Skip to content

Commit 142a213

Browse files
authored
New profile: sniffnet (#5920)
* disable-programs.inc: add sniffnet support * Create sniffnet.profile * firecfg.config: add sniffnet support
1 parent a95a742 commit 142a213

File tree

3 files changed

+51
-0
lines changed

3 files changed

+51
-0
lines changed

etc/inc/disable-programs.inc

+1
Original file line numberDiff line numberDiff line change
@@ -624,6 +624,7 @@ blacklist ${HOME}/.config/slimjet
624624
blacklist ${HOME}/.config/smplayer
625625
blacklist ${HOME}/.config/smtube
626626
blacklist ${HOME}/.config/smuxi
627+
blacklist ${HOME}/.config/sniffnet
627628
blacklist ${HOME}/.config/snox
628629
blacklist ${HOME}/.config/sound-juicer
629630
blacklist ${HOME}/.config/specialmailcollectionsrc

etc/profile-m-z/sniffnet.profile

+49
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,49 @@
1+
# Firejail profile for sniffnet
2+
# Description: Network traffic monitor
3+
# This file is overwritten after every install/update
4+
# Persistent local customizations
5+
include sniffnet.local
6+
# Persistent global definitions
7+
include globals.local
8+
9+
noblacklist ${HOME}/.config/sniffnet
10+
11+
include disable-common.inc
12+
include disable-devel.inc
13+
include disable-exec.inc
14+
include disable-interpreters.inc
15+
include disable-proc.inc
16+
include disable-programs.inc
17+
include disable-xdg.inc
18+
19+
include whitelist-common.inc
20+
include whitelist-run-common.inc
21+
include whitelist-runuser-common.inc
22+
include whitelist-usr-share-common.inc
23+
include whitelist-var-common.inc
24+
25+
apparmor
26+
#caps.drop all
27+
caps.keep net_admin,net_raw
28+
netfilter
29+
nodvd
30+
nogroups
31+
noinput
32+
# nonewprivs - breaks network traffic capture for unprivileged users
33+
# noroot
34+
notv
35+
nou2f
36+
novideo
37+
#seccomp
38+
tracelog
39+
40+
disable-mnt
41+
#private-bin sniffnet
42+
# private-dev prevents (some) interfaces from being shown.
43+
private-etc @network,@tls-ca
44+
private-tmp
45+
46+
dbus-user none
47+
dbus-system none
48+
49+
#restrict-namespaces

src/firecfg/firecfg.config

+1
Original file line numberDiff line numberDiff line change
@@ -774,6 +774,7 @@ slashem
774774
smplayer
775775
smtube
776776
smuxi-frontend-gnome
777+
sniffnet
777778
snox
778779
soffice
779780
sol

0 commit comments

Comments
 (0)