diff --git a/etc-fixes/0.9.52/atom.profile b/etc-fixes/0.9.52/atom.profile new file mode 100644 index 00000000000..87ffdced96a --- /dev/null +++ b/etc-fixes/0.9.52/atom.profile @@ -0,0 +1,31 @@ +# Firejail profile for atom +# This file is overwritten after every install/update +# Persistent local customizations +include /etc/firejail/atom.local +# Persistent global definitions +include /etc/firejail/globals.local + +# blacklist /run/user/*/bus + +noblacklist ${HOME}/.atom +noblacklist ${HOME}/.config/Atom + +include /etc/firejail/disable-common.inc +include /etc/firejail/disable-passwdmgr.inc +include /etc/firejail/disable-programs.inc + +caps.keep sys_admin,sys_chroot +# net none +netfilter +nodvd +nogroups +nosound +notv +novideo +shell none + +private-dev +private-tmp + +noexec ${HOME} +noexec /tmp diff --git a/etc-fixes/0.9.58/atom.profile b/etc-fixes/0.9.58/atom.profile new file mode 100644 index 00000000000..9bc35da5ac1 --- /dev/null +++ b/etc-fixes/0.9.58/atom.profile @@ -0,0 +1,36 @@ + +# Firejail profile for atom +# Description: A hackable text editor for the 21st Century +# This file is overwritten after every install/update +# Persistent local customizations +include atom.local +# Persistent global definitions +include globals.local + +noblacklist ${HOME}/.atom +noblacklist ${HOME}/.config/Atom +noblacklist ${HOME}/.cargo/config +noblacklist ${HOME}/.cargo/registry + +include disable-common.inc +include disable-passwdmgr.inc +include disable-programs.inc + +caps.keep sys_admin,sys_chroot +# net none +netfilter +nodbus +nodvd +nogroups +nosound +notv +nou2f +novideo +shell none + +private-cache +private-dev +private-tmp + +noexec ${HOME} +noexec /tmp diff --git a/etc-fixes/0.9.60/atom.profile b/etc-fixes/0.9.60/atom.profile new file mode 100644 index 00000000000..c8929127b6e --- /dev/null +++ b/etc-fixes/0.9.60/atom.profile @@ -0,0 +1,37 @@ +# Firejail profile for atom +# Description: A hackable text editor for the 21st Century +# This file is overwritten after every install/update +# Persistent local customizations +include atom.local +# Persistent global definitions +include globals.local + +noblacklist ${HOME}/.atom +noblacklist ${HOME}/.config/Atom +noblacklist ${HOME}/.config/git +noblacklist ${HOME}/.cargo/config +noblacklist ${HOME}/.cargo/registry +noblacklist ${HOME}/.gitconfig +noblacklist ${HOME}/.git-credentials +noblacklist ${HOME}/.pythonrc.py + +include disable-common.inc +include disable-exec.inc +include disable-passwdmgr.inc +include disable-programs.inc + +caps.keep sys_admin,sys_chroot +# net none +netfilter +nodbus +nodvd +nogroups +nosound +notv +nou2f +novideo +shell none + +private-cache +private-dev +private-tmp