summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLibravatar glitsj16 <glitsj16@users.noreply.github.com>2019-10-18 22:22:06 +0000
committerLibravatar GitHub <noreply@github.com>2019-10-18 22:22:06 +0000
commit9f90e7924db093cbfbe974eb69618f9d8b54a078 (patch)
tree4d7293dc4dc335a5799badc65c44b7a7e958467a
parentMerge pull request #3004 from rusty-snake/fix-2995 (diff)
downloadfirejail-9f90e7924db093cbfbe974eb69618f9d8b54a078.tar.gz
firejail-9f90e7924db093cbfbe974eb69618f9d8b54a078.tar.zst
firejail-9f90e7924db093cbfbe974eb69618f9d8b54a078.zip
Add wusc to more profiles (#3005)
* Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add qt/qt4 support to wusc * Add wusc to more profiles * Add wusc to more profiles * Update enchant.profile * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add wusc to more profiles * Add /usr/share/ca-certs to wusc * Add ca-certs to wusc * Add ca-certs to wusc * Add ca-certs to wusc * Add ca-certs to wusc * Add ca-certs to wusc * Add ca-certs to wusc * Add ca-certs to wusc * Add ca-certs to wusc * Add ca-certs to wusc * Add ca-certs to wusc * Add ca-certs to wusc * Add ca-certs to wusc * Add ca-certs to wusc * Add ca-certs to wusc * Add ca-certs to wusc * Add ca-certs to wusc * Add ca-certs to wusc * Add ca-certs to wusc * Add ca-certs to wusc * Add ca-certs to wusc * Add ca-certs to wusc * Add ca-certs to wusc * Add ca-certs to wusc * Add ca-certs to wusc * Add ca-certs to wusc * Add ca-certs to wusc * Add ca-certs to wusc * Add ca-certs to wusc
-rw-r--r--etc/QMediathekView.profile2
-rw-r--r--etc/arch-audit.profile3
-rw-r--r--etc/aria2c.profile2
-rw-r--r--etc/artha.profile3
-rw-r--r--etc/assogiate.profile1
-rw-r--r--etc/checkbashisms.profile1
-rw-r--r--etc/claws-mail.profile3
-rw-r--r--etc/clawsker.profile1
-rw-r--r--etc/clipit.profile1
-rw-r--r--etc/conky.profile2
-rw-r--r--etc/curl.profile2
-rw-r--r--etc/d-feet.profile2
-rw-r--r--etc/dconf.profile1
-rw-r--r--etc/devhelp.profile2
-rw-r--r--etc/devilspie.profile1
-rw-r--r--etc/devilspie2.profile1
-rw-r--r--etc/dig.profile1
-rw-r--r--etc/display.profile1
-rw-r--r--etc/dnscrypt-proxy.profile3
-rw-r--r--etc/easystroke.profile2
-rw-r--r--etc/enchant.profile2
-rw-r--r--etc/exfalso.profile1
-rw-r--r--etc/exiftool.profile2
-rw-r--r--etc/ffmpeg.profile3
-rw-r--r--etc/font-manager.profile2
-rw-r--r--etc/gconf.profile3
-rw-r--r--etc/geekbench.profile1
-rw-r--r--etc/git.profile6
-rw-r--r--etc/gjs.profile2
-rw-r--r--etc/gnome-calculator.profile1
-rw-r--r--etc/gnome-keyring.profile3
-rw-r--r--etc/gnome-nettool.profile2
-rw-r--r--etc/gnome-recipes.profile2
-rw-r--r--etc/gnome-schedule.profile2
-rw-r--r--etc/gnome-system-log.profile1
-rw-r--r--etc/gpg-agent.profile4
-rw-r--r--etc/gpg.profile5
-rw-r--r--etc/gpicview.profile2
-rw-r--r--etc/img2txt.profile3
-rw-r--r--etc/inkscape.profile2
-rw-r--r--etc/liferea.profile2
-rw-r--r--etc/mediainfo.profile2
-rw-r--r--etc/mpDris2.profile1
-rw-r--r--etc/mpd.profile2
-rw-r--r--etc/mpg123.profile1
-rw-r--r--etc/mplayer.profile1
-rw-r--r--etc/nano.profile3
-rw-r--r--etc/netactview.profile2
-rw-r--r--etc/nitroshare.profile2
-rw-r--r--etc/ocenaudio.profile2
-rw-r--r--etc/patch.profile1
-rw-r--r--etc/pavucontrol.profile3
-rw-r--r--etc/pdftotext.profile2
-rw-r--r--etc/pidgin.profile1
-rw-r--r--etc/ping.profile2
-rw-r--r--etc/regextester.profile3
-rw-r--r--etc/seahorse.profile5
-rw-r--r--etc/shellcheck.profile2
-rw-r--r--etc/simple-scan.profile3
-rw-r--r--etc/simplescreenrecorder.profile3
-rw-r--r--etc/smplayer.profile2
-rw-r--r--etc/smtube.profile3
-rw-r--r--etc/soundconverter.profile2
-rw-r--r--etc/spectre-meltdown-checker.profile1
-rw-r--r--etc/ssh-agent.profile2
-rw-r--r--etc/ssh.profile2
-rw-r--r--etc/subdownloader.profile2
-rw-r--r--etc/sysprof.profile2
-rw-r--r--etc/transgui.profile1
-rw-r--r--etc/transmission-common.profile1
-rw-r--r--etc/transmission-gtk.profile2
-rw-r--r--etc/tshark.profile2
-rw-r--r--etc/uget-gtk.profile1
-rw-r--r--etc/unbound.profile2
-rw-r--r--etc/uudeview.profile2
-rw-r--r--etc/viewnior.profile2
-rw-r--r--etc/weechat.profile2
-rw-r--r--etc/whitelist-usr-share-common.inc3
-rw-r--r--etc/whois.profile1
-rw-r--r--etc/wireshark.profile2
-rw-r--r--etc/xfce4-mixer.profile3
81 files changed, 165 insertions, 2 deletions
diff --git a/etc/QMediathekView.profile b/etc/QMediathekView.profile
index eb21349a9..b9ddd80c4 100644
--- a/etc/QMediathekView.profile
+++ b/etc/QMediathekView.profile
@@ -27,6 +27,8 @@ include disable-passwdmgr.inc
27include disable-programs.inc 27include disable-programs.inc
28include disable-xdg.inc 28include disable-xdg.inc
29 29
30whitelist /usr/share/qtchooser
31include whitelist-usr-share-common.inc
30include whitelist-var-common.inc 32include whitelist-var-common.inc
31 33
32caps.drop all 34caps.drop all
diff --git a/etc/arch-audit.profile b/etc/arch-audit.profile
index 2f08fa169..0a87ec297 100644
--- a/etc/arch-audit.profile
+++ b/etc/arch-audit.profile
@@ -17,6 +17,9 @@ include disable-passwdmgr.inc
17include disable-programs.inc 17include disable-programs.inc
18include disable-xdg.inc 18include disable-xdg.inc
19 19
20whitelist /usr/share/arch-audit
21include whitelist-usr-share-common.inc
22
20apparmor 23apparmor
21caps.drop all 24caps.drop all
22ipc-namespace 25ipc-namespace
diff --git a/etc/aria2c.profile b/etc/aria2c.profile
index 910e52a82..72e577d56 100644
--- a/etc/aria2c.profile
+++ b/etc/aria2c.profile
@@ -15,6 +15,8 @@ include disable-interpreters.inc
15include disable-passwdmgr.inc 15include disable-passwdmgr.inc
16include disable-programs.inc 16include disable-programs.inc
17 17
18include whitelist-usr-share-common.inc
19
18caps.drop all 20caps.drop all
19ipc-namespace 21ipc-namespace
20netfilter 22netfilter
diff --git a/etc/artha.profile b/etc/artha.profile
index f886921cb..f1d30a415 100644
