summaryrefslogtreecommitdiff
path: root/profiles
diff options
context:
space:
mode:
Diffstat (limited to 'profiles')
-rw-r--r--profiles/hearts-of-iron-iv.profile29
-rw-r--r--profiles/rtorrent.local24
2 files changed, 53 insertions, 0 deletions
diff --git a/profiles/hearts-of-iron-iv.profile b/profiles/hearts-of-iron-iv.profile
new file mode 100644
index 0000000..6749b14
--- /dev/null
+++ b/profiles/hearts-of-iron-iv.profile
@@ -0,0 +1,29 @@
+# This file is overwritten after every install/update
+# Persistent local customizations
+include hearts-of-iron-iv.local
+# Persistent global definitions
+include globals.local
+
+noblacklist ${HOME}/games/Hearts of Iron IV
+noblacklist ${HOME}/.local/share/Paradox Interactive
+noblacklist ${HOME}/.local/share/Paradox Interactive/Hearts of Iron IV
+
+whitelist ${HOME}/games/Hearts of Iron IV
+read-only ${HOME}/games/Hearts of Iron IV
+mkdir ${HOME}/.local/share/Paradox Interactive
+mkdir ${HOME}/.local/share/Paradox Interactive/Hearts of Iron IV
+whitelist ${HOME}/.local/share/Paradox Interactive
+read-only ${HOME}/.local/share/Paradox Interactive
+whitelist ${HOME}/.local/share/Paradox Interactive/Hearts of Iron IV
+read-write ${HOME}/.local/share/Paradox Interactive/Hearts of Iron IV
+
+# HoI4 requires ptrace to function
+seccomp !ptrace
+
+private-etc asound.conf,group,localtime,machine-id,passwd,pulse
+
+ignore memory-deny-write-execute
+
+ignore noexec ${HOME}
+
+include generic-game.inc
diff --git a/profiles/rtorrent.local b/profiles/rtorrent.local
new file mode 100644
index 0000000..5bbc634
--- /dev/null
+++ b/profiles/rtorrent.local
@@ -0,0 +1,24 @@
+noblacklist ${HOME}/rtorrent
+noblacklist ${HOME}/.rtorrent.rc
+whitelist ${HOME}/rtorrent
+whitelist ${HOME}/.rtorrent.rc
+
+include disable-xdg.inc
+
+ipc-namespace
+no3d
+noautopulse
+nogroups
+tracelog
+
+disable-mnt
+private-bin rtorrent,mkdir,mv
+private-etc ca-certificates,machine-id,passwd,resolv.conf,ssl,xdg
+
+memory-deny-write-execute
+
+dbus-user none
+dbus-system none
+
+# # Use with hardened-malloc package
+env LD_PRELOAD=/usr/lib/libhardened_malloc.so