aboutsummaryrefslogtreecommitdiffstats
path: root/etc/caja.profile
diff options
context:
space:
mode:
authorLibravatar Fred Barclay <Fred-Barclay@users.noreply.github.com>2017-04-28 11:28:44 -0500
committerLibravatar Fred Barclay <Fred-Barclay@users.noreply.github.com>2017-04-28 11:28:44 -0500
commite1f738891aefa1c200b973fc6ed0bda56b6fd870 (patch)
treefde00547b1be1868ea7262634e884615ab8a9a45 /etc/caja.profile
parentAdded noexec to qtox profile (diff)
downloadfirejail-e1f738891aefa1c200b973fc6ed0bda56b6fd870.tar.gz
firejail-e1f738891aefa1c200b973fc6ed0bda56b6fd870.tar.zst
firejail-e1f738891aefa1c200b973fc6ed0bda56b6fd870.zip
Very basic Caja profile.
Modified from existing nautilus profile. It might need some future editing and tweaking.
Diffstat (limited to 'etc/caja.profile')
-rw-r--r--etc/caja.profile32
1 files changed, 32 insertions, 0 deletions
diff --git a/etc/caja.profile b/etc/caja.profile
new file mode 100644
index 000000000..fe89d7b2d
--- /dev/null
+++ b/etc/caja.profile
@@ -0,0 +1,32 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/caja.local
4
5# Caja profile for Firejail
6
7# Caja is started by systemd on most systems. Therefore it is not firejailed by default. Since there
8 # is already a caja process running on MATE desktops firejail will have no effect.
9
10noblacklist ~/.config/caja
11noblacklist ~/.local/share/caja
12
13include /etc/firejail/disable-common.inc
14# caja needs to be able to start arbitrary applications so we cannot blacklist their files
15#include /etc/firejail/disable-programs.inc
16include /etc/firejail/disable-devel.inc
17include /etc/firejail/disable-passwdmgr.inc
18
19caps.drop all
20nogroups
21nonewprivs
22noroot
23protocol unix
24seccomp
25netfilter
26shell none
27tracelog
28
29# private-bin caja
30# private-tmp
31# private-dev
32# private-etc fonts