aboutsummaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
authorLibravatar netblue30 <netblue30@yahoo.com>2017-04-26 08:45:52 -0400
committerLibravatar netblue30 <netblue30@yahoo.com>2017-04-26 08:45:52 -0400
commitda9bdbaeadeba6c2271dd39245cb7583d430bf39 (patch)
tree0b37949c0aa788b9c01159624cb50a5e02dd4d57 /etc
parentAdded noexec for home and tmp, spotify profile. (diff)
downloadfirejail-da9bdbaeadeba6c2271dd39245cb7583d430bf39.tar.gz
firejail-da9bdbaeadeba6c2271dd39245cb7583d430bf39.tar.zst
firejail-da9bdbaeadeba6c2271dd39245cb7583d430bf39.zip
PCManFM profile
Diffstat (limited to 'etc')
-rw-r--r--etc/Thunar.profile10
-rw-r--r--etc/disable-programs.inc1
-rw-r--r--etc/pcmanfm.profile30
3 files changed, 40 insertions, 1 deletions
diff --git a/etc/Thunar.profile b/etc/Thunar.profile
index 5a27177e0..f1b75b1f3 100644
--- a/etc/Thunar.profile
+++ b/etc/Thunar.profile
@@ -7,7 +7,7 @@ noblacklist ~/.config/Thunar
7noblacklist ~/.config/xfce4/xfconf/xfce-perchannel-xml/thunar.xml 7noblacklist ~/.config/xfce4/xfconf/xfce-perchannel-xml/thunar.xml
8 8
9include /etc/firejail/disable-common.inc 9include /etc/firejail/disable-common.inc
10include /etc/firejail/disable-programs.inc 10#include /etc/firejail/disable-programs.inc
11include /etc/firejail/disable-devel.inc 11include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-passwdmgr.inc 12include /etc/firejail/disable-passwdmgr.inc
13 13
@@ -21,3 +21,11 @@ protocol unix
21seccomp 21seccomp
22shell none 22shell none
23tracelog 23tracelog
24
25#
26# depending on you usage, you can enable some of the commands below:
27#
28# private-bin program
29# private-etc none
30# private-dev
31# private-tmp
diff --git a/etc/disable-programs.inc b/etc/disable-programs.inc
index 9b84f5e8a..18b644987 100644
--- a/etc/disable-programs.inc
+++ b/etc/disable-programs.inc
@@ -107,6 +107,7 @@ blacklist ${HOME}/.config/opera
107blacklist ${HOME}/.config/opera-beta 107blacklist ${HOME}/.config/opera-beta
108blacklist ${HOME}/.config/orage 108blacklist ${HOME}/.config/orage
109blacklist ${HOME}/.config/org.kde.gwenviewrc 109blacklist ${HOME}/.config/org.kde.gwenviewrc
110blacklist ${HOME}/.config/pcmanfm
110blacklist ${HOME}/.config/pix 111blacklist ${HOME}/.config/pix
111blacklist ${HOME}/.config/pluma 112blacklist ${HOME}/.config/pluma
112blacklist ${HOME}/.config/psi+ 113blacklist ${HOME}/.config/psi+
diff --git a/etc/pcmanfm.profile b/etc/pcmanfm.profile
new file mode 100644
index 000000000..e51c5e3b8
--- /dev/null
+++ b/etc/pcmanfm.profile
@@ -0,0 +1,30 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include /etc/firejail/pcmanfm.local
4
5noblacklist ~/.config/pcmanfm
6noblacklist ~/.config/libfm
7include /etc/firejail/disable-common.inc
8#include /etc/firejail/disable-programs.inc
9include /etc/firejail/disable-devel.inc
10include /etc/firejail/disable-passwdmgr.inc
11
12caps.drop all
13netfilter
14nogroups
15nonewprivs
16noroot
17nosound
18protocol unix
19seccomp
20shell none
21tracelog
22
23#
24# depending on you usage, you can enable some of the commands below:
25#
26# private-bin program
27# private-etc none
28# private-dev
29# private-tmp
30