aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
-rw-r--r--etc/inc/disable-programs.inc2
-rw-r--r--etc/profile-m-z/rawtherapee.profile39
2 files changed, 41 insertions, 0 deletions
diff --git a/etc/inc/disable-programs.inc b/etc/inc/disable-programs.inc
index 50e4854ac..659245724 100644
--- a/etc/inc/disable-programs.inc
+++ b/etc/inc/disable-programs.inc
@@ -78,6 +78,7 @@ blacklist ${HOME}/.cache/PawelStolowski
78blacklist ${HOME}/.cache/Psi 78blacklist ${HOME}/.cache/Psi
79blacklist ${HOME}/.cache/QuiteRss 79blacklist ${HOME}/.cache/QuiteRss
80blacklist ${HOME}/.cache/Quotient/quaternion 80blacklist ${HOME}/.cache/Quotient/quaternion
81blacklist ${HOME}/.cache/RawTherapee
81blacklist ${HOME}/.cache/Shortwave 82blacklist ${HOME}/.cache/Shortwave
82blacklist ${HOME}/.cache/Tox 83blacklist ${HOME}/.cache/Tox
83blacklist ${HOME}/.cache/Zeal 84blacklist ${HOME}/.cache/Zeal
@@ -335,6 +336,7 @@ blacklist ${HOME}/.config/QuiteRssrc
335blacklist ${HOME}/.config/Quotient 336blacklist ${HOME}/.config/Quotient
336blacklist ${HOME}/.config/RSS Guard 4 337blacklist ${HOME}/.config/RSS Guard 4
337blacklist ${HOME}/.config/Rambox 338blacklist ${HOME}/.config/Rambox
339blacklist ${HOME}/.config/RawTherapee
338blacklist ${HOME}/.config/Riot 340blacklist ${HOME}/.config/Riot
339blacklist ${HOME}/.config/Rocket.Chat 341blacklist ${HOME}/.config/Rocket.Chat
340blacklist ${HOME}/.config/RogueLegacy 342blacklist ${HOME}/.config/RogueLegacy
diff --git a/etc/profile-m-z/rawtherapee.profile b/etc/profile-m-z/rawtherapee.profile
new file mode 100644
index 000000000..0cf946eec
--- /dev/null
+++ b/etc/profile-m-z/rawtherapee.profile
@@ -0,0 +1,39 @@
1# Firejail profile for rawtherapee
2# Description: Free cross-platform raw image processing program
3# This file is overwritten after every install/update
4# Persistent local customizations
5include rawtherapee.local
6# Persistent global definitions
7include globals.local
8
9noblacklist ${HOME}/.cache/RawTherapee
10noblacklist ${HOME}/.config/RawTherapee
11noblacklist ${PICTURES}
12
13include disable-common.inc
14include disable-devel.inc
15include disable-exec.inc
16include disable-interpreters.inc
17include disable-programs.inc
18include disable-shell.inc
19include disable-xdg.inc
20
21caps.drop all
22netfilter
23nodvd
24nogroups
25noinput
26nonewprivs
27noroot
28nosound
29notv
30nou2f
31novideo
32protocol unix,inet,inet6
33seccomp
34
35private-bin rawtherapee
36private-dev
37private-tmp
38
39restrict-namespaces