aboutsummaryrefslogtreecommitdiffstats
path: root/etc/profile-m-z
diff options
context:
space:
mode:
authorLibravatar glitsj16 <glitsj16@users.noreply.github.com>2022-10-03 18:32:54 +0000
committerLibravatar GitHub <noreply@github.com>2022-10-03 18:32:54 +0000
commit669c18c606893be64011d6b76763243db1b79b9c (patch)
tree36572bbb53a90672c95782135e0817672b8cfaad /etc/profile-m-z
parentFix D-Bus mpris support (diff)
downloadfirejail-669c18c606893be64011d6b76763243db1b79b9c.tar.gz
firejail-669c18c606893be64011d6b76763243db1b79b9c.tar.zst
firejail-669c18c606893be64011d6b76763243db1b79b9c.zip
Harden qutebrowser
Diffstat (limited to 'etc/profile-m-z')
-rw-r--r--etc/profile-m-z/qutebrowser.profile9
1 files changed, 9 insertions, 0 deletions
diff --git a/etc/profile-m-z/qutebrowser.profile b/etc/profile-m-z/qutebrowser.profile
index 5b254c58b..ae62c0b89 100644
--- a/etc/profile-m-z/qutebrowser.profile
+++ b/etc/profile-m-z/qutebrowser.profile
@@ -10,6 +10,9 @@ noblacklist ${HOME}/.cache/qutebrowser
10noblacklist ${HOME}/.config/qutebrowser 10noblacklist ${HOME}/.config/qutebrowser
11noblacklist ${HOME}/.local/share/qutebrowser 11noblacklist ${HOME}/.local/share/qutebrowser
12 12
13# Allow /bin/sh (blacklisted by disable-shell.inc)
14include allow-bin-sh.inc
15
13# Allow python (blacklisted by disable-interpreters.inc) 16# Allow python (blacklisted by disable-interpreters.inc)
14include allow-python2.inc 17include allow-python2.inc
15include allow-python3.inc 18include allow-python3.inc
@@ -19,6 +22,7 @@ include disable-devel.inc
19include disable-exec.inc 22include disable-exec.inc
20include disable-interpreters.inc 23include disable-interpreters.inc
21include disable-programs.inc 24include disable-programs.inc
25include disable-shell.inc
22 26
23mkdir ${HOME}/.cache/qutebrowser 27mkdir ${HOME}/.cache/qutebrowser
24mkdir ${HOME}/.config/qutebrowser 28mkdir ${HOME}/.config/qutebrowser
@@ -27,7 +31,12 @@ whitelist ${DOWNLOADS}
27whitelist ${HOME}/.cache/qutebrowser 31whitelist ${HOME}/.cache/qutebrowser
28whitelist ${HOME}/.config/qutebrowser 32whitelist ${HOME}/.config/qutebrowser
29whitelist ${HOME}/.local/share/qutebrowser 33whitelist ${HOME}/.local/share/qutebrowser
34whitelist /usr/share/qtbrowser
30include whitelist-common.inc 35include whitelist-common.inc
36include whitelist-run-common.inc
37include whitelist-runuser-common.inc
38include whitelist-usr-share-common.inc
39include whitelist-var-common.inc
31 40
32apparmor 41apparmor
33caps.drop all 42caps.drop all