aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLibravatar SYN-cook <syncookongit@gmail.com>2017-03-31 16:24:38 +0200
committerLibravatar Fred Barclay <Fred-Barclay@users.noreply.github.com>2017-03-31 14:24:38 +0000
commitba85fa81088a0b468f3fb98d96b535f8d07989c8 (patch)
treebef5910fdcbc1b393079b61cc11782f50f3a3017
parentrestrict more KDE files (#1181) (diff)
downloadfirejail-ba85fa81088a0b468f3fb98d96b535f8d07989c8.tar.gz
firejail-ba85fa81088a0b468f3fb98d96b535f8d07989c8.tar.zst
firejail-ba85fa81088a0b468f3fb98d96b535f8d07989c8.zip
tidy up (#1182)
* minor reorganization * tidy up * tidy up * tidy up * tidy up * tidy up * tidy up
-rw-r--r--etc/abrowser.profile1
-rw-r--r--etc/cyberfox.profile1
-rw-r--r--etc/disable-common.inc11
-rw-r--r--etc/firefox.profile1
-rw-r--r--etc/icecat.profile1
-rw-r--r--etc/midori.profile1
-rw-r--r--etc/seamonkey.profile1
7 files changed, 7 insertions, 10 deletions
diff --git a/etc/abrowser.profile b/etc/abrowser.profile
index b9a30d6bf..e53796fa2 100644
--- a/etc/abrowser.profile
+++ b/etc/abrowser.profile
@@ -6,7 +6,6 @@ include /etc/firejail/abrowser.local
6noblacklist ~/.mozilla 6noblacklist ~/.mozilla
7noblacklist ~/.cache/mozilla 7noblacklist ~/.cache/mozilla
8noblacklist ~/.pki 8noblacklist ~/.pki
9noblacklist ~/.lastpass
10include /etc/firejail/disable-common.inc 9include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-programs.inc 10include /etc/firejail/disable-programs.inc
12include /etc/firejail/disable-devel.inc 11include /etc/firejail/disable-devel.inc
diff --git a/etc/cyberfox.profile b/etc/cyberfox.profile
index a79303f77..c51c2f4f9 100644
--- a/etc/cyberfox.profile
+++ b/etc/cyberfox.profile
@@ -6,7 +6,6 @@ include /etc/firejail/cyberfox.local
6noblacklist ~/.8pecxstudios 6noblacklist ~/.8pecxstudios
7noblacklist ~/.cache/8pecxstudios 7noblacklist ~/.cache/8pecxstudios
8noblacklist ~/.pki 8noblacklist ~/.pki
9noblacklist ~/.lastpass
10include /etc/firejail/disable-common.inc 9include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-programs.inc 10include /etc/firejail/disable-programs.inc
12include /etc/firejail/disable-devel.inc 11include /etc/firejail/disable-devel.inc
diff --git a/etc/disable-common.inc b/etc/disable-common.inc
index 0ada3314f..451203865 100644
--- a/etc/disable-common.inc
+++ b/etc/disable-common.inc
@@ -6,11 +6,8 @@ include /etc/firejail/disable-common.local
6blacklist-nolog ${HOME}/.history 6blacklist-nolog ${HOME}/.history
7blacklist-nolog ${HOME}/.*_history 7blacklist-nolog ${HOME}/.*_history
8blacklist-nolog ${HOME}/.bash_history 8blacklist-nolog ${HOME}/.bash_history
9blacklist ${HOME}/.local/share/systemd
10blacklist ${HOME}/.config/systemd
11blacklist-nolog ${HOME}/.adobe 9blacklist-nolog ${HOME}/.adobe
12blacklist-nolog ${HOME}/.macromedia 10blacklist-nolog ${HOME}/.macromedia
13read-only ${HOME}/.local/share/applications
14 11
15# X11 session autostart 12# X11 session autostart
16blacklist ${HOME}/.xinitrc 13blacklist ${HOME}/.xinitrc
@@ -74,6 +71,10 @@ blacklist ${HOME}/.local/share/kservices5
74blacklist ${HOME}/.local/share/plasma 71blacklist ${HOME}/.local/share/plasma
75blacklist ${HOME}/.local/share/solid 72blacklist ${HOME}/.local/share/solid
76 73
74# systemd
75blacklist ${HOME}/.local/share/systemd
76blacklist ${HOME}/.config/systemd
77
77# VirtualBox 78# VirtualBox
