summaryrefslogtreecommitdiff
path: root/profiles/kristall.profile
diff options
context:
space:
mode:
authorjc_gargma <jc_gargma@iserlohn-fortress.net>2021-06-23 01:14:34 -0700
committerjc_gargma <jc_gargma@iserlohn-fortress.net>2021-06-23 01:14:34 -0700
commitbc8d91400256b6d0739c50097f1564d1598310a4 (patch)
tree93554f7223fc03c4edef955a69ded013cb059278 /profiles/kristall.profile
parentAdd profiles for stellaris, cataclysm-bn, cataclysm-bn-tiles, amfora (diff)
downloadfirejail-profiles-bc8d91400256b6d0739c50097f1564d1598310a4.tar.xz
Add kristall profile
Update amfora profile
Diffstat (limited to 'profiles/kristall.profile')
-rw-r--r--profiles/kristall.profile59
1 files changed, 59 insertions, 0 deletions
diff --git a/profiles/kristall.profile b/profiles/kristall.profile
new file mode 100644
index 0000000..4e570b2
--- /dev/null
+++ b/profiles/kristall.profile
@@ -0,0 +1,59 @@
+# Firejail profile for kristall
+# This file is overwritten after every install/update
+# Persistent local customizations
+include kristall.local
+# Persistent global definitions
+include globals.local
+
+
+noblacklist ${HOME}/.cache/kristall
+noblacklist ${HOME}/.config/xqTechnologies
+#noblacklist ${HOME}/.local/share/kristall
+
+include /etc/firejail/disable-common.inc
+include /etc/firejail/disable-devel.inc
+include /etc/firejail/disable-interpreters.inc
+include /etc/firejail/disable-passwdmgr.inc
+include /etc/firejail/disable-programs.inc
+include /etc/firejail/disable-xdg.inc
+
+mkdir ${HOME}/.config/xqTechnologies
+#mkdir ${HOME}/.local/share/kristall
+
+whitelist ${DOWNLOADS}
+#whitelist ${HOME}/.cache/kristall
+whitelist ${HOME}/.config/xqTechnologies
+#whitelist ${HOME}/.local/share/kristall
+include /etc/firejail/whitelist-common.inc
+
+
+caps.drop all
+machine-id
+netfilter
+nodvd
+nogroups
+nonewprivs
+noroot
+notv
+nou2f
+novideo
+protocol unix,inet,inet6,netlink
+seccomp !name_to_handle_at
+shell none
+tracelog
+
+disable-mnt
+private-bin bash,kristall
+private-cache
+private-dev
+private-etc ca-certificates,fonts,machine-id,resolv.conf,ssl
+private-tmp
+
+dbus-user none
+dbus-system none
+
+noexec ${HOME}
+noexec /tmp
+
+# # Use with hardened-malloc package
+env LD_PRELOAD=/usr/lib/libhardened_malloc.so