aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLibravatar netblue30 <netblue30@protonmail.com>2023-01-31 18:02:37 -0500
committerLibravatar GitHub <noreply@github.com>2023-01-31 18:02:37 -0500
commit4b2a38bc2aedd787089e34063c74ab5e7456b529 (patch)
tree0c6e14a0ff4f77922b1c58c7e120797a9475ddb5
parentMerge pull request #5631 from glitsj16/inkscape (diff)
parentdisable-common.inc: make ~/.config/nano read-only (diff)
downloadfirejail-4b2a38bc2aedd787089e34063c74ab5e7456b529.tar.gz
firejail-4b2a38bc2aedd787089e34063c74ab5e7456b529.tar.zst
firejail-4b2a38bc2aedd787089e34063c74ab5e7456b529.zip
Merge pull request #5635 from kmk3/dc-add-ro-editor-browser
disable-common.inc: add more ro editor/browser paths
-rw-r--r--etc/inc/disable-common.inc4
-rw-r--r--etc/profile-a-l/elinks.profile2
-rw-r--r--etc/profile-m-z/mutt.profile3
-rw-r--r--etc/profile-m-z/nano.profile2
-rw-r--r--etc/profile-m-z/neomutt.profile3
-rw-r--r--etc/profile-m-z/w3m.profile1
6 files changed, 9 insertions, 6 deletions
diff --git a/etc/inc/disable-common.inc b/etc/inc/disable-common.inc
index 66a309d85..03daaa9a6 100644
--- a/etc/inc/disable-common.inc
+++ b/etc/inc/disable-common.inc
@@ -327,9 +327,11 @@ read-only ${HOME}/.ssh/config.d
327# Initialization files that allow arbitrary command execution 327# Initialization files that allow arbitrary command execution
328read-only ${HOME}/.caffrc 328read-only ${HOME}/.caffrc
329read-only ${HOME}/.cargo/env 329read-only ${HOME}/.cargo/env
330read-only ${HOME}/.config/nano
330read-only ${HOME}/.config/nvim 331read-only ${HOME}/.config/nvim
331read-only ${HOME}/.config/pkcs11 332read-only ${HOME}/.config/pkcs11
332read-only ${HOME}/.dotfiles 333read-only ${HOME}/.dotfiles
334read-only ${HOME}/.elinks
333read-only ${HOME}/.emacs 335read-only ${HOME}/.emacs
334read-only ${HOME}/.emacs.d 336read-only ${HOME}/.emacs.d
335read-only ${HOME}/.exrc 337read-only ${HOME}/.exrc
@@ -345,6 +347,7 @@ read-only ${HOME}/.msmtprc
345read-only ${HOME}/.mutt/muttrc 347read-only ${HOME}/.mutt/muttrc
346read-only ${HOME}/.muttrc 348read-only ${HOME}/.muttrc
347read-only ${HOME}/.nano 349read-only ${HOME}/.nano
350read-only ${HOME}/.nanorc
348read-only ${HOME}/.npmrc 351read-only ${HOME}/.npmrc
349read-only ${HOME}/.pythonrc.py 352read-only ${HOME}/.pythonrc.py
350read-only ${HOME}/.reportbugrc 353read-only ${HOME}/.reportbugrc
@@ -352,6 +355,7 @@ read-only ${HOME}/.tmux.conf
352read-only ${HOME}/.vim 355read-only ${HOME}/.vim
353read-only ${HOME}/.viminfo 356read-only ${HOME}/.viminfo
354read-only ${HOME}/.vimrc 357read-only ${HOME}/.vimrc
358read-only ${HOME}/.w3m
355read-only ${HOME}/.xmonad 359read-only ${HOME}/.xmonad
356read-only ${HOME}/.xscreensaver 360read-only ${HOME}/.xscreensaver
357read-only ${HOME}/.yarnrc 361read-only ${HOME}/.yarnrc
diff --git a/etc/profile-a-l/elinks.profile b/etc/profile-a-l/elinks.profile
index a3596bb5e..aab3b3902 100644
--- a/etc/profile-a-l/elinks.profile
+++ b/etc/profile-a-l/elinks.profile
@@ -17,5 +17,7 @@ whitelist ${HOME}/.elinks
17 17
18private-bin elinks 18private-bin elinks
19 19
20read-write ${HOME}/.elinks
21
20# Redirect 22# Redirect
21include links-common.profile 23include links-common.profile
diff --git a/etc/profile-m-z/mutt.profile b/etc/profile-m-z/mutt.profile
index bce56743a..904b0cd7c 100644
--- a/etc/profile-m-z/mutt.profile
+++ b/etc/profile-m-z/mutt.profile
@@ -133,8 +133,5 @@ dbus-user none
133dbus-system none 133dbus-system none
134 134
135memory-deny-write-execute 135memory-deny-write-execute
136read-only ${HOME}/.elinks
137read-only ${HOME}/.nanorc
138read-only ${HOME}/.signature 136read-only ${HOME}/.signature
139read-only ${HOME}/.w3m
140restrict-namespaces 137restrict-namespaces
diff --git a/etc/profile-m-z/nano.profile b/etc/profile-m-z/nano.profile
index a20eb3828..74403c335 100644
--- a/etc/profile-m-z/nano.profile
+++ b/etc/profile-m-z/nano.profile
@@ -56,4 +56,6 @@ dbus-user none
56dbus-system none 56dbus-system none
57 57
58memory-deny-write-execute 58memory-deny-write-execute
59read-write ${HOME}/.config/nano
60read-write ${HOME}/.nanorc
59restrict-namespaces 61restrict-namespaces
diff --git a/etc/profile-m-z/neomutt.profile b/etc/profile-m-z/neomutt.profile
index c255a85c9..f343226ae 100644
--- a/etc/profile-m-z/neomutt.profile
+++ b/etc/profile-m-z/neomutt.profile
@@ -125,8 +125,5 @@ dbus-user none
125dbus-system none 125dbus-system none
126 126
127memory-deny-write-execute 127memory-deny-write-execute
128read-only ${HOME}/.elinks
129read-only ${HOME}/.nanorc
130read-only ${HOME}/.signature 128read-only ${HOME}/.signature
131read-only ${HOME}/.w3m
132restrict-namespaces 129restrict-namespaces
diff --git a/etc/profile-m-z/w3m.profile b/etc/profile-m-z/w3m.profile
index fab5315aa..1e111f83e 100644
--- a/etc/profile-m-z/w3m.profile
+++ b/etc/profile-m-z/w3m.profile
@@ -68,4 +68,5 @@ dbus-user none
68dbus-system none 68dbus-system none
69 69
70memory-deny-write-execute 70memory-deny-write-execute
71read-write ${HOME}/.w3m
71restrict-namespaces 72restrict-namespaces