summaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
authorLibravatar glitsj16 <glitsj16@users.noreply.github.com>2019-03-01 00:17:43 +0000
committerLibravatar GitHub <noreply@github.com>2019-03-01 00:17:43 +0000
commitf12bd3cf566c85190537e73e938636800d425e83 (patch)
tree68f8f6593ac877bb3b43039ebfe33ddabe320903 /etc
parentAdd new profile for netactview (#2484) (diff)
downloadfirejail-f12bd3cf566c85190537e73e938636800d425e83.tar.gz
firejail-f12bd3cf566c85190537e73e938636800d425e83.tar.zst
firejail-f12bd3cf566c85190537e73e938636800d425e83.zip
Add new profile for gnome-nettool (#2485)
* Create gnome-nettool.profile * Add gnome-nettool to firecfg
Diffstat (limited to 'etc')
-rw-r--r--etc/gnome-nettool.profile49
1 files changed, 49 insertions, 0 deletions
diff --git a/etc/gnome-nettool.profile b/etc/gnome-nettool.profile
new file mode 100644
index 000000000..585fb9a20
--- /dev/null
+++ b/etc/gnome-nettool.profile
@@ -0,0 +1,49 @@
1# Firejail profile for gnome-nettool
2# Description: Graphical interface for various networking tools
3# This file is overwritten after every install/update
4# Persistent local customizations
5include gnome-nettool.local
6# Persistent global definitions
7include globals.local
8
9include disable-common.inc
10include disable-devel.inc
11include disable-interpreters.inc
12include disable-passwdmgr.inc
13include disable-programs.inc
14include disable-xdg.inc
15
16include whitelist-common.inc
17include whitelist-var-common.inc
18
19caps.keep net_raw
20ipc-namespace
21machine-id
22netfilter
23no3d
24nodbus
25nodvd
26nogroups
27# ping needs to elevate privileges, noroot and nonewprivs will kill it
28#nonewprivs
29#noroot
30nosound
31notv
32nou2f
33novideo
34#seccomp
35#shell none
36
37disable-mnt
38#private-bin gnome-nettool
39private-cache
40private-dev
41#private-etc alternatives
42private-lib libbind9.so.*,libcrypto.so.*,libdns.so.*,libirs.so.*,liblua.so.*,libssh2.so.*,libssl.so.*
43private-tmp
44
45noexec ${HOME}
46noexec /tmp
47
48# never write anything
49read-only ${HOME}