aboutsummaryrefslogtreecommitdiffstats
path: root/etc/profile-a-l/alacarte.profile
diff options
context:
space:
mode:
authorLibravatar kortewegdevries <62639087+kortewegdevries@users.noreply.github.com>2020-12-16 18:12:48 +0000
committerLibravatar GitHub <noreply@github.com>2020-12-16 18:12:48 +0000
commitf3056a862a6eb9ccbd08760c1b8d7fa769f90e9f (patch)
tree071ecab873aa6e02620f5a71d11d8a5e946d66bf /etc/profile-a-l/alacarte.profile
parentarchiver fixes (#3830) (diff)
downloadfirejail-f3056a862a6eb9ccbd08760c1b8d7fa769f90e9f.tar.gz
firejail-f3056a862a6eb9ccbd08760c1b8d7fa769f90e9f.tar.zst
firejail-f3056a862a6eb9ccbd08760c1b8d7fa769f90e9f.zip
New profiles for alacarte,tootle,photoflare (#3816)
* New profiles for alacarte,tootle,photoflare * Fix dbus Co-authored-by: kortewegdevries <kortewegdevries@protonmail.ch>
Diffstat (limited to 'etc/profile-a-l/alacarte.profile')
-rw-r--r--etc/profile-a-l/alacarte.profile64
1 files changed, 64 insertions, 0 deletions
diff --git a/etc/profile-a-l/alacarte.profile b/etc/profile-a-l/alacarte.profile
new file mode 100644
index 000000000..5fabf8283
--- /dev/null
+++ b/etc/profile-a-l/alacarte.profile
@@ -0,0 +1,64 @@
1# Firejail profile for alacarte
2# Description: Create desktop and menu launchers easily
3# This file is overwritten after every install/update
4# Persistent local customizations
5include alacarte.local
6# Persistent global definitions
7include globals.local
8
9include allow-python2.inc
10include allow-python3.inc
11
12include disable-common.inc
13include disable-devel.inc
14include disable-exec.inc
15include disable-interpreters.inc
16include disable-programs.inc
17include disable-passwdmgr.inc
18include disable-xdg.inc
19
20# Whitelist your system icon directory,varies by distro
21whitelist /usr/share/alacarte
22whitelist /usr/share/app-info
23whitelist /usr/share/desktop-directories
24whitelist /usr/share/icons
25whitelist /var/lib/app-info/icons
26whitelist /var/lib/flatpak/exports/share/applications
27whitelist /var/lib/flatpak/exports/share/icons
28include whitelist-runuser-common.inc
29include whitelist-usr-share-common.inc
30include whitelist-var-common.inc
31
32apparmor
33caps.drop all
34machine-id
35net none
36nodvd
37no3d
38nogroups
39nonewprivs
40noroot
41nosound
42notv
43nou2f
44novideo
45protocol unix
46seccomp
47seccomp.block-secondary
48shell none
49tracelog
50
51disable-mnt
52private-bin alacarte,bash,python*,sh
53private-cache
54private-dev
55private-etc alternatives,dconf,fonts,gtk-3.0,locale.alias,locale.conf,login.defs,mime.types,nsswitch.conf,passwd,pki,X11,xdg
56private-tmp
57
58dbus-user none
59dbus-system none
60
61read-write ${HOME}/.config/menus
62read-write ${HOME}/.gnome/apps
63read-write ${HOME}/.local/share/applications
64read-write ${HOME}/.local/share/flatpak/exports