aboutsummaryrefslogtreecommitdiffstats
path: root/etc/zulip.profile
diff options
context:
space:
mode:
authorLibravatar Jean Lucas <jean@4ray.co>2019-07-31 03:23:02 -0400
committerLibravatar Jean Lucas <jean@4ray.co>2019-07-31 13:58:06 -0400
commitb0b62e28dc9e14b8d693c8d24bc2722e6a8e56ef (patch)
treeae31c11497ab5749ad4fd444c5c37e18cdc9a796 /etc/zulip.profile
parentAdd tb-starter-wrapper.profile (#2863) (diff)
downloadfirejail-b0b62e28dc9e14b8d693c8d24bc2722e6a8e56ef.tar.gz
firejail-b0b62e28dc9e14b8d693c8d24bc2722e6a8e56ef.tar.zst
firejail-b0b62e28dc9e14b8d693c8d24bc2722e6a8e56ef.zip
Add Zulip profile
Diffstat (limited to 'etc/zulip.profile')
-rw-r--r--etc/zulip.profile46
1 files changed, 46 insertions, 0 deletions
diff --git a/etc/zulip.profile b/etc/zulip.profile
new file mode 100644
index 000000000..d3f9a2240
--- /dev/null
+++ b/etc/zulip.profile
@@ -0,0 +1,46 @@
1# Firejail profile for zulip
2# Description: Real-time team chat based on the email threading model
3# This file is overwritten after every install/update
4# Persistent local customizations
5include zulip.local
6# Persistent global definitions
7include globals.local
8
9ignore noexec /tmp
10
11noblacklist ${HOME}/.config/Zulip
12
13include disable-common.inc
14include disable-devel.inc
15include disable-exec.inc
16include disable-interpreters.inc
17include disable-passwdmgr.inc
18include disable-programs.inc
19
20mkdir ${HOME}/.config/Zulip
21whitelist ${HOME}/.config/Zulip
22whitelist ${DOWNLOADS}
23include whitelist-common.inc
24include whitelist-var-common.inc
25
26apparmor
27caps.drop all
28netfilter
29no3d
30nodvd
31nogroups
32nonewprivs
33noroot
34notv
35nou2f
36novideo
37protocol unix,inet,inet6
38seccomp
39shell none
40
41disable-mnt
42private-bin locale,zulip
43private-cache
44private-dev
45private-etc asound.conf,fonts,machine-id
46private-tmp