aboutsummaryrefslogtreecommitdiffstats
path: root/etc/yandex-browser.profile
diff options
context:
space:
mode:
Diffstat (limited to 'etc/yandex-browser.profile')
-rw-r--r--etc/yandex-browser.profile52
1 files changed, 33 insertions, 19 deletions
diff --git a/etc/yandex-browser.profile b/etc/yandex-browser.profile
index b1a26c3ea..bfb7b9d87 100644
--- a/etc/yandex-browser.profile
+++ b/etc/yandex-browser.profile
@@ -1,28 +1,42 @@
1# Chromium browser profile 1# Firejail profile for yandex-browser
2noblacklist ~/.config/yandex-browser-beta 2# This file is overwritten after every install/update
3# Persistent local customizations
4include /etc/firejail/yandex-browser.local
5# Persistent global definitions
6include /etc/firejail/globals.local
7
8noblacklist ~/.cache/yandex-browser
3noblacklist ~/.cache/yandex-browser-beta 9noblacklist ~/.cache/yandex-browser-beta
10noblacklist ~/.config/yandex-browser
11noblacklist ~/.config/yandex-browser-beta
12noblacklist ~/.pki
13
4include /etc/firejail/disable-common.inc 14include /etc/firejail/disable-common.inc
15include /etc/firejail/disable-devel.inc
5include /etc/firejail/disable-programs.inc 16include /etc/firejail/disable-programs.inc
6 17
7# chromium is distributed with a perl script on Arch 18mkdir ~/.cache/yandex-browser
8# include /etc/firejail/disable-devel.inc
9#
10
11netfilter
12
13whitelist ${DOWNLOADS}
14mkdir ~/.config/yandex-browser-beta
15whitelist ~/.config/yandex-browser-beta
16mkdir ~/.cache/yandex-browser-beta 19mkdir ~/.cache/yandex-browser-beta
17whitelist ~/.cache/yandex-browser-beta 20mkdir ~/.config/yandex-browser
21mkdir ~/.config/yandex-browser-beta
18mkdir ~/.pki 22mkdir ~/.pki
23whitelist ${DOWNLOADS}
24whitelist ~/.cache/yandex-browser
25whitelist ~/.cache/yandex-browser-beta
26whitelist ~/.config/yandex-browser
27whitelist ~/.config/yandex-browser-beta
19whitelist ~/.pki 28whitelist ~/.pki
29include /etc/firejail/whitelist-common.inc
30
31caps.keep sys_chroot,sys_admin
32netfilter
33nodvd
34nogroups
35notv
36shell none
20 37
21# lastpass, keepassx 38private-dev
22whitelist ~/.keepassx 39# private-tmp - problems with multiple browser sessions
23whitelist ~/.config/keepassx
24whitelist ~/keepassx.kdbx
25whitelist ~/.lastpass
26whitelist ~/.config/lastpass
27 40
28include /etc/firejail/whitelist-common.inc 41noexec ${HOME}
42noexec /tmp