aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLibravatar netblue30 <netblue30@protonmail.com>2021-07-05 07:23:31 -0400
committerLibravatar netblue30 <netblue30@protonmail.com>2021-07-05 07:23:31 -0400
commitfe0f975f447d59977d90c3226cc8c623b31b20b3 (patch)
tree70897a33cde6c716e273d927d18a6be4b54c18a9
parentdeprecated whitelist=yes/no in /etc/firejail/firejail.config (diff)
downloadfirejail-fe0f975f447d59977d90c3226cc8c623b31b20b3.tar.gz
firejail-fe0f975f447d59977d90c3226cc8c623b31b20b3.tar.zst
firejail-fe0f975f447d59977d90c3226cc8c623b31b20b3.zip
move whitelist/blacklist to allow/deny
-rw-r--r--etc/inc/allow-bin-sh.inc6
-rw-r--r--etc/inc/allow-common-devel.inc36
-rw-r--r--etc/inc/allow-gjs.inc16
-rw-r--r--etc/inc/allow-java.inc10
-rw-r--r--etc/inc/allow-lua.inc16
-rw-r--r--etc/inc/allow-nodejs.inc4
-rw-r--r--etc/inc/allow-opengl-game.inc4
-rw-r--r--etc/inc/allow-perl.inc16
-rw-r--r--etc/inc/allow-php.inc6
-rw-r--r--etc/inc/allow-python2.inc10
-rw-r--r--etc/inc/allow-python3.inc12
-rw-r--r--etc/inc/allow-ruby.inc4
-rw-r--r--etc/inc/allow-ssh.inc8
-rw-r--r--etc/inc/disable-common.inc684
-rw-r--r--etc/inc/disable-devel.inc80
-rw-r--r--etc/inc/disable-interpreters.inc84
-rw-r--r--etc/inc/disable-passwdmgr.inc30
-rw-r--r--etc/inc/disable-programs.inc2178
-rw-r--r--etc/inc/disable-shell.inc22
-rw-r--r--etc/inc/disable-xdg.inc8
-rw-r--r--etc/inc/whitelist-1793-workaround.inc46
-rw-r--r--etc/inc/whitelist-common.inc130
-rw-r--r--etc/inc/whitelist-player-common.inc10
-rw-r--r--etc/inc/whitelist-runuser-common.inc20
-rw-r--r--etc/inc/whitelist-usr-share-common.inc126
-rw-r--r--etc/inc/whitelist-var-common.inc18
-rw-r--r--etc/profile-a-l/0ad.profile18
-rw-r--r--etc/profile-a-l/2048-qt.profile8
-rw-r--r--etc/profile-a-l/Cryptocat.profile2
-rw-r--r--etc/profile-a-l/Discord.profile4
-rw-r--r--etc/profile-a-l/DiscordCanary.profile4
-rw-r--r--etc/profile-a-l/Fritzing.profile4
-rw-r--r--etc/profile-a-l/JDownloader.profile6
-rw-r--r--etc/profile-a-l/abiword.profile4
-rw-r--r--etc/profile-a-l/abrowser.profile8
-rw-r--r--etc/profile-a-l/agetpkg.profile6
-rw-r--r--etc/profile-a-l/akonadi_control.profile32
-rw-r--r--etc/profile-a-l/akregator.profile14
-rw-r--r--etc/profile-a-l/alacarte.profile14
-rw-r--r--etc/profile-a-l/alienarena.profile6
-rw-r--r--etc/profile-a-l/alpine.profile46
-rw-r--r--etc/profile-a-l/amarok.profile2
-rw-r--r--etc/profile-a-l/amule.profile6
-rw-r--r--etc/profile-a-l/android-studio.profile14
-rw-r--r--etc/profile-a-l/anki.profile8
-rw-r--r--etc/profile-a-l/anydesk.profile4
-rw-r--r--etc/profile-a-l/aosp.profile14
-rw-r--r--etc/profile-a-l/apostrophe.profile18
-rw-r--r--etc/profile-a-l/arch-audit.profile4
-rw-r--r--etc/profile-a-l/archaudit-report.profile2
-rw-r--r--etc/profile-a-l/archiver-common.profile2
-rw-r--r--etc/profile-a-l/ardour5.profile12
-rw-r--r--etc/profile-a-l/arduino.profile6
-rw-r--r--etc/profile-a-l/aria2c.profile10
-rw-r--r--etc/profile-a-l/ark.profile6
-rw-r--r--etc/profile-a-l/arm.profile4
-rw-r--r--etc/profile-a-l/artha.profile14
-rw-r--r--etc/profile-a-l/assogiate.profile4
-rw-r--r--etc/profile-a-l/asunder.profile10
-rw-r--r--etc/profile-a-l/atom.profile4
-rw-r--r--etc/profile-a-l/atril.profile6
-rw-r--r--etc/profile-a-l/audacious.profile6
-rw-r--r--etc/profile-a-l/audacity.profile6
-rw-r--r--etc/profile-a-l/audio-recorder.profile10
-rw-r--r--etc/profile-a-l/authenticator-rs.profile8
-rw-r--r--etc/profile-a-l/authenticator.profile4
-rw-r--r--etc/profile-a-l/autokey-common.profile4
-rw-r--r--etc/profile-a-l/avidemux.profile12
-rw-r--r--etc/profile-a-l/aweather.profile4
-rw-r--r--etc/profile-a-l/awesome.profile2
-rw-r--r--etc/profile-a-l/ballbuster.profile6
-rw-r--r--etc/profile-a-l/baloo_file.profile12
-rw-r--r--etc/profile-a-l/balsa.profile36
-rw-r--r--etc/profile-a-l/barrier.profile6
-rw-r--r--etc/profile-a-l/basilisk.profile8
-rw-r--r--etc/profile-a-l/bcompare.profile4
-rw-r--r--etc/profile-a-l/beaker.profile4
-rw-r--r--etc/profile-a-l/bibletime.profile20
-rw-r--r--etc/profile-a-l/bijiben.profile14
-rw-r--r--etc/profile-a-l/bitcoin-qt.profile8
-rw-r--r--etc/profile-a-l/bitlbee.profile4
-rw-r--r--etc/profile-a-l/bitwarden.profile4
-rw-r--r--etc/profile-a-l/blackbox.profile2
-rw-r--r--etc/profile-a-l/blender.profile6
-rw-r--r--etc/profile-a-l/bless.profile2
-rw-r--r--etc/profile-a-l/blobby.profile6
-rw-r--r--etc/profile-a-l/blobwars.profile6
-rw-r--r--etc/profile-a-l/bnox.profile8
-rw-r--r--etc/profile-a-l/brackets.profile2
-rw-r--r--etc/profile-a-l/brasero.profile2
-rw-r--r--etc/profile-a-l/brave.profile22
-rw-r--r--etc/profile-a-l/bzflag.profile4
-rw-r--r--etc/profile-a-l/calibre.profile6
-rw-r--r--etc/profile-a-l/calligra.profile2
-rw-r--r--etc/profile-a-l/calligragemini.profile2
-rw-r--r--etc/profile-a-l/calligraplan.profile2
-rw-r--r--etc/profile-a-l/calligraplanwork.profile2
-rw-r--r--etc/profile-a-l/calligrasheets.profile2
-rw-r--r--etc/profile-a-l/calligrastage.profile2
-rw-r--r--etc/profile-a-l/calligrawords.profile2
-rw-r--r--etc/profile-a-l/cameramonitor.profile2
-rw-r--r--etc/profile-a-l/cantata.profile8
-rw-r--r--etc/profile-a-l/cargo.profile10
-rw-r--r--etc/profile-a-l/catfish.profile4
-rw-r--r--etc/profile-a-l/cawbird.profile2
-rw-r--r--etc/profile-a-l/celluloid.profile14
-rw-r--r--etc/profile-a-l/checkbashisms.profile4
-rw-r--r--etc/profile-a-l/cheese.profile10
-rw-r--r--etc/profile-a-l/cherrytree.profile4
-rw-r--r--etc/profile-a-l/chromium-browser-privacy.profile10
-rw-r--r--etc/profile-a-l/chromium-common.profile10
-rw-r--r--etc/profile-a-l/chromium.profile16
-rw-r--r--etc/profile-a-l/cin.profile2
-rw-r--r--etc/profile-a-l/clamav.profile2
-rw-r--r--etc/profile-a-l/claws-mail.profile6
-rw-r--r--etc/profile-a-l/clawsker.profile4
-rw-r--r--etc/profile-a-l/clementine.profile6
-rw-r--r--etc/profile-a-l/clion.profile14
-rw-r--r--etc/profile-a-l/clipgrab.profile6
-rw-r--r--etc/profile-a-l/clipit.profile8
-rw-r--r--etc/profile-a-l/cliqz.profile12
-rw-r--r--etc/profile-a-l/cmus.profile4
-rw-r--r--etc/profile-a-l/code.profile8
-rw-r--r--etc/profile-a-l/colorful.profile6
-rw-r--r--etc/profile-a-l/com.github.bleakgrey.tootle.profile6
-rw-r--r--etc/profile-a-l/com.github.dahenson.agenda.profile12
-rw-r--r--etc/profile-a-l/com.github.johnfactotum.Foliate.profile18
-rw-r--r--etc/profile-a-l/com.github.phase1geo.minder.profile14
-rw-r--r--etc/profile-a-l/conkeror.profile22
-rw-r--r--etc/profile-a-l/conky.profile2
-rw-r--r--etc/profile-a-l/corebird.profile2
-rw-r--r--etc/profile-a-l/cower.profile4
-rw-r--r--etc/profile-a-l/coyim.profile4
-rw-r--r--etc/profile-a-l/cpio.profile4
-rw-r--r--etc/profile-a-l/crawl.profile4
-rw-r--r--etc/profile-a-l/crow.profile4
-rw-r--r--etc/profile-a-l/curl.profile8
-rw-r--r--etc/profile-a-l/cyberfox.profile8
-rw-r--r--etc/profile-a-l/d-feet.profile6
-rw-r--r--etc/profile-a-l/darktable.profile6
-rw-r--r--etc/profile-a-l/dbus-send.profile4
-rw-r--r--etc/profile-a-l/dconf-editor.profile2
-rw-r--r--etc/profile-a-l/dconf.profile4
-rw-r--r--etc/profile-a-l/ddgtk.profile4
-rw-r--r--etc/profile-a-l/deadbeef.profile4
-rw-r--r--etc/profile-a-l/deluge.profile6
-rw-r--r--etc/profile-a-l/desktopeditors.profile6
-rw-r--r--etc/profile-a-l/devhelp.profile6
-rw-r--r--etc/profile-a-l/devilspie.profile6
-rw-r--r--etc/profile-a-l/devilspie2.profile8
-rw-r--r--etc/profile-a-l/dia.profile6
-rw-r--r--etc/profile-a-l/dig.profile10
-rw-r--r--etc/profile-a-l/digikam.profile12
-rw-r--r--etc/profile-a-l/dillo.profile8
-rw-r--r--etc/profile-a-l/dino.profile6
-rw-r--r--etc/profile-a-l/discord-canary.profile4
-rw-r--r--etc/profile-a-l/discord-common.profile4
-rw-r--r--etc/profile-a-l/discord.profile4
-rw-r--r--etc/profile-a-l/display.profile2
-rw-r--r--etc/profile-a-l/dnox.profile8
-rw-r--r--etc/profile-a-l/dnscrypt-proxy.profile10
-rw-r--r--etc/profile-a-l/dnsmasq.profile8
-rw-r--r--etc/profile-a-l/dolphin-emu.profile14
-rw-r--r--etc/profile-a-l/dooble.profile6
-rw-r--r--etc/profile-a-l/dosbox.profile4
-rw-r--r--etc/profile-a-l/dragon.profile8
-rw-r--r--etc/profile-a-l/drawio.profile6
-rw-r--r--etc/profile-a-l/drill.profile6
-rw-r--r--etc/profile-a-l/dropbox.profile14
-rw-r--r--etc/profile-a-l/easystroke.profile4
-rw-r--r--etc/profile-a-l/electron-mail.profile6
-rw-r--r--etc/profile-a-l/electron.profile2
-rw-r--r--etc/profile-a-l/electrum.profile4
-rw-r--r--etc/profile-a-l/element-desktop.profile6
-rw-r--r--etc/profile-a-l/elinks.profile4
-rw-r--r--etc/profile-a-l/emacs.profile4
-rw-r--r--etc/profile-a-l/email-common.profile30
-rw-r--r--etc/profile-a-l/enchant.profile6
-rw-r--r--etc/profile-a-l/enox.profile8
-rw-r--r--etc/profile-a-l/enpass.profile20
-rw-r--r--etc/profile-a-l/eo-common.profile8
-rw-r--r--etc/profile-a-l/eog.profile4
-rw-r--r--etc/profile-a-l/eom.profile4
-rw-r--r--etc/profile-a-l/ephemeral.profile10
-rw-r--r--etc/profile-a-l/epiphany.profile14
-rw-r--r--etc/profile-a-l/equalx.profile18
-rw-r--r--etc/profile-a-l/etr.profile10
-rw-r--r--etc/profile-a-l/evince.profile14
-rw-r--r--etc/profile-a-l/evolution.profile18
-rw-r--r--etc/profile-a-l/exiftool.profile4
-rw-r--r--etc/profile-a-l/falkon.profile12
-rw-r--r--etc/profile-a-l/fbreader.profile4
-rw-r--r--etc/profile-a-l/fdns.profile8
-rw-r--r--etc/profile-a-l/feedreader.profile10
-rw-r--r--etc/profile-a-l/ferdi.profile18
-rw-r--r--etc/profile-a-l/fetchmail.profile4
-rw-r--r--etc/profile-a-l/ffmpeg.profile10
-rw-r--r--etc/profile-a-l/file-roller.profile4
-rw-r--r--etc/profile-a-l/file.profile2
-rw-r--r--etc/profile-a-l/filezilla.profile4
-rw-r--r--etc/profile-a-l/firedragon.profile8
-rw-r--r--etc/profile-a-l/firefox-common-addons.profile130
-rw-r--r--etc/profile-a-l/firefox-common.profile10
-rw-r--r--etc/profile-a-l/firefox-esr.profile2
-rw-r--r--etc/profile-a-l/firefox.profile22
-rw-r--r--etc/profile-a-l/five-or-more.profile6
-rw-r--r--etc/profile-a-l/flameshot.profile8
-rw-r--r--etc/profile-a-l/flashpeak-slimjet.profile8
-rw-r--r--etc/profile-a-l/flowblade.profile4
-rw-r--r--etc/profile-a-l/fluxbox.profile2
-rw-r--r--etc/profile-a-l/font-manager.profile10
-rw-r--r--etc/profile-a-l/fontforge.profile4
-rw-r--r--etc/profile-a-l/fossamail.profile12
-rw-r--r--etc/profile-a-l/four-in-a-row.profile2
-rw-r--r--etc/profile-a-l/fractal.profile6
-rw-r--r--etc/profile-a-l/franz.profile18
-rw-r--r--etc/profile-a-l/freecad.profile4
-rw-r--r--etc/profile-a-l/freeciv.profile4
-rw-r--r--etc/profile-a-l/freecol.profile18
-rw-r--r--etc/profile-a-l/freemind.profile4
-rw-r--r--etc/profile-a-l/freetube.profile4
-rw-r--r--etc/profile-a-l/frogatto.profile8
-rw-r--r--etc/profile-a-l/frozen-bubble.profile4
-rw-r--r--etc/profile-a-l/funnyboat.profile8
-rw-r--r--etc/profile-a-l/gajim.profile24
-rw-r--r--etc/profile-a-l/galculator.profile4
-rw-r--r--etc/profile-a-l/gapplication.profile4
-rw-r--r--etc/profile-a-l/gcloud.profile6
-rw-r--r--etc/profile-a-l/gconf-editor.profile4
-rw-r--r--etc/profile-a-l/gconf.profile10
-rw-r--r--etc/profile-a-l/geany.profile2
-rw-r--r--etc/profile-a-l/geary.profile36
-rw-r--r--etc/profile-a-l/gedit.profile4
-rw-r--r--etc/profile-a-l/geeqie.profile6
-rw-r--r--etc/profile-a-l/gfeeds.profile20
-rw-r--r--etc/profile-a-l/gget.profile6
-rw-r--r--etc/profile-a-l/ghostwriter.profile16
-rw-r--r--etc/profile-a-l/gimp.profile22
-rw-r--r--etc/profile-a-l/gist.profile10
-rw-r--r--etc/profile-a-l/git-cola.profile32
-rw-r--r--etc/profile-a-l/git.profile34
-rw-r--r--etc/profile-a-l/gitg.profile10
-rw-r--r--etc/profile-a-l/github-desktop.profile8
-rw-r--r--etc/profile-a-l/gitter.profile10
-rw-r--r--etc/profile-a-l/gjs.profile8
-rw-r--r--etc/profile-a-l/gl-117.profile6
-rw-r--r--etc/profile-a-l/glaxium.profile6
-rw-r--r--etc/profile-a-l/globaltime.profile2
-rw-r--r--etc/profile-a-l/gmpc.profile10
-rw-r--r--etc/profile-a-l/gnome-2048.profile4
-rw-r--r--etc/profile-a-l/gnome-books.profile4
-rw-r--r--etc/profile-a-l/gnome-builder.profile8
-rw-r--r--etc/profile-a-l/gnome-calendar.profile2
-rw-r--r--etc/profile-a-l/gnome-characters.profile2
-rw-r--r--etc/profile-a-l/gnome-chess.profile8
-rw-r--r--etc/profile-a-l/gnome-clocks.profile4
-rw-r--r--etc/profile-a-l/gnome-contacts.profile2
-rw-r--r--etc/profile-a-l/gnome-documents.profile4
-rw-r--r--etc/profile-a-l/gnome-hexgl.profile2
-rw-r--r--etc/profile-a-l/gnome-keyring.profile14
-rw-r--r--etc/profile-a-l/gnome-klotski.profile4
-rw-r--r--etc/profile-a-l/gnome-latex.profile8
-rw-r--r--etc/profile-a-l/gnome-logs.profile2
-rw-r--r--etc/profile-a-l/gnome-mahjongg.profile2
-rw-r--r--etc/profile-a-l/gnome-maps.profile20
-rw-r--r--etc/profile-a-l/gnome-mines.profile6
-rw-r--r--etc/profile-a-l/gnome-mplayer.profile6
-rw-r--r--etc/profile-a-l/gnome-music.profile4
-rw-r--r--etc/profile-a-l/gnome-nettool.profile2
-rw-r--r--etc/profile-a-l/gnome-nibbles.profile6
-rw-r--r--etc/profile-a-l/gnome-passwordsafe.profile12
-rw-r--r--etc/profile-a-l/gnome-photos.profile2
-rw-r--r--etc/profile-a-l/gnome-pie.profile2
-rw-r--r--etc/profile-a-l/gnome-pomodoro.profile6
-rw-r--r--etc/profile-a-l/gnome-recipes.profile10
-rw-r--r--etc/profile-a-l/gnome-ring.profile2
-rw-r--r--etc/profile-a-l/gnome-robots.profile2
-rw-r--r--etc/profile-a-l/gnome-schedule.profile22
-rw-r--r--etc/profile-a-l/gnome-screenshot.profile4
-rw-r--r--etc/profile-a-l/gnome-sound-recorder.profile4
-rw-r--r--etc/profile-a-l/gnome-sudoku.profile4
-rw-r--r--etc/profile-a-l/gnome-system-log.profile2
-rw-r--r--etc/profile-a-l/gnome-taquin.profile2
-rw-r--r--etc/profile-a-l/gnome-todo.profile2
-rw-r--r--etc/profile-a-l/gnome-twitch.profile8
-rw-r--r--etc/profile-a-l/gnome-weather.profile2
-rw-r--r--etc/profile-a-l/gnote.profile10
-rw-r--r--etc/profile-a-l/gnubik.profile2
-rw-r--r--etc/profile-a-l/godot.profile6
-rw-r--r--etc/profile-a-l/goobox.profile2
-rw-r--r--etc/profile-a-l/google-chrome-beta.profile16
-rw-r--r--etc/profile-a-l/google-chrome-unstable.profile16
-rw-r--r--etc/profile-a-l/google-chrome.profile16
-rw-r--r--etc/profile-a-l/google-earth.profile8
-rw-r--r--etc/profile-a-l/google-play-music-desktop-player.profile4
-rw-r--r--etc/profile-a-l/googler-common.profile8
-rw-r--r--etc/profile-a-l/gpa.profile2
-rw-r--r--etc/profile-a-l/gpg-agent.profile16
-rw-r--r--etc/profile-a-l/gpg.profile16
-rw-r--r--etc/profile-a-l/gpicview.profile4
-rw-r--r--etc/profile-a-l/gpredict.profile4
-rw-r--r--etc/profile-a-l/gradio.profile8
-rw-r--r--etc/profile-a-l/gramps.profile4
-rw-r--r--etc/profile-a-l/gravity-beams-and-evaporating-stars.profile2
-rw-r--r--etc/profile-a-l/gthumb.profile6
-rw-r--r--etc/profile-a-l/gtk-update-icon-cache.profile2
-rw-r--r--etc/profile-a-l/gtk2-youtube-viewer.profile4
-rw-r--r--etc/profile-a-l/gtk3-youtube-viewer.profile4
-rw-r--r--etc/profile-a-l/guayadeque.profile4
-rw-r--r--etc/profile-a-l/gummi.profile4
-rw-r--r--etc/profile-a-l/guvcview.profile12
-rw-r--r--etc/profile-a-l/gwenview.profile22
-rw-r--r--etc/profile-a-l/gzip.profile2
-rw-r--r--etc/profile-a-l/handbrake.profile6
-rw-r--r--etc/profile-a-l/hashcat.profile8
-rw-r--r--etc/profile-a-l/hasher-common.profile2
-rw-r--r--etc/profile-a-l/hedgewars.profile4
-rw-r--r--etc/profile-a-l/hexchat.profile4
-rw-r--r--etc/profile-a-l/highlight.profile2
-rw-r--r--etc/profile-a-l/homebank.profile8
-rw-r--r--etc/profile-a-l/host.profile4
-rw-r--r--etc/profile-a-l/hugin.profile6
-rw-r--r--etc/profile-a-l/hyperrogue.profile6
-rw-r--r--etc/profile-a-l/i2prouter.profile20
-rw-r--r--etc/profile-a-l/i3.profile2
-rw-r--r--etc/profile-a-l/icecat.profile8
-rw-r--r--etc/profile-a-l/icedove.profile12
-rw-r--r--etc/profile-a-l/idea.sh.profile12
-rw-r--r--etc/profile-a-l/imagej.profile2
-rw-r--r--etc/profile-a-l/img2txt.profile8
-rw-r--r--etc/profile-a-l/impressive.profile10
-rw-r--r--etc/profile-a-l/inkscape.profile16
-rw-r--r--etc/profile-a-l/inox.profile8
-rw-r--r--etc/profile-a-l/iridium.profile8
-rw-r--r--etc/profile-a-l/itch.profile8
-rw-r--r--etc/profile-a-l/jami-gnome.profile8
-rw-r--r--etc/profile-a-l/jd-gui.profile2
-rw-r--r--etc/profile-a-l/jerry.profile2
-rw-r--r--etc/profile-a-l/jitsi-meet-desktop.profile6
-rw-r--r--etc/profile-a-l/jitsi.profile2
-rw-r--r--etc/profile-a-l/jumpnbump.profile6
-rw-r--r--etc/profile-a-l/k3b.profile10
-rw-r--r--etc/profile-a-l/kaffeine.profile16
-rw-r--r--etc/profile-a-l/kalgebra.profile6
-rw-r--r--etc/profile-a-l/karbon.profile2
-rw-r--r--etc/profile-a-l/kate.profile28
-rw-r--r--etc/profile-a-l/kazam.profile8
-rw-r--r--etc/profile-a-l/kcalc.profile16
-rw-r--r--etc/profile-a-l/kdenlive.profile8
-rw-r--r--etc/profile-a-l/kdiff3.profile8
-rw-r--r--etc/profile-a-l/keepass.profile16
-rw-r--r--etc/profile-a-l/keepassx.profile10
-rw-r--r--etc/profile-a-l/keepassxc.profile30
-rw-r--r--etc/profile-a-l/kget.profile14
-rw-r--r--etc/profile-a-l/kid3-qt.profile2
-rw-r--r--etc/profile-a-l/kid3.profile6
-rw-r--r--etc/profile-a-l/kino.profile4
-rw-r--r--etc/profile-a-l/kiwix-desktop.profile8
-rw-r--r--etc/profile-a-l/klatexformula.profile4
-rw-r--r--etc/profile-a-l/klavaro.profile8
-rw-r--r--etc/profile-a-l/kmail.profile42
-rw-r--r--etc/profile-a-l/kmplayer.profile10
-rw-r--r--etc/profile-a-l/knotes.profile6
-rw-r--r--etc/profile-a-l/kodi.profile8
-rw-r--r--etc/profile-a-l/konversation.profile10
-rw-r--r--etc/profile-a-l/kopete.profile12
-rw-r--r--etc/profile-a-l/krita.profile8
-rw-r--r--etc/profile-a-l/krunner.profile6
-rw-r--r--etc/profile-a-l/ktorrent.profile30
-rw-r--r--etc/profile-a-l/ktouch.profile8
-rw-r--r--etc/profile-a-l/kube.profile36
-rw-r--r--etc/profile-a-l/kwin_x11.profile8
-rw-r--r--etc/profile-a-l/kwrite.profile18
-rw-r--r--etc/profile-a-l/latex-common.profile2
-rw-r--r--etc/profile-a-l/leafpad.profile2
-rw-r--r--etc/profile-a-l/less.profile4
-rw-r--r--etc/profile-a-l/librecad.profile6
-rw-r--r--etc/profile-a-l/libreoffice.profile6
-rw-r--r--etc/profile-a-l/librewolf.profile16
-rw-r--r--etc/profile-a-l/liferea.profile14
-rw-r--r--etc/profile-a-l/lightsoff.profile2
-rw-r--r--etc/profile-a-l/lincity-ng.profile4
-rw-r--r--etc/profile-a-l/links-common.profile6
-rw-r--r--etc/profile-a-l/links.profile4
-rw-r--r--etc/profile-a-l/links2.profile4
-rw-r--r--etc/profile-a-l/linphone.profile18
-rw-r--r--etc/profile-a-l/lmms.profile6
-rw-r--r--etc/profile-a-l/lollypop.profile4
-rw-r--r--etc/profile-a-l/lugaru.profile8
-rw-r--r--etc/profile-a-l/luminance-hdr.profile4
-rw-r--r--etc/profile-a-l/lutris.profile34
-rw-r--r--etc/profile-a-l/lximage-qt.profile2
-rw-r--r--etc/profile-a-l/lxmusic.profile6
-rw-r--r--etc/profile-a-l/lynx.profile4
-rw-r--r--etc/profile-a-l/lyx.profile14
-rw-r--r--etc/profile-a-l/sway.profile4
-rw-r--r--etc/profile-m-z/Maelstrom.profile4
-rw-r--r--etc/profile-m-z/Mathematica.profile10
-rw-r--r--etc/profile-m-z/PCSX2.profile4
-rw-r--r--etc/profile-m-z/QMediathekView.profile26
-rw-r--r--etc/profile-m-z/QOwnNotes.profile16
-rw-r--r--etc/profile-m-z/Viber.profile8
-rw-r--r--etc/profile-m-z/XMind.profile6
-rw-r--r--etc/profile-m-z/Xephyr.profile2
-rw-r--r--etc/profile-m-z/Xvfb.profile2
-rw-r--r--etc/profile-m-z/ZeGrapher.profile4
-rw-r--r--etc/profile-m-z/macrofusion.profile4
-rw-r--r--etc/profile-m-z/magicor.profile6
-rw-r--r--etc/profile-m-z/makepkg.profile18
-rw-r--r--etc/profile-m-z/man.profile18
-rw-r--r--etc/profile-m-z/manaplus.profile8
-rw-r--r--etc/profile-m-z/marker.profile8
-rw-r--r--etc/profile-m-z/masterpdfeditor.profile4
-rw-r--r--etc/profile-m-z/mate-calc.profile8
-rw-r--r--etc/profile-m-z/mate-dictionary.profile4
-rw-r--r--etc/profile-m-z/matrix-mirage.profile12
-rw-r--r--etc/profile-m-z/mattermost-desktop.profile4
-rw-r--r--etc/profile-m-z/mcabber.profile4
-rw-r--r--etc/profile-m-z/mcomix.profile8
-rw-r--r--etc/profile-m-z/mdr.profile4
-rw-r--r--etc/profile-m-z/mediainfo.profile2
-rw-r--r--etc/profile-m-z/mediathekview.profile20
-rw-r--r--etc/profile-m-z/megaglest.profile8
-rw-r--r--etc/profile-m-z/meld.profile14
-rw-r--r--etc/profile-m-z/mendeleydesktop.profile14
-rw-r--r--etc/profile-m-z/menulibre.profile14
-rw-r--r--etc/profile-m-z/meteo-qt.profile8
-rw-r--r--etc/profile-m-z/microsoft-edge-dev.profile8
-rw-r--r--etc/profile-m-z/midori.profile38
-rw-r--r--etc/profile-m-z/min.profile4
-rw-r--r--etc/profile-m-z/mindless.profile2
-rw-r--r--etc/profile-m-z/minecraft-launcher.profile4
-rw-r--r--etc/profile-m-z/minetest.profile12
-rw-r--r--etc/profile-m-z/minitube.profile18
-rw-r--r--etc/profile-m-z/mirage.profile16
-rw-r--r--etc/profile-m-z/mirrormagic.profile6
-rw-r--r--etc/profile-m-z/mocp.profile4
-rw-r--r--etc/profile-m-z/mousepad.profile2
-rw-r--r--etc/profile-m-z/mp3splt-gtk.profile2
-rw-r--r--etc/profile-m-z/mp3splt.profile4
-rw-r--r--etc/profile-m-z/mpDris2.profile8
-rw-r--r--etc/profile-m-z/mpd.profile8
-rw-r--r--etc/profile-m-z/mpg123.profile2
-rw-r--r--etc/profile-m-z/mplayer.profile4
-rw-r--r--etc/profile-m-z/mpsyt.profile28
-rw-r--r--etc/profile-m-z/mpv.profile20
-rw-r--r--etc/profile-m-z/mrrescue.profile8
-rw-r--r--etc/profile-m-z/ms-excel.profile2
-rw-r--r--etc/profile-m-z/ms-office.profile4
-rw-r--r--etc/profile-m-z/ms-onenote.profile2
-rw-r--r--etc/profile-m-z/ms-outlook.profile2
-rw-r--r--etc/profile-m-z/ms-powerpoint.profile2
-rw-r--r--etc/profile-m-z/ms-skype.profile2
-rw-r--r--etc/profile-m-z/ms-word.profile2
-rw-r--r--etc/profile-m-z/mtpaint.profile2
-rw-r--r--etc/profile-m-z/multimc5.profile12
-rw-r--r--etc/profile-m-z/mumble.profile12
-rw-r--r--etc/profile-m-z/mupdf-gl.profile2
-rw-r--r--etc/profile-m-z/mupdf.profile2
-rw-r--r--etc/profile-m-z/mupen64plus.profile8
-rw-r--r--etc/profile-m-z/musescore.profile12
-rw-r--r--etc/profile-m-z/musictube.profile14
-rw-r--r--etc/profile-m-z/musixmatch.profile2
-rw-r--r--etc/profile-m-z/mutt.profile120
-rw-r--r--etc/profile-m-z/mypaint.profile8
-rw-r--r--etc/profile-m-z/nano.profile8
-rw-r--r--etc/profile-m-z/natron.profile6
-rw-r--r--etc/profile-m-z/ncdu.profile2
-rw-r--r--etc/profile-m-z/neochat.profile18
-rw-r--r--etc/profile-m-z/neomutt.profile128
-rw-r--r--etc/profile-m-z/netactview.profile6
-rw-r--r--etc/profile-m-z/nethack-vultures.profile6
-rw-r--r--etc/profile-m-z/nethack.profile4
-rw-r--r--etc/profile-m-z/netsurf.profile10
-rw-r--r--etc/profile-m-z/neverball.profile6
-rw-r--r--etc/profile-m-z/newsbeuter.profile14
-rw-r--r--etc/profile-m-z/newsboat.profile24
-rw-r--r--etc/profile-m-z/newsflash.profile12
-rw-r--r--etc/profile-m-z/nextcloud.profile12
-rw-r--r--etc/profile-m-z/nheko.profile14
-rw-r--r--etc/profile-m-z/nicotine.profile8
-rw-r--r--etc/profile-m-z/nitroshare.profile4
-rw-r--r--etc/profile-m-z/nodejs-common.profile26
-rw-r--r--etc/profile-m-z/nomacs.profile8
-rw-r--r--etc/profile-m-z/notify-send.profile2
-rw-r--r--etc/profile-m-z/nslookup.profile8
-rw-r--r--etc/profile-m-z/nuclear.profile4
-rw-r--r--etc/profile-m-z/nylas.profile10
-rw-r--r--etc/profile-m-z/nyx.profile4
-rw-r--r--etc/profile-m-z/obs.profile8
-rw-r--r--etc/profile-m-z/ocenaudio.profile6
-rw-r--r--etc/profile-m-z/odt2txt.profile4
-rw-r--r--etc/profile-m-z/okular.profile42
-rw-r--r--etc/profile-m-z/onboard.profile6
-rw-r--r--etc/profile-m-z/onionshare-gui.profile2
-rw-r--r--etc/profile-m-z/open-invaders.profile4
-rw-r--r--etc/profile-m-z/openarena.profile6
-rw-r--r--etc/profile-m-z/openbox.profile2
-rw-r--r--etc/profile-m-z/opencity.profile4
-rw-r--r--etc/profile-m-z/openclonk.profile4
-rw-r--r--etc/profile-m-z/openmw.profile10
-rw-r--r--etc/profile-m-z/openshot.profile8
-rw-r--r--etc/profile-m-z/openttd.profile4
-rw-r--r--etc/profile-m-z/opera-beta.profile8
-rw-r--r--etc/profile-m-z/opera.profile12
-rw-r--r--etc/profile-m-z/orage.profile4
-rw-r--r--etc/profile-m-z/ostrichriders.profile6
-rw-r--r--etc/profile-m-z/otter-browser.profile20
-rw-r--r--etc/profile-m-z/palemoon.profile8
-rw-r--r--etc/profile-m-z/pandoc.profile4
-rw-r--r--etc/profile-m-z/parole.profile4
-rw-r--r--etc/profile-m-z/patch.profile4
-rw-r--r--etc/profile-m-z/pavucontrol-qt.profile4
-rw-r--r--etc/profile-m-z/pavucontrol.profile6
-rw-r--r--etc/profile-m-z/pcsxr.profile4
-rw-r--r--etc/profile-m-z/pdfchain.profile2
-rw-r--r--etc/profile-m-z/pdfmod.profile6
-rw-r--r--etc/profile-m-z/pdfsam.profile2
-rw-r--r--etc/profile-m-z/pdftotext.profile10
-rw-r--r--etc/profile-m-z/peek.profile6
-rw-r--r--etc/profile-m-z/penguin-command.profile4
-rw-r--r--etc/profile-m-z/photoflare.profile2
-rw-r--r--etc/profile-m-z/picard.profile6
-rw-r--r--etc/profile-m-z/pidgin.profile8
-rw-r--r--etc/profile-m-z/pinball.profile8
-rw-r--r--etc/profile-m-z/ping.profile4
-rw-r--r--etc/profile-m-z/pingus.profile8
-rw-r--r--etc/profile-m-z/pinta.profile6
-rw-r--r--etc/profile-m-z/pioneer.profile4
-rw-r--r--etc/profile-m-z/pipe-viewer.profile8
-rw-r--r--etc/profile-m-z/pitivi.profile2
-rw-r--r--etc/profile-m-z/pix.profile8
-rw-r--r--etc/profile-m-z/pkglog.profile6
-rw-r--r--etc/profile-m-z/playonlinux.profile4
-rw-r--r--etc/profile-m-z/pluma.profile4
-rw-r--r--etc/profile-m-z/plv.profile6
-rw-r--r--etc/profile-m-z/pngquant.profile4
-rw-r--r--etc/profile-m-z/polari.profile12
-rw-r--r--etc/profile-m-z/ppsspp.profile6
-rw-r--r--etc/profile-m-z/pragha.profile4
-rw-r--r--etc/profile-m-z/profanity.profile4
-rw-r--r--etc/profile-m-z/psi-plus.profile12
-rw-r--r--etc/profile-m-z/psi.profile24
-rw-r--r--etc/profile-m-z/pybitmessage.profile6
-rw-r--r--etc/profile-m-z/pycharm-community.profile2
-rw-r--r--etc/profile-m-z/pycharm-professional.profile2
-rw-r--r--etc/profile-m-z/qbittorrent.profile18
-rw-r--r--etc/profile-m-z/qcomicbook.profile10
-rw-r--r--etc/profile-m-z/qemu-launcher.profile2
-rw-r--r--etc/profile-m-z/qgis.profile16
-rw-r--r--etc/profile-m-z/qlipper.profile2
-rw-r--r--etc/profile-m-z/qmmp.profile4
-rw-r--r--etc/profile-m-z/qnapi.profile6
-rw-r--r--etc/profile-m-z/qpdfview.profile6
-rw-r--r--etc/profile-m-z/qrencode.profile2
-rw-r--r--etc/profile-m-z/qtox.profile8
-rw-r--r--etc/profile-m-z/quadrapassel.profile6
-rw-r--r--etc/profile-m-z/quaternion.profile12
-rw-r--r--etc/profile-m-z/quiterss.profile20
-rw-r--r--etc/profile-m-z/quodlibet.profile18
-rw-r--r--etc/profile-m-z/qupzilla.profile8
-rw-r--r--etc/profile-m-z/qutebrowser.profile14
-rw-r--r--etc/profile-m-z/rambox.profile14
-rw-r--r--etc/profile-m-z/redeclipse.profile6
-rw-r--r--etc/profile-m-z/redshift.profile8
-rw-r--r--etc/profile-m-z/regextester.profile2
-rw-r--r--etc/profile-m-z/remmina.profile6
-rw-r--r--etc/profile-m-z/rhythmbox.profile14
-rw-r--r--etc/profile-m-z/ricochet.profile6
-rw-r--r--etc/profile-m-z/riot-web.profile6
-rw-r--r--etc/profile-m-z/ripperx.profile4
-rw-r--r--etc/profile-m-z/ristretto.profile6
-rw-r--r--etc/profile-m-z/rocketchat.profile4
-rw-r--r--etc/profile-m-z/rsync-download_only.profile4
-rw-r--r--etc/profile-m-z/rtv-addons.profile18
-rw-r--r--etc/profile-m-z/rtv.profile12
-rw-r--r--etc/profile-m-z/sayonara.profile4
-rw-r--r--etc/profile-m-z/scallion.profile8
-rw-r--r--etc/profile-m-z/scorched3d.profile8
-rw-r--r--etc/profile-m-z/scorchwentbonkers.profile6
-rw-r--r--etc/profile-m-z/scribus.profile36
-rw-r--r--etc/profile-m-z/seahorse-adventures.profile4
-rw-r--r--etc/profile-m-z/seahorse.profile18
-rw-r--r--etc/profile-m-z/seamonkey.profile46
-rw-r--r--etc/profile-m-z/server.profile8
-rw-r--r--etc/profile-m-z/shellcheck.profile6
-rw-r--r--etc/profile-m-z/shortwave.profile10
-rw-r--r--etc/profile-m-z/shotcut.profile2
-rw-r--r--etc/profile-m-z/shotwell.profile12
-rw-r--r--etc/profile-m-z/signal-cli.profile8
-rw-r--r--etc/profile-m-z/signal-desktop.profile8
-rw-r--r--etc/profile-m-z/simple-scan.profile8
-rw-r--r--etc/profile-m-z/simplescreenrecorder.profile6
-rw-r--r--etc/profile-m-z/simutrans.profile4
-rw-r--r--etc/profile-m-z/skanlite.profile2
-rw-r--r--etc/profile-m-z/skypeforlinux.profile2
-rw-r--r--etc/profile-m-z/slack.profile4
-rw-r--r--etc/profile-m-z/slashem.profile4
-rw-r--r--etc/profile-m-z/smplayer.profile16
-rw-r--r--etc/profile-m-z/smtube.profile20
-rw-r--r--etc/profile-m-z/smuxi-frontend-gnome.profile14
-rw-r--r--etc/profile-m-z/snox.profile8
-rw-r--r--etc/profile-m-z/softmaker-common.profile6
-rw-r--r--etc/profile-m-z/sound-juicer.profile4
-rw-r--r--etc/profile-m-z/soundconverter.profile8
-rw-r--r--etc/profile-m-z/spectacle.profile12
-rw-r--r--etc/profile-m-z/spectral.profile10
-rw-r--r--etc/profile-m-z/spectre-meltdown-checker.profile6
-rw-r--r--etc/profile-m-z/spotify.profile14
-rw-r--r--etc/profile-m-z/sqlitebrowser.profile4
-rw-r--r--etc/profile-m-z/ssh-agent.profile4
-rw-r--r--etc/profile-m-z/ssh.profile8
-rw-r--r--etc/profile-m-z/standardnotes-desktop.profile8
-rw-r--r--etc/profile-m-z/start-tor-browser.desktop.profile126
-rw-r--r--etc/profile-m-z/steam.profile130
-rw-r--r--etc/profile-m-z/stellarium.profile8
-rw-r--r--etc/profile-m-z/straw-viewer.profile8
-rw-r--r--etc/profile-m-z/strawberry.profile8
-rw-r--r--etc/profile-m-z/strings.profile2
-rw-r--r--etc/profile-m-z/subdownloader.profile4
-rw-r--r--etc/profile-m-z/supertux2.profile8
-rw-r--r--etc/profile-m-z/supertuxkart.profile18
-rw-r--r--etc/profile-m-z/surf.profile6
-rw-r--r--etc/profile-m-z/swell-foop.profile6
-rw-r--r--etc/profile-m-z/sylpheed.profile6
-rw-r--r--etc/profile-m-z/synfigstudio.profile4
-rw-r--r--etc/profile-m-z/sysprof.profile16
-rw-r--r--etc/profile-m-z/tar.profile2
-rw-r--r--etc/profile-m-z/tb-starter-wrapper.profile4
-rw-r--r--etc/profile-m-z/tcpdump.profile6
-rw-r--r--etc/profile-m-z/teams-for-linux.profile4
-rw-r--r--etc/profile-m-z/teams.profile8
-rw-r--r--etc/profile-m-z/teamspeak3.profile8
-rw-r--r--etc/profile-m-z/teeworlds.profile4
-rw-r--r--etc/profile-m-z/telegram.profile10
-rw-r--r--etc/profile-m-z/terasology.profile6
-rw-r--r--etc/profile-m-z/thunderbird.profile24
-rw-r--r--etc/profile-m-z/tilp.profile2
-rw-r--r--etc/profile-m-z/tin.profile10
-rw-r--r--etc/profile-m-z/tmux.profile6
-rw-r--r--etc/profile-m-z/tor-browser-ar.profile4
-rw-r--r--etc/profile-m-z/tor-browser-ca.profile4
-rw-r--r--etc/profile-m-z/tor-browser-cs.profile4
-rw-r--r--etc/profile-m-z/tor-browser-da.profile4
-rw-r--r--etc/profile-m-z/tor-browser-de.profile4
-rw-r--r--etc/profile-m-z/tor-browser-el.profile4
-rw-r--r--etc/profile-m-z/tor-browser-en-us.profile4
-rw-r--r--etc/profile-m-z/tor-browser-en.profile4
-rw-r--r--etc/profile-m-z/tor-browser-es-es.profile4
-rw-r--r--etc/profile-m-z/tor-browser-es.profile4
-rw-r--r--etc/profile-m-z/tor-browser-fa.profile4
-rw-r--r--etc/profile-m-z/tor-browser-fr.profile4
-rw-r--r--etc/profile-m-z/tor-browser-ga-ie.profile4
-rw-r--r--etc/profile-m-z/tor-browser-he.profile4
-rw-r--r--etc/profile-m-z/tor-browser-hu.profile4
-rw-r--r--etc/profile-m-z/tor-browser-id.profile4
-rw-r--r--etc/profile-m-z/tor-browser-is.profile4
-rw-r--r--etc/profile-m-z/tor-browser-it.profile4
-rw-r--r--etc/profile-m-z/tor-browser-ja.profile4
-rw-r--r--etc/profile-m-z/tor-browser-ka.profile4
-rw-r--r--etc/profile-m-z/tor-browser-ko.profile4
-rw-r--r--etc/profile-m-z/tor-browser-nb.profile4
-rw-r--r--etc/profile-m-z/tor-browser-nl.profile4
-rw-r--r--etc/profile-m-z/tor-browser-pl.profile4
