aboutsummaryrefslogtreecommitdiffstats
path: root/etc/profile-m-z
diff options
context:
space:
mode:
authorLibravatar glitsj16 <glitsj16@users.noreply.github.com>2023-07-25 19:39:21 +0000
committerLibravatar GitHub <noreply@github.com>2023-07-25 19:39:21 +0000
commit142a2130f79250a464a9a2dcaf02cdec61fdb92b (patch)
treee65b85a7f89bb3a02a62ff094c9187b415ae2c48 /etc/profile-m-z
parentprofiles: fixes and cleanups for opening links with firefox (#5919) (diff)
downloadfirejail-142a2130f79250a464a9a2dcaf02cdec61fdb92b.tar.gz
firejail-142a2130f79250a464a9a2dcaf02cdec61fdb92b.tar.zst
firejail-142a2130f79250a464a9a2dcaf02cdec61fdb92b.zip
New profile: sniffnet (#5920)
* disable-programs.inc: add sniffnet support * Create sniffnet.profile * firecfg.config: add sniffnet support
Diffstat (limited to 'etc/profile-m-z')
-rw-r--r--etc/profile-m-z/sniffnet.profile49
1 files changed, 49 insertions, 0 deletions
diff --git a/etc/profile-m-z/sniffnet.profile b/etc/profile-m-z/sniffnet.profile
new file mode 100644
index 000000000..eb18c1f01
--- /dev/null
+++ b/etc/profile-m-z/sniffnet.profile
@@ -0,0 +1,49 @@
1# Firejail profile for sniffnet
2# Description: Network traffic monitor
3# This file is overwritten after every install/update
4# Persistent local customizations
5include sniffnet.local
6# Persistent global definitions
7include globals.local
8
9noblacklist ${HOME}/.config/sniffnet
10
11include disable-common.inc
12include disable-devel.inc
13include disable-exec.inc
14include disable-interpreters.inc
15include disable-proc.inc
16include disable-programs.inc
17include disable-xdg.inc
18
19include whitelist-common.inc
20include whitelist-run-common.inc
21include whitelist-runuser-common.inc
22include whitelist-usr-share-common.inc
23include whitelist-var-common.inc
24
25apparmor
26#caps.drop all
27caps.keep net_admin,net_raw
28netfilter
29nodvd
30nogroups
31noinput
32# nonewprivs - breaks network traffic capture for unprivileged users
33# noroot
34notv
35nou2f
36novideo
37#seccomp
38tracelog
39
40disable-mnt
41#private-bin sniffnet
42# private-dev prevents (some) interfaces from being shown.
43private-etc @network,@tls-ca
44private-tmp
45
46dbus-user none
47dbus-system none
48
49#restrict-namespaces