summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLibravatar glitsj16 <glitsj16@users.noreply.github.com>2019-05-02 06:17:33 +0000
committerLibravatar GitHub <noreply@github.com>2019-05-02 06:17:33 +0000
commitad31bb726b8a0c7934563c8abe99865a50d1946c (patch)
treedb5003ac3bd2d3718df7f0ebd1c56565c9197186
parentAdd Bitwarden profile (#2673) (diff)
downloadfirejail-ad31bb726b8a0c7934563c8abe99865a50d1946c.tar.gz
firejail-ad31bb726b8a0c7934563c8abe99865a50d1946c.tar.zst
firejail-ad31bb726b8a0c7934563c8abe99865a50d1946c.zip
Refactor min as chromium redirect profile (#2676)
-rw-r--r--etc/min.profile43
1 files changed, 2 insertions, 41 deletions
diff --git a/etc/min.profile b/etc/min.profile
index c89df0a95..7f3aeab44 100644
--- a/etc/min.profile
+++ b/etc/min.profile
@@ -8,47 +8,8 @@ include globals.local
8 8
9noblacklist ${HOME}/.config/Min 9noblacklist ${HOME}/.config/Min
10 10
11noblacklist ${HOME}/.pki
12noblacklist ${HOME}/.local/share/pki
13
14# noexec ${HOME} breaks DRM binaries.
15?BROWSER_ALLOW_DRM: ignore noexec ${HOME}
16
17include disable-common.inc
18include disable-devel.inc
19include disable-exec.inc
20include disable-interpreters.inc
21include disable-programs.inc
22
23mkdir ${HOME}/.pki
24mkdir ${HOME}/.config/Min 11mkdir ${HOME}/.config/Min
25mkdir ${HOME}/.local/share/pki
26whitelist ${DOWNLOADS}
27whitelist ${HOME}/.pki
28whitelist ${HOME}/.config/Min 12whitelist ${HOME}/.config/Min
29whitelist ${HOME}/.local/share/pki
30include whitelist-common.inc
31include whitelist-var-common.inc
32
33caps.drop all
34netfilter
35nodbus
36nodvd
37nogroups
38nonewprivs
39noroot
40notv
41nou2f
42protocol unix,inet,inet6
43seccomp
44shell none
45
46disable-mnt
47# private-bin min
48private-cache
49private-dev
50# private-etc below works fine on most distributions. There are some problems on CentOS.
51private-etc alternatives,ca-certificates,ssl,machine-id,dconf,selinux,passwd,group,hostname,hosts,localtime,nsswitch.conf,resolv.conf,xdg,gtk-2.0,gtk-3.0,X11,pango,fonts,mime.types,mailcap,asound.conf,pulse,pki,crypto-policies,ld.so.cache
52private-tmp
53 13
54# memory-deny-write-execute 14# Redirect
15include chromium-common.profile