From 9e3ba319be6b9546d7e8f450ca419ee2f3f4040b Mon Sep 17 00:00:00 2001 From: Tad Date: Mon, 7 Aug 2017 01:22:08 -0400 Subject: Unify all profiles --- etc/open-invaders.profile | 41 +++++++++++++++++------------------------ 1 file changed, 17 insertions(+), 24 deletions(-) (limited to 'etc/open-invaders.profile') diff --git a/etc/open-invaders.profile b/etc/open-invaders.profile index f95b0f5a2..e4c87e5b9 100644 --- a/etc/open-invaders.profile +++ b/etc/open-invaders.profile @@ -1,41 +1,34 @@ -# Persistent global definitions go here +# Firejail profile for open-invaders +# This file is overwritten after every install/update +# Persistent local customizations +include /etc/firejail/open-invaders.local +# Persistent global definitions include /etc/firejail/globals.local -# This file is overwritten during software install. -# Persistent customizations should go in a .local file. -include /etc/firejail/open-invaders.local +noblacklist ~/.openinvaders -################################ -# open-invaders profile -################################ +include /etc/firejail/disable-common.inc +include /etc/firejail/disable-passwdmgr.inc +include /etc/firejail/disable-programs.inc -noblacklist ~/.openinvaders mkdir ~/.openinvaders whitelist ~/.openinvaders include /etc/firejail/whitelist-common.inc -include /etc/firejail/disable-common.inc -include /etc/firejail/disable-programs.inc -include /etc/firejail/disable-passwdmgr.inc - caps.drop all +net none +nogroups nonewprivs noroot protocol unix,netlink seccomp - -# -# depending on your usage, you can enable some of the commands below: -# -net none -nogroups shell none -#private-bin open-invaders -# private-etc none + +# private-bin open-invaders private-dev +# private-etc none private-tmp -# nosound - - - +# CLOBBERED COMMENTS +# depending on your usage, you can enable some of the commands below: +# nosound -- cgit v1.2.3-54-g00ecf