aboutsummaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
authorLibravatar netblue30 <netblue30@yahoo.com>2019-06-13 08:38:16 -0400
committerLibravatar netblue30 <netblue30@yahoo.com>2019-06-13 08:38:16 -0400
commit4a5449b4c6869835b743a6a4566d89d84df3ce67 (patch)
tree7ecb5653d57c235466d9e8e5199fc04d068fd4cd /etc
parenthardening & fixing (diff)
downloadfirejail-4a5449b4c6869835b743a6a4566d89d84df3ce67.tar.gz
firejail-4a5449b4c6869835b743a6a4566d89d84df3ce67.tar.zst
firejail-4a5449b4c6869835b743a6a4566d89d84df3ce67.zip
OpenArena profile
Diffstat (limited to 'etc')
-rw-r--r--etc/disable-programs.inc1
-rw-r--r--etc/openarena.profile51
2 files changed, 52 insertions, 0 deletions
diff --git a/etc/disable-programs.inc b/etc/disable-programs.inc
index 9d3f3ab68..7684aefff 100644
--- a/etc/disable-programs.inc
+++ b/etc/disable-programs.inc
@@ -575,6 +575,7 @@ blacklist ${HOME}/.neverball
575blacklist ${HOME}/.newsboat 575blacklist ${HOME}/.newsboat
576blacklist ${HOME}/.nv 576blacklist ${HOME}/.nv
577blacklist ${HOME}/.nylas-mail 577blacklist ${HOME}/.nylas-mail
578blacklist ${HOME}/.openarena
578blacklist ${HOME}/.opencity 579blacklist ${HOME}/.opencity
579blacklist ${HOME}/.openinvaders 580blacklist ${HOME}/.openinvaders
580blacklist ${HOME}/.openshot 581blacklist ${HOME}/.openshot
diff --git a/etc/openarena.profile b/etc/openarena.profile
new file mode 100644
index 000000000..f36d3270f
--- /dev/null
+++ b/etc/openarena.profile
@@ -0,0 +1,51 @@
1# Firejail profile for OpenArena
2# Description: deathmatch FPS game based on GPL idTech3 technology
3# This file is overwritten after every install/update
4# Persistent local customizations
5include openarena.local
6# Persistent global definitions
7include globals.local
8
9noblacklist ${HOME}/.openarena
10
11include disable-common.inc
12include disable-devel.inc
13include disable-exec.inc
14include disable-interpreters.inc
15include disable-passwdmgr.inc
16include disable-programs.inc
17include disable-xdg.inc
18
19include whitelist-var-common.inc
20
21apparmor
22caps.drop all
23# ipc-namespace
24# machine-id
25# net none
26# netfilter
27# no3d
28# nodbus
29# nodvd
30# nogroups
31nonewprivs
32noroot
33# nosound
34notv
35# nou2f
36novideo
37protocol unix,inet,inet6,netlink
38seccomp
39shell none
40# tracelog
41
42# disable-mnt
43# private
44# private-bin openarena
45private-cache
46private-dev
47# private-etc machine-id,xdg,openal,udev,drirc,passwd,selinux
48# private-lib
49private-tmp
50
51# memory-deny-write-execute