aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
-rw-r--r--etc/disable-programs.inc1
-rw-r--r--etc/font-manager.profile54
-rw-r--r--src/firecfg/firecfg.config1
3 files changed, 56 insertions, 0 deletions
diff --git a/etc/disable-programs.inc b/etc/disable-programs.inc
index 5485550a8..6bcb5e46c 100644
--- a/etc/disable-programs.inc
+++ b/etc/disable-programs.inc
@@ -144,6 +144,7 @@ blacklist ${HOME}/.config/evolution
144blacklist ${HOME}/.config/falkon 144blacklist ${HOME}/.config/falkon
145blacklist ${HOME}/.config/filezilla 145blacklist ${HOME}/.config/filezilla
146blacklist ${HOME}/.config/flowblade 146blacklist ${HOME}/.config/flowblade
147blacklist ${HOME}/.config/font-manager
147blacklist ${HOME}/.config/gajim 148blacklist ${HOME}/.config/gajim
148blacklist ${HOME}/.config/galculator 149blacklist ${HOME}/.config/galculator
149blacklist ${HOME}/.config/gconf 150blacklist ${HOME}/.config/gconf
diff --git a/etc/font-manager.profile b/etc/font-manager.profile
new file mode 100644
index 000000000..fa5ee6105
--- /dev/null
+++ b/etc/font-manager.profile
@@ -0,0 +1,54 @@
1# Firejail profile for font-manager
2# Description: A simple font management application for GTK desktop environments
3# This file is overwritten after every install/update
4# Persistent local customizations
5include font-manager.local
6# Persistent global definitions
7include globals.local
8
9noblacklist ${HOME}/.config/font-manager
10whitelist ${HOME}/.config/font-manager
11
12# Allow python (blacklisted by disable-interpreters.inc)
13noblacklist ${PATH}/python2*
14noblacklist ${PATH}/python3*
15noblacklist /usr/lib/python2*
16noblacklist /usr/lib/python3*
17
18include disable-common.inc
19include disable-devel.inc
20include disable-interpreters.inc
21include disable-passwdmgr.inc
22include disable-programs.inc
23include disable-xdg.inc
24
25mkdir ${HOME}/.cache/font-manager
26whitelist ${HOME}/.cache/font-manager
27include whitelist-common.inc
28
29apparmor
30caps.drop all
31machine-id
32net none
33no3d
34nodvd
35nogroups
36nonewprivs
37noroot
38nosound
39notv
40nou2f
41novideo
42protocol unix
43seccomp
44shell none
45tracelog
46
47disable-mnt
48private-bin font-manager,python*,yelp
49private-dev
50private-tmp
51
52#memory-deny-write-execute - Breaks on Arch
53noexec ${HOME}
54noexec /tmp
diff --git a/src/firecfg/firecfg.config b/src/firecfg/firecfg.config
index bd45d7802..bb035445f 100644
--- a/src/firecfg/firecfg.config
+++ b/src/firecfg/firecfg.config
@@ -156,6 +156,7 @@ firefox-wayland
156flameshot 156flameshot
157flashpeak-slimjet 157flashpeak-slimjet
158flowblade 158flowblade
159font-manager
159fontforge 160fontforge
160franz 161franz
161freecad 162freecad