aboutsummaryrefslogtreecommitdiffstats
path: root/etc/frozen-bubble.profile
diff options
context:
space:
mode:
Diffstat (limited to 'etc/frozen-bubble.profile')
-rw-r--r--etc/frozen-bubble.profile38
1 files changed, 17 insertions, 21 deletions
diff --git a/etc/frozen-bubble.profile b/etc/frozen-bubble.profile
index 52f8e5b3e..dc8ad3e08 100644
--- a/etc/frozen-bubble.profile
+++ b/etc/frozen-bubble.profile
@@ -1,38 +1,34 @@
1# Persistent global definitions go here 1# Firejail profile for frozen-bubble
2# This file is overwritten after every install/update
3# Persistent local customizations
4include /etc/firejail/frozen-bubble.local
5# Persistent global definitions
2include /etc/firejail/globals.local 6include /etc/firejail/globals.local
3 7
4# This file is overwritten during software install. 8noblacklist ~/.frozen-bubble
5# Persistent customizations should go in a .local file.
6include /etc/firejail/frozen-bubble.local
7 9
8################################ 10include /etc/firejail/disable-common.inc
9# Frozen Bubble profile 11include /etc/firejail/disable-passwdmgr.inc
10################################ 12include /etc/firejail/disable-programs.inc
11 13
12noblacklist ~/.frozen-bubble
13mkdir ~/.frozen-bubble 14mkdir ~/.frozen-bubble
14whitelist ~/.frozen-bubble 15whitelist ~/.frozen-bubble
15include /etc/firejail/whitelist-common.inc 16include /etc/firejail/whitelist-common.inc
16 17
17include /etc/firejail/disable-common.inc
18include /etc/firejail/disable-programs.inc
19include /etc/firejail/disable-passwdmgr.inc
20
21caps.drop all 18caps.drop all
19net none
20nogroups
22nonewprivs 21nonewprivs
23noroot 22noroot
24protocol unix,netlink 23protocol unix,netlink
25seccomp 24seccomp
26
27#
28# depending on your usage, you can enable some of the commands below:
29#
30net none
31nogroups
32shell none 25shell none
33#private-bin frozen-bubble 26
34# private-etc none 27# private-bin frozen-bubble
35private-dev 28private-dev
29# private-etc none
36private-tmp 30private-tmp
37# nosound
38 31
32# CLOBBERED COMMENTS
33# depending on your usage, you can enable some of the commands below:
34# nosound