From b553272fac9b205bf5a3192b799a4d79e6fedcee Mon Sep 17 00:00:00 2001 From: Tad Date: Sat, 29 Jul 2017 10:08:56 -0400 Subject: Add a profile for arm --- etc/arm.profile | 42 ++++++++++++++++++++++++++++++++++++++++++ src/firecfg/firecfg.config | 1 + 2 files changed, 43 insertions(+) create mode 100644 etc/arm.profile diff --git a/etc/arm.profile b/etc/arm.profile new file mode 100644 index 000000000..3000c35d7 --- /dev/null +++ b/etc/arm.profile @@ -0,0 +1,42 @@ +# Persistent global definitions go here +include /etc/firejail/globals.local + +# This file is overwritten during software install. +# Persistent customizations should go in a .local file. +include /etc/firejail/arm.local + +# Firejail profile for arm + +noblacklist ${HOME}/.arm + +include /etc/firejail/disable-common.inc +include /etc/firejail/disable-devel.inc +include /etc/firejail/disable-passwdmgr.inc +include /etc/firejail/disable-programs.inc + +mkdir ${HOME}/.arm +whitelist ${HOME}/.arm +include /etc/firejail/whitelist-common.inc + +caps.drop all +ipc-namespace +netfilter +no3d +nogroups +nonewprivs +noroot +nosound +novideo +protocol unix,inet,inet6 +seccomp +shell none +tracelog + +disable-mnt +#private-bin arm,tor,sh,python2,python2.7,ps,lsof,ldconfig +private-dev +private-etc tor,passwd +private-tmp + +noexec ${HOME} +noexec /tmp diff --git a/src/firecfg/firecfg.config b/src/firecfg/firecfg.config index b3614bf64..eb611034f 100644 --- a/src/firecfg/firecfg.config +++ b/src/firecfg/firecfg.config @@ -9,6 +9,7 @@ amarok android-studio arduino ark +arm atom atom-beta atool -- cgit v1.2.3-70-g09d2