summaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
authorLibravatar SYN-cook <syncookongit@gmail.com>2017-04-08 23:54:28 +0200
committerLibravatar GitHub <noreply@github.com>2017-04-08 23:54:28 +0200
commit9c3bf8306b38297fc7f4c2f4f395b80ce2bee711 (patch)
treeeeb98a2df26fd2aec57c8875abb7946d878b4cc4 /etc
parentDoc update after merging #1198 (diff)
downloadfirejail-9c3bf8306b38297fc7f4c2f4f395b80ce2bee711.tar.gz
firejail-9c3bf8306b38297fc7f4c2f4f395b80ce2bee711.tar.zst
firejail-9c3bf8306b38297fc7f4c2f4f395b80ce2bee711.zip
new baloo profile
Diffstat (limited to 'etc')
-rw-r--r--etc/baloo_file.profile39
1 files changed, 39 insertions, 0 deletions
diff --git a/etc/baloo_file.profile b/etc/baloo_file.profile
new file mode 100644
index 000000000..1acb5def2
--- /dev/null
+++ b/etc/baloo_file.profile
@@ -0,0 +1,39 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/baloo_file.local
4
5# KDE Baloo file daemon profile
6noblacklist ${HOME}/.kde4/share/config/baloofilerc
7noblacklist ${HOME}/.kde4/share/config/baloorc
8noblacklist ${HOME}/.kde/share/config/baloofilerc
9noblacklist ${HOME}/.kde/share/config/baloorc
10noblacklist ${HOME}/.config/baloofilerc
11noblacklist ${HOME}/.local/share/baloo
12include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-programs.inc
14include /etc/firejail/disable-devel.inc
15include /etc/firejail/disable-passwdmgr.inc
16
17caps.drop all
18nogroups
19nonewprivs
20noroot
21nosound
22protocol unix
23# Baloo makes ioprio_set system calls, which are blacklisted by default.
24# That's why we need to disable seccomp
25#seccomp
26
27private-dev
28private-tmp
29
30# Experimental: make home directory read-only and allow writing only
31# to Baloo configuration files and databases
32#read-only ${HOME}
33#read-write ${HOME}/.kde4/share/config/baloofilerc
34#read-write ${HOME}/.kde4/share/config/baloorc
35#read-write ${HOME}/.kde/share/config/baloofilerc
36#read-write ${HOME}/.kde/share/config/baloorc
37#read-write ${HOME}/.config/baloofilerc
38#read-write ${HOME}/.local/share/baloo
39#read-write ${HOME}/.local/share/akonadi/search_db