /etc/firejail/disable-devel.inc
|
||||
include /etc/firejail/disable-passwdmgr.inc
|
||||
|
||||
blacklist ${HOME}/.wine
|
||||
|
||||
caps.drop all
|
||||
seccomp
|
||||
protocol unix,inet,inet6
|
||||
noroot
|
||||
|
||||
|
|
|
|||
|
|
@ -4,13 +4,9 @@ include /etc/firejail/disable-programs.inc
|
|||
include /etc/firejail/disable-devel.inc
|
||||
include /etc/firejail/disable-passwdmgr.inc
|
||||
|
||||
blacklist ${HOME}/.wine
|
||||
|
||||
caps.drop all
|
||||
seccomp
|
||||
protocol unix,inet,inet6
|
||||
netfilter
|
||||
noroot
|
||||
nosound
|
||||
|
||||
|
||||
|
|
|
|||
|
|
@ -1,10 +1,19 @@
|
|||
# various programs
|
||||
blacklist ${HOME}/.config/vlc
|
||||
blacklist ${HOME}/.remmina
|
||||
blacklist ${HOME}/.tconn
|
||||
blacklist ${HOME}/.FBReader
|
||||
blacklist ${HOME}/.wine
|
||||
blacklist ${HOME}/.Mathematica
|
||||
blacklist ${HOME}/.Wolfram Research
|
||||
blacklist ${HOME}/.config/mupen64plus
|
||||
blacklist ${HOME}/.config/transmission
|
||||
blacklist ${HOME}/.config/uGet
|
||||
|
||||
# Media players
|
||||
blacklist ${HOME}/.config/cmus
|
||||
blacklist ${HOME}/.config/deadbeef
|
||||
blacklist ${HOME}/.config/spotify
|
||||
blacklist ${HOME}/.config/vlc
|
||||
|
||||
# HTTP / FTP / Mail
|
||||
blacklist ${HOME}/.icedove
|
||||
|
|
@ -19,20 +28,14 @@ blacklist ${HOME}/.config/google-chrome-unstable
|
|||
blacklist ${HOME}/.config/opera
|
||||
blacklist ${HOME}/.config/opera-beta
|
||||
blacklist ${HOME}/.opera
|
||||
blacklist ~/.config/vivaldi
|
||||
blacklist ${HOME}/.config/vivaldi
|
||||
blacklist ${HOME}/.filezilla
|
||||
blacklist ${HOME}/.config/filezilla
|
||||
blacklist ~/.dillo
|
||||
|
||||
# cache
|
||||
blacklist ~/.cache/mozilla
|
||||
blacklist ~/.cache/chromium
|
||||
blacklist ~/.cache/google-chrome
|
||||
blacklist ~/.cache/google-chrome-beta
|
||||
blacklist ~/.cache/google-chrome-unstable
|
||||
blacklist ~/.cache/opera
|
||||
blacklist ~/.cache/opera-beta
|
||||
blacklist ~/.cache/vivaldi
|
||||
blacklist ${HOME}/.dillo
|
||||
blacklist ${HOME}/.conkeror.mozdev.org
|
||||
blacklist ${HOME}/.config/epiphany
|
||||
blacklist ${HOME}/.config/slimjet
|
||||
blacklist ${HOME}/.config/qutebrowser
|
||||
|
||||
# Instant Messaging
|
||||
blacklist ${HOME}/.config/hexchat
|
||||
|
|
@ -44,6 +47,12 @@ blacklist ${HOME}/.weechat
|
|||
blacklist ${HOME}/.config/xchat
|
||||
blacklist ${HOME}/.Skype
|
||||
blacklist ${HOME}/.config/tox
|
||||
blacklist ${HOME}/.TelegramDesktop
|
||||
|
||||
# Games
|
||||
blacklist ${HOME}/.hedgewars
|
||||
blacklist ${HOME}/.steam
|
||||
blacklist ${HOME}/.config/wesnoth
|
||||
|
||||
# Cryptocoins
|
||||
blacklist ${HOME}/.*coin
|
||||
|
|
@ -55,3 +64,27 @@ blacklist ${HOME}/.subversion
|
|||
blacklist ${HOME}/.gitconfig
|
||||
blacklist ${HOME}/.git-credential-cache
|
||||
|
||||
# cache
|
||||
blacklist ${HOME}/.cache/mozilla
|
||||
blacklist ${HOME}/.cache/chromium
|
||||
blacklist ${HOME}/.cache/google-chrome
|
||||
blacklist ${HOME}/.cache/google-chrome-beta
|
||||
blacklist ${HOME}/.cache/google-chrome-unstable
|
||||
blacklist ${HOME}/.cache/opera
|
||||
blacklist ${HOME}/.cache/opera-beta
|
||||
blacklist ${HOME}/.cache/vivaldi
|
||||
