aboutsummaryrefslogtreecommitdiffstats
path: root/etc/gajim.profile
diff options
context:
space:
mode:
Diffstat (limited to 'etc/gajim.profile')
-rw-r--r--etc/gajim.profile38
1 files changed, 38 insertions, 0 deletions
diff --git a/etc/gajim.profile b/etc/gajim.profile
new file mode 100644
index 000000000..eb60f858b
--- /dev/null
+++ b/etc/gajim.profile
@@ -0,0 +1,38 @@
1# Firejail profile for Gajim
2noblacklist ${HOME}/.cache/gajim
3noblacklist ${HOME}/.local/share/gajim
4noblacklist ${HOME}/.config/gajim
5
6mkdir ${HOME}/.cache/gajim
7mkdir ${HOME}/.local/share/gajim
8mkdir ${HOME}/.config/gajim
9mkdir ${HOME}/Downloads
10
11# Allow the local python 2.7 site packages, in case any plugins are using these
12mkdir ${HOME}/.local/lib/python2.7/site-packages/
13whitelist ${HOME}/.local/lib/python2.7/site-packages/
14read-only ${HOME}/.local/lib/python2.7/site-packages/
15
16whitelist ${HOME}/.cache/gajim
17whitelist ${HOME}/.local/share/gajim
18whitelist ${HOME}/.config/gajim
19whitelist ${HOME}/Downloads
20
21include /etc/firejail/disable-common.inc
22include /etc/firejail/disable-passwdmgr.inc
23include /etc/firejail/disable-programs.inc
24include /etc/firejail/disable-devel.inc
25
26caps.drop all
27netfilter
28nogroups
29nonewprivs
30noroot
31protocol unix,inet,inet6
32seccomp
33shell none
34
35#private-bin python2.7 gajim
36#private-etc fonts
37private-dev
38#private-tmp