aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLibravatar SkewedZeppelin <8296104+SkewedZeppelin@users.noreply.github.com>2018-06-14 07:56:27 -0400
committerLibravatar GitHub <noreply@github.com>2018-06-14 07:56:27 -0400
commit88059eb5df27fd13dcf5859953f848a3900800bb (patch)
tree2614b0f0638c4cfa665eacafa4d7ffe6d85fa351
parentmerges (diff)
parentInclude whitelist-var-common and add nodbus (diff)
downloadfirejail-88059eb5df27fd13dcf5859953f848a3900800bb.tar.gz
firejail-88059eb5df27fd13dcf5859953f848a3900800bb.tar.zst
firejail-88059eb5df27fd13dcf5859953f848a3900800bb.zip
Merge pull request #1996 from flacks/profiles/gnome-mpv
Add gnome-mpv profile
-rw-r--r--etc/disable-programs.inc1
-rw-r--r--etc/gnome-mpv.profile32
2 files changed, 33 insertions, 0 deletions
diff --git a/etc/disable-programs.inc b/etc/disable-programs.inc
index 020d493c7..ce27116ba 100644
--- a/etc/disable-programs.inc
+++ b/etc/disable-programs.inc
@@ -132,6 +132,7 @@ blacklist ${HOME}/.config/geeqie
132blacklist ${HOME}/.config/ghb 132blacklist ${HOME}/.config/ghb
133blacklist ${HOME}/.config/globaltime 133blacklist ${HOME}/.config/globaltime
134blacklist ${HOME}/.config/gnome-mplayer 134blacklist ${HOME}/.config/gnome-mplayer
135blacklist ${HOME}/.config/gnome-mpv
135blacklist ${HOME}/.config/google-chrome 136blacklist ${HOME}/.config/google-chrome
136blacklist ${HOME}/.config/google-chrome-beta 137blacklist ${HOME}/.config/google-chrome-beta
137blacklist ${HOME}/.config/google-chrome-unstable 138blacklist ${HOME}/.config/google-chrome-unstable
diff --git a/etc/gnome-mpv.profile b/etc/gnome-mpv.profile
new file mode 100644
index 000000000..e834e8ec7
--- /dev/null
+++ b/etc/gnome-mpv.profile
@@ -0,0 +1,32 @@
1# Firejail profile for gnome-mpv
2# This file is overwritten after every install/update
3# Persistent local customizations
4include /etc/firejail/gnome-mpv.local
5# Persistent global definitions
6include /etc/firejail/globals.local
7
8noblacklist ${HOME}/.config/gnome-mpv
9
10include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-interpreters.inc
13include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc
15
16include /etc/firejail/whitelist-var-common.inc
17
18caps.drop all
19nodbus
20nogroups
21nonewprivs
22noroot
23protocol unix,inet,inet6
24seccomp
25shell none
26
27private-bin gnome-mpv
28private-dev
29private-tmp
30
31noexec ${HOME}
32noexec /tmp