aboutsummaryrefslogtreecommitdiffstats
path: root/etc/rambox.profile
diff options
context:
space:
mode:
authorLibravatar Fred Barclay <Fred-Barclay@users.noreply.github.com>2017-08-02 12:02:28 -0500
committerLibravatar Fred Barclay <Fred-Barclay@users.noreply.github.com>2017-08-02 12:02:28 -0500
commit88d919ce9b9d0be693366b25eb1c4f3647c023d3 (patch)
treeabfa2be0b75e0b7fbf7ae50413afd9a0b901df86 /etc/rambox.profile
parentmerges (diff)
downloadfirejail-88d919ce9b9d0be693366b25eb1c4f3647c023d3.tar.gz
firejail-88d919ce9b9d0be693366b25eb1c4f3647c023d3.tar.zst
firejail-88d919ce9b9d0be693366b25eb1c4f3647c023d3.zip
Add rambox profile from #1425
Diffstat (limited to 'etc/rambox.profile')
-rw-r--r--etc/rambox.profile31
1 files changed, 31 insertions, 0 deletions
diff --git a/etc/rambox.profile b/etc/rambox.profile
new file mode 100644
index 000000000..2c70fbd13
--- /dev/null
+++ b/etc/rambox.profile
@@ -0,0 +1,31 @@
1#Persistent global definitions go here
2include /etc/firejail/globals.local
3
4#This file is overwritten during software install.
5#Persistent customizations should go in a .local file.
6include /etc/firejail/rambox.local
7
8# Rambox profile for firejail
9noblacklist ~/.config/Rambox
10noblacklist ~/.pki
11include /etc/firejail/disable-common.inc
12include /etc/firejail/disable-programs.inc
13include /etc/firejail/disable-devel.inc
14
15caps.drop all
16netfilter
17nogroups
18nonewprivs
19noroot
20protocol unix,inet,inet6,netlink
21seccomp
22#tracelog
23
24whitelist ${DOWNLOADS}
25mkdir ~/.config/Rambox
26whitelist ~/.config/Rambox
27mkdir ~/.pki
28whitelist ~/.pki
29
30include /etc/firejail/whitelist-common.inc
31