From b0b62e28dc9e14b8d693c8d24bc2722e6a8e56ef Mon Sep 17 00:00:00 2001 From: Jean Lucas Date: Wed, 31 Jul 2019 03:23:02 -0400 Subject: Add Zulip profile --- etc/zulip.profile | 46 ++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 46 insertions(+) create mode 100644 etc/zulip.profile diff --git a/etc/zulip.profile b/etc/zulip.profile new file mode 100644 index 000000000..d3f9a2240 --- /dev/null +++ b/etc/zulip.profile @@ -0,0 +1,46 @@ +# Firejail profile for zulip +# Description: Real-time team chat based on the email threading model +# This file is overwritten after every install/update +# Persistent local customizations +include zulip.local +# Persistent global definitions +include globals.local + +ignore noexec /tmp + +noblacklist ${HOME}/.config/Zulip + +include disable-common.inc +include disable-devel.inc +include disable-exec.inc +include disable-interpreters.inc +include disable-passwdmgr.inc +include disable-programs.inc + +mkdir ${HOME}/.config/Zulip +whitelist ${HOME}/.config/Zulip +whitelist ${DOWNLOADS} +include whitelist-common.inc +include whitelist-var-common.inc + +apparmor +caps.drop all +netfilter +no3d +nodvd +nogroups +nonewprivs +noroot +notv +nou2f +novideo +protocol unix,inet,inet6 +seccomp +shell none + +disable-mnt +private-bin locale,zulip +private-cache +private-dev +private-etc asound.conf,fonts,machine-id +private-tmp -- cgit v1.2.3-54-g00ecf