aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLibravatar 1dnrr <42580241+1dnrr@users.noreply.github.com>2018-08-23 14:37:01 +0000
committerLibravatar Vincent43 <31109921+Vincent43@users.noreply.github.com>2018-08-23 15:37:01 +0100
commit467be071b48009351622997b9539d544d7053f8f (patch)
tree891572defc5c6e9f40c9c4ba63140754890f312b
parentMerge pull request #2094 from 1dnrr/patch-3 (diff)
downloadfirejail-467be071b48009351622997b9539d544d7053f8f.tar.gz
firejail-467be071b48009351622997b9539d544d7053f8f.tar.zst
firejail-467be071b48009351622997b9539d544d7053f8f.zip
Create pybitmessage.profile (#2092)
tested on fedora-28 with pybitmessage 0.6.3.2
-rw-r--r--etc/pybitmessage.profile49
1 files changed, 49 insertions, 0 deletions
diff --git a/etc/pybitmessage.profile b/etc/pybitmessage.profile
new file mode 100644
index 000000000..02c35b104
--- /dev/null
+++ b/etc/pybitmessage.profile
@@ -0,0 +1,49 @@
1# Firejail profile for pybitmessage
2# This file is overwritten after every install/update
3# Persistent local customizations
4include /etc/firejail/pybitmessage.local
5# Persistent global definitions
6include /etc/firejail/globals.local
7
8noblacklist /sbin
9noblacklist /usr/local/sbin
10noblacklist /usr/sbin
11
12# Allow python (blacklisted by disable-interpreters.inc)
13noblacklist ${PATH}/python2*
14noblacklist ${PATH}/python3*
15noblacklist /usr/lib/python2*
16noblacklist /usr/lib/python3*
17
18include /etc/firejail/disable-common.inc
19include /etc/firejail/disable-devel.inc
20include /etc/firejail/disable-passwdmgr.inc
21include /etc/firejail/disable-programs.inc
22include /etc/firejail/disable-interpreters.inc
23
24include /etc/firejail/whitelist-var-common.inc
25
26caps.drop all
27ipc-namespace
28netfilter
29no3d
30nodvd
31nogroups
32nonewprivs
33noroot
34nosound
35notv
36novideo
37protocol unix,inet,inet6,netlink
38seccomp
39shell none
40
41disable-mnt
42private-bin pybitmessage,python*,sh,ldconfig,env,bash,stat
43private-dev
44private-etc PyBitmessage,PyBitmessage.conf,Trolltech.conf,fonts,gtk-2.0,hosts,ld.so.cache,ld.so.preload,localtime,pki,resolv.conf,selinux,sni-qt.conf,system-fips,xdg,ca-certificates,ssl,pki,crypto-policies
45private-tmp
46
47memory-deny-write-execute
48noexec ${HOME}
49noexec /tmp