aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
-rw-r--r--etc/profile-a-l/chafa.profile55
-rw-r--r--src/firecfg/firecfg.config1
2 files changed, 56 insertions, 0 deletions
diff --git a/etc/profile-a-l/chafa.profile b/etc/profile-a-l/chafa.profile
new file mode 100644
index 000000000..b042ac189
--- /dev/null
+++ b/etc/profile-a-l/chafa.profile
@@ -0,0 +1,55 @@
1# Firejail profile for chafa
2# Description: A terminal-based image viewer and image-to-text converter.
3# This file is overwritten after every install/update
4# Persistent local customizations
5include chafa.local
6# Persistent global definitions
7include globals.local
8
9blacklist ${RUNUSER}
10blacklist /usr/libexec
11
12include disable-common.inc
13include disable-devel.inc
14include disable-exec.inc
15include disable-interpreters.inc
16include disable-proc.inc
17include disable-programs.inc
18include disable-shell.inc
19include disable-write-mnt.inc
20
21include whitelist-run-common.inc
22include whitelist-runuser-common.inc
23# Add the following to your chafa.local if you do not need to view images in
24# /usr/share.
25#include whitelist-usr-share-common.inc
26include whitelist-var-common.inc
27
28apparmor
29caps.drop all
30machine-id
31net none
32no3d
33nodvd
34nogroups
35noinput
36nonewprivs
37noroot
38nosound
39notv
40nou2f
41novideo
42seccomp socket
43seccomp.block-secondary
44tracelog
45x11 none
46
47private-bin chafa
48private-cache
49private-dev
50private-tmp
51
52dbus-user none
53dbus-system none
54
55read-only ${HOME}
diff --git a/src/firecfg/firecfg.config b/src/firecfg/firecfg.config
index 1de107a03..72a33ed5a 100644
--- a/src/firecfg/firecfg.config
+++ b/src/firecfg/firecfg.config
@@ -127,6 +127,7 @@ cantata
127catfish 127catfish
128cawbird 128cawbird
129celluloid 129celluloid
130chafa
130checkbashisms 131checkbashisms
131cheese 132cheese
132cherrytree 133cherrytree