--- a/etc/artha.profile
+++ b/etc/artha.profile
@@ -20,7 +20,10 @@ mkdir ${HOME}/.config/artha.conf
20mkdir ${HOME}/.config/enchant 20mkdir ${HOME}/.config/enchant
21whitelist ${HOME}/.config/artha.conf 21whitelist ${HOME}/.config/artha.conf
22whitelist ${HOME}/.config/enchant 22whitelist ${HOME}/.config/enchant
23whitelist /usr/share/artha
24whitelist /usr/share/wordnet
23include whitelist-common.inc 25include whitelist-common.inc
26include whitelist-usr-share-common.inc
24include whitelist-var-common.inc 27include whitelist-var-common.inc
25 28
26apparmor 29apparmor
diff --git a/etc/assogiate.profile b/etc/assogiate.profile
index 074d82955..542b3da8d 100644
--- a/etc/assogiate.profile
+++ b/etc/assogiate.profile
@@ -18,6 +18,7 @@ include disable-xdg.inc
18 18
19whitelist ${PICTURES} 19whitelist ${PICTURES}
20include whitelist-common.inc 20include whitelist-common.inc
21include whitelist-usr-share-common.inc
21include whitelist-var-common.inc 22include whitelist-var-common.inc
22 23
23apparmor 24apparmor
diff --git a/etc/checkbashisms.profile b/etc/checkbashisms.profile
index 7b2d344e5..0abe87511 100644
--- a/etc/checkbashisms.profile
+++ b/etc/checkbashisms.profile
@@ -20,6 +20,7 @@ include disable-passwdmgr.inc
20include disable-programs.inc 20include disable-programs.inc
21include disable-xdg.inc 21include disable-xdg.inc
22 22
23include whitelist-usr-share-common.inc
23include whitelist-var-common.inc 24include whitelist-var-common.inc
24 25
25apparmor 26apparmor
diff --git a/etc/claws-mail.profile b/etc/claws-mail.profile
index f0656385f..f68500b8e 100644
--- a/etc/claws-mail.profile
+++ b/etc/claws-mail.profile
@@ -16,6 +16,9 @@ include disable-interpreters.inc
16include disable-passwdmgr.inc 16include disable-passwdmgr.inc
17include disable-programs.inc 17include disable-programs.inc
18 18
19whitelist /usr/share/doc
20include whitelist-usr-share-common.inc
21
19caps.drop all 22caps.drop all
20netfilter 23netfilter
21no3d 24no3d
diff --git a/etc/clawsker.profile b/etc/clawsker.profile
index f8c05a55b..eb05ed347 100644
--- a/etc/clawsker.profile
+++ b/etc/clawsker.profile
@@ -21,6 +21,7 @@ include disable-programs.inc
21mkdir ${HOME}/.claws-mail 21mkdir ${HOME}/.claws-mail
22whitelist ${HOME}/.claws-mail 22whitelist ${HOME}/.claws-mail
23include whitelist-common.inc 23include whitelist-common.inc
24include whitelist-usr-share-common.inc
24 25
25apparmor 26apparmor
26caps.drop all 27caps.drop all
diff --git a/etc/clipit.profile b/etc/clipit.profile
index 44cda0665..66b5fc859 100644
--- a/etc/clipit.profile
+++ b/etc/clipit.profile
@@ -22,6 +22,7 @@ mkdir ${HOME}/.local/share/clipit
22whitelist ${HOME}/.config/clipit 22whitelist ${HOME}/.config/clipit
23whitelist ${HOME}/.local/share/clipit 23whitelist ${HOME}/.local/share/clipit
24include whitelist-common.inc 24include whitelist-common.inc
25include whitelist-usr-share-common.inc
25include whitelist-var-common.inc 26include whitelist-var-common.inc
26 27
27apparmor 28apparmor
diff --git a/etc/conky.profile b/etc/conky.profile
index d5949ecfd..78f92720f 100644
--- a/etc/conky.profile
+++ b/etc/conky.profile
@@ -16,6 +16,8 @@ include disable-passwdmgr.inc
16include disable-programs.inc 16include disable-programs.inc
17include disable-xdg.inc 17include disable-xdg.inc
18 18
19include whitelist-usr-share-common.inc
20
19caps.drop all 21caps.drop all
20ipc-namespace 22ipc-namespace
21netfilter 23netfilter
diff --git a/etc/curl.profile b/etc/curl.profile
index d44ce0b96..2624e5545 100644
--- a/etc/curl.profile
+++ b/etc/curl.profile
@@ -14,6 +14,8 @@ include disable-exec.inc
14include disable-passwdmgr.inc 14include disable-passwdmgr.inc
15include disable-programs.inc 15include disable-programs.inc
16 16
17include whitelist-usr-share-common.inc
18
17caps.drop all 19caps.drop all
18ipc-namespace 20ipc-namespace
19machine-id 21machine-id
diff --git a/etc/d-feet.profile b/etc/d-feet.profile
index e06769601..897bf5f5d 100644
--- a/etc/d-feet.profile
+++ b/etc/d-feet.profile
@@ -22,7 +22,9 @@ include disable-xdg.inc
22 22
23mkdir ${HOME}/.config/d-feet 23mkdir ${HOME}/.config/d-feet
24whitelist ${HOME}/.config/d-feet 24whitelist ${HOME}/.config/d-feet
25whitelist /usr/share/d-feet
25include whitelist-common.inc 26include whitelist-common.inc
27include whitelist-usr-share-common.inc
26include whitelist-var-common.inc 28include whitelist-var-common.inc
27 29
28apparmor 30apparmor
diff --git a/etc/dconf.profile b/etc/dconf.profile
index 81763bd94..ebb362fb6 100644
--- a/etc/dconf.profile
+++ b/etc/dconf.profile
@@ -17,6 +17,7 @@ include disable-xdg.inc
17whitelist ${HOME}/.local/share/glib-2.0 17whitelist ${HOME}/.local/share/glib-2.0
18# dconf paths are whitelisted by the following 18# dconf paths are whitelisted by the following
19include whitelist-common.inc 19include whitelist-common.inc
20include whitelist-usr-share-common.inc
20 21
21apparmor 22apparmor
22caps.drop all 23caps.drop all
diff --git a/etc/devhelp.profile b/etc/devhelp.profile
index 02b752b5f..5c1935835 100644
--- a/etc/devhelp.profile
+++ b/etc/devhelp.profile
@@ -15,7 +15,9 @@ include disable-passwdmgr.inc
15include disable-programs.inc 15include disable-programs.inc
16include disable-xdg.inc 16include disable-xdg.inc
17 17
18whitelist /usr/share/devhelp
18include whitelist-common.inc 19include whitelist-common.inc
20include whitelist-usr-share-common.inc
19 21
20apparmor 22apparmor
21caps.drop all 23caps.drop all
diff --git a/etc/devilspie.profile b/etc/devilspie.profile
index ca617983d..ad891ffaf 100644
--- a/etc/devilspie.profile
+++ b/etc/devilspie.profile
@@ -19,6 +19,7 @@ include disable-xdg.inc
19mkdir ${HOME}/.devilspie 19mkdir ${HOME}/.devilspie
20whitelist ${HOME}/.devilspie 20whitelist ${HOME}/.devilspie