78blacklist ${HOME}/.VirtualBox 79blacklist ${HOME}/.VirtualBox
79blacklist ${HOME}/VirtualBox VMs 80blacklist ${HOME}/VirtualBox VMs
@@ -177,9 +178,11 @@ read-only ${HOME}/.luarocks
177read-only ${HOME}/.npm-packages 178read-only ${HOME}/.npm-packages
178 179
179# Make the contents of ~/.local read-only, 180# Make the contents of ~/.local read-only,
180# except the commonly-used ~/.local/share 181# except the commonly-used ~/.local/share,
182# but including ~/.local/share/applications
181read-only ${HOME}/.local 183read-only ${HOME}/.local
182read-write ${HOME}/.local/share 184read-write ${HOME}/.local/share
185read-only ${HOME}/.local/share/applications
183 186
184# top secret 187# top secret
185blacklist ${HOME}/.ecryptfs 188blacklist ${HOME}/.ecryptfs
diff --git a/etc/firefox.profile b/etc/firefox.profile
index 5f852d4c0..bd9d37560 100644
--- a/etc/firefox.profile
+++ b/etc/firefox.profile
@@ -10,7 +10,6 @@ noblacklist ~/.local/share/qpdfview
10noblacklist ~/.kde4/share/apps/okular 10noblacklist ~/.kde4/share/apps/okular
11noblacklist ~/.kde/share/apps/okular 11noblacklist ~/.kde/share/apps/okular
12noblacklist ~/.pki 12noblacklist ~/.pki
13noblacklist ~/.lastpass
14include /etc/firejail/disable-common.inc 13include /etc/firejail/disable-common.inc
15include /etc/firejail/disable-programs.inc 14include /etc/firejail/disable-programs.inc
16include /etc/firejail/disable-devel.inc 15include /etc/firejail/disable-devel.inc
diff --git a/etc/icecat.profile b/etc/icecat.profile
index 64401efe8..0611f5259 100644
--- a/etc/icecat.profile
+++ b/etc/icecat.profile
@@ -6,7 +6,6 @@ include /etc/firejail/icecat.local
6noblacklist ~/.mozilla 6noblacklist ~/.mozilla
7noblacklist ~/.cache/mozilla 7noblacklist ~/.cache/mozilla
8noblacklist ~/.pki 8noblacklist ~/.pki
9noblacklist ~/.lastpass
10include /etc/firejail/disable-common.inc 9include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-programs.inc 10include /etc/firejail/disable-programs.inc
12include /etc/firejail/disable-devel.inc 11include /etc/firejail/disable-devel.inc
diff --git a/etc/midori.profile b/etc/midori.profile
index a0bcb808c..aef61fa9f 100644
--- a/etc/midori.profile
+++ b/etc/midori.profile
@@ -8,7 +8,6 @@ noblacklist ~/.local/share/midori
8noblacklist ~/.local/share/webkit 8noblacklist ~/.local/share/webkit
9noblacklist ~/.local/share/webkitgtk 9noblacklist ~/.local/share/webkitgtk
10noblacklist ~/.pki 10noblacklist ~/.pki
11noblacklist ~/.lastpass
12include /etc/firejail/disable-common.inc 11include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-programs.inc 12include /etc/firejail/disable-programs.inc
14include /etc/firejail/disable-devel.inc 13include /etc/firejail/disable-devel.inc
diff --git a/etc/seamonkey.profile b/etc/seamonkey.profile
index df1910469..afac0ff88 100644
--- a/etc/seamonkey.profile
+++ b/etc/seamonkey.profile
@@ -6,7 +6,6 @@ include /etc/firejail/seamonkey.local
6noblacklist ~/.mozilla 6noblacklist ~/.mozilla
7noblacklist ~/.cache/mozilla 7noblacklist ~/.cache/mozilla
8noblacklist ~/.pki 8noblacklist ~/.pki
9noblacklist ~/.lastpass
10include /etc/firejail/disable-common.inc 9include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-programs.inc 10include /etc/firejail/disable-programs.inc
12include /etc/firejail/disable-devel.inc 11include /etc/firejail/disable-devel.inc