add parole.profile

This commit is contained in:
avoidr 2015-12-06 15:33:39 +01:00
parent bf768f5273
commit f332fe2614
3 changed files with 19 additions and 0 deletions

17
etc/parole.profile Normal file
View file

@ -0,0 +1,17 @@
# Profile for Parole, the default XFCE4 media player
include /etc/firejail/disable-mgmt.inc
include /etc/firejail/disable-secret.inc
include /etc/firejail/disable-common.inc
include /etc/firejail/disable-devel.inc
private-etc passwd,group,fonts
private-bin parole,dbus-launch
blacklist ${HOME}/.pki/nssdb
blacklist ${HOME}/.lastpass
blacklist ${HOME}/.keepassx
blacklist ${HOME}/.password-store
caps.drop all
seccomp
protocol unix,inet,inet6
netfilter
noroot
shell none