summaryrefslogtreecommitdiffstats
path: root/etc/dconf.profile
diff options
context:
space:
mode:
Diffstat (limited to 'etc/dconf.profile')
-rw-r--r--etc/dconf.profile49
1 files changed, 49 insertions, 0 deletions
diff --git a/etc/dconf.profile b/etc/dconf.profile
new file mode 100644
index 000000000..a0bb5626d
--- /dev/null
+++ b/etc/dconf.profile
@@ -0,0 +1,49 @@
1# Firejail profile for dconf
2# Description: Configuration database system
3# This file is overwritten after every install/update
4# Persistent local customizations
5include dconf.local
6# Persistent global definitions
7include globals.local
8
9mkdir ${HOME}/.config/dconf
10whitelist ${HOME}/.config/dconf
11
12include disable-common.inc
13include disable-devel.inc
14include disable-interpreters.inc
15include disable-passwdmgr.inc
16include disable-programs.inc
17include disable-xdg.inc
18
19apparmor
20caps.drop all
21ipc-namespace
22machine-id
23net none
24no3d
25# nodbus - D-Bus is needed to commit changes to dconf
26nodvd
27nogroups
28nonewprivs
29noroot
30nosound
31notv
32nou2f
33novideo
34protocol unix
35seccomp
36shell none
37tracelog
38
39disable-mnt
40private-bin dconf,gsettings
41private-cache
42private-dev
43private-etc alternatives,dconf
44private-lib
45private-tmp
46
47memory-deny-write-execute
48noexec ${HOME}
49noexec /tmp