-rw-r--r--etc/profile-m-z/tor-browser-pt-br.profile4
-rw-r--r--etc/profile-m-z/tor-browser-ru.profile4
-rw-r--r--etc/profile-m-z/tor-browser-sv-se.profile4
-rw-r--r--etc/profile-m-z/tor-browser-tr.profile4
-rw-r--r--etc/profile-m-z/tor-browser-vi.profile4
-rw-r--r--etc/profile-m-z/tor-browser-zh-cn.profile4
-rw-r--r--etc/profile-m-z/tor-browser-zh-tw.profile4
-rw-r--r--etc/profile-m-z/tor-browser.profile4
-rw-r--r--etc/profile-m-z/tor-browser_ar.profile4
-rw-r--r--etc/profile-m-z/tor-browser_ca.profile4
-rw-r--r--etc/profile-m-z/tor-browser_cs.profile4
-rw-r--r--etc/profile-m-z/tor-browser_da.profile4
-rw-r--r--etc/profile-m-z/tor-browser_de.profile4
-rw-r--r--etc/profile-m-z/tor-browser_el.profile4
-rw-r--r--etc/profile-m-z/tor-browser_en-US.profile4
-rw-r--r--etc/profile-m-z/tor-browser_en.profile4
-rw-r--r--etc/profile-m-z/tor-browser_es-ES.profile4
-rw-r--r--etc/profile-m-z/tor-browser_es.profile4
-rw-r--r--etc/profile-m-z/tor-browser_fa.profile4
-rw-r--r--etc/profile-m-z/tor-browser_fr.profile4
-rw-r--r--etc/profile-m-z/tor-browser_ga-IE.profile4
-rw-r--r--etc/profile-m-z/tor-browser_he.profile4
-rw-r--r--etc/profile-m-z/tor-browser_hu.profile4
-rw-r--r--etc/profile-m-z/tor-browser_id.profile4
-rw-r--r--etc/profile-m-z/tor-browser_is.profile4
-rw-r--r--etc/profile-m-z/tor-browser_it.profile4
-rw-r--r--etc/profile-m-z/tor-browser_ja.profile4
-rw-r--r--etc/profile-m-z/tor-browser_ka.profile4
-rw-r--r--etc/profile-m-z/tor-browser_ko.profile4
-rw-r--r--etc/profile-m-z/tor-browser_nb.profile4
-rw-r--r--etc/profile-m-z/tor-browser_nl.profile4
-rw-r--r--etc/profile-m-z/tor-browser_pl.profile4
-rw-r--r--etc/profile-m-z/tor-browser_pt-BR.profile4
-rw-r--r--etc/profile-m-z/tor-browser_ru.profile4
-rw-r--r--etc/profile-m-z/tor-browser_sv-SE.profile4
-rw-r--r--etc/profile-m-z/tor-browser_tr.profile4
-rw-r--r--etc/profile-m-z/tor-browser_vi.profile4
-rw-r--r--etc/profile-m-z/tor-browser_zh-CN.profile4
-rw-r--r--etc/profile-m-z/tor-browser_zh-TW.profile4
-rw-r--r--etc/profile-m-z/torbrowser-launcher.profile16
-rw-r--r--etc/profile-m-z/torcs.profile8
-rw-r--r--etc/profile-m-z/totem.profile10
-rw-r--r--etc/profile-m-z/tracker.profile4
-rw-r--r--etc/profile-m-z/transgui.profile6
-rw-r--r--etc/profile-m-z/transmission-common.profile10
-rw-r--r--etc/profile-m-z/transmission-daemon.profile4
-rw-r--r--etc/profile-m-z/transmission-remote-gtk.profile4
-rw-r--r--etc/profile-m-z/tremulous.profile6
-rw-r--r--etc/profile-m-z/trojita.profile16
-rw-r--r--etc/profile-m-z/truecraft.profile8
-rw-r--r--etc/profile-m-z/ts3client_runscript.sh.profile8
-rw-r--r--etc/profile-m-z/tutanota-desktop.profile12
-rw-r--r--etc/profile-m-z/tuxguitar.profile6
-rw-r--r--etc/profile-m-z/tvbrowser.profile10
-rw-r--r--etc/profile-m-z/twitch.profile4
-rw-r--r--etc/profile-m-z/uefitool.profile2
-rw-r--r--etc/profile-m-z/uget-gtk.profile6
-rw-r--r--etc/profile-m-z/unbound.profile12
-rw-r--r--etc/profile-m-z/unf.profile4
-rw-r--r--etc/profile-m-z/unknown-horizons.profile6
-rw-r--r--etc/profile-m-z/unzip.profile2
-rw-r--r--etc/profile-m-z/utox.profile8
-rw-r--r--etc/profile-m-z/uudeview.profile2
-rw-r--r--etc/profile-m-z/uzbl-browser.profile16
-rw-r--r--etc/profile-m-z/viewnior.profile8
-rw-r--r--etc/profile-m-z/viking.profile6
-rw-r--r--etc/profile-m-z/vim.profile6
-rw-r--r--etc/profile-m-z/virtualbox.profile18
-rw-r--r--etc/profile-m-z/vivaldi.profile24
-rw-r--r--etc/profile-m-z/vlc.profile16
-rw-r--r--etc/profile-m-z/vmware-view.profile8
-rw-r--r--etc/profile-m-z/vmware.profile8
-rw-r--r--etc/profile-m-z/vscodium.profile2
-rw-r--r--etc/profile-m-z/vulturesclaw.profile4
-rw-r--r--etc/profile-m-z/vultureseye.profile4
-rw-r--r--etc/profile-m-z/vym.profile2
-rw-r--r--etc/profile-m-z/w3m.profile12
-rw-r--r--etc/profile-m-z/warmux.profile14
-rw-r--r--etc/profile-m-z/warsow.profile10
-rw-r--r--etc/profile-m-z/warzone2100.profile8
-rw-r--r--etc/profile-m-z/waterfox.profile8
-rw-r--r--etc/profile-m-z/webstorm.profile14
-rw-r--r--etc/profile-m-z/webui-aria2.profile2
-rw-r--r--etc/profile-m-z/weechat.profile4
-rw-r--r--etc/profile-m-z/wesnoth.profile12
-rw-r--r--etc/profile-m-z/wget.profile10
-rw-r--r--etc/profile-m-z/whalebird.profile4
-rw-r--r--etc/profile-m-z/whois.profile4
-rw-r--r--etc/profile-m-z/widelands.profile4
-rw-r--r--etc/profile-m-z/wine.profile14
-rw-r--r--etc/profile-m-z/wire-desktop.profile4
-rw-r--r--etc/profile-m-z/wireshark.profile8
-rw-r--r--etc/profile-m-z/wordwarvi.profile6
-rw-r--r--etc/profile-m-z/wps.profile6
-rw-r--r--etc/profile-m-z/x2goclient.profile4
-rw-r--r--etc/profile-m-z/xbill.profile4
-rw-r--r--etc/profile-m-z/xchat.profile2
-rw-r--r--etc/profile-m-z/xed.profile8
-rw-r--r--etc/profile-m-z/xfburn.profile2
-rw-r--r--etc/profile-m-z/xfce4-dict.profile2
-rw-r--r--etc/profile-m-z/xfce4-mixer.profile10
-rw-r--r--etc/profile-m-z/xfce4-notes.profile6
-rw-r--r--etc/profile-m-z/xfce4-screenshooter.profile4
-rw-r--r--etc/profile-m-z/xiphos.profile10
-rw-r--r--etc/profile-m-z/xlinks.profile2
-rw-r--r--etc/profile-m-z/xlinks22
-rw-r--r--etc/profile-m-z/xmms.profile4
-rw-r--r--etc/profile-m-z/xmr-stak.profile2
-rw-r--r--etc/profile-m-z/xonotic.profile6
-rw-r--r--etc/profile-m-z/xournal.profile6
-rw-r--r--etc/profile-m-z/xournalpp.profile8
-rw-r--r--etc/profile-m-z/xpdf.profile4
-rw-r--r--etc/profile-m-z/xplayer.profile8
-rw-r--r--etc/profile-m-z/xpra.profile2
-rw-r--r--etc/profile-m-z/xreader.profile6
-rw-r--r--etc/profile-m-z/xviewer.profile8
-rw-r--r--etc/profile-m-z/yandex-browser.profile16
-rw-r--r--etc/profile-m-z/yelp.profile20
-rw-r--r--etc/profile-m-z/youtube-dl-gui.profile6
-rw-r--r--etc/profile-m-z/youtube-dl.profile14
-rw-r--r--etc/profile-m-z/youtube-viewer.profile8
-rw-r--r--etc/profile-m-z/youtube-viewers-common.profile6
-rw-r--r--etc/profile-m-z/youtube.profile4
-rw-r--r--etc/profile-m-z/youtubemusic-nativefier.profile4
-rw-r--r--etc/profile-m-z/ytmdesktop.profile4
-rw-r--r--etc/profile-m-z/zaproxy.profile6
-rw-r--r--etc/profile-m-z/zart.profile4
-rw-r--r--etc/profile-m-z/zathura.profile10
-rw-r--r--etc/profile-m-z/zcat.profile2
-rw-r--r--etc/profile-m-z/zeal.profile12
-rw-r--r--etc/profile-m-z/zgrep.profile2
-rw-r--r--etc/profile-m-z/zoom.profile12
-rw-r--r--etc/profile-m-z/zulip.profile6
-rw-r--r--src/firejail/profile.c7
-rw-r--r--src/tools/profcleaner.c75
799 files changed, 5142 insertions, 5060 deletions
diff --git a/etc/inc/allow-bin-sh.inc b/etc/inc/allow-bin-sh.inc
index d6c295414..59cd40878 100644
--- a/etc/inc/allow-bin-sh.inc
+++ b/etc/inc/allow-bin-sh.inc
@@ -2,6 +2,6 @@
2# Persistent customizations should go in a .local file. 2# Persistent customizations should go in a .local file.
3include allow-bin-sh.local 3include allow-bin-sh.local
4 4
5noblacklist ${PATH}/bash 5nodeny ${PATH}/bash
6noblacklist ${PATH}/dash 6nodeny ${PATH}/dash
7noblacklist ${PATH}/sh 7nodeny ${PATH}/sh
diff --git a/etc/inc/allow-common-devel.inc b/etc/inc/allow-common-devel.inc
index 011bbe226..71b1483cd 100644
--- a/etc/inc/allow-common-devel.inc
+++ b/etc/inc/allow-common-devel.inc
@@ -3,29 +3,29 @@
3include allow-common-devel.local 3include allow-common-devel.local
4 4
5# Git 5# Git
6noblacklist ${HOME}/.config/git 6nodeny ${HOME}/.config/git
7noblacklist ${HOME}/.gitconfig 7nodeny ${HOME}/.gitconfig
8noblacklist ${HOME}/.git-credentials 8nodeny ${HOME}/.git-credentials
9 9
10# Java 10# Java
11noblacklist ${HOME}/.gradle 11nodeny ${HOME}/.gradle
12noblacklist ${HOME}/.java 12nodeny ${HOME}/.java
13 13
14# Node.js 14# Node.js
15noblacklist ${HOME}/.node-gyp 15nodeny ${HOME}/.node-gyp
16noblacklist ${HOME}/.npm 16nodeny ${HOME}/.npm
17noblacklist ${HOME}/.npmrc 17nodeny ${HOME}/.npmrc
18noblacklist ${HOME}/.nvm 18nodeny ${HOME}/.nvm
19noblacklist ${HOME}/.yarn 19nodeny ${HOME}/.yarn
20noblacklist ${HOME}/.yarn-config 20nodeny ${HOME}/.yarn-config
21noblacklist ${HOME}/.yarncache 21nodeny ${HOME}/.yarncache
22noblacklist ${HOME}/.yarnrc 22nodeny ${HOME}/.yarnrc
23 23
24# Python 24# Python
25noblacklist ${HOME}/.pylint.d 25nodeny ${HOME}/.pylint.d
26noblacklist ${HOME}/.python-history 26nodeny ${HOME}/.python-history
27noblacklist ${HOME}/.python_history 27nodeny ${HOME}/.python_history
28noblacklist ${HOME}/.pythonhist 28nodeny ${HOME}/.pythonhist
29 29
30# Rust 30# Rust
31noblacklist ${HOME}/.cargo/* 31nodeny ${HOME}/.cargo/*
diff --git a/etc/inc/allow-gjs.inc b/etc/inc/allow-gjs.inc
index c1366e093..2e2490079 100644
--- a/etc/inc/allow-gjs.inc
+++ b/etc/inc/allow-gjs.inc
@@ -2,11 +2,11 @@
2# Persistent customizations should go in a .local file. 2# Persistent customizations should go in a .local file.
3include allow-gjs.local 3include allow-gjs.local
4 4
5noblacklist ${PATH}/gjs 5nodeny ${PATH}/gjs
6noblacklist ${PATH}/gjs-console 6nodeny ${PATH}/gjs-console
7noblacklist /usr/lib/gjs 7nodeny /usr/lib/gjs
8noblacklist /usr/lib/libgjs* 8nodeny /usr/lib/libgjs*
9noblacklist /usr/lib/libmozjs-* 9nodeny /usr/lib/libmozjs-*
10noblacklist /usr/lib64/gjs 10nodeny /usr/lib64/gjs
11noblacklist /usr/lib64/libgjs* 11nodeny /usr/lib64/libgjs*
12noblacklist /usr/lib64/libmozjs-* 12nodeny /usr/lib64/libmozjs-*
diff --git a/etc/inc/allow-java.inc b/etc/inc/allow-java.inc
index 24d18fb77..af44f3664 100644
--- a/etc/inc/allow-java.inc
+++ b/etc/inc/allow-java.inc
@@ -2,8 +2,8 @@
2# Persistent customizations should go in a .local file. 2# Persistent customizations should go in a .local file.
3include allow-java.local 3include allow-java.local
4 4
5noblacklist ${HOME}/.java 5nodeny ${HOME}/.java
6noblacklist ${PATH}/java 6nodeny ${PATH}/java
7noblacklist /etc/java 7nodeny /etc/java
8noblacklist /usr/lib/java 8nodeny /usr/lib/java
9noblacklist /usr/share/java 9nodeny /usr/share/java
diff --git a/etc/inc/allow-lua.inc b/etc/inc/allow-lua.inc
index 9c47e7a3b..3d0a1997b 100644
--- a/etc/inc/allow-lua.inc
+++ b/etc/inc/allow-lua.inc
@@ -2,11 +2,11 @@
2# Persistent customizations should go in a .local file. 2# Persistent customizations should go in a .local file.
3include allow-lua.local 3include allow-lua.local
4 4
5noblacklist ${PATH}/lua* 5nodeny ${PATH}/lua*
6noblacklist /usr/include 6nodeny /usr/include
7noblacklist /usr/lib/liblua* 7nodeny /usr/lib/liblua*
8noblacklist /usr/lib/lua 8nodeny /usr/lib/lua
9noblacklist /usr/lib64/liblua* 9nodeny /usr/lib64/liblua*
10noblacklist /usr/lib64/lua 10nodeny /usr/lib64/lua
11noblacklist /usr/share/lua 11nodeny /usr/share/lua
12noblacklist /usr/share/lua* 12nodeny /usr/share/lua*
diff --git a/etc/inc/allow-nodejs.inc b/etc/inc/allow-nodejs.inc
index 351c94ab8..e915b3866 100644
--- a/etc/inc/allow-nodejs.inc
+++ b/etc/inc/allow-nodejs.inc
@@ -2,8 +2,8 @@
2# Persistent customizations should go in a .local file. 2# Persistent customizations should go in a .local file.
3include allow-nodejs.local 3include allow-nodejs.local
4 4
5noblacklist ${PATH}/node 5nodeny ${PATH}/node
6noblacklist /usr/include/node 6nodeny /usr/include/node
7 7
8# Allow python for node-gyp (blacklisted by disable-interpreters.inc) 8# Allow python for node-gyp (blacklisted by disable-interpreters.inc)
9include allow-python2.inc 9include allow-python2.inc
diff --git a/etc/inc/allow-opengl-game.inc b/etc/inc/allow-opengl-game.inc
index 5d2d6c5c1..00e35e983 100644
--- a/etc/inc/allow-opengl-game.inc
+++ b/etc/inc/allow-opengl-game.inc
@@ -2,6 +2,6 @@
2# Persistent customizations should go in a .local file. 2# Persistent customizations should go in a .local file.
3include allow-opengl-game.local 3include allow-opengl-game.local
4 4
5noblacklist ${PATH}/bash 5nodeny ${PATH}/bash
6whitelist /usr/share/opengl-games-utils/opengl-game-functions.sh 6allow /usr/share/opengl-games-utils/opengl-game-functions.sh
7private-bin basename,bash,cut,glxinfo,grep,head,sed,zenity 7private-bin basename,bash,cut,glxinfo,grep,head,sed,zenity
diff --git a/etc/inc/allow-perl.inc b/etc/inc/allow-perl.inc
index 5a1952c94..134d27239 100644
--- a/etc/inc/allow-perl.inc
+++ b/etc/inc/allow-perl.inc
@@ -2,11 +2,11 @@
2# Persistent customizations should go in a .local file. 2# Persistent customizations should go in a .local file.
3include allow-perl.local 3include allow-perl.local
4 4
5noblacklist ${PATH}/core_perl 5nodeny ${PATH}/core_perl
6noblacklist ${PATH}/cpan* 6nodeny ${PATH}/cpan*
7noblacklist ${PATH}/perl 7nodeny ${PATH}/perl
8noblacklist ${PATH}/site_perl 8nodeny ${PATH}/site_perl
9noblacklist ${PATH}/vendor_perl 9nodeny ${PATH}/vendor_perl
10noblacklist /usr/lib/perl* 10nodeny /usr/lib/perl*
11noblacklist /usr/lib64/perl* 11nodeny /usr/lib64/perl*
12noblacklist /usr/share/perl* 12nodeny /usr/share/perl*
diff --git a/etc/inc/allow-php.inc b/etc/inc/allow-php.inc
index a0950dc26..520c2019e 100644
--- a/etc/inc/allow-php.inc
+++ b/etc/inc/allow-php.inc
@@ -2,6 +2,6 @@
2# Persistent customizations should go in a .local file. 2# Persistent customizations should go in a .local file.
3include allow-php.local 3include allow-php.local
4 4
5noblacklist ${PATH}/php* 5nodeny ${PATH}/php*
6noblacklist /usr/lib/php* 6nodeny /usr/lib/php*
7noblacklist /usr/share/php* 7nodeny /usr/share/php*
diff --git a/etc/inc/allow-python2.inc b/etc/inc/allow-python2.inc
index b0525e2e1..f1830043a 100644
--- a/etc/inc/allow-python2.inc
+++ b/etc/inc/allow-python2.inc
@@ -2,8 +2,8 @@
2# Persistent customizations should go in a .local file. 2# Persistent customizations should go in a .local file.
3include allow-python2.local 3include allow-python2.local
4 4
5noblacklist ${PATH}/python2* 5nodeny ${PATH}/python2*
6noblacklist /usr/include/python2* 6nodeny /usr/include/python2*
7noblacklist /usr/lib/python2* 7nodeny /usr/lib/python2*
8noblacklist /usr/local/lib/python2* 8nodeny /usr/local/lib/python2*
9noblacklist /usr/share/python2* 9nodeny /usr/share/python2*
diff --git a/etc/inc/allow-python3.inc b/etc/inc/allow-python3.inc
index d968886b0..e4b6ed1a9 100644
--- a/etc/inc/allow-python3.inc
+++ b/etc/inc/allow-python3.inc
@@ -2,9 +2,9 @@
2# Persistent customizations should go in a .local file. 2# Persistent customizations should go in a .local file.
3include allow-python3.local 3include allow-python3.local
4 4
5noblacklist ${PATH}/python3* 5nodeny ${PATH}/python3*
6noblacklist /usr/include/python3* 6nodeny /usr/include/python3*
7noblacklist /usr/lib/python3* 7nodeny /usr/lib/python3*
8noblacklist /usr/lib64/python3* 8nodeny /usr/lib64/python3*
9noblacklist /usr/local/lib/python3* 9nodeny /usr/local/lib/python3*
10noblacklist /usr/share/python3* 10nodeny /usr/share/python3*
diff --git a/etc/inc/allow-ruby.inc b/etc/inc/allow-ruby.inc
index a8c701219..d949bbc84 100644
--- a/etc/inc/allow-ruby.inc
+++ b/etc/inc/allow-ruby.inc
@@ -2,5 +2,5 @@
2# Persistent customizations should go in a .local file. 2# Persistent customizations should go in a .local file.
3include allow-ruby.local 3include allow-ruby.local
4 4
5noblacklist ${PATH}/ruby 5nodeny ${PATH}/ruby
6noblacklist /usr/lib/ruby 6nodeny /usr/lib/ruby
diff --git a/etc/inc/allow-ssh.inc b/etc/inc/allow-ssh.inc
index 67c78a483..44957bf32 100644
--- a/etc/inc/allow-ssh.inc
+++ b/etc/inc/allow-ssh.inc
@@ -2,7 +2,7 @@
2# Persistent customizations should go in a .local file. 2# Persistent customizations should go in a .local file.
3include allow-ssh.local 3include allow-ssh.local
4 4
5noblacklist ${HOME}/.ssh 5nodeny ${HOME}/.ssh
6noblacklist /etc/ssh 6nodeny /etc/ssh
7noblacklist /etc/ssh/ssh_config 7nodeny /etc/ssh/ssh_config
8noblacklist /tmp/ssh-* 8nodeny /tmp/ssh-*
diff --git a/etc/inc/disable-common.inc b/etc/inc/disable-common.inc
index 2dc53d311..4c83284ee 100644
--- a/etc/inc/disable-common.inc
+++ b/etc/inc/disable-common.inc
@@ -5,63 +5,63 @@ include disable-common.local
5# The following block breaks trash functionality in file managers 5# The following block breaks trash functionality in file managers
6#read-only ${HOME}/.local 6#read-only ${HOME}/.local
7#read-write ${HOME}/.local/share 7#read-write ${HOME}/.local/share
8blacklist ${HOME}/.local/share/Trash 8deny ${HOME}/.local/share/Trash
9 9
10# History files in $HOME and clipboard managers 10# History files in $HOME and clipboard managers
11blacklist-nolog ${HOME}/.*_history 11deny-nolog ${HOME}/.*_history
12blacklist-nolog ${HOME}/.adobe 12deny-nolog ${HOME}/.adobe
13blacklist-nolog ${HOME}/.cache/greenclip* 13deny-nolog ${HOME}/.cache/greenclip*
14blacklist-nolog ${HOME}/.histfile 14deny-nolog ${HOME}/.histfile
15blacklist-nolog ${HOME}/.history 15deny-nolog ${HOME}/.history
16blacklist-nolog ${HOME}/.kde/share/apps/klipper 16deny-nolog ${HOME}/.kde/share/apps/klipper
17blacklist-nolog ${HOME}/.kde4/share/apps/klipper 17deny-nolog ${HOME}/.kde4/share/apps/klipper
18blacklist-nolog ${HOME}/.local/share/fish/fish_history 18deny-nolog ${HOME}/.local/share/fish/fish_history
19blacklist-nolog ${HOME}/.local/share/klipper 19deny-nolog ${HOME}/.local/share/klipper
20blacklist-nolog ${HOME}/.macromedia 20deny-nolog ${HOME}/.macromedia
21blacklist-nolog ${HOME}/.mupdf.history 21deny-nolog ${HOME}/.mupdf.history
22blacklist-nolog ${HOME}/.python-history 22deny-nolog ${HOME}/.python-history
23blacklist-nolog ${HOME}/.python_history 23deny-nolog ${HOME}/.python_history
24blacklist-nolog ${HOME}/.pythonhist 24deny-nolog ${HOME}/.pythonhist
25blacklist-nolog ${HOME}/.lesshst 25deny-nolog ${HOME}/.lesshst
26blacklist-nolog ${HOME}/.viminfo 26deny-nolog ${HOME}/.viminfo
27blacklist-nolog /tmp/clipmenu* 27deny-nolog /tmp/clipmenu*
28 28
29# X11 session autostart 29# X11 session autostart
30# blacklist ${HOME}/.xpra - this will kill --x11=xpra cmdline option for all programs 30# blacklist ${HOME}/.xpra - this will kill --x11=xpra cmdline option for all programs
31blacklist ${HOME}/.Xsession 31deny ${HOME}/.Xsession
32blacklist ${HOME}/.blackbox 32deny ${HOME}/.blackbox
33blacklist ${HOME}/.config/autostart 33deny ${HOME}/.config/autostart
34blacklist ${HOME}/.config/autostart-scripts 34deny ${HOME}/.config/autostart-scripts
35blacklist ${HOME}/.config/awesome 35deny ${HOME}/.config/awesome
36blacklist ${HOME}/.config/i3 36deny ${HOME}/.config/i3
37blacklist ${HOME}/.config/sway 37deny ${HOME}/.config/sway
38blacklist ${HOME}/.config/lxsession/LXDE/autostart 38deny ${HOME}/.config/lxsession/LXDE/autostart
39blacklist ${HOME}/.config/openbox 39deny ${HOME}/.config/openbox
40blacklist ${HOME}/.config/plasma-workspace 40deny ${HOME}/.config/plasma-workspace
41blacklist ${HOME}/.config/startupconfig 41deny ${HOME}/.config/startupconfig
42blacklist ${HOME}/.config/startupconfigkeys 42deny ${HOME}/.config/startupconfigkeys
43blacklist ${HOME}/.fluxbox 43deny ${HOME}/.fluxbox
44blacklist ${HOME}/.gnomerc 44deny ${HOME}/.gnomerc
45blacklist ${HOME}/.kde/Autostart 45deny ${HOME}/.kde/Autostart
46blacklist ${HOME}/.kde/env 46deny ${HOME}/.kde/env
47blacklist ${HOME}/.kde/share/autostart 47deny ${HOME}/.kde/share/autostart
48blacklist ${HOME}/.kde/share/config/startupconfig 48deny ${HOME}/.kde/share/config/startupconfig
49blacklist ${HOME}/.kde/share/config/startupconfigkeys 49deny ${HOME}/.kde/share/config/startupconfigkeys
50blacklist ${HOME}/.kde/shutdown 50deny ${HOME}/.kde/shutdown
51blacklist ${HOME}/.kde4/env 51deny ${HOME}/.kde4/env
52blacklist ${HOME}/.kde4/Autostart 52deny ${HOME}/.kde4/Autostart
53blacklist ${HOME}/.kde4/share/autostart 53deny ${HOME}/.kde4/share/autostart
54blacklist ${HOME}/.kde4/shutdown 54deny ${HOME}/.kde4/shutdown
55blacklist ${HOME}/.kde4/share/config/startupconfig 55deny ${HOME}/.kde4/share/config/startupconfig
56blacklist ${HOME}/.kde4/share/config/startupconfigkeys 56deny ${HOME}/.kde4/share/config/startupconfigkeys
57blacklist ${HOME}/.local/share/autostart 57deny ${HOME}/.local/share/autostart
58blacklist ${HOME}/.xinitrc 58deny ${HOME}/.xinitrc
59blacklist ${HOME}/.xprofile 59deny ${HOME}/.xprofile
60blacklist ${HOME}/.xserverrc 60deny ${HOME}/.xserverrc
61blacklist ${HOME}/.xsession 61deny ${HOME}/.xsession
62blacklist ${HOME}/.xsessionrc 62deny ${HOME}/.xsessionrc
63blacklist /etc/X11/Xsession.d 63deny /etc/X11/Xsession.d
64blacklist /etc/xdg/autostart 64deny /etc/xdg/autostart
65read-only ${HOME}/.Xauthority 65read-only ${HOME}/.Xauthority
66 66
67# Session manager 67# Session manager
@@ -70,46 +70,46 @@ read-only ${HOME}/.Xauthority
70#?HAS_X11: blacklist /tmp/.ICE-unix 70#?HAS_X11: blacklist /tmp/.ICE-unix
71 71
72# KDE config 72# KDE config
73blacklist ${HOME}/.cache/konsole 73deny ${HOME}/.cache/konsole
74blacklist ${HOME}/.config/khotkeysrc 74deny ${HOME}/.config/khotkeysrc
75blacklist ${HOME}/.config/krunnerrc 75deny ${HOME}/.config/krunnerrc
76blacklist ${HOME}/.config/kscreenlockerrc 76deny ${HOME}/.config/kscreenlockerrc
77blacklist ${HOME}/.config/ksslcertificatemanager 77deny ${HOME}/.config/ksslcertificatemanager
78blacklist ${HOME}/.config/kwalletrc 78deny ${HOME}/.config/kwalletrc
79blacklist ${HOME}/.config/kwinrc 79deny ${HOME}/.config/kwinrc
80blacklist ${HOME}/.config/kwinrulesrc 80deny ${HOME}/.config/kwinrulesrc
81blacklist ${HOME}/.config/plasma-locale-settings.sh 81deny ${HOME}/.config/plasma-locale-settings.sh
82blacklist ${HOME}/.config/plasma-org.kde.plasma.desktop-appletsrc 82deny ${HOME}/.config/plasma-org.kde.plasma.desktop-appletsrc
83blacklist ${HOME}/.config/plasmashellrc 83deny ${HOME}/.config/plasmashellrc
84blacklist ${HOME}/.config/plasmavaultrc 84deny ${HOME}/.config/plasmavaultrc
85blacklist ${HOME}/.kde/share/apps/kwin 85deny ${HOME}/.kde/share/apps/kwin
86blacklist ${HOME}/.kde/share/apps/plasma 86deny ${HOME}/.kde/share/apps/plasma
87blacklist ${HOME}/.kde/share/apps/solid 87deny ${HOME}/.kde/share/apps/solid
88blacklist ${HOME}/.kde/share/config/khotkeysrc 88deny ${HOME}/.kde/share/config/khotkeysrc
89blacklist ${HOME}/.kde/share/config/krunnerrc 89deny ${HOME}/.kde/share/config/krunnerrc
90blacklist ${HOME}/.kde/share/config/kscreensaverrc 90deny ${HOME}/.kde/share/config/kscreensaverrc
91blacklist ${HOME}/.kde/share/config/ksslcertificatemanager 91deny ${HOME}/.kde/share/config/ksslcertificatemanager
92blacklist ${HOME}/.kde/share/config/kwalletrc 92deny ${HOME}/.kde/share/config/kwalletrc
93blacklist ${HOME}/.kde/share/config/kwinrc 93deny ${HOME}/.kde/share/config/kwinrc
94blacklist ${HOME}/.kde/share/config/kwinrulesrc 94deny ${HOME}/.kde/share/config/kwinrulesrc
95blacklist ${HOME}/.kde/share/config/plasma-desktop-appletsrc 95deny ${HOME}/.kde/share/config/plasma-desktop-appletsrc
96blacklist ${HOME}/.kde4/share/apps/kwin 96deny ${HOME}/.kde4/share/apps/kwin
97blacklist ${HOME}/.kde4/share/apps/plasma 97deny ${HOME}/.kde4/share/apps/plasma
98blacklist ${HOME}/.kde4/share/apps/solid 98deny ${HOME}/.kde4/share/apps/solid
99blacklist ${HOME}/.kde4/share/config/khotkeysrc 99deny ${HOME}/.kde4/share/config/khotkeysrc
100blacklist ${HOME}/.kde4/share/config/krunnerrc 100deny ${HOME}/.kde4/share/config/krunnerrc
101blacklist ${HOME}/.kde4/share/config/kscreensaverrc 101deny ${HOME}/.kde4/share/config/kscreensaverrc
102blacklist ${HOME}/.kde4/share/config/ksslcertificatemanager 102deny ${HOME}/.kde4/share/config/ksslcertificatemanager
103blacklist ${HOME}/.kde4/share/config/kwalletrc 103deny ${HOME}/.kde4/share/config/kwalletrc
104blacklist ${HOME}/.kde4/share/config/kwinrc 104deny ${HOME}/.kde4/share/config/kwinrc
105blacklist ${HOME}/.kde4/share/config/kwinrulesrc 105deny ${HOME}/.kde4/share/config/kwinrulesrc
106blacklist ${HOME}/.kde4/share/config/plasma-desktop-appletsrc 106deny ${HOME}/.kde4/share/config/plasma-desktop-appletsrc
107blacklist ${HOME}/.local/share/kglobalaccel 107deny ${HOME}/.local/share/kglobalaccel
108blacklist ${HOME}/.local/share/kwin 108deny ${HOME}/.local/share/kwin
109blacklist ${HOME}/.local/share/plasma 109deny ${HOME}/.local/share/plasma
110blacklist ${HOME}/.local/share/plasmashell 110deny ${HOME}/.local/share/plasmashell
111blacklist ${HOME}/.local/share/solid 111deny ${HOME}/.local/share/solid
112blacklist /tmp/konsole-*.history 112deny /tmp/konsole-*.history
113read-only ${HOME}/.cache/ksycoca5_* 113read-only ${HOME}/.cache/ksycoca5_*
114read-only ${HOME}/.config/*notifyrc 114read-only ${HOME}/.config/*notifyrc
115read-only ${HOME}/.config/kdeglobals 115read-only ${HOME}/.config/kdeglobals
@@ -138,124 +138,124 @@ read-only ${HOME}/.local/share/kservices5
138read-only ${HOME}/.local/share/kssl 138read-only ${HOME}/.local/share/kssl
139 139
140# KDE sockets 140# KDE sockets
141blacklist ${RUNUSER}/*.slave-socket 141deny ${RUNUSER}/*.slave-socket
142blacklist ${RUNUSER}/kdeinit5__* 142deny ${RUNUSER}/kdeinit5__*
143blacklist ${RUNUSER}/kdesud_* 143deny ${RUNUSER}/kdesud_*
144# see #3358 144# see #3358
145#?HAS_NODBUS: blacklist ${RUNUSER}/ksocket-* 145#?HAS_NODBUS: blacklist ${RUNUSER}/ksocket-*
146#?HAS_NODBUS: blacklist /tmp/ksocket-* 146#?HAS_NODBUS: blacklist /tmp/ksocket-*
147 147
148# gnome 148# gnome
149# contains extensions, last used times of applications, and notifications 149# contains extensions, last used times of applications, and notifications
150blacklist ${HOME}/.local/share/gnome-shell 150deny ${HOME}/.local/share/gnome-shell
151# contains recently used files and serials of static/removable storage 151# contains recently used files and serials of static/removable storage
152blacklist ${HOME}/.local/share/gvfs-metadata 152deny ${HOME}/.local/share/gvfs-metadata
153# no direct modification of dconf database 153# no direct modification of dconf database
154read-only ${HOME}/.config/dconf 154read-only ${HOME}/.config/dconf
155blacklist ${RUNUSER}/gnome-session-leader-fifo 155deny ${RUNUSER}/gnome-session-leader-fifo
156blacklist ${RUNUSER}/gnome-shell 156deny ${RUNUSER}/gnome-shell
157blacklist ${RUNUSER}/gsconnect 157deny ${RUNUSER}/gsconnect
158 158
159# systemd 159# systemd
160blacklist ${HOME}/.config/systemd 160deny ${HOME}/.config/systemd
161blacklist ${HOME}/.local/share/systemd 161deny ${HOME}/.local/share/systemd
162blacklist /var/lib/systemd 162deny /var/lib/systemd
163blacklist ${PATH}/systemd-run 163deny ${PATH}/systemd-run
164blacklist ${RUNUSER}/systemd 164deny ${RUNUSER}/systemd
165# creates problems on Arch where /etc/resolv.conf is a symlink to /var/run/systemd/resolve/resolv.conf 165# creates problems on Arch where /etc/resolv.conf is a symlink to /var/run/systemd/resolve/resolv.conf
166#blacklist /var/run/systemd 166#blacklist /var/run/systemd
167 167
168# openrc 168# openrc
169blacklist /etc/runlevels/ 169deny /etc/runlevels/
170blacklist /etc/init.d/ 170deny /etc/init.d/
171blacklist /etc/rc.conf 171deny /etc/rc.conf
172 172
173# VirtualBox 173# VirtualBox
174blacklist ${HOME}/.VirtualBox 174deny ${HOME}/.VirtualBox
175blacklist ${HOME}/.config/VirtualBox 175deny ${HOME}/.config/VirtualBox
176blacklist ${HOME}/VirtualBox VMs 176deny ${HOME}/VirtualBox VMs
177 177
178# GNOME Boxes 178# GNOME Boxes
179blacklist ${HOME}/.config/gnome-boxes 179deny ${HOME}/.config/gnome-boxes
180blacklist ${HOME}/.local/share/gnome-boxes 180deny ${HOME}/.local/share/gnome-boxes
181 181
182# libvirt 182# libvirt
183blacklist ${HOME}/.cache/libvirt 183deny ${HOME}/.cache/libvirt
184blacklist ${HOME}/.config/libvirt 184deny ${HOME}/.config/libvirt
185blacklist ${RUNUSER}/libvirt 185deny ${RUNUSER}/libvirt
186blacklist /var/cache/libvirt 186deny /var/cache/libvirt
187blacklist /var/lib/libvirt 187deny /var/lib/libvirt
188blacklist /var/log/libvirt 188deny /var/log/libvirt
189 189
190# OCI-Containers / Podman 190# OCI-Containers / Podman
191blacklist ${RUNUSER}/containers 191deny ${RUNUSER}/containers
192blacklist ${RUNUSER}/crun 192deny ${RUNUSER}/crun
193blacklist ${RUNUSER}/libpod 193deny ${RUNUSER}/libpod
194blacklist ${RUNUSER}/runc 194deny ${RUNUSER}/runc
195blacklist ${RUNUSER}/toolbox 195deny ${RUNUSER}/toolbox
196 196
197# VeraCrypt 197# VeraCrypt
198blacklist ${HOME}/.VeraCrypt 198deny ${HOME}/.VeraCrypt
199blacklist ${PATH}/veracrypt 199deny ${PATH}/veracrypt
200blacklist ${PATH}/veracrypt-uninstall.sh 200deny ${PATH}/veracrypt-uninstall.sh
201blacklist /usr/share/applications/veracrypt.* 201deny /usr/share/applications/veracrypt.*
202blacklist /usr/share/pixmaps/veracrypt.* 202deny /usr/share/pixmaps/veracrypt.*
203blacklist /usr/share/veracrypt 203deny /usr/share/veracrypt
204 204
205# TrueCrypt 205# TrueCrypt
206blacklist ${HOME}/.TrueCrypt 206deny ${HOME}/.TrueCrypt
207blacklist ${PATH}/truecrypt 207deny ${PATH}/truecrypt
208blacklist ${PATH}/truecrypt-uninstall.sh 208deny ${PATH}/truecrypt-uninstall.sh
209blacklist /usr/share/applications/truecrypt.* 209deny /usr/share/applications/truecrypt.*
210blacklist /usr/share/pixmaps/truecrypt.* 210deny /usr/share/pixmaps/truecrypt.*
211blacklist /usr/share/truecrypt 211deny /usr/share/truecrypt
212 212
213# zuluCrypt 213# zuluCrypt
214blacklist ${HOME}/.zuluCrypt 214deny ${HOME}/.zuluCrypt
215blacklist ${HOME}/.zuluCrypt-socket 215deny ${HOME}/.zuluCrypt-socket
216blacklist ${PATH}/zuluCrypt-cli 216deny ${PATH}/zuluCrypt-cli
217blacklist ${PATH}/zuluMount-cli 217deny ${PATH}/zuluMount-cli
218 218
219# var 219# var
220blacklist /var/cache/apt 220deny /var/cache/apt
221blacklist /var/cache/pacman 221deny /var/cache/pacman
222blacklist /var/lib/apt 222deny /var/lib/apt
223blacklist /var/lib/clamav 223deny /var/lib/clamav
224blacklist /var/lib/dkms 224deny /var/lib/dkms
225blacklist /var/lib/mysql/mysql.sock 225deny /var/lib/mysql/mysql.sock
226blacklist /var/lib/mysqld/mysql.sock 226deny /var/lib/mysqld/mysql.sock
227blacklist /var/lib/pacman 227deny /var/lib/pacman
228blacklist /var/lib/upower 228deny /var/lib/upower
229# blacklist /var/log - a virtual /var/log directory (mostly empty) is build up by default for 229# blacklist /var/log - a virtual /var/log directory (mostly empty) is build up by default for
230# every sandbox, unless --writable-var-log switch is activated 230# every sandbox, unless --writable-var-log switch is activated
231blacklist /var/mail 231deny /var/mail
232blacklist /var/opt 232deny /var/opt
233blacklist /var/run/acpid.socket 233deny /var/run/acpid.socket
234blacklist /var/run/docker.sock 234deny /var/run/docker.sock
235blacklist /var/run/minissdpd.sock 235deny /var/run/minissdpd.sock
236blacklist /var/run/mysql/mysqld.sock 236deny /var/run/mysql/mysqld.sock
237blacklist /var/run/mysqld/mysqld.sock 237deny /var/run/mysqld/mysqld.sock
238blacklist /var/run/rpcbind.sock 238deny /var/run/rpcbind.sock
239blacklist /var/run/screens 239deny /var/run/screens
240blacklist /var/spool/anacron 240deny /var/spool/anacron
241blacklist /var/spool/cron 241deny /var/spool/cron
242blacklist /var/spool/mail 242deny /var/spool/mail
243 243
244# etc 244# etc
245blacklist /etc/anacrontab 245deny /etc/anacrontab
246blacklist /etc/cron* 246deny /etc/cron*
247blacklist /etc/profile.d 247deny /etc/profile.d
248blacklist /etc/rc.local 248deny /etc/rc.local
249# rc1.d, rc2.d, ... 249# rc1.d, rc2.d, ...
