aboutsummaryrefslogtreecommitdiffstats
path: root/etc/akonadi_control.profile
diff options
context:
space:
mode:
authorLibravatar netblue30 <netblue30@yahoo.com>2018-03-24 14:55:55 -0400
committerLibravatar netblue30 <netblue30@yahoo.com>2018-03-24 14:55:55 -0400
commit5fe509d56cfa37e8505e83dd7e37776c1ad550de (patch)
treea0570bdca8b51871d8e79f1692be4cd77b4f1873 /etc/akonadi_control.profile
parentfix sandbox name resolution, issue #1819 (diff)
parentcleanup (diff)
downloadfirejail-5fe509d56cfa37e8505e83dd7e37776c1ad550de.tar.gz
firejail-5fe509d56cfa37e8505e83dd7e37776c1ad550de.tar.zst
firejail-5fe509d56cfa37e8505e83dd7e37776c1ad550de.zip
Merge branch 'master' of http://github.com/netblue30/firejail
Diffstat (limited to 'etc/akonadi_control.profile')
-rw-r--r--etc/akonadi_control.profile44
1 files changed, 44 insertions, 0 deletions
diff --git a/etc/akonadi_control.profile b/etc/akonadi_control.profile
new file mode 100644
index 000000000..fb299a518
--- /dev/null
+++ b/etc/akonadi_control.profile
@@ -0,0 +1,44 @@
1# Firejail profile for akonadi_control
2# Persistent local customizations
3include /etc/firejail/akonadi_control.local
4# Persistent global definitions
5include /etc/firejail/globals.local
6
7noblacklist ${HOME}/.cache/akonadi*
8noblacklist ${HOME}/.config/akonadi*
9noblacklist ${HOME}/.config/baloorc
10noblacklist ${HOME}/.local/share/akonadi/*
11noblacklist ${HOME}/.local/share/contacts
12noblacklist ${HOME}/.local/share/local-mail
13noblacklist /usr/sbin
14
15include /etc/firejail/disable-common.inc
16include /etc/firejail/disable-devel.inc
17include /etc/firejail/disable-passwdmgr.inc
18include /etc/firejail/disable-programs.inc
19
20include /etc/firejail/whitelist-var-common.inc
21
22# depending on your setup it might be possible to
23# enable some of the commented options below
24
25caps.drop all
26ipc-namespace
27no3d
28netfilter
29nodvd
30nogroups
31# nonewprivs
32# noroot
33nosound
34notv
35novideo
36# protocol unix,inet,inet6
37# seccomp.drop @cpu-emulation,@debug,@obsolete,@privileged,@resources,add_key,fanotify_init,io_cancel,io_destroy,kcmp,keyctl,name_to_handle_at,ni_syscall,open_by_handle_at,personality,process_vm_readv,ptrace,remap_file_pages,request_key,syslog,umount,userfaultfd,vmsplice # we need to allow io_getevents, ioprio_set, io_setup, io_submit system calls
38tracelog
39
40private-dev
41# private-tmp - breaks programs that depend on akonadi
42
43noexec ${HOME}
44noexec /tmp