aboutsummaryrefslogtreecommitdiffstats
path: root/etc/profile-a-l
diff options
context:
space:
mode:
Diffstat (limited to 'etc/profile-a-l')
-rw-r--r--etc/profile-a-l/dexios.profile63
1 files changed, 63 insertions, 0 deletions
diff --git a/etc/profile-a-l/dexios.profile b/etc/profile-a-l/dexios.profile
new file mode 100644
index 000000000..4dfccd685
--- /dev/null
+++ b/etc/profile-a-l/dexios.profile
@@ -0,0 +1,63 @@
1# Firejail profile for dexios
2# Description: CLI encryption tool
3quiet
4# This file is overwritten after every install/update
5# Persistent local customizations
6include dexios.local
7# Persistent global definitions
8include globals.local
9
10blacklist /tmp/.X11-unix
11blacklist /usr/libexec
12blacklist ${RUNUSER}
13
14include disable-common.inc
15include disable-devel.inc
16include disable-exec.inc
17include disable-interpreters.inc
18include disable-proc.inc
19include disable-programs.inc
20include disable-shell.inc
21include disable-xdg.inc
22
23whitelist ${DOWNLOADS}
24include whitelist-run-common.inc
25include whitelist-usr-share-common.inc
26include whitelist-var-common.inc
27
28apparmor
29caps.drop all
30ipc-namespace
31machine-id
32netfilter
33no3d
34nodvd
35nogroups
36noinput
37nonewprivs
38noprinters
39noroot
40nosound
41notv
42nou2f
43novideo
44seccomp.drop socket
45seccomp.block-secondary
46tracelog
47x11 none
48
49disable-mnt
50private-bin dexios
51private-cache
52private-dev
53private-etc
54private-lib
55private-tmp
56
57dbus-user none
58dbus-system none
59
60memory-deny-write-execute
61read-only ${HOME}
62read-write ${DOWNLOADS}
63restrict-namespaces