aboutsummaryrefslogtreecommitdiffstats
path: root/etc/gnome-documents.profile
diff options
context:
space:
mode:
Diffstat (limited to 'etc/gnome-documents.profile')
-rw-r--r--etc/gnome-documents.profile16
1 files changed, 7 insertions, 9 deletions
diff --git a/etc/gnome-documents.profile b/etc/gnome-documents.profile
index 2d70bf7ef..e56a32a4a 100644
--- a/etc/gnome-documents.profile
+++ b/etc/gnome-documents.profile
@@ -1,20 +1,18 @@
1# Persistent global definitions go here 1# Firejail profile for gnome-documents
2include /etc/firejail/globals.local 2# This file is overwritten after every install/update
3 3# Persistent local customizations
4# This file is overwritten during software install.
5# Persistent customizations should go in a .local file.
6include /etc/firejail/gnome-documents.local 4include /etc/firejail/gnome-documents.local
7 5# Persistent global definitions
8# gnome-documents profile 6include /etc/firejail/globals.local
9 7
10# when gjs apps are started via gnome-shell, firejail is not applied because systemd will start them 8# when gjs apps are started via gnome-shell, firejail is not applied because systemd will start them
11 9
12noblacklist ~/.config/libreoffice 10noblacklist ~/.config/libreoffice
13 11
14include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
15include /etc/firejail/disable-programs.inc
16include /etc/firejail/disable-devel.inc 13include /etc/firejail/disable-devel.inc
17include /etc/firejail/disable-passwdmgr.inc 14include /etc/firejail/disable-passwdmgr.inc
15include /etc/firejail/disable-programs.inc
18 16
19caps.drop all 17caps.drop all
20netfilter 18netfilter
@@ -29,8 +27,8 @@ seccomp
29shell none 27shell none
30tracelog 28tracelog
31 29
32private-tmp
33private-dev 30private-dev
31private-tmp
34 32
35noexec ${HOME} 33noexec ${HOME}
36noexec /tmp 34noexec /tmp