Closed rusty-snake closed 3 years ago
Add caps.keep sys_admin,sys_chroot to electron.profile and remove the following. Additional add #include chromium-common-hardened.inc with a note.
caps.keep sys_admin,sys_chroot
#include chromium-common-hardened.inc
caps.drop all nonewprivs noroot protocol unix,inet,inet6,netlink seccomp
include whitelist-common.inc
include disable-devel.inc
include disable-exec.inc
include disable-interpreters.inc
include disable-xdg.inc
shell none
private-bin electron[0-9],electron[0-9][0-9]
nou2f
novideo
private-tmp
include whitelist-var-common.inc
include whitelist-usr-share-common.inc
include whitelist-runuser-common.inc
disable-mnt
private-cache
private-dev
include globals.local
$ grep -l "include electron.profile" /etc/firejail/*.profile /etc/firejail/beaker.profile /etc/firejail/freetube.profile /etc/firejail/jitsi-meet-desktop.profile /etc/firejail/nuclear.profile /etc/firejail/riot-web.profile /etc/firejail/rocketchat.profile /etc/firejail/teams-for-linux.profile /etc/firejail/teams.profile /etc/firejail/twitch.profile /etc/firejail/whalebird.profile /etc/firejail/wire-desktop.profile /etc/firejail/youtubemusic-nativefier.profile /etc/firejail/youtube.profile /etc/firejail/ytmdesktop.profile
Needs update:
Very nice idea :+1:, love it.
Add
caps.keep sys_admin,sys_chroot
to electron.profile and remove the following. Additional add#include chromium-common-hardened.inc
with a note.include whitelist-common.inc
to electron.profileinclude disable-devel.inc
include disable-exec.inc
include disable-interpreters.inc
include disable-xdg.inc
shell none
private-bin electron[0-9],electron[0-9][0-9]
~nou2f
novideo
private-tmp
include whitelist-var-common.inc
include whitelist-usr-share-common.inc
include whitelist-runuser-common.inc
disable-mnt
private-cache
private-dev
include globals.local
Needs update: