aboutsummaryrefslogtreecommitdiffstats
path: root/etc/profile-a-l
diff options
context:
space:
mode:
authorLibravatar crocket <748856+crocket@users.noreply.github.com>2021-10-09 22:43:30 +0900
committerLibravatar crocket <748856+crocket@users.noreply.github.com>2021-10-17 22:09:24 +0900
commitb6c1230e3b2d019b1d1803791ce0698cdb3c5ab9 (patch)
tree661607a7fa8ba918ccec9761c6d3e970c972b77c /etc/profile-a-l
parentUpdate README.md RELNOTES (diff)
downloadfirejail-b6c1230e3b2d019b1d1803791ce0698cdb3c5ab9.tar.gz
firejail-b6c1230e3b2d019b1d1803791ce0698cdb3c5ab9.tar.zst
firejail-b6c1230e3b2d019b1d1803791ce0698cdb3c5ab9.zip
Add profiles for imv, retroarch, and torbrowser
imv, retroarch, and torbrowser are also added to firecfg.config
Diffstat (limited to 'etc/profile-a-l')
-rw-r--r--etc/profile-a-l/imv.profile57
1 files changed, 57 insertions, 0 deletions
diff --git a/etc/profile-a-l/imv.profile b/etc/profile-a-l/imv.profile
new file mode 100644
index 000000000..65e7537bf
--- /dev/null
+++ b/etc/profile-a-l/imv.profile
@@ -0,0 +1,57 @@
1# Firejail profile for imv
2# Description: imv is an image viewer.
3# This file is overwritten after every install/update
4# Persistent local customizations
5include imv.local
6# Persistent global definitions
7include globals.local
8
9include allow-bin-sh.inc
10
11blacklist /usr/libexec
12
13include disable-common.inc
14include disable-devel.inc
15include disable-exec.inc
16include disable-interpreters.inc
17include disable-programs.inc
18include disable-shell.inc
19include disable-write-mnt.inc
20# Users may want to view images in ${HOME}
21#include disable-xdg.inc
22
23# Users may want to view images in ${HOME}
24#include whitelist-common.inc
25include whitelist-run-common.inc
26include whitelist-runuser-common.inc
27# Users may want to view images in /usr/share
28#include whitelist-usr-share-common.inc
29include whitelist-var-common.inc
30
31apparmor
32caps.drop all
33net none
34nodvd
35nogroups
36noinput
37nonewprivs
38noroot
39nosound
40notv
41nou2f
42novideo
43protocol unix
44seccomp
45seccomp.block-secondary
46shell none
47tracelog
48
49private-bin imv,imv-wayland,imv-x11,sh
50private-cache
51private-dev
52private-tmp
53
54dbus-user none
55dbus-system none
56
57read-only ${HOME}