aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLibravatar netblue30 <netblue30@yahoo.com>2017-03-29 09:03:19 -0400
committerLibravatar netblue30 <netblue30@yahoo.com>2017-03-29 09:03:19 -0400
commit8e66c46ea814b2f3ca48008c3db5904567ba7609 (patch)
treef9d41af436e4176cfb2ef5ca56329236e1748517
parentblacklist nemo config (file manager for Cinnamon) (diff)
downloadfirejail-8e66c46ea814b2f3ca48008c3db5904567ba7609.tar.gz
firejail-8e66c46ea814b2f3ca48008c3db5904567ba7609.tar.zst
firejail-8e66c46ea814b2f3ca48008c3db5904567ba7609.zip
bringing back ~/.cache in all profiles
-rw-r--r--etc/0ad.profile4
-rw-r--r--etc/abrowser.profile4
-rw-r--r--etc/chromium.profile3
-rw-r--r--etc/cyberfox.profile4
-rw-r--r--etc/disable-programs.inc40
-rw-r--r--etc/epiphany.profile3
-rw-r--r--etc/evolution.profile1
-rw-r--r--etc/firefox.profile4
-rw-r--r--etc/flashpeak-slimjet.profile3
-rw-r--r--etc/fossamail.profile3
-rw-r--r--etc/franz.profile3
-rw-r--r--etc/gajim.profile3
-rw-r--r--etc/geeqie.profile1
-rw-r--r--etc/gjs.profile2
-rw-r--r--etc/gnome-books.profile1
-rw-r--r--etc/gnome-weather.profile1
-rw-r--r--etc/google-chrome-beta.profile3
-rw-r--r--etc/google-chrome-unstable.profile3
-rw-r--r--etc/google-chrome.profile3
-rw-r--r--etc/icecat.profile4
-rw-r--r--etc/icedove.profile4
-rw-r--r--etc/inox.profile3
-rw-r--r--etc/iridium.profile3
-rw-r--r--etc/mutt.profile1
-rw-r--r--etc/netsurf.profile3
-rw-r--r--etc/opera-beta.profile2
-rw-r--r--etc/opera.profile3
-rw-r--r--etc/palemoon.profile4
-rw-r--r--etc/polari.profile2
-rw-r--r--etc/psi-plus.profile2
-rw-r--r--etc/quiterss.profile3
-rw-r--r--etc/qupzilla.profile2
-rw-r--r--etc/qutebrowser.profile3
-rw-r--r--etc/seamonkey.profile4
-rw-r--r--etc/simple-scan.profile2
-rw-r--r--etc/spotify.profile3
-rw-r--r--etc/thunderbird.profile4
-rw-r--r--etc/transmission-cli.profile1
-rw-r--r--etc/transmission-gtk.profile1
-rw-r--r--etc/transmission-qt.profile1
-rw-r--r--etc/transmission-show.profile1
-rw-r--r--etc/vivaldi.profile3
-rw-r--r--etc/wesnoth.profile3
-rw-r--r--etc/whitelist-common.inc1
-rw-r--r--etc/xreader.profile1
45 files changed, 153 insertions, 0 deletions
diff --git a/etc/0ad.profile b/etc/0ad.profile
index d4f06f732..a6a763ae0 100644
--- a/etc/0ad.profile
+++ b/etc/0ad.profile
@@ -3,6 +3,7 @@
3include /etc/firejail/0ad.local 3include /etc/firejail/0ad.local
4 4
5# Firejail profile for 0ad. 5# Firejail profile for 0ad.
6noblacklist ~/.cache/0ad
6noblacklist ~/.config/0ad 7noblacklist ~/.config/0ad
7noblacklist ~/.local/share/0ad 8noblacklist ~/.local/share/0ad
8include /etc/firejail/disable-common.inc 9include /etc/firejail/disable-common.inc
@@ -17,6 +18,9 @@ whitelist ~/.config/0ad
17mkdir ~/.local/share/0ad 18mkdir ~/.local/share/0ad
18whitelist ~/.local/share/0ad 19whitelist ~/.local/share/0ad
19 20
21mkdir ~/.cache/0ad
22whitelist ~/.cache/0ad
23
20caps.drop all 24caps.drop all
21netfilter 25netfilter
22nogroups 26nogroups
diff --git a/etc/abrowser.profile b/etc/abrowser.profile
index 3b60750d5..b9a30d6bf 100644
--- a/etc/abrowser.profile
+++ b/etc/abrowser.profile
@@ -4,6 +4,7 @@ include /etc/firejail/abrowser.local
4 4
5# Firejail profile for Abrowser 5# Firejail profile for Abrowser
6noblacklist ~/.mozilla 6noblacklist ~/.mozilla
7noblacklist ~/.cache/mozilla
7noblacklist ~/.pki 8noblacklist ~/.pki
8noblacklist ~/.lastpass 9noblacklist ~/.lastpass
9include /etc/firejail/disable-common.inc 10include /etc/firejail/disable-common.inc
@@ -21,6 +22,8 @@ tracelog
21whitelist ${DOWNLOADS} 22whitelist ${DOWNLOADS}
22mkdir ~/.mozilla 23mkdir ~/.mozilla
23whitelist ~/.mozilla 24whitelist ~/.mozilla
25mkdir ~/.cache/mozilla/abrowser
26whitelist ~/.cache/mozilla/abrowser
24whitelist ~/dwhelper 27whitelist ~/dwhelper
25whitelist ~/.zotero 28whitelist ~/.zotero
26whitelist ~/.vimperatorrc 29whitelist ~/.vimperatorrc
@@ -29,6 +32,7 @@ whitelist ~/.pentadactylrc
29whitelist ~/.pentadactyl 32whitelist ~/.pentadactyl
30whitelist ~/.keysnail.js 33whitelist ~/.keysnail.js
31whitelist ~/.config/gnome-mplayer 34whitelist ~/.config/gnome-mplayer
35whitelist ~/.cache/gnome-mplayer/plugin
32whitelist ~/.pki 36whitelist ~/.pki
33whitelist ~/.lastpass 37whitelist ~/.lastpass
34 38
diff --git a/etc/chromium.profile b/etc/chromium.profile
index ce823e0db..995c0001b 100644
--- a/etc/chromium.profile
+++ b/etc/chromium.profile
@@ -4,6 +4,7 @@ include /etc/firejail/chromium.local
4 4
5# Chromium browser profile 5# Chromium browser profile
6noblacklist ~/.config/chromium 6noblacklist ~/.config/chromium
7noblacklist ~/.cache/chromium
7noblacklist ~/.pki 8noblacklist ~/.pki
8include /etc/firejail/disable-common.inc 9include /etc/firejail/disable-common.inc
9include /etc/firejail/disable-programs.inc 10include /etc/firejail/disable-programs.inc
@@ -17,6 +18,8 @@ netfilter
17whitelist ${DOWNLOADS} 18whitelist ${DOWNLOADS}
18mkdir ~/.config/chromium 19mkdir ~/.config/chromium
19whitelist ~/.config/chromium 20whitelist ~/.config/chromium
21mkdir ~/.cache/chromium
22whitelist ~/.cache/chromium
20mkdir ~/.pki 23mkdir ~/.pki
