aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLibravatar rusty-snake <41237666+rusty-snake@users.noreply.github.com>2020-09-02 13:03:21 +0200
committerLibravatar rusty-snake <41237666+rusty-snake@users.noreply.github.com>2020-09-02 13:03:21 +0200
commit8f23b473099b0b458128cee5896c1254c460e129 (patch)
treed9b659ab2dcfe81485172e15d795b8769afe3ef8
parentreadme and relnotes (diff)
downloadfirejail-8f23b473099b0b458128cee5896c1254c460e129.tar.gz
firejail-8f23b473099b0b458128cee5896c1254c460e129.tar.zst
firejail-8f23b473099b0b458128cee5896c1254c460e129.zip
allow flatpak/exports also for systemd-wide location
-rw-r--r--etc/inc/disable-common.inc12
1 files changed, 4 insertions, 8 deletions
diff --git a/etc/inc/disable-common.inc b/etc/inc/disable-common.inc
index c7516ab42..b2be4270e 100644
--- a/etc/inc/disable-common.inc
+++ b/etc/inc/disable-common.inc
@@ -472,14 +472,9 @@ blacklist /.snapshots
472# flatpak 472# flatpak
473blacklist ${HOME}/.cache/flatpak 473blacklist ${HOME}/.cache/flatpak
474blacklist ${HOME}/.config/flatpak 474blacklist ${HOME}/.config/flatpak
475blacklist ${HOME}/.local/share/flatpak/app 475noblacklist ${HOME}/.local/share/flatpak/exports
476blacklist ${HOME}/.local/share/flatpak/appstream
477blacklist ${HOME}/.local/share/flatpak/db
478read-only ${HOME}/.local/share/flatpak/exports 476read-only ${HOME}/.local/share/flatpak/exports
479blacklist ${HOME}/.local/share/flatpak/oci 477blacklist ${HOME}/.local/share/flatpak/*
480blacklist ${HOME}/.local/share/flatpak/overrides
481blacklist ${HOME}/.local/share/flatpak/repo
482blacklist ${HOME}/.local/share/flatpak/runtime
483blacklist ${HOME}/.var 478blacklist ${HOME}/.var
484blacklist ${RUNUSER}/app 479blacklist ${RUNUSER}/app
485blacklist ${RUNUSER}/doc 480blacklist ${RUNUSER}/doc
@@ -487,7 +482,8 @@ blacklist ${RUNUSER}/.dbus-proxy
487blacklist ${RUNUSER}/.flatpak 482blacklist ${RUNUSER}/.flatpak
488blacklist ${RUNUSER}/.flatpak-helper 483blacklist ${RUNUSER}/.flatpak-helper
489blacklist /usr/share/flatpak 484blacklist /usr/share/flatpak
490blacklist /var/lib/flatpak 485noblacklist /var/lib/flatpak/exports
486blacklist /var/lib/flatpak/*
491# most of the time bwrap is SUID binary 487# most of the time bwrap is SUID binary
492blacklist ${PATH}/bwrap 488blacklist ${PATH}/bwrap
493 489