aboutsummaryrefslogtreecommitdiffstats
path: root/etc/chromium.profile
diff options
context:
space:
mode:
Diffstat (limited to 'etc/chromium.profile')
-rw-r--r--etc/chromium.profile34
1 files changed, 15 insertions, 19 deletions
diff --git a/etc/chromium.profile b/etc/chromium.profile
index 8266770d7..cec5366d9 100644
--- a/etc/chromium.profile
+++ b/etc/chromium.profile
@@ -1,41 +1,37 @@
1# Persistent global definitions go here 1# Firejail profile for chromium
2include /etc/firejail/globals.local 2# This file is overwritten after every install/update
3 3# Persistent local customizations
4# This file is overwritten during software install.
5# Persistent customizations should go in a .local file.
6include /etc/firejail/chromium.local 4include /etc/firejail/chromium.local
5# Persistent global definitions
6include /etc/firejail/globals.local
7 7
8# Chromium browser profile
9noblacklist ~/.config/chromium
10noblacklist ~/.cache/chromium 8noblacklist ~/.cache/chromium
11noblacklist ~/.pki 9noblacklist ~/.config/chromium
12# specific to Arch
13noblacklist ~/.config/chromium-flags.conf 10noblacklist ~/.config/chromium-flags.conf
11noblacklist ~/.pki
12
14include /etc/firejail/disable-common.inc 13include /etc/firejail/disable-common.inc
15include /etc/firejail/disable-programs.inc
16# chromium is distributed with a perl script on Arch 14# chromium is distributed with a perl script on Arch
17# include /etc/firejail/disable-devel.inc 15# include /etc/firejail/disable-devel.inc
16include /etc/firejail/disable-programs.inc
18 17
19whitelist ${DOWNLOADS}
20mkdir ~/.config/chromium
21whitelist ~/.config/chromium
22mkdir ~/.cache/chromium 18mkdir ~/.cache/chromium
23whitelist ~/.cache/chromium 19mkdir ~/.config/chromium
24mkdir ~/.pki 20mkdir ~/.pki
25whitelist ~/.pki 21whitelist ${DOWNLOADS}
22whitelist ~/.cache/chromium
23whitelist ~/.config/chromium
26whitelist ~/.config/chromium-flags.conf 24whitelist ~/.config/chromium-flags.conf
27 25whitelist ~/.pki
28include /etc/firejail/whitelist-common.inc 26include /etc/firejail/whitelist-common.inc
29 27
30caps.keep sys_chroot,sys_admin 28caps.keep sys_chroot,sys_admin
31#ipc-namespace
32netfilter 29netfilter
33nogroups 30nogroups
34shell none 31shell none
35 32
36private-dev 33private-dev
37#private-tmp - problems with multiple browser sessions 34# private-tmp - problems with multiple browser sessions
38#disable-mnt
39 35
40noexec ${HOME} 36noexec ${HOME}
41noexec /tmp 37noexec /tmp