aboutsummaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
authorLibravatar Jonas Heinrich <onny@project-insanity.org>2017-10-07 12:20:17 +0200
committerLibravatar GitHub <noreply@github.com>2017-10-07 12:20:17 +0200
commit7ad904c876ec50558add02452e6b3879873e087e (patch)
treef7d3ba0a4efe7135fe07b4681be5fe0b976b5e22 /etc
parentfldd fixes (diff)
downloadfirejail-7ad904c876ec50558add02452e6b3879873e087e.tar.gz
firejail-7ad904c876ec50558add02452e6b3879873e087e.tar.zst
firejail-7ad904c876ec50558add02452e6b3879873e087e.zip
Create signal-desktop.profile
Profile for signal-desktop (standalone electron app, see https://github.com/WhisperSystems/Signal-Desktop)
Diffstat (limited to 'etc')
-rw-r--r--etc/signal-desktop.profile35
1 files changed, 35 insertions, 0 deletions
diff --git a/etc/signal-desktop.profile b/etc/signal-desktop.profile
new file mode 100644
index 000000000..f515e64a6
--- /dev/null
+++ b/etc/signal-desktop.profile
@@ -0,0 +1,35 @@
1# Firejail profile for sinal-desktop
2# This file is overwritten after every install/update
3# Persistent local customizations
4include /etc/firejail/signal-desktop.local
5# Persistent global definitions
6include /etc/firejail/globals.local
7
8noblacklist ~/.config/Signal
9
10include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-programs.inc
13
14mkdir ~/.config/Signal
15whitelist ${DOWNLOADS}
16whitelist ~/.config/Signal
17include /etc/firejail/whitelist-common.inc
18
19caps.drop all
20netfilter
21nodvd
22nogroups
23nonewprivs
24noroot
25notv
26protocol unix,inet,inet6,netlink
27seccomp
28shell none
29
30disable-mnt
31private-dev
32private-tmp
33
34noexec ${HOME}
35noexec /tmp