21whitelist ~/.pki 24whitelist ~/.pki
22 25
diff --git a/etc/cyberfox.profile b/etc/cyberfox.profile
index d9896e4a7..a79303f77 100644
--- a/etc/cyberfox.profile
+++ b/etc/cyberfox.profile
@@ -4,6 +4,7 @@ include /etc/firejail/cyberfox.local
4 4
5# Firejail profile for Cyberfox (based on Mozilla Firefox) 5# Firejail profile for Cyberfox (based on Mozilla Firefox)
6noblacklist ~/.8pecxstudios 6noblacklist ~/.8pecxstudios
7noblacklist ~/.cache/8pecxstudios
7noblacklist ~/.pki 8noblacklist ~/.pki
8noblacklist ~/.lastpass 9noblacklist ~/.lastpass
9include /etc/firejail/disable-common.inc 10include /etc/firejail/disable-common.inc
@@ -21,6 +22,8 @@ tracelog
21whitelist ${DOWNLOADS} 22whitelist ${DOWNLOADS}
22mkdir ~/.8pecxstudios 23mkdir ~/.8pecxstudios
23whitelist ~/.8pecxstudios 24whitelist ~/.8pecxstudios
25mkdir ~/.cache/8pecxstudios
26whitelist ~/.cache/8pecxstudios
24whitelist ~/dwhelper 27whitelist ~/dwhelper
25whitelist ~/.zotero 28whitelist ~/.zotero
26whitelist ~/.vimperatorrc 29whitelist ~/.vimperatorrc
@@ -29,6 +32,7 @@ whitelist ~/.pentadactylrc
29whitelist ~/.pentadactyl 32whitelist ~/.pentadactyl
30whitelist ~/.keysnail.js 33whitelist ~/.keysnail.js
31whitelist ~/.config/gnome-mplayer 34whitelist ~/.config/gnome-mplayer
35whitelist ~/.cache/gnome-mplayer/plugin
32whitelist ~/.pki 36whitelist ~/.pki
33whitelist ~/.lastpass 37whitelist ~/.lastpass
34 38
diff --git a/etc/disable-programs.inc b/etc/disable-programs.inc
index 946a170ac..c31b92d1f 100644
--- a/etc/disable-programs.inc
+++ b/etc/disable-programs.inc
@@ -261,3 +261,43 @@ blacklist ${HOME}/.xpdfrc
261blacklist ${HOME}/.zoom 261blacklist ${HOME}/.zoom
262blacklist ${HOME}/wallet.dat 262blacklist ${HOME}/wallet.dat
263blacklist /tmp/ssh-* 263blacklist /tmp/ssh-*
264
265# ~/.cache directory
266blacklist ${HOME}/.cache/0ad
267blacklist ${HOME}/.cache/8pecxstudios
268blacklist ${HOME}/.cache/Franz
269blacklist ${HOME}/.cache/INRIA
270blacklist ${HOME}/.cache/QuiteRss
271blacklist ${HOME}/.cache/champlain
272blacklist ${HOME}/.cache/chromium
273blacklist ${HOME}/.cache/qupzilla
274blacklist ${HOME}/.cache/chromium-dev
275blacklist ${HOME}/.cache/darktable
276blacklist ${HOME}/.cache/epiphany
277blacklist ${HOME}/.cache/evolution
278blacklist ${HOME}/.cache/gajim
279blacklist ${HOME}/.cache/geeqie
280blacklist ${HOME}/.cache/google-chrome
281blacklist ${HOME}/.cache/google-chrome-beta
282blacklist ${HOME}/.cache/google-chrome-unstable
283blacklist ${HOME}/.cache/icedove
284blacklist ${HOME}/.cache/inox
285blacklist ${HOME}/.cache/libgweather
286blacklist ${HOME}/.cache/midori
287blacklist ${HOME}/.cache/mozilla
288blacklist ${HOME}/.cache/mutt
289blacklist ${HOME}/.cache/netsurf
290blacklist ${HOME}/.cache/opera
291blacklist ${HOME}/.cache/opera-beta
292blacklist ${HOME}/.cache/org.gnome.Books
293blacklist ${HOME}/.cache/qutebrowser
294blacklist ${HOME}/.cache/simple-scan
295blacklist ${HOME}/.cache/slimjet
296blacklist ${HOME}/.cache/spotify
297blacklist ${HOME}/.cache/telepathy
298blacklist ${HOME}/.cache/thunderbird
299blacklist ${HOME}/.cache/torbrowser
300blacklist ${HOME}/.cache/transmission
301blacklist ${HOME}/.cache/vivaldi
302blacklist ${HOME}/.cache/wesnoth
303blacklist ${HOME}/.cache/xreader
diff --git a/etc/epiphany.profile b/etc/epiphany.profile
index 0b281c448..a80c50f56 100644
--- a/etc/epiphany.profile
+++ b/etc/epiphany.profile
@@ -5,6 +5,7 @@ include /etc/firejail/epiphany.local
5# Epiphany browser profile 5# Epiphany browser profile
6noblacklist ${HOME}/.config/epiphany 6noblacklist ${HOME}/.config/epiphany
7noblacklist ${HOME}/.local/share/epiphany 7noblacklist ${HOME}/.local/share/epiphany
8noblacklist ${HOME}/.cache/epiphany
8 9
9include /etc/firejail/disable-common.inc 10include /etc/firejail/disable-common.inc
10include /etc/firejail/disable-programs.inc 11include /etc/firejail/disable-programs.inc
@@ -15,6 +16,8 @@ mkdir ${HOME}/.local/share/epiphany
15whitelist ${HOME}/.local/share/epiphany 16whitelist ${HOME}/.local/share/epiphany
16mkdir ${HOME}/.config/epiphany 17mkdir ${HOME}/.config/epiphany
17whitelist ${HOME}/.config/epiphany 18whitelist ${HOME}/.config/epiphany
19mkdir ${HOME}/.cache/epiphany
20whitelist ${HOME}/.cache/epiphany
18include /etc/firejail/whitelist-common.inc 21include /etc/firejail/whitelist-common.inc
19 22
20caps.drop all 23caps.drop all
diff --git a/etc/evolution.profile b/etc/evolution.profile
index 637ac334a..cb6615716 100644
--- a/etc/evolution.profile
+++ b/etc/evolution.profile
@@ -5,6 +5,7 @@ include /etc/firejail/evolution.local
5# evolution profile 5# evolution profile
6noblacklist ~/.config/evolution 6noblacklist ~/.config/evolution
7noblacklist ~/.local/share/evolution 7noblacklist ~/.local/share/evolution
8noblacklist ~/.cache/evolution
8noblacklist ~/.pki 9noblacklist ~/.pki
9noblacklist ~/.pki/nssdb 10noblacklist ~/.pki/nssdb
10noblacklist ~/.gnupg 11noblacklist ~/.gnupg
diff --git a/etc/firefox.profile b/etc/firefox.profile
index 20acde62a..3b55d4700 100644
--- a/etc/firefox.profile
