aboutsummaryrefslogtreecommitdiffstats
path: root/etc/profile-a-l/artha.profile
diff options
context:
space:
mode:
authorLibravatar netblue30 <netblue30@yahoo.com>2020-04-21 08:24:28 -0400
committerLibravatar netblue30 <netblue30@yahoo.com>2020-04-21 08:24:28 -0400
commit018d75775eab4a0f045949a9d069c57686ca2686 (patch)
treeaac3a1a65cca0d4875795c55109a5c3e35efdefb /etc/profile-a-l/artha.profile
parentsmall fixes (diff)
downloadfirejail-018d75775eab4a0f045949a9d069c57686ca2686.tar.gz
firejail-018d75775eab4a0f045949a9d069c57686ca2686.tar.zst
firejail-018d75775eab4a0f045949a9d069c57686ca2686.zip
reorganize github etc directory
Diffstat (limited to 'etc/profile-a-l/artha.profile')
-rw-r--r--etc/profile-a-l/artha.profile65
1 files changed, 65 insertions, 0 deletions
diff --git a/etc/profile-a-l/artha.profile b/etc/profile-a-l/artha.profile
new file mode 100644
index 000000000..19a4771aa
--- /dev/null
+++ b/etc/profile-a-l/artha.profile
@@ -0,0 +1,65 @@
1# Firejail profile for artha
2# Description: A free cross-platform English thesaurus based on WordNet
3# This file is overwritten after every install/update
4# Persistent local customizations
5include artha.local
6# Persistent global definitions
7include globals.local
8
9noblacklist ${HOME}/.config/artha.conf
10noblacklist ${HOME}/.config/artha.log
11noblacklist ${HOME}/.config/enchant
12
13blacklist /tmp/.X11-unix
14blacklist ${RUNUSER}/wayland-*
15
16include disable-common.inc
17include disable-devel.inc
18include disable-exec.inc
19include disable-interpreters.inc
20include disable-passwdmgr.inc
21include disable-programs.inc
22include disable-xdg.inc
23
24# whitelisting in ${HOME} makes settings immutable, see #3112
25#mkfile ${HOME}/.config/artha.conf
26#mkdir ${HOME}/.config/enchant
27#whitelist ${HOME}/.config/artha.conf
28#whitelist ${HOME}/.config/artha.log
29#whitelist ${HOME}/.config/enchant
30whitelist /usr/share/artha
31whitelist /usr/share/wordnet
32#include whitelist-common.inc
33include whitelist-usr-share-common.inc
34include whitelist-var-common.inc
35
36apparmor
37caps.drop all
38ipc-namespace
39# net none - breaks on Ubuntu
40no3d
41nodvd
42nogroups
43nonewprivs
44noroot
45nosound
46notv
47nou2f
48novideo
49protocol unix
50seccomp
51shell none
52tracelog
53
54disable-mnt
55private-bin artha,enchant,notify-send
56private-cache
57private-dev
58private-etc alternatives,fonts,machine-id
59private-lib libnotify.so.*
60private-tmp
61
62# dbus-user none
63# dbus-system none
64
65memory-deny-write-execute