aboutsummaryrefslogtreecommitdiffstats
path: root/etc/icecat.profile
diff options
context:
space:
mode:
Diffstat (limited to 'etc/icecat.profile')
-rw-r--r--etc/icecat.profile51
1 files changed, 50 insertions, 1 deletions
diff --git a/etc/icecat.profile b/etc/icecat.profile
index 25d426ad2..2f8e2df7f 100644
--- a/etc/icecat.profile
+++ b/etc/icecat.profile
@@ -1,2 +1,51 @@
1# Firejail profile for GNU Icecat 1# Firejail profile for GNU Icecat
2include /etc/firejail/firefox.profile 2
3noblacklist ~/.mozilla
4noblacklist ~/.cache/mozilla
5include /etc/firejail/disable-common.inc
6include /etc/firejail/disable-programs.inc
7include /etc/firejail/disable-devel.inc
8
9caps.drop all
10netfilter
11nonewprivs
12noroot
13protocol unix,inet,inet6,netlink
14seccomp
15tracelog
16
17whitelist ${DOWNLOADS}
18mkdir ~/.mozilla
19whitelist ~/.mozilla
20mkdir ~/.cache/mozilla/icecat
21whitelist ~/.cache/mozilla/icecat
22whitelist ~/dwhelper
23whitelist ~/.zotero
24whitelist ~/.vimperatorrc
25whitelist ~/.vimperator
26whitelist ~/.pentadactylrc
27whitelist ~/.pentadactyl
28whitelist ~/.keysnail.js
29whitelist ~/.config/gnome-mplayer
30whitelist ~/.cache/gnome-mplayer/plugin
31whitelist ~/.pki
32
33# lastpass, keepassx
34whitelist ~/.keepassx
35whitelist ~/.config/keepassx
36whitelist ~/keepassx.kdbx
37whitelist ~/.lastpass
38whitelist ~/.config/lastpass
39
40
41#silverlight
42whitelist ~/.wine-pipelight
43whitelist ~/.wine-pipelight64
44whitelist ~/.config/pipelight-widevine
45whitelist ~/.config/pipelight-silverlight5.1
46
47include /etc/firejail/whitelist-common.inc
48
49# experimental features
50#private-etc passwd,group,hostname,hosts,localtime,nsswitch.conf,resolv.conf,gtk-2.0,pango,fonts,iceweasel,firefox,adobe,mime.types,mailcap,asound.conf,pulse
51