aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLibravatar glitsj16 <glitsj16@users.noreply.github.com>2019-02-14 15:51:28 +0000
committerLibravatar GitHub <noreply@github.com>2019-02-14 15:51:28 +0000
commit3a69230a511c752a1b7c4aac250984acd43b5ac3 (patch)
treef4b53fc3b55a132bb0182457570ffaf88115da6a
parentRetire snap.profile (diff)
downloadfirejail-3a69230a511c752a1b7c4aac250984acd43b5ac3.tar.gz
firejail-3a69230a511c752a1b7c4aac250984acd43b5ac3.tar.zst
firejail-3a69230a511c752a1b7c4aac250984acd43b5ac3.zip
Delete snap.profile
-rw-r--r--etc/snap.profile62
1 files changed, 0 insertions, 62 deletions
diff --git a/etc/snap.profile b/etc/snap.profile
deleted file mode 100644
index ef4f3d3a6..000000000
--- a/etc/snap.profile
+++ /dev/null
@@ -1,62 +0,0 @@
1# Firejail profile for snap
2# Description: Install, configure, refresh and remove snap packages
3# This file is overwritten after every install/update
4quiet
5# Persistent local customizations
6include snap.local
7# Persistent global definitions
8include globals.local
9
10# Note: Snap packages have their own confinement mechanism relying on snapd and apparmor.
11# As such firejail is not able to deliver any additional sandboxing for snaps. This profile does sandbox
12# the snap tool which is used to interact with snap packages.
13# See https://docs.snapcraft.io/ for more detailed info.
14
15noblacklist ${HOME}/.snap
16noblacklist ${HOME}/snap
17noblacklist ${DOWNLOADS}
18
19noblacklist /var/cache/snapd
20noblacklist /var/lib/snapd
21noblacklist /var/snap
22
23mkdir ${HOME}/.snap
24mkdir ${HOME}/snap
25whitelist ${HOME}/.snap
26whitelist ${HOME}/snap
27
28include disable-common.inc
29include disable-devel.inc
30include disable-interpreters.inc
31include disable-passwdmgr.inc
32include disable-programs.inc
33include disable-xdg.inc
34
35caps.drop all
36ipc-namespace
37machine-id
38netfilter
39no3d
40nodbus
41nodvd
42nogroups
43nonewprivs
44noroot
45nosound
46notv
47nou2f
48novideo
49protocol unix,inet,inet6
50seccomp
51shell none
52
53disable-mnt
54private-bin snap
55private-dev
56private-etc group,passwd
57private-lib snapd
58private-tmp
59
60memory-deny-write-execute
61noexec ${HOME}
62noexec /tmp