aboutsummaryrefslogtreecommitdiffstats
path: root/etc/arm.profile
diff options
context:
space:
mode:
authorLibravatar Tad <tad@spotco.us>2017-07-29 10:08:56 -0400
committerLibravatar Tad <tad@spotco.us>2017-07-29 10:08:56 -0400
commitb553272fac9b205bf5a3192b799a4d79e6fedcee (patch)
tree0fb7a9e99fe9cb9d83d945bbfd6942dea032fe13 /etc/arm.profile
parentmerges (diff)
downloadfirejail-b553272fac9b205bf5a3192b799a4d79e6fedcee.tar.gz
firejail-b553272fac9b205bf5a3192b799a4d79e6fedcee.tar.zst
firejail-b553272fac9b205bf5a3192b799a4d79e6fedcee.zip
Add a profile for arm
Diffstat (limited to 'etc/arm.profile')
-rw-r--r--etc/arm.profile42
1 files changed, 42 insertions, 0 deletions
diff --git a/etc/arm.profile b/etc/arm.profile
new file mode 100644
index 000000000..3000c35d7
--- /dev/null
+++ b/etc/arm.profile
@@ -0,0 +1,42 @@
1# Persistent global definitions go here
2include /etc/firejail/globals.local
3
4# This file is overwritten during software install.
5# Persistent customizations should go in a .local file.
6include /etc/firejail/arm.local
7
8# Firejail profile for arm
9
10noblacklist ${HOME}/.arm
11
12include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-devel.inc
14include /etc/firejail/disable-passwdmgr.inc
15include /etc/firejail/disable-programs.inc
16
17mkdir ${HOME}/.arm
18whitelist ${HOME}/.arm
19include /etc/firejail/whitelist-common.inc
20
21caps.drop all
22ipc-namespace
23netfilter
24no3d
25nogroups
26nonewprivs
27noroot
28nosound
29novideo
30protocol unix,inet,inet6
31seccomp
32shell none
33tracelog
34
35disable-mnt
36#private-bin arm,tor,sh,python2,python2.7,ps,lsof,ldconfig
37private-dev
38private-etc tor,passwd
39private-tmp
40
41noexec ${HOME}
42noexec /tmp