+++ b/etc/firefox.profile
@@ -4,6 +4,7 @@ include /etc/firejail/firefox.local
4 4
5# Firejail profile for Mozilla Firefox (Iceweasel in Debian) 5# Firejail profile for Mozilla Firefox (Iceweasel in Debian)
6noblacklist ~/.mozilla 6noblacklist ~/.mozilla
7noblacklist ~/.cache/mozilla
7noblacklist ~/.config/qpdfview 8noblacklist ~/.config/qpdfview
8noblacklist ~/.local/share/qpdfview 9noblacklist ~/.local/share/qpdfview
9noblacklist ~/.kde/share/apps/okular 10noblacklist ~/.kde/share/apps/okular
@@ -24,6 +25,8 @@ tracelog
24whitelist ${DOWNLOADS} 25whitelist ${DOWNLOADS}
25mkdir ~/.mozilla 26mkdir ~/.mozilla
26whitelist ~/.mozilla 27whitelist ~/.mozilla
28mkdir ~/.cache/mozilla/firefox
29whitelist ~/.cache/mozilla/firefox
27whitelist ~/dwhelper 30whitelist ~/dwhelper
28whitelist ~/.zotero 31whitelist ~/.zotero
29whitelist ~/.vimperatorrc 32whitelist ~/.vimperatorrc
@@ -32,6 +35,7 @@ whitelist ~/.pentadactylrc
32whitelist ~/.pentadactyl 35whitelist ~/.pentadactyl
33whitelist ~/.keysnail.js 36whitelist ~/.keysnail.js
34whitelist ~/.config/gnome-mplayer 37whitelist ~/.config/gnome-mplayer
38whitelist ~/.cache/gnome-mplayer/plugin
35mkdir ~/.pki 39mkdir ~/.pki
36whitelist ~/.pki 40whitelist ~/.pki
37whitelist ~/.lastpass 41whitelist ~/.lastpass
diff --git a/etc/flashpeak-slimjet.profile b/etc/flashpeak-slimjet.profile
index a35aa7a33..4dc5b5cfc 100644
--- a/etc/flashpeak-slimjet.profile
+++ b/etc/flashpeak-slimjet.profile
@@ -10,6 +10,7 @@ include /etc/firejail/flashpeak-slimjet.local
10# firejail flashpeak-slimjet --no-sandbox 10# firejail flashpeak-slimjet --no-sandbox
11# 11#
12noblacklist ~/.config/slimjet 12noblacklist ~/.config/slimjet
13noblacklist ~/.cache/slimjet
13noblacklist ~/.pki 14noblacklist ~/.pki
14include /etc/firejail/disable-common.inc 15include /etc/firejail/disable-common.inc
15include /etc/firejail/disable-programs.inc 16include /etc/firejail/disable-programs.inc
@@ -28,6 +29,8 @@ seccomp
28whitelist ${DOWNLOADS} 29whitelist ${DOWNLOADS}
29mkdir ~/.config/slimjet 30mkdir ~/.config/slimjet
30whitelist ~/.config/slimjet 31whitelist ~/.config/slimjet
32mkdir ~/.cache/slimjet
33whitelist ~/.cache/slimjet
31mkdir ~/.pki 34mkdir ~/.pki
32whitelist ~/.pki 35whitelist ~/.pki
33 36
diff --git a/etc/fossamail.profile b/etc/fossamail.profile
index a33514c88..3caaad71c 100644
--- a/etc/fossamail.profile
+++ b/etc/fossamail.profile
@@ -12,5 +12,8 @@ noblacklist ~/.fossamail
12mkdir ~/.fossamail 12mkdir ~/.fossamail
13whitelist ~/.fossamail 13whitelist ~/.fossamail
14 14
15noblacklist ~/.cache/fossamail
16mkdir ~/.cache/fossamail
17whitelist ~/.cache/fossamail
15 18
16include /etc/firejail/firefox.profile 19include /etc/firejail/firefox.profile
diff --git a/etc/franz.profile b/etc/franz.profile
index 1692f4516..05ff72a47 100644
--- a/etc/franz.profile
+++ b/etc/franz.profile
@@ -4,6 +4,7 @@ include /etc/firejail/franz.local
4 4
5# Franz profile 5# Franz profile
6noblacklist ~/.config/Franz 6noblacklist ~/.config/Franz
7noblacklist ~/.cache/Franz
7noblacklist ~/.pki 8noblacklist ~/.pki
8include /etc/firejail/disable-common.inc 9include /etc/firejail/disable-common.inc
9include /etc/firejail/disable-programs.inc 10include /etc/firejail/disable-programs.inc
@@ -20,6 +21,8 @@ seccomp
20whitelist ${DOWNLOADS} 21whitelist ${DOWNLOADS}
21mkdir ~/.config/Franz 22mkdir ~/.config/Franz
22whitelist ~/.config/Franz 23whitelist ~/.config/Franz
24mkdir ~/.cache/Franz
25whitelist ~/.cache/Franz
23mkdir ~/.pki 26mkdir ~/.pki
24whitelist ~/.pki 27whitelist ~/.pki
25 28
diff --git a/etc/gajim.profile b/etc/gajim.profile
index f64d9241a..89bac21d4 100644
--- a/etc/gajim.profile
+++ b/etc/gajim.profile
@@ -5,7 +5,9 @@ include /etc/firejail/gajim.local
5# Firejail profile for Gajim 5# Firejail profile for Gajim
6noblacklist ${HOME}/.local/share/gajim 6noblacklist ${HOME}/.local/share/gajim
7noblacklist ${HOME}/.config/gajim 7noblacklist ${HOME}/.config/gajim
8noblacklist ${HOME}/.cache/gajim
8 9
10mkdir ${HOME}/.cache/gajim
9mkdir ${HOME}/.local/share/gajim 11mkdir ${HOME}/.local/share/gajim
10mkdir ${HOME}/.config/gajim 12mkdir ${HOME}/.config/gajim
11mkdir ${HOME}/Downloads 13mkdir ${HOME}/Downloads
@@ -15,6 +17,7 @@ mkdir ${HOME}/.local/lib/python2.7/site-packages/
15whitelist ${HOME}/.local/lib/python2.7/site-packages/ 17whitelist ${HOME}/.local/lib/python2.7/site-packages/
16read-only ${HOME}/.local/lib/python2.7/site-packages/ 18read-only ${HOME}/.local/lib/python2.7/site-packages/
17 19
20whitelist ${HOME}/.cache/gajim
18whitelist ${HOME}/.local/share/gajim 21whitelist ${HOME}/.local/share/gajim
19whitelist ${HOME}/.config/gajim 22whitelist ${HOME}/.config/gajim
20whitelist ${HOME}/Downloads 23whitelist ${HOME}/Downloads
diff --git a/etc/geeqie.profile b/etc/geeqie.profile
index 9f79e15b8..cabddc88a 100644
--- a/etc/geeqie.profile
+++ b/etc/geeqie.profile
@@ -5,6 +5,7 @@ include /etc/firejail/geeqie.local
5# Firejail profile for Geeqie 5# Firejail profile for Geeqie
6noblacklist ~/.config/geeqie 6noblacklist ~/.config/geeqie