blacklist ${HOME}/.cache/epiphany
|
||||
blacklist ${HOME}/.cache/slimjet
|
||||
blacklist ${HOME}/.cache/qutebrowser
|
||||
blacklist ${HOME}/.cache/spotify
|
||||
blacklist ${HOME}/.cache/thunderbird
|
||||
blacklist ${HOME}/.cache/icedove
|
||||
blacklist ${HOME}/.cache/transmission
|
||||
blacklist ${HOME}/.cache/wesnoth
|
||||
|
||||
# share
|
||||
blacklist ${HOME}/.local/share/epiphany
|
||||
blacklist ${HOME}/.local/share/mupen64plus
|
||||
blacklist ${HOME}/.local/share/spotify
|
||||
blacklist ${HOME}/.local/share/steam
|
||||
blacklist ${HOME}/.local/share/wesnoth
|
||||
|
|
|
|||
|
|
@ -3,10 +3,7 @@ include /etc/firejail/disable-common.inc
|
|||
include /etc/firejail/disable-programs.inc
|
||||
include /etc/firejail/disable-passwdmgr.inc
|
||||
|
||||
blacklist ${HOME}/.wine
|
||||
|
||||
caps
|
||||
seccomp
|
||||
protocol unix,inet,inet6
|
||||
noroot
|
||||
|
||||
|
|
|
|||
|
|
@ -3,10 +3,7 @@ include /etc/firejail/disable-common.inc
|
|||
include /etc/firejail/disable-programs.inc
|
||||
include /etc/firejail/disable-devel.inc
|
||||
|
||||
blacklist ${HOME}/.wine
|
||||
|
||||
caps.drop all
|
||||
seccomp
|
||||
protocol unix,inet,inet6
|
||||
netfilter
|
||||
|
||||
|
|
|
|||
|
|
@ -1,4 +1,8 @@
|
|||
# Epiphany browser profile
|
||||
noblacklist ${HOME}/.config/epiphany
|
||||
noblacklist ${HOME}/.cache/epiphany
|
||||
noblacklist ${HOME}/.local/share/epiphany
|
||||
|
||||
include /etc/firejail/disable-common.inc
|
||||
include /etc/firejail/disable-programs.inc
|
||||
include /etc/firejail/disable-devel.inc
|
||||
|
|
|
|||
|
|
@ -4,11 +4,8 @@ include /etc/firejail/disable-programs.inc
|
|||
include /etc/firejail/disable-devel.inc
|
||||
include /etc/firejail/disable-passwdmgr.inc
|
||||
|
||||
blacklist ${HOME}/.wine
|
||||
|
||||
caps.drop all
|
||||
seccomp
|
||||
protocol unix,inet,inet6
|
||||
noroot
|
||||
nosound
|
||||
|
||||
|
|
|
|||
|
|
@ -1,16 +1,14 @@
|
|||
# fbreader ebook reader profile
|
||||
noblacklist ${HOME}/.FBReader
|
||||
|
||||
include /etc/firejail/disable-common.inc
|
||||
include /etc/firejail/disable-programs.inc
|
||||
include /etc/firejail/disable-devel.inc
|
||||
include /etc/firejail/disable-passwdmgr.inc
|
||||
|
||||
blacklist ${HOME}/.wine
|
||||
|
||||
caps.drop all
|
||||
seccomp
|
||||
protocol unix,inet,inet6
|
||||
netfilter
|
||||
noroot
|
||||
nosound
|
||||
|
||||
|
|
|
|||
|
|
@ -1,18 +1,14 @@
|
|||
# FileZilla ftp profile
|
||||
noblacklist ${HOME}/.filezilla
|
||||
noblacklist ${HOME}/.config/filezilla
|
||||
|
||||
include /etc/firejail/disable-common.inc
|
||||
include /etc/firejail/disable-programs.inc
|
||||
include /etc/firejail/disable-devel.inc
|
||||
|
||||
blacklist ${HOME}/.wine
|
||||
|
||||
caps.drop all
|
||||
seccomp
|
||||
protocol unix,inet,inet6
|
||||
noroot
|
||||
netfilter
|
||||
nosound
|
||||
|
||||
|
||||
|
||||
|
|
|
|||
|
|
@ -4,8 +4,6 @@ include /etc/firejail/disable-programs.inc
|
|||
include /etc/firejail/disable-devel.inc
|
||||
include /etc/firejail/disable-passwdmgr.inc
|
||||
|
||||
blacklist ${HOME}/.wine
|
||||
|
||||
caps.drop all
|
||||
seccomp
|
||||
protocol unix,inet,inet6
|
||||
|
|
|
|||
|
|
@ -1,4 +1,5 @@
|
|||
