# mupdf reader profile include /etc/firejail/disable-common.inc include /etc/firejail/disable-programs.inc include /etc/firejail/disable-devel.inc include /etc/firejail/disable-passwdmgr.inc caps.drop all nogroups nonewprivs noroot nosound protocol unix seccomp netfilter shell none tracelog private-bin mupdf private-tmp private-dev # mupdf will never write anything read-only ${HOME}