aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLibravatar netblue30 <netblue30@protonmail.com>2023-01-31 18:01:21 -0500
committerLibravatar GitHub <noreply@github.com>2023-01-31 18:01:21 -0500
commita185042808b99d22b3e644506fd7d3418b99a344 (patch)
treea930a7c278282e4ee178c31c1f843df880a67443
parentMerge pull request #5630 from glitsj16/warzone2100 (diff)
parentinkscape: rebase and drop mdwe comment (diff)
downloadfirejail-a185042808b99d22b3e644506fd7d3418b99a344.tar.gz
firejail-a185042808b99d22b3e644506fd7d3418b99a344.tar.zst
firejail-a185042808b99d22b3e644506fd7d3418b99a344.zip
Merge pull request #5631 from glitsj16/inkscape
inkscape: additional hardening and settings saving via D-Bus
-rw-r--r--etc/profile-a-l/inkscape.profile18
1 files changed, 15 insertions, 3 deletions
diff --git a/etc/profile-a-l/inkscape.profile b/etc/profile-a-l/inkscape.profile
index abe75f2ae..c4fc16c87 100644
--- a/etc/profile-a-l/inkscape.profile
+++ b/etc/profile-a-l/inkscape.profile
@@ -16,7 +16,6 @@ noblacklist ${PICTURES}
16noblacklist ${HOME}/.config/GIMP 16noblacklist ${HOME}/.config/GIMP
17noblacklist ${HOME}/.gimp* 17noblacklist ${HOME}/.gimp*
18 18
19
20# Allow python (blacklisted by disable-interpreters.inc) 19# Allow python (blacklisted by disable-interpreters.inc)
21include allow-python2.inc 20include allow-python2.inc
22include allow-python3.inc 21include allow-python3.inc
@@ -28,8 +27,19 @@ include disable-interpreters.inc
28include disable-programs.inc 27include disable-programs.inc
29include disable-xdg.inc 28include disable-xdg.inc
30 29
30mkdir ${HOME}/.cache/inkscape
31mkdir ${HOME}/.config/inkscape
32mkdir ${HOME}/.inkscape
33whitelist ${DOCUMENTS}
34whitelist ${DOWNLOADS}
35whitelist ${PICTURES}
36whitelist ${HOME}/.cache/inkscape
37whitelist ${HOME}/.config/inkscape
38whitelist ${HOME}/.inkscape
31whitelist /usr/share/inkscape 39whitelist /usr/share/inkscape
40include whitelist-common.inc
32include whitelist-run-common.inc 41include whitelist-run-common.inc
42include whitelist-runuser-common.inc
33include whitelist-usr-share-common.inc 43include whitelist-usr-share-common.inc
34include whitelist-var-common.inc 44include whitelist-var-common.inc
35 45
@@ -57,8 +67,10 @@ private-dev
57private-etc @x11,ImageMagick*,python* 67private-etc @x11,ImageMagick*,python*
58private-tmp 68private-tmp
59 69
60dbus-user none 70dbus-user filter
71dbus-user.own org.inkscape.Inkscape
72dbus-user.talk ca.desrt.dconf
73dbus-user.talk org.gtk.vfs.*
61dbus-system none 74dbus-system none
62 75
63# memory-deny-write-execute
64restrict-namespaces 76restrict-namespaces