7noblacklist ~/.local/share/geeqie 7noblacklist ~/.local/share/geeqie
8noblacklist ~/.cache/geeqie
8include /etc/firejail/disable-common.inc 9include /etc/firejail/disable-common.inc
9include /etc/firejail/disable-programs.inc 10include /etc/firejail/disable-programs.inc
10include /etc/firejail/disable-devel.inc 11include /etc/firejail/disable-devel.inc
diff --git a/etc/gjs.profile b/etc/gjs.profile
index 03dd7893c..b61341e7d 100644
--- a/etc/gjs.profile
+++ b/etc/gjs.profile
@@ -8,6 +8,8 @@ include /etc/firejail/gjs.local
8 8
9noblacklist ~/.config/libreoffice 9noblacklist ~/.config/libreoffice
10noblacklist ~/.local/share/gnome-photos 10noblacklist ~/.local/share/gnome-photos
11noblacklist ~/.cache/org.gnome.Books
12noblacklist ~/.cache/libgweather
11 13
12include /etc/firejail/disable-common.inc 14include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-programs.inc 15include /etc/firejail/disable-programs.inc
diff --git a/etc/gnome-books.profile b/etc/gnome-books.profile
index bf2a9f36f..d7bd5c633 100644
--- a/etc/gnome-books.profile
+++ b/etc/gnome-books.profile
@@ -5,6 +5,7 @@ include /etc/firejail/gnome-books.local
5# gnome-books profile 5# gnome-books profile
6 6
7# when gjs apps are started via gnome-shell, firejail is not applied because systemd will start them 7# when gjs apps are started via gnome-shell, firejail is not applied because systemd will start them
8noblacklist ~/.cache/org.gnome.Books
8 9
9include /etc/firejail/disable-common.inc 10include /etc/firejail/disable-common.inc
10include /etc/firejail/disable-programs.inc 11include /etc/firejail/disable-programs.inc
diff --git a/etc/gnome-weather.profile b/etc/gnome-weather.profile
index 3b6bdd130..f1fa1d15f 100644
--- a/etc/gnome-weather.profile
+++ b/etc/gnome-weather.profile
@@ -5,6 +5,7 @@ include /etc/firejail/gnome-weather.local
5# gnome-weather profile 5# gnome-weather profile
6 6
7# when gjs apps are started via gnome-shell, firejail is not applied because systemd will start them 7# when gjs apps are started via gnome-shell, firejail is not applied because systemd will start them
8noblacklist ~/.cache/libgweather
8 9
9include /etc/firejail/disable-common.inc 10include /etc/firejail/disable-common.inc
10include /etc/firejail/disable-programs.inc 11include /etc/firejail/disable-programs.inc
diff --git a/etc/google-chrome-beta.profile b/etc/google-chrome-beta.profile
index 65bc42648..3bd16de4a 100644
--- a/etc/google-chrome-beta.profile
+++ b/etc/google-chrome-beta.profile
@@ -4,6 +4,7 @@ include /etc/firejail/google-chrome-beta.local
4 4
5# Google Chrome beta browser profile 5# Google Chrome beta browser profile
6noblacklist ~/.config/google-chrome-beta 6noblacklist ~/.config/google-chrome-beta
7noblacklist ~/.cache/google-chrome-beta
7noblacklist ~/.pki 8noblacklist ~/.pki
8include /etc/firejail/disable-common.inc 9include /etc/firejail/disable-common.inc
9include /etc/firejail/disable-programs.inc 10include /etc/firejail/disable-programs.inc
@@ -17,6 +18,8 @@ netfilter
17whitelist ${DOWNLOADS} 18whitelist ${DOWNLOADS}
18mkdir ~/.config/google-chrome-beta 19mkdir ~/.config/google-chrome-beta
19whitelist ~/.config/google-chrome-beta 20whitelist ~/.config/google-chrome-beta
21mkdir ~/.cache/google-chrome-beta
22whitelist ~/.cache/google-chrome-beta
20mkdir ~/.pki 23mkdir ~/.pki
21whitelist ~/.pki 24whitelist ~/.pki
22include /etc/firejail/whitelist-common.inc 25include /etc/firejail/whitelist-common.inc
diff --git a/etc/google-chrome-unstable.profile b/etc/google-chrome-unstable.profile
index 6f6fa1bf2..d2def4f96 100644
--- a/etc/google-chrome-unstable.profile
+++ b/etc/google-chrome-unstable.profile
@@ -4,6 +4,7 @@ include /etc/firejail/google-chrome-unstable.local
4 4
5# Google Chrome unstable browser profile 5# Google Chrome unstable browser profile
6noblacklist ~/.config/google-chrome-unstable 6noblacklist ~/.config/google-chrome-unstable
7noblacklist ~/.cache/google-chrome-unstable
7noblacklist ~/.pki 8noblacklist ~/.pki
8include /etc/firejail/disable-common.inc 9include /etc/firejail/disable-common.inc
9include /etc/firejail/disable-programs.inc 10include /etc/firejail/disable-programs.inc
@@ -17,6 +18,8 @@ netfilter
17whitelist ${DOWNLOADS} 18whitelist ${DOWNLOADS}
18mkdir ~/.config/google-chrome-unstable 19mkdir ~/.config/google-chrome-unstable
19whitelist ~/.config/google-chrome-unstable 20whitelist ~/.config/google-chrome-unstable
21mkdir ~/.cache/google-chrome-unstable
22whitelist ~/.cache/google-chrome-unstable
20mkdir ~/.pki 23mkdir ~/.pki
21whitelist ~/.pki 24whitelist ~/.pki
22include /etc/firejail/whitelist-common.inc 25include /etc/firejail/whitelist-common.inc
diff --git a/etc/google-chrome.profile b/etc/google-chrome.profile
index 131538dd9..38feb12a5 100644
--- a/etc/google-chrome.profile
+++ b/etc/google-chrome.profile
@@ -4,6 +4,7 @@ include /etc/firejail/google-chrome.local
4 4
5# Google Chrome browser profile 5# Google Chrome browser profile
6noblacklist ~/.config/google-chrome 6noblacklist ~/.config/google-chrome
