summaryrefslogtreecommitdiffstats
path: root/etc/chromium.profile
diff options
context:
space:
mode:
authorLibravatar Tad <tad@spotco.us>2017-04-17 17:11:24 -0400
committerLibravatar Tad <tad@spotco.us>2017-04-17 17:11:24 -0400
commit4f238b75de05d91f200305335da1f019810ac149 (patch)
tree40f021c8d9e7bb70f7bd0a868d571286fa438420 /etc/chromium.profile
parentMerge pull request #1229 from SpotComms/firecfg2 (diff)
downloadfirejail-4f238b75de05d91f200305335da1f019810ac149.tar.gz
firejail-4f238b75de05d91f200305335da1f019810ac149.tar.zst
firejail-4f238b75de05d91f200305335da1f019810ac149.zip
Harden more profiles
Diffstat (limited to 'etc/chromium.profile')
-rw-r--r--etc/chromium.profile15
1 files changed, 11 insertions, 4 deletions
diff --git a/etc/chromium.profile b/etc/chromium.profile
index 995c0001b..071c8a18a 100644
--- a/etc/chromium.profile
+++ b/etc/chromium.profile
@@ -8,12 +8,8 @@ noblacklist ~/.cache/chromium
8noblacklist ~/.pki 8noblacklist ~/.pki
9include /etc/firejail/disable-common.inc 9include /etc/firejail/disable-common.inc
10include /etc/firejail/disable-programs.inc 10include /etc/firejail/disable-programs.inc
11
12# chromium is distributed with a perl script on Arch 11# chromium is distributed with a perl script on Arch
13# include /etc/firejail/disable-devel.inc 12# include /etc/firejail/disable-devel.inc
14#
15
16netfilter
17 13
18whitelist ${DOWNLOADS} 14whitelist ${DOWNLOADS}
19mkdir ~/.config/chromium 15mkdir ~/.config/chromium
@@ -27,3 +23,14 @@ whitelist ~/.pki
27whitelist ~/.config/chromium-flags.conf 23whitelist ~/.config/chromium-flags.conf
28 24
29include /etc/firejail/whitelist-common.inc 25include /etc/firejail/whitelist-common.inc
26
27ipc-namespace
28netfilter
29nogroups
30shell none
31
32private-dev
33private-tmp
34
35noexec ${HOME}
36noexec /tmp