aboutsummaryrefslogtreecommitdiffstats
path: root/etc/profile-a-l/gnome-recipes.profile
diff options
context:
space:
mode:
Diffstat (limited to 'etc/profile-a-l/gnome-recipes.profile')
-rw-r--r--etc/profile-a-l/gnome-recipes.profile52
1 files changed, 52 insertions, 0 deletions
diff --git a/etc/profile-a-l/gnome-recipes.profile b/etc/profile-a-l/gnome-recipes.profile
new file mode 100644
index 000000000..20c355371
--- /dev/null
+++ b/etc/profile-a-l/gnome-recipes.profile
@@ -0,0 +1,52 @@
1# Firejail profile for gnome-recipes
2# Description: Recipe application for GNOME
3# This file is overwritten after every install/update
4# Persistent local customizations
5include gnome-recipes.local
6# Persistent global definitions
7include globals.local
8
9
10noblacklist ${HOME}/.cache/gnome-recipes
11noblacklist ${HOME}/.local/share/gnome-recipes
12
13include disable-common.inc
14include disable-devel.inc
15include disable-exec.inc
16include disable-interpreters.inc
17include disable-passwdmgr.inc
18include disable-programs.inc
19
20mkdir ${HOME}/.cache/gnome-recipes
21mkdir ${HOME}/.local/share/gnome-recipes
22whitelist ${HOME}/.cache/gnome-recipes
23whitelist ${HOME}/.local/share/gnome-recipes
24whitelist /usr/share/gnome-recipes
25include whitelist-common.inc
26include whitelist-usr-share-common.inc
27include whitelist-var-common.inc
28
29apparmor
30caps.drop all
31ipc-namespace
32machine-id
33netfilter
34nodvd
35nogroups
36nonewprivs
37noroot
38nosound
39notv
40nou2f
41novideo
42protocol unix,inet,inet6
43seccomp
44shell none
45
46disable-mnt
47private-bin gnome-recipes,tar
48private-dev
49private-etc alternatives,ca-certificates,crypto-policies,fonts,pki,ssl
50private-lib gdk-pixbuf-2.0,gio,gvfs/libgvfscommon.so,libgconf-2.so.*,libgnutls.so.*,libjpeg.so.*,libp11-kit.so.*,libproxy.so.*,librsvg-2.so.*
51private-tmp
52