aboutsummaryrefslogtreecommitdiffstats
path: root/etc/profile-a-l/chromium-common.profile
diff options
context:
space:
mode:
Diffstat (limited to 'etc/profile-a-l/chromium-common.profile')
-rw-r--r--etc/profile-a-l/chromium-common.profile13
1 files changed, 12 insertions, 1 deletions
diff --git a/etc/profile-a-l/chromium-common.profile b/etc/profile-a-l/chromium-common.profile
index 899400d25..6a9cf99b0 100644
--- a/etc/profile-a-l/chromium-common.profile
+++ b/etc/profile-a-l/chromium-common.profile
@@ -16,16 +16,25 @@ include disable-common.inc
16include disable-devel.inc 16include disable-devel.inc
17include disable-exec.inc 17include disable-exec.inc
18include disable-interpreters.inc 18include disable-interpreters.inc
19# include disable-passwdmgr.inc
19include disable-programs.inc 20include disable-programs.inc
21include disable-xdg.inc
20 22
21mkdir ${HOME}/.pki 23mkdir ${HOME}/.pki
22mkdir ${HOME}/.local/share/pki 24mkdir ${HOME}/.local/share/pki
23whitelist ${DOWNLOADS} 25whitelist ${DOWNLOADS}
24whitelist ${HOME}/.pki 26whitelist ${HOME}/.pki
25whitelist ${HOME}/.local/share/pki 27whitelist ${HOME}/.local/share/pki
28whitelist /usr/share/chromium
26include whitelist-common.inc 29include whitelist-common.inc
30include whitelist-runuser-common.inc
31include whitelist-usr-share-common.inc
27include whitelist-var-common.inc 32include whitelist-var-common.inc
28 33
34# Uncomment the next line (or add it to your chromium-common.local)
35# if your kernel allows unprivileged userns clone.
36#include chromium-common-hardened.inc
37
29apparmor 38apparmor
30caps.keep sys_admin,sys_chroot 39caps.keep sys_admin,sys_chroot
31netfilter 40netfilter
@@ -36,8 +45,10 @@ notv
36shell none 45shell none
37 46
38disable-mnt 47disable-mnt
48private-cache
39?BROWSER_DISABLE_U2F: private-dev 49?BROWSER_DISABLE_U2F: private-dev
40# private-tmp - problems with multiple browser sessions 50# problems with multiple browser sessions
51#private-tmp
41 52
42# prevents access to passwords saved in GNOME Keyring and KWallet, also breaks Gnome connector 53# prevents access to passwords saved in GNOME Keyring and KWallet, also breaks Gnome connector
43# dbus-user none 54# dbus-user none