aboutsummaryrefslogtreecommitdiffstats
path: root/etc/icecat.profile
diff options
context:
space:
mode:
Diffstat (limited to 'etc/icecat.profile')
-rw-r--r--etc/icecat.profile50
1 files changed, 49 insertions, 1 deletions
diff --git a/etc/icecat.profile b/etc/icecat.profile
index 25d426ad2..0348076da 100644
--- a/etc/icecat.profile
+++ b/etc/icecat.profile
@@ -1,2 +1,50 @@
1# Firejail profile for GNU Icecat 1# Firejail profile for GNU Icecat
2include /etc/firejail/firefox.profile 2noblacklist ~/.mozilla
3noblacklist ~/.cache/mozilla
4include /etc/firejail/disable-common.inc
5include /etc/firejail/disable-programs.inc
6include /etc/firejail/disable-devel.inc
7
8caps.drop all
9netfilter
10nonewprivs
11noroot
12protocol unix,inet,inet6,netlink
13seccomp
14tracelog
15
16whitelist ${DOWNLOADS}
17mkdir ~/.mozilla
18whitelist ~/.mozilla
19mkdir ~/.cache/mozilla/icecat
20whitelist ~/.cache/mozilla/icecat
21whitelist ~/dwhelper
22whitelist ~/.zotero
23whitelist ~/.vimperatorrc
24whitelist ~/.vimperator
25whitelist ~/.pentadactylrc
26whitelist ~/.pentadactyl
27whitelist ~/.keysnail.js
28whitelist ~/.config/gnome-mplayer
29whitelist ~/.cache/gnome-mplayer/plugin
30whitelist ~/.pki
31
32# lastpass, keepassx
33whitelist ~/.keepassx
34whitelist ~/.config/keepassx
35whitelist ~/keepassx.kdbx
36whitelist ~/.lastpass
37whitelist ~/.config/lastpass
38
39
40#silverlight
41whitelist ~/.wine-pipelight
42whitelist ~/.wine-pipelight64
43whitelist ~/.config/pipelight-widevine
44whitelist ~/.config/pipelight-silverlight5.1
45
46include /etc/firejail/whitelist-common.inc
47
48# experimental features
49#private-etc passwd,group,hostname,hosts,localtime,nsswitch.conf,resolv.conf,gtk-2.0,pango,fonts,iceweasel,firefox,adobe,mime.types,mailcap,asound.conf,pulse
50