summaryrefslogtreecommitdiffstats
path: root/etc/baloo_file.profile
diff options
context:
space:
mode:
authorLibravatar netblue30 <netblue30@yahoo.com>2017-04-09 11:22:07 -0400
committerLibravatar GitHub <noreply@github.com>2017-04-09 11:22:07 -0400
commit7bec8bf8e8f93ce1d6700aeccb5aecf93865b0b9 (patch)
tree0b67124121e10fdd6b689e023a4109dc410e8060 /etc/baloo_file.profile
parentDoc update after merging #1198 (diff)
parentimprove x11 isolation (diff)
downloadfirejail-7bec8bf8e8f93ce1d6700aeccb5aecf93865b0b9.tar.gz
firejail-7bec8bf8e8f93ce1d6700aeccb5aecf93865b0b9.tar.zst
firejail-7bec8bf8e8f93ce1d6700aeccb5aecf93865b0b9.zip
Merge pull request #1201 from SYN-cook/patch-2
new baloo profile
Diffstat (limited to 'etc/baloo_file.profile')
-rw-r--r--etc/baloo_file.profile41
1 files changed, 41 insertions, 0 deletions
diff --git a/etc/baloo_file.profile b/etc/baloo_file.profile
new file mode 100644
index 000000000..d9c37911b
--- /dev/null
+++ b/etc/baloo_file.profile
@@ -0,0 +1,41 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/baloo_file.local
4
5# KDE Baloo file daemon profile
6noblacklist ${HOME}/.kde4/share/config/baloofilerc
7noblacklist ${HOME}/.kde4/share/config/baloorc
8noblacklist ${HOME}/.kde/share/config/baloofilerc
9noblacklist ${HOME}/.kde/share/config/baloorc
10noblacklist ${HOME}/.config/baloofilerc
11noblacklist ${HOME}/.local/share/baloo
12include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-programs.inc
14include /etc/firejail/disable-devel.inc
15include /etc/firejail/disable-passwdmgr.inc
16
17caps.drop all
18nogroups
19nonewprivs
20noroot
21nosound
22protocol unix
23# Baloo makes ioprio_set system calls, which are blacklisted by default.
24# That's why we need to disable seccomp
25#seccomp
26
27blacklist /tmp/.X11-unix
28
29private-dev
30private-tmp
31
32# Experimental: make home directory read-only and allow writing only
33# to Baloo configuration files and databases
34#read-only ${HOME}
35#read-write ${HOME}/.kde4/share/config/baloofilerc
36#read-write ${HOME}/.kde4/share/config/baloorc
37#read-write ${HOME}/.kde/share/config/baloofilerc
38#read-write ${HOME}/.kde/share/config/baloorc
39#read-write ${HOME}/.config/baloofilerc
40#read-write ${HOME}/.local/share/baloo
41#read-write ${HOME}/.local/share/akonadi/search_db