aboutsummaryrefslogtreecommitdiffstats
path: root/etc/liferea.profile
diff options
context:
space:
mode:
Diffstat (limited to 'etc/liferea.profile')
-rw-r--r--etc/liferea.profile37
1 files changed, 16 insertions, 21 deletions
diff --git a/etc/liferea.profile b/etc/liferea.profile
index f11137cdd..f9c050acb 100644
--- a/etc/liferea.profile
+++ b/etc/liferea.profile
@@ -1,47 +1,42 @@
1# Persistent global definitions go here 1# Firejail profile for liferea
2include /etc/firejail/global.local 2# This file is overwritten after every install/update
3 3# Persistent local customizations
4# This file is overwritten during software install.
5# Persistent customizations should go in a .local file.
6include /etc/firejail/liferea.local 4include /etc/firejail/liferea.local
5# Persistent global definitions
6include /etc/firejail/globals.local
7 7
8####################### 8noblacklist ~/.cache/liferea
9# profile for Liferea #
10#######################
11noblacklist ~/.config/liferea 9noblacklist ~/.config/liferea
12mkdir ~/.config/liferea
13whitelist ~/.config/liferea
14
15noblacklist ~/.local/share/liferea 10noblacklist ~/.local/share/liferea
16mkdir ~/.local/share/liferea
17whitelist ~/.local/share/liferea
18
19noblacklist ~/.cache/liferea
20mkdir ~/.cache/liferea
21whitelist ~/.cache/liferea
22 11
23include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
24include /etc/firejail/disable-devel.inc 13include /etc/firejail/disable-devel.inc
25include /etc/firejail/disable-passwdmgr.inc 14include /etc/firejail/disable-passwdmgr.inc
26include /etc/firejail/disable-programs.inc 15include /etc/firejail/disable-programs.inc
16
17mkdir ~/.cache/liferea
18mkdir ~/.config/liferea
19mkdir ~/.local/share/liferea
20whitelist ~/.cache/liferea
21whitelist ~/.config/liferea
22whitelist ~/.local/share/liferea
27include /etc/firejail/whitelist-common.inc 23include /etc/firejail/whitelist-common.inc
28 24
29caps.drop all 25caps.drop all
30#ipc-namespace
31netfilter 26netfilter
32#no3d 27# no3d
33nogroups 28nogroups
34nonewprivs 29nonewprivs
35noroot 30noroot
36#nosound 31# nosound
37novideo 32novideo
38protocol unix,inet,inet6 33protocol unix,inet,inet6
39seccomp 34seccomp
40shell none 35shell none
41 36
37disable-mnt
42private-dev 38private-dev
43private-tmp 39private-tmp
44disable-mnt
45 40
46noexec ${HOME} 41noexec ${HOME}
47noexec /tmp 42noexec /tmp