aboutsummaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
authorLibravatar netblue30 <netblue30@yahoo.com>2018-03-12 16:45:10 -0400
committerLibravatar netblue30 <netblue30@yahoo.com>2018-03-12 16:45:10 -0400
commitabf3f585b35042866de433233cafe3ca0ee5f2ba (patch)
tree799ad3ee5dc6f9aa968f14b79e33221240fe465c /etc
parentbringing back private-lib in evince, and some fixes for Arch Linux (diff)
parentAdd a profile for gnome-builder (diff)
downloadfirejail-abf3f585b35042866de433233cafe3ca0ee5f2ba.tar.gz
firejail-abf3f585b35042866de433233cafe3ca0ee5f2ba.tar.zst
firejail-abf3f585b35042866de433233cafe3ca0ee5f2ba.zip
Merge branch 'master' of http://github.com/netblue30/firejail
Diffstat (limited to 'etc')
-rw-r--r--etc/gnome-builder.profile25
-rw-r--r--etc/viewnior.profile3
2 files changed, 27 insertions, 1 deletions
diff --git a/etc/gnome-builder.profile b/etc/gnome-builder.profile
new file mode 100644
index 000000000..a5a48e97a
--- /dev/null
+++ b/etc/gnome-builder.profile
@@ -0,0 +1,25 @@
1# Firejail profile for gnome-builder
2# This file is overwritten after every install/update
3# Persistent local customizations
4include /etc/firejail/gnome-builder.local
5# Persistent global definitions
6include /etc/firejail/globals.local
7
8include /etc/firejail/disable-common.inc
9include /etc/firejail/disable-passwdmgr.inc
10include /etc/firejail/disable-programs.inc
11
12caps.drop all
13ipc-namespace
14netfilter
15nodvd
16nogroups
17nonewprivs
18noroot
19notv
20novideo
21protocol unix,inet,inet6
22seccomp
23shell none
24
25private-dev
diff --git a/etc/viewnior.profile b/etc/viewnior.profile
index 4df71f728..39bf3f7ce 100644
--- a/etc/viewnior.profile
+++ b/etc/viewnior.profile
@@ -37,6 +37,7 @@ private-dev
37private-etc fonts 37private-etc fonts
38private-tmp 38private-tmp
39 39
40memory-deny-write-execute 40# memory-deny-write-executes breaks on Arch - see issue #1808
41#memory-deny-write-execute
41noexec ${HOME} 42noexec ${HOME}
42noexec /tmp 43noexec /tmp