aboutsummaryrefslogtreecommitdiffstats
path: root/etc/gjs.profile
diff options
context:
space:
mode:
authorLibravatar valoq <valoq@mailbox.org>2016-11-19 21:57:42 +0100
committerLibravatar valoq <valoq@mailbox.org>2016-11-19 21:57:42 +0100
commitfa10ab0e093a4224b16491273b0162b0e0a77a3a (patch)
treeb04a3501e2a119ede58b2bc58aedbd8d0d9cc772 /etc/gjs.profile
parentvarious fixes (diff)
downloadfirejail-fa10ab0e093a4224b16491273b0162b0e0a77a3a.tar.gz
firejail-fa10ab0e093a4224b16491273b0162b0e0a77a3a.tar.zst
firejail-fa10ab0e093a4224b16491273b0162b0e0a77a3a.zip
many new profiles
Diffstat (limited to 'etc/gjs.profile')
-rw-r--r--etc/gjs.profile28
1 files changed, 28 insertions, 0 deletions
diff --git a/etc/gjs.profile b/etc/gjs.profile
new file mode 100644
index 000000000..8d71728a2
--- /dev/null
+++ b/etc/gjs.profile
@@ -0,0 +1,28 @@
1# gjs (gnome javascript bindings) profile
2
3# when gjs apps are started via gnome-shell, firejail is not applied because systemd will start them
4
5noblacklist ~/.cache/org.gnome.Books
6noblacklist ~/.config/libreoffice
7noblacklist ~/.local/share/gnome-photos
8noblacklist ~/.cache/libgweather
9
10include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-programs.inc
12include /etc/firejail/disable-devel.inc
13include /etc/firejail/disable-passwdmgr.inc
14
15caps.drop all
16nogroups
17nonewprivs
18noroot
19protocol unix,inet,inet6
20seccomp
21netfilter
22shell none
23tracelog
24
25# private-bin gjs,gnome-books,gnome-documents,gnome-photos,gnome-maps,gnome-weather
26private-tmp
27private-dev
28# private-etc fonts