aboutsummaryrefslogtreecommitdiffstats
path: root/etc/electrum.profile
diff options
context:
space:
mode:
authorLibravatar startx2017 <vradu.startx@yandex.com>2018-08-14 08:04:40 -0400
committerLibravatar startx2017 <vradu.startx@yandex.com>2018-08-14 08:04:40 -0400
commit327d3d815db6619cc81fa6858a8ca8667189f7b7 (patch)
treee6e3a70e1a876113afdbd5154c6bc7b215cb6ef8 /etc/electrum.profile
parentphase1 (diff)
downloadfirejail-327d3d815db6619cc81fa6858a8ca8667189f7b7.tar.gz
firejail-327d3d815db6619cc81fa6858a8ca8667189f7b7.tar.zst
firejail-327d3d815db6619cc81fa6858a8ca8667189f7b7.zip
merge 0.9.56-rc1
Diffstat (limited to 'etc/electrum.profile')
-rw-r--r--etc/electrum.profile52
1 files changed, 52 insertions, 0 deletions
diff --git a/etc/electrum.profile b/etc/electrum.profile
new file mode 100644
index 000000000..d611f3e61
--- /dev/null
+++ b/etc/electrum.profile
@@ -0,0 +1,52 @@
1# Firejail profile for electrum
2# This file is overwritten after every install/update
3# Persistent local customizations
4include /etc/firejail/electrum.local
5# Persistent global definitions
6include /etc/firejail/globals.local
7
8noblacklist ${HOME}/.electrum
9
10# Allow python (blacklisted by disable-interpreters.inc)
11noblacklist ${PATH}/python2*
12noblacklist ${PATH}/python3*
13noblacklist /usr/lib/python2*
14noblacklist /usr/lib/python3*
15
16include /etc/firejail/disable-common.inc
17include /etc/firejail/disable-devel.inc
18include /etc/firejail/disable-interpreters.inc
19include /etc/firejail/disable-passwdmgr.inc
20include /etc/firejail/disable-programs.inc
21include /etc/firejail/disable-xdg.inc
22
23mkdir ${HOME}/.electrum
24whitelist ${HOME}/.electrum
25include /etc/firejail/whitelist-common.inc
26include /etc/firejail/whitelist-var-common.inc
27
28caps.drop all
29ipc-namespace
30netfilter
31no3d
32#nodbus
33nodvd
34nogroups
35nonewprivs
36noroot
37nosound
38notv
39novideo
40protocol unix,inet,inet6
41seccomp
42shell none
43
44disable-mnt
45private-bin electrum,python*
46private-cache
47private-dev
48private-etc fonts,dconf,ca-certificates,ssl,pki,crypto-policies,machine-id
49private-tmp
50
51noexec ${HOME}
52noexec /tmp