21include whitelist-common.inc 21include whitelist-common.inc
22include whitelist-usr-share-common.inc
22include whitelist-var-common.inc 23include whitelist-var-common.inc
23 24
24apparmor 25apparmor
diff --git a/etc/devilspie2.profile b/etc/devilspie2.profile
index 74b0dc939..f2bacda9a 100644
--- a/etc/devilspie2.profile
+++ b/etc/devilspie2.profile
@@ -22,6 +22,7 @@ include disable-xdg.inc
22mkdir ${HOME}/.config/devilspie2 22mkdir ${HOME}/.config/devilspie2
23whitelist ${HOME}/.config/devilspie2 23whitelist ${HOME}/.config/devilspie2
24include whitelist-common.inc 24include whitelist-common.inc
25include whitelist-usr-share-common.inc
25include whitelist-var-common.inc 26include whitelist-var-common.inc
26 27
27apparmor 28apparmor
diff --git a/etc/dig.profile b/etc/dig.profile
index 611cbf026..e609105b4 100644
--- a/etc/dig.profile
+++ b/etc/dig.profile
@@ -20,6 +20,7 @@ include disable-xdg.inc
20#mkfile ${HOME}/.digrc -- see #903 20#mkfile ${HOME}/.digrc -- see #903
21whitelist ${HOME}/.digrc 21whitelist ${HOME}/.digrc
22include whitelist-common.inc 22include whitelist-common.inc
23include whitelist-usr-share-common.inc
23include whitelist-var-common.inc 24include whitelist-var-common.inc
24 25
25caps.drop all 26caps.drop all
diff --git a/etc/display.profile b/etc/display.profile
index 0b9d685e8..9e976c11a 100644
--- a/etc/display.profile
+++ b/etc/display.profile
@@ -19,6 +19,7 @@ include disable-passwdmgr.inc
19include disable-programs.inc 19include disable-programs.inc
20include disable-xdg.inc 20include disable-xdg.inc
21 21
22include whitelist-usr-share-common.inc
22include whitelist-var-common.inc 23include whitelist-var-common.inc
23 24
24caps.drop all 25caps.drop all
diff --git a/etc/dnscrypt-proxy.profile b/etc/dnscrypt-proxy.profile
index bba94e3cb..d0430d5ca 100644
--- a/etc/dnscrypt-proxy.profile
+++ b/etc/dnscrypt-proxy.profile
@@ -18,6 +18,9 @@ include disable-passwdmgr.inc
18include disable-programs.inc 18include disable-programs.inc
19include disable-xdg.inc 19include disable-xdg.inc
20 20
21whitelist /usr/share/dnscrypt-proxy
22include whitelist-usr-share-common.inc
23
21caps.keep ipc_lock,net_bind_service,setgid,setuid,sys_chroot 24caps.keep ipc_lock,net_bind_service,setgid,setuid,sys_chroot
22ipc-namespace 25ipc-namespace
23machine-id 26machine-id
diff --git a/etc/easystroke.profile b/etc/easystroke.profile
index 42529d302..623a4cadc 100644
--- a/etc/easystroke.profile
+++ b/etc/easystroke.profile
@@ -16,6 +16,8 @@ include disable-passwdmgr.inc
16include disable-programs.inc 16include disable-programs.inc
17include disable-xdg.inc 17include disable-xdg.inc
18 18
19include whitelist-usr-share-common.inc
20
19apparmor 21apparmor
20caps.drop all 22caps.drop all
21machine-id 23machine-id
diff --git a/etc/enchant.profile b/etc/enchant.profile
index d30fb8232..d276cec84 100644
--- a/etc/enchant.profile
+++ b/etc/enchant.profile
@@ -16,6 +16,8 @@ include disable-passwdmgr.inc
16include disable-programs.inc 16include disable-programs.inc
17include disable-xdg.inc 17include disable-xdg.inc
18 18
19include whitelist-usr-share-common.inc
20
19apparmor 21apparmor
20caps.drop all 22caps.drop all
21ipc-namespace 23ipc-namespace
diff --git a/etc/exfalso.profile b/etc/exfalso.profile
index b5eda059f..7d91f2854 100644
--- a/etc/exfalso.profile
+++ b/etc/exfalso.profile
@@ -27,6 +27,7 @@ include disable-xdg.inc
27mkdir ${HOME}/.quodlibet 27mkdir ${HOME}/.quodlibet
28whitelist ${HOME}/.quodlibet 28whitelist ${HOME}/.quodlibet
29include whitelist-common.inc 29include whitelist-common.inc
30include whitelist-usr-share-common.inc
30include whitelist-var-common.inc 31include whitelist-var-common.inc
31 32
32caps.drop all 33caps.drop all
diff --git a/etc/exiftool.profile b/etc/exiftool.profile
index e76a4ca4c..565ae8fe9 100644
--- a/etc/exiftool.profile
+++ b/etc/exiftool.profile
@@ -16,6 +16,8 @@ include disable-interpreters.inc
16include disable-passwdmgr.inc 16include disable-passwdmgr.inc
17include disable-programs.inc 17include disable-programs.inc
18 18
19include whitelist-usr-share-common.inc
20
19apparmor 21apparmor
20caps.drop all 22caps.drop all
21ipc-namespace 23ipc-namespace
diff --git a/etc/ffmpeg.profile b/etc/ffmpeg.profile
index 0771bf6a5..19d9a7644 100644
--- a/etc/ffmpeg.profile
+++ b/etc/ffmpeg.profile
@@ -18,6 +18,9 @@ include disable-passwdmgr.inc
18include disable-programs.inc 18include disable-programs.inc
19include disable-xdg.inc 19include disable-xdg.inc
20 20
21whitelist /usr/share/ffmpeg
22whitelist /usr/share/qtchooser
23include whitelist-usr-share-common.inc
21include whitelist-var-common.inc 24include whitelist-var-common.inc
22 25
23apparmor 26apparmor
diff --git a/etc/font-manager.profile b/etc/font-manager.profile
index 1699e5cfc..064df38d7 100644
--- a/etc/font-manager.profile
+++ b/etc/font-manager.profile
@@ -25,7 +25,9 @@ mkdir ${HOME}/.cache/font-manager
25mkdir ${HOME}/.config/font-manager 25mkdir ${HOME}/.config/font-manager
26whitelist ${HOME}/.cache/font-manager 26whitelist ${HOME}/.cache/font-manager
27whitelist ${HOME}/.config/font-manager 27whitelist ${HOME}/.config/font-manager
28whitelist /usr/share/font-manager
28include whitelist-common.inc 29include whitelist-common.inc
30include whitelist-usr-share-common.inc
29 31
30apparmor 32apparmor
31caps.drop all 33caps.drop all
diff --git a/etc/gconf.profile b/etc/gconf.profile
index 4baf8c957..2f930235c 100644
--- a/etc/gconf.profile
+++ b/etc/gconf.profile
@@ -22,7 +22,10 @@ include disable-xdg.inc
22 22
23mkdir ${HOME}/.config/gconf 23mkdir ${HOME}/.config/gconf
24whitelist ${HOME}/.config/gconf 24whitelist ${HOME}/.config/gconf
25whitelist /usr/share/GConf
26whitelist /usr/share/gconf
25include whitelist-common.inc 27include whitelist-common.inc
