aboutsummaryrefslogtreecommitdiff
path: root/config.dot/firejail/ranger.profile.link
diff options
context:
space:
mode:
Diffstat (limited to 'config.dot/firejail/ranger.profile.link')
-rw-r--r--config.dot/firejail/ranger.profile.link33
1 files changed, 7 insertions, 26 deletions
diff --git a/config.dot/firejail/ranger.profile.link b/config.dot/firejail/ranger.profile.link
index 738bc3c..78ab30c 100644
--- a/config.dot/firejail/ranger.profile.link
+++ b/config.dot/firejail/ranger.profile.link
@@ -1,10 +1,11 @@
# ranger file manager profile
quiet
-noblacklist /usr/bin/perl
-#noblacklist /usr/bin/cpan*
-noblacklist /usr/share/perl*
-noblacklist /usr/lib/perl*
-noblacklist ${HOME}/.config/ranger
+
+# include the default profile
+include /etc/firejail/ranger.profile
+
+# allow write operations in non-default folders
+include whitelist-common.local
# from fbreader ebook reader profile
noblacklist ${HOME}/.FBReader
@@ -13,28 +14,8 @@ noblacklist ${HOME}/.FBReader
noblacklist ~/.config/zathura
noblacklist ~/.local/share/zathura
-# from gimp profile
+## from gimp profile
noblacklist ${HOME}/.gimp*
# from mpv profile
noblacklist ${HOME}/.config/mpv
-
-include /etc/firejail/disable-common.inc
-include /etc/firejail/disable-programs.inc
-include /etc/firejail/disable-devel.inc
-include /etc/firejail/disable-passwdmgr.inc
-
-caps.drop all
-netfilter
-net none
-nonewprivs
-noroot
-nogroups
-protocol unix
-seccomp
-
-# We need sound support to play media files
-#nosound
-
-private-tmp
-private-dev