aboutsummaryrefslogtreecommitdiffstats
path: root/etc/baloo_file.profile
diff options
context:
space:
mode:
Diffstat (limited to 'etc/baloo_file.profile')
-rw-r--r--etc/baloo_file.profile27
1 files changed, 13 insertions, 14 deletions
diff --git a/etc/baloo_file.profile b/etc/baloo_file.profile
index 2fe6d1927..9c2909b0f 100644
--- a/etc/baloo_file.profile
+++ b/etc/baloo_file.profile
@@ -1,21 +1,21 @@
1# Persistent global definitions go here 1# Firejail profile for baloo_file
2include /etc/firejail/globals.local 2# This file is overwritten after every install/update
3 3# Persistent local customizations
4# This file is overwritten during software install.
5# Persistent customizations should go in a .local file.
6include /etc/firejail/baloo_file.local 4include /etc/firejail/baloo_file.local
5# Persistent global definitions
6include /etc/firejail/globals.local
7 7
8# KDE Baloo file daemon profile 8noblacklist ${HOME}/.config/baloofilerc
9noblacklist ${HOME}/.kde4/share/config/baloofilerc
10noblacklist ${HOME}/.kde4/share/config/baloorc
11noblacklist ${HOME}/.kde/share/config/baloofilerc 9noblacklist ${HOME}/.kde/share/config/baloofilerc
12noblacklist ${HOME}/.kde/share/config/baloorc 10noblacklist ${HOME}/.kde/share/config/baloorc
13noblacklist ${HOME}/.config/baloofilerc 11noblacklist ${HOME}/.kde4/share/config/baloofilerc
12noblacklist ${HOME}/.kde4/share/config/baloorc
14noblacklist ${HOME}/.local/share/baloo 13noblacklist ${HOME}/.local/share/baloo
14
15include /etc/firejail/disable-common.inc 15include /etc/firejail/disable-common.inc
16include /etc/firejail/disable-programs.inc
17include /etc/firejail/disable-devel.inc 16include /etc/firejail/disable-devel.inc
18include /etc/firejail/disable-passwdmgr.inc 17include /etc/firejail/disable-passwdmgr.inc
18include /etc/firejail/disable-programs.inc
19 19
20caps.drop all 20caps.drop all
21nogroups 21nogroups
@@ -26,7 +26,6 @@ novideo
26protocol unix 26protocol unix
27# Baloo makes ioprio_set system calls, which are blacklisted by default. 27# Baloo makes ioprio_set system calls, which are blacklisted by default.
28seccomp.drop mount,umount2,ptrace,kexec_load,kexec_file_load,name_to_handle_at,open_by_handle_at,create_module,init_module,finit_module,delete_module,iopl,ioperm,swapon,swapoff,syslog,process_vm_readv,process_vm_writev,sysfs,_sysctl,adjtimex,clock_adjtime,lookup_dcookie,perf_event_open,fanotify_init,kcmp,add_key,request_key,keyctl,uselib,acct,modify_ldt,pivot_root,io_setup,io_destroy,io_getevents,io_submit,io_cancel,remap_file_pages,mbind,get_mempolicy,set_mempolicy,migrate_pages,move_pages,vmsplice,chroot,tuxcall,reboot,mfsservctl,get_kernel_syms,bpf,clock_settime,personality,process_vm_writev,query_module,settimeofday,stime,umount,userfaultfd,ustat,vm86,vm86old 28seccomp.drop mount,umount2,ptrace,kexec_load,kexec_file_load,name_to_handle_at,open_by_handle_at,create_module,init_module,finit_module,delete_module,iopl,ioperm,swapon,swapoff,syslog,process_vm_readv,process_vm_writev,sysfs,_sysctl,adjtimex,clock_adjtime,lookup_dcookie,perf_event_open,fanotify_init,kcmp,add_key,request_key,keyctl,uselib,acct,modify_ldt,pivot_root,io_setup,io_destroy,io_getevents,io_submit,io_cancel,remap_file_pages,mbind,get_mempolicy,set_mempolicy,migrate_pages,move_pages,vmsplice,chroot,tuxcall,reboot,mfsservctl,get_kernel_syms,bpf,clock_settime,personality,process_vm_writev,query_module,settimeofday,stime,umount,userfaultfd,ustat,vm86,vm86old
29
30x11 xorg 29x11 xorg
31 30
32private-dev 31private-dev
@@ -37,6 +36,6 @@ noexec /tmp
37 36
38# Make home directory read-only and allow writing only to ~/.local/share 37# Make home directory read-only and allow writing only to ~/.local/share
39# Note: Baloo will not be able to update the "first run" key in its configuration files. 38# Note: Baloo will not be able to update the "first run" key in its configuration files.
40#read-only ${HOME} 39# noexec ${HOME}/.local/share
41#read-write ${HOME}/.local/share 40# read-only ${HOME}
42#noexec ${HOME}/.local/share 41# read-write ${HOME}/.local/share