diff options
Diffstat (limited to 'etc')
-rw-r--r-- | etc/disable-programs.inc | 2 | ||||
-rw-r--r-- | etc/pix.profile | 19 |
2 files changed, 21 insertions, 0 deletions
diff --git a/etc/disable-programs.inc b/etc/disable-programs.inc index a5b33c860..70deb2b0c 100644 --- a/etc/disable-programs.inc +++ b/etc/disable-programs.inc | |||
@@ -17,6 +17,7 @@ blacklist ${HOME}/.config/atril | |||
17 | blacklist ${HOME}/.config/xreader | 17 | blacklist ${HOME}/.config/xreader |
18 | blacklist ${HOME}/.config/xviewer | 18 | blacklist ${HOME}/.config/xviewer |
19 | blacklist ${HOME}/.config/libreoffice | 19 | blacklist ${HOME}/.config/libreoffice |
20 | blacklist ${HOME}/.config/pix | ||
20 | blacklist ${HOME}/.kde/share/apps/okular | 21 | blacklist ${HOME}/.kde/share/apps/okular |
21 | blacklist ${HOME}/.kde/share/config/okularrc | 22 | blacklist ${HOME}/.kde/share/config/okularrc |
22 | blacklist ${HOME}/.kde/share/config/okularpartrc | 23 | blacklist ${HOME}/.kde/share/config/okularpartrc |
@@ -120,3 +121,4 @@ blacklist ${HOME}/.local/share/0ad | |||
120 | blacklist ${HOME}/.local/share/xplayer | 121 | blacklist ${HOME}/.local/share/xplayer |
121 | blacklist ${HOME}/.local/share/totem | 122 | blacklist ${HOME}/.local/share/totem |
122 | blacklist ${HOME}/.local/share/psi+ | 123 | blacklist ${HOME}/.local/share/psi+ |
124 | blacklist ${HOME}/.local/share/pix | ||
diff --git a/etc/pix.profile b/etc/pix.profile new file mode 100644 index 000000000..ccf0c0381 --- /dev/null +++ b/etc/pix.profile | |||
@@ -0,0 +1,19 @@ | |||
1 | # gthumb profile | ||
2 | noblacklist ${HOME}/.config/pix | ||
3 | noblacklist ${HOME}/.local/share/pix | ||
4 | |||
5 | include /etc/firejail/disable-common.inc | ||
6 | include /etc/firejail/disable-programs.inc | ||
7 | include /etc/firejail/disable-devel.inc | ||
8 | include /etc/firejail/disable-passwdmgr.inc | ||
9 | |||
10 | caps.drop all | ||
11 | netfilter | ||
12 | nonewprivs | ||
13 | noroot | ||
14 | protocol unix,inet,inet6 | ||
15 | seccomp | ||
16 | |||
17 | shell none | ||
18 | private-bin pix | ||
19 | whitelist /tmp/.X11-unix | ||