aboutsummaryrefslogtreecommitdiffstats
path: root/etc/gnome-books.profile
diff options
context:
space:
mode:
authorLibravatar valoq <valoq@mailbox.org>2016-11-19 21:57:42 +0100
committerLibravatar valoq <valoq@mailbox.org>2016-11-19 21:57:42 +0100
commitfa10ab0e093a4224b16491273b0162b0e0a77a3a (patch)
treeb04a3501e2a119ede58b2bc58aedbd8d0d9cc772 /etc/gnome-books.profile
parentvarious fixes (diff)
downloadfirejail-fa10ab0e093a4224b16491273b0162b0e0a77a3a.tar.gz
firejail-fa10ab0e093a4224b16491273b0162b0e0a77a3a.tar.zst
firejail-fa10ab0e093a4224b16491273b0162b0e0a77a3a.zip
many new profiles
Diffstat (limited to 'etc/gnome-books.profile')
-rw-r--r--etc/gnome-books.profile26
1 files changed, 26 insertions, 0 deletions
diff --git a/etc/gnome-books.profile b/etc/gnome-books.profile
new file mode 100644
index 000000000..10b06e173
--- /dev/null
+++ b/etc/gnome-books.profile
@@ -0,0 +1,26 @@
1# gnome-books profile
2
3# when gjs apps are started via gnome-shell, firejail is not applied because systemd will start them
4
5noblacklist ~/.cache/org.gnome.Books
6
7include /etc/firejail/disable-common.inc
8include /etc/firejail/disable-programs.inc
9include /etc/firejail/disable-devel.inc
10include /etc/firejail/disable-passwdmgr.inc
11
12caps.drop all
13nogroups
14nonewprivs
15noroot
16nosound
17protocol unix
18seccomp
19netfilter
20shell none
21tracelog
22
23# private-bin gjs gnome-books
24private-tmp
25private-dev
26private-etc fonts