aboutsummaryrefslogtreecommitdiffstats
path: root/etc/barrier.profile
diff options
context:
space:
mode:
authorLibravatar Adrian L. Shaw <adrianlshaw@gmail.com>2020-01-04 12:13:20 +0000
committerLibravatar rusty-snake <print_hello_world+Public@protonmail.com>2020-01-04 12:13:20 +0000
commit108eea75093e8a9fe8c9bd30027bf35e3d7559a1 (patch)
tree2163fe47a83e7241b3893c378b05eb26f5158d20 /etc/barrier.profile
parentGentoo fixes (#3120) (diff)
downloadfirejail-108eea75093e8a9fe8c9bd30027bf35e3d7559a1.tar.gz
firejail-108eea75093e8a9fe8c9bd30027bf35e3d7559a1.tar.zst
firejail-108eea75093e8a9fe8c9bd30027bf35e3d7559a1.zip
Add barrier profile (#3115)
* Add barrier.profile * Add newline before special options * Modify description * Add disable mount to barrier.profile * Address feedback from rusty-snake * Remove stray carriage return * Add noexec for /home/user and /tmp * Don't blacklist openssl * Remove redundant rules
Diffstat (limited to 'etc/barrier.profile')
-rw-r--r--etc/barrier.profile45
1 files changed, 45 insertions, 0 deletions
diff --git a/etc/barrier.profile b/etc/barrier.profile
new file mode 100644
index 000000000..a35bb1e09
--- /dev/null
+++ b/etc/barrier.profile
@@ -0,0 +1,45 @@
1# Firejail profile for barrier
2# Description: Keyboard and mouse sharing application
3# This file is overwritten after every install/update
4# Persistent local customizations
5include barrier.local
6# Persistent global definitions
7include globals.local
8
9noblacklist ${HOME}/.config/Debauchee/Barrier.conf
10noblacklist ${HOME}/.local/share/barrier
11noblacklist ${PATH}/openssl
12
13include disable-common.inc
14include disable-devel.inc
15include disable-exec.inc
16include disable-interpreters.inc
17include disable-passwdmgr.inc
18include disable-programs.inc
19include disable-xdg.inc
20
21include whitelist-var-common.inc
22
23caps.drop all
24machine-id
25netfilter
26no3d
27nodvd
28nogroups
29nonewprivs
30noroot
31nosound
32notv
33nou2f
34novideo
35protocol unix,inet,inet6,netlink
36seccomp
37shell none
38tracelog
39
40disable-mnt
41private-dev
42private-cache
43private-tmp
44
45memory-deny-write-execute