aboutsummaryrefslogtreecommitdiffstats
path: root/etc/firefox.profile
diff options
context:
space:
mode:
Diffstat (limited to 'etc/firefox.profile')
-rw-r--r--etc/firefox.profile29
1 files changed, 17 insertions, 12 deletions
diff --git a/etc/firefox.profile b/etc/firefox.profile
index 1ea94a2c7..4f971f330 100644
--- a/etc/firefox.profile
+++ b/etc/firefox.profile
@@ -1,23 +1,24 @@
1# Firejail profile for Mozilla Firefox (Iceweasel in Debian) 1# Firejail profile for Mozilla Firefox (Iceweasel in Debian)
2
3noblacklist ~/.mozilla 2noblacklist ~/.mozilla
4noblacklist ~/.cache/mozilla 3noblacklist ~/.cache/mozilla
4noblacklist ~/.config/qpdfview
5noblacklist ~/.local/share/qpdfview
6noblacklist ~/.kde/share/apps/okular
5include /etc/firejail/disable-common.inc 7include /etc/firejail/disable-common.inc
6include /etc/firejail/disable-programs.inc 8include /etc/firejail/disable-programs.inc
7include /etc/firejail/disable-devel.inc 9include /etc/firejail/disable-devel.inc
8 10
9caps.drop all 11caps.drop all
10seccomp
11protocol unix,inet,inet6,netlink
12netfilter 12netfilter
13tracelog 13nonewprivs
14noroot 14noroot
15protocol unix,inet,inet6,netlink
16seccomp
17tracelog
15 18
16whitelist ${DOWNLOADS} 19whitelist ${DOWNLOADS}
17mkdir ~/.mozilla 20mkdir ~/.mozilla
18whitelist ~/.mozilla 21whitelist ~/.mozilla
19mkdir ~/.cache
20mkdir ~/.cache/mozilla
21mkdir ~/.cache/mozilla/firefox 22mkdir ~/.cache/mozilla/firefox
22whitelist ~/.cache/mozilla/firefox 23whitelist ~/.cache/mozilla/firefox
23whitelist ~/dwhelper 24whitelist ~/dwhelper
@@ -30,6 +31,9 @@ whitelist ~/.keysnail.js
30whitelist ~/.config/gnome-mplayer 31whitelist ~/.config/gnome-mplayer
31whitelist ~/.cache/gnome-mplayer/plugin 32whitelist ~/.cache/gnome-mplayer/plugin
32whitelist ~/.pki 33whitelist ~/.pki
34whitelist ~/.config/qpdfview
35whitelist ~/.local/share/qpdfview
36whitelist ~/.kde/share/apps/okular
33 37
34# lastpass, keepassx 38# lastpass, keepassx
35whitelist ~/.keepassx 39whitelist ~/.keepassx
@@ -40,14 +44,15 @@ whitelist ~/.config/lastpass
40 44
41 45
42#silverlight 46#silverlight
43whitelist ~/.wine-pipelight 47whitelist ~/.wine-pipelight
44whitelist ~/.wine-pipelight64 48whitelist ~/.wine-pipelight64
45whitelist ~/.config/pipelight-widevine 49whitelist ~/.config/pipelight-widevine
46whitelist ~/.config/pipelight-silverlight5.1 50whitelist ~/.config/pipelight-silverlight5.1
47 51
48include /etc/firejail/whitelist-common.inc 52include /etc/firejail/whitelist-common.inc
49 53
50# experimental features 54# experimental features
51#private-etc passwd,group,hostname,hosts,localtime,nsswitch.conf,resolv.conf,gtk-2.0,pango,fonts,iceweasel,firefox,adobe,mime.types,mailcap,asound.conf,pulse 55#private-bin firefox,which,sh,dbus-launch,dbus-send,env
52 56#private-etc passwd,group,hostname,hosts,localtime,nsswitch.conf,resolv.conf,xdg,gtk-2.0,gtk-3.0,X11,pango,fonts,firefox,mime.types,mailcap,asound.conf,pulse
53 57private-dev
58private-tmp