diff options
author | avoidr <avoidr@users.noreply.github.com> | 2015-12-06 15:33:39 +0100 |
---|---|---|
committer | avoidr <avoidr@users.noreply.github.com> | 2015-12-06 15:33:39 +0100 |
commit | f332fe2614980e1d50e59e9429ff88ac49ec137c (patch) | |
tree | e04f45a524501e30ccde780f9e23260a7eb4cf22 /etc/parole.profile | |
parent | malloc memory fix (diff) | |
download | firejail-f332fe2614980e1d50e59e9429ff88ac49ec137c.tar.gz firejail-f332fe2614980e1d50e59e9429ff88ac49ec137c.tar.zst firejail-f332fe2614980e1d50e59e9429ff88ac49ec137c.zip |
add parole.profile
Diffstat (limited to 'etc/parole.profile')
-rw-r--r-- | etc/parole.profile | 17 |
1 files changed, 17 insertions, 0 deletions
diff --git a/etc/parole.profile b/etc/parole.profile new file mode 100644 index 000000000..24181c8d6 --- /dev/null +++ b/etc/parole.profile | |||
@@ -0,0 +1,17 @@ | |||
1 | # Profile for Parole, the default XFCE4 media player | ||
2 | include /etc/firejail/disable-mgmt.inc | ||
3 | include /etc/firejail/disable-secret.inc | ||
4 | include /etc/firejail/disable-common.inc | ||
5 | include /etc/firejail/disable-devel.inc | ||
6 | private-etc passwd,group,fonts | ||
7 | private-bin parole,dbus-launch | ||
8 | blacklist ${HOME}/.pki/nssdb | ||
9 | blacklist ${HOME}/.lastpass | ||
10 | blacklist ${HOME}/.keepassx | ||
11 | blacklist ${HOME}/.password-store | ||
12 | caps.drop all | ||
13 | seccomp | ||
14 | protocol unix,inet,inet6 | ||
15 | netfilter | ||
16 | noroot | ||
17 | shell none | ||