aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLibravatar Vincent43 <31109921+Vincent43@users.noreply.github.com>2018-07-04 11:45:14 +0100
committerLibravatar GitHub <noreply@github.com>2018-07-04 11:45:14 +0100
commit169dbec1bd633a58e513b3d2374802db47c9d70b (patch)
tree9232463164f88d01d48c7d6806ab41274be860d1
parentFix geary profile - see issue #2018 (diff)
parentCreating the gradio profile and editing the geary profile (diff)
downloadfirejail-169dbec1bd633a58e513b3d2374802db47c9d70b.tar.gz
firejail-169dbec1bd633a58e513b3d2374802db47c9d70b.tar.zst
firejail-169dbec1bd633a58e513b3d2374802db47c9d70b.zip
Merge pull request #2025 from Bundy01/master
Creating the gradio profile and editing the geary profile
-rw-r--r--etc/geary.profile4
-rw-r--r--etc/gradio.profile39
2 files changed, 42 insertions, 1 deletions
diff --git a/etc/geary.profile b/etc/geary.profile
index 5c01dec69..872d21fdd 100644
--- a/etc/geary.profile
+++ b/etc/geary.profile
@@ -14,12 +14,14 @@ noblacklist ${HOME}/.local/share/geary
14mkdir ${HOME}/.gnupg 14mkdir ${HOME}/.gnupg
15mkdir ${HOME}/.config/geary 15mkdir ${HOME}/.config/geary
16mkdir ${HOME}/.local/share/geary 16mkdir ${HOME}/.local/share/geary
17
17whitelist ${HOME}/.gnupg 18whitelist ${HOME}/.gnupg
18whitelist ${HOME}/.config/geary 19whitelist ${HOME}/.config/geary
19whitelist ${HOME}/.local/share/geary 20whitelist ${HOME}/.local/share/geary
21
20include /etc/firejail/whitelist-common.inc 22include /etc/firejail/whitelist-common.inc
21 23
22ignore dbus 24ignore nodbus
23ignore private-tmp 25ignore private-tmp
24 26
25read-only ${HOME}/.config/mimeapps.list 27read-only ${HOME}/.config/mimeapps.list
diff --git a/etc/gradio.profile b/etc/gradio.profile
new file mode 100644
index 000000000..1a7ff60ed
--- /dev/null
+++ b/etc/gradio.profile
@@ -0,0 +1,39 @@
1# Firejail profile for gradio
2# This file is overwritten after every install/update
3# Persistent local customizations
4include /etc/firejail/gradio.local
5# Persistent global definitions
6include /etc/firejail/globals.local
7
8noblacklist ${HOME}/.local/share/gradio
9mkdir ${HOME}/.local/share/gradio
10whitelist ${HOME}/.local/share/gradio
11whitelist ${HOME}/.cache/gradio
12
13include /etc/firejail/disable-common.inc
14include /etc/firejail/disable-devel.inc
15include /etc/firejail/disable-interpreters.inc
16include /etc/firejail/disable-passwdmgr.inc
17include /etc/firejail/disable-programs.inc
18
19include /etc/firejail/whitelist-common.inc
20include /etc/firejail/whitelist-var-common.inc
21
22caps.drop all
23netfilter
24no3d
25nodvd
26nogroups
27nonewprivs
28noroot
29notv
30novideo
31protocol unix,inet,inet6
32seccomp
33shell none
34
35private-etc asound.conf,ca-certificates,fonts,host.conf,hostname,hosts,pulse,resolv.conf,ssl,pki,crypto-policies,gtk-3.0,xdg,machine-id
36private-tmp
37
38noexec ${HOME}
39noexec /tmp