From c9f3b36f73b2bcf4609f61ea53a77bc83e4e854e Mon Sep 17 00:00:00 2001 From: valoq Date: Tue, 18 Oct 2016 16:58:02 +0200 Subject: added profiles --- etc/eog.profile | 23 +++++++++++++++++++++++ etc/evolution.profile | 25 +++++++++++++++++++++++++ 2 files changed, 48 insertions(+) create mode 100644 etc/eog.profile create mode 100644 etc/evolution.profile diff --git a/etc/eog.profile b/etc/eog.profile new file mode 100644 index 000000000..32b54a042 --- /dev/null +++ b/etc/eog.profile @@ -0,0 +1,23 @@ +# eog (gnome image viewer) profile + +noblacklist ~/.config/eog + +include /etc/firejail/disable-common.inc +include /etc/firejail/disable-programs.inc +include /etc/firejail/disable-devel.inc +include /etc/firejail/disable-passwdmgr.inc + +caps.drop all +netfilter +nonewprivs +noroot +nogroups +protocol unix +seccomp +shell none + +private-bin eog +private-dev +private-etc fonts +private-tmp + diff --git a/etc/evolution.profile b/etc/evolution.profile new file mode 100644 index 000000000..cf581643d --- /dev/null +++ b/etc/evolution.profile @@ -0,0 +1,25 @@ +# evolution profile + +noblacklist ~/.config/evolution +noblacklist ~/.local/share/evolution +noblacklist ~/.cache/evolution +noblacklist ~/.pki +noblacklist ~/.pki/nssdb +noblacklist ~/.gnupg + +include /etc/firejail/disable-common.inc +include /etc/firejail/disable-programs.inc +include /etc/firejail/disable-devel.inc +include /etc/firejail/disable-passwdmgr.inc + +caps.drop all +netfilter +nonewprivs +noroot +nogroups +protocol unix,inet,inet6 +seccomp +shell none + +private-dev +private-tmp -- cgit v1.2.3-54-g00ecf