From 72f5e973273e8052ea18825a8b31e30c03c36038 Mon Sep 17 00:00:00 2001 From: Hans-Christoph Steiner Date: Thu, 27 Feb 2020 14:13:24 +0100 Subject: add xournal.profile --- etc/xournal.profile | 47 +++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 47 insertions(+) create mode 100644 etc/xournal.profile (limited to 'etc') diff --git a/etc/xournal.profile b/etc/xournal.profile new file mode 100644 index 000000000..fa5200ea3 --- /dev/null +++ b/etc/xournal.profile @@ -0,0 +1,47 @@ +# Firejail profile for xournal +# Description: Note taking and PDF editing +# This file is overwritten after every install/update +# Persistent local customizations +include xournal.local +# Persistent global definitions +include globals.local + +noblacklist ${DOCUMENTS} + +include disable-common.inc +include disable-devel.inc +include disable-exec.inc +include disable-interpreters.inc +include disable-passwdmgr.inc +include disable-programs.inc +include disable-xdg.inc + +whitelist /usr/share/xournal +whitelist /usr/share/poppler +include whitelist-usr-share-common.inc +include whitelist-var-common.inc + +caps.drop all +machine-id +net none +no3d +nodbus +nodvd +nogroups +nonewprivs +noroot +nosound +notv +nou2f +novideo +protocol unix +seccomp +shell none +tracelog + +private-bin xournal +private-cache +private-dev +private-etc alternatives,fonts,group,machine-id,passwd +# TODO should use private-lib +private-tmp -- cgit v1.2.3-54-g00ecf