aboutsummaryrefslogtreecommitdiffstats
path: root/etc/cower.profile
diff options
context:
space:
mode:
Diffstat (limited to 'etc/cower.profile')
-rw-r--r--etc/cower.profile47
1 files changed, 47 insertions, 0 deletions
diff --git a/etc/cower.profile b/etc/cower.profile
new file mode 100644
index 000000000..5e5c367c4
--- /dev/null
+++ b/etc/cower.profile
@@ -0,0 +1,47 @@
1# Firejail profile for cower
2# This file is overwritten after every install/update
3
4# This profile could be significantly strengthened by adding the following to cower.local
5# whitelist ~/<Your Build Folder>
6# whitelist ~/.config/cower/
7
8quiet
9
10# Persistent local customizations
11include /etc/firejail/cower.local
12# Persistent global definitions
13include /etc/firejail/globals.local
14
15noblacklist ~/.config/cower/config
16read-only ~/.config/cower/config
17
18noblacklist /var/lib/pacman
19
20include /etc/firejail/disable-common.inc
21include /etc/firejail/disable-devel.inc
22include /etc/firejail/disable-passwdmgr.inc
23include /etc/firejail/disable-programs.inc
24
25caps.drop all
26ipc-namespace
27netfilter
28no3d
29nodvd
30nogroups
31nonewprivs
32noroot
33nosound
34notv
35novideo
36protocol unix,inet,inet6
37seccomp
38shell none
39
40disable-mnt
41private-bin cower
42private-dev
43private-tmp
44
45memory-deny-write-execute
46noexec ${HOME}
47noexec /tmp