28include whitelist-usr-share-common.inc
26 29
27apparmor 30apparmor
28caps.drop all 31caps.drop all
diff --git a/etc/geekbench.profile b/etc/geekbench.profile
index 8d7dbd48e..bf9d27788 100644
--- a/etc/geekbench.profile
+++ b/etc/geekbench.profile
@@ -14,6 +14,7 @@ include disable-passwdmgr.inc
14include disable-programs.inc 14include disable-programs.inc
15include disable-xdg.inc 15include disable-xdg.inc
16 16
17include whitelist-usr-share-common.inc
17include whitelist-var-common.inc 18include whitelist-var-common.inc
18 19
19apparmor 20apparmor
diff --git a/etc/git.profile b/etc/git.profile
index 8b1c81ca4..f290f8ffe 100644
--- a/etc/git.profile
+++ b/etc/git.profile
@@ -26,6 +26,12 @@ include disable-exec.inc
26include disable-passwdmgr.inc 26include disable-passwdmgr.inc
27include disable-programs.inc 27include disable-programs.inc
28 28
29whitelist /usr/share/git
30whitelist /usr/share/git-core
31whitelist /usr/share/gitgui
32whitelist /usr/share/gitweb
33include whitelist-usr-share-common.inc
34
29apparmor 35apparmor
30caps.drop all 36caps.drop all
31ipc-namespace 37ipc-namespace
diff --git a/etc/gjs.profile b/etc/gjs.profile
index 17b0aa5cf..871020ae0 100644
--- a/etc/gjs.profile
+++ b/etc/gjs.profile
@@ -19,6 +19,8 @@ include disable-interpreters.inc
19include disable-passwdmgr.inc 19include disable-passwdmgr.inc
20include disable-programs.inc 20include disable-programs.inc
21 21
22include whitelist-usr-share-common.inc
23
22caps.drop all 24caps.drop all
23netfilter 25netfilter
24nodvd 26nodvd
diff --git a/etc/gnome-calculator.profile b/etc/gnome-calculator.profile
index c9ad4831f..6709a331e 100644
--- a/etc/gnome-calculator.profile
+++ b/etc/gnome-calculator.profile
@@ -16,6 +16,7 @@ include disable-programs.inc
16include disable-xdg.inc 16include disable-xdg.inc
17 17
18include whitelist-common.inc 18include whitelist-common.inc
19include whitelist-usr-share-common.inc
19include whitelist-var-common.inc 20include whitelist-var-common.inc
20 21
21apparmor 22apparmor
diff --git a/etc/gnome-keyring.profile b/etc/gnome-keyring.profile
index 47d8ca2c0..8b24da8c4 100644
--- a/etc/gnome-keyring.profile
+++ b/etc/gnome-keyring.profile
@@ -17,7 +17,10 @@ include disable-interpreters.inc
17include disable-programs.inc 17include disable-programs.inc
18include disable-xdg.inc 18include disable-xdg.inc
19 19
20whitelist /usr/share/gnupg
21whitelist /usr/share/gnupg2
20#include whitelist-common.inc 22#include whitelist-common.inc
23include whitelist-usr-share-common.inc
21include whitelist-var-common.inc 24include whitelist-var-common.inc
22 25
23apparmor 26apparmor
diff --git a/etc/gnome-nettool.profile b/etc/gnome-nettool.profile
index 001274372..d15299890 100644
--- a/etc/gnome-nettool.profile
+++ b/etc/gnome-nettool.profile
@@ -14,7 +14,9 @@ include disable-passwdmgr.inc
14include disable-programs.inc 14include disable-programs.inc
15include disable-xdg.inc 15include disable-xdg.inc
16 16
17whitelist /usr/share/gnome-nettool
17#include whitelist-common.inc -- see #903 18#include whitelist-common.inc -- see #903
19include whitelist-usr-share-common.inc
18include whitelist-var-common.inc 20include whitelist-var-common.inc
19 21
20caps.keep net_raw 22caps.keep net_raw
diff --git a/etc/gnome-recipes.profile b/etc/gnome-recipes.profile
index 567fa262c..b4791afc5 100644
--- a/etc/gnome-recipes.profile
+++ b/etc/gnome-recipes.profile
@@ -21,7 +21,9 @@ mkdir ${HOME}/.cache/gnome-recipes
21mkdir ${HOME}/.local/share/gnome-recipes 21mkdir ${HOME}/.local/share/gnome-recipes
22whitelist ${HOME}/.cache/gnome-recipes 22whitelist ${HOME}/.cache/gnome-recipes
23whitelist ${HOME}/.local/share/gnome-recipes 23whitelist ${HOME}/.local/share/gnome-recipes
24whitelist /usr/share/gnome-recipes
24include whitelist-common.inc 25include whitelist-common.inc
26include whitelist-usr-share-common.inc
25include whitelist-var-common.inc 27include whitelist-var-common.inc
26 28
27caps.drop all 29caps.drop all
diff --git a/etc/gnome-schedule.profile b/etc/gnome-schedule.profile
index 30ca56094..c8dd8ead7 100644
--- a/etc/gnome-schedule.profile
+++ b/etc/gnome-schedule.profile
@@ -35,9 +35,11 @@ include disable-xdg.inc
35 35
36mkfile ${HOME}/.gnome/gnome-schedule 36mkfile ${HOME}/.gnome/gnome-schedule
37whitelist ${HOME}/.gnome/gnome-schedule 37whitelist ${HOME}/.gnome/gnome-schedule
38whitelist /usr/share/gnome-schedule
38whitelist /var/spool/atd 39whitelist /var/spool/atd
39whitelist /var/spool/cron 40whitelist /var/spool/cron
40include whitelist-common.inc 41include whitelist-common.inc
42include whitelist-usr-share-common.inc
41include whitelist-var-common.inc 43include whitelist-var-common.inc
42 44
43apparmor 45apparmor
diff --git a/etc/gnome-system-log.profile b/etc/gnome-system-log.profile
index b2907b32c..cfe39d18b 100644
--- a/etc/gnome-system-log.profile
+++ b/etc/gnome-system-log.profile
@@ -16,6 +16,7 @@ include disable-xdg.inc
16 16
17whitelist /var/log 17whitelist /var/log
18include whitelist-common.inc 18include whitelist-common.inc
19include whitelist-usr-share-common.inc
19include whitelist-var-common.inc 20include whitelist-var-common.inc
20 21
21apparmor 22apparmor
diff --git a/etc/gpg-agent.profile b/etc/gpg-agent.profile
index 61b485df5..36e50370e 100644
--- a/etc/gpg-agent.profile
+++ b/etc/gpg-agent.profile
@@ -16,6 +16,10 @@ include disable-interpreters.inc
16include disable-passwdmgr.inc 16include disable-passwdmgr.inc
17include disable-programs.inc 17include disable-programs.inc
18 18
19whitelist /usr/share/gnupg
20whitelist /usr/share/gnupg2
21include whitelist-usr-share-common.inc
22
19caps.drop all 23caps.drop all
20netfilter 24netfilter
21no3d 25no3d
diff --git a/etc/gpg.profile b/etc/gpg.profile
index 99ad1b888..1ed5e484a 100644
--- a/etc/gpg.profile
+++ b/etc/gpg.profile
