aboutsummaryrefslogtreecommitdiffstats
path: root/etc/feedreader.profile
diff options
context:
space:
mode:
authorLibravatar Tad <tad@spotco.us>2018-11-22 13:50:48 -0500
committerLibravatar Tad <tad@spotco.us>2018-11-22 13:50:48 -0500
commitcc898c19023a9aea92bc7e863f8fd46600d27598 (patch)
tree8dcaab722a48b4fe44ddd2b4e7f9c02116d528b0 /etc/feedreader.profile
parentplayonlinux.profile: allow python (diff)
downloadfirejail-cc898c19023a9aea92bc7e863f8fd46600d27598.tar.gz
firejail-cc898c19023a9aea92bc7e863f8fd46600d27598.tar.zst
firejail-cc898c19023a9aea92bc7e863f8fd46600d27598.zip
Aisleriot fixes + add profile for FeedReader
Diffstat (limited to 'etc/feedreader.profile')
-rw-r--r--etc/feedreader.profile45
1 files changed, 45 insertions, 0 deletions
diff --git a/etc/feedreader.profile b/etc/feedreader.profile
new file mode 100644
index 000000000..44ed475bc
--- /dev/null
+++ b/etc/feedreader.profile
@@ -0,0 +1,45 @@
1# Firejail profile for feedreader
2# Description: RSS client
3# This file is overwritten after every install/update
4# Persistent local customizations
5include feedreader.local
6# Persistent global definitions
7include globals.local
8
9noblacklist ${HOME}/.cache/feedreader
10noblacklist ${HOME}/.local/share/feedreader
11
12include disable-common.inc
13include disable-devel.inc
14include disable-interpreters.inc
15include disable-passwdmgr.inc
16include disable-programs.inc
17
18mkdir ${HOME}/.cache/feedreader
19mkdir ${HOME}/.local/share/feedreader
20whitelist ${HOME}/.cache/feedreader
21whitelist ${HOME}/.local/share/feedreader
22include whitelist-common.inc
23include whitelist-var-common.inc
24
25caps.drop all
26netfilter
27# no3d
28nodvd
29nogroups
30nonewprivs
31noroot
32# nosound
33notv
34nou2f
35novideo
36protocol unix,inet,inet6
37seccomp
38shell none
39
40disable-mnt
41private-dev
42private-tmp
43
44noexec ${HOME}
45noexec /tmp