7noblacklist ~/.cache/google-chrome
7noblacklist ~/.pki 8noblacklist ~/.pki
8include /etc/firejail/disable-common.inc 9include /etc/firejail/disable-common.inc
9include /etc/firejail/disable-programs.inc 10include /etc/firejail/disable-programs.inc
@@ -17,6 +18,8 @@ netfilter
17whitelist ${DOWNLOADS} 18whitelist ${DOWNLOADS}
18mkdir ~/.config/google-chrome 19mkdir ~/.config/google-chrome
19whitelist ~/.config/google-chrome 20whitelist ~/.config/google-chrome
21mkdir ~/.cache/google-chrome
22whitelist ~/.cache/google-chrome
20mkdir ~/.pki 23mkdir ~/.pki
21whitelist ~/.pki 24whitelist ~/.pki
22include /etc/firejail/whitelist-common.inc 25include /etc/firejail/whitelist-common.inc
diff --git a/etc/icecat.profile b/etc/icecat.profile
index 4bd3f3047..64401efe8 100644
--- a/etc/icecat.profile
+++ b/etc/icecat.profile
@@ -4,6 +4,7 @@ include /etc/firejail/icecat.local
4 4
5# Firejail profile for GNU Icecat 5# Firejail profile for GNU Icecat
6noblacklist ~/.mozilla 6noblacklist ~/.mozilla
7noblacklist ~/.cache/mozilla
7noblacklist ~/.pki 8noblacklist ~/.pki
8noblacklist ~/.lastpass 9noblacklist ~/.lastpass
9include /etc/firejail/disable-common.inc 10include /etc/firejail/disable-common.inc
@@ -21,6 +22,8 @@ tracelog
21whitelist ${DOWNLOADS} 22whitelist ${DOWNLOADS}
22mkdir ~/.mozilla 23mkdir ~/.mozilla
23whitelist ~/.mozilla 24whitelist ~/.mozilla
25mkdir ~/.cache/mozilla/icecat
26whitelist ~/.cache/mozilla/icecat
24whitelist ~/dwhelper 27whitelist ~/dwhelper
25whitelist ~/.zotero 28whitelist ~/.zotero
26whitelist ~/.vimperatorrc 29whitelist ~/.vimperatorrc
@@ -29,6 +32,7 @@ whitelist ~/.pentadactylrc
29whitelist ~/.pentadactyl 32whitelist ~/.pentadactyl
30whitelist ~/.keysnail.js 33whitelist ~/.keysnail.js
31whitelist ~/.config/gnome-mplayer 34whitelist ~/.config/gnome-mplayer
35whitelist ~/.cache/gnome-mplayer/plugin
32whitelist ~/.pki 36whitelist ~/.pki
33whitelist ~/.lastpass 37whitelist ~/.lastpass
34 38
diff --git a/etc/icedove.profile b/etc/icedove.profile
index aae0e3bf5..b5265e992 100644
--- a/etc/icedove.profile
+++ b/etc/icedove.profile
@@ -14,6 +14,10 @@ noblacklist ~/.icedove
14mkdir ~/.icedove 14mkdir ~/.icedove
15whitelist ~/.icedove 15whitelist ~/.icedove
16 16
17noblacklist ~/.cache/icedove
18mkdir ~/.cache/icedove
19whitelist ~/.cache/icedove
20
17# allow browsers 21# allow browsers
18ignore private-tmp 22ignore private-tmp
19include /etc/firejail/firefox.profile 23include /etc/firejail/firefox.profile
diff --git a/etc/inox.profile b/etc/inox.profile
index 6043ded8a..0b2e4ee5e 100644
--- a/etc/inox.profile
+++ b/etc/inox.profile
@@ -4,6 +4,7 @@ include /etc/firejail/inox.local
4 4
5# Inox browser profile 5# Inox browser profile
6noblacklist ~/.config/inox 6noblacklist ~/.config/inox
7noblacklist ~/.cache/inox
7noblacklist ~/.pki 8noblacklist ~/.pki
8include /etc/firejail/disable-common.inc 9include /etc/firejail/disable-common.inc
9include /etc/firejail/disable-programs.inc 10include /etc/firejail/disable-programs.inc
@@ -13,6 +14,8 @@ netfilter
13whitelist ${DOWNLOADS} 14whitelist ${DOWNLOADS}
14mkdir ~/.config/inox 15mkdir ~/.config/inox
15whitelist ~/.config/inox 16whitelist ~/.config/inox
17mkdir ~/.cache/inox
18whitelist ~/.cache/inox
16mkdir ~/.pki 19mkdir ~/.pki
17whitelist ~/.pki 20whitelist ~/.pki
18 21
diff --git a/etc/iridium.profile b/etc/iridium.profile
index dcbd0b84b..2d79a3935 100644
--- a/etc/iridium.profile
+++ b/etc/iridium.profile
@@ -4,6 +4,7 @@ include /etc/firejail/iridium.local
4 4
5# Iridium browser profile 5# Iridium browser profile
6noblacklist ~/.config/iridium 6noblacklist ~/.config/iridium
7noblacklist ~/.cache/iridium
7include /etc/firejail/disable-common.inc 8include /etc/firejail/disable-common.inc
8include /etc/firejail/disable-programs.inc 9include /etc/firejail/disable-programs.inc
9 10
@@ -16,6 +17,8 @@ netfilter
16whitelist ${DOWNLOADS} 17whitelist ${DOWNLOADS}
17mkdir ~/.config/iridium 18mkdir ~/.config/iridium
18whitelist ~/.config/iridium 19whitelist ~/.config/iridium
20mkdir ~/.cache/iridium
21whitelist ~/.cache/iridium
19mkdir ~/.pki 22mkdir ~/.pki
20whitelist ~/.pki 23whitelist ~/.pki
21 24
diff --git a/etc/mutt.profile b/etc/mutt.profile
index f9d537779..2f0809f02 100644
--- a/etc/mutt.profile
+++ b/etc/mutt.profile
@@ -14,6 +14,7 @@ noblacklist ~/mail
14noblacklist ~/Mail 14noblacklist ~/Mail
15noblacklist ~/sent 15noblacklist ~/sent
16noblacklist ~/postponed 16noblacklist ~/postponed
17noblacklist ~/.cache/mutt
17noblacklist ~/.w3m 18noblacklist ~/.w3m
18noblacklist ~/.elinks 19noblacklist ~/.elinks
19noblacklist ~/.vim 20noblacklist ~/.vim
diff --git a/etc/netsurf.profile b/etc/netsurf.profile
index a3c360c1e..c217346de 100644
--- a/etc/netsurf.profile
+++ b/etc/netsurf.profile
@@ -4,6 +4,7 @@ include /etc/firejail/netsurf.local
4 4
5# Firejail profile for Mozilla Firefox (Iceweasel in Debian) 5# Firejail profile for Mozilla Firefox (Iceweasel in Debian)
6noblacklist ~/.config/netsurf 6noblacklist ~/.config/netsurf
7noblacklist ~/.cache/netsurf