250blacklist /etc/rc?.d 250deny /etc/rc?.d
251blacklist /etc/kernel* 251deny /etc/kernel*
252blacklist /etc/grub* 252deny /etc/grub*
253blacklist /etc/dkms 253deny /etc/dkms
254blacklist /etc/apparmor* 254deny /etc/apparmor*
255blacklist /etc/selinux 255deny /etc/selinux
256blacklist /etc/modules* 256deny /etc/modules*
257blacklist /etc/logrotate* 257deny /etc/logrotate*
258blacklist /etc/adduser.conf 258deny /etc/adduser.conf
259 259
260# Startup files 260# Startup files
261read-only ${HOME}/.antigen 261read-only ${HOME}/.antigen
@@ -292,13 +292,13 @@ read-only ${HOME}/.zshrc
292read-only ${HOME}/.zshrc.local 292read-only ${HOME}/.zshrc.local
293 293
294# Remote access 294# Remote access
295blacklist ${HOME}/.rhosts 295deny ${HOME}/.rhosts
296blacklist ${HOME}/.shosts 296deny ${HOME}/.shosts
297blacklist ${HOME}/.ssh/authorized_keys 297deny ${HOME}/.ssh/authorized_keys
298blacklist ${HOME}/.ssh/authorized_keys2 298deny ${HOME}/.ssh/authorized_keys2
299blacklist ${HOME}/.ssh/environment 299deny ${HOME}/.ssh/environment
300blacklist ${HOME}/.ssh/rc 300deny ${HOME}/.ssh/rc
301blacklist /etc/hosts.equiv 301deny /etc/hosts.equiv
302read-only ${HOME}/.ssh/config 302read-only ${HOME}/.ssh/config
303read-only ${HOME}/.ssh/config.d 303read-only ${HOME}/.ssh/config.d
304 304
@@ -359,200 +359,200 @@ read-only ${HOME}/.local/share/mime
359read-only ${HOME}/.local/share/thumbnailers 359read-only ${HOME}/.local/share/thumbnailers
360 360
361# prevent access to ssh-agent 361# prevent access to ssh-agent
362blacklist /tmp/ssh-* 362deny /tmp/ssh-*
363 363
364# top secret 364# top secret
365blacklist ${HOME}/*.kdb 365deny ${HOME}/*.kdb
366blacklist ${HOME}/*.kdbx 366deny ${HOME}/*.kdbx
367blacklist ${HOME}/*.key 367deny ${HOME}/*.key
368blacklist ${HOME}/.Private 368deny ${HOME}/.Private
369blacklist ${HOME}/.caff 369deny ${HOME}/.caff
370blacklist ${HOME}/.cargo/credentials 370deny ${HOME}/.cargo/credentials
371blacklist ${HOME}/.cargo/credentials.toml 371deny ${HOME}/.cargo/credentials.toml
372blacklist ${HOME}/.cert 372deny ${HOME}/.cert
373blacklist ${HOME}/.config/keybase 373deny ${HOME}/.config/keybase
374blacklist ${HOME}/.davfs2/secrets 374deny ${HOME}/.davfs2/secrets
375blacklist ${HOME}/.ecryptfs 375deny ${HOME}/.ecryptfs
376blacklist ${HOME}/.fetchmailrc 376deny ${HOME}/.fetchmailrc
377blacklist ${HOME}/.fscrypt 377deny ${HOME}/.fscrypt
378blacklist ${HOME}/.git-credential-cache 378deny ${HOME}/.git-credential-cache
379blacklist ${HOME}/.git-credentials 379deny ${HOME}/.git-credentials
380blacklist ${HOME}/.gnome2/keyrings 380deny ${HOME}/.gnome2/keyrings
381blacklist ${HOME}/.gnupg 381deny ${HOME}/.gnupg
382blacklist ${HOME}/.config/hub 382deny ${HOME}/.config/hub
383blacklist ${HOME}/.kde/share/apps/kwallet 383deny ${HOME}/.kde/share/apps/kwallet
384blacklist ${HOME}/.kde4/share/apps/kwallet 384deny ${HOME}/.kde4/share/apps/kwallet
385blacklist ${HOME}/.local/share/keyrings 385deny ${HOME}/.local/share/keyrings
386blacklist ${HOME}/.local/share/kwalletd 386deny ${HOME}/.local/share/kwalletd
387blacklist ${HOME}/.local/share/plasma-vault 387deny ${HOME}/.local/share/plasma-vault
388blacklist ${HOME}/.msmtprc 388deny ${HOME}/.msmtprc
389blacklist ${HOME}/.mutt 389deny ${HOME}/.mutt
390blacklist ${HOME}/.muttrc 390deny ${HOME}/.muttrc
391blacklist ${HOME}/.netrc 391deny ${HOME}/.netrc
392blacklist ${HOME}/.nyx 392deny ${HOME}/.nyx
393blacklist ${HOME}/.pki 393deny ${HOME}/.pki
394blacklist ${HOME}/.local/share/pki 394deny ${HOME}/.local/share/pki
395blacklist ${HOME}/.smbcredentials 395deny ${HOME}/.smbcredentials
396blacklist ${HOME}/.ssh 396deny ${HOME}/.ssh
397blacklist ${HOME}/.vaults 397deny ${HOME}/.vaults
398blacklist /.fscrypt 398deny /.fscrypt
399blacklist /etc/davfs2/secrets 399deny /etc/davfs2/secrets
400blacklist /etc/group+ 400deny /etc/group+
401blacklist /etc/group- 401deny /etc/group-
402blacklist /etc/gshadow 402deny /etc/gshadow
403blacklist /etc/gshadow+ 403deny /etc/gshadow+
404blacklist /etc/gshadow- 404deny /etc/gshadow-
405blacklist /etc/passwd+ 405deny /etc/passwd+
406blacklist /etc/passwd- 406deny /etc/passwd-
407blacklist /etc/shadow 407deny /etc/shadow
408blacklist /etc/shadow+ 408deny /etc/shadow+
409blacklist /etc/shadow- 409deny /etc/shadow-
410blacklist /etc/ssh 410deny /etc/ssh
411blacklist /etc/ssh/* 411deny /etc/ssh/*
412blacklist /home/.ecryptfs 412deny /home/.ecryptfs
413blacklist /home/.fscrypt 413deny /home/.fscrypt
414blacklist /var/backup 414deny /var/backup
415 415
416# cloud provider configuration 416# cloud provider configuration
417blacklist ${HOME}/.aws 417deny ${HOME}/.aws
418blacklist ${HOME}/.boto 418deny ${HOME}/.boto
419blacklist ${HOME}/.config/gcloud 419deny ${HOME}/.config/gcloud
420blacklist ${HOME}/.kube 420deny ${HOME}/.kube
421blacklist ${HOME}/.passwd-s3fs 421deny ${HOME}/.passwd-s3fs
422blacklist ${HOME}/.s3cmd 422deny ${HOME}/.s3cmd
423blacklist /etc/boto.cfg 423deny /etc/boto.cfg
424 424
425# system directories 425# system directories
426blacklist /sbin 426deny /sbin
427blacklist /usr/local/sbin 427deny /usr/local/sbin
428blacklist /usr/sbin 428deny /usr/sbin
429 429
430# system management 430# system management
431blacklist ${PATH}/at 431deny ${PATH}/at
432blacklist ${PATH}/busybox 432deny ${PATH}/busybox
433blacklist ${PATH}/chage 433deny ${PATH}/chage
434blacklist ${PATH}/chfn 434deny ${PATH}/chfn
435blacklist ${PATH}/chsh 435deny ${PATH}/chsh
436blacklist ${PATH}/crontab 436deny ${PATH}/crontab
437blacklist ${PATH}/evtest 437deny ${PATH}/evtest
438blacklist ${PATH}/expiry 438deny ${PATH}/expiry
439blacklist ${PATH}/fusermount 439deny ${PATH}/fusermount
440blacklist ${PATH}/gksu 440deny ${PATH}/gksu
441blacklist ${PATH}/gksudo 441deny ${PATH}/gksudo
442blacklist ${PATH}/gpasswd 442deny ${PATH}/gpasswd
443blacklist ${PATH}/kdesudo 443deny ${PATH}/kdesudo
444blacklist ${PATH}/ksu 444deny ${PATH}/ksu
445blacklist ${PATH}/mount 445deny ${PATH}/mount
446blacklist ${PATH}/mount.ecryptfs_private 446deny ${PATH}/mount.ecryptfs_private
447blacklist ${PATH}/nc 447deny ${PATH}/nc
448blacklist ${PATH}/ncat 448deny ${PATH}/ncat
449blacklist ${PATH}/nmap 449deny ${PATH}/nmap
450blacklist ${PATH}/newgidmap 450deny ${PATH}/newgidmap
451blacklist ${PATH}/newgrp 451deny ${PATH}/newgrp
452blacklist ${PATH}/newuidmap 452deny ${PATH}/newuidmap
453blacklist ${PATH}/ntfs-3g 453deny ${PATH}/ntfs-3g
454blacklist ${PATH}/pkexec 454deny ${PATH}/pkexec
455blacklist ${PATH}/procmail 455deny ${PATH}/procmail
456blacklist ${PATH}/sg 456deny ${PATH}/sg
457blacklist ${PATH}/strace 457deny ${PATH}/strace
458blacklist ${PATH}/su 458deny ${PATH}/su
459blacklist ${PATH}/sudo 459deny ${PATH}/sudo
460blacklist ${PATH}/tcpdump 460deny ${PATH}/tcpdump
461blacklist ${PATH}/umount 461deny ${PATH}/umount
462blacklist ${PATH}/unix_chkpwd 462deny ${PATH}/unix_chkpwd
463blacklist ${PATH}/xev 463deny ${PATH}/xev
464blacklist ${PATH}/xinput 464deny ${PATH}/xinput
465 465
466# other SUID binaries 466# other SUID binaries
467blacklist /usr/lib/virtualbox 467deny /usr/lib/virtualbox
468blacklist /usr/lib64/virtualbox 468deny /usr/lib64/virtualbox
469 469
470# prevent lxterminal connecting to an existing lxterminal session 470# prevent lxterminal connecting to an existing lxterminal session
471blacklist /tmp/.lxterminal-socket* 471deny /tmp/.lxterminal-socket*
472# prevent tmux connecting to an existing session 472# prevent tmux connecting to an existing session
473blacklist /tmp/tmux-* 473deny /tmp/tmux-*
474 474
475# disable terminals running as server resulting in sandbox escape 475# disable terminals running as server resulting in sandbox escape
476blacklist ${PATH}/lxterminal 476deny ${PATH}/lxterminal
477blacklist ${PATH}/gnome-terminal 477deny ${PATH}/gnome-terminal
478blacklist ${PATH}/gnome-terminal.wrapper 478deny ${PATH}/gnome-terminal.wrapper
479blacklist ${PATH}/lilyterm 479deny ${PATH}/lilyterm
480blacklist ${PATH}/mate-terminal 480deny ${PATH}/mate-terminal
481blacklist ${PATH}/mate-terminal.wrapper 481deny ${PATH}/mate-terminal.wrapper
482blacklist ${PATH}/pantheon-terminal 482deny ${PATH}/pantheon-terminal
483blacklist ${PATH}/roxterm 483deny ${PATH}/roxterm
484blacklist ${PATH}/roxterm-config 484deny ${PATH}/roxterm-config
485blacklist ${PATH}/terminix 485deny ${PATH}/terminix
486blacklist ${PATH}/tilix 486deny ${PATH}/tilix
487blacklist ${PATH}/urxvtc 487deny ${PATH}/urxvtc
488blacklist ${PATH}/urxvtcd 488deny ${PATH}/urxvtcd
489blacklist ${PATH}/xfce4-terminal 489deny ${PATH}/xfce4-terminal
490blacklist ${PATH}/xfce4-terminal.wrapper 490deny ${PATH}/xfce4-terminal.wrapper
491# blacklist ${PATH}/konsole 491# blacklist ${PATH}/konsole
492# konsole doesn't seem to have this problem - last tested on Ubuntu 16.04 492# konsole doesn't seem to have this problem - last tested on Ubuntu 16.04
493 493
494# kernel files 494# kernel files
495blacklist /initrd* 495deny /initrd*
496blacklist /vmlinuz* 496deny /vmlinuz*
497 497
498# snapshot files 498# snapshot files
499blacklist /.snapshots 499deny /.snapshots
500 500
501# flatpak 501# flatpak
502blacklist ${HOME}/.cache/flatpak 502deny ${HOME}/.cache/flatpak
503blacklist ${HOME}/.config/flatpak 503deny ${HOME}/.config/flatpak
504noblacklist ${HOME}/.local/share/flatpak/exports 504nodeny ${HOME}/.local/share/flatpak/exports
505read-only ${HOME}/.local/share/flatpak/exports 505read-only ${HOME}/.local/share/flatpak/exports
506blacklist ${HOME}/.local/share/flatpak/* 506deny ${HOME}/.local/share/flatpak/*
507blacklist ${HOME}/.var 507deny ${HOME}/.var
508blacklist ${RUNUSER}/app 508deny ${RUNUSER}/app
509blacklist ${RUNUSER}/doc 509deny ${RUNUSER}/doc
510blacklist ${RUNUSER}/.dbus-proxy 510deny ${RUNUSER}/.dbus-proxy
511blacklist ${RUNUSER}/.flatpak 511deny ${RUNUSER}/.flatpak
512blacklist ${RUNUSER}/.flatpak-cache 512deny ${RUNUSER}/.flatpak-cache
513blacklist ${RUNUSER}/.flatpak-helper 513deny ${RUNUSER}/.flatpak-helper
514blacklist /usr/share/flatpak 514deny /usr/share/flatpak
515noblacklist /var/lib/flatpak/exports 515nodeny /var/lib/flatpak/exports
516blacklist /var/lib/flatpak/* 516deny /var/lib/flatpak/*
517# most of the time bwrap is SUID binary 517# most of the time bwrap is SUID binary
518blacklist ${PATH}/bwrap 518deny ${PATH}/bwrap
519 519
520# snap 520# snap
521blacklist ${RUNUSER}/snapd-session-agent.socket 521deny ${RUNUSER}/snapd-session-agent.socket
522 522
523# mail directories used by mutt 523# mail directories used by mutt
524blacklist ${HOME}/.Mail 524deny ${HOME}/.Mail
525blacklist ${HOME}/.mail 525deny ${HOME}/.mail
526blacklist ${HOME}/.signature 526deny ${HOME}/.signature
527blacklist ${HOME}/Mail 527deny ${HOME}/Mail
528blacklist ${HOME}/mail 528deny ${HOME}/mail
529blacklist ${HOME}/postponed 529deny ${HOME}/postponed
530blacklist ${HOME}/sent 530deny ${HOME}/sent
531 531
532# kernel configuration 532# kernel configuration
533blacklist /proc/config.gz 533deny /proc/config.gz
534 534
535# prevent DNS malware attempting to communicate with the server 535# prevent DNS malware attempting to communicate with the server
536# using regular DNS tools 536# using regular DNS tools
537blacklist ${PATH}/dig 537deny ${PATH}/dig
538blacklist ${PATH}/dlint 538deny ${PATH}/dlint
539blacklist ${PATH}/dns2tcp 539deny ${PATH}/dns2tcp
540blacklist ${PATH}/dnssec-* 540deny ${PATH}/dnssec-*
541blacklist ${PATH}/dnswalk 541deny ${PATH}/dnswalk
542blacklist ${PATH}/drill 542deny ${PATH}/drill
543blacklist ${PATH}/host 543deny ${PATH}/host
544blacklist ${PATH}/iodine 544deny ${PATH}/iodine
545blacklist ${PATH}/kdig 545deny ${PATH}/kdig
546blacklist ${PATH}/khost 546deny ${PATH}/khost
547blacklist ${PATH}/knsupdate 547deny ${PATH}/knsupdate
548blacklist ${PATH}/ldns-* 548deny ${PATH}/ldns-*
549blacklist ${PATH}/ldnsd 549deny ${PATH}/ldnsd
550blacklist ${PATH}/nslookup 550deny ${PATH}/nslookup
551blacklist ${PATH}/resolvectl 551deny ${PATH}/resolvectl
552blacklist ${PATH}/unbound-host 552deny ${PATH}/unbound-host
553 553
554# rest of ${RUNUSER} 554# rest of ${RUNUSER}
555blacklist ${RUNUSER}/*.lock 555deny ${RUNUSER}/*.lock
556blacklist ${RUNUSER}/inaccessible 556deny ${RUNUSER}/inaccessible
557blacklist ${RUNUSER}/pk-debconf-socket 557deny ${RUNUSER}/pk-debconf-socket
558blacklist ${RUNUSER}/update-notifier.pid 558deny ${RUNUSER}/update-notifier.pid
diff --git a/etc/inc/disable-devel.inc b/etc/inc/disable-devel.inc
index e74b1b40b..a893eb3f3 100644
--- a/etc/inc/disable-devel.inc
+++ b/etc/inc/disable-devel.inc
@@ -5,65 +5,65 @@ include disable-devel.local
5# development tools 5# development tools
6 6
7# clang/llvm 7# clang/llvm
8blacklist ${PATH}/clang* 8deny ${PATH}/clang*
9blacklist ${PATH}/lldb* 9deny ${PATH}/lldb*
10blacklist ${PATH}/llvm* 10deny ${PATH}/llvm*
11# see issue #2106 - it disables hardware acceleration in Firefox on Radeon GPU 11# see issue #2106 - it disables hardware acceleration in Firefox on Radeon GPU
12# blacklist /usr/lib/llvm* 12# blacklist /usr/lib/llvm*
13 13
14# GCC 14# GCC
15blacklist ${PATH}/as 15deny ${PATH}/as
16blacklist ${PATH}/cc 16deny ${PATH}/cc
17blacklist ${PATH}/c++* 17deny ${PATH}/c++*
18blacklist ${PATH}/c8* 18deny ${PATH}/c8*
19blacklist ${PATH}/c9* 19deny ${PATH}/c9*
20blacklist ${PATH}/cpp* 20deny ${PATH}/cpp*
21blacklist ${PATH}/g++* 21deny ${PATH}/g++*
22blacklist ${PATH}/gcc* 22deny ${PATH}/gcc*
23blacklist ${PATH}/gdb 23deny ${PATH}/gdb
24blacklist ${PATH}/ld 24deny ${PATH}/ld
25blacklist ${PATH}/*-gcc* 25deny ${PATH}/*-gcc*
26blacklist ${PATH}/*-g++* 26deny ${PATH}/*-g++*
27blacklist ${PATH}/*-gcc* 27deny ${PATH}/*-gcc*
28blacklist ${PATH}/*-g++* 28deny ${PATH}/*-g++*
29# seems to create problems on Gentoo 29# seems to create problems on Gentoo
30#blacklist /usr/lib/gcc 30#blacklist /usr/lib/gcc
31 31
32#Go 32#Go
33blacklist ${PATH}/gccgo 33deny ${PATH}/gccgo
34blacklist ${PATH}/go 34deny ${PATH}/go
35blacklist ${PATH}/gofmt 35deny ${PATH}/gofmt
36 36
37# Java 37# Java
38blacklist ${PATH}/java 38deny ${PATH}/java
39blacklist ${PATH}/javac 39deny ${PATH}/javac
40blacklist /etc/java 40deny /etc/java
41blacklist /usr/lib/java 41deny /usr/lib/java
42blacklist /usr/share/java 42deny /usr/share/java
43 43
44#OpenSSL 44#OpenSSL
45blacklist ${PATH}/openssl 45deny ${PATH}/openssl
46blacklist ${PATH}/openssl-1.0 46deny ${PATH}/openssl-1.0
47 47
48#Rust 48#Rust
49blacklist ${PATH}/rust-gdb 49deny ${PATH}/rust-gdb
50blacklist ${PATH}/rust-lldb 50deny ${PATH}/rust-lldb
51blacklist ${PATH}/rustc 51deny ${PATH}/rustc
52blacklist ${HOME}/.rustup 52deny ${HOME}/.rustup
53 53
54# tcc - Tiny C Compiler 54# tcc - Tiny C Compiler
55blacklist ${PATH}/tcc 55deny ${PATH}/tcc
56blacklist ${PATH}/x86_64-tcc 56deny ${PATH}/x86_64-tcc
57blacklist /usr/lib/tcc 57deny /usr/lib/tcc
58 58
59# Valgrind 59# Valgrind
60blacklist ${PATH}/valgrind* 60deny ${PATH}/valgrind*
61blacklist /usr/lib/valgrind 61deny /usr/lib/valgrind
62 62
63 63
64# Source-Code 64# Source-Code
65 65
66blacklist /usr/src 66deny /usr/src
67blacklist /usr/local/src 67deny /usr/local/src
68blacklist /usr/include 68deny /usr/include
69blacklist /usr/local/include 69deny /usr/local/include
diff --git a/etc/inc/disable-interpreters.inc b/etc/inc/disable-interpreters.inc
index 5d8a236fb..c77d9a490 100644
--- a/etc/inc/disable-interpreters.inc
+++ b/etc/inc/disable-interpreters.inc
@@ -3,66 +3,66 @@
3include disable-interpreters.local 3include disable-interpreters.local
4 4
5# gjs 5# gjs
6blacklist ${PATH}/gjs 6deny ${PATH}/gjs
7blacklist ${PATH}/gjs-console 7deny ${PATH}/gjs-console
8blacklist /usr/lib/gjs 8deny /usr/lib/gjs
9blacklist /usr/lib/libgjs* 9deny /usr/lib/libgjs*
10blacklist /usr/lib64/gjs 10deny /usr/lib64/gjs
11blacklist /usr/lib64/libgjs* 11deny /usr/lib64/libgjs*
12 12
13# Lua 13# Lua
14blacklist ${PATH}/lua* 14deny ${PATH}/lua*
15blacklist /usr/include/lua* 15deny /usr/include/lua*
16blacklist /usr/lib/liblua* 16deny /usr/lib/liblua*
17blacklist /usr/lib/lua 17deny /usr/lib/lua
18blacklist /usr/lib64/liblua* 18deny /usr/lib64/liblua*
19blacklist /usr/lib64/lua 19deny /usr/lib64/lua
20blacklist /usr/share/lua* 20deny /usr/share/lua*
21 21
22# mozjs 22# mozjs
23blacklist /usr/lib/libmozjs-* 23deny /usr/lib/libmozjs-*
24blacklist /usr/lib64/libmozjs-* 24deny /usr/lib64/libmozjs-*
25 25
26# Node.js 26# Node.js
27blacklist ${PATH}/node 27deny ${PATH}/node
28blacklist /usr/include/node 28deny /usr/include/node
29 29
30# nvm 30# nvm
31blacklist ${HOME}/.nvm 31deny ${HOME}/.nvm
32 32
33# Perl 33# Perl
34blacklist ${PATH}/core_perl 34deny ${PATH}/core_perl
35blacklist ${PATH}/cpan* 35deny ${PATH}/cpan*
36blacklist ${PATH}/perl 36deny ${PATH}/perl
37blacklist ${PATH}/site_perl 37deny ${PATH}/site_perl
38blacklist ${PATH}/vendor_perl 38deny ${PATH}/vendor_perl
39blacklist /usr/lib/perl* 39deny /usr/lib/perl*
40blacklist /usr/lib64/perl* 40deny /usr/lib64/perl*
41blacklist /usr/share/perl* 41deny /usr/share/perl*
42 42
43# PHP 43# PHP
44blacklist ${PATH}/php* 44deny ${PATH}/php*
45blacklist /usr/lib/php* 45deny /usr/lib/php*
46blacklist /usr/share/php* 46deny /usr/share/php*
47 47
48# Ruby 48# Ruby
49blacklist ${PATH}/ruby 49deny ${PATH}/ruby
50blacklist /usr/lib/ruby 50deny /usr/lib/ruby
51 51
52# Programs using python: deluge, firefox addons, filezilla, cherrytree, xchat, hexchat, libreoffice, scribus 52# Programs using python: deluge, firefox addons, filezilla, cherrytree, xchat, hexchat, libreoffice, scribus
53# Python 2 53# Python 2
54blacklist ${PATH}/python2* 54deny ${PATH}/python2*
55blacklist /usr/include/python2* 55deny /usr/include/python2*
56blacklist /usr/lib/python2* 56deny /usr/lib/python2*
57blacklist /usr/local/lib/python2* 57deny /usr/local/lib/python2*
58blacklist /usr/share/python2* 58deny /usr/share/python2*
59 59
60# You will want to add noblacklist for python3 stuff in the firefox and/or chromium profiles if you use the Gnome connector (see Issue #2026) 60# You will want to add noblacklist for python3 stuff in the firefox and/or chromium profiles if you use the Gnome connector (see Issue #2026)
61 61
62# Python 3 62# Python 3
63blacklist ${PATH}/python3* 63deny ${PATH}/python3*
64blacklist /usr/include/python3* 64deny /usr/include/python3*
65blacklist /usr/lib/python3* 65deny /usr/lib/python3*
66blacklist /usr/lib64/python3* 66deny /usr/lib64/python3*
67blacklist /usr/local/lib/python3* 67deny /usr/local/lib/python3*
68blacklist /usr/share/python3* 68deny /usr/share/python3*
diff --git a/etc/inc/disable-passwdmgr.inc b/etc/inc/disable-passwdmgr.inc
index 3ed9a1b14..0a61bc46f 100644
--- a/etc/inc/disable-passwdmgr.inc
+++ b/etc/inc/disable-passwdmgr.inc
@@ -2,18 +2,18 @@
2# Persistent customizations should go in a .local file. 2# Persistent customizations should go in a .local file.
3include disable-passwdmgr.local 3include disable-passwdmgr.local
4 4
5blacklist ${HOME}/.config/Bitwarden 5deny ${HOME}/.config/Bitwarden
6blacklist ${HOME}/.config/KeePass 6deny ${HOME}/.config/KeePass
7blacklist ${HOME}/.config/keepass 7deny ${HOME}/.config/keepass
8blacklist ${HOME}/.config/keepassx 8deny ${HOME}/.config/keepassx
9blacklist ${HOME}/.config/keepassxc 9deny ${HOME}/.config/keepassxc
10blacklist ${HOME}/.config/KeePassXCrc 10deny ${HOME}/.config/KeePassXCrc
11blacklist ${HOME}/.config/Sinew Software Systems 11deny ${HOME}/.config/Sinew Software Systems
12blacklist ${HOME}/.fpm 12deny ${HOME}/.fpm
13blacklist ${HOME}/.keepass 13deny ${HOME}/.keepass
14blacklist ${HOME}/.keepassx 14deny ${HOME}/.keepassx
15blacklist ${HOME}/.keepassxc 15deny ${HOME}/.keepassxc
16blacklist ${HOME}/.lastpass 16deny ${HOME}/.lastpass
17blacklist ${HOME}/.local/share/KeePass 17deny ${HOME}/.local/share/KeePass
18blacklist ${HOME}/.local/share/keepass 18deny ${HOME}/.local/share/keepass
19blacklist ${HOME}/.password-store 19deny ${HOME}/.password-store
diff --git a/etc/inc/disable-programs.inc b/etc/inc/disable-programs.inc
index 0e575e5eb..8a32bc685 100644
--- a/etc/inc/disable-programs.inc
+++ b/etc/inc/disable-programs.inc
@@ -2,1094 +2,1094 @@
2# Persistent customizations should go in a .local file. 2# Persistent customizations should go in a .local file.
