aboutsummaryrefslogtreecommitdiffstats
path: root/etc/authenticator.profile
diff options
context:
space:
mode:
authorLibravatar glitsj16 <glitsj16@users.noreply.github.com>2018-10-11 06:52:33 +0000
committerLibravatar GitHub <noreply@github.com>2018-10-11 06:52:33 +0000
commit82c48d4e3cdf122dddfef3e536e9032351363af7 (patch)
tree09e49013e7ae698c4677a4b110e723def937a5e9 /etc/authenticator.profile
parentmerges (diff)
downloadfirejail-82c48d4e3cdf122dddfef3e536e9032351363af7.tar.gz
firejail-82c48d4e3cdf122dddfef3e536e9032351363af7.tar.zst
firejail-82c48d4e3cdf122dddfef3e536e9032351363af7.zip
Create authenticator.profile
Diffstat (limited to 'etc/authenticator.profile')
-rw-r--r--etc/authenticator.profile49
1 files changed, 49 insertions, 0 deletions
diff --git a/etc/authenticator.profile b/etc/authenticator.profile
new file mode 100644
index 000000000..f10abdda8
--- /dev/null
+++ b/etc/authenticator.profile
@@ -0,0 +1,49 @@
1# Firejail profile for authenticator
2# Description: 2FA code generator for GNOME
3# This file is overwritten after every install/update
4# Persistent local customizations
5include /etc/firejail/authenticator.local
6# Persistent global definitions
7include /etc/firejail/globals.local
8
9# blacklisted in 'disable-programs.local'
10noblacklist ${HOME}/.config/Authenticator
11
12# Allow python 3.x (blacklisted by disable-interpreters.inc)
13noblacklist ${PATH}/python3*
14noblacklist /usr/lib/python3*
15
16include /etc/firejail/disable-common.inc
17include /etc/firejail/disable-devel.inc
18include /etc/firejail/disable-interpreters.inc
19include /etc/firejail/disable-passwdmgr.inc
20include /etc/firejail/disable-programs.inc
21
22# apparmor
23caps.drop all
24net none
25no3d
26# nodbus - makes settings immutable
27nodvd
28nogroups
29nonewprivs
30noroot
31nosound
32notv
33# novideo
34nou2f
35protocol unix
36seccomp
37shell none
38
39disable-mnt
40# private-bin authenticator
41private-cache
42private-dev
43private-etc fonts,ld.so.cache
44# private-lib
45private-tmp
46
47# memory-deny-write-execute - breaks on Arch
48noexec ${HOME}
49noexec /tmp