7include /etc/firejail/disable-common.inc 8include /etc/firejail/disable-common.inc
8include /etc/firejail/disable-programs.inc 9include /etc/firejail/disable-programs.inc
9include /etc/firejail/disable-devel.inc 10include /etc/firejail/disable-devel.inc
@@ -19,5 +20,7 @@ tracelog
19whitelist ${DOWNLOADS} 20whitelist ${DOWNLOADS}
20mkdir ~/.config/netsurf 21mkdir ~/.config/netsurf
21whitelist ~/.config/netsurf 22whitelist ~/.config/netsurf
23mkdir ~/.cache/netsurf
24whitelist ~/.cache/netsurf
22 25
23include /etc/firejail/whitelist-common.inc 26include /etc/firejail/whitelist-common.inc
diff --git a/etc/opera-beta.profile b/etc/opera-beta.profile
index 5a0d54744..2782ce8e6 100644
--- a/etc/opera-beta.profile
+++ b/etc/opera-beta.profile
@@ -14,6 +14,8 @@ netfilter
14whitelist ${DOWNLOADS} 14whitelist ${DOWNLOADS}
15mkdir ~/.config/opera-beta 15mkdir ~/.config/opera-beta
16whitelist ~/.config/opera-beta 16whitelist ~/.config/opera-beta
17mkdir ~/.cache/opera
18whitelist ~/.cache/opera
17mkdir ~/.pki 19mkdir ~/.pki
18whitelist ~/.pki 20whitelist ~/.pki
19include /etc/firejail/whitelist-common.inc 21include /etc/firejail/whitelist-common.inc
diff --git a/etc/opera.profile b/etc/opera.profile
index 4af502060..f903108b3 100644
--- a/etc/opera.profile
+++ b/etc/opera.profile
@@ -5,6 +5,7 @@ include /etc/firejail/opera.local
5# Opera browser profile 5# Opera browser profile
6noblacklist ~/.config/opera 6noblacklist ~/.config/opera
7noblacklist ~/.opera 7noblacklist ~/.opera
8noblacklist ~/.cache/opera
8noblacklist ~/.pki 9noblacklist ~/.pki
9include /etc/firejail/disable-common.inc 10include /etc/firejail/disable-common.inc
10include /etc/firejail/disable-programs.inc 11include /etc/firejail/disable-programs.inc
@@ -16,6 +17,8 @@ whitelist ${DOWNLOADS}
16mkdir ~/.config/opera 17mkdir ~/.config/opera
17whitelist ~/.config/opera 18whitelist ~/.config/opera
18mkdir ~/.opera 19mkdir ~/.opera
20mkdir ~/.cache/opera
21whitelist ~/.cache/opera
19whitelist ~/.opera 22whitelist ~/.opera
20mkdir ~/.pki 23mkdir ~/.pki
21whitelist ~/.pki 24whitelist ~/.pki
diff --git a/etc/palemoon.profile b/etc/palemoon.profile
index 472d58cee..8cac00e03 100644
--- a/etc/palemoon.profile
+++ b/etc/palemoon.profile
@@ -4,6 +4,7 @@ include /etc/firejail/palemoon.local
4 4
5# Firejail profile for Pale Moon 5# Firejail profile for Pale Moon
6noblacklist ~/.moonchild productions/pale moon 6noblacklist ~/.moonchild productions/pale moon
7noblacklist ~/.cache/moonchild productions/pale moon
7include /etc/firejail/disable-common.inc 8include /etc/firejail/disable-common.inc
8include /etc/firejail/disable-programs.inc 9include /etc/firejail/disable-programs.inc
9include /etc/firejail/disable-devel.inc 10include /etc/firejail/disable-devel.inc
@@ -12,6 +13,8 @@ include /etc/firejail/whitelist-common.inc
12whitelist ${DOWNLOADS} 13whitelist ${DOWNLOADS}
13mkdir ~/.moonchild productions 14mkdir ~/.moonchild productions
14whitelist ~/.moonchild productions 15whitelist ~/.moonchild productions
16mkdir ~/.cache/moonchild productions/pale moon
17whitelist ~/.cache/moonchild productions/pale moon
15 18
16caps.drop all 19caps.drop all
17netfilter 20netfilter
@@ -37,6 +40,7 @@ private-tmp
37#whitelist ~/.pentadactyl 40#whitelist ~/.pentadactyl
38#whitelist ~/.keysnail.js 41#whitelist ~/.keysnail.js
39#whitelist ~/.config/gnome-mplayer 42#whitelist ~/.config/gnome-mplayer
43#whitelist ~/.cache/gnome-mplayer/plugin
40#whitelist ~/.pki 44#whitelist ~/.pki
41#whitelist ~/.lastpass 45#whitelist ~/.lastpass
42 46
diff --git a/etc/polari.profile b/etc/polari.profile
index 52a58322e..834a8b3d6 100644
--- a/etc/polari.profile
+++ b/etc/polari.profile
@@ -15,6 +15,8 @@ mkdir ${HOME}/.local/share/TpLogger
15whitelist ${HOME}/.local/share/TpLogger 15whitelist ${HOME}/.local/share/TpLogger
16mkdir ${HOME}/.config/telepathy-account-widgets 16mkdir ${HOME}/.config/telepathy-account-widgets
17whitelist ${HOME}/.config/telepathy-account-widgets 17whitelist ${HOME}/.config/telepathy-account-widgets
18mkdir ${HOME}/.cache/telepathy
19whitelist ${HOME}/.cache/telepathy
18mkdir ${HOME}/.purple 20mkdir ${HOME}/.purple
19whitelist ${HOME}/.purple 21whitelist ${HOME}/.purple
20include /etc/firejail/whitelist-common.inc 22include /etc/firejail/whitelist-common.inc
diff --git a/etc/psi-plus.profile b/etc/psi-plus.profile
index 5106fccb2..45cb22ee4 100644
--- a/etc/psi-plus.profile
+++ b/etc/psi-plus.profile
@@ -14,6 +14,8 @@ mkdir ~/.config/psi+
14whitelist ~/.config/psi+ 14whitelist ~/.config/psi+
15mkdir ~/.local/share/psi+ 15mkdir ~/.local/share/psi+
16whitelist ~/.local/share/psi+ 16whitelist ~/.local/share/psi+
17mkdir ~/.cache/psi+
18whitelist ~/.cache/psi+
17 19
18caps.drop all 20caps.drop all
19netfilter 21netfilter
diff --git a/etc/quiterss.profile b/etc/quiterss.profile
index 158425e18..f4e4f96d3 100644
--- a/etc/quiterss.profile
+++ b/etc/quiterss.profile
@@ -2,6 +2,7 @@
2# Persistent customizations should go in a .local file. 2# Persistent customizations should go in a .local file.
