aboutsummaryrefslogtreecommitdiffstats
path: root/etc/tor-browser-en.profile
diff options
context:
space:
mode:
authorLibravatar Tad <tad@spotco.us>2017-09-16 13:47:31 -0400
committerLibravatar Tad <tad@spotco.us>2017-09-18 18:24:13 -0400
commit60606c2d041dc08b0af10baff1b18dbf507f8d81 (patch)
tree75ca83f6148cf6e93e75df9be3b85ab702a5fb9c /etc/tor-browser-en.profile
parentAdd 5 profiles (diff)
downloadfirejail-60606c2d041dc08b0af10baff1b18dbf507f8d81.tar.gz
firejail-60606c2d041dc08b0af10baff1b18dbf507f8d81.tar.zst
firejail-60606c2d041dc08b0af10baff1b18dbf507f8d81.zip
Fixup 36 profiles
Diffstat (limited to 'etc/tor-browser-en.profile')
-rw-r--r--etc/tor-browser-en.profile28
1 files changed, 7 insertions, 21 deletions
diff --git a/etc/tor-browser-en.profile b/etc/tor-browser-en.profile
index 1f0b61c75..65ea41e18 100644
--- a/etc/tor-browser-en.profile
+++ b/etc/tor-browser-en.profile
@@ -5,26 +5,15 @@ include /etc/firejail/tor-browser-en.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8blacklist /boot 8
9blacklist /media 9noblacklist ${HOME}/.tor-browser-en
10blacklist /mnt 10
11blacklist /opt 11include /etc/firejail/disable-common.inc
12blacklist /usr/local/bin 12include /etc/firejail/disable-devel.inc
13blacklist /var 13include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc
14 15
15whitelist ${HOME}/.tor-browser-en 16whitelist ${HOME}/.tor-browser-en
16whitelist /dev/dri
17whitelist /dev/full
18whitelist /dev/null
19whitelist /dev/ptmx
20whitelist /dev/pts
21whitelist /dev/random
22whitelist /dev/shm
23whitelist /dev/snd
24whitelist /dev/tty
25whitelist /dev/urandom
26whitelist /dev/video0
27whitelist /dev/zero
28include /etc/firejail/whitelist-common.inc 17include /etc/firejail/whitelist-common.inc
29 18
30caps.drop all 19caps.drop all
@@ -33,9 +22,6 @@ seccomp
33shell none 22shell none
34 23
35private-bin bash,grep,sed,tail,tor-browser-en,env,id,readlink,dirname,test,mkdir,ln,sed,cp,rm,getconf,file,expr 24private-bin bash,grep,sed,tail,tor-browser-en,env,id,readlink,dirname,test,mkdir,ln,sed,cp,rm,getconf,file,expr
36# FIXME: Spoof D-Bus machine id (tor-browser segfaults when it is missing!)
37# https://github.com/netblue30/firejail/issues/955
38private-etc X11,pulse,machine-id
39private-tmp 25private-tmp
40 26
41noexec /tmp 27noexec /tmp