summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLibravatar Fred Barclay <Fred-Barclay@users.noreply.github.com>2017-04-17 02:37:02 +0000
committerLibravatar GitHub <noreply@github.com>2017-04-17 02:37:02 +0000
commit9eb8c8463642e1d595968132bfbb969c3d64e978 (patch)
tree21cc1369415a452148089b5d0b502a9d752e2607
parentCleanup for .config/qt5ct blacklist (part 2) and tightening (diff)
parentAdd a profile for Arduino IDE (diff)
downloadfirejail-9eb8c8463642e1d595968132bfbb969c3d64e978.tar.gz
firejail-9eb8c8463642e1d595968132bfbb969c3d64e978.tar.zst
firejail-9eb8c8463642e1d595968132bfbb969c3d64e978.zip
Merge pull request #1223 from SpotComms/arduino
Add a profile for Arduino IDE
-rw-r--r--etc/arduino.profile28
1 files changed, 28 insertions, 0 deletions
diff --git a/etc/arduino.profile b/etc/arduino.profile
new file mode 100644
index 000000000..e80222bb6
--- /dev/null
+++ b/etc/arduino.profile
@@ -0,0 +1,28 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/arduino.local
4
5# Firejail profile for arduino
6noblacklist ${HOME}/.arduino15
7noblacklist ${HOME}/Arduino
8
9include /etc/firejail/disable-common.inc
10include /etc/firejail/disable-programs.inc
11include /etc/firejail/disable-passwdmgr.inc
12include /etc/firejail/disable-devel.inc
13
14caps.drop all
15netfilter
16no3d
17nogroups
18nonewprivs
19noroot
20nosound
21protocol unix,inet,inet6
22seccomp
23shell none
24
25private-tmp
26
27noexec ${HOME}
28noexec /tmp