diff --git a/etc/min.profile b/etc/min.profile index c89df0a95..7f3aeab44 100644 --- a/etc/min.profile +++ b/etc/min.profile @@ -8,47 +8,8 @@ include globals.local noblacklist ${HOME}/.config/Min -noblacklist ${HOME}/.pki -noblacklist ${HOME}/.local/share/pki - -# noexec ${HOME} breaks DRM binaries. -?BROWSER_ALLOW_DRM: ignore noexec ${HOME} - -include disable-common.inc -include disable-devel.inc -include disable-exec.inc -include disable-interpreters.inc -include disable-programs.inc - -mkdir ${HOME}/.pki mkdir ${HOME}/.config/Min -mkdir ${HOME}/.local/share/pki -whitelist ${DOWNLOADS} -whitelist ${HOME}/.pki whitelist ${HOME}/.config/Min -whitelist ${HOME}/.local/share/pki -include whitelist-common.inc -include whitelist-var-common.inc -caps.drop all -netfilter -nodbus -nodvd -nogroups -nonewprivs -noroot -notv -nou2f -protocol unix,inet,inet6 -seccomp -shell none - -disable-mnt -# private-bin min -private-cache -private-dev -# private-etc below works fine on most distributions. There are some problems on CentOS. -private-etc alternatives,ca-certificates,ssl,machine-id,dconf,selinux,passwd,group,hostname,hosts,localtime,nsswitch.conf,resolv.conf,xdg,gtk-2.0,gtk-3.0,X11,pango,fonts,mime.types,mailcap,asound.conf,pulse,pki,crypto-policies,ld.so.cache -private-tmp - -# memory-deny-write-execute +# Redirect +include chromium-common.profile