aboutsummaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
Diffstat (limited to 'etc')
-rw-r--r--etc/disable-programs.inc1
-rw-r--r--etc/pavucontrol.profile50
2 files changed, 51 insertions, 0 deletions
diff --git a/etc/disable-programs.inc b/etc/disable-programs.inc
index abca8d8ec..10d8b0463 100644
--- a/etc/disable-programs.inc
+++ b/etc/disable-programs.inc
@@ -221,6 +221,7 @@ blacklist ${HOME}/.config/opera
221blacklist ${HOME}/.config/opera-beta 221blacklist ${HOME}/.config/opera-beta
222blacklist ${HOME}/.config/orage 222blacklist ${HOME}/.config/orage
223blacklist ${HOME}/.config/org.kde.gwenviewrc 223blacklist ${HOME}/.config/org.kde.gwenviewrc
224blacklist ${HOME}/.config/pavucontrol.ini
224blacklist ${HOME}/.config/pcmanfm 225blacklist ${HOME}/.config/pcmanfm
225blacklist ${HOME}/.config/pdfmod 226blacklist ${HOME}/.config/pdfmod
226blacklist ${HOME}/.config/Pinta 227blacklist ${HOME}/.config/Pinta
diff --git a/etc/pavucontrol.profile b/etc/pavucontrol.profile
new file mode 100644
index 000000000..5d0cf2238
--- /dev/null
+++ b/etc/pavucontrol.profile
@@ -0,0 +1,50 @@
1# Firejail profile for pavucontrol
2# Description: PulseAudio Volume Control
3# This file is overwritten after every install/update
4# Persistent local customizations
5include pavucontrol.local
6# Persistent global definitions
7include globals.local
8
9noblacklist ${HOME}/.config/pavucontrol.ini
10
11include disable-common.inc
12include disable-devel.inc
13include disable-interpreters.inc
14include disable-passwdmgr.inc
15include disable-programs.inc
16include disable-xdg.inc
17
18include whitelist-common.inc
19include whitelist-var-common.inc
20
21apparmor
22caps.drop all
23ipc-namespace
24machine-id
25net none
26no3d
27nodbus
28nodvd
29nogroups
30nonewprivs
31noroot
32# nosound
33notv
34nou2f
35novideo
36protocol unix
37seccomp
38shell none
39
40disable-mnt
41private-bin pavucontrol
42private-cache
43private-dev
44private-etc alternatives,asound.conf,fonts,pulse
45private-lib
46private-tmp
47
48memory-deny-write-execute
49noexec ${HOME}
50noexec /tmp