aboutsummaryrefslogtreecommitdiffstats
path: root/etc/itch.profile
diff options
context:
space:
mode:
Diffstat (limited to 'etc/itch.profile')
-rw-r--r--etc/itch.profile12
1 files changed, 8 insertions, 4 deletions
diff --git a/etc/itch.profile b/etc/itch.profile
index c7a12dfee..7e8f0518d 100644
--- a/etc/itch.profile
+++ b/etc/itch.profile
@@ -5,14 +5,18 @@ include /etc/firejail/itch.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.config/itch 8# itch.io has native firejail/sandboxing support bundled in
9# See https://itch.io/docs/itch/using/sandbox/linux.html
10
11noblacklist ${HOME}/.config/itch
9 12
10include /etc/firejail/disable-common.inc 13include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-devel.inc 14include /etc/firejail/disable-devel.inc
15include /etc/firejail/disable-passwdmgr.inc
12include /etc/firejail/disable-programs.inc 16include /etc/firejail/disable-programs.inc
13 17
14whitelist ~/.config/itch 18mkdir ${HOME}/.config/itch
15 19whitelist ${HOME}/.config/itch
16include /etc/firejail/whitelist-common.inc 20include /etc/firejail/whitelist-common.inc
17 21
18caps.drop all 22caps.drop all
@@ -22,6 +26,7 @@ nogroups
22nonewprivs 26nonewprivs
23noroot 27noroot
24notv 28notv
29novideo
25protocol unix,inet,inet6,netlink 30protocol unix,inet,inet6,netlink
26seccomp 31seccomp
27shell none 32shell none
@@ -29,5 +34,4 @@ shell none
29private-dev 34private-dev
30private-tmp 35private-tmp
31 36
32noexec ${HOME}
33noexec /tmp 37noexec /tmp