aboutsummaryrefslogtreecommitdiffstats
path: root/etc/torbrowser-launcher.profile
diff options
context:
space:
mode:
Diffstat (limited to 'etc/torbrowser-launcher.profile')
-rw-r--r--etc/torbrowser-launcher.profile7
1 files changed, 6 insertions, 1 deletions
diff --git a/etc/torbrowser-launcher.profile b/etc/torbrowser-launcher.profile
index 9e3e0ef49..f175b6590 100644
--- a/etc/torbrowser-launcher.profile
+++ b/etc/torbrowser-launcher.profile
@@ -1,4 +1,5 @@
1# Firejail profile for torbrowser-launcher 1# Firejail profile for torbrowser-launcher
2# Description: Helps download and run the Tor Browser Bundle
2# This file is overwritten after every install/update 3# This file is overwritten after every install/update
3# Persistent local customizations 4# Persistent local customizations
4include /etc/firejail/torbrowser-launcher.local 5include /etc/firejail/torbrowser-launcher.local
@@ -19,9 +20,11 @@ include /etc/firejail/disable-devel.inc
19include /etc/firejail/disable-interpreters.inc 20include /etc/firejail/disable-interpreters.inc
20include /etc/firejail/disable-passwdmgr.inc 21include /etc/firejail/disable-passwdmgr.inc
21include /etc/firejail/disable-programs.inc 22include /etc/firejail/disable-programs.inc
23include /etc/firejail/disable-xdg.inc
22 24
23mkdir ${HOME}/.config/torbrowser 25mkdir ${HOME}/.config/torbrowser
24mkdir ${HOME}/.local/share/torbrowser 26mkdir ${HOME}/.local/share/torbrowser
27whitelist ${DOWNLOADS}
25whitelist ${HOME}/.config/torbrowser 28whitelist ${HOME}/.config/torbrowser
26whitelist ${HOME}/.local/share/torbrowser 29whitelist ${HOME}/.local/share/torbrowser
27include /etc/firejail/whitelist-common.inc 30include /etc/firejail/whitelist-common.inc
@@ -29,6 +32,7 @@ include /etc/firejail/whitelist-var-common.inc
29 32
30caps.drop all 33caps.drop all
31netfilter 34netfilter
35nodbus
32nodvd 36nodvd
33nogroups 37nogroups
34nonewprivs 38nonewprivs
@@ -36,8 +40,9 @@ noroot
36notv 40notv
37novideo 41novideo
38protocol unix,inet,inet6 42protocol unix,inet,inet6
39seccomp 43seccomp.drop @clock,@cpu-emulation,@debug,@module,@obsolete,@raw-io,@reboot,@resources,@swap,acct,add_key,bpf,fanotify_init,io_cancel,io_destroy,io_getevents,io_setup,io_submit,ioprio_set,kcmp,keyctl,mount,name_to_handle_at,nfsservctl,ni_syscall,open_by_handle_at,personality,pivot_root,process_vm_readv,ptrace,remap_file_pages,request_key,setdomainname,sethostname,syslog,umount,umount2,userfaultfd,vhangup,vmsplice
40shell none 44shell none
45# tracelog may cause issues, see github issue #1930
41tracelog 46tracelog
42 47
43disable-mnt 48disable-mnt