aboutsummaryrefslogtreecommitdiffstats
path: root/etc/psi-plus.profile
diff options
context:
space:
mode:
authorLibravatar Tad <tad@spotco.us>2017-08-07 01:22:08 -0400
committerLibravatar Tad <tad@spotco.us>2017-08-07 01:22:08 -0400
commit9e3ba319be6b9546d7e8f450ca419ee2f3f4040b (patch)
tree0aebe82de78a61877c267f4dcb2ebcc13a2e37c9 /etc/psi-plus.profile
parentvarious profile fixes (#1433) (diff)
downloadfirejail-9e3ba319be6b9546d7e8f450ca419ee2f3f4040b.tar.gz
firejail-9e3ba319be6b9546d7e8f450ca419ee2f3f4040b.tar.zst
firejail-9e3ba319be6b9546d7e8f450ca419ee2f3f4040b.zip
Unify all profiles
Diffstat (limited to 'etc/psi-plus.profile')
-rw-r--r--etc/psi-plus.profile24
1 files changed, 11 insertions, 13 deletions
diff --git a/etc/psi-plus.profile b/etc/psi-plus.profile
index 9500731fe..27ee2500c 100644
--- a/etc/psi-plus.profile
+++ b/etc/psi-plus.profile
@@ -1,27 +1,25 @@
1# Persistent global definitions go here 1# Firejail profile for psi-plus
2include /etc/firejail/globals.local 2# This file is overwritten after every install/update
3 3# Persistent local customizations
4# This file is overwritten during software install.
5# Persistent customizations should go in a .local file.
6include /etc/firejail/psi-plus.local 4include /etc/firejail/psi-plus.local
5# Persistent global definitions
6include /etc/firejail/globals.local
7 7
8# Firejail profile for Psi+
9noblacklist ${HOME}/.config/psi+ 8noblacklist ${HOME}/.config/psi+
10noblacklist ${HOME}/.local/share/psi+ 9noblacklist ${HOME}/.local/share/psi+
11 10
12include /etc/firejail/disable-common.inc 11include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-devel.inc 12include /etc/firejail/disable-devel.inc
14include /etc/firejail/disable-programs.inc
15include /etc/firejail/disable-passwdmgr.inc 13include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc
16 15
17whitelist ${DOWNLOADS} 16mkdir ~/.cache/psi+
18mkdir ~/.config/psi+ 17mkdir ~/.config/psi+
19whitelist ~/.config/psi+
20mkdir ~/.local/share/psi+ 18mkdir ~/.local/share/psi+
21whitelist ~/.local/share/psi+ 19whitelist ${DOWNLOADS}
22mkdir ~/.cache/psi+
23whitelist ~/.cache/psi+ 20whitelist ~/.cache/psi+
24 21whitelist ~/.config/psi+
22whitelist ~/.local/share/psi+
25include /etc/firejail/whitelist-common.inc 23include /etc/firejail/whitelist-common.inc
26 24
27caps.drop all 25caps.drop all
@@ -35,9 +33,9 @@ protocol unix,inet,inet6
35seccomp 33seccomp
36shell none 34shell none
37 35
36disable-mnt
38private-dev 37private-dev
39private-tmp 38private-tmp
40disable-mnt
41 39
42noexec ${HOME} 40noexec ${HOME}
43noexec /tmp 41noexec /tmp