@@ -16,6 +16,11 @@ include disable-interpreters.inc
16include disable-passwdmgr.inc 16include disable-passwdmgr.inc
17include disable-programs.inc 17include disable-programs.inc
18 18
19whitelist /usr/share/gnupg
20whitelist /usr/share/gnupg2
21whitelist /usr/share/pacman/keyrings
22include whitelist-usr-share-common.inc
23
19caps.drop all 24caps.drop all
20netfilter 25netfilter
21no3d 26no3d
diff --git a/etc/gpicview.profile b/etc/gpicview.profile
index 17371aec0..eb00688dd 100644
--- a/etc/gpicview.profile
+++ b/etc/gpicview.profile
@@ -15,6 +15,8 @@ include disable-interpreters.inc
15include disable-passwdmgr.inc 15include disable-passwdmgr.inc
16include disable-programs.inc 16include disable-programs.inc
17 17
18whitelist /usr/share/gpicview
19include whitelist-usr-share-common.inc
18include whitelist-var-common.inc 20include whitelist-var-common.inc
19 21
20apparmor 22apparmor
diff --git a/etc/img2txt.profile b/etc/img2txt.profile
index 19b4e1ed7..c17e82870 100644
--- a/etc/img2txt.profile
+++ b/etc/img2txt.profile
@@ -16,6 +16,9 @@ include disable-passwdmgr.inc
16include disable-programs.inc 16include disable-programs.inc
17include disable-xdg.inc 17include disable-xdg.inc
18 18
19whitelist /usr/share/imlib2
20include whitelist-usr-share-common.inc
21
19apparmor 22apparmor
20caps.drop all 23caps.drop all
21ipc-namespace 24ipc-namespace
diff --git a/etc/inkscape.profile b/etc/inkscape.profile
index a968609a9..30cb5d75d 100644
--- a/etc/inkscape.profile
+++ b/etc/inkscape.profile
@@ -28,6 +28,8 @@ include disable-passwdmgr.inc
28include disable-programs.inc 28include disable-programs.inc
29include disable-xdg.inc 29include disable-xdg.inc
30 30
31whitelist /usr/share/inkscape
32include whitelist-usr-share-common.inc
31include whitelist-var-common.inc 33include whitelist-var-common.inc
32 34
33apparmor 35apparmor
diff --git a/etc/liferea.profile b/etc/liferea.profile
index 70d317199..045adc1bf 100644
--- a/etc/liferea.profile
+++ b/etc/liferea.profile
@@ -27,7 +27,9 @@ mkdir ${HOME}/.local/share/liferea
27whitelist ${HOME}/.cache/liferea 27whitelist ${HOME}/.cache/liferea
28whitelist ${HOME}/.config/liferea 28whitelist ${HOME}/.config/liferea
29whitelist ${HOME}/.local/share/liferea 29whitelist ${HOME}/.local/share/liferea
30whitelist /usr/share/liferea
30include whitelist-common.inc 31include whitelist-common.inc
32include whitelist-usr-share-common.inc
31include whitelist-var-common.inc 33include whitelist-var-common.inc
32 34
33caps.drop all 35caps.drop all
diff --git a/etc/mediainfo.profile b/etc/mediainfo.profile
index 02d4a937c..00730c00b 100644
--- a/etc/mediainfo.profile
+++ b/etc/mediainfo.profile
@@ -13,6 +13,8 @@ include disable-interpreters.inc
13include disable-passwdmgr.inc 13include disable-passwdmgr.inc
14include disable-programs.inc 14include disable-programs.inc
15 15
16include whitelist-usr-share-common.inc
17
16apparmor 18apparmor
17caps.drop all 19caps.drop all
18ipc-namespace 20ipc-namespace
diff --git a/etc/mpDris2.profile b/etc/mpDris2.profile
index eb49b52ab..fd0351db0 100644
--- a/etc/mpDris2.profile
+++ b/etc/mpDris2.profile
@@ -26,6 +26,7 @@ whitelist ${MUSIC}
26 26
27mkdir ${HOME}/.config/mpDris2 27mkdir ${HOME}/.config/mpDris2
28whitelist ${HOME}/.config/mpDris2 28whitelist ${HOME}/.config/mpDris2
29include whitelist-usr-share-common.inc
29include whitelist-var-common.inc 30include whitelist-var-common.inc
30 31
31caps.drop all 32caps.drop all
diff --git a/etc/mpd.profile b/etc/mpd.profile
index 6c5963793..80f4df7cb 100644
--- a/etc/mpd.profile
+++ b/etc/mpd.profile
@@ -19,6 +19,8 @@ include disable-passwdmgr.inc
19include disable-programs.inc 19include disable-programs.inc
20include disable-xdg.inc 20include disable-xdg.inc
21 21
22include whitelist-usr-share-common.inc
23
22caps.drop all 24caps.drop all
23netfilter 25netfilter
24no3d 26no3d
diff --git a/etc/mpg123.profile b/etc/mpg123.profile
index 8a8907c39..6dfeb4586 100644
--- a/etc/mpg123.profile
+++ b/etc/mpg123.profile
@@ -17,6 +17,7 @@ include disable-passwdmgr.inc
17include disable-programs.inc 17include disable-programs.inc
18include disable-xdg.inc 18include disable-xdg.inc
19 19
20include whitelist-usr-share-common.inc
20include whitelist-var-common.inc 21include whitelist-var-common.inc
21 22
22apparmor 23apparmor
diff --git a/etc/mplayer.profile b/etc/mplayer.profile
index 877b92564..9ab4f8c7f 100644
--- a/etc/mplayer.profile
+++ b/etc/mplayer.profile
@@ -18,6 +18,7 @@ include disable-passwdmgr.inc
18include disable-programs.inc 18include disable-programs.inc
19include disable-xdg.inc 19include disable-xdg.inc
20 20
21include whitelist-usr-share-common.inc
21include whitelist-var-common.inc 22include whitelist-var-common.inc
22 23
23caps.drop all 24caps.drop all
diff --git a/etc/nano.profile b/etc/nano.profile
index 9965d8a6b..af6fcc3fe 100644
--- a/etc/nano.profile
+++ b/etc/nano.profile
@@ -17,6 +17,9 @@ include disable-interpreters.inc
17include disable-passwdmgr.inc 17include disable-passwdmgr.inc
18include disable-programs.inc 18include disable-programs.inc
19 19
20whitelist /usr/share/nano
21include whitelist-usr-share-common.inc
22
20apparmor 23apparmor
21caps.drop all 24caps.drop all
22ipc-namespace 25ipc-namespace
diff --git a/etc/netactview.profile b/etc/netactview.profile
index c91822a9d..0618caf68 100644
--- a/etc/netactview.profile
+++ b/etc/netactview.profile
@@ -18,7 +18,9 @@ include disable-xdg.inc
18 18
19mkfile ${HOME}/.netactview 19mkfile ${HOME}/.netactview
20whitelist ${HOME}/.netactview 20whitelist ${HOME}/.netactview
21whitelist /usr/share/netactview
21include whitelist-common.inc 22include whitelist-common.inc
23include whitelist-usr-share-common.inc
22include whitelist-var-common.inc 24include whitelist-var-common.inc
