diff --git a/README b/README index 71dac1fd4..d41ae967a 100644 --- a/README +++ b/README @@ -49,6 +49,8 @@ Committers Firejail Authors (alphabetical order) +7twin (https://github.com/7twin_ + - fix typos 1dnrr (https://github.com/1dnrr) - add pybitmessage profile Aidan Gauland (https://github.com/aidalgol) @@ -439,6 +441,7 @@ n1trux (https://github.com/n1trux) - fix flashpeak-slimjet profile typos Nick Fox (https://github.com/njfox) - add a profile alias for code-oss + - add code-oss config directory NickMolloy (https://github.com/NickMolloy) - ARP address length fix Niklas Haas (https://github.com/haasn) @@ -450,6 +453,7 @@ Ondra Nekola (https://github.com/satai) Lorenzo "Palinuro" Faletra (https://github.com/PalinuroSec) - prevent thunderbird conflicts when firefox is running - add join-or-start to pluma to open multiple files in tabs + - fixes to keepassxc, thunderbird and pluma Panzerfather (https://github.com/Panzerfather) - allow eog to access user's trash Patrick Toomey (https://sourceforge.net/u/ptoomey/profile/) @@ -478,6 +482,8 @@ Petter Reinholdtsen (pere@hungry.com) PharmaceuticalCobweb (https://github.com/PharmaceuticalCobweb) - fix quiterss profile - added profile for gnome-ring +pianoslum (https://github.com/pianoslum) + - nodbus breaking evince two-page-view warning pirate486743186 (https://github.com/pirate486743186) - KMail profile - mpsyt profile @@ -553,6 +559,8 @@ sarneaud (https://github.com/sarneaud) - various enhancements and bug fixes Sergey Alirzaev (https://github.com/l29ah) - firejail.h enum fix +Tobias Schmidl (https://github.com/schtobia) + - added profile for webui-aria2 Simon Peter (https://github.com/probonopd) - set $APPIMAGE and $APPDIR environment variables - AppImage version detection @@ -715,6 +723,12 @@ veloute (https://github.com/veloute) - fixed discord profile - fixes for various profiles - removed vim and ranger from firecfg + - fixing keepassxc auto-type, noexec /tmp + - fix ipc-namespace prblem in file-roller + - fix exiftool, viewnior, aria2c, ffmpegthumbnailer + - fix pavucontrol (ipcnamespace) + - fix gnuchess + - add anki profile Vincent43 (https://github.com/Vincent43) - apparmor enhancements vismir2 (https://github.com/vismir2) diff --git a/etc/0ad.profile b/etc/0ad.profile index 674fb2c6a..88c9c453b 100644 --- a/etc/0ad.profile +++ b/etc/0ad.profile @@ -12,6 +12,7 @@ noblacklist ${HOME}/.local/share/0ad include disable-common.inc include disable-devel.inc +include disable-exec.inc include disable-interpreters.inc include disable-passwdmgr.inc include disable-programs.inc @@ -44,5 +45,3 @@ private-bin 0ad,pyrogenesis,sh,which private-dev private-tmp -noexec ${HOME} -noexec /tmp diff --git a/etc/2048-qt.profile b/etc/2048-qt.profile index 10f354f19..2347039a6 100644 --- a/etc/2048-qt.profile +++ b/etc/2048-qt.profile @@ -11,6 +11,7 @@ noblacklist ${HOME}/.config/xiaoyong include disable-common.inc include disable-devel.inc +include disable-exec.inc include disable-interpreters.inc include disable-passwdmgr.inc include disable-programs.inc @@ -39,6 +40,3 @@ shell none disable-mnt private-dev private-tmp - -noexec ${HOME} -noexec /tmp diff --git a/etc/calibre.profile b/etc/calibre.profile index 5c7d3e1e7..363e9191d 100644 --- a/etc/calibre.profile +++ b/etc/calibre.profile @@ -12,6 +12,7 @@ noblacklist ${DOCUMENTS} include disable-common.inc include disable-devel.inc +include disable-exec.inc include disable-passwdmgr.inc include disable-programs.inc include