aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
-rw-r--r--etc/profile-a-l/erd.profile44
-rw-r--r--src/firecfg/firecfg.config1
2 files changed, 45 insertions, 0 deletions
diff --git a/etc/profile-a-l/erd.profile b/etc/profile-a-l/erd.profile
new file mode 100644
index 000000000..8ab145016
--- /dev/null
+++ b/etc/profile-a-l/erd.profile
@@ -0,0 +1,44 @@
1# Firejail profile for erd
2# Description: Multi-threaded file-tree visualizer and disk usage analyzer
3# This file is overwritten after every install/update
4quiet
5# Persistent local customizations
6include erd.local
7# Persistent global definitions
8include globals.local
9
10blacklist /tmp/.X11-unix
11
12include disable-exec.inc
13
14apparmor
15caps.drop all
16ipc-namespace
17machine-id
18net none
19no3d
20nodvd
21nogroups
22noinput
23nonewprivs
24noprinters
25noroot
26nosound
27notv
28nou2f
29novideo
30seccomp socket
31seccomp.block-secondary
32x11 none
33
34# private-bin erd does work but defeats the purpose of this app
35#private-bin erd
36private-dev
37
38dbus-user none
39dbus-system none
40
41memory-deny-write-execute
42read-only ${HOME}
43read-only ${RUNUSER}
44restrict-namespaces
diff --git a/src/firecfg/firecfg.config b/src/firecfg/firecfg.config
index cf60b8112..4dc773c2c 100644
--- a/src/firecfg/firecfg.config
+++ b/src/firecfg/firecfg.config
@@ -243,6 +243,7 @@ eom
243ephemeral 243ephemeral
244#epiphany # see #2995 244#epiphany # see #2995
245equalx 245equalx
246erd
246et 247et
247etr 248etr
248evince 249evince