aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
-rw-r--r--etc/google-chrome-beta.profile12
-rw-r--r--etc/google-chrome-unstable.profile12
-rw-r--r--etc/google-chrome.profile13
-rw-r--r--etc/vivaldi.profile11
4 files changed, 40 insertions, 8 deletions
diff --git a/etc/google-chrome-beta.profile b/etc/google-chrome-beta.profile
index e527318c2..22a2e8f88 100644
--- a/etc/google-chrome-beta.profile
+++ b/etc/google-chrome-beta.profile
@@ -16,8 +16,6 @@ include /etc/firejail/disable-programs.inc
16# include /etc/firejail/disable-devel.inc 16# include /etc/firejail/disable-devel.inc
17# 17#
18 18
19netfilter
20
21whitelist ${DOWNLOADS} 19whitelist ${DOWNLOADS}
22mkdir ~/.config/google-chrome-beta 20mkdir ~/.config/google-chrome-beta
23whitelist ~/.config/google-chrome-beta 21whitelist ~/.config/google-chrome-beta
@@ -27,5 +25,15 @@ mkdir ~/.pki
27whitelist ~/.pki 25whitelist ~/.pki
28include /etc/firejail/whitelist-common.inc 26include /etc/firejail/whitelist-common.inc
29 27
28caps.keep sys_chroot,sys_admin
29#ipc-namespace
30netfilter
31nogroups
32shell none
33
34private-dev
35#private-tmp - problems with multiple browser sessions
36#disable-mnt
37
30noexec ${HOME} 38noexec ${HOME}
31noexec /tmp 39noexec /tmp
diff --git a/etc/google-chrome-unstable.profile b/etc/google-chrome-unstable.profile
index 860e2488a..0675d7b49 100644
--- a/etc/google-chrome-unstable.profile
+++ b/etc/google-chrome-unstable.profile
@@ -16,8 +16,6 @@ include /etc/firejail/disable-programs.inc
16# include /etc/firejail/disable-devel.inc 16# include /etc/firejail/disable-devel.inc
17# 17#
18 18
19netfilter
20
21whitelist ${DOWNLOADS} 19whitelist ${DOWNLOADS}
22mkdir ~/.config/google-chrome-unstable 20mkdir ~/.config/google-chrome-unstable
23whitelist ~/.config/google-chrome-unstable 21whitelist ~/.config/google-chrome-unstable
@@ -27,5 +25,15 @@ mkdir ~/.pki
27whitelist ~/.pki 25whitelist ~/.pki
28include /etc/firejail/whitelist-common.inc 26include /etc/firejail/whitelist-common.inc
29 27
28caps.keep sys_chroot,sys_admin
29#ipc-namespace
30netfilter
31nogroups
32shell none
33
34private-dev
35#private-tmp - problems with multiple browser sessions
36#disable-mnt
37
30noexec ${HOME} 38noexec ${HOME}
31noexec /tmp 39noexec /tmp
diff --git a/etc/google-chrome.profile b/etc/google-chrome.profile
index 7d27355d2..e6fceadec 100644
--- a/etc/google-chrome.profile
+++ b/etc/google-chrome.profile
@@ -16,9 +16,6 @@ include /etc/firejail/disable-programs.inc
16# include /etc/firejail/disable-devel.inc 16# include /etc/firejail/disable-devel.inc
17# 17#
18 18
19caps.keep sys_chroot,sys_admin
20netfilter
21
22whitelist ${DOWNLOADS} 19whitelist ${DOWNLOADS}
23mkdir ~/.config/google-chrome 20mkdir ~/.config/google-chrome
24whitelist ~/.config/google-chrome 21whitelist ~/.config/google-chrome
@@ -28,5 +25,15 @@ mkdir ~/.pki
28whitelist ~/.pki 25whitelist ~/.pki
29include /etc/firejail/whitelist-common.inc 26include /etc/firejail/whitelist-common.inc
30 27
28caps.keep sys_chroot,sys_admin
29#ipc-namespace
30netfilter
31nogroups
32shell none
33
34private-dev
35#private-tmp - problems with multiple browser sessions
36#disable-mnt
37
31noexec ${HOME} 38noexec ${HOME}
32noexec /tmp 39noexec /tmp
diff --git a/etc/vivaldi.profile b/etc/vivaldi.profile
index 7b9c4c9c6..fab620499 100644
--- a/etc/vivaldi.profile
+++ b/etc/vivaldi.profile
@@ -14,7 +14,6 @@ include /etc/firejail/disable-common.inc
14include /etc/firejail/disable-programs.inc 14include /etc/firejail/disable-programs.inc
15include /etc/firejail/disable-devel.inc 15include /etc/firejail/disable-devel.inc
16 16
17netfilter
18 17
19whitelist ${DOWNLOADS} 18whitelist ${DOWNLOADS}
20mkdir ~/.config/vivaldi 19mkdir ~/.config/vivaldi
@@ -23,5 +22,15 @@ mkdir ~/.cache/vivaldi
23whitelist ~/.cache/vivaldi 22whitelist ~/.cache/vivaldi
24include /etc/firejail/whitelist-common.inc 23include /etc/firejail/whitelist-common.inc
25 24
25caps.keep sys_chroot,sys_admin
26#ipc-namespace
27netfilter
28nogroups
29shell none
30
31private-dev
32#private-tmp - problems with multiple browser sessions
33#disable-mnt
34
26noexec ${HOME} 35noexec ${HOME}
27noexec /tmp 36noexec /tmp