From 9c1a79dcb4cdc183133623bb54b254908861760b Mon Sep 17 00:00:00 2001 From: 0x7969 <1438229+0x7969@users.noreply.github.com> Date: Wed, 25 Mar 2020 12:22:24 +0000 Subject: Create ferdi.profile Exact copy of franz.profile, simply renamed franz to ferdi. --- etc/ferdi.profile | 46 ++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 46 insertions(+) create mode 100644 etc/ferdi.profile diff --git a/etc/ferdi.profile b/etc/ferdi.profile new file mode 100644 index 000000000..9b4c5f114 --- /dev/null +++ b/etc/ferdi.profile @@ -0,0 +1,46 @@ +# Firejail profile for ferdi +# This file is overwritten after every install/update +# Persistent local customizations +include ferdi.local +# Persistent global definitions +include globals.local + +ignore noexec /tmp + +noblacklist ${HOME}/.cache/Ferdi +noblacklist ${HOME}/.config/Ferdi +noblacklist ${HOME}/.pki +noblacklist ${HOME}/.local/share/pki + +include disable-common.inc +include disable-devel.inc +include disable-exec.inc +include disable-interpreters.inc +include disable-programs.inc + +mkdir ${HOME}/.cache/Ferdi +mkdir ${HOME}/.config/Ferdi +mkdir ${HOME}/.pki +mkdir ${HOME}/.local/share/pki +whitelist ${DOWNLOADS} +whitelist ${HOME}/.cache/Ferdi +whitelist ${HOME}/.config/Ferdi +whitelist ${HOME}/.pki +whitelist ${HOME}/.local/share/pki +include whitelist-common.inc + +caps.drop all +netfilter +nodvd +nogroups +nonewprivs +noroot +notv +nou2f +protocol unix,inet,inet6,netlink +seccomp !chroot +shell none + +disable-mnt +private-dev +private-tmp -- cgit v1.2.3-70-g09d2