aboutsummaryrefslogtreecommitdiffstats
path: root/etc/start-tor-browser.profile
diff options
context:
space:
mode:
authorLibravatar Tad <tad@spotco.us>2018-02-27 02:34:22 -0500
committerLibravatar Tad <tad@spotco.us>2018-02-27 02:34:22 -0500
commit63d455fbe6cfde2f97137f51b779d44f22cb4675 (patch)
tree6aaf268fa06938fdcc72ca450d5a9e6c94521172 /etc/start-tor-browser.profile
parentAdd ld.so.cache to torbrowser-launcher.profile (diff)
downloadfirejail-63d455fbe6cfde2f97137f51b779d44f22cb4675.tar.gz
firejail-63d455fbe6cfde2f97137f51b779d44f22cb4675.tar.zst
firejail-63d455fbe6cfde2f97137f51b779d44f22cb4675.zip
Sync start-tor-browser with torbrowser-launcher profile'
start-tor-browser.profile should stay seperate from torbrowser-launcher for the case when downloaded manually. The other tor-browser-* are okay to extend torbrowser-launcher because their paths are known.
Diffstat (limited to 'etc/start-tor-browser.profile')
-rw-r--r--etc/start-tor-browser.profile6
1 files changed, 4 insertions, 2 deletions
diff --git a/etc/start-tor-browser.profile b/etc/start-tor-browser.profile
index a2bf47281..4cec0ad81 100644
--- a/etc/start-tor-browser.profile
+++ b/etc/start-tor-browser.profile
@@ -11,6 +11,8 @@ include /etc/firejail/disable-devel.inc
11include /etc/firejail/disable-passwdmgr.inc 11include /etc/firejail/disable-passwdmgr.inc
12include /etc/firejail/disable-programs.inc 12include /etc/firejail/disable-programs.inc
13 13
14include /etc/firejail/whitelist-var-common.inc
15
14caps.drop all 16caps.drop all
15netfilter 17netfilter
16nodvd 18nodvd
@@ -25,9 +27,9 @@ shell none
25tracelog 27tracelog
26 28
27disable-mnt 29disable-mnt
28private-bin bash,sh,grep,tail,env,gpg,id,readlink,dirname,test,mkdir,ln,sed,cp,rm,getconf 30private-bin bash,cp,dirname,env,expr,file,getconf,gpg,grep,id,ln,mkdir,python*,readlink,rm,sed,sh,tail,test,tor-browser-en,torbrowser-launcher
29private-dev 31private-dev
30private-etc fonts 32private-etc fonts,hostname,hosts,resolv.conf,pki,ssl,ca-certificates,crypto-policies,alsa,asound.conf,pulse,machine-id,ld.so.cache
31private-tmp 33private-tmp
32 34
33noexec /tmp 35noexec /tmp