3include /etc/firejail/quiterss.local 3include /etc/firejail/quiterss.local
4 4
5noblacklist ${HOME}/.cache/QuiteRss
5noblacklist ${HOME}/.config/QuiteRss 6noblacklist ${HOME}/.config/QuiteRss
6noblacklist ${HOME}/.config/QuiteRssrc 7noblacklist ${HOME}/.config/QuiteRssrc
7noblacklist ${HOME}/.local/share/QuiteRss 8noblacklist ${HOME}/.local/share/QuiteRss
@@ -18,6 +19,8 @@ whitelist ${HOME}/.config/QuiteRssrc
18mkdir ~/.local/share/data 19mkdir ~/.local/share/data
19mkdir ~/.local/share/data/QuiteRss 20mkdir ~/.local/share/data/QuiteRss
20whitelist ${HOME}/.local/share/data/QuiteRss 21whitelist ${HOME}/.local/share/data/QuiteRss
22mkdir ~/.cache/QuiteRss
23whitelist ${HOME}/.cache/QuiteRss
21 24
22caps.drop all 25caps.drop all
23netfilter 26netfilter
diff --git a/etc/qupzilla.profile b/etc/qupzilla.profile
index 783bc516d..3f5cb60c0 100644
--- a/etc/qupzilla.profile
+++ b/etc/qupzilla.profile
@@ -4,6 +4,7 @@ include /etc/firejail/qupzilla.local
4 4
5# Firejail profile for Qupzilla web browser 5# Firejail profile for Qupzilla web browser
6noblacklist ${HOME}/.config/qupzilla 6noblacklist ${HOME}/.config/qupzilla
7noblacklist ${HOME}/.cache/qupzilla
7include /etc/firejail/disable-mgmt.inc 8include /etc/firejail/disable-mgmt.inc
8include /etc/firejail/disable-secret.inc 9include /etc/firejail/disable-secret.inc
9include /etc/firejail/disable-common.inc 10include /etc/firejail/disable-common.inc
@@ -16,6 +17,7 @@ tracelog
16noroot 17noroot
17whitelist ${DOWNLOADS} 18whitelist ${DOWNLOADS}
18whitelist ~/.config/qupzilla 19whitelist ~/.config/qupzilla
20whitelist ~/.cache/qupzilla
19include /etc/firejail/whitelist-common.inc 21include /etc/firejail/whitelist-common.inc
20 22
21# experimental features 23# experimental features
diff --git a/etc/qutebrowser.profile b/etc/qutebrowser.profile
index 53be1178c..f43307ef9 100644
--- a/etc/qutebrowser.profile
+++ b/etc/qutebrowser.profile
@@ -4,6 +4,7 @@ include /etc/firejail/qutebrowser.local
4 4
5# Firejail profile for Qutebrowser (Qt5-Webkit+Python) browser 5# Firejail profile for Qutebrowser (Qt5-Webkit+Python) browser
6noblacklist ~/.config/qutebrowser 6noblacklist ~/.config/qutebrowser
7noblacklist ~/.cache/qutebrowser
7include /etc/firejail/disable-common.inc 8include /etc/firejail/disable-common.inc
8include /etc/firejail/disable-programs.inc 9include /etc/firejail/disable-programs.inc
9include /etc/firejail/disable-devel.inc 10include /etc/firejail/disable-devel.inc
@@ -19,6 +20,8 @@ tracelog
19whitelist ${DOWNLOADS} 20whitelist ${DOWNLOADS}
20mkdir ~/.config/qutebrowser 21mkdir ~/.config/qutebrowser
21whitelist ~/.config/qutebrowser 22whitelist ~/.config/qutebrowser
23mkdir ~/.cache/qutebrowser
24whitelist ~/.cache/qutebrowser
22mkdir ~/.local/share/qutebrowser 25mkdir ~/.local/share/qutebrowser
23whitelist ~/.local/share/qutebrowser 26whitelist ~/.local/share/qutebrowser
24include /etc/firejail/whitelist-common.inc 27include /etc/firejail/whitelist-common.inc
diff --git a/etc/seamonkey.profile b/etc/seamonkey.profile
index 756700c2f..df1910469 100644
--- a/etc/seamonkey.profile
+++ b/etc/seamonkey.profile
@@ -4,6 +4,7 @@ include /etc/firejail/seamonkey.local
4 4
5# Firejail profile for Seamoneky based off Mozilla Firefox 5# Firejail profile for Seamoneky based off Mozilla Firefox
6noblacklist ~/.mozilla 6noblacklist ~/.mozilla
7noblacklist ~/.cache/mozilla
7noblacklist ~/.pki 8noblacklist ~/.pki
8noblacklist ~/.lastpass 9noblacklist ~/.lastpass
9include /etc/firejail/disable-common.inc 10include /etc/firejail/disable-common.inc
@@ -21,6 +22,8 @@ tracelog
21whitelist ${DOWNLOADS} 22whitelist ${DOWNLOADS}
22mkdir ~/.mozilla/seamonkey 23mkdir ~/.mozilla/seamonkey
23whitelist ~/.mozilla/seamonkey 24whitelist ~/.mozilla/seamonkey
25mkdir ~/.cache/mozilla/seamonkey
26whitelist ~/.cache/mozilla/seamonkey
24whitelist ~/dwhelper 27whitelist ~/dwhelper
25whitelist ~/.zotero 28whitelist ~/.zotero
26whitelist ~/.vimperatorrc 29whitelist ~/.vimperatorrc
@@ -29,6 +32,7 @@ whitelist ~/.pentadactylrc
29whitelist ~/.pentadactyl 32whitelist ~/.pentadactyl
30whitelist ~/.keysnail.js 33whitelist ~/.keysnail.js
31whitelist ~/.config/gnome-mplayer 34whitelist ~/.config/gnome-mplayer
35whitelist ~/.cache/gnome-mplayer/plugin
32whitelist ~/.pki 36whitelist ~/.pki
33whitelist ~/.lastpass 37whitelist ~/.lastpass
34include /etc/firejail/whitelist-common.inc 38include /etc/firejail/whitelist-common.inc
diff --git a/etc/simple-scan.profile b/etc/simple-scan.profile
index 0f6d626a5..ee7e50ba7 100644
--- a/etc/simple-scan.profile
+++ b/etc/simple-scan.profile
@@ -3,6 +3,8 @@
3include /etc/firejail/simple-scan.local 3include /etc/firejail/simple-scan.local
4 4
5# simple-scan profile 5# simple-scan profile
6noblacklist ~/.cache/simple-scan
7
6include /etc/firejail/disable-common.inc 8include /etc/firejail/disable-common.inc
7include /etc/firejail/disable-programs.inc 9include /etc/firejail/disable-programs.inc
8include /etc/firejail/disable-devel.inc 10include /etc/firejail/disable-devel.inc
diff --git a/etc/spotify.profile b/etc/spotify.profile
index 23ef75b71..843038a2b 100644
--- a/etc/spotify.profile
+++ b/etc/spotify.profile
@@ -4,6 +4,7 @@ include /etc/firejail/spotify.local
4 4
5# Spotify media player profile 5# Spotify media player profile
6noblacklist ${HOME}/.config/spotify 6noblacklist ${HOME}/.config/spotify
7noblacklist ${HOME}/.cache/spotify
7noblacklist ${HOME}/.local/share/spotify 8noblacklist ${HOME}/.local/share/spotify
8include /etc/firejail/disable-common.inc 9include /etc/firejail/disable-common.inc
9include /etc/firejail/disable-programs.inc 10include /etc/firejail/disable-programs.inc
@@ -15,6 +16,8 @@ mkdir ${HOME}/.config/spotify
15whitelist ${HOME}/.config/spotify 16whitelist ${HOME}/.config/spotify
16mkdir ${HOME}/.local/share/spotify 17mkdir ${HOME}/.local/share/spotify
17whitelist ${HOME}/.local/share/spotify 18whitelist ${HOME}/.local/share/spotify
19mkdir ${HOME}/.cache/spotify
20whitelist ${HOME}/.cache/spotify
18 21
19caps.drop all 22caps.drop all
20netfilter 23netfilter
