aboutsummaryrefslogtreecommitdiffstats
path: root/etc/nautilus.profile
diff options
context:
space:
mode:
Diffstat (limited to 'etc/nautilus.profile')
-rw-r--r--etc/nautilus.profile20
1 files changed, 9 insertions, 11 deletions
diff --git a/etc/nautilus.profile b/etc/nautilus.profile
index 4f2f50d9f..2da8f32d7 100644
--- a/etc/nautilus.profile
+++ b/etc/nautilus.profile
@@ -1,25 +1,22 @@
1# Persistent global definitions go here 1# Firejail profile for nautilus
2include /etc/firejail/globals.local 2# This file is overwritten after every install/update
3 3# Persistent local customizations
4# This file is overwritten during software install.
5# Persistent customizations should go in a .local file.
6include /etc/firejail/nautilus.local 4include /etc/firejail/nautilus.local
7 5# Persistent global definitions
8# nautilus profile 6include /etc/firejail/globals.local
9 7
10# Nautilus is started by systemd on most systems. Therefore it is not firejailed by default. Since there 8# Nautilus is started by systemd on most systems. Therefore it is not firejailed by default. Since there
11# is already a nautilus process running on gnome desktops firejail will have no effect. 9# is already a nautilus process running on gnome desktops firejail will have no effect.
12 10
13noblacklist ~/.config/nautilus 11noblacklist ~/.config/nautilus
12noblacklist ~/.local/share/Trash
14noblacklist ~/.local/share/nautilus 13noblacklist ~/.local/share/nautilus
15noblacklist ~/.local/share/nautilus-python 14noblacklist ~/.local/share/nautilus-python
16noblacklist ~/.local/share/Trash
17 15
18include /etc/firejail/disable-common.inc 16include /etc/firejail/disable-common.inc
19# nautilus needs to be able to start arbitrary applications so we cannot blacklist their files
20#include /etc/firejail/disable-programs.inc
21include /etc/firejail/disable-devel.inc 17include /etc/firejail/disable-devel.inc
22include /etc/firejail/disable-passwdmgr.inc 18include /etc/firejail/disable-passwdmgr.inc
19# include /etc/firejail/disable-programs.inc
23 20
24caps.drop all 21caps.drop all
25netfilter 22netfilter
@@ -31,7 +28,8 @@ seccomp
31shell none 28shell none
32tracelog 29tracelog
33 30
31# nautilus needs to be able to start arbitrary applications so we cannot blacklist their files
34# private-bin nautilus 32# private-bin nautilus
35# private-tmp
36# private-dev 33# private-dev
37# private-etc fonts 34# private-etc fonts
35# private-tmp