aboutsummaryrefslogtreecommitdiffstats
path: root/etc/rambox.profile
diff options
context:
space:
mode:
authorLibravatar Fred Barclay <Fred-Barclay@users.noreply.github.com>2017-08-07 13:41:08 -0500
committerLibravatar GitHub <noreply@github.com>2017-08-07 13:41:08 -0500
commite24b15f8647997dbb26a7152c921af94e36294ce (patch)
tree4c98b42844c8c67853643d4b4b7253dbd8764f1e /etc/rambox.profile
parentmerges (diff)
parentUnify last 8 profiles (diff)
downloadfirejail-e24b15f8647997dbb26a7152c921af94e36294ce.tar.gz
firejail-e24b15f8647997dbb26a7152c921af94e36294ce.tar.zst
firejail-e24b15f8647997dbb26a7152c921af94e36294ce.zip
Merge pull request #1427 from SpotComms/pr
Unify all profiles
Diffstat (limited to 'etc/rambox.profile')
-rw-r--r--etc/rambox.profile32
1 files changed, 15 insertions, 17 deletions
diff --git a/etc/rambox.profile b/etc/rambox.profile
index 2c70fbd13..a5b87e901 100644
--- a/etc/rambox.profile
+++ b/etc/rambox.profile
@@ -1,16 +1,23 @@
1#Persistent global definitions go here 1# Firejail profile for rambox
2include /etc/firejail/globals.local 2# This file is overwritten after every install/update
3 3# Persistent local customizations
4#This file is overwritten during software install.
5#Persistent customizations should go in a .local file.
6include /etc/firejail/rambox.local 4include /etc/firejail/rambox.local
5# Persistent global definitions
6include /etc/firejail/globals.local
7 7
8# Rambox profile for firejail
9noblacklist ~/.config/Rambox 8noblacklist ~/.config/Rambox
10noblacklist ~/.pki 9noblacklist ~/.pki
10
11include /etc/firejail/disable-common.inc 11include /etc/firejail/disable-common.inc
12include /etc/firejail/disable-programs.inc
13include /etc/firejail/disable-devel.inc 12include /etc/firejail/disable-devel.inc
13include /etc/firejail/disable-programs.inc
14
15mkdir ~/.config/Rambox
16mkdir ~/.pki
17whitelist ${DOWNLOADS}
18whitelist ~/.config/Rambox
19whitelist ~/.pki
20include /etc/firejail/whitelist-common.inc
14 21
15caps.drop all 22caps.drop all
16netfilter 23netfilter
@@ -19,13 +26,4 @@ nonewprivs
19noroot 26noroot
20protocol unix,inet,inet6,netlink 27protocol unix,inet,inet6,netlink
21seccomp 28seccomp
22#tracelog 29# tracelog
23
24whitelist ${DOWNLOADS}
25mkdir ~/.config/Rambox
26whitelist ~/.config/Rambox
27mkdir ~/.pki
28whitelist ~/.pki
29
30include /etc/firejail/whitelist-common.inc
31