aboutsummaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
authorLibravatar rusty-snake <41237666+rusty-snake@users.noreply.github.com>2020-07-30 20:41:02 +0000
committerLibravatar GitHub <noreply@github.com>2020-07-30 20:41:02 +0000
commit8cddf9dc2e3292d1abfdc7ea0a92acac08a6c70c (patch)
tree9fb3a024c539db2bb9010132b1a48be2c1066ee1 /etc
parentAdded lyx profile (#3556) (diff)
downloadfirejail-8cddf9dc2e3292d1abfdc7ea0a92acac08a6c70c.tar.gz
firejail-8cddf9dc2e3292d1abfdc7ea0a92acac08a6c70c.tar.zst
firejail-8cddf9dc2e3292d1abfdc7ea0a92acac08a6c70c.zip
add profile for sushi (#3558)
Diffstat (limited to 'etc')
-rw-r--r--etc/profile-m-z/org.gnome.NautilusPreviewer.profile10
-rw-r--r--etc/profile-m-z/sushi.profile48
2 files changed, 58 insertions, 0 deletions
diff --git a/etc/profile-m-z/org.gnome.NautilusPreviewer.profile b/etc/profile-m-z/org.gnome.NautilusPreviewer.profile
new file mode 100644
index 000000000..eb75add58
--- /dev/null
+++ b/etc/profile-m-z/org.gnome.NautilusPreviewer.profile
@@ -0,0 +1,10 @@
1# Firejail profile alias for sushi
2# This file is overwritten after every install/update
3# Persistent local customizations
4include org.gnome.NautilusPreviewer.local
5# Persistent global definitions
6# added by included profile
7#include globals.local
8
9# Redirect
10include sushi.profile
diff --git a/etc/profile-m-z/sushi.profile b/etc/profile-m-z/sushi.profile
new file mode 100644
index 000000000..68abd8c94
--- /dev/null
+++ b/etc/profile-m-z/sushi.profile
@@ -0,0 +1,48 @@
1# Firejail profile for sushi
2# Description: A quick previewer for Nautilus
3# This file is overwritten after every install/update
4# Persistent local customizations
5include sushi.local
6# Persistent global definitions
7include globals.local
8
9# Allow gjs (blacklisted by disable-interpreters.inc)
10include allow-gjs.inc
11
12include disable-common.inc
13include disable-devel.inc
14include disable-exec.inc
15include disable-interpreters.inc
16include disable-passwdmgr.inc
17# include disable-programs.inc
18include disable-shell.inc
19
20include whitelist-runuser-common.inc
21
22apparmor
23caps.drop all
24net none
25nodvd
26nogroups
27nonewprivs
28noroot
29notv
30nou2f
31novideo
32protocol unix
33seccomp
34shell none
35tracelog
36
37private-bin gjs,sushi
38private-dev
39private-tmp
40
41dbus-system none
42
43read-only /
44read-only /mnt
45read-only /media
46read-only /run/mount
47read-only /run/media
48read-only ${HOME}