aboutsummaryrefslogtreecommitdiffstats
path: root/etc/profile-a-l/blink-common.profile
diff options
context:
space:
mode:
authorLibravatar pirate486743186 <>2023-03-16 02:30:52 +0100
committerLibravatar pirate486743186 <>2023-03-16 15:00:37 +0100
commit47e3c82ab58b0d0c02066666aea3f7a04078c86b (patch)
tree10d06366bb00a50209ea0c24366e599061cff53a /etc/profile-a-l/blink-common.profile
parentfirejail.txt: remove extraneous endif (diff)
downloadfirejail-47e3c82ab58b0d0c02066666aea3f7a04078c86b.tar.gz
firejail-47e3c82ab58b0d0c02066666aea3f7a04078c86b.tar.zst
firejail-47e3c82ab58b0d0c02066666aea3f7a04078c86b.zip
create blink-common.profile
Diffstat (limited to 'etc/profile-a-l/blink-common.profile')
-rw-r--r--etc/profile-a-l/blink-common.profile40
1 files changed, 40 insertions, 0 deletions
diff --git a/etc/profile-a-l/blink-common.profile b/etc/profile-a-l/blink-common.profile
new file mode 100644
index 000000000..ff17dc479
--- /dev/null
+++ b/etc/profile-a-l/blink-common.profile
@@ -0,0 +1,40 @@
1# Firejail profile for blink-common
2# Description: Common profile for Blink-based applications
3# This file is overwritten after every install/update
4# Persistent local customizations
5include blink-common.local
6# Persistent global definitions
7# added by caller profile
8#include globals.local
9
10include disable-common.inc
11include disable-devel.inc
12include disable-exec.inc
13include disable-interpreters.inc
14include disable-programs.inc
15include disable-xdg.inc
16
17whitelist ${DOWNLOADS}
18include whitelist-common.inc
19#include whitelist-run-common.inc
20include whitelist-runuser-common.inc
21include whitelist-usr-share-common.inc
22include whitelist-var-common.inc
23
24# If your kernel allows the creation of user namespaces by unprivileged users
25# (for example, if running `unshare -U echo enabled` prints "enabled"), you
26# can add the next line to your blink-common.local.
27#include blink-common-hardened.inc.profile
28
29apparmor
30caps.keep sys_admin,sys_chroot
31netfilter
32nodvd
33nogroups
34noinput
35notv
36
37disable-mnt
38private-cache
39
40dbus-system none