diff --git a/etc/inc/disable-programs.inc b/etc/inc/disable-programs.inc index e78f15e1004..254d05e8e6b 100644 --- a/etc/inc/disable-programs.inc +++ b/etc/inc/disable-programs.inc @@ -1120,6 +1120,7 @@ blacklist ${HOME}/TeamSpeak3-Client-linux_x86 blacklist ${HOME}/hyperrogue.ini blacklist ${HOME}/i2p blacklist ${HOME}/mps +blacklist ${HOME}/openstego.ini blacklist ${HOME}/wallet.dat blacklist ${HOME}/yt-dlp.conf blacklist ${RUNUSER}/*firefox* diff --git a/etc/profile-m-z/openstego.profile b/etc/profile-m-z/openstego.profile new file mode 100644 index 00000000000..f6622b38d77 --- /dev/null +++ b/etc/profile-m-z/openstego.profile @@ -0,0 +1,58 @@ +# Firejail profile for OpenStego +# Description: Steganography application that provides data hiding and watermarking functionality +# This file is overwritten after every install/update +# Persistent local customizations +include openstego.local +# Persistent global definitions +include globals.local + +noblacklist ${HOME}/openstego.ini + +# Allow java (blacklisted by disable-devel.inc) +include allow-java.inc + +include disable-common.inc +include disable-devel.inc +include disable-exec.inc +include disable-interpreters.inc +include disable-proc.inc +include disable-programs.inc + +mkfile ${HOME}/openstego.ini +whitelist ${HOME}/openstego.ini +whitelist ${HOME}/.java +whitelist ${PICTURES} +whitelist ${DOCUMENTS} +whitelist ${DESKTOP} +whitelist /usr/share/java +include whitelist-common.inc +include whitelist-run-common.inc +include whitelist-runuser-common.inc +include whitelist-usr-share-common.inc +include whitelist-var-common.inc + +caps.drop all +machine-id +net none +no3d +nogroups +noinput +nonewprivs +noroot +nosound +notv +nou2f +novideo +seccomp +seccomp.block-secondary +shell none +tracelog + +disable-mnt +private-bin bash,dirname,openstego,readlink,sh +private-cache +private-dev +private-tmp + +dbus-user none +dbus-system none diff --git a/src/firecfg/firecfg.config b/src/firecfg/firecfg.config index 740095ee728..117c6f6aea5 100644 --- a/src/firecfg/firecfg.config +++ b/src/firecfg/firecfg.config @@ -616,6 +616,7 @@ openmw-launcher openoffice.org openshot openshot-qt +openstego openttd opera opera-beta