From 255b087f869bd8ecb8135c3452a84b262fdfb7ef Mon Sep 17 00:00:00 2001 From: PizzaDude Date: Mon, 14 Aug 2017 12:31:12 -0400 Subject: firejail profile for torbrowser-launcher --- etc/torbrowser-launcher.profile | 37 +++++++++++++++++++++++++++++++++++++ 1 file changed, 37 insertions(+) create mode 100644 etc/torbrowser-launcher.profile diff --git a/etc/torbrowser-launcher.profile b/etc/torbrowser-launcher.profile new file mode 100644 index 000000000..8ae0c56c1 --- /dev/null +++ b/etc/torbrowser-launcher.profile @@ -0,0 +1,37 @@ +# Firejail profile for torbrowser-launcher +# This file is overwritten after every install/update +# Persistent local customizations +include /etc/firejail/torbrowser-launcher.local +# Persistent global definitions +include /etc/firejail/globals.local + + +noblacklist ~/.config/torbrowser +whitelist ~/.config/torbrowser +noblacklist ~/.local/share/torbrowser +whitelist ~/.local/share/torbrowser + + +include /etc/firejail/disable-common.inc +include /etc/firejail/disable-devel.inc +include /etc/firejail/disable-passwdmgr.inc +include /etc/firejail/disable-programs.inc + + +caps.drop all +netfilter +nodvd +nogroups +nonewprivs +noroot +notv +protocol unix,inet,inet6 +seccomp +shell none +tracelog + +private-bin torbrowser-launcher,python2.7,python,bash,dash,sh,grep,tail,env,gpg,id,readlink,dirname,test,mkdir,ln,sed,cp,rm,getconf +private-dev +private-etc fonts +private-tmp + -- cgit v1.2.3-70-g09d2