aboutsummaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
authorLibravatar Fred-Barclay <Fred-Barclay@users.noreply.github.com>2016-07-09 05:27:38 +1000
committerLibravatar Fred-Barclay <Fred-Barclay@users.noreply.github.com>2016-07-09 05:27:38 +1000
commitc99ddd579d823dae018e1f65ad28b3234e8e51bb (patch)
treeca7bf413aadb264c62071de320ed9302371a117d /etc
parentmissed a file... (diff)
downloadfirejail-c99ddd579d823dae018e1f65ad28b3234e8e51bb.tar.gz
firejail-c99ddd579d823dae018e1f65ad28b3234e8e51bb.tar.zst
firejail-c99ddd579d823dae018e1f65ad28b3234e8e51bb.zip
tightened and fixed permissions warning
Diffstat (limited to 'etc')
-rw-r--r--etc/0ad.profile26
1 files changed, 15 insertions, 11 deletions
diff --git a/etc/0ad.profile b/etc/0ad.profile
index 3797ae5cd..11fb45463 100644
--- a/etc/0ad.profile
+++ b/etc/0ad.profile
@@ -1,21 +1,13 @@
1# Firejail profile for 0ad. 1# Firejail profile for 0ad.
2noblacklist ~/.cache/0ad
2noblacklist ~/.config/0ad 3noblacklist ~/.config/0ad
4noblacklist ~/.local/share/0ad
3include /etc/firejail/disable-common.inc 5include /etc/firejail/disable-common.inc
4include /etc/firejail/disable-devel.inc 6include /etc/firejail/disable-devel.inc
5include /etc/firejail/disable-passwdmgr.inc 7include /etc/firejail/disable-passwdmgr.inc
6include /etc/firejail/disable-programs.inc 8include /etc/firejail/disable-programs.inc
7 9
8# Call these options
9caps.drop all
10netfilter
11noroot
12nonewprivs
13protocol unix,inet,inet6,netlink
14seccomp
15tracelog
16
17# Whitelists 10# Whitelists
18noblacklist ~/.cache/0ad
19mkdir ~/.cache 11mkdir ~/.cache
20mkdir ~/.cache/0ad 12mkdir ~/.cache/0ad
21whitelist ~/.cache/0ad 13whitelist ~/.cache/0ad
@@ -24,8 +16,20 @@ mkdir ~/.config
24mkdir ~/.config/0ad 16mkdir ~/.config/0ad
25whitelist ~/.config/0ad 17whitelist ~/.config/0ad
26 18
27noblacklist ~/.local/share/0ad
28mkdir ~/.local 19mkdir ~/.local
29mkdir ~/.local/share 20mkdir ~/.local/share
30mkdir ~/.local/share/0ad 21mkdir ~/.local/share/0ad
31whitelist ~/.local/share/0ad 22whitelist ~/.local/share/0ad
23
24caps.drop all
25netfilter
26nonewprivs
27nogroups
28noroot
29protocol unix,inet,inet6
30seccomp
31shell none
32tracelog
33
34private-dev
35