aboutsummaryrefslogtreecommitdiffstats
path: root/etc/cyberfox.profile
diff options
context:
space:
mode:
authorLibravatar hawkeye116477 <hawkeye116477@gmail.com>2017-05-30 21:31:39 +0200
committerLibravatar hawkeye116477 <hawkeye116477@gmail.com>2017-05-30 21:31:39 +0200
commitae4de575327be1f8ba8bc668622932c0c0fdfe0c (patch)
tree37377da945de5f5e95357c015c91e78c6476b7f7 /etc/cyberfox.profile
parentAdd Firejail profile for Waterfox (diff)
downloadfirejail-ae4de575327be1f8ba8bc668622932c0c0fdfe0c.tar.gz
firejail-ae4de575327be1f8ba8bc668622932c0c0fdfe0c.tar.zst
firejail-ae4de575327be1f8ba8bc668622932c0c0fdfe0c.zip
Update profile for Cyberfox
Diffstat (limited to 'etc/cyberfox.profile')
-rw-r--r--etc/cyberfox.profile23
1 files changed, 22 insertions, 1 deletions
diff --git a/etc/cyberfox.profile b/etc/cyberfox.profile
index 068131d25..c237e33ff 100644
--- a/etc/cyberfox.profile
+++ b/etc/cyberfox.profile
@@ -8,17 +8,25 @@ include /etc/firejail/cyberfox.local
8# Firejail profile for Cyberfox (based on Mozilla Firefox) 8# Firejail profile for Cyberfox (based on Mozilla Firefox)
9noblacklist ~/.8pecxstudios 9noblacklist ~/.8pecxstudios
10noblacklist ~/.cache/8pecxstudios 10noblacklist ~/.cache/8pecxstudios
11noblacklist ~/.config/qpdfview
12noblacklist ~/.local/share/qpdfview
13noblacklist ~/.kde4/share/apps/okular
14noblacklist ~/.kde/share/apps/okular
15noblacklist ~/.local/share/okular
11noblacklist ~/.pki 16noblacklist ~/.pki
12include /etc/firejail/disable-common.inc 17include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-programs.inc 18include /etc/firejail/disable-programs.inc
14include /etc/firejail/disable-devel.inc 19include /etc/firejail/disable-devel.inc
15 20
16caps.drop all 21caps.drop all
22# ipc-namespace crashes cyberfox on some setups
17netfilter 23netfilter
24nogroups
18nonewprivs 25nonewprivs
19noroot 26noroot
20protocol unix,inet,inet6,netlink 27protocol unix,inet,inet6,netlink
21seccomp 28seccomp
29shell none
22tracelog 30tracelog
23 31
24whitelist ${DOWNLOADS} 32whitelist ${DOWNLOADS}
@@ -35,8 +43,14 @@ whitelist ~/.pentadactyl
35whitelist ~/.keysnail.js 43whitelist ~/.keysnail.js
36whitelist ~/.config/gnome-mplayer 44whitelist ~/.config/gnome-mplayer
37whitelist ~/.cache/gnome-mplayer/plugin 45whitelist ~/.cache/gnome-mplayer/plugin
46mkdir ~/.pki
38whitelist ~/.pki 47whitelist ~/.pki
39whitelist ~/.lastpass 48whitelist ~/.lastpass
49whitelist ~/.config/qpdfview
50whitelist ~/.local/share/qpdfview
51whitelist ~/.kde4/share/apps/okular
52whitelist ~/.kde/share/apps/okular
53whitelist ~/.local/share/okular
40 54
41# silverlight 55# silverlight
42whitelist ~/.wine-pipelight 56whitelist ~/.wine-pipelight
@@ -47,4 +61,11 @@ whitelist ~/.config/pipelight-silverlight5.1
47include /etc/firejail/whitelist-common.inc 61include /etc/firejail/whitelist-common.inc
48 62
49# experimental features 63# experimental features
50#private-etc passwd,group,hostname,hosts,localtime,nsswitch.conf,resolv.conf,gtk-2.0,pango,fonts,iceweasel,firefox,adobe,mime.types,mailcap,asound.conf,pulse 64#private-bin cyberfox,which,sh,dbus-launch,dbus-send,env
65#private-etc passwd,group,hostname,hosts,localtime,nsswitch.conf,resolv.conf,xdg,gtk-2.0,gtk-3.0,X11,pango,fonts,cyberfox,mime.types,mailcap,asound.conf,pulse
66# private-dev might prevent video calls going out
67private-dev
68private-tmp
69
70noexec ${HOME}
71noexec /tmp