aboutsummaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
authorLibravatar Fred Barclay <Fred-Barclay@users.noreply.github.com>2017-08-14 11:54:08 -0500
committerLibravatar GitHub <noreply@github.com>2017-08-14 11:54:08 -0500
commit3dd2aaecf3de5250b4bfd2c746b0ef81da29bc9f (patch)
tree3c724c907082c97df75f6b646dec4db9ecf9b91f /etc
parentFixes for Gitter (diff)
parentfirejail profile for torbrowser-launcher (diff)
downloadfirejail-3dd2aaecf3de5250b4bfd2c746b0ef81da29bc9f.tar.gz
firejail-3dd2aaecf3de5250b4bfd2c746b0ef81da29bc9f.tar.zst
firejail-3dd2aaecf3de5250b4bfd2c746b0ef81da29bc9f.zip
Merge pull request #1468 from pizzadude/patch-2
firejail profile for torbrowser-launcher
Diffstat (limited to 'etc')
-rw-r--r--etc/torbrowser-launcher.profile37
1 files changed, 37 insertions, 0 deletions
diff --git a/etc/torbrowser-launcher.profile b/etc/torbrowser-launcher.profile
new file mode 100644
index 000000000..8ae0c56c1
--- /dev/null
+++ b/etc/torbrowser-launcher.profile
@@ -0,0 +1,37 @@
1# Firejail profile for torbrowser-launcher
2# This file is overwritten after every install/update
3# Persistent local customizations
4include /etc/firejail/torbrowser-launcher.local
5# Persistent global definitions
6include /etc/firejail/globals.local
7
8
9noblacklist ~/.config/torbrowser
10whitelist ~/.config/torbrowser
11noblacklist ~/.local/share/torbrowser
12whitelist ~/.local/share/torbrowser
13
14
15include /etc/firejail/disable-common.inc
16include /etc/firejail/disable-devel.inc
17include /etc/firejail/disable-passwdmgr.inc
18include /etc/firejail/disable-programs.inc
19
20
21caps.drop all
22netfilter
23nodvd
24nogroups
25nonewprivs
26noroot
27notv
28protocol unix,inet,inet6
29seccomp
30shell none
31tracelog
32
33private-bin torbrowser-launcher,python2.7,python,bash,dash,sh,grep,tail,env,gpg,id,readlink,dirname,test,mkdir,ln,sed,cp,rm,getconf
34private-dev
35private-etc fonts
36private-tmp
37