aboutsummaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
authorLibravatar Fred-Barclay <Fred-Barclay@users.noreply.github.com>2018-03-05 13:04:03 -0600
committerLibravatar Fred-Barclay <Fred-Barclay@users.noreply.github.com>2018-03-05 13:04:03 -0600
commit45e044c275aab65c3f9c97a479733ab1db8f4ed2 (patch)
tree8cd354b714292636c84c15efd323d8d2bf7a266c /etc
parentFix #1797 - Brave doesn't open with noexec /tmp (diff)
downloadfirejail-45e044c275aab65c3f9c97a479733ab1db8f4ed2.tar.gz
firejail-45e044c275aab65c3f9c97a479733ab1db8f4ed2.tar.zst
firejail-45e044c275aab65c3f9c97a479733ab1db8f4ed2.zip
Add falkon profile - see #1794
Diffstat (limited to 'etc')
-rw-r--r--etc/disable-programs.inc2
-rw-r--r--etc/falkon.profile37
2 files changed, 39 insertions, 0 deletions
diff --git a/etc/disable-programs.inc b/etc/disable-programs.inc
index a78355031..8f2a4ab64 100644
--- a/etc/disable-programs.inc
+++ b/etc/disable-programs.inc
@@ -107,6 +107,7 @@ blacklist ${HOME}/.config/eog
107blacklist ${HOME}/.config/epiphany 107blacklist ${HOME}/.config/epiphany
108blacklist ${HOME}/.config/evince 108blacklist ${HOME}/.config/evince
109blacklist ${HOME}/.config/evolution 109blacklist ${HOME}/.config/evolution
110blacklist ${HOME}/.config/falkon
110blacklist ${HOME}/.config/filezilla 111blacklist ${HOME}/.config/filezilla
111blacklist ${HOME}/.config/flowblade 112blacklist ${HOME}/.config/flowblade
112blacklist ${HOME}/.config/gajim 113blacklist ${HOME}/.config/gajim
@@ -502,6 +503,7 @@ blacklist ${HOME}/.cache/discover
502blacklist ${HOME}/.cache/dolphin 503blacklist ${HOME}/.cache/dolphin
503blacklist ${HOME}/.cache/epiphany 504blacklist ${HOME}/.cache/epiphany
504blacklist ${HOME}/.cache/evolution 505blacklist ${HOME}/.cache/evolution
506blacklist ${HOME}/.cache/falkon
505blacklist ${HOME}/.cache/fossamail 507blacklist ${HOME}/.cache/fossamail
506blacklist ${HOME}/.cache/gajim 508blacklist ${HOME}/.cache/gajim
507blacklist ${HOME}/.cache/geeqie 509blacklist ${HOME}/.cache/geeqie
diff --git a/etc/falkon.profile b/etc/falkon.profile
new file mode 100644
index 000000000..03484382a
--- /dev/null
+++ b/etc/falkon.profile
@@ -0,0 +1,37 @@
1# Firejail profile for falkon
2# This file is overwritten after every install/update
3# Persistent local customizations
4include /etc/firejail/falkon.local
5# Persistent global definitions
6include /etc/firejail/globals.local
7
8noblacklist ${HOME}/.cache/falkon
9noblacklist ${HOME}/.config/falkon
10
11include /etc/firejail/disable-common.inc
12include /etc/firejail/disable-devel.inc
13include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc
15
16whitelist ${DOWNLOADS}
17whitelist ~/.cache/falkon
18whitelist ~/.config/falkon
19include /etc/firejail/whitelist-common.inc
20include /etc/firejail/whitelist-var-common.inc
21
22caps.drop all
23netfilter
24nodvd
25nogroups
26nonewprivs
27noroot
28notv
29protocol unix,inet,inet6,netlink
30seccomp
31tracelog
32
33private-dev
34private-tmp
35
36noexec ${HOME}
37noexec /tmp