aboutsummaryrefslogtreecommitdiffstats
path: root/etc/wire-desktop.profile
diff options
context:
space:
mode:
Diffstat (limited to 'etc/wire-desktop.profile')
-rw-r--r--etc/wire-desktop.profile40
1 files changed, 40 insertions, 0 deletions
diff --git a/etc/wire-desktop.profile b/etc/wire-desktop.profile
new file mode 100644
index 000000000..74d44efe3
--- /dev/null
+++ b/etc/wire-desktop.profile
@@ -0,0 +1,40 @@
1# Firejail profile for wire-desktop
2# This file is overwritten after every install/update
3# Persistent local customizations
4include /etc/firejail/wire-desktop.local
5# Persistent global definitions
6include /etc/firejail/globals.local
7
8noblacklist ${HOME}/.config/Wire
9
10include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-interpreters.inc
13include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc
15
16mkdir ${HOME}/.config/Wire
17whitelist ${HOME}/.config/Wire
18whitelist ${DOWNLOADS}
19
20include /etc/firejail/whitelist-common.inc
21
22caps.drop all
23netfilter
24nodvd
25nogroups
26nonewprivs
27noroot
28notv
29protocol unix,inet,inet6,netlink
30seccomp
31shell none
32
33# Note: The current version of Wire is located in /opt/wire-desktop/wire-desktop, and therefore
34# it is not in PATH. To use Wire with firejail, run "firejail /opt/wire-desktop/wire-desktop"
35
36private-bin wire-desktop
37private-dev
38private-etc fonts,machine-id
39disable-mnt
40private-tmp