summaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
authorLibravatar rusty-snake <print_hello_world+Public@protonmail.com>2019-04-10 20:39:27 +0200
committerLibravatar rusty-snake <print_hello_world+Public@protonmail.com>2019-04-10 20:39:27 +0200
commitf6df6db285f6fe66fbcee281594d069c613d5295 (patch)
tree9269f8f65bd25e7b4bca7dd592f39dc112c019ac /etc
parentin addition to bd976150 -- Temp fix firecfg (#2634) (diff)
downloadfirejail-f6df6db285f6fe66fbcee281594d069c613d5295.tar.gz
firejail-f6df6db285f6fe66fbcee281594d069c613d5295.tar.zst
firejail-f6df6db285f6fe66fbcee281594d069c613d5295.zip
Add utox.profile
Requested by @nyancat18 in https://github.com/netblue30/firejail/issues/1139#issuecomment-314527143
Diffstat (limited to 'etc')
-rw-r--r--etc/utox.profile47
1 files changed, 47 insertions, 0 deletions
diff --git a/etc/utox.profile b/etc/utox.profile
new file mode 100644
index 000000000..9216a6a05
--- /dev/null
+++ b/etc/utox.profile
@@ -0,0 +1,47 @@
1# Firejail profile for utox
2# Description: Lightweight Tox client
3# This file is overwritten after every install/update
4# Persistent local customizations
5include utox.local
6# Persistent global definitions
7include globals.local
8
9noblacklist ${HOME}/.config/tox
10
11include disable-common.inc
12include disable-devel.inc
13include disable-exec.inc
14include disable-interpreters.inc
15include disable-passwdmgr.inc
16include disable-programs.inc
17include disable-xdg.inc
18
19mkdir ${HOME}/.config/tox
20whitelist ${DOWNLOADS}
21whitelist ${HOME}/.config/tox
22include whitelist-common.inc
23include whitelist-var-common.inc
24
25apparmor
26caps.drop all
27ipc-namespace
28netfilter
29nodvd
30nogroups
31nonewprivs
32noroot
33notv
34nou2f
35protocol unix,inet,inet6
36seccomp
37shell none
38tracelog
39
40disable-mnt
41private-bin utox
42private-cache
43private-dev
44private-etc alternatives,fonts,resolv.conf,ld.so.cache,localtime,ca-certificates,ssl,pki,crypto-policies,machine-id,pulse,openal
45private-tmp
46
47memory-deny-write-execute