diff options
Diffstat (limited to 'etc/akonadi_control.profile')
-rw-r--r-- | etc/akonadi_control.profile | 44 |
1 files changed, 44 insertions, 0 deletions
diff --git a/etc/akonadi_control.profile b/etc/akonadi_control.profile new file mode 100644 index 000000000..44184b76a --- /dev/null +++ b/etc/akonadi_control.profile | |||
@@ -0,0 +1,44 @@ | |||
1 | # Firejail profile for akonadi_control | ||
2 | # Persistent local customizations | ||
3 | include /etc/firejail/akonadi_control.local | ||
4 | # Persistent global definitions | ||
5 | include /etc/firejail/globals.local | ||
6 | |||
7 | noblacklist ${HOME}/.cache/akonadi* | ||
8 | noblacklist ${HOME}/.config/akonadi* | ||
9 | noblacklist ${HOME}/.config/baloorc | ||
10 | noblacklist ${HOME}/.local/share/akonadi/* | ||
11 | noblacklist ${HOME}/.local/share/contacts | ||
12 | noblacklist ${HOME}/.local/share/local-mail | ||
13 | noblacklist /usr/sbin | ||
14 | |||
15 | include /etc/firejail/disable-common.inc | ||
16 | include /etc/firejail/disable-devel.inc | ||
17 | include /etc/firejail/disable-passwdmgr.inc | ||
18 | include /etc/firejail/disable-programs.inc | ||
19 | |||
20 | include /etc/firejail/whitelist-var-common.inc | ||
21 | |||
22 | # depending on your setup it might be possible to | ||
23 | # enable some of the commented options below | ||
24 | |||
25 | caps.drop all | ||
26 | ipc-namespace | ||
27 | no3d | ||
28 | netfilter | ||
29 | nodvd | ||
30 | nogroups | ||
31 | # nonewprivs | ||
32 | # noroot | ||
33 | nosound | ||
34 | notv | ||
35 | novideo | ||
36 | # protocol unix,inet,inet6 | ||
37 | # seccomp.drop @cpu-emulation,@debug,@obsolete,@privileged,@resources,add_key,fanotify_init,io_cancel,io_destroy,kcmp,keyctl,name_to_handle_at,ni_syscall,open_by_handle_at,personality,process_vm_readv,ptrace,remap_file_pages,request_key,syslog,umount,userfaultfd,vmsplice # we need to allow io_getevents, ioprio_set, io_setup, io_submit system calls | ||
38 | tracelog | ||
39 | |||
40 | private-dev | ||
41 | # private-tmp - breaks programs that depend on akonadi | ||
42 | |||
43 | noexec ${HOME} | ||
44 | noexec /tmp | ||