--- /dev/null
+quiet
+disable-mnt
+net none
+no3d
+noautopulse
+nodbus
+nodvd
+nogroups
+nonewprivs
+noroot
+nosound
+notv
+nou2f
+novideo
+shell none
+whitelist /home/sfr/bin
+whitelist /home/sfr/kernels/next/etc
+whitelist /home/sfr/kernels/next/tools
+whitelist /home/sfr/next
+read-only /home/sfr/bin
+read-only /home/sfr/kernels/next/etc
+read-only /home/sfr/kernels/next/tools
+x11 none
+private-dev
+#tracelog
fi
obdir="$bparent/old/$tree"
-cmd="/bin/sh"
+cmd="firejail --profile=$bin_dir/build.profile /bin/sh"
[ "$build_host" ] &&
cmd="ssh root@$build_host unshare -n su $(id -u -n)"