summaryrefslogtreecommitdiff
path: root/.config/firejail/newsboat.profile
diff options
context:
space:
mode:
authorSam Chudnick <sam@chudnick.com>2022-06-16 21:27:02 -0400
committerSam Chudnick <sam@chudnick.com>2022-06-16 21:27:02 -0400
commit3c1666bd4791467e11b53b843e062b2122c59b33 (patch)
tree7a9dabc4199e4cb31e27440a1dd796bdabc8f6a5 /.config/firejail/newsboat.profile
parentc090ce58a2fd1edfbdefd756e18bf2f2296d8a4a (diff)
Added customizations for several firejail profiles
Configured local customizations for several firejail profiles. Whitelisted non-standard paths needed for firefox and newsboat. Blacklisted non-standard password manager paths.
Diffstat (limited to '.config/firejail/newsboat.profile')
-rw-r--r--.config/firejail/newsboat.profile54
1 files changed, 54 insertions, 0 deletions
diff --git a/.config/firejail/newsboat.profile b/.config/firejail/newsboat.profile
new file mode 100644
index 0000000..0de5928
--- /dev/null
+++ b/.config/firejail/newsboat.profile
@@ -0,0 +1,54 @@
1# Firejail profile for Newsboat
2# Description: RSS program
3# This file is overwritten after every install/update
4# Persistent local customizations
5include newsboat.local
6# Persistent global definitions
7include globals.local
8
9noblacklist ${HOME}/.newsboat
10
11include disable-common.inc
12include disable-devel.inc
13include disable-exec.inc
14include disable-interpreters.inc
15include disable-passwdmgr.inc
16include disable-programs.inc
17include disable-xdg.inc
18
19whitelist ${HOME}/.config/newsboat
20whitelist ${HOME}/.local/share/newsboat
21whitelist ${HOME}/repos/website/rss.xml
22
23include whitelist-common.inc
24include whitelist-runuser-common.inc
25include whitelist-var-common.inc
26
27caps.drop all
28ipc-namespace
29netfilter
30no3d
31nodvd
32nogroups
33nonewprivs
34noroot
35notv
36nou2f
37novideo
38protocol inet,inet6
39seccomp
40shell none
41
42disable-mnt
43private-bin gzip,lynx,newsboat,sh
44private-cache
45private-dev
46private-etc alternatives,ca-certificates,crypto-policies,lynx.cfg,lynx.lss,pki,resolv.conf,ssl,terminfo
47private-tmp
48
49dbus-user none
50dbus-system none
51
52memory-deny-write-execute
53
54quiet