# whitelist profile for Hedgewars (game)
|
||||
noblacklist ${HOME}/.hedgewars
|
||||
|
||||
include /etc/firejail/disable-common.inc
|
||||
include /etc/firejail/disable-programs.inc
|
||||
|
|
|
|||
|
|
@ -1,17 +1,14 @@
|
|||
# kmail profile
|
||||
noblacklist ${HOME}/.gnupg
|
||||
|
||||
include /etc/firejail/disable-common.inc
|
||||
include /etc/firejail/disable-programs.inc
|
||||
include /etc/firejail/disable-devel.inc
|
||||
include /etc/firejail/disable-passwdmgr.inc
|
||||
|
||||
blacklist ${HOME}/.wine
|
||||
|
||||
caps.drop all
|
||||
seccomp
|
||||
protocol unix,inet,inet6,netlink
|
||||
netfilter
|
||||
noroot
|
||||
tracelog
|
||||
|
||||
|
||||
|
|
|
|||
|
|
@ -1,5 +1,8 @@
|
|||
# mupen64plus profile
|
||||
# manually whitelist ROM files
|
||||
noblacklist ${HOME}/.config/mupen64plus
|
||||
noblacklist ${HOME}/.local/share/mupen64plus
|
||||
|
||||
include /etc/firejail/disable-common.inc
|
||||
include /etc/firejail/disable-programs.inc
|
||||
include /etc/firejail/disable-devel.inc
|
||||
|
|
|
|||
|
|
@ -1,11 +1,10 @@
|
|||
# Pidgin profile
|
||||
noblacklist ${HOME}/.purple
|
||||
|
||||
include /etc/firejail/disable-common.inc
|
||||
include /etc/firejail/disable-programs.inc
|
||||
include /etc/firejail/disable-devel.inc
|
||||
|
||||
blacklist ${HOME}/.wine
|
||||
|
||||
caps.drop all
|
||||
seccomp
|
||||
protocol unix,inet,inet6
|
||||
|
|
|
|||
|
|
@ -4,13 +4,9 @@ include /etc/firejail/disable-programs.inc
|
|||
include /etc/firejail/disable-devel.inc
|
||||
include /etc/firejail/disable-passwdmgr.inc
|
||||
|
||||
blacklist ${HOME}/.wine
|
||||
|
||||
caps.drop all
|
||||
seccomp
|
||||
protocol unix,inet,inet6
|
||||
netfilter
|
||||
noroot
|
||||
nosound
|
||||
|
||||
|
||||
|
|
|
|||
|
|
@ -3,11 +3,8 @@ include /etc/firejail/disable-common.inc
|
|||
include /etc/firejail/disable-programs.inc
|
||||
include /etc/firejail/disable-devel.inc
|
||||
|
||||
blacklist ${HOME}/.wine
|
||||
|
||||
caps.drop all
|
||||
seccomp
|
||||
protocol unix,inet,inet6
|
||||
noroot
|
||||
netfilter
|
||||
|
||||
|
|
|
|||
|
|
@ -4,11 +4,8 @@ include /etc/firejail/disable-programs.inc
|
|||
include /etc/firejail/disable-devel.inc
|
||||
include /etc/firejail/disable-passwdmgr.inc
|
||||
|
||||
blacklist ${HOME}/.wine
|
||||
|
||||
caps.drop all
|
||||
seccomp
|
||||
protocol unix,inet,inet6
|
||||
noroot
|
||||
netfilter
|
||||
|
||||
|
|
|
|||
|
|
@ -1,4 +1,7 @@
|
|||
# Spotify media player profile
|
||||
noblacklist ${HOME}/.config/spotify
|
||||
noblacklist ${HOME}/.cache/spotify
|
||||
noblacklist ${HOME}/.local/share/spotify
|
||||
include /etc/firejail/disable-common.inc
|
||||
include /etc/firejail/disable-programs.inc
|
||||
include /etc/firejail/disable-devel.inc
|
||||
|
|
|
|||
|
|
@ -1,14 +1,12 @@
|
|||
# ssh client
|
||||
noblacklist ~/.ssh
|
||||
|
||||
include /etc/firejail/disable-common.inc
|
||||
include /etc/firejail/disable-programs.inc
|
||||
include /etc/firejail/disable-passwdmgr.inc
|
||||
|
||||
blacklist ${HOME}/.wine
|
||||
|
||||
caps.drop all
|
||||
seccomp
|
||||
protocol unix,inet,inet6
|
||||
netfilter
|
||||
noroot
|
||||
|
||||
|
|
|
|||
|
|
@ -4,8 +4,6 @@ include /etc/firejail/disable-programs.inc
