From 9e3ba319be6b9546d7e8f450ca419ee2f3f4040b Mon Sep 17 00:00:00 2001 From: Tad Date: Mon, 7 Aug 2017 01:22:08 -0400 Subject: Unify all profiles --- etc/tracker.profile | 25 ++++++++++++------------- 1 file changed, 12 insertions(+), 13 deletions(-) (limited to 'etc/tracker.profile') diff --git a/etc/tracker.profile b/etc/tracker.profile index b87bebf43..98040133c 100644 --- a/etc/tracker.profile +++ b/etc/tracker.profile @@ -1,34 +1,33 @@ -# Persistent global definitions go here -include /etc/firejail/globals.local - -# This file is overwritten during software install. -# Persistent customizations should go in a .local file. +# Firejail profile for tracker +# This file is overwritten after every install/update +# Persistent local customizations include /etc/firejail/tracker.local +# Persistent global definitions +include /etc/firejail/globals.local -# tracker profile - -# Tracker is started by systemd on most systems. Therefore it is not firejailed by default +blacklist /tmp/.X11-unix include /etc/firejail/disable-common.inc -include /etc/firejail/disable-programs.inc include /etc/firejail/disable-devel.inc include /etc/firejail/disable-passwdmgr.inc +include /etc/firejail/disable-programs.inc caps.drop all netfilter +no3d nogroups nonewprivs noroot nosound -no3d protocol unix seccomp shell none tracelog -blacklist /tmp/.X11-unix - # private-bin tracker -# private-tmp # private-dev # private-etc fonts +# private-tmp + +# CLOBBERED COMMENTS +# Tracker is started by systemd on most systems. Therefore it is not firejailed by default -- cgit v1.2.3-54-g00ecf