aboutsummaryrefslogtreecommitdiffstats
path: root/etc/krunner.profile
diff options
context:
space:
mode:
authorLibravatar smitsohu <smitsohu@gmail.com>2018-02-01 22:39:21 +0100
committerLibravatar smitsohu <smitsohu@gmail.com>2018-02-01 22:39:21 +0100
commit8aec7694cb4c7c0d07b333b689ab19faacb519f9 (patch)
treed5cc911a2b94d80faf8d9bcfabc8fd156d75e887 /etc/krunner.profile
parentunbound fix (part 2) - whitelist /var/run (diff)
downloadfirejail-8aec7694cb4c7c0d07b333b689ab19faacb519f9.tar.gz
firejail-8aec7694cb4c7c0d07b333b689ab19faacb519f9.tar.zst
firejail-8aec7694cb4c7c0d07b333b689ab19faacb519f9.zip
KDE related enhancements
Diffstat (limited to 'etc/krunner.profile')
-rw-r--r--etc/krunner.profile8
1 files changed, 6 insertions, 2 deletions
diff --git a/etc/krunner.profile b/etc/krunner.profile
index 606b67677..1e97f4290 100644
--- a/etc/krunner.profile
+++ b/etc/krunner.profile
@@ -5,12 +5,15 @@ include /etc/firejail/krunner.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8# start a program in krunner: program will run with this generic profile 8# - programs started in krunner run with this generic profile.
9# open a file in krunner: file viewer will run with its own profile (if firejailed automatically) 9# - when a file is opened in krunner, the file viewer runs in its own sandbox
10# with its own profile, if it is sandboxed automatically.
10 11
12# noblacklist ${HOME}/.cache/krunner
11noblacklist ${HOME}/.config/krunnerrc 13noblacklist ${HOME}/.config/krunnerrc
12noblacklist ${HOME}/.kde/share/config/krunnerrc 14noblacklist ${HOME}/.kde/share/config/krunnerrc
13noblacklist ${HOME}/.kde4/share/config/krunnerrc 15noblacklist ${HOME}/.kde4/share/config/krunnerrc
16# noblacklist ${HOME}/.local/share/baloo
14 17
15include /etc/firejail/disable-common.inc 18include /etc/firejail/disable-common.inc
16# include /etc/firejail/disable-devel.inc 19# include /etc/firejail/disable-devel.inc
@@ -21,6 +24,7 @@ include /etc/firejail/whitelist-var-common.inc
21 24
22caps.drop all 25caps.drop all
23netfilter 26netfilter
27nogroups
24nonewprivs 28nonewprivs
25noroot 29noroot
26protocol unix,inet,inet6 30protocol unix,inet,inet6