aboutsummaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
authorLibravatar Fred Barclay <Fred-Barclay@users.noreply.github.com>2017-04-15 22:07:04 +0000
committerLibravatar GitHub <noreply@github.com>2017-04-15 22:07:04 +0000
commitab093e0e560cd72fbb57edce2ef7a0ed12a5a57e (patch)
tree29f9cd3e54c5c6aaed98d873d9b9844367452c6b /etc
parentMerge pull request #1220 from SpotComms/harden (diff)
parentAdd 'tracelog' to Kodi profile (diff)
downloadfirejail-ab093e0e560cd72fbb57edce2ef7a0ed12a5a57e.tar.gz
firejail-ab093e0e560cd72fbb57edce2ef7a0ed12a5a57e.tar.zst
firejail-ab093e0e560cd72fbb57edce2ef7a0ed12a5a57e.zip
Merge pull request #1221 from SpotComms/kodi
Add a profile for Kodi
Diffstat (limited to 'etc')
-rw-r--r--etc/kodi.profile28
1 files changed, 28 insertions, 0 deletions
diff --git a/etc/kodi.profile b/etc/kodi.profile
new file mode 100644
index 000000000..45a8430f1
--- /dev/null
+++ b/etc/kodi.profile
@@ -0,0 +1,28 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/kodi.local
4
5# Firejail profile for kodi
6noblacklist ${HOME}/.kodi
7mkdir ${HOME}/.kodi
8
9include /etc/firejail/disable-common.inc
10include /etc/firejail/disable-passwdmgr.inc
11include /etc/firejail/disable-programs.inc
12include /etc/firejail/disable-devel.inc
13
14caps.drop all
15netfilter
16nogroups
17nonewprivs
18noroot
19protocol unix,inet,inet6,netlink
20seccomp
21shell none
22tracelog
23
24private-dev
25private-tmp
26
27noexec ${HOME}
28noexec /tmp