23 25
24apparmor 26apparmor
diff --git a/etc/nitroshare.profile b/etc/nitroshare.profile
index 19b6615ef..28879d09b 100644
--- a/etc/nitroshare.profile
+++ b/etc/nitroshare.profile
@@ -20,6 +20,8 @@ include disable-interpreters.inc
20include disable-passwdmgr.inc 20include disable-passwdmgr.inc
21include disable-programs.inc 21include disable-programs.inc
22 22
23include whitelist-usr-share-common.inc
24
23caps.drop all 25caps.drop all
24netfilter 26netfilter
25no3d 27no3d
diff --git a/etc/ocenaudio.profile b/etc/ocenaudio.profile
index 25e8089ab..acc249000 100644
--- a/etc/ocenaudio.profile
+++ b/etc/ocenaudio.profile
@@ -18,6 +18,8 @@ include disable-passwdmgr.inc
18include disable-programs.inc 18include disable-programs.inc
19include disable-xdg.inc 19include disable-xdg.inc
20 20
21include whitelist-usr-share-common.inc
22
21apparmor 23apparmor
22caps.drop all 24caps.drop all
23ipc-namespace 25ipc-namespace
diff --git a/etc/patch.profile b/etc/patch.profile
index aa5c1ed4e..03f5a4b71 100644
--- a/etc/patch.profile
+++ b/etc/patch.profile
@@ -16,6 +16,7 @@ include disable-interpreters.inc
16include disable-passwdmgr.inc 16include disable-passwdmgr.inc
17include disable-xdg.inc 17include disable-xdg.inc
18 18
19include whitelist-usr-share-common.inc
19include whitelist-var-common.inc 20include whitelist-var-common.inc
20 21
21caps.drop all 22caps.drop all
diff --git a/etc/pavucontrol.profile b/etc/pavucontrol.profile
index e74394b22..5bbe1386f 100644
--- a/etc/pavucontrol.profile
+++ b/etc/pavucontrol.profile
@@ -18,7 +18,10 @@ include disable-xdg.inc
18 18
19mkfile ${HOME}/.config/pavucontrol.ini 19mkfile ${HOME}/.config/pavucontrol.ini
20whitelist ${HOME}/.config/pavucontrol.ini 20whitelist ${HOME}/.config/pavucontrol.ini
21whitelist /usr/share/pavucontrol
22whitelist /usr/share/pavucontrol-qt
21include whitelist-common.inc 23include whitelist-common.inc
24include whitelist-usr-share-common.inc
22include whitelist-var-common.inc 25include whitelist-var-common.inc
23 26
24apparmor 27apparmor
diff --git a/etc/pdftotext.profile b/etc/pdftotext.profile
index f1a5741d0..e9572d914 100644
--- a/etc/pdftotext.profile
+++ b/etc/pdftotext.profile
@@ -17,6 +17,8 @@ include disable-xdg.inc
17 17
18whitelist ${DOCUMENTS} 18whitelist ${DOCUMENTS}
19whitelist ${DOWNLOADS} 19whitelist ${DOWNLOADS}
20whitelist /usr/share/poppler
21include whitelist-usr-share-common.inc
20include whitelist-var-common.inc 22include whitelist-var-common.inc
21 23
22caps.drop all 24caps.drop all
diff --git a/etc/pidgin.profile b/etc/pidgin.profile
index 299f807af..2e4215744 100644
--- a/etc/pidgin.profile
+++ b/etc/pidgin.profile
@@ -22,6 +22,7 @@ include disable-xdg.inc
22mkdir ${HOME}/.purple 22mkdir ${HOME}/.purple
23whitelist ${HOME}/.purple 23whitelist ${HOME}/.purple
24include whitelist-common.inc 24include whitelist-common.inc
25include whitelist-usr-share-common.inc
25include whitelist-var-common.inc 26include whitelist-var-common.inc
26 27
27apparmor 28apparmor
diff --git a/etc/ping.profile b/etc/ping.profile
index 4ff5250d7..11dbbcd58 100644
--- a/etc/ping.profile
+++ b/etc/ping.profile
@@ -14,6 +14,8 @@ include disable-interpreters.inc
14include disable-passwdmgr.inc 14include disable-passwdmgr.inc
15include disable-programs.inc 15include disable-programs.inc
16include disable-xdg.inc 16include disable-xdg.inc
17
18include whitelist-usr-share-common.inc
17include whitelist-common.inc 19include whitelist-common.inc
18 20
19caps.keep net_raw 21caps.keep net_raw
diff --git a/etc/regextester.profile b/etc/regextester.profile
index c7c59bec2..e30748946 100644
--- a/etc/regextester.profile
+++ b/etc/regextester.profile
@@ -14,6 +14,9 @@ include disable-interpreters.inc
14include disable-programs.inc 14include disable-programs.inc
15include disable-xdg.inc 15include disable-xdg.inc
16 16
17whitelist /usr/share/com.github.artemanufrij.regextester
18include whitelist-usr-share-common.inc
19
17include whitelist-common.inc 20include whitelist-common.inc
18include whitelist-var-common.inc 21include whitelist-var-common.inc
19 22
diff --git a/etc/seahorse.profile b/etc/seahorse.profile
index fe29a6731..6acf8aa5d 100644
--- a/etc/seahorse.profile
+++ b/etc/seahorse.profile
@@ -25,6 +25,11 @@ mkdir ${HOME}/.ssh
25whitelist ${HOME}/.gnupg 25whitelist ${HOME}/.gnupg
26whitelist ${HOME}/.ssh 26whitelist ${HOME}/.ssh
27whitelist /tmp/ssh-* 27whitelist /tmp/ssh-*
28whitelist /usr/share/gnupg
29whitelist /usr/share/gnupg2
30whitelist /usr/share/seahorse
31whitelist /usr/share/seahorse-nautilus
32include whitelist-usr-share-common.inc
28include whitelist-common.inc 33include whitelist-common.inc
29include whitelist-var-common.inc 34include whitelist-var-common.inc
30 35
diff --git a/etc/shellcheck.profile b/etc/shellcheck.profile
index 2fcd69d3b..d26096c77 100644
--- a/etc/shellcheck.profile
+++ b/etc/shellcheck.profile
@@ -17,6 +17,8 @@ include disable-passwdmgr.inc
17include disable-programs.inc 17include disable-programs.inc
18include disable-xdg.inc 18include disable-xdg.inc
19 19
20whitelist /usr/share/shellcheck
21include whitelist-usr-share-common.inc
20include whitelist-var-common.inc 22include whitelist-var-common.inc
21 23
22caps.drop all 24caps.drop all
diff --git a/etc/simple-scan.profile b/etc/simple-scan.profile
index a0c9e8303..ff6de9ec2 100644
--- a/etc/simple-scan.profile
+++ b/etc/simple-scan.profile
@@ -16,6 +16,9 @@ include disable-passwdmgr.inc
16include disable-programs.inc 16include disable-programs.inc
17include disable-xdg.inc 17include disable-xdg.inc
18 18
19whitelist /usr/share/simple-scan
20include whitelist-usr-share-common.inc
21
19caps.drop all 22caps.drop all
20netfilter 23netfilter
21nodvd 24nodvd
diff --git a/etc/simplescreenrecorder.profile b/etc/simplescreenrecorder.profile