3include disable-programs.local 3include disable-programs.local
4 4
5blacklist ${HOME}/Arduino 5deny ${HOME}/Arduino
6blacklist ${HOME}/i2p 6deny ${HOME}/i2p
7blacklist ${HOME}/Monero/wallets 7deny ${HOME}/Monero/wallets
8blacklist ${HOME}/Nextcloud 8deny ${HOME}/Nextcloud
9blacklist ${HOME}/Nextcloud/Notes 9deny ${HOME}/Nextcloud/Notes
10blacklist ${HOME}/SoftMaker 10deny ${HOME}/SoftMaker
11blacklist ${HOME}/Standard Notes Backups 11deny ${HOME}/Standard Notes Backups
12blacklist ${HOME}/TeamSpeak3-Client-linux_x86 12deny ${HOME}/TeamSpeak3-Client-linux_x86
13blacklist ${HOME}/TeamSpeak3-Client-linux_amd64 13deny ${HOME}/TeamSpeak3-Client-linux_amd64
14blacklist ${HOME}/hyperrogue.ini 14deny ${HOME}/hyperrogue.ini
15blacklist ${HOME}/mps 15deny ${HOME}/mps
16blacklist ${HOME}/wallet.dat 16deny ${HOME}/wallet.dat
17blacklist ${HOME}/.*coin 17deny ${HOME}/.*coin
18blacklist ${HOME}/.8pecxstudios 18deny ${HOME}/.8pecxstudios
19blacklist ${HOME}/.AndroidStudio* 19deny ${HOME}/.AndroidStudio*
20blacklist ${HOME}/.Atom 20deny ${HOME}/.Atom
21blacklist ${HOME}/.CLion* 21deny ${HOME}/.CLion*
22blacklist ${HOME}/.FBReader 22deny ${HOME}/.FBReader
23blacklist ${HOME}/.FontForge 23deny ${HOME}/.FontForge
24blacklist ${HOME}/.IdeaIC* 24deny ${HOME}/.IdeaIC*
25blacklist ${HOME}/.LuminanceHDR 25deny ${HOME}/.LuminanceHDR
26blacklist ${HOME}/.Mathematica 26deny ${HOME}/.Mathematica
27blacklist ${HOME}/.Natron 27deny ${HOME}/.Natron
28blacklist ${HOME}/.PlayOnLinux 28deny ${HOME}/.PlayOnLinux
29blacklist ${HOME}/.PyCharm* 29deny ${HOME}/.PyCharm*
30blacklist ${HOME}/.Sayonara 30deny ${HOME}/.Sayonara
31blacklist ${HOME}/.Steam 31deny ${HOME}/.Steam
32blacklist ${HOME}/.Steampath 32deny ${HOME}/.Steampath
33blacklist ${HOME}/.Steampid 33deny ${HOME}/.Steampid
34blacklist ${HOME}/.TelegramDesktop 34deny ${HOME}/.TelegramDesktop
35blacklist ${HOME}/.VSCodium 35deny ${HOME}/.VSCodium
36blacklist ${HOME}/.ViberPC 36deny ${HOME}/.ViberPC
37blacklist ${HOME}/.VirtualBox 37deny ${HOME}/.VirtualBox
38blacklist ${HOME}/.WebStorm* 38deny ${HOME}/.WebStorm*
39blacklist ${HOME}/.Wolfram Research 39deny ${HOME}/.Wolfram Research
40blacklist ${HOME}/.ZAP 40deny ${HOME}/.ZAP
41blacklist ${HOME}/.abook 41deny ${HOME}/.abook
42blacklist ${HOME}/.addressbook 42deny ${HOME}/.addressbook
43blacklist ${HOME}/.alpine-smime 43deny ${HOME}/.alpine-smime
44blacklist ${HOME}/.aMule 44deny ${HOME}/.aMule
45blacklist ${HOME}/.android 45deny ${HOME}/.android
46blacklist ${HOME}/.anydesk 46deny ${HOME}/.anydesk
47blacklist ${HOME}/.arduino15 47deny ${HOME}/.arduino15
48blacklist ${HOME}/.aria2 48deny ${HOME}/.aria2
49blacklist ${HOME}/.arm 49deny ${HOME}/.arm
50blacklist ${HOME}/.asunder_album_artist 50deny ${HOME}/.asunder_album_artist
51blacklist ${HOME}/.asunder_album_genre 51deny ${HOME}/.asunder_album_genre
52blacklist ${HOME}/.asunder_album_title 52deny ${HOME}/.asunder_album_title
53blacklist ${HOME}/.atom 53deny ${HOME}/.atom
54blacklist ${HOME}/.attic 54deny ${HOME}/.attic
55blacklist ${HOME}/.audacity-data 55deny ${HOME}/.audacity-data
56blacklist ${HOME}/.avidemux6 56deny ${HOME}/.avidemux6
57blacklist ${HOME}/.ballbuster.hs 57deny ${HOME}/.ballbuster.hs
58blacklist ${HOME}/.balsa 58deny ${HOME}/.balsa
59blacklist ${HOME}/.bcast5 59deny ${HOME}/.bcast5
60blacklist ${HOME}/.bibletime 60deny ${HOME}/.bibletime
61blacklist ${HOME}/.bitcoin 61deny ${HOME}/.bitcoin
62blacklist ${HOME}/.blobby 62deny ${HOME}/.blobby
63blacklist ${HOME}/.bogofilter 63deny ${HOME}/.bogofilter
64blacklist ${HOME}/.bzf 64deny ${HOME}/.bzf
65blacklist ${HOME}/.cargo/* 65deny ${HOME}/.cargo/*
66blacklist ${HOME}/.claws-mail 66deny ${HOME}/.claws-mail
67blacklist ${HOME}/.cliqz 67deny ${HOME}/.cliqz
68blacklist ${HOME}/.clonk 68deny ${HOME}/.clonk
69blacklist ${HOME}/.config/0ad 69deny ${HOME}/.config/0ad
70blacklist ${HOME}/.config/2048-qt 70deny ${HOME}/.config/2048-qt
71blacklist ${HOME}/.config/Atom 71deny ${HOME}/.config/Atom
72blacklist ${HOME}/.config/Audaciousrc 72deny ${HOME}/.config/Audaciousrc
73blacklist ${HOME}/.config/Authenticator 73deny ${HOME}/.config/Authenticator
74blacklist ${HOME}/.config/Beaker Browser 74deny ${HOME}/.config/Beaker Browser
75blacklist ${HOME}/.config/Bitcoin 75deny ${HOME}/.config/Bitcoin
76blacklist ${HOME}/.config/Bitwarden 76deny ${HOME}/.config/Bitwarden
77blacklist ${HOME}/.config/Brackets 77deny ${HOME}/.config/Brackets
78blacklist ${HOME}/.config/BraveSoftware 78deny ${HOME}/.config/BraveSoftware
79blacklist ${HOME}/.config/Clementine 79deny ${HOME}/.config/Clementine
80blacklist ${HOME}/.config/Code 80deny ${HOME}/.config/Code
81blacklist ${HOME}/.config/Code - OSS 81deny ${HOME}/.config/Code - OSS
82blacklist ${HOME}/.config/Code Industry 82deny ${HOME}/.config/Code Industry
83blacklist ${HOME}/.config/Cryptocat 83deny ${HOME}/.config/Cryptocat
84blacklist ${HOME}/.config/Debauchee/Barrier.conf 84deny ${HOME}/.config/Debauchee/Barrier.conf
85blacklist ${HOME}/.config/Dharkael 85deny ${HOME}/.config/Dharkael
86blacklist ${HOME}/.config/Element 86deny ${HOME}/.config/Element
87blacklist ${HOME}/.config/Element (Riot) 87deny ${HOME}/.config/Element (Riot)
88blacklist ${HOME}/.config/ENCOM 88deny ${HOME}/.config/ENCOM
89blacklist ${HOME}/.config/Enox 89deny ${HOME}/.config/Enox
90blacklist ${HOME}/.config/Epic 90deny ${HOME}/.config/Epic
91blacklist ${HOME}/.config/Ferdi 91deny ${HOME}/.config/Ferdi
92blacklist ${HOME}/.config/Flavio Tordini 92deny ${HOME}/.config/Flavio Tordini
93blacklist ${HOME}/.config/Franz 93deny ${HOME}/.config/Franz
94blacklist ${HOME}/.config/FreeCAD 94deny ${HOME}/.config/FreeCAD
95blacklist ${HOME}/.config/FreeTube 95deny ${HOME}/.config/FreeTube
96blacklist ${HOME}/.config/Fritzing 96deny ${HOME}/.config/Fritzing
97blacklist ${HOME}/.config/GIMP 97deny ${HOME}/.config/GIMP
98blacklist ${HOME}/.config/GitHub Desktop 98deny ${HOME}/.config/GitHub Desktop
99blacklist ${HOME}/.config/Gitter 99deny ${HOME}/.config/Gitter
100blacklist ${HOME}/.config/Google 100deny ${HOME}/.config/Google
101blacklist ${HOME}/.config/Google Play Music Desktop Player 101deny ${HOME}/.config/Google Play Music Desktop Player
102blacklist ${HOME}/.config/Gpredict 102deny ${HOME}/.config/Gpredict
103blacklist ${HOME}/.config/INRIA 103deny ${HOME}/.config/INRIA
104blacklist ${HOME}/.config/InSilmaril 104deny ${HOME}/.config/InSilmaril
105blacklist ${HOME}/.config/Jitsi Meet 105deny ${HOME}/.config/Jitsi Meet
106blacklist ${HOME}/.config/KDE/neochat 106deny ${HOME}/.config/KDE/neochat
107blacklist ${HOME}/.config/Kid3 107deny ${HOME}/.config/Kid3
108blacklist ${HOME}/.config/Kingsoft 108deny ${HOME}/.config/Kingsoft
109blacklist ${HOME}/.config/LibreCAD 109deny ${HOME}/.config/LibreCAD
110blacklist ${HOME}/.config/Loop_Hero 110deny ${HOME}/.config/Loop_Hero
111blacklist ${HOME}/.config/Luminance 111deny ${HOME}/.config/Luminance
112blacklist ${HOME}/.config/LyX 112deny ${HOME}/.config/LyX
113blacklist ${HOME}/.config/Mattermost 113deny ${HOME}/.config/Mattermost
114blacklist ${HOME}/.config/Meltytech 114deny ${HOME}/.config/Meltytech
115blacklist ${HOME}/.config/Mendeley Ltd. 115deny ${HOME}/.config/Mendeley Ltd.
116blacklist ${HOME}/.config/Min 116deny ${HOME}/.config/Min
117blacklist ${HOME}/.config/ModTheSpire 117deny ${HOME}/.config/ModTheSpire
118blacklist ${HOME}/.config/Mousepad 118deny ${HOME}/.config/Mousepad
119blacklist ${HOME}/.config/Mumble 119deny ${HOME}/.config/Mumble
120blacklist ${HOME}/.config/MusE 120deny ${HOME}/.config/MusE
121blacklist ${HOME}/.config/MuseScore 121deny ${HOME}/.config/MuseScore
122blacklist ${HOME}/.config/MusicBrainz 122deny ${HOME}/.config/MusicBrainz
123blacklist ${HOME}/.config/Nathan Osman 123deny ${HOME}/.config/Nathan Osman
124blacklist ${HOME}/.config/Nextcloud 124deny ${HOME}/.config/Nextcloud
125blacklist ${HOME}/.config/Nylas Mail 125deny ${HOME}/.config/Nylas Mail
126blacklist ${HOME}/.config/PacmanLogViewer 126deny ${HOME}/.config/PacmanLogViewer
127blacklist ${HOME}/.config/PawelStolowski 127deny ${HOME}/.config/PawelStolowski
128blacklist ${HOME}/.config/PBE 128deny ${HOME}/.config/PBE
129blacklist ${HOME}/.config/Philipp Schmieder 129deny ${HOME}/.config/Philipp Schmieder
130blacklist ${HOME}/.config/QGIS 130deny ${HOME}/.config/QGIS
131blacklist ${HOME}/.config/QMediathekView 131deny ${HOME}/.config/QMediathekView
132blacklist ${HOME}/.config/Qlipper 132deny ${HOME}/.config/Qlipper
133blacklist ${HOME}/.config/QuiteRss 133deny ${HOME}/.config/QuiteRss
134blacklist ${HOME}/.config/QuiteRssrc 134deny ${HOME}/.config/QuiteRssrc
135blacklist ${HOME}/.config/Quotient 135deny ${HOME}/.config/Quotient
136blacklist ${HOME}/.config/Rambox 136deny ${HOME}/.config/Rambox
137blacklist ${HOME}/.config/Riot 137deny ${HOME}/.config/Riot
138blacklist ${HOME}/.config/Rocket.Chat 138deny ${HOME}/.config/Rocket.Chat
139blacklist ${HOME}/.config/RogueLegacy 139deny ${HOME}/.config/RogueLegacy
140blacklist ${HOME}/.config/RogueLegacyStorageContainer 140deny ${HOME}/.config/RogueLegacyStorageContainer
141blacklist ${HOME}/.config/Signal 141deny ${HOME}/.config/Signal
142blacklist ${HOME}/.config/Sinew Software Systems 142deny ${HOME}/.config/Sinew Software Systems
143blacklist ${HOME}/.config/Slack 143deny ${HOME}/.config/Slack
144blacklist ${HOME}/.config/Standard Notes 144deny ${HOME}/.config/Standard Notes
145blacklist ${HOME}/.config/SubDownloader 145deny ${HOME}/.config/SubDownloader
146blacklist ${HOME}/.config/Thunar 146deny ${HOME}/.config/Thunar
147blacklist ${HOME}/.config/Twitch 147deny ${HOME}/.config/Twitch
148blacklist ${HOME}/.config/Unknown Organization 148deny ${HOME}/.config/Unknown Organization
149blacklist ${HOME}/.config/VirtualBox 149deny ${HOME}/.config/VirtualBox
150blacklist ${HOME}/.config/Wire 150deny ${HOME}/.config/Wire
151blacklist ${HOME}/.config/Youtube 151deny ${HOME}/.config/Youtube
152blacklist ${HOME}/.config/Zeal 152deny ${HOME}/.config/Zeal
153blacklist ${HOME}/.config/ZeGrapher Project 153deny ${HOME}/.config/ZeGrapher Project
154blacklist ${HOME}/.config/aacs 154deny ${HOME}/.config/aacs
155blacklist ${HOME}/.config/abiword 155deny ${HOME}/.config/abiword
156blacklist ${HOME}/.config/agenda 156deny ${HOME}/.config/agenda
157blacklist ${HOME}/.config/akonadi* 157deny ${HOME}/.config/akonadi*
158blacklist ${HOME}/.config/akregatorrc 158deny ${HOME}/.config/akregatorrc
159blacklist ${HOME}/.config/alacritty 159deny ${HOME}/.config/alacritty
160blacklist ${HOME}/.config/ardour4 160deny ${HOME}/.config/ardour4
161blacklist ${HOME}/.config/ardour5 161deny ${HOME}/.config/ardour5
162blacklist ${HOME}/.config/aria2 162deny ${HOME}/.config/aria2
163blacklist ${HOME}/.config/arkrc 163deny ${HOME}/.config/arkrc
164blacklist ${HOME}/.config/artha.conf 164deny ${HOME}/.config/artha.conf
165blacklist ${HOME}/.config/artha.log 165deny ${HOME}/.config/artha.log
166blacklist ${HOME}/.config/asunder 166deny ${HOME}/.config/asunder
167blacklist ${HOME}/.config/atril 167deny ${HOME}/.config/atril
168blacklist ${HOME}/.config/audacious 168deny ${HOME}/.config/audacious
169blacklist ${HOME}/.config/autokey 169deny ${HOME}/.config/autokey
170blacklist ${HOME}/.config/avidemux3_qt5rc 170deny ${HOME}/.config/avidemux3_qt5rc
171blacklist ${HOME}/.config/aweather 171deny ${HOME}/.config/aweather
172blacklist ${HOME}/.config/backintime 172deny ${HOME}/.config/backintime
173blacklist ${HOME}/.config/baloofilerc 173deny ${HOME}/.config/baloofilerc
174blacklist ${HOME}/.config/baloorc 174deny ${HOME}/.config/baloorc
175blacklist ${HOME}/.config/bcompare 175deny ${HOME}/.config/bcompare
176blacklist ${HOME}/.config/blender 176deny ${HOME}/.config/blender
177blacklist ${HOME}/.config/bless 177deny ${HOME}/.config/bless
178blacklist ${HOME}/.config/bnox 178deny ${HOME}/.config/bnox
179blacklist ${HOME}/.config/borg 179deny ${HOME}/.config/borg
180blacklist ${HOME}/.config/brasero 180deny ${HOME}/.config/brasero
181blacklist ${HOME}/.config/brave 181deny ${HOME}/.config/brave
182blacklist ${HOME}/.config/brave-flags.conf 182deny ${HOME}/.config/brave-flags.conf
183blacklist ${HOME}/.config/caja 183deny ${HOME}/.config/caja
184blacklist ${HOME}/.config/calibre 184deny ${HOME}/.config/calibre
185blacklist ${HOME}/.config/cantata 185deny ${HOME}/.config/cantata
186blacklist ${HOME}/.config/catfish 186deny ${HOME}/.config/catfish
187blacklist ${HOME}/.config/cawbird 187deny ${HOME}/.config/cawbird
188blacklist ${HOME}/.config/celluloid 188deny ${HOME}/.config/celluloid
189blacklist ${HOME}/.config/cherrytree 189deny ${HOME}/.config/cherrytree
190blacklist ${HOME}/.config/chrome-beta-flags.conf 190deny ${HOME}/.config/chrome-beta-flags.conf
191blacklist ${HOME}/.config/chrome-beta-flags.config 191deny ${HOME}/.config/chrome-beta-flags.config
192blacklist ${HOME}/.config/chrome-flags.conf 192deny ${HOME}/.config/chrome-flags.conf
193blacklist ${HOME}/.config/chrome-flags.config 193deny ${HOME}/.config/chrome-flags.config
194blacklist ${HOME}/.config/chrome-unstable-flags.conf 194deny ${HOME}/.config/chrome-unstable-flags.conf
195blacklist ${HOME}/.config/chrome-unstable-flags.config 195deny ${HOME}/.config/chrome-unstable-flags.config
196blacklist ${HOME}/.config/chromium 196deny ${HOME}/.config/chromium
197blacklist ${HOME}/.config/chromium-dev 197deny ${HOME}/.config/chromium-dev
198blacklist ${HOME}/.config/chromium-flags.conf 198deny ${HOME}/.config/chromium-flags.conf
199blacklist ${HOME}/.config/clipit 199deny ${HOME}/.config/clipit
200blacklist ${HOME}/.config/cliqz 200deny ${HOME}/.config/cliqz
201blacklist ${HOME}/.config/cmus 201deny ${HOME}/.config/cmus
202blacklist ${HOME}/.config/com.github.bleakgrey.tootle 202deny ${HOME}/.config/com.github.bleakgrey.tootle
203blacklist ${HOME}/.config/corebird 203deny ${HOME}/.config/corebird
204blacklist ${HOME}/.config/cower 204deny ${HOME}/.config/cower
205blacklist ${HOME}/.config/coyim 205deny ${HOME}/.config/coyim
206blacklist ${HOME}/.config/darktable 206deny ${HOME}/.config/darktable
207blacklist ${HOME}/.config/deadbeef 207deny ${HOME}/.config/deadbeef
208blacklist ${HOME}/.config/deluge 208deny ${HOME}/.config/deluge
209blacklist ${HOME}/.config/devilspie2 209deny ${HOME}/.config/devilspie2
210blacklist ${HOME}/.config/digikam 210deny ${HOME}/.config/digikam
211blacklist ${HOME}/.config/digikamrc 211deny ${HOME}/.config/digikamrc
212blacklist ${HOME}/.config/discord 212deny ${HOME}/.config/discord
213blacklist ${HOME}/.config/discordcanary 213deny ${HOME}/.config/discordcanary
214blacklist ${HOME}/.config/dkl 214deny ${HOME}/.config/dkl
215blacklist ${HOME}/.config/dnox 215deny ${HOME}/.config/dnox
216blacklist ${HOME}/.config/dolphin-emu 216deny ${HOME}/.config/dolphin-emu
217blacklist ${HOME}/.config/dolphinrc 217deny ${HOME}/.config/dolphinrc
218blacklist ${HOME}/.config/dragonplayerrc 218deny ${HOME}/.config/dragonplayerrc
219blacklist ${HOME}/.config/draw.io 219deny ${HOME}/.config/draw.io
220blacklist ${HOME}/.config/d-feet 220deny ${HOME}/.config/d-feet
221blacklist ${HOME}/.config/electron-mail 221deny ${HOME}/.config/electron-mail
222blacklist ${HOME}/.config/emaildefaults 222deny ${HOME}/.config/emaildefaults
223blacklist ${HOME}/.config/emailidentities 223deny ${HOME}/.config/emailidentities
224blacklist ${HOME}/.config/emilia 224deny ${HOME}/.config/emilia
225blacklist ${HOME}/.config/enchant 225deny ${HOME}/.config/enchant
226blacklist ${HOME}/.config/eog 226deny ${HOME}/.config/eog
227blacklist ${HOME}/.config/epiphany 227deny ${HOME}/.config/epiphany
228blacklist ${HOME}/.config/equalx 228deny ${HOME}/.config/equalx
229blacklist ${HOME}/.config/evince 229deny ${HOME}/.config/evince
230blacklist ${HOME}/.config/evolution 230deny ${HOME}/.config/evolution
231blacklist ${HOME}/.config/falkon 231deny ${HOME}/.config/falkon
232blacklist ${HOME}/.config/filezilla 232deny ${HOME}/.config/filezilla
233blacklist ${HOME}/.config/flameshot 233deny ${HOME}/.config/flameshot
234blacklist ${HOME}/.config/flaska.net 234deny ${HOME}/.config/flaska.net
235blacklist ${HOME}/.config/flowblade 235deny ${HOME}/.config/flowblade
236blacklist ${HOME}/.config/font-manager 236deny ${HOME}/.config/font-manager
237blacklist ${HOME}/.config/freecol 237deny ${HOME}/.config/freecol
238blacklist ${HOME}/.config/gajim 238deny ${HOME}/.config/gajim
239blacklist ${HOME}/.config/galculator 239deny ${HOME}/.config/galculator
240blacklist ${HOME}/.config/gconf 240deny ${HOME}/.config/gconf
241blacklist ${HOME}/.config/geany 241deny ${HOME}/.config/geany
242blacklist ${HOME}/.config/geary 242deny ${HOME}/.config/geary
243blacklist ${HOME}/.config/gedit 243deny ${HOME}/.config/gedit
244blacklist ${HOME}/.config/geeqie 244deny ${HOME}/.config/geeqie
245blacklist ${HOME}/.config/ghb 245deny ${HOME}/.config/ghb
246blacklist ${HOME}/.config/ghostwriter 246deny ${HOME}/.config/ghostwriter
247blacklist ${HOME}/.config/git 247deny ${HOME}/.config/git
248blacklist ${HOME}/.config/git-cola 248deny ${HOME}/.config/git-cola
249blacklist ${HOME}/.config/glade.conf 249deny ${HOME}/.config/glade.conf
250blacklist ${HOME}/.config/globaltime 250deny ${HOME}/.config/globaltime
251blacklist ${HOME}/.config/gmpc 251deny ${HOME}/.config/gmpc
252blacklist ${HOME}/.config/gnome-builder 252deny ${HOME}/.config/gnome-builder
253blacklist ${HOME}/.config/gnome-chess 253deny ${HOME}/.config/gnome-chess
254blacklist ${HOME}/.config/gnome-control-center 254deny ${HOME}/.config/gnome-control-center
255blacklist ${HOME}/.config/gnome-initial-setup-done 255deny ${HOME}/.config/gnome-initial-setup-done
256blacklist ${HOME}/.config/gnome-latex 256deny ${HOME}/.config/gnome-latex
257blacklist ${HOME}/.config/gnome-mplayer 257deny ${HOME}/.config/gnome-mplayer
258blacklist ${HOME}/.config/gnome-mpv 258deny ${HOME}/.config/gnome-mpv
259blacklist ${HOME}/.config/gnome-pie 259deny ${HOME}/.config/gnome-pie
260blacklist ${HOME}/.config/gnome-session 260deny ${HOME}/.config/gnome-session
261blacklist ${HOME}/.config/gnote 261deny ${HOME}/.config/gnote
262blacklist ${HOME}/.config/godot 262deny ${HOME}/.config/godot
263blacklist ${HOME}/.config/google-chrome 263deny ${HOME}/.config/google-chrome
264blacklist ${HOME}/.config/google-chrome-beta 264deny ${HOME}/.config/google-chrome-beta
265blacklist ${HOME}/.config/google-chrome-unstable 265deny ${HOME}/.config/google-chrome-unstable
266blacklist ${HOME}/.config/gpicview 266deny ${HOME}/.config/gpicview
267blacklist ${HOME}/.config/gthumb 267deny ${HOME}/.config/gthumb
268blacklist ${HOME}/.config/gummi 268deny ${HOME}/.config/gummi
269blacklist ${HOME}/.config/guvcview2 269deny ${HOME}/.config/guvcview2
270blacklist ${HOME}/.config/gwenviewrc 270deny ${HOME}/.config/gwenviewrc
271blacklist ${HOME}/.config/hexchat 271deny ${HOME}/.config/hexchat
272blacklist ${HOME}/.config/homebank 272deny ${HOME}/.config/homebank
273blacklist ${HOME}/.config/i2p 273deny ${HOME}/.config/i2p
274blacklist ${HOME}/.config/inkscape 274deny ${HOME}/.config/inkscape
275blacklist ${HOME}/.config/inox 275deny ${HOME}/.config/inox
276blacklist ${HOME}/.config/iridium 276deny ${HOME}/.config/iridium
277blacklist ${HOME}/.config/itch 277deny ${HOME}/.config/itch
278blacklist ${HOME}/.config/jami 278deny ${HOME}/.config/jami
279blacklist ${HOME}/.config/jd-gui.cfg 279deny ${HOME}/.config/jd-gui.cfg
280blacklist ${HOME}/.config/k3brc 280deny ${HOME}/.config/k3brc
281blacklist ${HOME}/.config/kaffeinerc 281deny ${HOME}/.config/kaffeinerc
282blacklist ${HOME}/.config/kalgebrarc 282deny ${HOME}/.config/kalgebrarc
283blacklist ${HOME}/.config/katemetainfos 283deny ${HOME}/.config/katemetainfos
284blacklist ${HOME}/.config/katepartrc 284deny ${HOME}/.config/katepartrc
285blacklist ${HOME}/.config/katerc 285deny ${HOME}/.config/katerc
286blacklist ${HOME}/.config/kateschemarc 286deny ${HOME}/.config/kateschemarc
287blacklist ${HOME}/.config/katesyntaxhighlightingrc 287deny ${HOME}/.config/katesyntaxhighlightingrc
288blacklist ${HOME}/.config/katevirc 288deny ${HOME}/.config/katevirc
289blacklist ${HOME}/.config/kazam 289deny ${HOME}/.config/kazam
290blacklist ${HOME}/.config/kdeconnect 290deny ${HOME}/.config/kdeconnect
291blacklist ${HOME}/.config/kdenliverc 291deny ${HOME}/.config/kdenliverc
292blacklist ${HOME}/.config/kdiff3fileitemactionrc 292deny ${HOME}/.config/kdiff3fileitemactionrc
293blacklist ${HOME}/.config/kdiff3rc 293deny ${HOME}/.config/kdiff3rc
294blacklist ${HOME}/.config/kfindrc 294deny ${HOME}/.config/kfindrc
295blacklist ${HOME}/.config/kgetrc 295deny ${HOME}/.config/kgetrc
296blacklist ${HOME}/.config/kid3rc 296deny ${HOME}/.config/kid3rc
297blacklist ${HOME}/.config/klavaro 297deny ${HOME}/.config/klavaro
298blacklist ${HOME}/.config/klipperrc 298deny ${HOME}/.config/klipperrc
299blacklist ${HOME}/.config/kmail2rc 299deny ${HOME}/.config/kmail2rc
300blacklist ${HOME}/.config/kmailsearchindexingrc 300deny ${HOME}/.config/kmailsearchindexingrc
301blacklist ${HOME}/.config/kmplayerrc 301deny ${HOME}/.config/kmplayerrc
302blacklist ${HOME}/.config/knotesrc 302deny ${HOME}/.config/knotesrc
303blacklist ${HOME}/.config/konversationrc 303deny ${HOME}/.config/konversationrc
304blacklist ${HOME}/.config/konversation.notifyrc 304deny ${HOME}/.config/konversation.notifyrc
305blacklist ${HOME}/.config/kritarc 305deny ${HOME}/.config/kritarc
306blacklist ${HOME}/.config/ktorrentrc 306deny ${HOME}/.config/ktorrentrc
307blacklist ${HOME}/.config/ktouch2rc 307deny ${HOME}/.config/ktouch2rc
308blacklist ${HOME}/.config/kube 308deny ${HOME}/.config/kube
309blacklist ${HOME}/.config/kwriterc 309deny ${HOME}/.config/kwriterc
310blacklist ${HOME}/.config/leafpad 310deny ${HOME}/.config/leafpad
311blacklist ${HOME}/.config/libreoffice 311deny ${HOME}/.config/libreoffice
312blacklist ${HOME}/.config/liferea 312deny ${HOME}/.config/liferea
313blacklist ${HOME}/.config/linphone 313deny ${HOME}/.config/linphone
314blacklist ${HOME}/.config/lugaru 314deny ${HOME}/.config/lugaru
315blacklist ${HOME}/.config/lutris 315deny ${HOME}/.config/lutris
316blacklist ${HOME}/.config/lximage-qt 316deny ${HOME}/.config/lximage-qt
317blacklist ${HOME}/.config/mailtransports 317deny ${HOME}/.config/mailtransports
318blacklist ${HOME}/.config/mana 318deny ${HOME}/.config/mana
319blacklist ${HOME}/.config/mate-calc 319deny ${HOME}/.config/mate-calc
320blacklist ${HOME}/.config/mate/eom 320deny ${HOME}/.config/mate/eom
321blacklist ${HOME}/.config/mate/mate-dictionary 321deny ${HOME}/.config/mate/mate-dictionary
322blacklist ${HOME}/.config/matrix-mirage 322deny ${HOME}/.config/matrix-mirage
323blacklist ${HOME}/.config/mcomix 323deny ${HOME}/.config/mcomix
324blacklist ${HOME}/.config/meld 324deny ${HOME}/.config/meld
325blacklist ${HOME}/.config/meteo-qt 325deny ${HOME}/.config/meteo-qt
326blacklist ${HOME}/.config/menulibre.cfg 326deny ${HOME}/.config/menulibre.cfg
327blacklist ${HOME}/.config/mfusion 327deny ${HOME}/.config/mfusion
328blacklist ${HOME}/.config/Microsoft 328deny ${HOME}/.config/Microsoft
329blacklist ${HOME}/.config/microsoft-edge-dev 329deny ${HOME}/.config/microsoft-edge-dev
330blacklist ${HOME}/.config/midori 330deny ${HOME}/.config/midori
331blacklist ${HOME}/.config/mirage 331deny ${HOME}/.config/mirage
332blacklist ${HOME}/.config/mono 332deny ${HOME}/.config/mono
333blacklist ${HOME}/.config/mpDris2 333deny ${HOME}/.config/mpDris2
334blacklist ${HOME}/.config/mpd 334deny ${HOME}/.config/mpd
335blacklist ${HOME}/.config/mps-youtube 335deny ${HOME}/.config/mps-youtube
336blacklist ${HOME}/.config/mpv 336deny ${HOME}/.config/mpv
337blacklist ${HOME}/.config/mupen64plus 337deny ${HOME}/.config/mupen64plus
338blacklist ${HOME}/.config/mutt 338deny ${HOME}/.config/mutt
339blacklist ${HOME}/.config/mutter 339deny ${HOME}/.config/mutter
340blacklist ${HOME}/.config/mypaint 340deny ${HOME}/.config/mypaint
341blacklist ${HOME}/.config/nano 341deny ${HOME}/.config/nano
342blacklist ${HOME}/.config/nautilus 342deny ${HOME}/.config/nautilus
343blacklist ${HOME}/.config/nemo 343deny ${HOME}/.config/nemo
344blacklist ${HOME}/.config/neochatrc 344deny ${HOME}/.config/neochatrc
345blacklist ${HOME}/.config/neochat.notifyrc 345deny ${HOME}/.config/neochat.notifyrc
346blacklist ${HOME}/.config/neomutt 346deny ${HOME}/.config/neomutt
347blacklist ${HOME}/.config/netsurf 347deny ${HOME}/.config/netsurf
348blacklist ${HOME}/.config/newsbeuter 348deny ${HOME}/.config/newsbeuter
349blacklist ${HOME}/.config/newsboat 349deny ${HOME}/.config/newsboat
350blacklist ${HOME}/.config/newsflash 350deny ${HOME}/.config/newsflash
351blacklist ${HOME}/.config/nheko 351deny ${HOME}/.config/nheko
352blacklist ${HOME}/.config/NitroShare 352deny ${HOME}/.config/NitroShare
353blacklist ${HOME}/.config/nomacs 353deny ${HOME}/.config/nomacs
354blacklist ${HOME}/.config/nuclear 354deny ${HOME}/.config/nuclear
355blacklist ${HOME}/.config/obs-studio 355deny ${HOME}/.config/obs-studio
356blacklist ${HOME}/.config/okularpartrc 356deny ${HOME}/.config/okularpartrc
357blacklist ${HOME}/.config/okularrc 357deny ${HOME}/.config/okularrc
358blacklist ${HOME}/.config/onboard 358deny ${HOME}/.config/onboard
359blacklist ${HOME}/.config/onionshare 359deny ${HOME}/.config/onionshare
360blacklist ${HOME}/.config/onlyoffice 360deny ${HOME}/.config/onlyoffice
361blacklist ${HOME}/.config/openmw 361deny ${HOME}/.config/openmw
362blacklist ${HOME}/.config/opera 362deny ${HOME}/.config/opera
363blacklist ${HOME}/.config/opera-beta 363deny ${HOME}/.config/opera-beta
364blacklist ${HOME}/.config/orage 364deny ${HOME}/.config/orage
365blacklist ${HOME}/.config/org.gabmus.gfeeds.json 365deny ${HOME}/.config/org.gabmus.gfeeds.json
366blacklist ${HOME}/.config/org.gabmus.gfeeds.saved_articles 366deny ${HOME}/.config/org.gabmus.gfeeds.saved_articles
367blacklist ${HOME}/.config/org.kde.gwenviewrc 367deny ${HOME}/.config/org.kde.gwenviewrc
368blacklist ${HOME}/.config/otter 368deny ${HOME}/.config/otter
369blacklist ${HOME}/.config/pavucontrol-qt 369deny ${HOME}/.config/pavucontrol-qt
370blacklist ${HOME}/.config/pavucontrol.ini 370deny ${HOME}/.config/pavucontrol.ini
371blacklist ${HOME}/.config/pcmanfm 371deny ${HOME}/.config/pcmanfm
372blacklist ${HOME}/.config/pdfmod 372deny ${HOME}/.config/pdfmod
373blacklist ${HOME}/.config/Pinta 373deny ${HOME}/.config/Pinta
374blacklist ${HOME}/.config/pipe-viewer 374deny ${HOME}/.config/pipe-viewer
375blacklist ${HOME}/.config/pitivi 375deny ${HOME}/.config/pitivi
376blacklist ${HOME}/.config/pix 376deny ${HOME}/.config/pix
377blacklist ${HOME}/.config/pluma 377deny ${HOME}/.config/pluma
378blacklist ${HOME}/.config/ppsspp 378deny ${HOME}/.config/ppsspp
379blacklist ${HOME}/.config/pragha 379deny ${HOME}/.config/pragha
380blacklist ${HOME}/.config/profanity 380deny ${HOME}/.config/profanity
381blacklist ${HOME}/.config/psi 381deny ${HOME}/.config/psi
382blacklist ${HOME}/.config/psi+ 382deny ${HOME}/.config/psi+
383blacklist ${HOME}/.config/qBittorrent 383deny ${HOME}/.config/qBittorrent
384blacklist ${HOME}/.config/qBittorrentrc 384deny ${HOME}/.config/qBittorrentrc
385blacklist ${HOME}/.config/qnapi.ini 385deny ${HOME}/.config/qnapi.ini
386blacklist ${HOME}/.config/qpdfview 386deny ${HOME}/.config/qpdfview
387blacklist ${HOME}/.config/quodlibet 387deny ${HOME}/.config/quodlibet
388blacklist ${HOME}/.config/qupzilla 388deny ${HOME}/.config/qupzilla
389blacklist ${HOME}/.config/qutebrowser 389deny ${HOME}/.config/qutebrowser
390blacklist ${HOME}/.config/ranger 390deny ${HOME}/.config/ranger
391blacklist ${HOME}/.config/redshift 391deny ${HOME}/.config/redshift
392blacklist ${HOME}/.config/redshift.conf 392deny ${HOME}/.config/redshift.conf
393blacklist ${HOME}/.config/remmina 393deny ${HOME}/.config/remmina
394blacklist ${HOME}/.config/ristretto 394deny ${HOME}/.config/ristretto
395blacklist ${HOME}/.config/rtv 395deny ${HOME}/.config/rtv
396blacklist ${HOME}/.config/scribus 396deny ${HOME}/.config/scribus
397blacklist ${HOME}/.config/scribusrc 397deny ${HOME}/.config/scribusrc
398blacklist ${HOME}/.config/sinew.in 398deny ${HOME}/.config/sinew.in
399blacklist ${HOME}/.config/sink 399deny ${HOME}/.config/sink
400blacklist ${HOME}/.config/skypeforlinux 400deny ${HOME}/.config/skypeforlinux
401blacklist ${HOME}/.config/slimjet 401deny ${HOME}/.config/slimjet
402blacklist ${HOME}/.config/smplayer 402deny ${HOME}/.config/smplayer
403blacklist ${HOME}/.config/smtube 403deny ${HOME}/.config/smtube
404blacklist ${HOME}/.config/smuxi 404deny ${HOME}/.config/smuxi
405blacklist ${HOME}/.config/snox 405deny ${HOME}/.config/snox
406blacklist ${HOME}/.config/sound-juicer 406deny ${HOME}/.config/sound-juicer
407blacklist ${HOME}/.config/specialmailcollectionsrc 407deny ${HOME}/.config/specialmailcollectionsrc
408blacklist ${HOME}/.config/spectaclerc 408deny ${HOME}/.config/spectaclerc
409blacklist ${HOME}/.config/spotify 409deny ${HOME}/.config/spotify
410blacklist ${HOME}/.config/sqlitebrowser 410deny ${HOME}/.config/sqlitebrowser
411blacklist ${HOME}/.config/stellarium 411deny ${HOME}/.config/stellarium
412blacklist ${HOME}/.config/strawberry 412deny ${HOME}/.config/strawberry
413blacklist ${HOME}/.config/straw-viewer 413deny ${HOME}/.config/straw-viewer
414blacklist ${HOME}/.config/supertuxkart 414deny ${HOME}/.config/supertuxkart
415blacklist ${HOME}/.config/synfig 415deny ${HOME}/.config/synfig
416blacklist ${HOME}/.config/teams 416deny ${HOME}/.config/teams
417blacklist ${HOME}/.config/teams-for-linux 417deny ${HOME}/.config/teams-for-linux
418blacklist ${HOME}/.config/telepathy-account-widgets 418deny ${HOME}/.config/telepathy-account-widgets
419blacklist ${HOME}/.config/torbrowser 419deny ${HOME}/.config/torbrowser
420blacklist ${HOME}/.config/totem 420deny ${HOME}/.config/totem
421blacklist ${HOME}/.config/tox 421deny ${HOME}/.config/tox
422blacklist ${HOME}/.config/transgui 422deny ${HOME}/.config/transgui
423blacklist ${HOME}/.config/transmission 423deny ${HOME}/.config/transmission
424blacklist ${HOME}/.config/truecraft 424deny ${HOME}/.config/truecraft
425blacklist ${HOME}/.config/tuta_integration 425deny ${HOME}/.config/tuta_integration
426blacklist ${HOME}/.config/tutanota-desktop 426deny ${HOME}/.config/tutanota-desktop
427blacklist ${HOME}/.config/tvbrowser 427deny ${HOME}/.config/tvbrowser
428blacklist ${HOME}/.config/uGet 428deny ${HOME}/.config/uGet
429blacklist ${HOME}/.config/ungoogled-chromium 429deny ${HOME}/.config/ungoogled-chromium
430blacklist ${HOME}/.config/uzbl 430deny ${HOME}/.config/uzbl
431blacklist ${HOME}/.config/viewnior 431deny ${HOME}/.config/viewnior
432blacklist ${HOME}/.config/vivaldi 432deny ${HOME}/.config/vivaldi
433blacklist ${HOME}/.config/vivaldi-snapshot 433deny ${HOME}/.config/vivaldi-snapshot
434blacklist ${HOME}/.config/vlc 434deny ${HOME}/.config/vlc
435blacklist ${HOME}/.config/wesnoth 435deny ${HOME}/.config/wesnoth
436blacklist ${HOME}/.config/wormux 436deny ${HOME}/.config/wormux
437blacklist ${HOME}/.config/Whalebird 437deny ${HOME}/.config/Whalebird
438blacklist ${HOME}/.config/wireshark 438deny ${HOME}/.config/wireshark
439blacklist ${HOME}/.config/xchat 439deny ${HOME}/.config/xchat
440blacklist ${HOME}/.config/xed 440deny ${HOME}/.config/xed
441blacklist ${HOME}/.config/xfburn 441deny ${HOME}/.config/xfburn
