aboutsummaryrefslogtreecommitdiffstats
path: root/etc/dino.profile
diff options
context:
space:
mode:
authorLibravatar Tad <tad@spotco.us>2017-08-07 01:22:08 -0400
committerLibravatar Tad <tad@spotco.us>2017-08-07 01:22:08 -0400
commit9e3ba319be6b9546d7e8f450ca419ee2f3f4040b (patch)
tree0aebe82de78a61877c267f4dcb2ebcc13a2e37c9 /etc/dino.profile
parentvarious profile fixes (#1433) (diff)
downloadfirejail-9e3ba319be6b9546d7e8f450ca419ee2f3f4040b.tar.gz
firejail-9e3ba319be6b9546d7e8f450ca419ee2f3f4040b.tar.zst
firejail-9e3ba319be6b9546d7e8f450ca419ee2f3f4040b.zip
Unify all profiles
Diffstat (limited to 'etc/dino.profile')
-rw-r--r--etc/dino.profile18
1 files changed, 8 insertions, 10 deletions
diff --git a/etc/dino.profile b/etc/dino.profile
index 94563fa1d..0501cd408 100644
--- a/etc/dino.profile
+++ b/etc/dino.profile
@@ -1,11 +1,10 @@
1# Persistent global definitions go here 1# Firejail profile for dino
2include /etc/firejail/globals.local 2# This file is overwritten after every install/update
3 3# Persistent local customizations
4# This file is overwritten during software install.
5# Persistent customizations should go in a .local file.
6include /etc/firejail/dino.local 4include /etc/firejail/dino.local
5# Persistent global definitions
6include /etc/firejail/globals.local
7 7
8# Firejail profile for Dino
9noblacklist ${HOME}/.local/share/dino 8noblacklist ${HOME}/.local/share/dino
10 9
11include /etc/firejail/disable-common.inc 10include /etc/firejail/disable-common.inc
@@ -13,13 +12,12 @@ include /etc/firejail/disable-devel.inc
13include /etc/firejail/disable-passwdmgr.inc 12include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc 13include /etc/firejail/disable-programs.inc
15 14
16whitelist ${HOME}/Downloads
17mkdir ${HOME}/.local/share/dino 15mkdir ${HOME}/.local/share/dino
18whitelist ${HOME}/.local/share/dino 16whitelist ${HOME}/.local/share/dino
17whitelist ${HOME}/Downloads
19include /etc/firejail/whitelist-common.inc 18include /etc/firejail/whitelist-common.inc
20 19
21caps.drop all 20caps.drop all
22#ipc-namespace
23netfilter 21netfilter
24no3d 22no3d
25nogroups 23nogroups
@@ -31,11 +29,11 @@ protocol unix,inet,inet6
31seccomp 29seccomp
32shell none 30shell none
33 31
32disable-mnt
34private-bin dino 33private-bin dino
35#private-etc fonts #breaks server connection
36private-dev 34private-dev
35# private-etc fonts # breaks server connection
37private-tmp 36private-tmp
38disable-mnt
39 37
40noexec ${HOME} 38noexec ${HOME}
41noexec /tmp 39noexec /tmp