aboutsummaryrefslogtreecommitdiffstats
path: root/etc-fixes
diff options
context:
space:
mode:
authorLibravatar Fred-Barclay <Fred-Barclay@users.noreply.github.com>2018-05-13 12:10:25 -0500
committerLibravatar Fred-Barclay <Fred-Barclay@users.noreply.github.com>2018-05-13 12:10:25 -0500
commit1f45aa83bde6fa9fae955f6d25b366552bb1dcc4 (patch)
treee130599bec831bc2aaa3b4ff0490f9334054bf16 /etc-fixes
parentprofile fixes for 0.9.52 (Ubuntu 18.04) in etc-fixes directory (diff)
downloadfirejail-1f45aa83bde6fa9fae955f6d25b366552bb1dcc4.tar.gz
firejail-1f45aa83bde6fa9fae955f6d25b366552bb1dcc4.tar.zst
firejail-1f45aa83bde6fa9fae955f6d25b366552bb1dcc4.zip
Firefox profile fix for 0.9.38 (Ubuntu 16.04) in etc-fixes/
Seccomp filter lifted from 0.9.54 version. Cosmetic errors occur for unrecognised options (such as @clock) but do not affect sandbox.
Diffstat (limited to 'etc-fixes')
-rw-r--r--etc-fixes/0.9.38/firefox.profile29
1 files changed, 29 insertions, 0 deletions
diff --git a/etc-fixes/0.9.38/firefox.profile b/etc-fixes/0.9.38/firefox.profile
new file mode 100644
index 000000000..c5c47d1b5
--- /dev/null
+++ b/etc-fixes/0.9.38/firefox.profile
@@ -0,0 +1,29 @@
1# Firejail profile for Mozilla Firefox (Iceweasel in Debian)
2noblacklist ${HOME}/.mozilla
3include /etc/firejail/disable-mgmt.inc
4include /etc/firejail/disable-secret.inc
5include /etc/firejail/disable-common.inc
6include /etc/firejail/disable-devel.inc
7caps.drop all
8seccomp.drop @clock,@cpu-emulation,@debug,@module,@obsolete,@raw-io,@reboot,@resources,@swap,acct,add_key,bpf,fanotify_init,io_cancel,io_destroy,io_getevents,io_setup,io_submit,ioprio_set,kcmp,keyctl,mount,name_to_handle_at,nfsservctl,ni_syscall,open_by_handle_at,personality,pivot_root,process_vm_readv,ptrace,remap_file_pages,request_key,setdomainname,sethostname,syslog,umount,umount2,userfaultfd,vhangup,vmsplice
9protocol unix,inet,inet6,netlink
10netfilter
11# tracelog
12noroot
13whitelist ${DOWNLOADS}
14whitelist ~/.mozilla
15whitelist ~/.cache/mozilla/firefox
16whitelist ~/dwhelper
17whitelist ~/.zotero
18whitelist ~/.lastpass
19whitelist ~/.vimperatorrc
20whitelist ~/.vimperator
21whitelist ~/.pentadactylrc
22whitelist ~/.pentadactyl
23whitelist ~/.keysnail.js
24whitelist ~/.config/gnome-mplayer
25whitelist ~/.cache/gnome-mplayer/plugin
26include /etc/firejail/whitelist-common.inc
27
28# experimental features
29#private-etc passwd,group,hostname,hosts,localtime,nsswitch.conf,resolv.conf,gtk-2.0,pango,fonts,iceweasel,firefox,adobe,mime.types,mailcap,asound.conf,pulse