aboutsummaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
authorLibravatar curiosityseeker <60518106+curiosityseeker@users.noreply.github.com>2020-04-04 13:54:36 +0200
committerLibravatar GitHub <noreply@github.com>2020-04-04 13:54:36 +0200
commit6d308b36d528cf5381415a33428172b62b953e47 (patch)
treea524d65ddd2bf40b933a41f24f4aeb652feaa0a9 /etc
parentHarden thunderbird.profile (diff)
downloadfirejail-6d308b36d528cf5381415a33428172b62b953e47.tar.gz
firejail-6d308b36d528cf5381415a33428172b62b953e47.tar.zst
firejail-6d308b36d528cf5381415a33428172b62b953e47.zip
Harden signal-desktop.profile and add rules for Firefox
Diffstat (limited to 'etc')
-rw-r--r--etc/signal-desktop.profile7
1 files changed, 7 insertions, 0 deletions
diff --git a/etc/signal-desktop.profile b/etc/signal-desktop.profile
index f810a37ec..25932720b 100644
--- a/etc/signal-desktop.profile
+++ b/etc/signal-desktop.profile
@@ -9,6 +9,11 @@ ignore noexec /tmp
9 9
10noblacklist ${HOME}/.config/Signal 10noblacklist ${HOME}/.config/Signal
11 11
12# These lines are needed to allow Firefox to open links
13noblacklist ${HOME}/.mozilla
14whitelist ${HOME}/.mozilla/firefox/profiles.ini
15read-only ${HOME}/.mozilla/firefox/profiles.ini
16
12include disable-common.inc 17include disable-common.inc
13include disable-devel.inc 18include disable-devel.inc
14include disable-exec.inc 19include disable-exec.inc
@@ -22,8 +27,10 @@ whitelist ${HOME}/.config/Signal
22include whitelist-common.inc 27include whitelist-common.inc
23include whitelist-var-common.inc 28include whitelist-var-common.inc
24 29
30apparmor
25caps.keep sys_admin,sys_chroot 31caps.keep sys_admin,sys_chroot
26netfilter 32netfilter
33nodbus
27nodvd 34nodvd
28nogroups 35nogroups
29notv 36notv