442blacklist ${HOME}/.config/xfce4/xfce4-notes.gtkrc 442deny ${HOME}/.config/xfce4/xfce4-notes.gtkrc
443blacklist ${HOME}/.config/xfce4/xfce4-notes.rc 443deny ${HOME}/.config/xfce4/xfce4-notes.rc
444blacklist ${HOME}/.config/xfce4/xfconf/xfce-perchannel-xml/thunar.xml 444deny ${HOME}/.config/xfce4/xfconf/xfce-perchannel-xml/thunar.xml
445blacklist ${HOME}/.config/xfce4/xfconf/xfce-perchannel-xml/xfce4-mixer.xml 445deny ${HOME}/.config/xfce4/xfconf/xfce-perchannel-xml/xfce4-mixer.xml
446blacklist ${HOME}/.config/xfce4-dict 446deny ${HOME}/.config/xfce4-dict
447blacklist ${HOME}/.config/xiaoyong 447deny ${HOME}/.config/xiaoyong
448blacklist ${HOME}/.config/xmms2 448deny ${HOME}/.config/xmms2
449blacklist ${HOME}/.config/xplayer 449deny ${HOME}/.config/xplayer
450blacklist ${HOME}/.config/xreader 450deny ${HOME}/.config/xreader
451blacklist ${HOME}/.config/xviewer 451deny ${HOME}/.config/xviewer
452blacklist ${HOME}/.config/yandex-browser 452deny ${HOME}/.config/yandex-browser
453blacklist ${HOME}/.config/yandex-browser-beta 453deny ${HOME}/.config/yandex-browser-beta
454blacklist ${HOME}/.config/yelp 454deny ${HOME}/.config/yelp
455blacklist ${HOME}/.config/youtube-dl 455deny ${HOME}/.config/youtube-dl
456blacklist ${HOME}/.config/youtube-dlg 456deny ${HOME}/.config/youtube-dlg
457blacklist ${HOME}/.config/youtubemusic-nativefier-040164 457deny ${HOME}/.config/youtubemusic-nativefier-040164
458blacklist ${HOME}/.config/youtube-music-desktop-app 458deny ${HOME}/.config/youtube-music-desktop-app
459blacklist ${HOME}/.config/youtube-viewer 459deny ${HOME}/.config/youtube-viewer
460blacklist ${HOME}/.config/zathura 460deny ${HOME}/.config/zathura
461blacklist ${HOME}/.config/zoomus.conf 461deny ${HOME}/.config/zoomus.conf
462blacklist ${HOME}/.config/Zulip 462deny ${HOME}/.config/Zulip
463blacklist ${HOME}/.conkeror.mozdev.org 463deny ${HOME}/.conkeror.mozdev.org
464blacklist ${HOME}/.crawl 464deny ${HOME}/.crawl
465blacklist ${HOME}/.cups 465deny ${HOME}/.cups
466blacklist ${HOME}/.curl-hsts 466deny ${HOME}/.curl-hsts
467blacklist ${HOME}/.curlrc 467deny ${HOME}/.curlrc
468blacklist ${HOME}/.dashcore 468deny ${HOME}/.dashcore
469blacklist ${HOME}/.devilspie 469deny ${HOME}/.devilspie
470blacklist ${HOME}/.dia 470deny ${HOME}/.dia
471blacklist ${HOME}/.digrc 471deny ${HOME}/.digrc
472blacklist ${HOME}/.dillo 472deny ${HOME}/.dillo
473blacklist ${HOME}/.dooble 473deny ${HOME}/.dooble
474blacklist ${HOME}/.dosbox 474deny ${HOME}/.dosbox
475blacklist ${HOME}/.dropbox* 475deny ${HOME}/.dropbox*
476blacklist ${HOME}/.easystroke 476deny ${HOME}/.easystroke
477blacklist ${HOME}/.electron-cache 477deny ${HOME}/.electron-cache
478blacklist ${HOME}/.electrum* 478deny ${HOME}/.electrum*
479blacklist ${HOME}/.elinks 479deny ${HOME}/.elinks
480blacklist ${HOME}/.emacs 480deny ${HOME}/.emacs
481blacklist ${HOME}/.emacs.d 481deny ${HOME}/.emacs.d
482blacklist ${HOME}/.equalx 482deny ${HOME}/.equalx
483blacklist ${HOME}/.ethereum 483deny ${HOME}/.ethereum
484blacklist ${HOME}/.etr 484deny ${HOME}/.etr
485blacklist ${HOME}/.filezilla 485deny ${HOME}/.filezilla
486blacklist ${HOME}/.firedragon 486deny ${HOME}/.firedragon
487blacklist ${HOME}/.flowblade 487deny ${HOME}/.flowblade
488blacklist ${HOME}/.fltk 488deny ${HOME}/.fltk
489blacklist ${HOME}/.fossamail 489deny ${HOME}/.fossamail
490blacklist ${HOME}/.freeciv 490deny ${HOME}/.freeciv
491blacklist ${HOME}/.freecol 491deny ${HOME}/.freecol
492blacklist ${HOME}/.freemind 492deny ${HOME}/.freemind
493blacklist ${HOME}/.frogatto 493deny ${HOME}/.frogatto
494blacklist ${HOME}/.frozen-bubble 494deny ${HOME}/.frozen-bubble
495blacklist ${HOME}/.funnyboat 495deny ${HOME}/.funnyboat
496blacklist ${HOME}/.gimp* 496deny ${HOME}/.gimp*
497blacklist ${HOME}/.gist 497deny ${HOME}/.gist
498blacklist ${HOME}/.gitconfig 498deny ${HOME}/.gitconfig
499blacklist ${HOME}/.gl-117 499deny ${HOME}/.gl-117
500blacklist ${HOME}/.glaxiumrc 500deny ${HOME}/.glaxiumrc
501blacklist ${HOME}/.gnome/gnome-schedule 501deny ${HOME}/.gnome/gnome-schedule
502blacklist ${HOME}/.googleearth 502deny ${HOME}/.googleearth
503blacklist ${HOME}/.gradle 503deny ${HOME}/.gradle
504blacklist ${HOME}/.gramps 504deny ${HOME}/.gramps
505blacklist ${HOME}/.guayadeque 505deny ${HOME}/.guayadeque
506blacklist ${HOME}/.hashcat 506deny ${HOME}/.hashcat
507blacklist ${HOME}/.hex-a-hop 507deny ${HOME}/.hex-a-hop
508blacklist ${HOME}/.hedgewars 508deny ${HOME}/.hedgewars
509blacklist ${HOME}/.hugin 509deny ${HOME}/.hugin
510blacklist ${HOME}/.i2p 510deny ${HOME}/.i2p
511blacklist ${HOME}/.icedove 511deny ${HOME}/.icedove
512blacklist ${HOME}/.imagej 512deny ${HOME}/.imagej
513blacklist ${HOME}/.inkscape 513deny ${HOME}/.inkscape
514blacklist ${HOME}/.itch 514deny ${HOME}/.itch
515blacklist ${HOME}/.jack-server 515deny ${HOME}/.jack-server
516blacklist ${HOME}/.jack-settings 516deny ${HOME}/.jack-settings
517blacklist ${HOME}/.jak 517deny ${HOME}/.jak
518blacklist ${HOME}/.java 518deny ${HOME}/.java
519blacklist ${HOME}/.jd 519deny ${HOME}/.jd
520blacklist ${HOME}/.jitsi 520deny ${HOME}/.jitsi
521blacklist ${HOME}/.jumpnbump 521deny ${HOME}/.jumpnbump
522blacklist ${HOME}/.kde/share/apps/digikam 522deny ${HOME}/.kde/share/apps/digikam
523blacklist ${HOME}/.kde/share/apps/gwenview 523deny ${HOME}/.kde/share/apps/gwenview
524blacklist ${HOME}/.kde/share/apps/kaffeine 524deny ${HOME}/.kde/share/apps/kaffeine
525blacklist ${HOME}/.kde/share/apps/kcookiejar 525deny ${HOME}/.kde/share/apps/kcookiejar
526blacklist ${HOME}/.kde/share/apps/kget 526deny ${HOME}/.kde/share/apps/kget
527blacklist ${HOME}/.kde/share/apps/khtml 527deny ${HOME}/.kde/share/apps/khtml
528blacklist ${HOME}/.kde/share/apps/klatexformula 528deny ${HOME}/.kde/share/apps/klatexformula
529blacklist ${HOME}/.kde/share/apps/konqsidebartng 529deny ${HOME}/.kde/share/apps/konqsidebartng
530blacklist ${HOME}/.kde/share/apps/konqueror 530deny ${HOME}/.kde/share/apps/konqueror
531blacklist ${HOME}/.kde/share/apps/kopete 531deny ${HOME}/.kde/share/apps/kopete
532blacklist ${HOME}/.kde/share/apps/ktorrent 532deny ${HOME}/.kde/share/apps/ktorrent
533blacklist ${HOME}/.kde/share/apps/okular 533deny ${HOME}/.kde/share/apps/okular
534blacklist ${HOME}/.kde/share/config/baloofilerc 534deny ${HOME}/.kde/share/config/baloofilerc
535blacklist ${HOME}/.kde/share/config/baloorc 535deny ${HOME}/.kde/share/config/baloorc
536blacklist ${HOME}/.kde/share/config/digikam 536deny ${HOME}/.kde/share/config/digikam
537blacklist ${HOME}/.kde/share/config/gwenviewrc 537deny ${HOME}/.kde/share/config/gwenviewrc
538blacklist ${HOME}/.kde/share/config/k3brc 538deny ${HOME}/.kde/share/config/k3brc
539blacklist ${HOME}/.kde/share/config/kaffeinerc 539deny ${HOME}/.kde/share/config/kaffeinerc
540blacklist ${HOME}/.kde/share/config/kcookiejarrc 540deny ${HOME}/.kde/share/config/kcookiejarrc
541blacklist ${HOME}/.kde/share/config/kfindrc 541deny ${HOME}/.kde/share/config/kfindrc
542blacklist ${HOME}/.kde/share/config/kgetrc 542deny ${HOME}/.kde/share/config/kgetrc
543blacklist ${HOME}/.kde/share/config/khtmlrc 543deny ${HOME}/.kde/share/config/khtmlrc
544blacklist ${HOME}/.kde/share/config/klipperrc 544deny ${HOME}/.kde/share/config/klipperrc
545blacklist ${HOME}/.kde/share/config/kmplayerrc 545deny ${HOME}/.kde/share/config/kmplayerrc
546blacklist ${HOME}/.kde/share/config/konq_history 546deny ${HOME}/.kde/share/config/konq_history
547blacklist ${HOME}/.kde/share/config/konqsidebartngrc 547deny ${HOME}/.kde/share/config/konqsidebartngrc
548blacklist ${HOME}/.kde/share/config/konquerorrc 548deny ${HOME}/.kde/share/config/konquerorrc
549blacklist ${HOME}/.kde/share/config/konversationrc 549deny ${HOME}/.kde/share/config/konversationrc
550blacklist ${HOME}/.kde/share/config/kopeterc 550deny ${HOME}/.kde/share/config/kopeterc
551blacklist ${HOME}/.kde/share/config/ktorrentrc 551deny ${HOME}/.kde/share/config/ktorrentrc
552blacklist ${HOME}/.kde/share/config/okularpartrc 552deny ${HOME}/.kde/share/config/okularpartrc
553blacklist ${HOME}/.kde/share/config/okularrc 553deny ${HOME}/.kde/share/config/okularrc
554blacklist ${HOME}/.kde4/share/apps/digikam 554deny ${HOME}/.kde4/share/apps/digikam
555blacklist ${HOME}/.kde4/share/apps/gwenview 555deny ${HOME}/.kde4/share/apps/gwenview
556blacklist ${HOME}/.kde4/share/apps/kaffeine 556deny ${HOME}/.kde4/share/apps/kaffeine
557blacklist ${HOME}/.kde4/share/apps/kcookiejar 557deny ${HOME}/.kde4/share/apps/kcookiejar
558blacklist ${HOME}/.kde4/share/apps/kget 558deny ${HOME}/.kde4/share/apps/kget
559blacklist ${HOME}/.kde4/share/apps/khtml 559deny ${HOME}/.kde4/share/apps/khtml
560blacklist ${HOME}/.kde4/share/apps/konqsidebartng 560deny ${HOME}/.kde4/share/apps/konqsidebartng
561blacklist ${HOME}/.kde4/share/apps/konqueror 561deny ${HOME}/.kde4/share/apps/konqueror
562blacklist ${HOME}/.kde4/share/apps/kopete 562deny ${HOME}/.kde4/share/apps/kopete
563blacklist ${HOME}/.kde4/share/apps/ktorrent 563deny ${HOME}/.kde4/share/apps/ktorrent
564blacklist ${HOME}/.kde4/share/apps/okular 564deny ${HOME}/.kde4/share/apps/okular
565blacklist ${HOME}/.kde4/share/config/baloofilerc 565deny ${HOME}/.kde4/share/config/baloofilerc
566blacklist ${HOME}/.kde4/share/config/baloorc 566deny ${HOME}/.kde4/share/config/baloorc
567blacklist ${HOME}/.kde4/share/config/digikam 567deny ${HOME}/.kde4/share/config/digikam
568blacklist ${HOME}/.kde4/share/config/gwenviewrc 568deny ${HOME}/.kde4/share/config/gwenviewrc
569blacklist ${HOME}/.kde4/share/config/k3brc 569deny ${HOME}/.kde4/share/config/k3brc
570blacklist ${HOME}/.kde4/share/config/kaffeinerc 570deny ${HOME}/.kde4/share/config/kaffeinerc
571blacklist ${HOME}/.kde4/share/config/kcookiejarrc 571deny ${HOME}/.kde4/share/config/kcookiejarrc
572blacklist ${HOME}/.kde4/share/config/kfindrc 572deny ${HOME}/.kde4/share/config/kfindrc
573blacklist ${HOME}/.kde4/share/config/kgetrc 573deny ${HOME}/.kde4/share/config/kgetrc
574blacklist ${HOME}/.kde4/share/config/khtmlrc 574deny ${HOME}/.kde4/share/config/khtmlrc
575blacklist ${HOME}/.kde4/share/config/klipperrc 575deny ${HOME}/.kde4/share/config/klipperrc
576blacklist ${HOME}/.kde4/share/config/konq_history 576deny ${HOME}/.kde4/share/config/konq_history
577blacklist ${HOME}/.kde4/share/config/konqsidebartngrc 577deny ${HOME}/.kde4/share/config/konqsidebartngrc
578blacklist ${HOME}/.kde4/share/config/konquerorrc 578deny ${HOME}/.kde4/share/config/konquerorrc
579blacklist ${HOME}/.kde4/share/config/konversationrc 579deny ${HOME}/.kde4/share/config/konversationrc
580blacklist ${HOME}/.kde4/share/config/kopeterc 580deny ${HOME}/.kde4/share/config/kopeterc
581blacklist ${HOME}/.kde4/share/config/ktorrentrc 581deny ${HOME}/.kde4/share/config/ktorrentrc
582blacklist ${HOME}/.kde4/share/config/okularpartrc 582deny ${HOME}/.kde4/share/config/okularpartrc
583blacklist ${HOME}/.kde4/share/config/okularrc 583deny ${HOME}/.kde4/share/config/okularrc
584blacklist ${HOME}/.killingfloor 584deny ${HOME}/.killingfloor
585blacklist ${HOME}/.kingsoft 585deny ${HOME}/.kingsoft
586blacklist ${HOME}/.kino-history 586deny ${HOME}/.kino-history
587blacklist ${HOME}/.kinorc 587deny ${HOME}/.kinorc
588blacklist ${HOME}/.klatexformula 588deny ${HOME}/.klatexformula
589blacklist ${HOME}/.klei 589deny ${HOME}/.klei
590blacklist ${HOME}/.kodi 590deny ${HOME}/.kodi
591blacklist ${HOME}/.librewolf 591deny ${HOME}/.librewolf
592blacklist ${HOME}/.lincity-ng 592deny ${HOME}/.lincity-ng
593blacklist ${HOME}/.links 593deny ${HOME}/.links
594blacklist ${HOME}/.links2 594deny ${HOME}/.links2
595blacklist ${HOME}/.linphone-history.db 595deny ${HOME}/.linphone-history.db
596blacklist ${HOME}/.linphonerc 596deny ${HOME}/.linphonerc
597blacklist ${HOME}/.lmmsrc.xml 597deny ${HOME}/.lmmsrc.xml
598blacklist ${HOME}/.local/lib/vivaldi 598deny ${HOME}/.local/lib/vivaldi
599blacklist ${HOME}/.local/share/0ad 599deny ${HOME}/.local/share/0ad
600blacklist ${HOME}/.local/share/3909/PapersPlease 600deny ${HOME}/.local/share/3909/PapersPlease
601blacklist ${HOME}/.local/share/Anki2 601deny ${HOME}/.local/share/Anki2
602blacklist ${HOME}/.local/share/Dredmor 602deny ${HOME}/.local/share/Dredmor
603blacklist ${HOME}/.local/share/Empathy 603deny ${HOME}/.local/share/Empathy
604blacklist ${HOME}/.local/share/Enpass 604deny ${HOME}/.local/share/Enpass
605blacklist ${HOME}/.local/share/Flavio Tordini 605deny ${HOME}/.local/share/Flavio Tordini
606blacklist ${HOME}/.local/share/JetBrains 606deny ${HOME}/.local/share/JetBrains
607blacklist ${HOME}/.local/share/KDE/neochat 607deny ${HOME}/.local/share/KDE/neochat
608blacklist ${HOME}/.local/share/Kingsoft 608deny ${HOME}/.local/share/Kingsoft
609blacklist ${HOME}/.local/share/LibreCAD 609deny ${HOME}/.local/share/LibreCAD
610blacklist ${HOME}/.local/share/Mendeley Ltd. 610deny ${HOME}/.local/share/Mendeley Ltd.
611blacklist ${HOME}/.local/share/Mumble 611deny ${HOME}/.local/share/Mumble
612blacklist ${HOME}/.local/share/Nextcloud 612deny ${HOME}/.local/share/Nextcloud
613blacklist ${HOME}/.local/share/PBE 613deny ${HOME}/.local/share/PBE
614blacklist ${HOME}/.local/share/PawelStolowski 614deny ${HOME}/.local/share/PawelStolowski
615blacklist ${HOME}/.local/share/PillarsOfEternity 615deny ${HOME}/.local/share/PillarsOfEternity
616blacklist ${HOME}/.local/share/Psi 616deny ${HOME}/.local/share/Psi
617blacklist ${HOME}/.local/share/QGIS 617deny ${HOME}/.local/share/QGIS
618blacklist ${HOME}/.local/share/QMediathekView 618deny ${HOME}/.local/share/QMediathekView
619blacklist ${HOME}/.local/share/QuiteRss 619deny ${HOME}/.local/share/QuiteRss
620blacklist ${HOME}/.local/share/Ricochet 620deny ${HOME}/.local/share/Ricochet
621blacklist ${HOME}/.local/share/RogueLegacy 621deny ${HOME}/.local/share/RogueLegacy
622blacklist ${HOME}/.local/share/RogueLegacyStorageContainer 622deny ${HOME}/.local/share/RogueLegacyStorageContainer
623blacklist ${HOME}/.local/share/Shortwave 623deny ${HOME}/.local/share/Shortwave
624blacklist ${HOME}/.local/share/Steam 624deny ${HOME}/.local/share/Steam
625blacklist ${HOME}/.local/share/SteamWorldDig 625deny ${HOME}/.local/share/SteamWorldDig
626blacklist ${HOME}/.local/share/SteamWorld Dig 2 626deny ${HOME}/.local/share/SteamWorld Dig 2
627blacklist ${HOME}/.local/share/SuperHexagon 627deny ${HOME}/.local/share/SuperHexagon
628blacklist ${HOME}/.local/share/TelegramDesktop 628deny ${HOME}/.local/share/TelegramDesktop
629blacklist ${HOME}/.local/share/Terraria 629deny ${HOME}/.local/share/Terraria
630blacklist ${HOME}/.local/share/TpLogger 630deny ${HOME}/.local/share/TpLogger
631blacklist ${HOME}/.local/share/Zeal 631deny ${HOME}/.local/share/Zeal
632blacklist ${HOME}/.local/share/akonadi* 632deny ${HOME}/.local/share/akonadi*
633blacklist ${HOME}/.local/share/akregator 633deny ${HOME}/.local/share/akregator
634blacklist ${HOME}/.local/share/agenda 634deny ${HOME}/.local/share/agenda
635blacklist ${HOME}/.local/share/apps/korganizer 635deny ${HOME}/.local/share/apps/korganizer
636blacklist ${HOME}/.local/share/aspyr-media 636deny ${HOME}/.local/share/aspyr-media
637blacklist ${HOME}/.local/share/autokey 637deny ${HOME}/.local/share/autokey
638blacklist ${HOME}/.local/share/authenticator-rs 638deny ${HOME}/.local/share/authenticator-rs
639blacklist ${HOME}/.local/share/backintime 639deny ${HOME}/.local/share/backintime
640blacklist ${HOME}/.local/share/baloo 640deny ${HOME}/.local/share/baloo
641blacklist ${HOME}/.local/share/barrier 641deny ${HOME}/.local/share/barrier
642blacklist ${HOME}/.local/share/bibletime 642deny ${HOME}/.local/share/bibletime
643blacklist ${HOME}/.local/share/bijiben 643deny ${HOME}/.local/share/bijiben
644blacklist ${HOME}/.local/share/bohemiainteractive 644deny ${HOME}/.local/share/bohemiainteractive
645blacklist ${HOME}/.local/share/caja-python 645deny ${HOME}/.local/share/caja-python
646blacklist ${HOME}/.local/share/calligragemini 646deny ${HOME}/.local/share/calligragemini
647blacklist ${HOME}/.local/share/cantata 647deny ${HOME}/.local/share/cantata
648blacklist ${HOME}/.local/share/cdprojektred 648deny ${HOME}/.local/share/cdprojektred
649blacklist ${HOME}/.local/share/clipit 649deny ${HOME}/.local/share/clipit
650blacklist ${HOME}/.local/share/com.github.johnfactotum.Foliate 650deny ${HOME}/.local/share/com.github.johnfactotum.Foliate
651blacklist ${HOME}/.local/share/contacts 651deny ${HOME}/.local/share/contacts
652blacklist ${HOME}/.local/share/cor-games 652deny ${HOME}/.local/share/cor-games
653blacklist ${HOME}/.local/share/data/Mendeley Ltd. 653deny ${HOME}/.local/share/data/Mendeley Ltd.
654blacklist ${HOME}/.local/share/data/Mumble 654deny ${HOME}/.local/share/data/Mumble
655blacklist ${HOME}/.local/share/data/MusE 655deny ${HOME}/.local/share/data/MusE
656blacklist ${HOME}/.local/share/data/MuseScore 656deny ${HOME}/.local/share/data/MuseScore
657blacklist ${HOME}/.local/share/data/nomacs 657deny ${HOME}/.local/share/data/nomacs
658blacklist ${HOME}/.local/share/data/qBittorrent 658deny ${HOME}/.local/share/data/qBittorrent
659blacklist ${HOME}/.local/share/dino 659deny ${HOME}/.local/share/dino
660blacklist ${HOME}/.local/share/dolphin 660deny ${HOME}/.local/share/dolphin
661blacklist ${HOME}/.local/share/dolphin-emu 661deny ${HOME}/.local/share/dolphin-emu
662blacklist ${HOME}/.local/share/emailidentities 662deny ${HOME}/.local/share/emailidentities
663blacklist ${HOME}/.local/share/epiphany 663deny ${HOME}/.local/share/epiphany
664blacklist ${HOME}/.local/share/evolution 664deny ${HOME}/.local/share/evolution
665blacklist ${HOME}/.local/share/FasterThanLight 665deny ${HOME}/.local/share/FasterThanLight
666blacklist ${HOME}/.local/share/feedreader 666deny ${HOME}/.local/share/feedreader
667blacklist ${HOME}/.local/share/feral-interactive 667deny ${HOME}/.local/share/feral-interactive
668blacklist ${HOME}/.local/share/five-or-more 668deny ${HOME}/.local/share/five-or-more
669blacklist ${HOME}/.local/share/freecol 669deny ${HOME}/.local/share/freecol
670blacklist ${HOME}/.local/share/gajim 670deny ${HOME}/.local/share/gajim
671blacklist ${HOME}/.local/share/geary 671deny ${HOME}/.local/share/geary
672blacklist ${HOME}/.local/share/geeqie 672deny ${HOME}/.local/share/geeqie
673blacklist ${HOME}/.local/share/ghostwriter 673deny ${HOME}/.local/share/ghostwriter
674blacklist ${HOME}/.local/share/gitg 674deny ${HOME}/.local/share/gitg
675blacklist ${HOME}/.local/share/gnome-2048 675deny ${HOME}/.local/share/gnome-2048
676blacklist ${HOME}/.local/share/gnome-boxes 676deny ${HOME}/.local/share/gnome-boxes
677blacklist ${HOME}/.local/share/gnome-builder 677deny ${HOME}/.local/share/gnome-builder
678blacklist ${HOME}/.local/share/gnome-chess 678deny ${HOME}/.local/share/gnome-chess
679blacklist ${HOME}/.local/share/gnome-klotski 679deny ${HOME}/.local/share/gnome-klotski
680blacklist ${HOME}/.local/share/gnome-latex 680deny ${HOME}/.local/share/gnome-latex
681blacklist ${HOME}/.local/share/gnome-mines 681deny ${HOME}/.local/share/gnome-mines
682blacklist ${HOME}/.local/share/gnome-music 682deny ${HOME}/.local/share/gnome-music
683blacklist ${HOME}/.local/share/gnome-nibbles 683deny ${HOME}/.local/share/gnome-nibbles
684blacklist ${HOME}/.local/share/gnome-photos 684deny ${HOME}/.local/share/gnome-photos
685blacklist ${HOME}/.local/share/gnome-pomodoro 685deny ${HOME}/.local/share/gnome-pomodoro
686blacklist ${HOME}/.local/share/gnome-recipes 686deny ${HOME}/.local/share/gnome-recipes
687blacklist ${HOME}/.local/share/gnome-ring 687deny ${HOME}/.local/share/gnome-ring
688blacklist ${HOME}/.local/share/gnome-sudoku 688deny ${HOME}/.local/share/gnome-sudoku
689blacklist ${HOME}/.local/share/gnome-twitch 689deny ${HOME}/.local/share/gnome-twitch
690blacklist ${HOME}/.local/share/gnote 690deny ${HOME}/.local/share/gnote
691blacklist ${HOME}/.local/share/godot 691deny ${HOME}/.local/share/godot
692blacklist ${HOME}/.local/share/gradio 692deny ${HOME}/.local/share/gradio
693blacklist ${HOME}/.local/share/gwenview 693deny ${HOME}/.local/share/gwenview
694blacklist ${HOME}/.local/share/i2p 694deny ${HOME}/.local/share/i2p
695blacklist ${HOME}/.local/share/IntoTheBreach 695deny ${HOME}/.local/share/IntoTheBreach
696blacklist ${HOME}/.local/share/jami 696deny ${HOME}/.local/share/jami
697blacklist ${HOME}/.local/share/kaffeine 697deny ${HOME}/.local/share/kaffeine
698blacklist ${HOME}/.local/share/kalgebra 698deny ${HOME}/.local/share/kalgebra
699blacklist ${HOME}/.local/share/kate 699deny ${HOME}/.local/share/kate
700blacklist ${HOME}/.local/share/kdenlive 700deny ${HOME}/.local/share/kdenlive
701blacklist ${HOME}/.local/share/kget 701deny ${HOME}/.local/share/kget
702blacklist ${HOME}/.local/share/kiwix 702deny ${HOME}/.local/share/kiwix
703blacklist ${HOME}/.local/share/kiwix-desktop 703deny ${HOME}/.local/share/kiwix-desktop
704blacklist ${HOME}/.local/share/klavaro 704deny ${HOME}/.local/share/klavaro
705blacklist ${HOME}/.local/share/kmail2 705deny ${HOME}/.local/share/kmail2
706blacklist ${HOME}/.local/share/kmplayer 706deny ${HOME}/.local/share/kmplayer
707blacklist ${HOME}/.local/share/knotes 707deny ${HOME}/.local/share/knotes
708blacklist ${HOME}/.local/share/krita 708deny ${HOME}/.local/share/krita
709blacklist ${HOME}/.local/share/ktorrent 709deny ${HOME}/.local/share/ktorrent
710blacklist ${HOME}/.local/share/ktorrentrc 710deny ${HOME}/.local/share/ktorrentrc
711blacklist ${HOME}/.local/share/ktouch 711deny ${HOME}/.local/share/ktouch
712blacklist ${HOME}/.local/share/kube 712deny ${HOME}/.local/share/kube
713blacklist ${HOME}/.local/share/kwrite 713deny ${HOME}/.local/share/kwrite
714blacklist ${HOME}/.local/share/kxmlgui5/* 714deny ${HOME}/.local/share/kxmlgui5/*
715blacklist ${HOME}/.local/share/liferea 715deny ${HOME}/.local/share/liferea
716blacklist ${HOME}/.local/share/linphone 716deny ${HOME}/.local/share/linphone
717blacklist ${HOME}/.local/share/local-mail 717deny ${HOME}/.local/share/local-mail
718blacklist ${HOME}/.local/share/lollypop 718deny ${HOME}/.local/share/lollypop
719blacklist ${HOME}/.local/share/love 719deny ${HOME}/.local/share/love
720blacklist ${HOME}/.local/share/lugaru 720deny ${HOME}/.local/share/lugaru
721blacklist ${HOME}/.local/share/lutris 721deny ${HOME}/.local/share/lutris
722blacklist ${HOME}/.local/share/man 722deny ${HOME}/.local/share/man
723blacklist ${HOME}/.local/share/mana 723deny ${HOME}/.local/share/mana
724blacklist ${HOME}/.local/share/maps-places.json 724deny ${HOME}/.local/share/maps-places.json
725blacklist ${HOME}/.local/share/matrix-mirage 725deny ${HOME}/.local/share/matrix-mirage
726blacklist ${HOME}/.local/share/mcomix 726deny ${HOME}/.local/share/mcomix
727blacklist ${HOME}/.local/share/meld 727deny ${HOME}/.local/share/meld
728blacklist ${HOME}/.local/share/midori 728deny ${HOME}/.local/share/midori
729blacklist ${HOME}/.local/share/minder 729deny ${HOME}/.local/share/minder
730blacklist ${HOME}/.local/share/mirage 730deny ${HOME}/.local/share/mirage
731blacklist ${HOME}/.local/share/multimc 731deny ${HOME}/.local/share/multimc
732blacklist ${HOME}/.local/share/multimc5 732deny ${HOME}/.local/share/multimc5
733blacklist ${HOME}/.local/share/mupen64plus 733deny ${HOME}/.local/share/mupen64plus
734blacklist ${HOME}/.local/share/mypaint 734deny ${HOME}/.local/share/mypaint
735blacklist ${HOME}/.local/share/nautilus 735deny ${HOME}/.local/share/nautilus
736blacklist ${HOME}/.local/share/nautilus-python 736deny ${HOME}/.local/share/nautilus-python
737blacklist ${HOME}/.local/share/nemo 737deny ${HOME}/.local/share/nemo
738blacklist ${HOME}/.local/share/nemo-python 738deny ${HOME}/.local/share/nemo-python
739blacklist ${HOME}/.local/share/news-flash 739deny ${HOME}/.local/share/news-flash
740blacklist ${HOME}/.local/share/newsbeuter 740deny ${HOME}/.local/share/newsbeuter
741blacklist ${HOME}/.local/share/newsboat 741deny ${HOME}/.local/share/newsboat
742blacklist ${HOME}/.local/share/nheko 742deny ${HOME}/.local/share/nheko
743blacklist ${HOME}/.local/share/nomacs 743deny ${HOME}/.local/share/nomacs
744blacklist ${HOME}/.local/share/notes 744deny ${HOME}/.local/share/notes
745blacklist ${HOME}/.local/share/ocenaudio 745deny ${HOME}/.local/share/ocenaudio
746blacklist ${HOME}/.local/share/okular 746deny ${HOME}/.local/share/okular
747blacklist ${HOME}/.local/share/onlyoffice 747deny ${HOME}/.local/share/onlyoffice
748blacklist ${HOME}/.local/share/openmw 748deny ${HOME}/.local/share/openmw
749blacklist ${HOME}/.local/share/orage 749deny ${HOME}/.local/share/orage
750blacklist ${HOME}/.local/share/org.kde.gwenview 750deny ${HOME}/.local/share/org.kde.gwenview
751blacklist ${HOME}/.local/share/Paradox Interactive 751deny ${HOME}/.local/share/Paradox Interactive
752blacklist ${HOME}/.local/share/pix 752deny ${HOME}/.local/share/pix
753blacklist ${HOME}/.local/share/plasma_notes 753deny ${HOME}/.local/share/plasma_notes
754blacklist ${HOME}/.local/share/profanity 754deny ${HOME}/.local/share/profanity
755blacklist ${HOME}/.local/share/psi 755deny ${HOME}/.local/share/psi
756blacklist ${HOME}/.local/share/psi+ 756deny ${HOME}/.local/share/psi+
757blacklist ${HOME}/.local/share/quadrapassel 757deny ${HOME}/.local/share/quadrapassel
758blacklist ${HOME}/.local/share/qpdfview 758deny ${HOME}/.local/share/qpdfview
759blacklist ${HOME}/.local/share/qutebrowser 759deny ${HOME}/.local/share/qutebrowser
760blacklist ${HOME}/.local/share/remmina 760deny ${HOME}/.local/share/remmina
761blacklist ${HOME}/.local/share/rhythmbox 761deny ${HOME}/.local/share/rhythmbox
762blacklist ${HOME}/.local/share/rtv 762deny ${HOME}/.local/share/rtv
763blacklist ${HOME}/.local/share/scribus 763deny ${HOME}/.local/share/scribus
764blacklist ${HOME}/.local/share/shotwell 764deny ${HOME}/.local/share/shotwell
765blacklist ${HOME}/.local/share/signal-cli 765deny ${HOME}/.local/share/signal-cli
766blacklist ${HOME}/.local/share/sink 766deny ${HOME}/.local/share/sink
767blacklist ${HOME}/.local/share/smuxi 767deny ${HOME}/.local/share/smuxi
768blacklist ${HOME}/.local/share/spotify 768deny ${HOME}/.local/share/spotify
769blacklist ${HOME}/.local/share/steam 769deny ${HOME}/.local/share/steam
770blacklist ${HOME}/.local/share/strawberry 770deny ${HOME}/.local/share/strawberry
771blacklist ${HOME}/.local/share/supertux2 771deny ${HOME}/.local/share/supertux2
772blacklist ${HOME}/.local/share/supertuxkart 772deny ${HOME}/.local/share/supertuxkart
773blacklist ${HOME}/.local/share/swell-foop 773deny ${HOME}/.local/share/swell-foop
774blacklist ${HOME}/.local/share/telepathy 774deny ${HOME}/.local/share/telepathy
775blacklist ${HOME}/.local/share/terasology 775deny ${HOME}/.local/share/terasology
776blacklist ${HOME}/.local/share/torbrowser 776deny ${HOME}/.local/share/torbrowser
777blacklist ${HOME}/.local/share/totem 777deny ${HOME}/.local/share/totem
778blacklist ${HOME}/.local/share/uzbl 778deny ${HOME}/.local/share/uzbl
779blacklist ${HOME}/.local/share/vlc 779deny ${HOME}/.local/share/vlc
780blacklist ${HOME}/.local/share/vpltd 780deny ${HOME}/.local/share/vpltd
781blacklist ${HOME}/.local/share/vulkan 781deny ${HOME}/.local/share/vulkan
782blacklist ${HOME}/.local/share/warsow-2.1 782deny ${HOME}/.local/share/warsow-2.1
783blacklist ${HOME}/.local/share/wesnoth 783deny ${HOME}/.local/share/wesnoth
784blacklist ${HOME}/.local/share/wormux 784deny ${HOME}/.local/share/wormux
785blacklist ${HOME}/.local/share/xplayer 785deny ${HOME}/.local/share/xplayer
786blacklist ${HOME}/.local/share/xreader 786deny ${HOME}/.local/share/xreader
787blacklist ${HOME}/.local/share/zathura 787deny ${HOME}/.local/share/zathura
788blacklist ${HOME}/.lv2 788deny ${HOME}/.lv2
789blacklist ${HOME}/.lyx 789deny ${HOME}/.lyx
790blacklist ${HOME}/.magicor 790deny ${HOME}/.magicor
791blacklist ${HOME}/.masterpdfeditor 791deny ${HOME}/.masterpdfeditor
792blacklist ${HOME}/.mbwarband 792deny ${HOME}/.mbwarband
793blacklist ${HOME}/.mcabber 793deny ${HOME}/.mcabber
794blacklist ${HOME}/.mcabberrc 794deny ${HOME}/.mcabberrc
795blacklist ${HOME}/.mediathek3 795deny ${HOME}/.mediathek3
796blacklist ${HOME}/.megaglest 796deny ${HOME}/.megaglest
797blacklist ${HOME}/.minecraft 797deny ${HOME}/.minecraft
798blacklist ${HOME}/.minetest 798deny ${HOME}/.minetest
799blacklist ${HOME}/.mirrormagic 799deny ${HOME}/.mirrormagic
800blacklist ${HOME}/.moc 800deny ${HOME}/.moc
801blacklist ${HOME}/.moonchild productions/basilisk 801deny ${HOME}/.moonchild productions/basilisk
802blacklist ${HOME}/.moonchild productions/pale moon 802deny ${HOME}/.moonchild productions/pale moon
803blacklist ${HOME}/.mozilla 803deny ${HOME}/.mozilla
804blacklist ${HOME}/.mp3splt-gtk 804deny ${HOME}/.mp3splt-gtk
805blacklist ${HOME}/.mpd 805deny ${HOME}/.mpd
806blacklist ${HOME}/.mpdconf 806deny ${HOME}/.mpdconf
807blacklist ${HOME}/.mplayer 807deny ${HOME}/.mplayer
808blacklist ${HOME}/.msmtprc 808deny ${HOME}/.msmtprc
809blacklist ${HOME}/.multimc5 809deny ${HOME}/.multimc5
810blacklist ${HOME}/.nanorc 810deny ${HOME}/.nanorc
811blacklist ${HOME}/.netactview 811deny ${HOME}/.netactview
812blacklist ${HOME}/.neverball 812deny ${HOME}/.neverball
813blacklist ${HOME}/.newsbeuter 813deny ${HOME}/.newsbeuter
814blacklist ${HOME}/.newsboat 814deny ${HOME}/.newsboat
815blacklist ${HOME}/.newsrc 815deny ${HOME}/.newsrc
816blacklist ${HOME}/.nicotine 816deny ${HOME}/.nicotine
817blacklist ${HOME}/.node-gyp 817deny ${HOME}/.node-gyp
818blacklist ${HOME}/.npm 818deny ${HOME}/.npm
819blacklist ${HOME}/.npmrc 819deny ${HOME}/.npmrc
820blacklist ${HOME}/.nv 820deny ${HOME}/.nv
821blacklist ${HOME}/.nvm 821deny ${HOME}/.nvm
822blacklist ${HOME}/.nylas-mail 822deny ${HOME}/.nylas-mail
823blacklist ${HOME}/.openarena 823deny ${HOME}/.openarena
824blacklist ${HOME}/.opencity 824deny ${HOME}/.opencity
825blacklist ${HOME}/.openinvaders 825deny ${HOME}/.openinvaders
826blacklist ${HOME}/.openshot 826deny ${HOME}/.openshot
827blacklist ${HOME}/.openshot_qt 827deny ${HOME}/.openshot_qt
828blacklist ${HOME}/.openttd 828deny ${HOME}/.openttd
829blacklist ${HOME}/.opera 829deny ${HOME}/.opera
830blacklist ${HOME}/.opera-beta 830deny ${HOME}/.opera-beta
831blacklist ${HOME}/.ostrichriders 831deny ${HOME}/.ostrichriders
832blacklist ${HOME}/.paradoxinteractive 832deny ${HOME}/.paradoxinteractive
833blacklist ${HOME}/.parallelrealities/blobwars 833deny ${HOME}/.parallelrealities/blobwars
834blacklist ${HOME}/.pcsxr 834deny ${HOME}/.pcsxr
835blacklist ${HOME}/.penguin-command 835deny ${HOME}/.penguin-command
836blacklist ${HOME}/.pine-crash 836deny ${HOME}/.pine-crash
837blacklist ${HOME}/.pine-debug1 837deny ${HOME}/.pine-debug1
838blacklist ${HOME}/.pine-debug2 838deny ${HOME}/.pine-debug2
839blacklist ${HOME}/.pine-debug3 839deny ${HOME}/.pine-debug3
840blacklist ${HOME}/.pine-debug4 840deny ${HOME}/.pine-debug4
841blacklist ${HOME}/.pine-interrupted-mail 841deny ${HOME}/.pine-interrupted-mail
842blacklist ${HOME}/.pinerc 842deny ${HOME}/.pinerc
843blacklist ${HOME}/.pinercex 843deny ${HOME}/.pinercex
844blacklist ${HOME}/.pingus 844deny ${HOME}/.pingus
845blacklist ${HOME}/.pioneer 845deny ${HOME}/.pioneer
846blacklist ${HOME}/.purple 846deny ${HOME}/.purple
847blacklist ${HOME}/.pylint.d 847deny ${HOME}/.pylint.d
848blacklist ${HOME}/.qemu-launcher 848deny ${HOME}/.qemu-launcher
