aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
-rw-r--r--etc/seahorse-tool.profile28
-rw-r--r--etc/seahorse.profile25
-rw-r--r--src/firecfg/firecfg.config1
3 files changed, 54 insertions, 0 deletions
diff --git a/etc/seahorse-tool.profile b/etc/seahorse-tool.profile
new file mode 100644
index 000000000..bbab69162
--- /dev/null
+++ b/etc/seahorse-tool.profile
@@ -0,0 +1,28 @@
1# Firejail profile for seahorse-tool
2# Description: PGP encryption and signing
3# This file is overwritten after every install/update
4# Persistent local customizations
5include seahorse-tool.local
6# Persistent global definitions
7# added by included profile
8#include globals.local
9
10# dconf
11mkdir ${HOME}/.config/dconf
12whitelist ${HOME}/.config/dconf
13
14include disable-xdg.inc
15include whitelist-var-common.inc
16
17apparmor
18ipc-namespace
19
20disable-mnt
21private-tmp
22
23memory-deny-write-execute
24noexec ${HOME}
25noexec /tmp
26
27# Redirect
28include gpg.profile
diff --git a/etc/seahorse.profile b/etc/seahorse.profile
new file mode 100644
index 000000000..0bf3b89fd
--- /dev/null
+++ b/etc/seahorse.profile
@@ -0,0 +1,25 @@
1# Firejail profile for seahorse
2# Description: GNOME application for managing PGP keys
3# This file is overwritten after every install/update
4# Persistent local customizations
5include seahorse.local
6# Persistent global definitions
7# added by included profile
8#include globals.local
9
10# dconf
11mkdir ${HOME}/.config/dconf
12whitelist ${HOME}/.config/dconf
13
14# ssh
15noblacklist /etc/ssh
16noblacklist /tmp/ssh-*
17noblacklist ${HOME}/.ssh
18
19include whitelist-var-common.inc
20
21apparmor
22ipc-namespace
23
24# Redirect
25include gpg.profile
diff --git a/src/firecfg/firecfg.config b/src/firecfg/firecfg.config
index c0166ff6f..ca3c00376 100644
--- a/src/firecfg/firecfg.config
+++ b/src/firecfg/firecfg.config
@@ -397,6 +397,7 @@ sayonara
397scallion 397scallion
398scribus 398scribus
399sdat2img 399sdat2img
400seahorse
400seamonkey 401seamonkey
401seamonkey-bin 402seamonkey-bin
402shellcheck 403shellcheck