index a3caedf88..5f8ab360f 100644
--- a/etc/simplescreenrecorder.profile
+++ b/etc/simplescreenrecorder.profile
@@ -16,6 +16,9 @@ include disable-passwdmgr.inc
16include disable-programs.inc 16include disable-programs.inc
17include disable-xdg.inc 17include disable-xdg.inc
18 18
19whitelist /usr/share/simplescreenrecorder
20include whitelist-usr-share-common.inc
21
19apparmor 22apparmor
20caps.drop all 23caps.drop all
21nodvd 24nodvd
diff --git a/etc/smplayer.profile b/etc/smplayer.profile
index c7324e6ca..395888c8a 100644
--- a/etc/smplayer.profile
+++ b/etc/smplayer.profile
@@ -25,6 +25,8 @@ include disable-passwdmgr.inc
25include disable-programs.inc 25include disable-programs.inc
26include disable-xdg.inc 26include disable-xdg.inc
27 27
28whitelist /usr/share/smplayer
29include whitelist-usr-share-common.inc
28include whitelist-var-common.inc 30include whitelist-var-common.inc
29 31
30apparmor 32apparmor
diff --git a/etc/smtube.profile b/etc/smtube.profile
index 1c7c6c0d2..98e0229ce 100644
--- a/etc/smtube.profile
+++ b/etc/smtube.profile
@@ -23,6 +23,9 @@ include disable-passwdmgr.inc
23include disable-programs.inc 23include disable-programs.inc
24include disable-xdg.inc 24include disable-xdg.inc
25 25
26whitelist /usr/share/smplayer
27whitelist /usr/share/smtube
28include whitelist-usr-share-common.inc
26include whitelist-var-common.inc 29include whitelist-var-common.inc
27 30
28caps.drop all 31caps.drop all
diff --git a/etc/soundconverter.profile b/etc/soundconverter.profile
index efd600eb2..bdd6eb7f5 100644
--- a/etc/soundconverter.profile
+++ b/etc/soundconverter.profile
@@ -22,7 +22,9 @@ include disable-xdg.inc
22 22
23whitelist ${DOWNLOADS} 23whitelist ${DOWNLOADS}
24whitelist ${MUSIC} 24whitelist ${MUSIC}
25whitelist /usr/share/soundconverter
25include whitelist-common.inc 26include whitelist-common.inc
27include whitelist-usr-share-common.inc
26include whitelist-var-common.inc 28include whitelist-var-common.inc
27 29
28apparmor 30apparmor
diff --git a/etc/spectre-meltdown-checker.profile b/etc/spectre-meltdown-checker.profile
index cb4a74e11..1e1b46d3c 100644
--- a/etc/spectre-meltdown-checker.profile
+++ b/etc/spectre-meltdown-checker.profile
@@ -20,6 +20,7 @@ include disable-passwdmgr.inc
20include disable-programs.inc 20include disable-programs.inc
21include disable-xdg.inc 21include disable-xdg.inc
22 22
23include whitelist-usr-share-common.inc
23include whitelist-var-common.inc 24include whitelist-var-common.inc
24 25
25allow-debuggers 26allow-debuggers
diff --git a/etc/ssh-agent.profile b/etc/ssh-agent.profile
index 9934e92b0..8e355a176 100644
--- a/etc/ssh-agent.profile
+++ b/etc/ssh-agent.profile
@@ -16,6 +16,8 @@ include disable-common.inc
16include disable-passwdmgr.inc 16include disable-passwdmgr.inc
17include disable-programs.inc 17include disable-programs.inc
18 18
19include whitelist-usr-share-common.inc
20
19caps.drop all 21caps.drop all
20netfilter 22netfilter
21no3d 23no3d
diff --git a/etc/ssh.profile b/etc/ssh.profile
index 6949299af..584c56b54 100644
--- a/etc/ssh.profile
+++ b/etc/ssh.profile
@@ -18,6 +18,8 @@ include disable-exec.inc
18include disable-passwdmgr.inc 18include disable-passwdmgr.inc
19include disable-programs.inc 19include disable-programs.inc
20 20
21include whitelist-usr-share-common.inc
22
21caps.drop all 23caps.drop all
22ipc-namespace 24ipc-namespace
23netfilter 25netfilter
diff --git a/etc/subdownloader.profile b/etc/subdownloader.profile
index 6de408740..828f3d327 100644
--- a/etc/subdownloader.profile
+++ b/etc/subdownloader.profile
@@ -21,6 +21,8 @@ include disable-passwdmgr.inc
21include disable-programs.inc 21include disable-programs.inc
22include disable-xdg.inc 22include disable-xdg.inc
23 23
24include whitelist-usr-share-common.inc
25
24apparmor 26apparmor
25caps.drop all 27caps.drop all
26netfilter 28netfilter
diff --git a/etc/sysprof.profile b/etc/sysprof.profile
index e978e03f2..9188df709 100644
--- a/etc/sysprof.profile
+++ b/etc/sysprof.profile
@@ -14,6 +14,8 @@ include disable-passwdmgr.inc
14include disable-programs.inc 14include disable-programs.inc
15include disable-xdg.inc 15include disable-xdg.inc
16 16
17include whitelist-usr-share-common.inc
18
17apparmor 19apparmor
18caps.drop all 20caps.drop all
19ipc-namespace 21ipc-namespace
diff --git a/etc/transgui.profile b/etc/transgui.profile
index 0d09cef87..567e2ab30 100644
--- a/etc/transgui.profile
+++ b/etc/transgui.profile
@@ -20,6 +20,7 @@ mkdir ${HOME}/.config/transgui
20whitelist ${HOME}/.config/transgui 20whitelist ${HOME}/.config/transgui
21whitelist ${DOWNLOADS} 21whitelist ${DOWNLOADS}
22include whitelist-common.inc 22include whitelist-common.inc
23include whitelist-usr-share-common.inc
23include whitelist-var-common.inc 24include whitelist-var-common.inc
24 25
25apparmor 26apparmor
diff --git a/etc/transmission-common.profile b/etc/transmission-common.profile
index 1b1fc4af7..a8b667e91 100644
--- a/etc/transmission-common.profile
+++ b/etc/transmission-common.profile
@@ -20,6 +20,7 @@ whitelist ${DOWNLOADS}
20whitelist ${HOME}/.cache/transmission 20whitelist ${HOME}/.cache/transmission
21whitelist ${HOME}/.config/transmission 21whitelist ${HOME}/.config/transmission
22include whitelist-common.inc 22include whitelist-common.inc
23include whitelist-usr-share-common.inc
23include whitelist-var-common.inc 24include whitelist-var-common.inc
24 25
25apparmor 26apparmor
diff --git a/etc/transmission-gtk.profile b/etc/transmission-gtk.profile
index de8da003b..01bdeb4ef 100644
--- a/etc/transmission-gtk.profile
+++ b/etc/transmission-gtk.profile
@@ -7,8 +7,6 @@ include transmission-gtk.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10include whitelist-usr-share-common.inc
11
