aboutsummaryrefslogtreecommitdiffstats
path: root/etc/google-chrome.profile
diff options
context:
space:
mode:
Diffstat (limited to 'etc/google-chrome.profile')
-rw-r--r--etc/google-chrome.profile30
1 files changed, 13 insertions, 17 deletions
diff --git a/etc/google-chrome.profile b/etc/google-chrome.profile
index e6fceadec..f0d452841 100644
--- a/etc/google-chrome.profile
+++ b/etc/google-chrome.profile
@@ -1,39 +1,35 @@
1# Persistent global definitions go here 1# Firejail profile for google-chrome
2include /etc/firejail/globals.local 2# This file is overwritten after every install/update
3 3# Persistent local customizations
4# This file is overwritten during software install.
5# Persistent customizations should go in a .local file.
6include /etc/firejail/google-chrome.local 4include /etc/firejail/google-chrome.local
5# Persistent global definitions
6include /etc/firejail/globals.local
7 7
8# Google Chrome browser profile
9noblacklist ~/.config/google-chrome
10noblacklist ~/.cache/google-chrome 8noblacklist ~/.cache/google-chrome
9noblacklist ~/.config/google-chrome
11noblacklist ~/.pki 10noblacklist ~/.pki
12include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-programs.inc
14 11
12include /etc/firejail/disable-common.inc
15# chromium is distributed with a perl script on Arch 13# chromium is distributed with a perl script on Arch
16# include /etc/firejail/disable-devel.inc 14# include /etc/firejail/disable-devel.inc
17# 15include /etc/firejail/disable-programs.inc
18 16
19whitelist ${DOWNLOADS}
20mkdir ~/.config/google-chrome
21whitelist ~/.config/google-chrome
22mkdir ~/.cache/google-chrome 17mkdir ~/.cache/google-chrome
23whitelist ~/.cache/google-chrome 18mkdir ~/.config/google-chrome
24mkdir ~/.pki 19mkdir ~/.pki
20whitelist ${DOWNLOADS}
21whitelist ~/.cache/google-chrome
22whitelist ~/.config/google-chrome
25whitelist ~/.pki 23whitelist ~/.pki
26include /etc/firejail/whitelist-common.inc 24include /etc/firejail/whitelist-common.inc
27 25
28caps.keep sys_chroot,sys_admin 26caps.keep sys_chroot,sys_admin
29#ipc-namespace
30netfilter 27netfilter
31nogroups 28nogroups
32shell none 29shell none
33 30
34private-dev 31private-dev
35#private-tmp - problems with multiple browser sessions 32# private-tmp - problems with multiple browser sessions
36#disable-mnt
37 33
38noexec ${HOME} 34noexec ${HOME}
39noexec /tmp 35noexec /tmp