aboutsummaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
authorLibravatar netblue30 <netblue30@yahoo.com>2018-10-11 08:37:04 -0500
committerLibravatar GitHub <noreply@github.com>2018-10-11 08:37:04 -0500
commitc67588ec3626254c56398deb0741baa012ef2c85 (patch)
tree1e6345a1e01441e5f29a38582f907ae57adea6f0 /etc
parentMerge pull request #2171 from glitsj16/desktop (diff)
parentUpdate for min (diff)
downloadfirejail-c67588ec3626254c56398deb0741baa012ef2c85.tar.gz
firejail-c67588ec3626254c56398deb0741baa012ef2c85.tar.zst
firejail-c67588ec3626254c56398deb0741baa012ef2c85.zip
Merge pull request #2172 from glitsj16/min
New profile min
Diffstat (limited to 'etc')
-rw-r--r--etc/disable-programs.inc1
-rw-r--r--etc/min.profile50
2 files changed, 51 insertions, 0 deletions
diff --git a/etc/disable-programs.inc b/etc/disable-programs.inc
index fe6b04ed0..6fa0eed26 100644
--- a/etc/disable-programs.inc
+++ b/etc/disable-programs.inc
@@ -66,6 +66,7 @@ blacklist ${HOME}/.config/INRIA
66blacklist ${HOME}/.config/InSilmaril 66blacklist ${HOME}/.config/InSilmaril
67blacklist ${HOME}/.config/Luminance 67blacklist ${HOME}/.config/Luminance
68blacklist ${HOME}/.config/Meltytech 68blacklist ${HOME}/.config/Meltytech
69blacklist ${HOME}/.config/Min
69blacklist ${HOME}/.config/Mousepad 70blacklist ${HOME}/.config/Mousepad
70blacklist ${HOME}/.config/Mumble 71blacklist ${HOME}/.config/Mumble
71blacklist ${HOME}/.config/MusE 72blacklist ${HOME}/.config/MusE
diff --git a/etc/min.profile b/etc/min.profile
new file mode 100644
index 000000000..91c6fce3c
--- /dev/null
+++ b/etc/min.profile
@@ -0,0 +1,50 @@
1# Firejail profile for min
2# Description: A faster, smarter web browser.
3# This file is overwritten after every install/update
4# Persistent local customizations
5include /etc/firejail/min.local
6# Persistent global definitions
7include /etc/firejail/globals.local
8
9noblacklist ${HOME}/.config/Min
10
11noblacklist ${HOME}/.pki
12
13include /etc/firejail/disable-common.inc
14include /etc/firejail/disable-devel.inc
15include /etc/firejail/disable-interpreters.inc
16include /etc/firejail/disable-programs.inc
17
18mkdir ${HOME}/.pki
19whitelist ${DOWNLOADS}
20whitelist ${HOME}/.pki
21include /etc/firejail/whitelist-common.inc
22include /etc/firejail/whitelist-var-common.inc
23
24caps.drop all
25# ipc-namespace
26# machine-id breaks pulse audio; it should work fine in setups where sound is not required
27#machine-id
28netfilter
29# no3d
30nodbus
31nodvd
32nogroups
33nonewprivs
34noroot
35notv
36protocol unix,inet,inet6
37seccomp
38shell none
39
40disable-mnt
41# private-bin min
42private-cache
43private-dev
44# private-etc below works fine on most distributions. There are some problems on CentOS.
45private-etc ca-certificates,ssl,machine-id,dconf,selinux,passwd,group,hostname,hosts,localtime,nsswitch.conf,resolv.conf,xdg,gtk-2.0,gtk-3.0,X11,pango,fonts,mime.types,mailcap,asound.conf,pulse,pki,crypto-policies,ld.so.cache
46private-tmp
47
48# memory-deny-write-execute
49noexec ${HOME}
50noexec /tmp