disable-xdg.inc @@ -36,6 +37,3 @@ tracelog private-dev private-tmp - -noexec ${HOME} -noexec /tmp diff --git a/etc/cherrytree.profile b/etc/cherrytree.profile index 22bda418a..44ef12aa2 100644 --- a/etc/cherrytree.profile +++ b/etc/cherrytree.profile @@ -19,6 +19,7 @@ noblacklist /usr/local/lib/python3* include disable-common.inc include disable-devel.inc +include disable-exec.inc include disable-interpreters.inc include disable-passwdmgr.inc include disable-programs.inc @@ -44,5 +45,3 @@ private-cache private-dev private-tmp -noexec ${HOME} -noexec /tmp diff --git a/etc/eom.profile b/etc/eom.profile index a6007f99c..745e650aa 100644 --- a/etc/eom.profile +++ b/etc/eom.profile @@ -13,6 +13,7 @@ noblacklist ${HOME}/.steam include disable-common.inc include disable-devel.inc +include disable-exec.inc include disable-interpreters.inc include disable-passwdmgr.inc include disable-programs.inc @@ -43,5 +44,3 @@ private-lib private-tmp #memory-deny-write-execute - breaks on Arch -noexec ${HOME} -noexec /tmp diff --git a/etc/evince.profile b/etc/evince.profile index 27b59506b..b1f984784 100644 --- a/etc/evince.profile +++ b/etc/evince.profile @@ -11,6 +11,7 @@ noblacklist ${DOCUMENTS} include disable-common.inc include disable-devel.inc +include disable-exec.inc include disable-interpreters.inc include disable-passwdmgr.inc include disable-programs.inc @@ -46,5 +47,3 @@ private-lib evince,gdk-pixbuf-2.*,gio,gvfs/libgvfscommon.so,libdjvulibre.so.*,li private-tmp # memory-deny-write-execute - might break application (https://github.com/netblue30/firejail/issues/1803) -noexec ${HOME} -noexec /tmp diff --git a/etc/gnome-chess.profile b/etc/gnome-chess.profile index dc5b62428..ed159fc82 100644 --- a/etc/gnome-chess.profile +++ b/etc/gnome-chess.profile @@ -10,6 +10,7 @@ noblacklist ${HOME}/.local/share/gnome-chess include disable-common.inc include disable-devel.inc +include disable-exec.iinc include disable-interpreters.inc include disable-passwdmgr.inc include disable-programs.inc @@ -37,6 +38,3 @@ private-bin fairymax,gnome-chess,hoichess,gnuchess private-dev private-etc alternatives,fonts,gnome-chess private-tmp - -noexec ${HOME} -noexec /tmp diff --git a/etc/gnome-contacts.profile b/etc/gnome-contacts.profile index 2a13b3b27..ac6d82451 100644 --- a/etc/gnome-contacts.profile +++ b/etc/gnome-contacts.profile @@ -10,6 +10,7 @@ noblacklist ${DOCUMENTS} include disable-common.inc include disable-devel.inc +include disable-exec.inc include disable-interpreters.inc include disable-passwdmgr.inc include disable-programs.inc @@ -35,5 +36,3 @@ disable-mnt private-dev private-tmp -noexec ${HOME} -noexec /tmp diff --git a/etc/hexchat.profile b/etc/hexchat.profile index e8abf4b31..ee70e6655 100644 --- a/etc/hexchat.profile +++ b/etc/hexchat.profile @@ -19,6 +19,7 @@ noblacklist /usr/local/lib/python3* include disable-common.inc include disable-devel.inc +include disable-exec.inc include disable-interpreters.inc include disable-passwdmgr.inc include disable-programs.inc @@ -53,5 +54,3 @@ private-dev private-tmp # memory-deny-write-execute - breaks python -noexec ${HOME} -noexec /tmp diff --git a/etc/leafpad.profile b/etc/leafpad.profile index 47ea5606a..56a792c8e 100644 --- a/etc/leafpad.profile +++ b/etc/leafpad.profile @@ -10,6 +10,7 @@ noblacklist ${HOME}/.config/leafpad include disable-common.inc include disable-devel.inc +include disable-exec.inc include disable-interpreters.inc include disable-passwdmgr.inc include