aboutsummaryrefslogtreecommitdiffstats
path: root/etc/desktop.profile
diff options
context:
space:
mode:
authorLibravatar netblue30 <netblue30@yahoo.com>2018-10-11 08:36:06 -0500
committerLibravatar GitHub <noreply@github.com>2018-10-11 08:36:06 -0500
commit418e61fc142205347dbfb84e519ba0b656a51903 (patch)
tree786b0a358c83c75290fe01b077312ffc69a1a7ba /etc/desktop.profile
parentMerge pull request #2170 from glitsj16/easystroke (diff)
parentUpdate for desktop (a.k.a. github-desktop) (diff)
downloadfirejail-418e61fc142205347dbfb84e519ba0b656a51903.tar.gz
firejail-418e61fc142205347dbfb84e519ba0b656a51903.tar.zst
firejail-418e61fc142205347dbfb84e519ba0b656a51903.zip
Merge pull request #2171 from glitsj16/desktop
New profile desktop (a.k.a. github-desktop)
Diffstat (limited to 'etc/desktop.profile')
-rw-r--r--etc/desktop.profile44
1 files changed, 44 insertions, 0 deletions
diff --git a/etc/desktop.profile b/etc/desktop.profile
new file mode 100644
index 000000000..8bfa885a3
--- /dev/null
+++ b/etc/desktop.profile
@@ -0,0 +1,44 @@
1# Firejail profile for desktop
2# Description: Extend your GitHub workflow beyond your browser with GitHub Desktop
3# This file is overwritten after every install/update
4# Persistent local customizations
5include /etc/firejail/github-desktop.local
6# Persistent global definitions
7include /etc/firejail/globals.local
8
9whitelist ${HOME}/.gitconfig
10whitelist ${HOME}/.config/GitHub Desktop
11
12include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc
15include /etc/firejail/disable-devel.inc
16include /etc/firejail/disable-interpreters.inc
17
18include /etc/firejail/whitelist-common.inc
19
20caps.drop all
21netfilter
22# no3d
23nodvd
24nogroups
25nonewprivs
26noroot
27nosound
28notv
29nou2f
30novideo
31protocol unix,inet,inet6,netlink
32seccomp
33
34disable-mnt
35# private-bin Atom,desktop
36# private-cache
37# private-dev
38# private-etc none
39# private-lib
40# private-tmp
41
42# memory-deny-write-execute
43# noexec ${HOME}
44# noexec /tmp