diff --git a/etc/thunderbird.profile b/etc/thunderbird.profile
index df1a4cdbb..64fe92c1e 100644
--- a/etc/thunderbird.profile
+++ b/etc/thunderbird.profile
@@ -18,6 +18,10 @@ noblacklist ~/.icedove
18mkdir ~/.icedove 18mkdir ~/.icedove
19whitelist ~/.icedove 19whitelist ~/.icedove
20 20
21noblacklist ~/.cache/thunderbird
22mkdir ~/.cache/thunderbird
23whitelist ~/.cache/thunderbird
24
21# allow browsers 25# allow browsers
22ignore private-tmp 26ignore private-tmp
23include /etc/firejail/firefox.profile 27include /etc/firejail/firefox.profile
diff --git a/etc/transmission-cli.profile b/etc/transmission-cli.profile
index 5b6bec4c1..dbcc8d041 100644
--- a/etc/transmission-cli.profile
+++ b/etc/transmission-cli.profile
@@ -4,6 +4,7 @@ include /etc/firejail/transmission-cli.local
4 4
5# transmission-cli bittorrent profile 5# transmission-cli bittorrent profile
6noblacklist ${HOME}/.config/transmission 6noblacklist ${HOME}/.config/transmission
7noblacklist ${HOME}/.cache/transmission
7 8
8include /etc/firejail/disable-common.inc 9include /etc/firejail/disable-common.inc
9include /etc/firejail/disable-programs.inc 10include /etc/firejail/disable-programs.inc
diff --git a/etc/transmission-gtk.profile b/etc/transmission-gtk.profile
index 78ce5fba2..dcd3317ef 100644
--- a/etc/transmission-gtk.profile
+++ b/etc/transmission-gtk.profile
@@ -4,6 +4,7 @@ include /etc/firejail/transmission-gtk.local
4 4
5# transmission-gtk bittorrent profile 5# transmission-gtk bittorrent profile
6noblacklist ${HOME}/.config/transmission 6noblacklist ${HOME}/.config/transmission
7noblacklist ${HOME}/.cache/transmission
7 8
8include /etc/firejail/disable-common.inc 9include /etc/firejail/disable-common.inc
9include /etc/firejail/disable-programs.inc 10include /etc/firejail/disable-programs.inc
diff --git a/etc/transmission-qt.profile b/etc/transmission-qt.profile
index 2f7fe0714..ed63f7cff 100644
--- a/etc/transmission-qt.profile
+++ b/etc/transmission-qt.profile
@@ -4,6 +4,7 @@ include /etc/firejail/transmission-qt.local
4 4
5# transmission-qt bittorrent profile 5# transmission-qt bittorrent profile
6noblacklist ${HOME}/.config/transmission 6noblacklist ${HOME}/.config/transmission
7noblacklist ${HOME}/.cache/transmission
7 8
8include /etc/firejail/disable-common.inc 9include /etc/firejail/disable-common.inc
9include /etc/firejail/disable-programs.inc 10include /etc/firejail/disable-programs.inc
diff --git a/etc/transmission-show.profile b/etc/transmission-show.profile
index 052843882..0b88789b1 100644
--- a/etc/transmission-show.profile
+++ b/etc/transmission-show.profile
@@ -4,6 +4,7 @@ include /etc/firejail/transmission-show.local
4 4
5# transmission-show profile 5# transmission-show profile
6noblacklist ${HOME}/.config/transmission 6noblacklist ${HOME}/.config/transmission
7noblacklist ${HOME}/.cache/transmission
7 8
8include /etc/firejail/disable-common.inc 9include /etc/firejail/disable-common.inc
9include /etc/firejail/disable-programs.inc 10include /etc/firejail/disable-programs.inc
diff --git a/etc/vivaldi.profile b/etc/vivaldi.profile
index bf6af3926..7ab2e5f70 100644
--- a/etc/vivaldi.profile
+++ b/etc/vivaldi.profile
@@ -1,6 +1,7 @@
1# This file is overwritten during software install. 1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file. 2# Persistent customizations should go in a .local file.
3include /etc/firejail/vivaldi.local 3include /etc/firejail/vivaldi.local
4noblacklist ~/.cache/vivaldi
4 5
5# Vivaldi browser profile 6# Vivaldi browser profile
6noblacklist ~/.config/vivaldi 7noblacklist ~/.config/vivaldi
@@ -13,4 +14,6 @@ netfilter
13whitelist ${DOWNLOADS} 14whitelist ${DOWNLOADS}
14mkdir ~/.config/vivaldi 15mkdir ~/.config/vivaldi
15whitelist ~/.config/vivaldi 16whitelist ~/.config/vivaldi
17mkdir ~/.cache/vivaldi
18whitelist ~/.cache/vivaldi
16include /etc/firejail/whitelist-common.inc 19include /etc/firejail/whitelist-common.inc
diff --git a/etc/wesnoth.profile b/etc/wesnoth.profile
index fbb381a86..212466f5a 100644
--- a/etc/wesnoth.profile
+++ b/etc/wesnoth.profile
@@ -4,6 +4,7 @@ include /etc/firejail/wesnoth.local
4 4
5# Whitelist-based profile for "Battle for Wesnoth" (game). 5# Whitelist-based profile for "Battle for Wesnoth" (game).
6noblacklist ${HOME}/.config/wesnoth 6noblacklist ${HOME}/.config/wesnoth
7noblacklist ${HOME}/.cache/wesnoth
7noblacklist ${HOME}/.local/share/wesnoth 8noblacklist ${HOME}/.local/share/wesnoth
8 9
9include /etc/firejail/disable-common.inc 10include /etc/firejail/disable-common.inc
@@ -22,6 +23,8 @@ private-tmp
22 23
23mkdir ${HOME}/.local/share/wesnoth 24mkdir ${HOME}/.local/share/wesnoth
24mkdir ${HOME}/.config/wesnoth 25mkdir ${HOME}/.config/wesnoth
26mkdir ${HOME}/.cache/wesnoth
25whitelist ${HOME}/.local/share/wesnoth 27whitelist ${HOME}/.local/share/wesnoth
26whitelist ${HOME}/.config/wesnoth 28whitelist ${HOME}/.config/wesnoth
29whitelist ${HOME}/.cache/wesnoth
27include /etc/firejail/whitelist-common.inc 30include /etc/firejail/whitelist-common.inc
diff --git a/etc/whitelist-common.inc b/etc/whitelist-common.inc
index 516f47041..cf7797100 100644
--- a/etc/whitelist-common.inc
+++ b/etc/whitelist-common.inc
@@ -19,6 +19,7 @@ whitelist ~/.fonts.conf
19whitelist ~/.fonts.conf.d 19whitelist ~/.fonts.conf.d
20whitelist ~/.local/share/fonts 20whitelist ~/.local/share/fonts
21whitelist ~/.config/fontconfig 21whitelist ~/.config/fontconfig
22whitelist ~/.cache/fontconfig
22 23
23# gtk 24# gtk
24whitelist ~/.gtkrc 25whitelist ~/.gtkrc
diff --git a/etc/xreader.profile b/etc/xreader.profile
index 51dbcad51..31ea14ca3 100644
--- a/etc/xreader.profile
+++ b/etc/xreader.profile
@@ -5,6 +5,7 @@ include /etc/firejail/xreader.local
5# Xreader profile 5# Xreader profile
6noblacklist ~/.config/xreader 6noblacklist ~/.config/xreader
7noblacklist ~/.local/share 7noblacklist ~/.local/share
8noblacklist ~/.cache/xreader
8 9
9include /etc/firejail/disable-common.inc 10include /etc/firejail/disable-common.inc
10include /etc/firejail/disable-programs.inc 11include /etc/firejail/disable-programs.inc