aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLibravatar Jean Lucas <jean@4ray.co>2018-06-22 14:29:11 -0400
committerLibravatar Jean Lucas <jean@4ray.co>2018-06-22 14:33:36 -0400
commit325aad5dead4e42ae893ce1a9a3cbdda4c5c8f8e (patch)
tree72544208716731eaa170fafad08a659d2fd832d7
parentAmend Wire profiles (diff)
downloadfirejail-325aad5dead4e42ae893ce1a9a3cbdda4c5c8f8e.tar.gz
firejail-325aad5dead4e42ae893ce1a9a3cbdda4c5c8f8e.tar.zst
firejail-325aad5dead4e42ae893ce1a9a3cbdda4c5c8f8e.zip
Further restrict Wire
-rw-r--r--etc/wire-desktop.profile9
1 files changed, 8 insertions, 1 deletions
diff --git a/etc/wire-desktop.profile b/etc/wire-desktop.profile
index c0e0b3c4b..74d44efe3 100644
--- a/etc/wire-desktop.profile
+++ b/etc/wire-desktop.profile
@@ -13,6 +13,12 @@ include /etc/firejail/disable-interpreters.inc
13include /etc/firejail/disable-passwdmgr.inc 13include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc 14include /etc/firejail/disable-programs.inc
15 15
16mkdir ${HOME}/.config/Wire
17whitelist ${HOME}/.config/Wire
18whitelist ${DOWNLOADS}
19
20include /etc/firejail/whitelist-common.inc
21
16caps.drop all 22caps.drop all
17netfilter 23netfilter
18nodvd 24nodvd
@@ -28,6 +34,7 @@ shell none
28# it is not in PATH. To use Wire with firejail, run "firejail /opt/wire-desktop/wire-desktop" 34# it is not in PATH. To use Wire with firejail, run "firejail /opt/wire-desktop/wire-desktop"
29 35
30private-bin wire-desktop 36private-bin wire-desktop
31disable-mnt
32private-dev 37private-dev
38private-etc fonts,machine-id
39disable-mnt
33private-tmp 40private-tmp