From 161318dc2b32111150d88db4d5a39f46aa617ed7 Mon Sep 17 00:00:00 2001 From: glitsj16 Date: Tue, 19 Mar 2024 06:08:35 +0000 Subject: New profile: mimetype.profile (#6247) Description: Determines the file type. https://metacpan.org/release/File-MimeInfo https://archlinux.org/packages/extra/any/perl-file-mimeinfo/ --- etc/profile-m-z/mimetype.profile | 48 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 48 insertions(+) create mode 100644 etc/profile-m-z/mimetype.profile (limited to 'etc') diff --git a/etc/profile-m-z/mimetype.profile b/etc/profile-m-z/mimetype.profile new file mode 100644 index 000000000..9902da882 --- /dev/null +++ b/etc/profile-m-z/mimetype.profile @@ -0,0 +1,48 @@ +# Firejail profile for mimetype +# Description: Determines the file type +# This file is overwritten after every install/update +quiet +# Persistent local customizations +include mimetype.local +# Persistent global definitions +include globals.local + +blacklist /tmp/.X11-unix +blacklist ${RUNUSER}/wayland-* + +include disable-exec.inc +include disable-proc.inc + +apparmor +caps.drop all +ipc-namespace +machine-id +net none +no3d +nodvd +nogroups +noinput +nonewprivs +noprinters +noroot +nosound +notv +nou2f +novideo +protocol unix +seccomp +seccomp.block-secondary +tracelog +x11 none + +private-dev + +dbus-user none +dbus-system none + +memory-deny-write-execute +read-only ${HOME} +read-only ${RUNUSER} +read-only /tmp + +restrict-namespaces -- cgit v1.2.3-54-g00ecf