aboutsummaryrefslogtreecommitdiffstats
path: root/etc/tor-browser-ko.profile
diff options
context:
space:
mode:
authorLibravatar Tad <tad@spotco.us>2018-01-01 05:38:43 -0500
committerLibravatar Tad <tad@spotco.us>2018-01-01 05:38:43 -0500
commit2cd93846c5133608e9870c6b8c0955bf0a09ab81 (patch)
treebb12bdc5453188a4eeb4aa5e7f62017d74daef4e /etc/tor-browser-ko.profile
parenttor flavours (diff)
downloadfirejail-2cd93846c5133608e9870c6b8c0955bf0a09ab81.tar.gz
firejail-2cd93846c5133608e9870c6b8c0955bf0a09ab81.tar.zst
firejail-2cd93846c5133608e9870c6b8c0955bf0a09ab81.zip
Simplfy locale specific Tor Browser profiles
Diffstat (limited to 'etc/tor-browser-ko.profile')
-rw-r--r--etc/tor-browser-ko.profile38
1 files changed, 5 insertions, 33 deletions
diff --git a/etc/tor-browser-ko.profile b/etc/tor-browser-ko.profile
index 6e87bd24f..c1a29f84e 100644
--- a/etc/tor-browser-ko.profile
+++ b/etc/tor-browser-ko.profile
@@ -1,36 +1,8 @@
1# Firejail profile for tor-browser-ko from the Arch User Repository: 1# Firejail profile alias for torbrowser-launcher
2# This file is overwritten after every install/update
2 3
3 4noblacklist ${HOME}/.tor-browser-ko
4blacklist /usr/local/bin
5blacklist /boot
6blacklist /media
7blacklist /mnt
8blacklist /opt
9blacklist /var
10
11private-bin bash,grep,sed,tail,tor-browser-ko,env,id,readlink,dirname,test,mkdir,ln,sed,cp,rm,getconf,file,expr
12whitelist ${HOME}/.tor-browser-ko 5whitelist ${HOME}/.tor-browser-ko
13whitelist /dev/dri
14whitelist /dev/full
15whitelist /dev/null
16whitelist /dev/ptmx
17whitelist /dev/pts
18whitelist /dev/random
19whitelist /dev/shm
20whitelist /dev/snd
21whitelist /dev/tty
22whitelist /dev/urandom
23whitelist /dev/video0
24whitelist /dev/zero
25whitelist ~/Downloads
26
27# FIXME: Spoof D-Bus machine id (tor-browser segfaults when it is missing!)
28# https://github.com/netblue30/firejail/issues/955
29private-etc X11,pulse,machine-id
30 6
31private-tmp 7# Redirect
32noexec /tmp 8include /etc/firejail/torbrowser-launcher.profile
33shell none
34seccomp
35noroot
36caps.drop all