aboutsummaryrefslogtreecommitdiffstats
path: root/etc/crow.profile
diff options
context:
space:
mode:
Diffstat (limited to 'etc/crow.profile')
-rw-r--r--etc/crow.profile57
1 files changed, 57 insertions, 0 deletions
diff --git a/etc/crow.profile b/etc/crow.profile
new file mode 100644
index 000000000..14145ffea
--- /dev/null
+++ b/etc/crow.profile
@@ -0,0 +1,57 @@
1# Firejail profile for crow
2# This file is overwritten after every install/update
3# Persistent local customizations
4include crow.local
5# Persistent global definitions
6include globals.local
7
8noblacklist ${HOME}/.config/crow
9noblacklist ${HOME}/.cache/gstreamer-1.0
10
11mkdir ${HOME}/.config/crow
12mkdir ${HOME}/.cache/gstreamer-1.0
13
14whitelist ${HOME}/.config/crow
15whitelist ${HOME}/.cache/gstreamer-1.0
16
17include disable-common.inc
18include disable-devel.inc
19include disable-interpreters.inc
20include disable-passwdmgr.inc
21include disable-programs.inc
22include disable-xdg.inc
23
24include whitelist-common.inc
25
26# apparmor
27caps.drop all
28# ipc-namespace
29netfilter
30no3d
31nodbus
32nodvd
33nogroups
34nonewprivs
35noroot
36# nosound
37notv
38nou2f
39novideo
40protocol unix,inet,inet6,netlink
41seccomp
42shell none
43# tracelog
44
45disable-mnt
46private-bin crow
47# private-cache
48private-dev
49private-etc ca-certificates,ssl,machine-id,dconf,nsswitch.conf,resolv.conf,fonts,asound.conf,pulse,pki,crypto-policies
50# private-lib
51private-opt none
52private-tmp
53private-srv none
54
55# memory-deny-write-execute
56noexec ${HOME}
57noexec /tmp