From 96f2c32c0bcda0eb4267b7af98da577acb0876d5 Mon Sep 17 00:00:00 2001 From: netblue30 Date: Sun, 28 Oct 2018 14:52:47 -0400 Subject: aisleriot profile --- etc/sol.profile | 48 ++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 48 insertions(+) create mode 100644 etc/sol.profile diff --git a/etc/sol.profile b/etc/sol.profile new file mode 100644 index 000000000..c0ad3c739 --- /dev/null +++ b/etc/sol.profile @@ -0,0 +1,48 @@ +# Firejail profile for default +# This file is overwritten after every install/update +# Persistent local customizations +include sol.local +# Persistent global definitions +include globals.local + +include disable-common.inc +include disable-devel.inc +include disable-interpreters.inc +include disable-passwdmgr.inc +include disable-programs.inc +include disable-xdg.inc + +# all necessary files in $HOME are in whitelist-common.inc +include whitelist-common.inc +include whitelist-var-common.inc +net none + +caps.drop all +# ipc-namespace +# netfilter +# no3d +# nodbus +nodvd +nogroups +nonewprivs +noroot +# nosound +notv +nou2f +novideo +protocol unix +seccomp +shell none + +disable-mnt +# private +private-bin sol +# private-cache +private-dev +# private-etc none +# private-lib +private-tmp + +memory-deny-write-execute +noexec ${HOME} +noexec /tmp -- cgit v1.2.3-54-g00ecf