signal-scli.profile (817B)
1 # Firejail profile for signal-desktop 2 # This file is overwritten after every install/update 3 # Persistent local customizations 4 #include signal-desktop.local 5 # Persistent global definitions 6 include globals.local 7 8 noblacklist ${HOME}/tmp 9 noblacklist ${HOME}/.local/share/signal-cli 10 noblacklist ${HOME}/code/dotfiles/lib/scli 11 12 include disable-common.inc 13 include disable-devel.inc 14 #include disable-interpreters.inc 15 include disable-programs.inc 16 include disable-passwdmgr.inc 17 18 #whitelist ${HOME}/tmp 19 #whitelist ${HOME}/.local/share/signal-cli 20 #whitelist ${HOME}/code/dotfiles/lib/scli 21 #include whitelist-common.inc 22 #include whitelist-var-common.inc 23 24 caps.drop all 25 netfilter 26 nodvd 27 nogroups 28 nonewprivs 29 noroot 30 notv 31 nou2f 32 protocol unix,inet,inet6,netlink 33 seccomp 34 shell none 35 36 disable-mnt 37 private-dev 38 private-tmp 39 40 #noexec ${HOME}