aboutsummaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
authorLibravatar SkewedZeppelin <8296104+SkewedZeppelin@users.noreply.github.com>2018-07-22 05:46:04 -0400
committerLibravatar GitHub <noreply@github.com>2018-07-22 05:46:04 -0400
commitad92c6435757051c82289f396d6c22f4196fe541 (patch)
treeaadbc3cbd2132446dc633707efda993b3753f961 /etc
parentMerge branch 'master' of https://github.com/netblue30/firejail (diff)
parentadded mkdir for whitelisted folders (diff)
downloadfirejail-ad92c6435757051c82289f396d6c22f4196fe541.tar.gz
firejail-ad92c6435757051c82289f396d6c22f4196fe541.tar.zst
firejail-ad92c6435757051c82289f396d6c22f4196fe541.zip
Merge pull request #2052 from veloute/master
Create standardnotes-desktop.profile
Diffstat (limited to 'etc')
-rw-r--r--etc/standardnotes-desktop.profile40
1 files changed, 40 insertions, 0 deletions
diff --git a/etc/standardnotes-desktop.profile b/etc/standardnotes-desktop.profile
new file mode 100644
index 000000000..202d3761d
--- /dev/null
+++ b/etc/standardnotes-desktop.profile
@@ -0,0 +1,40 @@
1# Firejail profile for standardnotes-desktop
2# This file is overwritten after every install/update
3# Persistent local customizations
4include /etc/firejail/standardnotes-desktop.local
5# Persistent global definitions
6include /etc/firejail/globals.local
7
8include /etc/firejail/disable-common.inc
9include /etc/firejail/disable-devel.inc
10include /etc/firejail/disable-interpreters.inc
11include /etc/firejail/disable-passwdmgr.inc
12include /etc/firejail/disable-programs.inc
13
14include /etc/firejail/whitelist-var-common.inc
15
16mkdir ${HOME}/Standard Notes Backups
17mkdir ${HOME}/.config/Standard Notes
18whitelist ${HOME}/Standard Notes Backups
19whitelist ${HOME}/.config/Standard Notes
20
21apparmor
22caps.drop all
23netfilter
24machine-id
25nodbus
26nodvd
27nogroups
28nonewprivs
29noroot
30nosound
31notv
32protocol unix,inet,inet6,netlink
33seccomp
34disable-mnt
35private-dev
36private-tmp
37private-etc ca-certificates,fonts,host.conf,hostname,hosts,resolv.conf,ssl,pki,crypto-policies,xdg
38
39noexec ${HOME}
40noexec /tmp