From 9e3ba319be6b9546d7e8f450ca419ee2f3f4040b Mon Sep 17 00:00:00 2001 From: Tad Date: Mon, 7 Aug 2017 01:22:08 -0400 Subject: Unify all profiles --- etc/gpg.profile | 19 +++++++++---------- 1 file changed, 9 insertions(+), 10 deletions(-) (limited to 'etc/gpg.profile') diff --git a/etc/gpg.profile b/etc/gpg.profile index 9ecc0a753..2d745b435 100644 --- a/etc/gpg.profile +++ b/etc/gpg.profile @@ -1,31 +1,30 @@ -# Persistent global definitions go here +# Firejail profile for gpg +# This file is overwritten after every install/update +# Persistent local customizations +include /etc/firejail/gpg.local +# Persistent global definitions include /etc/firejail/globals.local -# This file is overwritten during software install. -# Persistent customizations should go in a .local file. -include /etc/firejail/gpg.local +blacklist /tmp/.X11-unix -# gpg profile noblacklist ~/.gnupg include /etc/firejail/disable-common.inc -include /etc/firejail/disable-programs.inc include /etc/firejail/disable-devel.inc include /etc/firejail/disable-passwdmgr.inc +include /etc/firejail/disable-programs.inc caps.drop all +netfilter +no3d nogroups nonewprivs noroot nosound protocol unix,inet,inet6 seccomp -netfilter -no3d shell none tracelog -blacklist /tmp/.X11-unix - # private-bin gpg,gpg-agent private-dev -- cgit v1.2.3-54-g00ecf