From b553272fac9b205bf5a3192b799a4d79e6fedcee Mon Sep 17 00:00:00 2001 From: Tad Date: Sat, 29 Jul 2017 10:08:56 -0400 Subject: Add a profile for arm --- etc/arm.profile | 42 ++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 42 insertions(+) create mode 100644 etc/arm.profile (limited to 'etc') diff --git a/etc/arm.profile b/etc/arm.profile new file mode 100644 index 000000000..3000c35d7 --- /dev/null +++ b/etc/arm.profile @@ -0,0 +1,42 @@ +# Persistent global definitions go here +include /etc/firejail/globals.local + +# This file is overwritten during software install. +# Persistent customizations should go in a .local file. +include /etc/firejail/arm.local + +# Firejail profile for arm + +noblacklist ${HOME}/.arm + +include /etc/firejail/disable-common.inc +include /etc/firejail/disable-devel.inc +include /etc/firejail/disable-passwdmgr.inc +include /etc/firejail/disable-programs.inc + +mkdir ${HOME}/.arm +whitelist ${HOME}/.arm +include /etc/firejail/whitelist-common.inc + +caps.drop all +ipc-namespace +netfilter +no3d +nogroups +nonewprivs +noroot +nosound +novideo +protocol unix,inet,inet6 +seccomp +shell none +tracelog + +disable-mnt +#private-bin arm,tor,sh,python2,python2.7,ps,lsof,ldconfig +private-dev +private-etc tor,passwd +private-tmp + +noexec ${HOME} +noexec /tmp -- cgit v1.2.3-54-g00ecf