aboutsummaryrefslogtreecommitdiffstats
path: root/etc/wire-desktop.profile
diff options
context:
space:
mode:
authorLibravatar Jean Lucas <jean@4ray.co>2018-06-14 04:30:58 -0400
committerLibravatar Jean Lucas <jean@4ray.co>2018-06-14 04:32:51 -0400
commitf57bacc8c72c3f120b33b1516da965431dc543a4 (patch)
treee1f50484d8d0e64eeeb360456c9f71076e10298c /etc/wire-desktop.profile
parentAdd --keep-dev-shm (undocumented for now). (diff)
downloadfirejail-f57bacc8c72c3f120b33b1516da965431dc543a4.tar.gz
firejail-f57bacc8c72c3f120b33b1516da965431dc543a4.tar.zst
firejail-f57bacc8c72c3f120b33b1516da965431dc543a4.zip
Amend Wire profiles
Diffstat (limited to 'etc/wire-desktop.profile')
-rw-r--r--etc/wire-desktop.profile33
1 files changed, 33 insertions, 0 deletions
diff --git a/etc/wire-desktop.profile b/etc/wire-desktop.profile
new file mode 100644
index 000000000..c0e0b3c4b
--- /dev/null
+++ b/etc/wire-desktop.profile
@@ -0,0 +1,33 @@
1# Firejail profile for wire-desktop
2# This file is overwritten after every install/update
3# Persistent local customizations
4include /etc/firejail/wire-desktop.local
5# Persistent global definitions
6include /etc/firejail/globals.local
7
8noblacklist ${HOME}/.config/Wire
9
10include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-interpreters.inc
13include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc
15
16caps.drop all
17netfilter
18nodvd
19nogroups
20nonewprivs
21noroot
22notv
23protocol unix,inet,inet6,netlink
24seccomp
25shell none
26
27# Note: The current version of Wire is located in /opt/wire-desktop/wire-desktop, and therefore
28# it is not in PATH. To use Wire with firejail, run "firejail /opt/wire-desktop/wire-desktop"
29
30private-bin wire-desktop
31disable-mnt
32private-dev
33private-tmp