aboutsummaryrefslogtreecommitdiffstats
path: root/etc/geary.profile
diff options
context:
space:
mode:
authorLibravatar Tad <tad@spotco.us>2017-08-07 01:22:08 -0400
committerLibravatar Tad <tad@spotco.us>2017-08-07 01:22:08 -0400
commit9e3ba319be6b9546d7e8f450ca419ee2f3f4040b (patch)
tree0aebe82de78a61877c267f4dcb2ebcc13a2e37c9 /etc/geary.profile
parentvarious profile fixes (#1433) (diff)
downloadfirejail-9e3ba319be6b9546d7e8f450ca419ee2f3f4040b.tar.gz
firejail-9e3ba319be6b9546d7e8f450ca419ee2f3f4040b.tar.zst
firejail-9e3ba319be6b9546d7e8f450ca419ee2f3f4040b.zip
Unify all profiles
Diffstat (limited to 'etc/geary.profile')
-rw-r--r--etc/geary.profile35
1 files changed, 18 insertions, 17 deletions
diff --git a/etc/geary.profile b/etc/geary.profile
index f655f0efe..5833e51cf 100644
--- a/etc/geary.profile
+++ b/etc/geary.profile
@@ -1,28 +1,29 @@
1# Persistent global definitions go here 1# Firejail profile for geary
2include /etc/firejail/globals.local 2# This file is overwritten after every install/update
3 3# Persistent local customizations
4# This file is overwritten during software install.
5# Persistent customizations should go in a .local file.
6include /etc/firejail/geary.local 4include /etc/firejail/geary.local
7 5# Persistent global definitions
8# Firejail profile for Gnome Geary 6include /etc/firejail/globals.local
9# Users have Geary set to open a browser by clicking a link in an email
10# We are not allowed to blacklist browser-specific directories
11 7
12noblacklist ~/.gnupg 8noblacklist ~/.gnupg
13mkdir ~/.gnupg
14whitelist ~/.gnupg
15
16noblacklist ~/.local/share/geary 9noblacklist ~/.local/share/geary
10
11mkdir ~/.gnupg
17mkdir ~/.local/share/geary 12mkdir ~/.local/share/geary
13whitelist ~/.config/mimeapps.list
14whitelist ~/.gnupg
15whitelist ~/.local/share/applications
18whitelist ~/.local/share/geary 16whitelist ~/.local/share/geary
17include /etc/firejail/whitelist-common.inc
18
19ignore private-tmp
19 20
20whitelist ~/.config/mimeapps.list
21read-only ~/.config/mimeapps.list 21read-only ~/.config/mimeapps.list
22whitelist ~/.local/share/applications
23read-only ~/.local/share/applications 22read-only ~/.local/share/applications
24 23
25# allow browsers
26ignore private-tmp
27include /etc/firejail/firefox.profile 24include /etc/firejail/firefox.profile
28#include /etc/firejail/chromium.profile - chromium runs as suid! 25
26# CLOBBERED COMMENTS
27# Users have Geary set to open a browser by clicking a link in an email
28# We are not allowed to blacklist browser-specific directories
29# allow browsers