|
|||
include /etc/firejail/disable-devel.inc
|
||||
include /etc/firejail/disable-passwdmgr.inc
|
||||
|
||||
blacklist ${HOME}/.wine
|
||||
|
||||
caps.drop all
|
||||
seccomp
|
||||
protocol unix,inet,inet6
|
||||
|
|
|
|||
|
|
@ -1,11 +1,12 @@
|
|||
# transmission-gtk profile
|
||||
noblacklist ${HOME}/.config/transmission
|
||||
noblacklist ${HOME}/.cache/transmission
|
||||
|
||||
include /etc/firejail/disable-common.inc
|
||||
include /etc/firejail/disable-programs.inc
|
||||
include /etc/firejail/disable-devel.inc
|
||||
include /etc/firejail/disable-passwdmgr.inc
|
||||
|
||||
blacklist ${HOME}/.wine
|
||||
|
||||
caps.drop all
|
||||
seccomp
|
||||
protocol unix,inet,inet6
|
||||
|
|
@ -13,7 +14,3 @@ netfilter
|
|||
noroot
|
||||
tracelog
|
||||
nosound
|
||||
|
||||
|
||||
|
||||
|
||||
|
|
|
|||
|
|
@ -1,11 +1,12 @@
|
|||
# transmission-qt profile
|
||||
noblacklist ${HOME}/.config/transmission
|
||||
noblacklist ${HOME}/.cache/transmission
|
||||
|
||||
include /etc/firejail/disable-common.inc
|
||||
include /etc/firejail/disable-programs.inc
|
||||
include /etc/firejail/disable-devel.inc
|
||||
include /etc/firejail/disable-passwdmgr.inc
|
||||
|
||||
blacklist ${HOME}/.wine
|
||||
|
||||
caps.drop all
|
||||
seccomp
|
||||
protocol unix,inet,inet6
|
||||
|
|
@ -13,5 +14,3 @@ netfilter
|
|||
noroot
|
||||
tracelog
|
||||
nosound
|
||||
|
||||
|
||||
|
|
|
|||
|
|
@ -1,4 +1,6 @@
|
|||
# uGet profile
|
||||
noblacklist ${HOME}/.config/uGet
|
||||
|
||||
include /etc/firejail/disable-common.inc
|
||||
include /etc/firejail/disable-programs.inc
|
||||
include /etc/firejail/disable-devel.inc
|
||||
|
|
|
|||
|
|
@ -1,12 +1,11 @@
|
|||
# VLC media player profile
|
||||
noblacklist ${HOME}/.config/vlc
|
||||
|
||||
include /etc/firejail/disable-common.inc
|
||||
include /etc/firejail/disable-programs.inc
|
||||
include /etc/firejail/disable-devel.inc
|
||||
include /etc/firejail/disable-passwdmgr.inc
|
||||
|
||||
blacklist ${HOME}/.wine
|
||||
|
||||
caps.drop all
|
||||
seccomp
|
||||
protocol unix,inet,inet6
|
||||
|
|
|
|||
|
|
@ -1,4 +1,8 @@
|
|||
# Whitelist-based profile for "Battle for Wesnoth" (game).
|
||||
noblacklist ${HOME}/.config/wesnoth
|
||||
noblacklist ${HOME}/.cache/wesnoth
|
||||
noblacklist ${HOME}/.local/share/wesnoth
|
||||
|
||||
include /etc/firejail/disable-common.inc
|
||||
include /etc/firejail/disable-programs.inc
|
||||
include /etc/firejail/disable-devel.inc
|
||||
|
|
|
|||
|
|
@ -2,6 +2,7 @@
|
|||
noblacklist ${HOME}/.steam
|
||||
noblacklist ${HOME}/.local/share/steam
|
||||
noblacklist ${HOME}/.wine
|
||||
|
||||
include /etc/firejail/disable-common.inc
|
||||
include /etc/firejail/disable-programs.inc
|
||||
include /etc/firejail/disable-devel.inc
|
||||
|
|
|
|||
|
|
@ -1,11 +1,10 @@
|
|||
# XChat IRC profile
|
||||
noblacklist ${HOME}/.config/xchat
|
||||
|
||||
include /etc/firejail/disable-common.inc
|
||||
include /etc/firejail/disable-programs.inc
|
||||
include /etc/firejail/disable-devel.inc
|
||||
|
||||
blacklist ${HOME}/.wine
|
||||
|
||||
caps.drop all
|
||||
seccomp
|
||||
protocol unix,inet,inet6
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue