aboutsummaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
Diffstat (limited to 'etc')
-rw-r--r--etc/gnome-builder.profile25
-rw-r--r--etc/viewnior.profile3
2 files changed, 27 insertions, 1 deletions
diff --git a/etc/gnome-builder.profile b/etc/gnome-builder.profile
new file mode 100644
index 000000000..a5a48e97a
--- /dev/null
+++ b/etc/gnome-builder.profile
@@ -0,0 +1,25 @@
1# Firejail profile for gnome-builder
2# This file is overwritten after every install/update
3# Persistent local customizations
4include /etc/firejail/gnome-builder.local
5# Persistent global definitions
6include /etc/firejail/globals.local
7
8include /etc/firejail/disable-common.inc
9include /etc/firejail/disable-passwdmgr.inc
10include /etc/firejail/disable-programs.inc
11
12caps.drop all
13ipc-namespace
14netfilter
15nodvd
16nogroups
17nonewprivs
18noroot
19notv
20novideo
21protocol unix,inet,inet6
22seccomp
23shell none
24
25private-dev
diff --git a/etc/viewnior.profile b/etc/viewnior.profile
index 4df71f728..39bf3f7ce 100644
--- a/etc/viewnior.profile
+++ b/etc/viewnior.profile
@@ -37,6 +37,7 @@ private-dev
37private-etc fonts 37private-etc fonts
38private-tmp 38private-tmp
39 39
40memory-deny-write-execute 40# memory-deny-write-executes breaks on Arch - see issue #1808
41#memory-deny-write-execute
41noexec ${HOME} 42noexec ${HOME}
42noexec /tmp 43noexec /tmp