aboutsummaryrefslogtreecommitdiffstats
path: root/etc/cower.profile
diff options
context:
space:
mode:
authorLibravatar netblue30 <netblue30@yahoo.com>2017-11-15 08:20:17 -0500
committerLibravatar netblue30 <netblue30@yahoo.com>2017-11-15 08:20:17 -0500
commit6c10737f064e96047620d228f82564530a182400 (patch)
tree20b66fce36f0590b1c7d84a024227a56bd6a373e /etc/cower.profile
parentmakepkg profile for Arch platform, #1642 (diff)
downloadfirejail-6c10737f064e96047620d228f82564530a182400.tar.gz
firejail-6c10737f064e96047620d228f82564530a182400.tar.zst
firejail-6c10737f064e96047620d228f82564530a182400.zip
archaudit-report and cower for Arch platforms, #1642
Diffstat (limited to 'etc/cower.profile')
-rw-r--r--etc/cower.profile47
1 files changed, 47 insertions, 0 deletions
diff --git a/etc/cower.profile b/etc/cower.profile
new file mode 100644
index 000000000..5e5c367c4
--- /dev/null
+++ b/etc/cower.profile
@@ -0,0 +1,47 @@
1# Firejail profile for cower
2# This file is overwritten after every install/update
3
4# This profile could be significantly strengthened by adding the following to cower.local
5# whitelist ~/<Your Build Folder>
6# whitelist ~/.config/cower/
7
8quiet
9
10# Persistent local customizations
11include /etc/firejail/cower.local
12# Persistent global definitions
13include /etc/firejail/globals.local
14
15noblacklist ~/.config/cower/config
16read-only ~/.config/cower/config
17
18noblacklist /var/lib/pacman
19
20include /etc/firejail/disable-common.inc
21include /etc/firejail/disable-devel.inc
22include /etc/firejail/disable-passwdmgr.inc
23include /etc/firejail/disable-programs.inc
24
25caps.drop all
26ipc-namespace
27netfilter
28no3d
29nodvd
30nogroups
31nonewprivs
32noroot
33nosound
34notv
35novideo
36protocol unix,inet,inet6
37seccomp
38shell none
39
40disable-mnt
41private-bin cower
42private-dev
43private-tmp
44
45memory-deny-write-execute
46noexec ${HOME}
47noexec /tmp