aboutsummaryrefslogtreecommitdiffstats
path: root/etc/yandex-browser.profile
diff options
context:
space:
mode:
authorLibravatar Tad <tad@spotco.us>2017-09-02 10:32:45 -0400
committerLibravatar Tad <tad@spotco.us>2017-09-02 10:42:06 -0400
commit7fd9fa0cf4e1d2fc997bef23caea883850da6693 (patch)
tree2839a7865d0c4696e0e2ad4f39f40ef92953be5f /etc/yandex-browser.profile
parentImprove seccomp support for non-x86 architectures (diff)
downloadfirejail-7fd9fa0cf4e1d2fc997bef23caea883850da6693.tar.gz
firejail-7fd9fa0cf4e1d2fc997bef23caea883850da6693.tar.zst
firejail-7fd9fa0cf4e1d2fc997bef23caea883850da6693.zip
Add a profile for Yandex browser
Thanks to @larkvirtual for the paths and testing
Diffstat (limited to 'etc/yandex-browser.profile')
-rw-r--r--etc/yandex-browser.profile42
1 files changed, 42 insertions, 0 deletions
diff --git a/etc/yandex-browser.profile b/etc/yandex-browser.profile
new file mode 100644
index 000000000..bfb7b9d87
--- /dev/null
+++ b/etc/yandex-browser.profile
@@ -0,0 +1,42 @@
1# Firejail profile for yandex-browser
2# This file is overwritten after every install/update
3# Persistent local customizations
4include /etc/firejail/yandex-browser.local
5# Persistent global definitions
6include /etc/firejail/globals.local
7
8noblacklist ~/.cache/yandex-browser
9noblacklist ~/.cache/yandex-browser-beta
10noblacklist ~/.config/yandex-browser
11noblacklist ~/.config/yandex-browser-beta
12noblacklist ~/.pki
13
14include /etc/firejail/disable-common.inc
15include /etc/firejail/disable-devel.inc
16include /etc/firejail/disable-programs.inc
17
18mkdir ~/.cache/yandex-browser
19mkdir ~/.cache/yandex-browser-beta
20mkdir ~/.config/yandex-browser
21mkdir ~/.config/yandex-browser-beta
22mkdir ~/.pki
23whitelist ${DOWNLOADS}
24whitelist ~/.cache/yandex-browser
25whitelist ~/.cache/yandex-browser-beta
26whitelist ~/.config/yandex-browser
27whitelist ~/.config/yandex-browser-beta
28whitelist ~/.pki
29include /etc/firejail/whitelist-common.inc
30
31caps.keep sys_chroot,sys_admin
32netfilter
33nodvd
34nogroups
35notv
36shell none
37
38private-dev
39# private-tmp - problems with multiple browser sessions
40
41noexec ${HOME}
42noexec /tmp