12private-bin transmission-gtk 10private-bin transmission-gtk
13 11
14ignore memory-deny-write-execute 12ignore memory-deny-write-execute
diff --git a/etc/tshark.profile b/etc/tshark.profile
index ea85f4e8a..0decb95cf 100644
--- a/etc/tshark.profile
+++ b/etc/tshark.profile
@@ -14,7 +14,9 @@ include disable-passwdmgr.inc
14include disable-programs.inc 14include disable-programs.inc
15include disable-xdg.inc 15include disable-xdg.inc
16 16
17whitelist /usr/share/wireshark
17include whitelist-common.inc 18include whitelist-common.inc
19include whitelist-usr-share-common.inc
18 20
19#caps.keep net_raw 21#caps.keep net_raw
20caps.keep dac_override,net_admin,net_raw 22caps.keep dac_override,net_admin,net_raw
diff --git a/etc/uget-gtk.profile b/etc/uget-gtk.profile
index 09821b411..ec1ac48a2 100644
--- a/etc/uget-gtk.profile
+++ b/etc/uget-gtk.profile
@@ -16,6 +16,7 @@ mkdir ${HOME}/.config/uGet
16whitelist ${DOWNLOADS} 16whitelist ${DOWNLOADS}
17whitelist ${HOME}/.config/uGet 17whitelist ${HOME}/.config/uGet
18include whitelist-common.inc 18include whitelist-common.inc
19include whitelist-usr-share-common.inc
19 20
20caps.drop all 21caps.drop all
21netfilter 22netfilter
diff --git a/etc/unbound.profile b/etc/unbound.profile
index c57bb45c4..67448d766 100644
--- a/etc/unbound.profile
+++ b/etc/unbound.profile
@@ -19,6 +19,8 @@ include disable-passwdmgr.inc
19include disable-programs.inc 19include disable-programs.inc
20include disable-xdg.inc 20include disable-xdg.inc
21 21
22include whitelist-usr-share-common.inc
23
22whitelist /var/lib/unbound 24whitelist /var/lib/unbound
23whitelist /var/run 25whitelist /var/run
24 26
diff --git a/etc/uudeview.profile b/etc/uudeview.profile
index af6cd620f..60a7f0d20 100644
--- a/etc/uudeview.profile
+++ b/etc/uudeview.profile
@@ -14,6 +14,8 @@ include disable-interpreters.inc
14include disable-passwdmgr.inc 14include disable-passwdmgr.inc
15include disable-programs.inc 15include disable-programs.inc
16 16
17include whitelist-usr-share-common.inc
18
17caps.drop all 19caps.drop all
18hostname uudeview 20hostname uudeview
19ipc-namespace 21ipc-namespace
diff --git a/etc/viewnior.profile b/etc/viewnior.profile
index e238db8ce..f9241c7e0 100644
--- a/etc/viewnior.profile
+++ b/etc/viewnior.profile
@@ -19,6 +19,8 @@ include disable-interpreters.inc
19include disable-passwdmgr.inc 19include disable-passwdmgr.inc
20include disable-programs.inc 20include disable-programs.inc
21 21
22include whitelist-usr-share-common.inc
23
22apparmor 24apparmor
23caps.drop all 25caps.drop all
24net none 26net none
diff --git a/etc/weechat.profile b/etc/weechat.profile
index 99b34048f..a94275c2c 100644
--- a/etc/weechat.profile
+++ b/etc/weechat.profile
@@ -11,6 +11,8 @@ noblacklist ${HOME}/.weechat
11include disable-common.inc 11include disable-common.inc
12include disable-programs.inc 12include disable-programs.inc
13 13
14include whitelist-usr-share-common.inc
15
14caps.drop all 16caps.drop all
15netfilter 17netfilter
16nodvd 18nodvd
diff --git a/etc/whitelist-usr-share-common.inc b/etc/whitelist-usr-share-common.inc
index 61c69b2f8..7d1439f59 100644
--- a/etc/whitelist-usr-share-common.inc
+++ b/etc/whitelist-usr-share-common.inc
@@ -5,6 +5,7 @@ include whitelist-usr-share-common.local
5 5
6whitelist /usr/share/alsa 6whitelist /usr/share/alsa
7whitelist /usr/share/applications 7whitelist /usr/share/applications
8whitelist /usr/share/ca-certificates
8whitelist /usr/share/crypto-policies 9whitelist /usr/share/crypto-policies
9whitelist /usr/share/cursors 10whitelist /usr/share/cursors
10whitelist /usr/share/dconf 11whitelist /usr/share/dconf
@@ -38,6 +39,8 @@ whitelist /usr/share/p11-kit
38whitelist /usr/share/pixmaps 39whitelist /usr/share/pixmaps
39whitelist /usr/share/pki 40whitelist /usr/share/pki
40whitelist /usr/share/plasma 41whitelist /usr/share/plasma
42whitelist /usr/share/qt
43whitelist /usr/share/qt4
41whitelist /usr/share/qt5 44whitelist /usr/share/qt5
42whitelist /usr/share/sounds 45whitelist /usr/share/sounds
43whitelist /usr/share/tcl8.6 46whitelist /usr/share/tcl8.6
diff --git a/etc/whois.profile b/etc/whois.profile
index 859542533..fed3709e5 100644
--- a/etc/whois.profile
+++ b/etc/whois.profile
@@ -15,6 +15,7 @@ include disable-passwdmgr.inc
15include disable-programs.inc 15include disable-programs.inc
16#include disable-xdg.inc 16#include disable-xdg.inc
17 17
18include whitelist-usr-share-common.inc
18include whitelist-var-common.inc 19include whitelist-var-common.inc
19 20
20caps.drop all 21caps.drop all
diff --git a/etc/wireshark.profile b/etc/wireshark.profile
index 58ff93750..d73e2e279 100644
--- a/etc/wireshark.profile
+++ b/etc/wireshark.profile
@@ -21,6 +21,8 @@ include disable-passwdmgr.inc
21include disable-programs.inc 21include disable-programs.inc
22include disable-xdg.inc 22include disable-xdg.inc
23 23
24whitelist /usr/share/wireshark
25include whitelist-usr-share-common.inc
24include whitelist-var-common.inc 26include whitelist-var-common.inc
25 27
26apparmor 28apparmor
diff --git a/etc/xfce4-mixer.profile b/etc/xfce4-mixer.profile
index e6bbb4259..6ef85f318 100644
--- a/etc/xfce4-mixer.profile
+++ b/etc/xfce4-mixer.profile
@@ -18,7 +18,10 @@ include disable-xdg.inc
18 18
19mkfile ${HOME}/.config/xfce4/xfconf/xfce-perchannel-xml/xfce4-mixer.xml 19mkfile ${HOME}/.config/xfce4/xfconf/xfce-perchannel-xml/xfce4-mixer.xml
20whitelist ${HOME}/.config/xfce4/xfconf/xfce-perchannel-xml/xfce4-mixer.xml 20whitelist ${HOME}/.config/xfce4/xfconf/xfce-perchannel-xml/xfce4-mixer.xml
21whitelist /usr/share/xfce4
22whitelist /usr/share/xfce4-mixer
21include whitelist-common.inc 23include whitelist-common.inc
24include whitelist-usr-share-common.inc
22include whitelist-var-common.inc 25include whitelist-var-common.inc
23 26
24apparmor 27apparmor