From 7140573b9269b04cc36f5a9bd34a861ed2feb380 Mon Sep 17 00:00:00 2001 From: glitsj16 Date: Tue, 18 Apr 2023 02:36:55 +0000 Subject: New profile: url-eater (#5780) * Create url-eater.profile * RELNOTES: add url-eater to 'new profiles' --- etc/profile-m-z/url-eater.profile | 58 +++++++++++++++++++++++++++++++++++++++ 1 file changed, 58 insertions(+) create mode 100644 etc/profile-m-z/url-eater.profile (limited to 'etc/profile-m-z/url-eater.profile') diff --git a/etc/profile-m-z/url-eater.profile b/etc/profile-m-z/url-eater.profile new file mode 100644 index 000000000..a894ff0f6 --- /dev/null +++ b/etc/profile-m-z/url-eater.profile @@ -0,0 +1,58 @@ +# Firejail profile for url-eater +# Description: Clean unnecessary parameters from URLs copied to clipboard +# This file is overwritten after every install/update +# Persistent local customizations +include url-eater.local +# Persistent global definitions +include globals.local + +include disable-common.inc +include disable-devel.inc +include disable-exec.inc +include disable-interpreters.inc +include disable-proc.inc +include disable-programs.inc +include disable-shell.inc +include disable-xdg.inc + +include whitelist-common.inc +include whitelist-run-common.inc +include whitelist-runuser-common.inc +include whitelist-usr-share-common.inc +include whitelist-var-common.inc + +apparmor +caps.drop all +ipc-namespace +machine-id +net none +no3d +nodvd +nogroups +noinput +nonewprivs +noprinters +noroot +nosound +notv +nou2f +novideo +protocol unix +seccomp +seccomp.block-secondary +tracelog + +disable-mnt +private-bin url-eater +private-cache +private-dev +private-etc url-eater.kdl +private-lib +#private-tmp # breaks on Arch + +dbus-user none +dbus-system none + +memory-deny-write-execute +read-only ${HOME} +restrict-namespaces -- cgit v1.2.3-54-g00ecf