aboutsummaryrefslogtreecommitdiffstats
path: root/etc/penguin-command.profile
diff options
context:
space:
mode:
Diffstat (limited to 'etc/penguin-command.profile')
-rw-r--r--etc/penguin-command.profile40
1 files changed, 40 insertions, 0 deletions
diff --git a/etc/penguin-command.profile b/etc/penguin-command.profile
new file mode 100644
index 000000000..33e0651d4
--- /dev/null
+++ b/etc/penguin-command.profile
@@ -0,0 +1,40 @@
1# Firejail profile for open-invaders
2# Description: Space Invaders clone
3# This file is overwritten after every install/update
4# Persistent local customizations
5include open-invaders.local
6# Persistent global definitions
7include globals.local
8
9noblacklist ${HOME}/.penguin-command
10
11include disable-common.inc
12include disable-devel.inc
13include disable-exec.inc
14include disable-interpreters.inc
15include disable-passwdmgr.inc
16include disable-programs.inc
17
18mkdir ${HOME}/.openinvaders
19whitelist ${HOME}/.openinvaders
20include whitelist-common.inc
21include whitelist-var-common.inc
22
23apparmor
24caps.drop all
25net none
26nodbus
27nodvd
28nogroups
29nonewprivs
30noroot
31notv
32nou2f
33novideo
34protocol unix,netlink
35seccomp
36shell none
37
38private-bin penguin-command
39private-dev
40private-tmp