aboutsummaryrefslogtreecommitdiffstats
path: root/etc/profile-a-l
diff options
context:
space:
mode:
authorLibravatar glitsj16 <glitsj16@users.noreply.github.com>2021-02-25 12:55:21 +0000
committerLibravatar GitHub <noreply@github.com>2021-02-25 12:55:21 +0000
commit753c362aa8fe7d11a944fa6f2d4a61ee6101ee17 (patch)
tree4f3c8769c2569403c1d919689b44a8757d315d26 /etc/profile-a-l
parentadd gget (diff)
downloadfirejail-753c362aa8fe7d11a944fa6f2d4a61ee6101ee17.tar.gz
firejail-753c362aa8fe7d11a944fa6f2d4a61ee6101ee17.tar.zst
firejail-753c362aa8fe7d11a944fa6f2d4a61ee6101ee17.zip
Create gget.profile
Diffstat (limited to 'etc/profile-a-l')
-rw-r--r--etc/profile-a-l/gget.profile59
1 files changed, 59 insertions, 0 deletions
diff --git a/etc/profile-a-l/gget.profile b/etc/profile-a-l/gget.profile
new file mode 100644
index 000000000..c4e87e39d
--- /dev/null
+++ b/etc/profile-a-l/gget.profile
@@ -0,0 +1,59 @@
1# Firejail profile for gget
2# Description: a cli. to get things. from git repos
3# This file is overwritten after every install/update
4quiet
5# Persistent local customizations
6include gget.local
7# Persistent global definitions
8include globals.local
9
10blacklist /tmp/.X11-unix
11blacklist ${RUNUSER}
12
13include disable-common.inc
14include disable-devel.inc
15include disable-exec.inc
16include disable-interpreters.inc
17include disable-passwdmgr.inc
18include disable-programs.inc
19include disable-shell.inc
20include disable-xdg.inc
21
22whitelist ${DOWNLOADS}
23include whitelist-common.inc
24include whitelist-runuser-common.inc
25include whitelist-usr-share-common.inc
26include whitelist-var-common.inc
27
28apparmor
29caps.drop all
30ipc-namespace
31machine-id
32netfilter
33no3d
34nodvd
35nogroups
36nonewprivs
37noroot
38nosound
39notv
40nou2f
41novideo
42protocol inet,inet6
43seccomp
44seccomp.block-secondary
45shell none
46tracelog
47
48disable-mnt
49private-bin gget
50private-cache
51private-dev
52private-etc alternatives,ca-certificates,crypto-policies,pki,resolv.conf,ssl
53private-lib
54private-tmp
55
56dbus-user none
57dbus-system none
58
59memory-deny-write-execute