From 9e3ba319be6b9546d7e8f450ca419ee2f3f4040b Mon Sep 17 00:00:00 2001 From: Tad Date: Mon, 7 Aug 2017 01:22:08 -0400 Subject: Unify all profiles --- etc/franz.profile | 32 ++++++++++++++++---------------- 1 file changed, 16 insertions(+), 16 deletions(-) (limited to 'etc/franz.profile') diff --git a/etc/franz.profile b/etc/franz.profile index c5e019947..486326fe0 100644 --- a/etc/franz.profile +++ b/etc/franz.profile @@ -1,30 +1,28 @@ -# Persistent global definitions go here -include /etc/firejail/globals.local - -# This file is overwritten during software install. -# Persistent customizations should go in a .local file. +# Firejail profile for franz +# This file is overwritten after every install/update +# Persistent local customizations include /etc/firejail/franz.local +# Persistent global definitions +include /etc/firejail/globals.local -# Franz profile -noblacklist ~/.config/Franz noblacklist ~/.cache/Franz +noblacklist ~/.config/Franz noblacklist ~/.pki + include /etc/firejail/disable-common.inc -include /etc/firejail/disable-programs.inc include /etc/firejail/disable-devel.inc +include /etc/firejail/disable-programs.inc -whitelist ${DOWNLOADS} -mkdir ~/.config/Franz -whitelist ~/.config/Franz mkdir ~/.cache/Franz -whitelist ~/.cache/Franz +mkdir ~/.config/Franz mkdir ~/.pki +whitelist ${DOWNLOADS} +whitelist ~/.cache/Franz +whitelist ~/.config/Franz whitelist ~/.pki - include /etc/firejail/whitelist-common.inc caps.drop all -#ipc-namespace netfilter nogroups nonewprivs @@ -32,11 +30,13 @@ noroot protocol unix,inet,inet6,netlink seccomp shell none -#tracelog +disable-mnt private-dev private-tmp -disable-mnt noexec ${HOME} noexec /tmp + +# CLOBBERED COMMENTS +# tracelog -- cgit v1.2.3-54-g00ecf