aboutsummaryrefslogtreecommitdiffstats
path: root/etc/profile-a-l/blobby.profile
diff options
context:
space:
mode:
Diffstat (limited to 'etc/profile-a-l/blobby.profile')
-rw-r--r--etc/profile-a-l/blobby.profile52
1 files changed, 52 insertions, 0 deletions
diff --git a/etc/profile-a-l/blobby.profile b/etc/profile-a-l/blobby.profile
new file mode 100644
index 000000000..ee2a73b54
--- /dev/null
+++ b/etc/profile-a-l/blobby.profile
@@ -0,0 +1,52 @@
1# Firejail profile for blobby
2# Persistent local customizations
3include blobby.local
4# Persistent global definitions
5include globals.local
6
7nodeny ${HOME}/.blobby
8
9include disable-common.inc
10include disable-devel.inc
11include disable-exec.inc
12include disable-interpreters.inc
13include disable-passwdmgr.inc
14include disable-programs.inc
15include disable-shell.inc
16include disable-xdg.inc
17
18mkdir ${HOME}/.blobby
19allow ${HOME}/.blobby
20include whitelist-common.inc
21allow /usr/share/blobby
22include whitelist-usr-share-common.inc
23include whitelist-var-common.inc
24
25apparmor
26caps.drop all
27ipc-namespace
28netfilter
29nodvd
30nogroups
31noinput
32nonewprivs
33noroot
34notv
35nou2f
36novideo
37protocol unix,inet,inet6,netlink
38seccomp
39shell none
40tracelog
41
42disable-mnt
43private-bin blobby
44private-dev
45private-etc alsa,alternatives,asound.conf,drirc,group,hosts,login.defs,machine-id,passwd,pulse
46private-lib
47private-tmp
48
49dbus-user none
50dbus-system none
51
52memory-deny-write-execute