aboutsummaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
Diffstat (limited to 'etc')
-rw-r--r--etc/disable-programs.inc1
-rw-r--r--etc/minetest.profile39
2 files changed, 40 insertions, 0 deletions
diff --git a/etc/disable-programs.inc b/etc/disable-programs.inc
index 13ed3f212..7e44d582e 100644
--- a/etc/disable-programs.inc
+++ b/etc/disable-programs.inc
@@ -330,6 +330,7 @@ blacklist ${HOME}/.lv2
330blacklist ${HOME}/.mcabber 330blacklist ${HOME}/.mcabber
331blacklist ${HOME}/.mcabberrc 331blacklist ${HOME}/.mcabberrc
332blacklist ${HOME}/.mediathek3 332blacklist ${HOME}/.mediathek3
333blacklist ${HOME}/.minetest
333blacklist ${HOME}/.mozilla 334blacklist ${HOME}/.mozilla
334blacklist ${HOME}/.mpdconf 335blacklist ${HOME}/.mpdconf
335blacklist ${HOME}/.mplayer 336blacklist ${HOME}/.mplayer
diff --git a/etc/minetest.profile b/etc/minetest.profile
new file mode 100644
index 000000000..147328616
--- /dev/null
+++ b/etc/minetest.profile
@@ -0,0 +1,39 @@
1# Firejail profile for minetest
2# This file is overwritten after every install/update
3# Persistent local customizations
4include /etc/firejail/minetest.local
5# Persistent global definitions
6include /etc/firejail/globals.local
7
8noblacklist ${HOME}/.minetest
9
10include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-passwdmgr.inc
13include /etc/firejail/disable-programs.inc
14
15mkdir ${HOME}/.minetest
16whitelist ${HOME}/.minetest
17include /etc/firejail/whitelist-common.inc
18
19caps.drop all
20ipc-namespace
21netfilter
22nodvd
23nogroups
24nonewprivs
25noroot
26notv
27novideo
28protocol unix,inet,inet6
29seccomp
30shell none
31
32disable-mnt
33private-bin minetest
34private-dev
35private-etc asound.conf,ca-certificates,drirc,fonts,group,host.conf,hostname,hosts,ld.so.cache,ld.so.preload,localtime,nsswitch.conf,passwd,pulse,resolv.conf,ssl
36private-tmp
37
38noexec ${HOME}
39noexec /tmp