849blacklist ${HOME}/.qgis2 849deny ${HOME}/.qgis2
850blacklist ${HOME}/.qmmp 850deny ${HOME}/.qmmp
851blacklist ${HOME}/.quodlibet 851deny ${HOME}/.quodlibet
852blacklist ${HOME}/.redeclipse 852deny ${HOME}/.redeclipse
853blacklist ${HOME}/.remmina 853deny ${HOME}/.remmina
854blacklist ${HOME}/.repo_.gitconfig.json 854deny ${HOME}/.repo_.gitconfig.json
855blacklist ${HOME}/.repoconfig 855deny ${HOME}/.repoconfig
856blacklist ${HOME}/.retroshare 856deny ${HOME}/.retroshare
857blacklist ${HOME}/.ripperXrc 857deny ${HOME}/.ripperXrc
858blacklist ${HOME}/.scorched3d 858deny ${HOME}/.scorched3d
859blacklist ${HOME}/.scribus 859deny ${HOME}/.scribus
860blacklist ${HOME}/.scribusrc 860deny ${HOME}/.scribusrc
861blacklist ${HOME}/.simutrans 861deny ${HOME}/.simutrans
862blacklist ${HOME}/.smartgit/*/passwords 862deny ${HOME}/.smartgit/*/passwords
863blacklist ${HOME}/.ssr 863deny ${HOME}/.ssr
864blacklist ${HOME}/.steam 864deny ${HOME}/.steam
865blacklist ${HOME}/.steampath 865deny ${HOME}/.steampath
866blacklist ${HOME}/.steampid 866deny ${HOME}/.steampid
867blacklist ${HOME}/.stellarium 867deny ${HOME}/.stellarium
868blacklist ${HOME}/.subversion 868deny ${HOME}/.subversion
869blacklist ${HOME}/.surf 869deny ${HOME}/.surf
870blacklist ${HOME}/.suve/colorful 870deny ${HOME}/.suve/colorful
871blacklist ${HOME}/.swb.ini 871deny ${HOME}/.swb.ini
872blacklist ${HOME}/.sword 872deny ${HOME}/.sword
873blacklist ${HOME}/.sylpheed-2.0 873deny ${HOME}/.sylpheed-2.0
874blacklist ${HOME}/.synfig 874deny ${HOME}/.synfig
875blacklist ${HOME}/.tb 875deny ${HOME}/.tb
876blacklist ${HOME}/.tconn 876deny ${HOME}/.tconn
877blacklist ${HOME}/.teeworlds 877deny ${HOME}/.teeworlds
878blacklist ${HOME}/.texlive20* 878deny ${HOME}/.texlive20*
879blacklist ${HOME}/.thunderbird 879deny ${HOME}/.thunderbird
880blacklist ${HOME}/.tilp 880deny ${HOME}/.tilp
881blacklist ${HOME}/.tin 881deny ${HOME}/.tin
882blacklist ${HOME}/.tooling 882deny ${HOME}/.tooling
883blacklist ${HOME}/.tor-browser* 883deny ${HOME}/.tor-browser*
884blacklist ${HOME}/.torcs 884deny ${HOME}/.torcs
885blacklist ${HOME}/.tremulous 885deny ${HOME}/.tremulous
886blacklist ${HOME}/.ts3client 886deny ${HOME}/.ts3client
887blacklist ${HOME}/.tuxguitar* 887deny ${HOME}/.tuxguitar*
888blacklist ${HOME}/.tvbrowser 888deny ${HOME}/.tvbrowser
889blacklist ${HOME}/.unknown-horizons 889deny ${HOME}/.unknown-horizons
890blacklist ${HOME}/.viking 890deny ${HOME}/.viking
891blacklist ${HOME}/.viking-maps 891deny ${HOME}/.viking-maps
892blacklist ${HOME}/.vim 892deny ${HOME}/.vim
893blacklist ${HOME}/.vimrc 893deny ${HOME}/.vimrc
894blacklist ${HOME}/.vmware 894deny ${HOME}/.vmware
895blacklist ${HOME}/.vscode 895deny ${HOME}/.vscode
896blacklist ${HOME}/.vscode-oss 896deny ${HOME}/.vscode-oss
897blacklist ${HOME}/.vst 897deny ${HOME}/.vst
898blacklist ${HOME}/.vultures 898deny ${HOME}/.vultures
899blacklist ${HOME}/.w3m 899deny ${HOME}/.w3m
900blacklist ${HOME}/.warzone2100-3.* 900deny ${HOME}/.warzone2100-3.*
901blacklist ${HOME}/.waterfox 901deny ${HOME}/.waterfox
902blacklist ${HOME}/.weechat 902deny ${HOME}/.weechat
903blacklist ${HOME}/.wget-hsts 903deny ${HOME}/.wget-hsts
904blacklist ${HOME}/.wgetrc 904deny ${HOME}/.wgetrc
905blacklist ${HOME}/.widelands 905deny ${HOME}/.widelands
906blacklist ${HOME}/.wine 906deny ${HOME}/.wine
907blacklist ${HOME}/.wine64 907deny ${HOME}/.wine64
908blacklist ${HOME}/.wireshark 908deny ${HOME}/.wireshark
909blacklist ${HOME}/.wordwarvi 909deny ${HOME}/.wordwarvi
910blacklist ${HOME}/.wormux 910deny ${HOME}/.wormux
911blacklist ${HOME}/.xiphos 911deny ${HOME}/.xiphos
912blacklist ${HOME}/.xmind 912deny ${HOME}/.xmind
913blacklist ${HOME}/.xmms 913deny ${HOME}/.xmms
914blacklist ${HOME}/.xmr-stak 914deny ${HOME}/.xmr-stak
915blacklist ${HOME}/.xonotic 915deny ${HOME}/.xonotic
916blacklist ${HOME}/.xournalpp 916deny ${HOME}/.xournalpp
917blacklist ${HOME}/.xpdfrc 917deny ${HOME}/.xpdfrc
918blacklist ${HOME}/.yarn 918deny ${HOME}/.yarn
919blacklist ${HOME}/.yarn-config 919deny ${HOME}/.yarn-config
920blacklist ${HOME}/.yarncache 920deny ${HOME}/.yarncache
921blacklist ${HOME}/.yarnrc 921deny ${HOME}/.yarnrc
922blacklist ${HOME}/.zoom 922deny ${HOME}/.zoom
923blacklist /tmp/akonadi-* 923deny /tmp/akonadi-*
924blacklist /tmp/.wine-* 924deny /tmp/.wine-*
925blacklist /var/games/nethack 925deny /var/games/nethack
926blacklist /var/games/slashem 926deny /var/games/slashem
927blacklist /var/games/vulturesclaw 927deny /var/games/vulturesclaw
928blacklist /var/games/vultureseye 928deny /var/games/vultureseye
929blacklist /var/lib/games/Maelstrom-Scores 929deny /var/lib/games/Maelstrom-Scores
930 930
931# ${HOME}/.cache directory 931# ${HOME}/.cache directory
932blacklist ${HOME}/.cache/0ad 932deny ${HOME}/.cache/0ad
933blacklist ${HOME}/.cache/8pecxstudios 933deny ${HOME}/.cache/8pecxstudios
934blacklist ${HOME}/.cache/Authenticator 934deny ${HOME}/.cache/Authenticator
935blacklist ${HOME}/.cache/BraveSoftware 935deny ${HOME}/.cache/BraveSoftware
936blacklist ${HOME}/.cache/Clementine 936deny ${HOME}/.cache/Clementine
937blacklist ${HOME}/.cache/ENCOM/Spectral 937deny ${HOME}/.cache/ENCOM/Spectral
938blacklist ${HOME}/.cache/Enox 938deny ${HOME}/.cache/Enox
939blacklist ${HOME}/.cache/Enpass 939deny ${HOME}/.cache/Enpass
940blacklist ${HOME}/.cache/Ferdi 940deny ${HOME}/.cache/Ferdi
941blacklist ${HOME}/.cache/Flavio Tordini 941deny ${HOME}/.cache/Flavio Tordini
942blacklist ${HOME}/.cache/Franz 942deny ${HOME}/.cache/Franz
943blacklist ${HOME}/.cache/INRIA 943deny ${HOME}/.cache/INRIA
944blacklist ${HOME}/.cache/MusicBrainz 944deny ${HOME}/.cache/MusicBrainz
945blacklist ${HOME}/.cache/NewsFlashGTK 945deny ${HOME}/.cache/NewsFlashGTK
946blacklist ${HOME}/.cache/Otter 946deny ${HOME}/.cache/Otter
947blacklist ${HOME}/.cache/PawelStolowski 947deny ${HOME}/.cache/PawelStolowski
948blacklist ${HOME}/.cache/Psi 948deny ${HOME}/.cache/Psi
949blacklist ${HOME}/.cache/QuiteRss 949deny ${HOME}/.cache/QuiteRss
950blacklist ${HOME}/.cache/quodlibet 950deny ${HOME}/.cache/quodlibet
951blacklist ${HOME}/.cache/Quotient/quaternion 951deny ${HOME}/.cache/Quotient/quaternion
952blacklist ${HOME}/.cache/Shortwave 952deny ${HOME}/.cache/Shortwave
953blacklist ${HOME}/.cache/Tox 953deny ${HOME}/.cache/Tox
954blacklist ${HOME}/.cache/Zeal 954deny ${HOME}/.cache/Zeal
955blacklist ${HOME}/.cache/agenda 955deny ${HOME}/.cache/agenda
956blacklist ${HOME}/.cache/akonadi* 956deny ${HOME}/.cache/akonadi*
957blacklist ${HOME}/.cache/atril 957deny ${HOME}/.cache/atril
958blacklist ${HOME}/.cache/attic 958deny ${HOME}/.cache/attic
959blacklist ${HOME}/.cache/babl 959deny ${HOME}/.cache/babl
960blacklist ${HOME}/.cache/bnox 960deny ${HOME}/.cache/bnox
961blacklist ${HOME}/.cache/borg 961deny ${HOME}/.cache/borg
962blacklist ${HOME}/.cache/calibre 962deny ${HOME}/.cache/calibre
963blacklist ${HOME}/.cache/cantata 963deny ${HOME}/.cache/cantata
964blacklist ${HOME}/.cache/champlain 964deny ${HOME}/.cache/champlain
965blacklist ${HOME}/.cache/chromium 965deny ${HOME}/.cache/chromium
966blacklist ${HOME}/.cache/chromium-dev 966deny ${HOME}/.cache/chromium-dev
967blacklist ${HOME}/.cache/cliqz 967deny ${HOME}/.cache/cliqz
968blacklist ${HOME}/.cache/com.github.johnfactotum.Foliate 968deny ${HOME}/.cache/com.github.johnfactotum.Foliate
969blacklist ${HOME}/.cache/darktable 969deny ${HOME}/.cache/darktable
970blacklist ${HOME}/.cache/deja-dup 970deny ${HOME}/.cache/deja-dup
971blacklist ${HOME}/.cache/discover 971deny ${HOME}/.cache/discover
972blacklist ${HOME}/.cache/dnox 972deny ${HOME}/.cache/dnox
973blacklist ${HOME}/.cache/dolphin 973deny ${HOME}/.cache/dolphin
974blacklist ${HOME}/.cache/dolphin-emu 974deny ${HOME}/.cache/dolphin-emu
975blacklist ${HOME}/.cache/ephemeral 975deny ${HOME}/.cache/ephemeral
976blacklist ${HOME}/.cache/epiphany 976deny ${HOME}/.cache/epiphany
977blacklist ${HOME}/.cache/evolution 977deny ${HOME}/.cache/evolution
978blacklist ${HOME}/.cache/falkon 978deny ${HOME}/.cache/falkon
979blacklist ${HOME}/.cache/feedreader 979deny ${HOME}/.cache/feedreader
980blacklist ${HOME}/.cache/firedragon 980deny ${HOME}/.cache/firedragon
981blacklist ${HOME}/.cache/flaska.net/trojita 981deny ${HOME}/.cache/flaska.net/trojita
982blacklist ${HOME}/.cache/folks 982deny ${HOME}/.cache/folks
983blacklist ${HOME}/.cache/font-manager 983deny ${HOME}/.cache/font-manager
984blacklist ${HOME}/.cache/fossamail 984deny ${HOME}/.cache/fossamail
985blacklist ${HOME}/.cache/fractal 985deny ${HOME}/.cache/fractal
986blacklist ${HOME}/.cache/freecol 986deny ${HOME}/.cache/freecol
987blacklist ${HOME}/.cache/gajim 987deny ${HOME}/.cache/gajim
988blacklist ${HOME}/.cache/geary 988deny ${HOME}/.cache/geary
989blacklist ${HOME}/.cache/gegl-0.4 989deny ${HOME}/.cache/gegl-0.4
990blacklist ${HOME}/.cache/geeqie 990deny ${HOME}/.cache/geeqie
991blacklist ${HOME}/.cache/gfeeds 991deny ${HOME}/.cache/gfeeds
992blacklist ${HOME}/.cache/gimp 992deny ${HOME}/.cache/gimp
993blacklist ${HOME}/.cache/gnome-boxes 993deny ${HOME}/.cache/gnome-boxes
994blacklist ${HOME}/.cache/gnome-builder 994deny ${HOME}/.cache/gnome-builder
995blacklist ${HOME}/.cache/gnome-control-center 995deny ${HOME}/.cache/gnome-control-center
996blacklist ${HOME}/.cache/gnome-recipes 996deny ${HOME}/.cache/gnome-recipes
997blacklist ${HOME}/.cache/gnome-screenshot 997deny ${HOME}/.cache/gnome-screenshot
998blacklist ${HOME}/.cache/gnome-software 998deny ${HOME}/.cache/gnome-software
999blacklist ${HOME}/.cache/gnome-twitch 999deny ${HOME}/.cache/gnome-twitch
1000blacklist ${HOME}/.cache/godot 1000deny ${HOME}/.cache/godot
1001blacklist ${HOME}/.cache/google-chrome 1001deny ${HOME}/.cache/google-chrome
1002blacklist ${HOME}/.cache/google-chrome-beta 1002deny ${HOME}/.cache/google-chrome-beta
1003blacklist ${HOME}/.cache/google-chrome-unstable 1003deny ${HOME}/.cache/google-chrome-unstable
1004blacklist ${HOME}/.cache/gradio 1004deny ${HOME}/.cache/gradio
1005blacklist ${HOME}/.cache/gummi 1005deny ${HOME}/.cache/gummi
1006blacklist ${HOME}/.cache/icedove 1006deny ${HOME}/.cache/icedove
1007blacklist ${HOME}/.cache/INRIA/Natron 1007deny ${HOME}/.cache/INRIA/Natron
1008blacklist ${HOME}/.cache/inkscape 1008deny ${HOME}/.cache/inkscape
1009blacklist ${HOME}/.cache/inox 1009deny ${HOME}/.cache/inox
1010blacklist ${HOME}/.cache/iridium 1010deny ${HOME}/.cache/iridium
1011blacklist ${HOME}/.cache/kcmshell5 1011deny ${HOME}/.cache/kcmshell5
1012blacklist ${HOME}/.cache/KDE/neochat 1012deny ${HOME}/.cache/KDE/neochat
1013blacklist ${HOME}/.cache/kdenlive 1013deny ${HOME}/.cache/kdenlive
1014blacklist ${HOME}/.cache/keepassxc 1014deny ${HOME}/.cache/keepassxc
1015blacklist ${HOME}/.cache/kfind 1015deny ${HOME}/.cache/kfind
1016blacklist ${HOME}/.cache/kinfocenter 1016deny ${HOME}/.cache/kinfocenter
1017blacklist ${HOME}/.cache/kmail2 1017deny ${HOME}/.cache/kmail2
1018blacklist ${HOME}/.cache/krunner 1018deny ${HOME}/.cache/krunner
1019blacklist ${HOME}/.cache/krunnerbookmarkrunnerfirefoxdbfile.sqlite* 1019deny ${HOME}/.cache/krunnerbookmarkrunnerfirefoxdbfile.sqlite*
1020blacklist ${HOME}/.cache/kscreenlocker_greet 1020deny ${HOME}/.cache/kscreenlocker_greet
1021blacklist ${HOME}/.cache/ksmserver-logout-greeter 1021deny ${HOME}/.cache/ksmserver-logout-greeter
1022blacklist ${HOME}/.cache/ksplashqml 1022deny ${HOME}/.cache/ksplashqml
1023blacklist ${HOME}/.cache/kube 1023deny ${HOME}/.cache/kube
1024blacklist ${HOME}/.cache/kwin 1024deny ${HOME}/.cache/kwin
1025blacklist ${HOME}/.cache/libgweather 1025deny ${HOME}/.cache/libgweather
1026blacklist ${HOME}/.cache/librewolf 1026deny ${HOME}/.cache/librewolf
1027blacklist ${HOME}/.cache/liferea 1027deny ${HOME}/.cache/liferea
1028blacklist ${HOME}/.cache/lutris 1028deny ${HOME}/.cache/lutris
1029blacklist ${HOME}/.cache/Mendeley Ltd. 1029deny ${HOME}/.cache/Mendeley Ltd.
1030blacklist ${HOME}/.cache/marker 1030deny ${HOME}/.cache/marker
1031blacklist ${HOME}/.cache/matrix-mirage 1031deny ${HOME}/.cache/matrix-mirage
1032blacklist ${HOME}/.cache/microsoft-edge-dev 1032deny ${HOME}/.cache/microsoft-edge-dev
1033blacklist ${HOME}/.cache/midori 1033deny ${HOME}/.cache/midori
1034blacklist ${HOME}/.cache/minetest 1034deny ${HOME}/.cache/minetest
1035blacklist ${HOME}/.cache/mirage 1035deny ${HOME}/.cache/mirage
1036blacklist ${HOME}/.cache/moonchild productions/basilisk 1036deny ${HOME}/.cache/moonchild productions/basilisk
1037blacklist ${HOME}/.cache/moonchild productions/pale moon 1037deny ${HOME}/.cache/moonchild productions/pale moon
1038blacklist ${HOME}/.cache/mozilla 1038deny ${HOME}/.cache/mozilla
1039blacklist ${HOME}/.cache/ms-excel-online 1039deny ${HOME}/.cache/ms-excel-online
1040blacklist ${HOME}/.cache/ms-office-online 1040deny ${HOME}/.cache/ms-office-online
1041blacklist ${HOME}/.cache/ms-onenote-online 1041deny ${HOME}/.cache/ms-onenote-online
1042blacklist ${HOME}/.cache/ms-outlook-online 1042deny ${HOME}/.cache/ms-outlook-online
1043blacklist ${HOME}/.cache/ms-powerpoint-online 1043deny ${HOME}/.cache/ms-powerpoint-online
1044blacklist ${HOME}/.cache/ms-skype-online 1044deny ${HOME}/.cache/ms-skype-online
1045blacklist ${HOME}/.cache/ms-word-online 1045deny ${HOME}/.cache/ms-word-online
1046blacklist ${HOME}/.cache/mutt 1046deny ${HOME}/.cache/mutt
1047blacklist ${HOME}/.cache/mypaint 1047deny ${HOME}/.cache/mypaint
1048blacklist ${HOME}/.cache/nheko 1048deny ${HOME}/.cache/nheko
1049blacklist ${HOME}/.cache/netsurf 1049deny ${HOME}/.cache/netsurf
1050blacklist ${HOME}/.cache/okular 1050deny ${HOME}/.cache/okular
1051blacklist ${HOME}/.cache/opera 1051deny ${HOME}/.cache/opera
1052blacklist ${HOME}/.cache/opera-beta 1052deny ${HOME}/.cache/opera-beta
1053blacklist ${HOME}/.cache/org.gabmus.gfeeds 1053deny ${HOME}/.cache/org.gabmus.gfeeds
1054blacklist ${HOME}/.cache/org.gnome.Books 1054deny ${HOME}/.cache/org.gnome.Books
1055blacklist ${HOME}/.cache/org.gnome.Maps 1055deny ${HOME}/.cache/org.gnome.Maps
1056blacklist ${HOME}/.cache/pdfmod 1056deny ${HOME}/.cache/pdfmod
1057blacklist ${HOME}/.cache/peek 1057deny ${HOME}/.cache/peek
1058blacklist ${HOME}/.cache/pip 1058deny ${HOME}/.cache/pip
1059blacklist ${HOME}/.cache/pipe-viewer 1059deny ${HOME}/.cache/pipe-viewer
1060blacklist ${HOME}/.cache/plasmashell 1060deny ${HOME}/.cache/plasmashell
1061blacklist ${HOME}/.cache/plasmashellbookmarkrunnerfirefoxdbfile.sqlite* 1061deny ${HOME}/.cache/plasmashellbookmarkrunnerfirefoxdbfile.sqlite*
1062blacklist ${HOME}/.cache/psi 1062deny ${HOME}/.cache/psi
1063blacklist ${HOME}/.cache/qBittorrent 1063deny ${HOME}/.cache/qBittorrent
1064blacklist ${HOME}/.cache/qupzilla 1064deny ${HOME}/.cache/qupzilla
1065blacklist ${HOME}/.cache/qutebrowser 1065deny ${HOME}/.cache/qutebrowser
1066blacklist ${HOME}/.cache/rhythmbox 1066deny ${HOME}/.cache/rhythmbox
1067blacklist ${HOME}/.cache/shotwell 1067deny ${HOME}/.cache/shotwell
1068blacklist ${HOME}/.cache/simple-scan 1068deny ${HOME}/.cache/simple-scan
1069blacklist ${HOME}/.cache/slimjet 1069deny ${HOME}/.cache/slimjet
1070blacklist ${HOME}/.cache/smuxi 1070deny ${HOME}/.cache/smuxi
1071blacklist ${HOME}/.cache/snox 1071deny ${HOME}/.cache/snox
1072blacklist ${HOME}/.cache/spotify 1072deny ${HOME}/.cache/spotify
1073blacklist ${HOME}/.cache/strawberry 1073deny ${HOME}/.cache/strawberry
1074blacklist ${HOME}/.cache/straw-viewer 1074deny ${HOME}/.cache/straw-viewer
1075blacklist ${HOME}/.cache/supertuxkart 1075deny ${HOME}/.cache/supertuxkart
1076blacklist ${HOME}/.cache/systemsettings 1076deny ${HOME}/.cache/systemsettings
1077blacklist ${HOME}/.cache/telepathy 1077deny ${HOME}/.cache/telepathy
1078blacklist ${HOME}/.cache/thunderbird 1078deny ${HOME}/.cache/thunderbird
1079blacklist ${HOME}/.cache/torbrowser 1079deny ${HOME}/.cache/torbrowser
1080blacklist ${HOME}/.cache/transmission 1080deny ${HOME}/.cache/transmission
1081blacklist ${HOME}/.cache/ungoogled-chromium 1081deny ${HOME}/.cache/ungoogled-chromium
1082blacklist ${HOME}/.cache/vivaldi 1082deny ${HOME}/.cache/vivaldi
1083blacklist ${HOME}/.cache/vivaldi-snapshot 1083deny ${HOME}/.cache/vivaldi-snapshot
1084blacklist ${HOME}/.cache/vlc 1084deny ${HOME}/.cache/vlc
1085blacklist ${HOME}/.cache/vmware 1085deny ${HOME}/.cache/vmware
1086blacklist ${HOME}/.cache/warsow-2.1 1086deny ${HOME}/.cache/warsow-2.1
1087blacklist ${HOME}/.cache/waterfox 1087deny ${HOME}/.cache/waterfox
1088blacklist ${HOME}/.cache/wesnoth 1088deny ${HOME}/.cache/wesnoth
1089blacklist ${HOME}/.cache/winetricks 1089deny ${HOME}/.cache/winetricks
1090blacklist ${HOME}/.cache/xmms2 1090deny ${HOME}/.cache/xmms2
1091blacklist ${HOME}/.cache/xreader 1091deny ${HOME}/.cache/xreader
1092blacklist ${HOME}/.cache/yandex-browser 1092deny ${HOME}/.cache/yandex-browser
1093blacklist ${HOME}/.cache/yandex-browser-beta 1093deny ${HOME}/.cache/yandex-browser-beta
1094blacklist ${HOME}/.cache/youtube-dl 1094deny ${HOME}/.cache/youtube-dl
1095blacklist ${HOME}/.cache/youtube-viewer 1095deny ${HOME}/.cache/youtube-viewer
diff --git a/etc/inc/disable-shell.inc b/etc/inc/disable-shell.inc
index 8274b0215..da6fb31a3 100644
--- a/etc/inc/disable-shell.inc
+++ b/etc/inc/disable-shell.inc
@@ -2,14 +2,14 @@
2# Persistent customizations should go in a .local file. 2# Persistent customizations should go in a .local file.
3include disable-shell.local 3include disable-shell.local
4 4
5blacklist ${PATH}/bash 5deny ${PATH}/bash
6blacklist ${PATH}/csh 6deny ${PATH}/csh
7blacklist ${PATH}/dash 7deny ${PATH}/dash
8blacklist ${PATH}/fish 8deny ${PATH}/fish
9blacklist ${PATH}/ksh 9deny ${PATH}/ksh
10blacklist ${PATH}/mksh 10deny ${PATH}/mksh
11blacklist ${PATH}/oksh 11deny ${PATH}/oksh
12blacklist ${PATH}/sh 12deny ${PATH}/sh
13blacklist ${PATH}/tclsh 13deny ${PATH}/tclsh
14blacklist ${PATH}/tcsh 14deny ${PATH}/tcsh
15blacklist ${PATH}/zsh 15deny ${PATH}/zsh
diff --git a/etc/inc/disable-xdg.inc b/etc/inc/disable-xdg.inc
index 22acf272d..32aa8c7f6 100644
--- a/etc/inc/disable-xdg.inc
+++ b/etc/inc/disable-xdg.inc
@@ -2,10 +2,10 @@
2# Persistent customizations should go in a .local file. 2# Persistent customizations should go in a .local file.
3include disable-xdg.local 3include disable-xdg.local
4 4
5blacklist ${DOCUMENTS} 5deny ${DOCUMENTS}
6blacklist ${MUSIC} 6deny ${MUSIC}
7blacklist ${PICTURES} 7deny ${PICTURES}
8blacklist ${VIDEOS} 8deny ${VIDEOS}
9 9
10# The following should be considered catch-all directories 10# The following should be considered catch-all directories
11#blacklist ${DESKTOP} 11#blacklist ${DESKTOP}
diff --git a/etc/inc/whitelist-1793-workaround.inc b/etc/inc/whitelist-1793-workaround.inc
index 862837f12..06a424440 100644
--- a/etc/inc/whitelist-1793-workaround.inc
+++ b/etc/inc/whitelist-1793-workaround.inc
@@ -3,27 +3,27 @@
3include whitelist-1793-workaround.local 3include whitelist-1793-workaround.local
4# This works around bug 1793, and allows whitelisting to be used for some KDE applications. 4# This works around bug 1793, and allows whitelisting to be used for some KDE applications.
5 5
6noblacklist ${HOME}/.config/ibus 6nodeny ${HOME}/.config/ibus
7noblacklist ${HOME}/.config/mimeapps.list 7nodeny ${HOME}/.config/mimeapps.list
8noblacklist ${HOME}/.config/pkcs11 8nodeny ${HOME}/.config/pkcs11
9noblacklist ${HOME}/.config/user-dirs.dirs 9nodeny ${HOME}/.config/user-dirs.dirs
10noblacklist ${HOME}/.config/user-dirs.locale 10nodeny ${HOME}/.config/user-dirs.locale
11noblacklist ${HOME}/.config/dconf 11nodeny ${HOME}/.config/dconf
12noblacklist ${HOME}/.config/fontconfig 12nodeny ${HOME}/.config/fontconfig
13noblacklist ${HOME}/.config/gtk-2.0 13nodeny ${HOME}/.config/gtk-2.0
14noblacklist ${HOME}/.config/gtk-3.0 14nodeny ${HOME}/.config/gtk-3.0
15noblacklist ${HOME}/.config/gtk-4.0 15nodeny ${HOME}/.config/gtk-4.0
16noblacklist ${HOME}/.config/gtkrc 16nodeny ${HOME}/.config/gtkrc
17noblacklist ${HOME}/.config/gtkrc-2.0 17nodeny ${HOME}/.config/gtkrc-2.0
18noblacklist ${HOME}/.config/Kvantum 18nodeny ${HOME}/.config/Kvantum
19noblacklist ${HOME}/.config/Trolltech.conf 19nodeny ${HOME}/.config/Trolltech.conf
20noblacklist ${HOME}/.config/QtProject.conf 20nodeny ${HOME}/.config/QtProject.conf
21noblacklist ${HOME}/.config/kdeglobals 21nodeny ${HOME}/.config/kdeglobals
22noblacklist ${HOME}/.config/kio_httprc 22nodeny ${HOME}/.config/kio_httprc
23noblacklist ${HOME}/.config/kioslaverc 23nodeny ${HOME}/.config/kioslaverc
24noblacklist ${HOME}/.config/ksslcablacklist 24nodeny ${HOME}/.config/ksslcablacklist
25noblacklist ${HOME}/.config/qt5ct 25nodeny ${HOME}/.config/qt5ct
26noblacklist ${HOME}/.config/qtcurve 26nodeny ${HOME}/.config/qtcurve
27 27
28blacklist ${HOME}/.config/* 28deny ${HOME}/.config/*
29whitelist ${HOME}/.config 29allow ${HOME}/.config
diff --git a/etc/inc/whitelist-common.inc b/etc/inc/whitelist-common.inc
index fedfb2bc2..11070e372 100644
--- a/etc/inc/whitelist-common.inc
+++ b/etc/inc/whitelist-common.inc
@@ -4,82 +4,82 @@ include whitelist-common.local
4 4
5# common whitelist for all profiles 5# common whitelist for all profiles
6 6
7whitelist ${HOME}/.XCompose 7allow ${HOME}/.XCompose
8whitelist ${HOME}/.alsaequal.bin 8allow ${HOME}/.alsaequal.bin
9whitelist ${HOME}/.asoundrc 9allow ${HOME}/.asoundrc
10whitelist ${HOME}/.config/ibus 10allow ${HOME}/.config/ibus
11whitelist ${HOME}/.config/mimeapps.list 11allow ${HOME}/.config/mimeapps.list
12whitelist ${HOME}/.config/pkcs11 12allow ${HOME}/.config/pkcs11
13read-only ${HOME}/.config/pkcs11 13read-only ${HOME}/.config/pkcs11
14whitelist ${HOME}/.config/user-dirs.dirs 14allow ${HOME}/.config/user-dirs.dirs
15read-only ${HOME}/.config/user-dirs.dirs 15read-only ${HOME}/.config/user-dirs.dirs
16whitelist ${HOME}/.config/user-dirs.locale 16allow ${HOME}/.config/user-dirs.locale
17read-only ${HOME}/.config/user-dirs.locale 17read-only ${HOME}/.config/user-dirs.locale
18whitelist ${HOME}/.drirc 18allow ${HOME}/.drirc
19whitelist ${HOME}/.icons 19allow ${HOME}/.icons
20?HAS_APPIMAGE: whitelist ${HOME}/.local/share/appimagekit 20?HAS_APPIMAGE: whitelist ${HOME}/.local/share/appimagekit
21whitelist ${HOME}/.local/share/applications 21allow ${HOME}/.local/share/applications
22read-only ${HOME}/.local/share/applications 22read-only ${HOME}/.local/share/applications
23whitelist ${HOME}/.local/share/icons 23allow ${HOME}/.local/share/icons
24whitelist ${HOME}/.local/share/mime 24allow ${HOME}/.local/share/mime
25whitelist ${HOME}/.mime.types 25allow ${HOME}/.mime.types
26whitelist ${HOME}/.sndio/cookie 26allow ${HOME}/.sndio/cookie
27whitelist ${HOME}/.uim.d 27allow ${HOME}/.uim.d
28 28
29# dconf 29# dconf
30mkdir ${HOME}/.config/dconf 30mkdir ${HOME}/.config/dconf
31whitelist ${HOME}/.config/dconf 31allow ${HOME}/.config/dconf
32 32
33# fonts 33# fonts
34whitelist ${HOME}/.cache/fontconfig 34allow ${HOME}/.cache/fontconfig
35whitelist ${HOME}/.config/fontconfig 35allow ${HOME}/.config/fontconfig
36whitelist ${HOME}/.fontconfig 36allow ${HOME}/.fontconfig
37whitelist ${HOME}/.fonts 37allow ${HOME}/.fonts
38whitelist ${HOME}/.fonts.conf 38allow ${HOME}/.fonts.conf
39whitelist ${HOME}/.fonts.conf.d 39allow ${HOME}/.fonts.conf.d
40whitelist ${HOME}/.fonts.d 40allow ${HOME}/.fonts.d
41whitelist ${HOME}/.local/share/fonts 41allow ${HOME}/.local/share/fonts
42whitelist ${HOME}/.pangorc 42allow ${HOME}/.pangorc
43 43
44# gtk 44# gtk
45whitelist ${HOME}/.config/gtk-2.0 45allow ${HOME}/.config/gtk-2.0
46whitelist ${HOME}/.config/gtk-3.0 46allow ${HOME}/.config/gtk-3.0
47whitelist ${HOME}/.config/gtk-4.0 47allow ${HOME}/.config/gtk-4.0
48whitelist ${HOME}/.config/gtkrc 48allow ${HOME}/.config/gtkrc
49whitelist ${HOME}/.config/gtkrc-2.0 49allow ${HOME}/.config/gtkrc-2.0
50whitelist ${HOME}/.gnome2 50allow ${HOME}/.gnome2
51whitelist ${HOME}/.gnome2-private 51allow ${HOME}/.gnome2-private
52whitelist ${HOME}/.gtk-2.0 52allow ${HOME}/.gtk-2.0
53whitelist ${HOME}/.gtkrc 53allow ${HOME}/.gtkrc
54whitelist ${HOME}/.gtkrc-2.0 54allow ${HOME}/.gtkrc-2.0
55whitelist ${HOME}/.kde/share/config/gtkrc 55allow ${HOME}/.kde/share/config/gtkrc
56whitelist ${HOME}/.kde/share/config/gtkrc-2.0 56allow ${HOME}/.kde/share/config/gtkrc-2.0
57whitelist ${HOME}/.kde4/share/config/gtkrc 57allow ${HOME}/.kde4/share/config/gtkrc
58whitelist ${HOME}/.kde4/share/config/gtkrc-2.0 58allow ${HOME}/.kde4/share/config/gtkrc-2.0
59whitelist ${HOME}/.local/share/themes 59allow ${HOME}/.local/share/themes
60whitelist ${HOME}/.themes 60allow ${HOME}/.themes
61 61
62# qt/kde 62# qt/kde
63whitelist ${HOME}/.cache/kioexec/krun 63allow ${HOME}/.cache/kioexec/krun
64whitelist ${HOME}/.config/Kvantum 64allow ${HOME}/.config/Kvantum
65whitelist ${HOME}/.config/Trolltech.conf 65allow ${HOME}/.config/Trolltech.conf
66whitelist ${HOME}/.config/QtProject.conf 66allow ${HOME}/.config/QtProject.conf
67whitelist ${HOME}/.config/kdeglobals 67allow ${HOME}/.config/kdeglobals
68whitelist ${HOME}/.config/kio_httprc 68allow ${HOME}/.config/kio_httprc
69whitelist ${HOME}/.config/kioslaverc 69allow ${HOME}/.config/kioslaverc
70whitelist ${HOME}/.config/ksslcablacklist 70allow ${HOME}/.config/ksslcablacklist
71whitelist ${HOME}/.config/qt5ct 71allow ${HOME}/.config/qt5ct
72whitelist ${HOME}/.config/qtcurve 72allow ${HOME}/.config/qtcurve
73whitelist ${HOME}/.kde/share/config/kdeglobals 73allow ${HOME}/.kde/share/config/kdeglobals
74whitelist ${HOME}/.kde/share/config/kio_httprc 74allow ${HOME}/.kde/share/config/kio_httprc
75whitelist ${HOME}/.kde/share/config/kioslaverc 75allow ${HOME}/.kde/share/config/kioslaverc
76whitelist ${HOME}/.kde/share/config/ksslcablacklist 76allow ${HOME}/.kde/share/config/ksslcablacklist
77whitelist ${HOME}/.kde/share/config/oxygenrc 77allow ${HOME}/.kde/share/config/oxygenrc
78whitelist ${HOME}/.kde/share/icons 78allow ${HOME}/.kde/share/icons
79whitelist ${HOME}/.kde4/share/config/kdeglobals 79allow ${HOME}/.kde4/share/config/kdeglobals
80whitelist ${HOME}/.kde4/share/config/kio_httprc 80allow ${HOME}/.kde4/share/config/kio_httprc
81whitelist ${HOME}/.kde4/share/config/kioslaverc 81allow ${HOME}/.kde4/share/config/kioslaverc
82whitelist ${HOME}/.kde4/share/config/ksslcablacklist 82allow ${HOME}/.kde4/share/config/ksslcablacklist
83whitelist ${HOME}/.kde4/share/config/oxygenrc 83allow ${HOME}/.kde4/share/config/oxygenrc
84whitelist ${HOME}/.kde4/share/icons 84allow ${HOME}/.kde4/share/icons
85whitelist ${HOME}/.local/share/qt5ct 85allow ${HOME}/.local/share/qt5ct
diff --git a/etc/inc/whitelist-player-common.inc b/etc/inc/whitelist-player-common.inc
index e5bf36804..d6ae8eab6 100644
--- a/etc/inc/whitelist-player-common.inc
+++ b/etc/inc/whitelist-player-common.inc
@@ -4,8 +4,8 @@ include whitelist-player-common.local
4 4
5# common whitelist for all media players 5# common whitelist for all media players
6 6
7whitelist ${DESKTOP} 7allow ${DESKTOP}
8whitelist ${DOWNLOADS} 8allow ${DOWNLOADS}
9whitelist ${MUSIC} 9allow ${MUSIC}
10whitelist ${PICTURES} 10allow ${PICTURES}
11whitelist ${VIDEOS} 11allow ${VIDEOS}
diff --git a/etc/inc/whitelist-runuser-common.inc b/etc/inc/whitelist-runuser-common.inc
index 48309ffe3..86e5264b9 100644
--- a/etc/inc/whitelist-runuser-common.inc
+++ b/etc/inc/whitelist-runuser-common.inc
@@ -4,13 +4,13 @@ include whitelist-runuser-common.local
4 4
5# common ${RUNUSER} (=/run/user/$UID) whitelist for all profiles 5# common ${RUNUSER} (=/run/user/$UID) whitelist for all profiles
6 6
7whitelist ${RUNUSER}/bus 7allow ${RUNUSER}/bus
8whitelist ${RUNUSER}/dconf 8allow ${RUNUSER}/dconf
9whitelist ${RUNUSER}/gdm/Xauthority 9allow ${RUNUSER}/gdm/Xauthority
10whitelist ${RUNUSER}/ICEauthority 10allow ${RUNUSER}/ICEauthority
11whitelist ${RUNUSER}/.mutter-Xwaylandauth.* 11allow ${RUNUSER}/.mutter-Xwaylandauth.*
12whitelist ${RUNUSER}/pulse/native 12allow ${RUNUSER}/pulse/native
13whitelist ${RUNUSER}/wayland-0 13allow ${RUNUSER}/wayland-0
14whitelist ${RUNUSER}/wayland-1 14allow ${RUNUSER}/wayland-1
15whitelist ${RUNUSER}/xauth_* 15allow ${RUNUSER}/xauth_*
16whitelist ${RUNUSER}/[[:xdigit:]][[:xdigit:]][[:xdigit:]][[:xdigit:]][[:xdigit:]][[:xdigit:]][[:xdigit:]][[:xdigit:]]-[[:xdigit:]][[:xdigit:]][[:xdigit:]][[:xdigit:]]-[[:xdigit:]][[:xdigit:]][[:xdigit:]][[:xdigit:]]-[[:xdigit:]][[:xdigit:]][[:xdigit:]][[:xdigit:]]-[[:xdigit:]][[:xdigit:]][[:xdigit:]][[:xdigit:]][[:xdigit:]][[:xdigit:]][[:xdigit:]][[:xdigit:]][[:xdigit:]][[:xdigit:]][[:xdigit:]][[:xdigit:]] 16allow ${RUNUSER}/[[:xdigit:]][[:xdigit:]][[:xdigit:]][[:xdigit:]][[:xdigit:]][[:xdigit:]][[:xdigit:]][[:xdigit:]]-[[:xdigit:]][[:xdigit:]][[:xdigit:]][[:xdigit:]]-[[:xdigit:]][[:xdigit:]][[:xdigit:]][[:xdigit:]]-[[:xdigit:]][[:xdigit:]][[:xdigit:]][[:xdigit:]]-[[:xdigit:]][[:xdigit:]][[:xdigit:]][[:xdigit:]][[:xdigit:]][[:xdigit:]][[:xdigit:]][[:xdigit:]][[:xdigit:]][[:xdigit:]][[:xdigit:]][[:xdigit:]]
diff --git a/etc/inc/whitelist-usr-share-common.inc b/etc/inc/whitelist-usr-share-common.inc
index fe0097934..64296da15 100644
--- a/etc/inc/whitelist-usr-share-common.inc
+++ b/etc/inc/whitelist-usr-share-common.inc
@@ -4,66 +4,66 @@ include whitelist-usr-share-common.local
4 4
5# common /usr/share whitelist for all profiles 5# common /usr/share whitelist for all profiles
6 6
7whitelist /usr/share/alsa 7allow /usr/share/alsa
8whitelist /usr/share/applications 8allow /usr/share/applications
9whitelist /usr/share/ca-certificates 9allow /usr/share/ca-certificates
10whitelist /usr/share/crypto-policies 10allow /usr/share/crypto-policies
11whitelist /usr/share/cursors 11allow /usr/share/cursors
12whitelist /usr/share/dconf 12allow /usr/share/dconf
13whitelist /usr/share/distro-info 13allow /usr/share/distro-info
14whitelist /usr/share/drirc.d 14allow /usr/share/drirc.d
15whitelist /usr/share/enchant 15allow /usr/share/enchant
16whitelist /usr/share/enchant-2 16allow /usr/share/enchant-2
17whitelist /usr/share/file 17allow /usr/share/file
18whitelist /usr/share/fontconfig 18allow /usr/share/fontconfig
19whitelist /usr/share/fonts 19allow /usr/share/fonts
20whitelist /usr/share/fonts-config 20allow /usr/share/fonts-config
21whitelist /usr/share/gir-1.0 21allow /usr/share/gir-1.0
22whitelist /usr/share/gjs-1.0 22allow /usr/share/gjs-1.0
23whitelist /usr/share/glib-2.0 23allow /usr/share/glib-2.0
24whitelist /usr/share/glvnd 24allow /usr/share/glvnd
25whitelist /usr/share/gtk-2.0 25allow /usr/share/gtk-2.0
26whitelist /usr/share/gtk-3.0 26allow /usr/share/gtk-3.0
27whitelist /usr/share/gtk-engines 27allow /usr/share/gtk-engines
28whitelist /usr/share/gtksourceview-3.0 28allow /usr/share/gtksourceview-3.0
29whitelist /usr/share/gtksourceview-4 29allow /usr/share/gtksourceview-4
30whitelist /usr/share/hunspell 30allow /usr/share/hunspell
31whitelist /usr/share/hwdata 31allow /usr/share/hwdata
32whitelist /usr/share/icons 32allow /usr/share/icons
33whitelist /usr/share/icu 33allow /usr/share/icu
34whitelist /usr/share/knotifications5 34allow /usr/share/knotifications5
35whitelist /usr/share/kservices5 35allow /usr/share/kservices5
36whitelist /usr/share/Kvantum 36allow /usr/share/Kvantum
37whitelist /usr/share/kxmlgui5 37allow /usr/share/kxmlgui5
38whitelist /usr/share/libdrm 38allow /usr/share/libdrm
39whitelist /usr/share/libthai 39allow /usr/share/libthai
40whitelist /usr/share/locale 40allow /usr/share/locale
