From ca09dafadcf00cf419e23fc13adf9874fc905fb5 Mon Sep 17 00:00:00 2001 From: netblue30 Date: Sat, 30 Jun 2018 07:48:24 -0400 Subject: merged Amend Wire profiles #1998 form @flacks --- etc/wire-desktop.profile | 40 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 40 insertions(+) create mode 100644 etc/wire-desktop.profile (limited to 'etc/wire-desktop.profile') diff --git a/etc/wire-desktop.profile b/etc/wire-desktop.profile new file mode 100644 index 000000000..74d44efe3 --- /dev/null +++ b/etc/wire-desktop.profile @@ -0,0 +1,40 @@ +# Firejail profile for wire-desktop +# This file is overwritten after every install/update +# Persistent local customizations +include /etc/firejail/wire-desktop.local +# Persistent global definitions +include /etc/firejail/globals.local + +noblacklist ${HOME}/.config/Wire + +include /etc/firejail/disable-common.inc +include /etc/firejail/disable-devel.inc +include /etc/firejail/disable-interpreters.inc +include /etc/firejail/disable-passwdmgr.inc +include /etc/firejail/disable-programs.inc + +mkdir ${HOME}/.config/Wire +whitelist ${HOME}/.config/Wire +whitelist ${DOWNLOADS} + +include /etc/firejail/whitelist-common.inc + +caps.drop all +netfilter +nodvd +nogroups +nonewprivs +noroot +notv +protocol unix,inet,inet6,netlink +seccomp +shell none + +# Note: The current version of Wire is located in /opt/wire-desktop/wire-desktop, and therefore +# it is not in PATH. To use Wire with firejail, run "firejail /opt/wire-desktop/wire-desktop" + +private-bin wire-desktop +private-dev +private-etc fonts,machine-id +disable-mnt +private-tmp -- cgit v1.2.3-70-g09d2