aboutsummaryrefslogtreecommitdiffstats
path: root/etc/unknown-horizons.profile
diff options
context:
space:
mode:
Diffstat (limited to 'etc/unknown-horizons.profile')
-rw-r--r--etc/unknown-horizons.profile39
1 files changed, 16 insertions, 23 deletions
diff --git a/etc/unknown-horizons.profile b/etc/unknown-horizons.profile
index c4e535070..fc24fc04d 100644
--- a/etc/unknown-horizons.profile
+++ b/etc/unknown-horizons.profile
@@ -1,40 +1,33 @@
1# Persistent global definitions go here 1# Firejail profile for unknown-horizons
2# This file is overwritten after every install/update
3# Persistent local customizations
4include /etc/firejail/unknown-horizons.local
5# Persistent global definitions
2include /etc/firejail/globals.local 6include /etc/firejail/globals.local
3 7
4# This file is overwritten during software install. 8noblacklist ~/.unknown-horizons
5# Persistent customizations should go in a .local file.
6include /etc/firejail/unknown-horizons.local
7 9
8################################ 10include /etc/firejail/disable-common.inc
9# Extreme Tux Racer profile 11include /etc/firejail/disable-passwdmgr.inc
10################################ 12include /etc/firejail/disable-programs.inc
11 13
12noblacklist ~/.unknown-horizons
13mkdir ~/.unknown-horizons 14mkdir ~/.unknown-horizons
14whitelist ~/.unknown-horizons 15whitelist ~/.unknown-horizons
15include /etc/firejail/whitelist-common.inc 16include /etc/firejail/whitelist-common.inc
16 17
17include /etc/firejail/disable-common.inc
18include /etc/firejail/disable-programs.inc
19include /etc/firejail/disable-passwdmgr.inc
20
21caps.drop all 18caps.drop all
19nogroups
22nonewprivs 20nonewprivs
23noroot 21noroot
24protocol unix,netlink,inet,inet6 22protocol unix,netlink,inet,inet6
25seccomp 23seccomp
26
27#
28# depending on your usage, you can enable some of the commands below:
29#
30nogroups
31shell none 24shell none
32#private-bin unknown-horizons 25
33# private-etc none 26# private-bin unknown-horizons
34private-dev 27private-dev
28# private-etc none
35private-tmp 29private-tmp
36# nosound
37
38
39
40 30
31# CLOBBERED COMMENTS
32# depending on your usage, you can enable some of the commands below:
33# nosound