aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
-rw-r--r--etc/gnome-nettool.profile49
-rw-r--r--src/firecfg/firecfg.config1
2 files changed, 50 insertions, 0 deletions
diff --git a/etc/gnome-nettool.profile b/etc/gnome-nettool.profile
new file mode 100644
index 000000000..585fb9a20
--- /dev/null
+++ b/etc/gnome-nettool.profile
@@ -0,0 +1,49 @@
1# Firejail profile for gnome-nettool
2# Description: Graphical interface for various networking tools
3# This file is overwritten after every install/update
4# Persistent local customizations
5include gnome-nettool.local
6# Persistent global definitions
7include globals.local
8
9include disable-common.inc
10include disable-devel.inc
11include disable-interpreters.inc
12include disable-passwdmgr.inc
13include disable-programs.inc
14include disable-xdg.inc
15
16include whitelist-common.inc
17include whitelist-var-common.inc
18
19caps.keep net_raw
20ipc-namespace
21machine-id
22netfilter
23no3d
24nodbus
25nodvd
26nogroups
27# ping needs to elevate privileges, noroot and nonewprivs will kill it
28#nonewprivs
29#noroot
30nosound
31notv
32nou2f
33novideo
34#seccomp
35#shell none
36
37disable-mnt
38#private-bin gnome-nettool
39private-cache
40private-dev
41#private-etc alternatives
42private-lib libbind9.so.*,libcrypto.so.*,libdns.so.*,libirs.so.*,liblua.so.*,libssh2.so.*,libssl.so.*
43private-tmp
44
45noexec ${HOME}
46noexec /tmp
47
48# never write anything
49read-only ${HOME}
diff --git a/src/firecfg/firecfg.config b/src/firecfg/firecfg.config
index 11a147636..9664d2198 100644
--- a/src/firecfg/firecfg.config
+++ b/src/firecfg/firecfg.config
@@ -198,6 +198,7 @@ gnome-maps
198gnome-mplayer 198gnome-mplayer
199gnome-mpv 199gnome-mpv
200gnome-music 200gnome-music
201gnome-nettool
201gnome-photos 202gnome-photos
202gnome-recipes 203gnome-recipes
203gnome-twitch 204gnome-twitch