aboutsummaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
authorLibravatar rusty-snake <41237666+rusty-snake@users.noreply.github.com>2020-03-29 13:40:09 +0000
committerLibravatar GitHub <noreply@github.com>2020-03-29 13:40:09 +0000
commit2d4485ef8ad989f1bfa7adb4a08ee9db7737a44d (patch)
tree7cdbeca9d6313a3a55aa8aa2db7ad5182a1d7fdc /etc
parentblacklist libvirt and flatpak [skip ci] (diff)
parentAdded paths for ferdi (diff)
downloadfirejail-2d4485ef8ad989f1bfa7adb4a08ee9db7737a44d.tar.gz
firejail-2d4485ef8ad989f1bfa7adb4a08ee9db7737a44d.tar.zst
firejail-2d4485ef8ad989f1bfa7adb4a08ee9db7737a44d.zip
Merge pull request #3296 from 0x7969/master
Create ferdi.profile
Diffstat (limited to 'etc')
-rw-r--r--etc/disable-programs.inc2
-rw-r--r--etc/ferdi.profile46
2 files changed, 48 insertions, 0 deletions
diff --git a/etc/disable-programs.inc b/etc/disable-programs.inc
index be8f0ff75..15a62d4e2 100644
--- a/etc/disable-programs.inc
+++ b/etc/disable-programs.inc
@@ -75,6 +75,7 @@ blacklist ${HOME}/.config/Code Industry
75blacklist ${HOME}/.config/Cryptocat 75blacklist ${HOME}/.config/Cryptocat
76blacklist ${HOME}/.config/Debauchee/Barrier.conf 76blacklist ${HOME}/.config/Debauchee/Barrier.conf
77blacklist ${HOME}/.config/Enox 77blacklist ${HOME}/.config/Enox
78blacklist ${HOME}/.config/Ferdi
78blacklist ${HOME}/.config/Franz 79blacklist ${HOME}/.config/Franz
79blacklist ${HOME}/.config/FreeCAD 80blacklist ${HOME}/.config/FreeCAD
80blacklist ${HOME}/.config/Fritzing 81blacklist ${HOME}/.config/Fritzing
@@ -738,6 +739,7 @@ blacklist ${HOME}/.cache/BraveSoftware
738blacklist ${HOME}/.cache/Clementine 739blacklist ${HOME}/.cache/Clementine
739blacklist ${HOME}/.cache/Enox 740blacklist ${HOME}/.cache/Enox
740blacklist ${HOME}/.cache/Enpass 741blacklist ${HOME}/.cache/Enpass
742blacklist ${HOME}/.cache/Ferdi
741blacklist ${HOME}/.cache/Franz 743blacklist ${HOME}/.cache/Franz
742blacklist ${HOME}/.cache/INRIA 744blacklist ${HOME}/.cache/INRIA
743blacklist ${HOME}/.cache/MusicBrainz 745blacklist ${HOME}/.cache/MusicBrainz
diff --git a/etc/ferdi.profile b/etc/ferdi.profile
new file mode 100644
index 000000000..9b4c5f114
--- /dev/null
+++ b/etc/ferdi.profile
@@ -0,0 +1,46 @@
1# Firejail profile for ferdi
2# This file is overwritten after every install/update
3# Persistent local customizations
4include ferdi.local
5# Persistent global definitions
6include globals.local
7
8ignore noexec /tmp
9
10noblacklist ${HOME}/.cache/Ferdi
11noblacklist ${HOME}/.config/Ferdi
12noblacklist ${HOME}/.pki
13noblacklist ${HOME}/.local/share/pki
14
15include disable-common.inc
16include disable-devel.inc
17include disable-exec.inc
18include disable-interpreters.inc
19include disable-programs.inc
20
21mkdir ${HOME}/.cache/Ferdi
22mkdir ${HOME}/.config/Ferdi
23mkdir ${HOME}/.pki
24mkdir ${HOME}/.local/share/pki
25whitelist ${DOWNLOADS}
26whitelist ${HOME}/.cache/Ferdi
27whitelist ${HOME}/.config/Ferdi
28whitelist ${HOME}/.pki
29whitelist ${HOME}/.local/share/pki
30include whitelist-common.inc
31
32caps.drop all
33netfilter
34nodvd
35nogroups
36nonewprivs
37noroot
38notv
39nou2f
40protocol unix,inet,inet6,netlink
41seccomp !chroot
42shell none
43
44disable-mnt
45private-dev
46private-tmp