41whitelist /usr/share/mime 41allow /usr/share/mime
42whitelist /usr/share/misc 42allow /usr/share/misc
43whitelist /usr/share/Modules 43allow /usr/share/Modules
44whitelist /usr/share/myspell 44allow /usr/share/myspell
45whitelist /usr/share/p11-kit 45allow /usr/share/p11-kit
46whitelist /usr/share/perl 46allow /usr/share/perl
47whitelist /usr/share/perl5 47allow /usr/share/perl5
48whitelist /usr/share/pixmaps 48allow /usr/share/pixmaps
49whitelist /usr/share/pki 49allow /usr/share/pki
50whitelist /usr/share/plasma 50allow /usr/share/plasma
51whitelist /usr/share/publicsuffix 51allow /usr/share/publicsuffix
52whitelist /usr/share/qt 52allow /usr/share/qt
53whitelist /usr/share/qt4 53allow /usr/share/qt4
54whitelist /usr/share/qt5 54allow /usr/share/qt5
55whitelist /usr/share/qt5ct 55allow /usr/share/qt5ct
56whitelist /usr/share/sounds 56allow /usr/share/sounds
57whitelist /usr/share/tcl8.6 57allow /usr/share/tcl8.6
58whitelist /usr/share/tcltk 58allow /usr/share/tcltk
59whitelist /usr/share/terminfo 59allow /usr/share/terminfo
60whitelist /usr/share/texlive 60allow /usr/share/texlive
61whitelist /usr/share/texmf 61allow /usr/share/texmf
62whitelist /usr/share/themes 62allow /usr/share/themes
63whitelist /usr/share/thumbnail.so 63allow /usr/share/thumbnail.so
64whitelist /usr/share/uim 64allow /usr/share/uim
65whitelist /usr/share/vulkan 65allow /usr/share/vulkan
66whitelist /usr/share/X11 66allow /usr/share/X11
67whitelist /usr/share/xml 67allow /usr/share/xml
68whitelist /usr/share/zenity 68allow /usr/share/zenity
69whitelist /usr/share/zoneinfo 69allow /usr/share/zoneinfo
diff --git a/etc/inc/whitelist-var-common.inc b/etc/inc/whitelist-var-common.inc
index d8ba84ad0..c449e8905 100644
--- a/etc/inc/whitelist-var-common.inc
+++ b/etc/inc/whitelist-var-common.inc
@@ -4,12 +4,12 @@ include whitelist-var-common.local
4 4
5# common /var whitelist for all profiles 5# common /var whitelist for all profiles
6 6
7whitelist /var/lib/aspell 7allow /var/lib/aspell
8whitelist /var/lib/ca-certificates 8allow /var/lib/ca-certificates
9whitelist /var/lib/dbus 9allow /var/lib/dbus
10whitelist /var/lib/menu-xdg 10allow /var/lib/menu-xdg
11whitelist /var/lib/uim 11allow /var/lib/uim
12whitelist /var/cache/fontconfig 12allow /var/cache/fontconfig
13whitelist /var/tmp 13allow /var/tmp
14whitelist /var/run 14allow /var/run
15whitelist /var/lock 15allow /var/lock
diff --git a/etc/profile-a-l/0ad.profile b/etc/profile-a-l/0ad.profile
index 4009853d3..6f493fff1 100644
--- a/etc/profile-a-l/0ad.profile
+++ b/etc/profile-a-l/0ad.profile
@@ -6,11 +6,11 @@ include 0ad.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.cache/0ad 9nodeny ${HOME}/.cache/0ad
10noblacklist ${HOME}/.config/0ad 10nodeny ${HOME}/.config/0ad
11noblacklist ${HOME}/.local/share/0ad 11nodeny ${HOME}/.local/share/0ad
12 12
13blacklist /usr/libexec 13deny /usr/libexec
14 14
15include disable-common.inc 15include disable-common.inc
16include disable-devel.inc 16include disable-devel.inc
@@ -23,11 +23,11 @@ include disable-xdg.inc
23mkdir ${HOME}/.cache/0ad 23mkdir ${HOME}/.cache/0ad
24mkdir ${HOME}/.config/0ad 24mkdir ${HOME}/.config/0ad
25mkdir ${HOME}/.local/share/0ad 25mkdir ${HOME}/.local/share/0ad
26whitelist ${HOME}/.cache/0ad 26allow ${HOME}/.cache/0ad
27whitelist ${HOME}/.config/0ad 27allow ${HOME}/.config/0ad
28whitelist ${HOME}/.local/share/0ad 28allow ${HOME}/.local/share/0ad
29whitelist /usr/share/0ad 29allow /usr/share/0ad
30whitelist /usr/share/games 30allow /usr/share/games
31include whitelist-common.inc 31include whitelist-common.inc
32include whitelist-usr-share-common.inc 32include whitelist-usr-share-common.inc
33include whitelist-var-common.inc 33include whitelist-var-common.inc
diff --git a/etc/profile-a-l/2048-qt.profile b/etc/profile-a-l/2048-qt.profile
index 1d787cba7..3a7b331a7 100644
--- a/etc/profile-a-l/2048-qt.profile
+++ b/etc/profile-a-l/2048-qt.profile
@@ -6,8 +6,8 @@ include 2048-qt.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/2048-qt 9nodeny ${HOME}/.config/2048-qt
10noblacklist ${HOME}/.config/xiaoyong 10nodeny ${HOME}/.config/xiaoyong
11 11
12include disable-common.inc 12include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
@@ -18,8 +18,8 @@ include disable-programs.inc
18 18
19mkdir ${HOME}/.config/2048-qt 19mkdir ${HOME}/.config/2048-qt
20mkdir ${HOME}/.config/xiaoyong 20mkdir ${HOME}/.config/xiaoyong
21whitelist ${HOME}/.config/2048-qt 21allow ${HOME}/.config/2048-qt
22whitelist ${HOME}/.config/xiaoyong 22allow ${HOME}/.config/xiaoyong
23include whitelist-common.inc 23include whitelist-common.inc
24include whitelist-var-common.inc 24include whitelist-var-common.inc
25 25
diff --git a/etc/profile-a-l/Cryptocat.profile b/etc/profile-a-l/Cryptocat.profile
index 1d86b0fbf..def0ec111 100644
--- a/etc/profile-a-l/Cryptocat.profile
+++ b/etc/profile-a-l/Cryptocat.profile
@@ -5,7 +5,7 @@ include Cryptocat.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${HOME}/.config/Cryptocat 8nodeny ${HOME}/.config/Cryptocat
9 9
10include disable-common.inc 10include disable-common.inc
11include disable-devel.inc 11include disable-devel.inc
diff --git a/etc/profile-a-l/Discord.profile b/etc/profile-a-l/Discord.profile
index 3f274b21c..1d3ae49ca 100644
--- a/etc/profile-a-l/Discord.profile
+++ b/etc/profile-a-l/Discord.profile
@@ -5,10 +5,10 @@ include Discord.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${HOME}/.config/discord 8nodeny ${HOME}/.config/discord
9 9
10mkdir ${HOME}/.config/discord 10mkdir ${HOME}/.config/discord
11whitelist ${HOME}/.config/discord 11allow ${HOME}/.config/discord
12 12
13private-bin Discord 13private-bin Discord
14private-opt Discord 14private-opt Discord
diff --git a/etc/profile-a-l/DiscordCanary.profile b/etc/profile-a-l/DiscordCanary.profile
index d24e73ed8..3c85f187b 100644
--- a/etc/profile-a-l/DiscordCanary.profile
+++ b/etc/profile-a-l/DiscordCanary.profile
@@ -5,10 +5,10 @@ include DiscordCanary.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${HOME}/.config/discordcanary 8nodeny ${HOME}/.config/discordcanary
9 9
10mkdir ${HOME}/.config/discordcanary 10mkdir ${HOME}/.config/discordcanary
11whitelist ${HOME}/.config/discordcanary 11allow ${HOME}/.config/discordcanary
12 12
13private-bin DiscordCanary 13private-bin DiscordCanary
14private-opt DiscordCanary 14private-opt DiscordCanary
diff --git a/etc/profile-a-l/Fritzing.profile b/etc/profile-a-l/Fritzing.profile
index 7dc6b5ff0..8f746581f 100644
--- a/etc/profile-a-l/Fritzing.profile
+++ b/etc/profile-a-l/Fritzing.profile
@@ -6,8 +6,8 @@ include Fritzing.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/Fritzing 9nodeny ${HOME}/.config/Fritzing
10noblacklist ${DOCUMENTS} 10nodeny ${DOCUMENTS}
11 11
12include disable-common.inc 12include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
diff --git a/etc/profile-a-l/JDownloader.profile b/etc/profile-a-l/JDownloader.profile
index d10b70796..9a00c3230 100644
--- a/etc/profile-a-l/JDownloader.profile
+++ b/etc/profile-a-l/JDownloader.profile
@@ -5,7 +5,7 @@ include JDownloader.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${HOME}/.jd 8nodeny ${HOME}/.jd
9 9
10# Allow java (blacklisted by disable-devel.inc) 10# Allow java (blacklisted by disable-devel.inc)
11include allow-java.inc 11include allow-java.inc
@@ -19,8 +19,8 @@ include disable-programs.inc
19include disable-xdg.inc 19include disable-xdg.inc
20 20
21mkdir ${HOME}/.jd 21mkdir ${HOME}/.jd
22whitelist ${HOME}/.jd 22allow ${HOME}/.jd
23whitelist ${DOWNLOADS} 23allow ${DOWNLOADS}
24include whitelist-common.inc 24include whitelist-common.inc
25include whitelist-var-common.inc 25include whitelist-var-common.inc
26 26
diff --git a/etc/profile-a-l/abiword.profile b/etc/profile-a-l/abiword.profile
index 75da9a956..2a92c7db4 100644
--- a/etc/profile-a-l/abiword.profile
+++ b/etc/profile-a-l/abiword.profile
@@ -6,7 +6,7 @@ include abiword.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/abiword 9nodeny ${HOME}/.config/abiword
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -16,7 +16,7 @@ include disable-passwdmgr.inc
16include disable-programs.inc 16include disable-programs.inc
17include disable-shell.inc 17include disable-shell.inc
18 18
19whitelist /usr/share/abiword-3.0 19allow /usr/share/abiword-3.0
20include whitelist-usr-share-common.inc 20include whitelist-usr-share-common.inc
21include whitelist-runuser-common.inc 21include whitelist-runuser-common.inc
22include whitelist-var-common.inc 22include whitelist-var-common.inc
diff --git a/etc/profile-a-l/abrowser.profile b/etc/profile-a-l/abrowser.profile
index 2e6e8f1af..70ddcec20 100644
--- a/etc/profile-a-l/abrowser.profile
+++ b/etc/profile-a-l/abrowser.profile
@@ -5,13 +5,13 @@ include abrowser.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${HOME}/.cache/mozilla 8nodeny ${HOME}/.cache/mozilla
9noblacklist ${HOME}/.mozilla 9nodeny ${HOME}/.mozilla
10 10
11mkdir ${HOME}/.cache/mozilla/abrowser 11mkdir ${HOME}/.cache/mozilla/abrowser
12mkdir ${HOME}/.mozilla 12mkdir ${HOME}/.mozilla
13whitelist ${HOME}/.cache/mozilla/abrowser 13allow ${HOME}/.cache/mozilla/abrowser
14whitelist ${HOME}/.mozilla 14allow ${HOME}/.mozilla
15 15
16# private-etc must first be enabled in firefox-common.profile 16# private-etc must first be enabled in firefox-common.profile
17#private-etc abrowser 17#private-etc abrowser
diff --git a/etc/profile-a-l/agetpkg.profile b/etc/profile-a-l/agetpkg.profile
index 34f59769e..d32586c5b 100644
--- a/etc/profile-a-l/agetpkg.profile
+++ b/etc/profile-a-l/agetpkg.profile
@@ -7,8 +7,8 @@ include agetpkg.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10blacklist /tmp/.X11-unix 10deny /tmp/.X11-unix
11blacklist ${RUNUSER}/wayland-* 11deny ${RUNUSER}/wayland-*
12 12
13# Allow python (blacklisted by disable-interpreters.inc) 13# Allow python (blacklisted by disable-interpreters.inc)
14#include allow-python2.inc 14#include allow-python2.inc
@@ -23,7 +23,7 @@ include disable-programs.inc
23include disable-shell.inc 23include disable-shell.inc
24include disable-xdg.inc 24include disable-xdg.inc
25 25
26whitelist ${DOWNLOADS} 26allow ${DOWNLOADS}
27include whitelist-common.inc 27include whitelist-common.inc
28include whitelist-usr-share-common.inc 28include whitelist-usr-share-common.inc
29include whitelist-var-common.inc 29include whitelist-var-common.inc
diff --git a/etc/profile-a-l/akonadi_control.profile b/etc/profile-a-l/akonadi_control.profile
index 37fdb38b5..7b1d1445f 100644
--- a/etc/profile-a-l/akonadi_control.profile
+++ b/etc/profile-a-l/akonadi_control.profile
@@ -4,22 +4,22 @@ include akonadi_control.local
4# Persistent global definitions 4# Persistent global definitions
5include globals.local 5include globals.local
6 6
7noblacklist ${HOME}/.cache/akonadi* 7nodeny ${HOME}/.cache/akonadi*
8noblacklist ${HOME}/.config/akonadi* 8nodeny ${HOME}/.config/akonadi*
9noblacklist ${HOME}/.config/baloorc 9nodeny ${HOME}/.config/baloorc
10noblacklist ${HOME}/.config/emaildefaults 10nodeny ${HOME}/.config/emaildefaults
11noblacklist ${HOME}/.config/emailidentities 11nodeny ${HOME}/.config/emailidentities
12noblacklist ${HOME}/.config/kmail2rc 12nodeny ${HOME}/.config/kmail2rc
13noblacklist ${HOME}/.config/mailtransports 13nodeny ${HOME}/.config/mailtransports
14noblacklist ${HOME}/.config/specialmailcollectionsrc 14nodeny ${HOME}/.config/specialmailcollectionsrc
15noblacklist ${HOME}/.local/share/akonadi* 15nodeny ${HOME}/.local/share/akonadi*
16noblacklist ${HOME}/.local/share/apps/korganizer 16nodeny ${HOME}/.local/share/apps/korganizer
17noblacklist ${HOME}/.local/share/contacts 17nodeny ${HOME}/.local/share/contacts
18noblacklist ${HOME}/.local/share/local-mail 18nodeny ${HOME}/.local/share/local-mail
19noblacklist ${HOME}/.local/share/notes 19nodeny ${HOME}/.local/share/notes
20noblacklist /sbin 20nodeny /sbin
21noblacklist /tmp/akonadi-* 21nodeny /tmp/akonadi-*
22noblacklist /usr/sbin 22nodeny /usr/sbin
23 23
24include disable-common.inc 24include disable-common.inc
25include disable-devel.inc 25include disable-devel.inc
diff --git a/etc/profile-a-l/akregator.profile b/etc/profile-a-l/akregator.profile
index 38fcd2dc1..b2323547c 100644
--- a/etc/profile-a-l/akregator.profile
+++ b/etc/profile-a-l/akregator.profile
@@ -6,9 +6,9 @@ include akregator.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/akregatorrc 9nodeny ${HOME}/.config/akregatorrc
10noblacklist ${HOME}/.local/share/akregator 10nodeny ${HOME}/.local/share/akregator
11noblacklist ${HOME}/.local/share/kxmlgui5/akregator 11nodeny ${HOME}/.local/share/kxmlgui5/akregator
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
@@ -21,10 +21,10 @@ include disable-shell.inc
21mkfile ${HOME}/.config/akregatorrc 21mkfile ${HOME}/.config/akregatorrc
22mkdir ${HOME}/.local/share/akregator 22mkdir ${HOME}/.local/share/akregator
23mkdir ${HOME}/.local/share/kxmlgui5/akregator 23mkdir ${HOME}/.local/share/kxmlgui5/akregator
24whitelist ${HOME}/.config/akregatorrc 24allow ${HOME}/.config/akregatorrc
25whitelist ${HOME}/.local/share/akregator 25allow ${HOME}/.local/share/akregator
26whitelist ${HOME}/.local/share/kssl 26allow ${HOME}/.local/share/kssl
27whitelist ${HOME}/.local/share/kxmlgui5/akregator 27allow ${HOME}/.local/share/kxmlgui5/akregator
28include whitelist-common.inc 28include whitelist-common.inc
29include whitelist-var-common.inc 29include whitelist-var-common.inc
30 30
diff --git a/etc/profile-a-l/alacarte.profile b/etc/profile-a-l/alacarte.profile
index 4c6d68020..ca6c8d887 100644
--- a/etc/profile-a-l/alacarte.profile
+++ b/etc/profile-a-l/alacarte.profile
@@ -19,13 +19,13 @@ include disable-passwdmgr.inc
19include disable-xdg.inc 19include disable-xdg.inc
20 20
21# Whitelist your system icon directory,varies by distro 21# Whitelist your system icon directory,varies by distro
22whitelist /usr/share/alacarte 22allow /usr/share/alacarte
23whitelist /usr/share/app-info 23allow /usr/share/app-info
24whitelist /usr/share/desktop-directories 24allow /usr/share/desktop-directories
25whitelist /usr/share/icons 25allow /usr/share/icons
26whitelist /var/lib/app-info/icons 26allow /var/lib/app-info/icons
27whitelist /var/lib/flatpak/exports/share/applications 27allow /var/lib/flatpak/exports/share/applications
28whitelist /var/lib/flatpak/exports/share/icons 28allow /var/lib/flatpak/exports/share/icons
29include whitelist-runuser-common.inc 29include whitelist-runuser-common.inc
30include whitelist-usr-share-common.inc 30include whitelist-usr-share-common.inc
31include whitelist-var-common.inc 31include whitelist-var-common.inc
diff --git a/etc/profile-a-l/alienarena.profile b/etc/profile-a-l/alienarena.profile
index 81ee6bd46..220c3345d 100644
--- a/etc/profile-a-l/alienarena.profile
+++ b/etc/profile-a-l/alienarena.profile
@@ -6,7 +6,7 @@ include alienarena.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.local/share/cor-games 9nodeny ${HOME}/.local/share/cor-games
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -18,8 +18,8 @@ include disable-shell.inc
18include disable-xdg.inc 18include disable-xdg.inc
19 19
20mkdir ${HOME}/.local/share/cor-games 20mkdir ${HOME}/.local/share/cor-games
21whitelist ${HOME}/.local/share/cor-games 21allow ${HOME}/.local/share/cor-games
22whitelist /usr/share/alienarena 22allow /usr/share/alienarena
23include whitelist-common.inc 23include whitelist-common.inc
24include whitelist-runuser-common.inc 24include whitelist-runuser-common.inc
25include whitelist-usr-share-common.inc 25include whitelist-usr-share-common.inc
diff --git a/etc/profile-a-l/alpine.profile b/etc/profile-a-l/alpine.profile
index 0b5cf0df0..6fa3edfa1 100644
--- a/etc/profile-a-l/alpine.profile
+++ b/etc/profile-a-l/alpine.profile
@@ -10,28 +10,28 @@ include globals.local
10# Workaround for bug https://github.com/netblue30/firejail/issues/2747 10# Workaround for bug https://github.com/netblue30/firejail/issues/2747
11# firejail --private-bin=sh --include='${CFG}/allow-bin-sh.inc' --profile=alpine sh -c '(alpine)' 11# firejail --private-bin=sh --include='${CFG}/allow-bin-sh.inc' --profile=alpine sh -c '(alpine)'
12 12
13noblacklist /var/mail 13nodeny /var/mail
14noblacklist /var/spool/mail 14nodeny /var/spool/mail
15noblacklist ${DOCUMENTS} 15nodeny ${DOCUMENTS}
16noblacklist ${HOME}/.addressbook 16nodeny ${HOME}/.addressbook
17noblacklist ${HOME}/.alpine-smime 17nodeny ${HOME}/.alpine-smime
18noblacklist ${HOME}/.mailcap 18nodeny ${HOME}/.mailcap
19noblacklist ${HOME}/.mh_profile 19nodeny ${HOME}/.mh_profile
20noblacklist ${HOME}/.mime.types 20nodeny ${HOME}/.mime.types
21noblacklist ${HOME}/.newsrc 21nodeny ${HOME}/.newsrc
22noblacklist ${HOME}/.pine-crash 22nodeny ${HOME}/.pine-crash
23noblacklist ${HOME}/.pine-debug1 23nodeny ${HOME}/.pine-debug1
24noblacklist ${HOME}/.pine-debug2 24nodeny ${HOME}/.pine-debug2
25noblacklist ${HOME}/.pine-debug3 25nodeny ${HOME}/.pine-debug3
26noblacklist ${HOME}/.pine-debug4 26nodeny ${HOME}/.pine-debug4
27noblacklist ${HOME}/.pine-interrupted-mail 27nodeny ${HOME}/.pine-interrupted-mail
28noblacklist ${HOME}/.pinerc 28nodeny ${HOME}/.pinerc
29noblacklist ${HOME}/.pinercex 29nodeny ${HOME}/.pinercex
30noblacklist ${HOME}/.signature 30nodeny ${HOME}/.signature
31noblacklist ${HOME}/mail 31nodeny ${HOME}/mail
32 32
33blacklist /tmp/.X11-unix 33deny /tmp/.X11-unix
34blacklist ${RUNUSER}/wayland-* 34deny ${RUNUSER}/wayland-*
35 35
36include disable-common.inc 36include disable-common.inc
37include disable-devel.inc 37include disable-devel.inc
@@ -60,8 +60,8 @@ include disable-xdg.inc
60#whitelist ${HOME}/.pine-debug4 60#whitelist ${HOME}/.pine-debug4
61#whitelist ${HOME}/.signature 61#whitelist ${HOME}/.signature
62#whitelist ${HOME}/mail 62#whitelist ${HOME}/mail
63whitelist /var/mail 63allow /var/mail
64whitelist /var/spool/mail 64allow /var/spool/mail
65#include whitelist-common.inc 65#include whitelist-common.inc
66include whitelist-runuser-common.inc 66include whitelist-runuser-common.inc
67include whitelist-usr-share-common.inc 67include whitelist-usr-share-common.inc
diff --git a/etc/profile-a-l/amarok.profile b/etc/profile-a-l/amarok.profile
index a7caddc4c..03aba36e4 100644
--- a/etc/profile-a-l/amarok.profile
+++ b/etc/profile-a-l/amarok.profile
@@ -6,7 +6,7 @@ include amarok.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${MUSIC} 9nodeny ${MUSIC}
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
diff --git a/etc/profile-a-l/amule.profile b/etc/profile-a-l/amule.profile
index e3c4164ee..00039a7e9 100644
--- a/etc/profile-a-l/amule.profile
+++ b/etc/profile-a-l/amule.profile
@@ -6,7 +6,7 @@ include amule.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.aMule 9nodeny ${HOME}/.aMule
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -16,8 +16,8 @@ include disable-passwdmgr.inc
16include disable-programs.inc 16include disable-programs.inc
17 17
18mkdir ${HOME}/.aMule 18mkdir ${HOME}/.aMule
19whitelist ${DOWNLOADS} 19allow ${DOWNLOADS}
20whitelist ${HOME}/.aMule 20allow ${HOME}/.aMule
21include whitelist-common.inc 21include whitelist-common.inc
22 22
23caps.drop all 23caps.drop all
diff --git a/etc/profile-a-l/android-studio.profile b/etc/profile-a-l/android-studio.profile
index 5a21744cf..5bf6ed773 100644
--- a/etc/profile-a-l/android-studio.profile
+++ b/etc/profile-a-l/android-studio.profile
@@ -5,13 +5,13 @@ include android-studio.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${HOME}/.config/Google 8nodeny ${HOME}/.config/Google
9noblacklist ${HOME}/.AndroidStudio* 9nodeny ${HOME}/.AndroidStudio*
10noblacklist ${HOME}/.android 10nodeny ${HOME}/.android
11noblacklist ${HOME}/.jack-server 11nodeny ${HOME}/.jack-server
12noblacklist ${HOME}/.jack-settings 12nodeny ${HOME}/.jack-settings
13noblacklist ${HOME}/.local/share/JetBrains 13nodeny ${HOME}/.local/share/JetBrains
14noblacklist ${HOME}/.tooling 14nodeny ${HOME}/.tooling
15 15
16# Allows files commonly used by IDEs 16# Allows files commonly used by IDEs
17include allow-common-devel.inc 17include allow-common-devel.inc
diff --git a/etc/profile-a-l/anki.profile b/etc/profile-a-l/anki.profile
index ef60e91c2..ec99fe6c2 100644
--- a/etc/profile-a-l/anki.profile
+++ b/etc/profile-a-l/anki.profile
@@ -6,8 +6,8 @@ include anki.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${DOCUMENTS} 9nodeny ${DOCUMENTS}
10noblacklist ${HOME}/.local/share/Anki2 10nodeny ${HOME}/.local/share/Anki2
11 11
12# Allow python (blacklisted by disable-interpreters.inc) 12# Allow python (blacklisted by disable-interpreters.inc)
13include allow-python2.inc 13include allow-python2.inc
@@ -23,8 +23,8 @@ include disable-shell.inc
23include disable-xdg.inc 23include disable-xdg.inc
24 24
25mkdir ${HOME}/.local/share/Anki2 25mkdir ${HOME}/.local/share/Anki2
26whitelist ${DOCUMENTS} 26allow ${DOCUMENTS}
27whitelist ${HOME}/.local/share/Anki2 27allow ${HOME}/.local/share/Anki2
28include whitelist-common.inc 28include whitelist-common.inc
29include whitelist-var-common.inc 29include whitelist-var-common.inc
30 30
diff --git a/etc/profile-a-l/anydesk.profile b/etc/profile-a-l/anydesk.profile
index fdaf10259..cb30ed8da 100644
--- a/etc/profile-a-l/anydesk.profile
+++ b/etc/profile-a-l/anydesk.profile
@@ -5,7 +5,7 @@ include anydesk.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${HOME}/.anydesk 8nodeny ${HOME}/.anydesk
9 9
10include disable-common.inc 10include disable-common.inc
11include disable-devel.inc 11include disable-devel.inc
@@ -15,7 +15,7 @@ include disable-programs.inc
15include disable-shell.inc 15include disable-shell.inc
16 16
17mkdir ${HOME}/.anydesk 17mkdir ${HOME}/.anydesk
18whitelist ${HOME}/.anydesk 18allow ${HOME}/.anydesk
19include whitelist-common.inc 19include whitelist-common.inc
20 20
21caps.drop all 21caps.drop all
diff --git a/etc/profile-a-l/aosp.profile b/etc/profile-a-l/aosp.profile
index e7b09283e..d647a4657 100644
--- a/etc/profile-a-l/aosp.profile
+++ b/etc/profile-a-l/aosp.profile
@@ -5,13 +5,13 @@ include aosp.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${HOME}/.android 8nodeny ${HOME}/.android
9noblacklist ${HOME}/.bash_history 9nodeny ${HOME}/.bash_history
10noblacklist ${HOME}/.jack-server 10nodeny ${HOME}/.jack-server
11noblacklist ${HOME}/.jack-settings 11nodeny ${HOME}/.jack-settings
12noblacklist ${HOME}/.repo_.gitconfig.json 12nodeny ${HOME}/.repo_.gitconfig.json
13noblacklist ${HOME}/.repoconfig 13nodeny ${HOME}/.repoconfig
14noblacklist ${HOME}/.tooling 14nodeny ${HOME}/.tooling
15 15
16# Allows files commonly used by IDEs 16# Allows files commonly used by IDEs
17include allow-common-devel.inc 17include allow-common-devel.inc
diff --git a/etc/profile-a-l/apostrophe.profile b/etc/profile-a-l/apostrophe.profile
index 01566314f..020ae2812 100644
--- a/etc/profile-a-l/apostrophe.profile
+++ b/etc/profile-a-l/apostrophe.profile
@@ -6,9 +6,9 @@ include apostrophe.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.texlive20* 9nodeny ${HOME}/.texlive20*
10noblacklist ${DOCUMENTS} 10nodeny ${DOCUMENTS}
11noblacklist ${PICTURES} 11nodeny ${PICTURES}
12 12
13# Allow lua (blacklisted by disable-interpreters.inc) 13# Allow lua (blacklisted by disable-interpreters.inc)
14include allow-lua.inc 14include allow-lua.inc
@@ -31,12 +31,12 @@ include disable-programs.inc
31include disable-shell.inc 31include disable-shell.inc
32include disable-xdg.inc 32include disable-xdg.inc
33 33
34whitelist /usr/libexec/webkit2gtk-4.0 34allow /usr/libexec/webkit2gtk-4.0
35whitelist /usr/share/apostrophe 35allow /usr/share/apostrophe
36whitelist /usr/share/texlive 36allow /usr/share/texlive
37whitelist /usr/share/texmf 37allow /usr/share/texmf
38whitelist /usr/share/pandoc-* 38allow /usr/share/pandoc-*
39whitelist /usr/share/perl5 39allow /usr/share/perl5
40include whitelist-runuser-common.inc 40include whitelist-runuser-common.inc
41include whitelist-usr-share-common.inc 41include whitelist-usr-share-common.inc
42include whitelist-var-common.inc 42include whitelist-var-common.inc
diff --git a/etc/profile-a-l/arch-audit.profile b/etc/profile-a-l/arch-audit.profile
index accabb6f5..8c71dd574 100644
--- a/etc/profile-a-l/arch-audit.profile
+++ b/etc/profile-a-l/arch-audit.profile
@@ -7,7 +7,7 @@ include arch-audit.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10noblacklist /var/lib/pacman 10nodeny /var/lib/pacman
11 11
12include disable-common.inc 12include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
@@ -18,7 +18,7 @@ include disable-programs.inc
18include disable-shell.inc 18include disable-shell.inc
19include disable-xdg.inc 19include disable-xdg.inc
20 20
21whitelist /usr/share/arch-audit 21allow /usr/share/arch-audit
22include whitelist-usr-share-common.inc 22include whitelist-usr-share-common.inc
23 23
24apparmor 24apparmor
diff --git a/etc/profile-a-l/archaudit-report.profile b/etc/profile-a-l/archaudit-report.profile
index 19c37f90e..0915ede33 100644
--- a/etc/profile-a-l/archaudit-report.profile
+++ b/etc/profile-a-l/archaudit-report.profile
@@ -6,7 +6,7 @@ include archaudit-report.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist /var/lib/pacman 9nodeny /var/lib/pacman
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
diff --git a/etc/profile-a-l/archiver-common.profile b/etc/profile-a-l/archiver-common.profile
index 1fab4606b..5b859ceb1 100644
--- a/etc/profile-a-l/archiver-common.profile
+++ b/etc/profile-a-l/archiver-common.profile
@@ -4,7 +4,7 @@ include archiver-common.local
4 4
5# common profile for archiver/compression tools 5# common profile for archiver/compression tools
6 6
7blacklist ${RUNUSER} 7deny ${RUNUSER}
8 8
9# Comment/uncomment the relevant include file(s) in your archiver-common.local 9# Comment/uncomment the relevant include file(s) in your archiver-common.local
10# to (un)restrict file access for **all** archivers. Another option is to do this **per archiver** 10# to (un)restrict file access for **all** archivers. Another option is to do this **per archiver**
diff --git a/etc/profile-a-l/ardour5.profile b/etc/profile-a-l/ardour5.profile
index 84b1d6c18..960948afc 100644
--- a/etc/profile-a-l/ardour5.profile
+++ b/etc/profile-a-l/ardour5.profile
@@ -5,12 +5,12 @@ include ardour5.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${HOME}/.config/ardour4 8nodeny ${HOME}/.config/ardour4
9noblacklist ${HOME}/.config/ardour5 9nodeny ${HOME}/.config/ardour5
10noblacklist ${HOME}/.lv2 10nodeny ${HOME}/.lv2
11noblacklist ${HOME}/.vst 11nodeny ${HOME}/.vst
12noblacklist ${DOCUMENTS} 12nodeny ${DOCUMENTS}
13noblacklist ${MUSIC} 13nodeny ${MUSIC}
14 14
15include disable-common.inc 15include disable-common.inc
16include disable-devel.inc 16include disable-devel.inc
diff --git a/etc/profile-a-l/arduino.profile b/etc/profile-a-l/arduino.profile
index fd1ca9a09..88f14fbfe 100644
--- a/etc/profile-a-l/arduino.profile
+++ b/etc/profile-a-l/arduino.profile
@@ -6,9 +6,9 @@ include arduino.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.arduino15 9nodeny ${HOME}/.arduino15
10noblacklist ${HOME}/Arduino 10nodeny ${HOME}/Arduino
11noblacklist ${DOCUMENTS} 11nodeny ${DOCUMENTS}
12 12
13# Allow java (blacklisted by disable-devel.inc) 13# Allow java (blacklisted by disable-devel.inc)
14include allow-java.inc 14include allow-java.inc
diff --git a/etc/profile-a-l/aria2c.profile b/etc/profile-a-l/aria2c.profile
index 22b8ecd65..be56011f0 100644
--- a/etc/profile-a-l/aria2c.profile
+++ b/etc/profile-a-l/aria2c.profile
@@ -6,12 +6,12 @@ include aria2c.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.aria2 9nodeny ${HOME}/.aria2
10noblacklist ${HOME}/.config/aria2 10nodeny ${HOME}/.config/aria2
11noblacklist ${HOME}/.netrc 11nodeny ${HOME}/.netrc
12 12
13blacklist /tmp/.X11-unix 13deny /tmp/.X11-unix
14blacklist ${RUNUSER}/wayland-* 14deny ${RUNUSER}/wayland-*
15 15
16include disable-common.inc 16include disable-common.inc
17include disable-devel.inc 17include disable-devel.inc
diff --git a/etc/profile-a-l/ark.profile b/etc/profile-a-l/ark.profile
index a63dd8f5f..031c57080 100644
--- a/etc/profile-a-l/ark.profile
+++ b/etc/profile-a-l/ark.profile
@@ -6,8 +6,8 @@ include ark.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/arkrc 9nodeny ${HOME}/.config/arkrc
10noblacklist ${HOME}/.local/share/kxmlgui5/ark 10nodeny ${HOME}/.local/share/kxmlgui5/ark
11 11
12include disable-common.inc 12include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
@@ -16,7 +16,7 @@ include disable-interpreters.inc
16include disable-passwdmgr.inc 16include disable-passwdmgr.inc
17include disable-programs.inc 17include disable-programs.inc
18 18
19whitelist /usr/share/ark 19allow /usr/share/ark
20include whitelist-usr-share-common.inc 20include whitelist-usr-share-common.inc
21include whitelist-var-common.inc 21include whitelist-var-common.inc
22 22
diff --git a/etc/profile-a-l/arm.profile b/etc/profile-a-l/arm.profile
index 2c8b630ce..9ed8076be 100644
--- a/etc/profile-a-l/arm.profile
+++ b/etc/profile-a-l/arm.profile
@@ -6,7 +6,7 @@ include arm.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.arm 9nodeny ${HOME}/.arm
10 10
11# Allow python (blacklisted by disable-interpreters.inc) 11# Allow python (blacklisted by disable-interpreters.inc)
12include allow-python2.inc 12include allow-python2.inc
@@ -20,7 +20,7 @@ include disable-passwdmgr.inc
20include disable-programs.inc 20include disable-programs.inc
21 21
22mkdir ${HOME}/.arm 22mkdir ${HOME}/.arm
23whitelist ${HOME}/.arm 23allow ${HOME}/.arm
24include whitelist-common.inc 24include whitelist-common.inc
25 25
26caps.drop all 26caps.drop all
diff --git a/etc/profile-a-l/artha.profile b/etc/profile-a-l/artha.profile
index fab72b7d3..7cfac4915 100644
--- a/etc/profile-a-l/artha.profile
+++ b/etc/profile-a-l/artha.profile
@@ -6,12 +6,12 @@ include artha.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/artha.conf 9nodeny ${HOME}/.config/artha.conf
10noblacklist ${HOME}/.config/artha.log 10nodeny ${HOME}/.config/artha.log
11noblacklist ${HOME}/.config/enchant 11nodeny ${HOME}/.config/enchant
12 12
13blacklist /tmp/.X11-unix 13deny /tmp/.X11-unix
14blacklist ${RUNUSER}/wayland-* 14deny ${RUNUSER}/wayland-*
15 15
16include disable-common.inc 16include disable-common.inc
17include disable-devel.inc 17include disable-devel.inc
@@ -28,8 +28,8 @@ include disable-xdg.inc
28#whitelist ${HOME}/.config/artha.conf 28#whitelist ${HOME}/.config/artha.conf
29#whitelist ${HOME}/.config/artha.log 29#whitelist ${HOME}/.config/artha.log
30#whitelist ${HOME}/.config/enchant 30#whitelist ${HOME}/.config/enchant
31whitelist /usr/share/artha 31allow /usr/share/artha
32whitelist /usr/share/wordnet 32allow /usr/share/wordnet
33#include whitelist-common.inc 33#include whitelist-common.inc
34include whitelist-usr-share-common.inc 34include whitelist-usr-share-common.inc
35include whitelist-var-common.inc 35include whitelist-var-common.inc
diff --git a/etc/profile-a-l/assogiate.profile b/etc/profile-a-l/assogiate.profile
index 977fe30a4..f2251c210 100644
--- a/etc/profile-a-l/assogiate.profile
+++ b/etc/profile-a-l/assogiate.profile
@@ -6,7 +6,7 @@ include assogiate.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${PICTURES} 9nodeny ${PICTURES}
