aboutsummaryrefslogtreecommitdiffstats
path: root/etc/d-feet.profile
diff options
context:
space:
mode:
authorLibravatar glitsj16 <glitsj16@users.noreply.github.com>2019-03-01 04:43:32 +0000
committerLibravatar GitHub <noreply@github.com>2019-03-01 04:43:32 +0000
commitcf5f2bce410be2b944211e0a4567ccd03adc702f (patch)
tree1c47bedce000279c44abb964bdd7d7ea63a08aa3 /etc/d-feet.profile
parentAdd new profile for seahorse (#2491) (diff)
downloadfirejail-cf5f2bce410be2b944211e0a4567ccd03adc702f.tar.gz
firejail-cf5f2bce410be2b944211e0a4567ccd03adc702f.tar.zst
firejail-cf5f2bce410be2b944211e0a4567ccd03adc702f.zip
Add new profile for d-feet (#2492)
* Create d-feet.profile * Add d-feet config to disable-programs.inc * Add d-feet to firecfg
Diffstat (limited to 'etc/d-feet.profile')
-rw-r--r--etc/d-feet.profile55
1 files changed, 55 insertions, 0 deletions
diff --git a/etc/d-feet.profile b/etc/d-feet.profile
new file mode 100644
index 000000000..8526f1b0b
--- /dev/null
+++ b/etc/d-feet.profile
@@ -0,0 +1,55 @@
1# Firejail profile for d-feet
2# Description: D-Bus debugger for GNOME
3# This file is overwritten after every install/update
4# Persistent local customizations
5include d-feet.local
6# Persistent global definitions
7include globals.local
8
9noblacklist ${HOME}/.config/d-feet
10
11# Allow python (disabled by disable-interpreters.inc)
12#noblacklist ${PATH}/python2*
13noblacklist ${PATH}/python3*
14#noblacklist /usr/lib/python2*
15noblacklist /usr/lib/python3*
16
17include disable-common.inc
18include disable-devel.inc
19include disable-interpreters.inc
20include disable-passwdmgr.inc
21include disable-programs.inc
22include disable-xdg.inc
23
24include whitelist-common.inc
25include whitelist-var-common.inc
26
27apparmor
28caps.drop all
29ipc-namespace
30machine-id
31net none
32no3d
33# nodbus
34nodvd
35nogroups
36nonewprivs
37noroot
38nosound
39notv
40nou2f
41novideo
42protocol unix
43seccomp
44shell none
45
46disable-mnt
47private-bin d-feet,python*
48private-cache
49private-dev
50private-etc alternatives,dbus-1,fonts
51private-tmp
52
53# memory-deny-write-execute - Breaks on Arch
54noexec ${HOME}
55noexec /tmp