aboutsummaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
Diffstat (limited to 'etc')
-rw-r--r--etc/Screenshot.profile6
-rw-r--r--etc/disable-programs.inc1
-rw-r--r--etc/gnome-screenshot.profile47
3 files changed, 54 insertions, 0 deletions
diff --git a/etc/Screenshot.profile b/etc/Screenshot.profile
new file mode 100644
index 000000000..d4b083736
--- /dev/null
+++ b/etc/Screenshot.profile
@@ -0,0 +1,6 @@
1# Firejail profile for gnome-screenshot
2# This file is overwritten after every install/update
3
4# Temporary fix for https://github.com/netblue30/firejail/issues/2624
5# Redirect
6include gnome-screenshot.profile
diff --git a/etc/disable-programs.inc b/etc/disable-programs.inc
index db257c1b6..0786ba7d2 100644
--- a/etc/disable-programs.inc
+++ b/etc/disable-programs.inc
@@ -759,6 +759,7 @@ blacklist ${HOME}/.cache/gfeeds
759blacklist ${HOME}/.cache/gimp 759blacklist ${HOME}/.cache/gimp
760blacklist ${HOME}/.cache/gnome-builder 760blacklist ${HOME}/.cache/gnome-builder
761blacklist ${HOME}/.cache/gnome-recipes 761blacklist ${HOME}/.cache/gnome-recipes
762blacklist ${HOME}/.cache/gnome-screenshot
762blacklist ${HOME}/.cache/gnome-twitch 763blacklist ${HOME}/.cache/gnome-twitch
763blacklist ${HOME}/.cache/godot 764blacklist ${HOME}/.cache/godot
764blacklist ${HOME}/.cache/google-chrome 765blacklist ${HOME}/.cache/google-chrome
diff --git a/etc/gnome-screenshot.profile b/etc/gnome-screenshot.profile
new file mode 100644
index 000000000..c00aefdb7
--- /dev/null
+++ b/etc/gnome-screenshot.profile
@@ -0,0 +1,47 @@
1# Firejail profile for gnome-screenshot
2# Description: GNOME screenshot tool
3# This file is overwritten after every install/update
4# Persistent local customizations
5include gnome-screenshot.local
6# Persistent global definitions
7include globals.local
8
9noblacklist ${PICTURES}
10noblacklist ${HOME}/.cache/gnome-screenshot
11
12include disable-common.inc
13include disable-devel.inc
14include disable-exec.inc
15include disable-interpreters.inc
16include disable-passwdmgr.inc
17include disable-programs.inc
18include disable-xdg.inc
19
20whitelist ${RUNUSER}/bus
21whitelist ${RUNUSER}/pulse
22whitelist ${RUNUSER}/gdm/Xauthority
23whitelist ${RUNUSER}/wayland-0
24include whitelist-usr-share-common.inc
25include whitelist-var-common.inc
26
27apparmor
28caps.drop all
29net none
30no3d
31nodvd
32nogroups
33nonewprivs
34noroot
35notv
36nou2f
37novideo
38protocol unix
39seccomp
40shell none
41tracelog
42
43disable-mnt
44private-bin gnome-screenshot
45private-dev
46private-etc dconf,fonts,gtk-3.0,localtime,machine-id
47private-tmp