disable-programs.inc @@ -36,5 +37,3 @@ private-dev private-lib private-tmp -noexec ${HOME} -noexec /tmp diff --git a/etc/mousepad.profile b/etc/mousepad.profile index 4500f74a5..3b9807b28 100644 --- a/etc/mousepad.profile +++ b/etc/mousepad.profile @@ -10,6 +10,7 @@ noblacklist ${HOME}/.config/Mousepad include disable-common.inc include disable-devel.inc +include disable-exec.inc include disable-interpreters.inc include disable-passwdmgr.inc include disable-programs.inc diff --git a/etc/ping.profile b/etc/ping.profile index bdd29c1a1..66574bab5 100644 --- a/etc/ping.profile +++ b/etc/ping.profile @@ -8,6 +8,7 @@ include globals.local include disable-common.inc include disable-devel.inc +include disable-exec.inc include disable-interpreters.inc include disable-passwdmgr.inc include disable-programs.inc @@ -46,5 +47,3 @@ private-tmp # memory-deny-write-execute is built using seccomp; nonewprivs will kill it #memory-deny-write-execute -noexec ${HOME} -noexec /tmp diff --git a/etc/pinta.profile b/etc/pinta.profile index 3dfe3cc1b..8151bc98f 100644 --- a/etc/pinta.profile +++ b/etc/pinta.profile @@ -12,6 +12,7 @@ noblacklist ${PICTURES} include disable-common.inc include disable-devel.inc +include disable-exec.inc include disable-interpreters.inc include disable-passwdmgr.inc include disable-programs.inc @@ -37,5 +38,3 @@ private-dev private-cache private-tmp -noexec ${HOME} -noexec /tmp diff --git a/etc/sol.profile b/etc/sol.profile index c194eed05..ea1620b31 100644 --- a/etc/sol.profile +++ b/etc/sol.profile @@ -7,6 +7,7 @@ include globals.local include disable-common.inc include disable-devel.inc +include disable-exec.inc include disable-interpreters.inc include disable-passwdmgr.inc include disable-programs.inc @@ -40,5 +41,3 @@ private-dev private-tmp # memory-deny-write-execute -noexec ${HOME} -noexec /tmp diff --git a/etc/virtualbox.profile b/etc/virtualbox.profile index 1ef44dd5c..45f9949f3 100644 --- a/etc/virtualbox.profile +++ b/etc/virtualbox.profile @@ -14,6 +14,7 @@ noblacklist /usr/lib/virtualbox noblacklist /usr/lib64/virtualbox include disable-common.inc +include disable-exec.inc include disable-passwdmgr.inc include disable-programs.inc diff --git a/etc/warzone2100.profile b/etc/warzone2100.profile index 816f2236c..85cbc5e43 100644 --- a/etc/warzone2100.profile +++ b/etc/warzone2100.profile @@ -10,6 +10,7 @@ noblacklist ${HOME}/.warzone2100-3.* include disable-common.inc include disable-devel.inc +include disable-exec.inc include disable-interpreters.inc include disable-passwdmgr.inc include disable-programs.inc diff --git a/etc/wget.profile b/etc/wget.profile index c0a6f0d21..a7ef32e2c 100644 --- a/etc/wget.profile +++ b/etc/wget.profile @@ -13,6 +13,7 @@ noblacklist ${HOME}/.wget-hsts noblacklist ${HOME}/.wgetrc include disable-common.inc +include disable-exec.inc include disable-passwdmgr.inc include disable-programs.inc @@ -38,5 +39,3 @@ private-dev # private-etc alternatives,resolv.conf,ca-certificates,ssl,pki,crypto-policies # private-tmp -noexec ${HOME} -noexec /tmp diff --git a/etc/xcalc.profile b/etc/xcalc.profile index 1941787b1..0ad423d30 100644 --- a/etc/xcalc.profile +++ b/etc/xcalc.profile @@ -7,6 +7,7 @@ include globals.local include disable-common.inc include disable-devel.inc +include disable-exec.inc include disable-interpreters.inc include disable-passwdmgr.inc include disable-programs.inc @@ -38,5 +39,3 @@ private-dev private-lib private-tmp -noexec ${HOME} -noexec /tmp