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -17,7 +17,7 @@ include disable-programs.inc
17include disable-shell.inc 17include disable-shell.inc
18include disable-xdg.inc 18include disable-xdg.inc
19 19
20whitelist ${PICTURES} 20allow ${PICTURES}
21include whitelist-common.inc 21include whitelist-common.inc
22include whitelist-usr-share-common.inc 22include whitelist-usr-share-common.inc
23include whitelist-var-common.inc 23include whitelist-var-common.inc
diff --git a/etc/profile-a-l/asunder.profile b/etc/profile-a-l/asunder.profile
index c97fd691a..e65072266 100644
--- a/etc/profile-a-l/asunder.profile
+++ b/etc/profile-a-l/asunder.profile
@@ -6,11 +6,11 @@ include asunder.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/asunder 9nodeny ${HOME}/.config/asunder
10noblacklist ${HOME}/.asunder_album_genre 10nodeny ${HOME}/.asunder_album_genre
11noblacklist ${HOME}/.asunder_album_title 11nodeny ${HOME}/.asunder_album_title
12noblacklist ${HOME}/.asunder_album_artist 12nodeny ${HOME}/.asunder_album_artist
13noblacklist ${MUSIC} 13nodeny ${MUSIC}
14 14
15include disable-common.inc 15include disable-common.inc
16include disable-devel.inc 16include disable-devel.inc
diff --git a/etc/profile-a-l/atom.profile b/etc/profile-a-l/atom.profile
index 5f237ac59..ea3038537 100644
--- a/etc/profile-a-l/atom.profile
+++ b/etc/profile-a-l/atom.profile
@@ -18,8 +18,8 @@ ignore include whitelist-var-common.inc
18ignore apparmor 18ignore apparmor
19ignore disable-mnt 19ignore disable-mnt
20 20
21noblacklist ${HOME}/.atom 21nodeny ${HOME}/.atom
22noblacklist ${HOME}/.config/Atom 22nodeny ${HOME}/.config/Atom
23 23
24# Allows files commonly used by IDEs 24# Allows files commonly used by IDEs
25include allow-common-devel.inc 25include allow-common-devel.inc
diff --git a/etc/profile-a-l/atril.profile b/etc/profile-a-l/atril.profile
index 1c3ed66ff..8ae8617cf 100644
--- a/etc/profile-a-l/atril.profile
+++ b/etc/profile-a-l/atril.profile
@@ -6,9 +6,9 @@ include atril.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.cache/atril 9nodeny ${HOME}/.cache/atril
10noblacklist ${HOME}/.config/atril 10nodeny ${HOME}/.config/atril
11noblacklist ${DOCUMENTS} 11nodeny ${DOCUMENTS}
12 12
13#noblacklist ${HOME}/.local/share 13#noblacklist ${HOME}/.local/share
14# it seems to use only ${HOME}/.local/share/webkitgtk 14# it seems to use only ${HOME}/.local/share/webkitgtk
diff --git a/etc/profile-a-l/audacious.profile b/etc/profile-a-l/audacious.profile
index f9f209786..53baf0a2a 100644
--- a/etc/profile-a-l/audacious.profile
+++ b/etc/profile-a-l/audacious.profile
@@ -6,9 +6,9 @@ include audacious.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/Audaciousrc 9nodeny ${HOME}/.config/Audaciousrc
10noblacklist ${HOME}/.config/audacious 10nodeny ${HOME}/.config/audacious
11noblacklist ${MUSIC} 11nodeny ${MUSIC}
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
diff --git a/etc/profile-a-l/audacity.profile b/etc/profile-a-l/audacity.profile
index a2de8436a..c244846e1 100644
--- a/etc/profile-a-l/audacity.profile
+++ b/etc/profile-a-l/audacity.profile
@@ -6,9 +6,9 @@ include audacity.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.audacity-data 9nodeny ${HOME}/.audacity-data
10noblacklist ${DOCUMENTS} 10nodeny ${DOCUMENTS}
11noblacklist ${MUSIC} 11nodeny ${MUSIC}
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
diff --git a/etc/profile-a-l/audio-recorder.profile b/etc/profile-a-l/audio-recorder.profile
index 2c7fdc812..534792cc6 100644
--- a/etc/profile-a-l/audio-recorder.profile
+++ b/etc/profile-a-l/audio-recorder.profile
@@ -7,7 +7,7 @@ include audio-recorder.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10noblacklist ${MUSIC} 10nodeny ${MUSIC}
11 11
12include disable-common.inc 12include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
@@ -17,10 +17,10 @@ include disable-passwdmgr.inc
17include disable-programs.inc 17include disable-programs.inc
18include disable-xdg.inc 18include disable-xdg.inc
19 19
20whitelist ${MUSIC} 20allow ${MUSIC}
21whitelist ${DOWNLOADS} 21allow ${DOWNLOADS}
22whitelist /usr/share/audio-recorder 22allow /usr/share/audio-recorder
23whitelist /usr/share/gstreamer-1.0 23allow /usr/share/gstreamer-1.0
24include whitelist-common.inc 24include whitelist-common.inc
25include whitelist-usr-share-common.inc 25include whitelist-usr-share-common.inc
26include whitelist-var-common.inc 26include whitelist-var-common.inc
diff --git a/etc/profile-a-l/authenticator-rs.profile b/etc/profile-a-l/authenticator-rs.profile
index 2ebe35dd5..0d6eb6a21 100644
--- a/etc/profile-a-l/authenticator-rs.profile
+++ b/etc/profile-a-l/authenticator-rs.profile
@@ -6,7 +6,7 @@ include authenticator-rs.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.local/share/authenticator-rs 9nodeny ${HOME}/.local/share/authenticator-rs
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -18,9 +18,9 @@ include disable-shell.inc
18include disable-xdg.inc 18include disable-xdg.inc
19 19
20mkdir ${HOME}/.local/share/authenticator-rs 20mkdir ${HOME}/.local/share/authenticator-rs
21whitelist ${HOME}/.local/share/authenticator-rs 21allow ${HOME}/.local/share/authenticator-rs
22whitelist ${DOWNLOADS} 22allow ${DOWNLOADS}
23whitelist /usr/share/uk.co.grumlimited.authenticator-rs 23allow /usr/share/uk.co.grumlimited.authenticator-rs
24include whitelist-common.inc 24include whitelist-common.inc
25include whitelist-runuser-common.inc 25include whitelist-runuser-common.inc
26include whitelist-usr-share-common.inc 26include whitelist-usr-share-common.inc
diff --git a/etc/profile-a-l/authenticator.profile b/etc/profile-a-l/authenticator.profile
index 42d9cd56a..55d967e3e 100644
--- a/etc/profile-a-l/authenticator.profile
+++ b/etc/profile-a-l/authenticator.profile
@@ -6,8 +6,8 @@ include authenticator.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.cache/Authenticator 9nodeny ${HOME}/.cache/Authenticator
10noblacklist ${HOME}/.config/Authenticator 10nodeny ${HOME}/.config/Authenticator
11 11
12# Allow python (blacklisted by disable-interpreters.inc) 12# Allow python (blacklisted by disable-interpreters.inc)
13#include allow-python2.inc 13#include allow-python2.inc
diff --git a/etc/profile-a-l/autokey-common.profile b/etc/profile-a-l/autokey-common.profile
index 891928e5a..a5b3b22f6 100644
--- a/etc/profile-a-l/autokey-common.profile
+++ b/etc/profile-a-l/autokey-common.profile
@@ -7,8 +7,8 @@ include autokey-common.local
7# added by caller profile 7# added by caller profile
8#include globals.local 8#include globals.local
9 9
10noblacklist ${HOME}/.config/autokey 10nodeny ${HOME}/.config/autokey
11noblacklist ${HOME}/.local/share/autokey 11nodeny ${HOME}/.local/share/autokey
12 12
13# Allow python (blacklisted by disable-interpreters.inc) 13# Allow python (blacklisted by disable-interpreters.inc)
14include allow-python2.inc 14include allow-python2.inc
diff --git a/etc/profile-a-l/avidemux.profile b/etc/profile-a-l/avidemux.profile
index 1ecc03da1..0feb05d75 100644
--- a/etc/profile-a-l/avidemux.profile
+++ b/etc/profile-a-l/avidemux.profile
@@ -5,9 +5,9 @@ include avidemux.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${HOME}/.avidemux6 8nodeny ${HOME}/.avidemux6
9noblacklist ${HOME}/.config/avidemux3_qt5rc 9nodeny ${HOME}/.config/avidemux3_qt5rc
10noblacklist ${VIDEOS} 10nodeny ${VIDEOS}
11 11
12include disable-common.inc 12include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
@@ -20,9 +20,9 @@ include disable-xdg.inc
20 20
21mkdir ${HOME}/.avidemux6 21mkdir ${HOME}/.avidemux6
22mkdir ${HOME}/.config/avidemux3_qt5rc 22mkdir ${HOME}/.config/avidemux3_qt5rc
23whitelist ${HOME}/.avidemux6 23allow ${HOME}/.avidemux6
24whitelist ${HOME}/.config/avidemux3_qt5rc 24allow ${HOME}/.config/avidemux3_qt5rc
25whitelist ${VIDEOS} 25allow ${VIDEOS}
26include whitelist-common.inc 26include whitelist-common.inc
27include whitelist-runuser-common.inc 27include whitelist-runuser-common.inc
28include whitelist-usr-share-common.inc 28include whitelist-usr-share-common.inc
diff --git a/etc/profile-a-l/aweather.profile b/etc/profile-a-l/aweather.profile
index a57ad4014..abe9fdb24 100644
--- a/etc/profile-a-l/aweather.profile
+++ b/etc/profile-a-l/aweather.profile
@@ -6,7 +6,7 @@ include aweather.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/aweather 9nodeny ${HOME}/.config/aweather
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -16,7 +16,7 @@ include disable-programs.inc
16include disable-shell.inc 16include disable-shell.inc
17 17
18mkdir ${HOME}/.config/aweather 18mkdir ${HOME}/.config/aweather
19whitelist ${HOME}/.config/aweather 19allow ${HOME}/.config/aweather
20include whitelist-common.inc 20include whitelist-common.inc
21include whitelist-var-common.inc 21include whitelist-var-common.inc
22 22
diff --git a/etc/profile-a-l/awesome.profile b/etc/profile-a-l/awesome.profile
index 5d1bf5071..58f4f5e96 100644
--- a/etc/profile-a-l/awesome.profile
+++ b/etc/profile-a-l/awesome.profile
@@ -7,7 +7,7 @@ include awesome.local
7include globals.local 7include globals.local
8 8
9# all applications started in awesome will run in this profile 9# all applications started in awesome will run in this profile
10noblacklist ${HOME}/.config/awesome 10nodeny ${HOME}/.config/awesome
11include disable-common.inc 11include disable-common.inc
12 12
13caps.drop all 13caps.drop all
diff --git a/etc/profile-a-l/ballbuster.profile b/etc/profile-a-l/ballbuster.profile
index 3952921a3..46bb0b44e 100644
--- a/etc/profile-a-l/ballbuster.profile
+++ b/etc/profile-a-l/ballbuster.profile
@@ -6,7 +6,7 @@ include ballbuster.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.ballbuster.hs 9nodeny ${HOME}/.ballbuster.hs
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -18,8 +18,8 @@ include disable-shell.inc
18include disable-xdg.inc 18include disable-xdg.inc
19 19
20mkfile ${HOME}/.ballbuster.hs 20mkfile ${HOME}/.ballbuster.hs
21whitelist ${HOME}/.ballbuster.hs 21allow ${HOME}/.ballbuster.hs
22whitelist /usr/share/ballbuster 22allow /usr/share/ballbuster
23include whitelist-common.inc 23include whitelist-common.inc
24include whitelist-runuser-common.inc 24include whitelist-runuser-common.inc
25include whitelist-usr-share-common.inc 25include whitelist-usr-share-common.inc
diff --git a/etc/profile-a-l/baloo_file.profile b/etc/profile-a-l/baloo_file.profile
index fe86d9b80..2b10883f7 100644
--- a/etc/profile-a-l/baloo_file.profile
+++ b/etc/profile-a-l/baloo_file.profile
@@ -12,12 +12,12 @@ include globals.local
12# read-write ${HOME}/.local/share/baloo 12# read-write ${HOME}/.local/share/baloo
13# ignore read-write 13# ignore read-write
14 14
15noblacklist ${HOME}/.config/baloofilerc 15nodeny ${HOME}/.config/baloofilerc
16noblacklist ${HOME}/.kde/share/config/baloofilerc 16nodeny ${HOME}/.kde/share/config/baloofilerc
17noblacklist ${HOME}/.kde/share/config/baloorc 17nodeny ${HOME}/.kde/share/config/baloorc
18noblacklist ${HOME}/.kde4/share/config/baloofilerc 18nodeny ${HOME}/.kde4/share/config/baloofilerc
19noblacklist ${HOME}/.kde4/share/config/baloorc 19nodeny ${HOME}/.kde4/share/config/baloorc
20noblacklist ${HOME}/.local/share/baloo 20nodeny ${HOME}/.local/share/baloo
21 21
22include disable-common.inc 22include disable-common.inc
23include disable-devel.inc 23include disable-devel.inc
diff --git a/etc/profile-a-l/balsa.profile b/etc/profile-a-l/balsa.profile
index 8c69652c5..1e74443aa 100644
--- a/etc/profile-a-l/balsa.profile
+++ b/etc/profile-a-l/balsa.profile
@@ -6,13 +6,13 @@ include balsa.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.balsa 9nodeny ${HOME}/.balsa
10noblacklist ${HOME}/.gnupg 10nodeny ${HOME}/.gnupg
11noblacklist ${HOME}/.mozilla 11nodeny ${HOME}/.mozilla
12noblacklist ${HOME}/.signature 12nodeny ${HOME}/.signature
13noblacklist ${HOME}/mail 13nodeny ${HOME}/mail
14noblacklist /var/mail 14nodeny /var/mail
15noblacklist /var/spool/mail 15nodeny /var/spool/mail
16 16
17include disable-common.inc 17include disable-common.inc
18include disable-devel.inc 18include disable-devel.inc
@@ -27,17 +27,17 @@ mkdir ${HOME}/.balsa
27mkdir ${HOME}/.gnupg 27mkdir ${HOME}/.gnupg
28mkfile ${HOME}/.signature 28mkfile ${HOME}/.signature
29mkdir ${HOME}/mail 29mkdir ${HOME}/mail
30whitelist ${HOME}/.balsa 30allow ${HOME}/.balsa
31whitelist ${HOME}/.gnupg 31allow ${HOME}/.gnupg
32whitelist ${HOME}/.mozilla/firefox/profiles.ini 32allow ${HOME}/.mozilla/firefox/profiles.ini
33whitelist ${HOME}/.signature 33allow ${HOME}/.signature
34whitelist ${HOME}/mail 34allow ${HOME}/mail
35whitelist ${RUNUSER}/gnupg 35allow ${RUNUSER}/gnupg
36whitelist /usr/share/balsa 36allow /usr/share/balsa
37whitelist /usr/share/gnupg 37allow /usr/share/gnupg
38whitelist /usr/share/gnupg2 38allow /usr/share/gnupg2
39whitelist /var/mail 39allow /var/mail
40whitelist /var/spool/mail 40allow /var/spool/mail
41include whitelist-common.inc 41include whitelist-common.inc
42include whitelist-runuser-common.inc 42include whitelist-runuser-common.inc
43include whitelist-usr-share-common.inc 43include whitelist-usr-share-common.inc
diff --git a/etc/profile-a-l/barrier.profile b/etc/profile-a-l/barrier.profile
index 7b50e9199..fcea9b3ba 100644
--- a/etc/profile-a-l/barrier.profile
+++ b/etc/profile-a-l/barrier.profile
@@ -6,9 +6,9 @@ include barrier.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/Debauchee/Barrier.conf 9nodeny ${HOME}/.config/Debauchee/Barrier.conf
10noblacklist ${HOME}/.local/share/barrier 10nodeny ${HOME}/.local/share/barrier
11noblacklist ${PATH}/openssl 11nodeny ${PATH}/openssl
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
diff --git a/etc/profile-a-l/basilisk.profile b/etc/profile-a-l/basilisk.profile
index 8dc3847a0..547c67fc8 100644
--- a/etc/profile-a-l/basilisk.profile
+++ b/etc/profile-a-l/basilisk.profile
@@ -5,13 +5,13 @@ include basilisk.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${HOME}/.cache/moonchild productions/basilisk 8nodeny ${HOME}/.cache/moonchild productions/basilisk
9noblacklist ${HOME}/.moonchild productions/basilisk 9nodeny ${HOME}/.moonchild productions/basilisk
10 10
11mkdir ${HOME}/.cache/moonchild productions/basilisk 11mkdir ${HOME}/.cache/moonchild productions/basilisk
12mkdir ${HOME}/.moonchild productions 12mkdir ${HOME}/.moonchild productions
13whitelist ${HOME}/.cache/moonchild productions/basilisk 13allow ${HOME}/.cache/moonchild productions/basilisk
14whitelist ${HOME}/.moonchild productions 14allow ${HOME}/.moonchild productions
15 15
16# Basilisk can use the full firejail seccomp filter (unlike firefox >= 60) 16# Basilisk can use the full firejail seccomp filter (unlike firefox >= 60)
17seccomp 17seccomp
diff --git a/etc/profile-a-l/bcompare.profile b/etc/profile-a-l/bcompare.profile
index 3ecaea7fe..a1d2b1e73 100644
--- a/etc/profile-a-l/bcompare.profile
+++ b/etc/profile-a-l/bcompare.profile
@@ -7,10 +7,10 @@ include bcompare.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10noblacklist ${HOME}/.config/bcompare 10nodeny ${HOME}/.config/bcompare
11# In case the user decides to include disable-programs.inc, still allow 11# In case the user decides to include disable-programs.inc, still allow
12# KDE's Gwenview to view images via right click -> Open With -> Associated Application 12# KDE's Gwenview to view images via right click -> Open With -> Associated Application
13noblacklist ${HOME}/.config/gwenviewrc 13nodeny ${HOME}/.config/gwenviewrc
14 14
15# Add the next line to your bcompare.local if you don't need to compare files in disable-common.inc. 15# Add the next line to your bcompare.local if you don't need to compare files in disable-common.inc.
16#include disable-common.inc 16#include disable-common.inc
diff --git a/etc/profile-a-l/beaker.profile b/etc/profile-a-l/beaker.profile
index f3a9568bd..588f460a8 100644
--- a/etc/profile-a-l/beaker.profile
+++ b/etc/profile-a-l/beaker.profile
@@ -19,10 +19,10 @@ ignore private-cache
19ignore private-dev 19ignore private-dev
20ignore private-tmp 20ignore private-tmp
21 21
22noblacklist ${HOME}/.config/Beaker Browser 22nodeny ${HOME}/.config/Beaker Browser
23 23
24mkdir ${HOME}/.config/Beaker Browser 24mkdir ${HOME}/.config/Beaker Browser
25whitelist ${HOME}/.config/Beaker Browser 25allow ${HOME}/.config/Beaker Browser
26 26
27# Redirect 27# Redirect
28include electron.profile 28include electron.profile
diff --git a/etc/profile-a-l/bibletime.profile b/etc/profile-a-l/bibletime.profile
index c7a82afbd..717d7258d 100644
--- a/etc/profile-a-l/bibletime.profile
+++ b/etc/profile-a-l/bibletime.profile
@@ -6,11 +6,11 @@ include bibletime.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.bibletime 9nodeny ${HOME}/.bibletime
10noblacklist ${HOME}/.sword 10nodeny ${HOME}/.sword
11noblacklist ${HOME}/.local/share/bibletime 11nodeny ${HOME}/.local/share/bibletime
12 12
13blacklist ${HOME}/.bashrc 13deny ${HOME}/.bashrc
14 14
15include disable-common.inc 15include disable-common.inc
16include disable-devel.inc 16include disable-devel.inc
@@ -22,12 +22,12 @@ include disable-programs.inc
22mkdir ${HOME}/.bibletime 22mkdir ${HOME}/.bibletime
23mkdir ${HOME}/.sword 23mkdir ${HOME}/.sword
24mkdir ${HOME}/.local/share/bibletime 24mkdir ${HOME}/.local/share/bibletime
25whitelist ${HOME}/.bibletime 25allow ${HOME}/.bibletime
26whitelist ${HOME}/.sword 26allow ${HOME}/.sword
27whitelist ${HOME}/.local/share/bibletime 27allow ${HOME}/.local/share/bibletime
28whitelist /usr/share/bibletime 28allow /usr/share/bibletime
29whitelist /usr/share/doc/bibletime 29allow /usr/share/doc/bibletime
30whitelist /usr/share/sword 30allow /usr/share/sword
31include whitelist-common.inc 31include whitelist-common.inc
32include whitelist-usr-share-common.inc 32include whitelist-usr-share-common.inc
33include whitelist-var-common.inc 33include whitelist-var-common.inc
diff --git a/etc/profile-a-l/bijiben.profile b/etc/profile-a-l/bijiben.profile
index 854fe5cb9..b02fcc3e0 100644
--- a/etc/profile-a-l/bijiben.profile
+++ b/etc/profile-a-l/bijiben.profile
@@ -6,7 +6,7 @@ include bijiben.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.local/share/bijiben 9nodeny ${HOME}/.local/share/bijiben
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -18,12 +18,12 @@ include disable-shell.inc
18include disable-xdg.inc 18include disable-xdg.inc
19 19
20mkdir ${HOME}/.local/share/bijiben 20mkdir ${HOME}/.local/share/bijiben
21whitelist ${HOME}/.local/share/bijiben 21allow ${HOME}/.local/share/bijiben
22whitelist ${HOME}/.cache/tracker 22allow ${HOME}/.cache/tracker
23whitelist /usr/libexec/webkit2gtk-4.0 23allow /usr/libexec/webkit2gtk-4.0
24whitelist /usr/share/bijiben 24allow /usr/share/bijiben
25whitelist /usr/share/tracker 25allow /usr/share/tracker
26whitelist /usr/share/tracker3 26allow /usr/share/tracker3
27include whitelist-common.inc 27include whitelist-common.inc
28include whitelist-runuser-common.inc 28include whitelist-runuser-common.inc
29include whitelist-usr-share-common.inc 29include whitelist-usr-share-common.inc
diff --git a/etc/profile-a-l/bitcoin-qt.profile b/etc/profile-a-l/bitcoin-qt.profile
index 932db9b73..c4ec0f820 100644
--- a/etc/profile-a-l/bitcoin-qt.profile
+++ b/etc/profile-a-l/bitcoin-qt.profile
@@ -6,8 +6,8 @@ include bitcoin-qt.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.bitcoin 9nodeny ${HOME}/.bitcoin
10noblacklist ${HOME}/.config/Bitcoin 10nodeny ${HOME}/.config/Bitcoin
11 11
12include disable-common.inc 12include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
@@ -19,8 +19,8 @@ include disable-shell.inc
19 19
20mkdir ${HOME}/.bitcoin 20mkdir ${HOME}/.bitcoin
21mkdir ${HOME}/.config/Bitcoin 21mkdir ${HOME}/.config/Bitcoin
22whitelist ${HOME}/.bitcoin 22allow ${HOME}/.bitcoin
23whitelist ${HOME}/.config/Bitcoin 23allow ${HOME}/.config/Bitcoin
24include whitelist-common.inc 24include whitelist-common.inc
25include whitelist-var-common.inc 25include whitelist-var-common.inc
26 26
diff --git a/etc/profile-a-l/bitlbee.profile b/etc/profile-a-l/bitlbee.profile
index dd7651979..0f000b26b 100644
--- a/etc/profile-a-l/bitlbee.profile
+++ b/etc/profile-a-l/bitlbee.profile
@@ -8,8 +8,8 @@ include globals.local
8 8
9ignore noexec ${HOME} 9ignore noexec ${HOME}
10 10
11noblacklist /sbin 11nodeny /sbin
12noblacklist /usr/sbin 12nodeny /usr/sbin
13# noblacklist /var/log 13# noblacklist /var/log
14 14
15include disable-common.inc 15include disable-common.inc
diff --git a/etc/profile-a-l/bitwarden.profile b/etc/profile-a-l/bitwarden.profile
index ba2eb2ea7..4b292d72a 100644
--- a/etc/profile-a-l/bitwarden.profile
+++ b/etc/profile-a-l/bitwarden.profile
@@ -11,12 +11,12 @@ ignore include whitelist-usr-share-common.inc
11 11
12ignore noexec /tmp 12ignore noexec /tmp
13 13
14noblacklist ${HOME}/.config/Bitwarden 14nodeny ${HOME}/.config/Bitwarden
15 15
16include disable-shell.inc 16include disable-shell.inc
17 17
18mkdir ${HOME}/.config/Bitwarden 18mkdir ${HOME}/.config/Bitwarden
19whitelist ${HOME}/.config/Bitwarden 19allow ${HOME}/.config/Bitwarden
20 20
21machine-id 21machine-id
22no3d 22no3d
diff --git a/etc/profile-a-l/blackbox.profile b/etc/profile-a-l/blackbox.profile
index 233f9a96f..616ad6801 100644
--- a/etc/profile-a-l/blackbox.profile
+++ b/etc/profile-a-l/blackbox.profile
@@ -7,7 +7,7 @@ include blackbox.local
7include globals.local 7include globals.local
8 8
9# all applications started in blackbox will run in this profile 9# all applications started in blackbox will run in this profile
10noblacklist ${HOME}/.blackbox 10nodeny ${HOME}/.blackbox
11include disable-common.inc 11include disable-common.inc
12 12
13caps.drop all 13caps.drop all
diff --git a/etc/profile-a-l/blender.profile b/etc/profile-a-l/blender.profile
index 701ae431e..8d0b5616f 100644
--- a/etc/profile-a-l/blender.profile
+++ b/etc/profile-a-l/blender.profile
@@ -6,7 +6,7 @@ include blender.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/blender 9nodeny ${HOME}/.config/blender
10 10
11# Allow python (blacklisted by disable-interpreters.inc) 11# Allow python (blacklisted by disable-interpreters.inc)
12include allow-python2.inc 12include allow-python2.inc
@@ -20,8 +20,8 @@ include disable-passwdmgr.inc
20include disable-programs.inc 20include disable-programs.inc
21 21
22# Allow usage of AMD GPU by OpenCL 22# Allow usage of AMD GPU by OpenCL
23noblacklist /sys/module 23nodeny /sys/module
24whitelist /sys/module/amdgpu 24allow /sys/module/amdgpu
25read-only /sys/module/amdgpu 25read-only /sys/module/amdgpu
26 26
27caps.drop all 27caps.drop all
diff --git a/etc/profile-a-l/bless.profile b/etc/profile-a-l/bless.profile
index 80dc750f7..ca5f96eee 100644
--- a/etc/profile-a-l/bless.profile
+++ b/etc/profile-a-l/bless.profile
@@ -6,7 +6,7 @@ include bless.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/bless 9nodeny ${HOME}/.config/bless
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
diff --git a/etc/profile-a-l/blobby.profile b/etc/profile-a-l/blobby.profile
index 229c20293..ee2a73b54 100644
--- a/etc/profile-a-l/blobby.profile
+++ b/etc/profile-a-l/blobby.profile
@@ -4,7 +4,7 @@ include blobby.local
4# Persistent global definitions 4# Persistent global definitions
5include globals.local 5include globals.local
6 6
7noblacklist ${HOME}/.blobby 7nodeny ${HOME}/.blobby
8 8
9include disable-common.inc 9include disable-common.inc
10include disable-devel.inc 10include disable-devel.inc
@@ -16,9 +16,9 @@ include disable-shell.inc
16include disable-xdg.inc 16include disable-xdg.inc
17 17
18mkdir ${HOME}/.blobby 18mkdir ${HOME}/.blobby
19whitelist ${HOME}/.blobby 19allow ${HOME}/.blobby
20include whitelist-common.inc 20include whitelist-common.inc
21whitelist /usr/share/blobby 21allow /usr/share/blobby
22include whitelist-usr-share-common.inc 22include whitelist-usr-share-common.inc
23include whitelist-var-common.inc 23include whitelist-var-common.inc
24 24
diff --git a/etc/profile-a-l/blobwars.profile b/etc/profile-a-l/blobwars.profile
index 904710cb5..e0be5261e 100644
--- a/etc/profile-a-l/blobwars.profile
+++ b/etc/profile-a-l/blobwars.profile
@@ -6,7 +6,7 @@ include blobwars.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.parallelrealities/blobwars 9nodeny ${HOME}/.parallelrealities/blobwars
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -18,8 +18,8 @@ include disable-shell.inc
18include disable-xdg.inc 18include disable-xdg.inc
19 19
20mkdir ${HOME}/.parallelrealities/blobwars 20mkdir ${HOME}/.parallelrealities/blobwars
21whitelist ${HOME}/.parallelrealities/blobwars 21allow ${HOME}/.parallelrealities/blobwars
22whitelist /usr/share/blobwars 22allow /usr/share/blobwars
23include whitelist-common.inc 23include whitelist-common.inc
24include whitelist-usr-share-common.inc 24include whitelist-usr-share-common.inc
25include whitelist-var-common.inc 25include whitelist-var-common.inc
diff --git a/etc/profile-a-l/bnox.profile b/etc/profile-a-l/bnox.profile
index 6e8f0d7d1..dcfd5d8d2 100644
--- a/etc/profile-a-l/bnox.profile
+++ b/etc/profile-a-l/bnox.profile
@@ -10,13 +10,13 @@ ignore whitelist /usr/share/chromium
10ignore include whitelist-runuser-common.inc 10ignore include whitelist-runuser-common.inc
11ignore include whitelist-usr-share-common.inc 11ignore include whitelist-usr-share-common.inc
12 12
13noblacklist ${HOME}/.cache/bnox 13nodeny ${HOME}/.cache/bnox
14noblacklist ${HOME}/.config/bnox 14nodeny ${HOME}/.config/bnox
15 15
16mkdir ${HOME}/.cache/bnox 16mkdir ${HOME}/.cache/bnox
17mkdir ${HOME}/.config/bnox 17mkdir ${HOME}/.config/bnox
18whitelist ${HOME}/.cache/bnox 18allow ${HOME}/.cache/bnox
19whitelist ${HOME}/.config/bnox 19allow ${HOME}/.config/bnox
20 20
21# Redirect 21# Redirect
22include chromium-common.profile 22include chromium-common.profile
diff --git a/etc/profile-a-l/brackets.profile b/etc/profile-a-l/brackets.profile
index 0cbac049a..a14bb8fef 100644
--- a/etc/profile-a-l/brackets.profile
+++ b/etc/profile-a-l/brackets.profile
@@ -5,7 +5,7 @@ include brackets.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${HOME}/.config/Brackets 8nodeny ${HOME}/.config/Brackets
9#noblacklist /opt/brackets 9#noblacklist /opt/brackets
10#noblacklist /opt/google 10#noblacklist /opt/google
11 11
diff --git a/etc/profile-a-l/brasero.profile b/etc/profile-a-l/brasero.profile
index 417a6b3e0..a78882409 100644
--- a/etc/profile-a-l/brasero.profile
+++ b/etc/profile-a-l/brasero.profile
@@ -6,7 +6,7 @@ include brasero.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/brasero 9nodeny ${HOME}/.config/brasero
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
diff --git a/etc/profile-a-l/brave.profile b/etc/profile-a-l/brave.profile
index 09548c761..bc2d7a6a1 100644
--- a/etc/profile-a-l/brave.profile
+++ b/etc/profile-a-l/brave.profile
@@ -14,24 +14,24 @@ ignore noexec /tmp
14# Alternatively you can add 'ignore apparmor' to your brave.local. 14# Alternatively you can add 'ignore apparmor' to your brave.local.
15ignore noexec ${HOME} 15ignore noexec ${HOME}
16 16
17noblacklist ${HOME}/.cache/BraveSoftware 17nodeny ${HOME}/.cache/BraveSoftware
18noblacklist ${HOME}/.config/BraveSoftware 18nodeny ${HOME}/.config/BraveSoftware
19noblacklist ${HOME}/.config/brave 19nodeny ${HOME}/.config/brave
20noblacklist ${HOME}/.config/brave-flags.conf 20nodeny ${HOME}/.config/brave-flags.conf
21# brave uses gpg for built-in password manager 21# brave uses gpg for built-in password manager
22noblacklist ${HOME}/.gnupg 22nodeny ${HOME}/.gnupg
23 23
24mkdir ${HOME}/.cache/BraveSoftware 24mkdir ${HOME}/.cache/BraveSoftware
25mkdir ${HOME}/.config/BraveSoftware 25mkdir ${HOME}/.config/BraveSoftware
26mkdir ${HOME}/.config/brave 26mkdir ${HOME}/.config/brave
27whitelist ${HOME}/.cache/BraveSoftware 27allow ${HOME}/.cache/BraveSoftware
28whitelist ${HOME}/.config/BraveSoftware 28allow ${HOME}/.config/BraveSoftware
29whitelist ${HOME}/.config/brave 29allow ${HOME}/.config/brave
30whitelist ${HOME}/.config/brave-flags.conf 30allow ${HOME}/.config/brave-flags.conf
31whitelist ${HOME}/.gnupg 31allow ${HOME}/.gnupg
32 32
33# Brave sandbox needs read access to /proc/config.gz 33# Brave sandbox needs read access to /proc/config.gz
34noblacklist /proc/config.gz 34nodeny /proc/config.gz
35 35
36# Redirect 36# Redirect
37include chromium-common.profile 37include chromium-common.profile
diff --git a/etc/profile-a-l/bzflag.profile b/etc/profile-a-l/bzflag.profile
index bda96bbb3..62ca041c2 100644
--- a/etc/profile-a-l/bzflag.profile
+++ b/etc/profile-a-l/bzflag.profile
@@ -6,7 +6,7 @@ include bzflag.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.bzf 9nodeny ${HOME}/.bzf
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -18,7 +18,7 @@ include disable-shell.inc
18include disable-xdg.inc 18include disable-xdg.inc
19 19
20mkdir ${HOME}/.bzf 20mkdir ${HOME}/.bzf
21whitelist ${HOME}/.bzf 21allow ${HOME}/.bzf
22include whitelist-common.inc 22include whitelist-common.inc
23include whitelist-var-common.inc 23include whitelist-var-common.inc
24 24
diff --git a/etc/profile-a-l/calibre.profile b/etc/profile-a-l/calibre.profile
index 83571397b..99706620c 100644
--- a/etc/profile-a-l/calibre.profile
+++ b/etc/profile-a-l/calibre.profile
@@ -6,9 +6,9 @@ include calibre.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.cache/calibre 9nodeny ${HOME}/.cache/calibre
10noblacklist ${HOME}/.config/calibre 10nodeny ${HOME}/.config/calibre
11noblacklist ${DOCUMENTS} 11nodeny ${DOCUMENTS}
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
diff --git a/etc/profile-a-l/calligra.profile b/etc/profile-a-l/calligra.profile
index fcff47662..36ecc06a0 100644
--- a/etc/profile-a-l/calligra.profile
+++ b/etc/profile-a-l/calligra.profile
@@ -6,7 +6,7 @@ include calligra.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.local/share/kxmlgui5/calligra 9nodeny ${HOME}/.local/share/kxmlgui5/calligra
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
diff --git a/etc/profile-a-l/calligragemini.profile b/etc/profile-a-l/calligragemini.profile
index 006c307ab..76123c96a 100644
--- a/etc/profile-a-l/calligragemini.profile
+++ b/etc/profile-a-l/calligragemini.profile
@@ -6,7 +6,7 @@ include calligragemini.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.local/share/calligragemini 9nodeny ${HOME}/.local/share/calligragemini
10 10
11# Redirect 11# Redirect
12include calligra.profile 12include calligra.profile
diff --git a/etc/profile-a-l/calligraplan.profile b/etc/profile-a-l/calligraplan.profile
index 81dbd4dcd..5fb1e16da 100644
--- a/etc/profile-a-l/calligraplan.profile
+++ b/etc/profile-a-l/calligraplan.profile
@@ -6,7 +6,7 @@ include calligraplan.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.local/share/kxmlgui5/calligraplan 9nodeny ${HOME}/.local/share/kxmlgui5/calligraplan
10 10
11# Redirect 11# Redirect
12include calligra.profile 12include calligra.profile
diff --git a/etc/profile-a-l/calligraplanwork.profile b/etc/profile-a-l/calligraplanwork.profile
index bba91b66b..c176bfea1 100644
--- a/etc/profile-a-l/calligraplanwork.profile
+++ b/etc/profile-a-l/calligraplanwork.profile
@@ -6,7 +6,7 @@ include calligraplanwork.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.local/share/kxmlgui5/calligraplanwork 9nodeny ${HOME}/.local/share/kxmlgui5/calligraplanwork
10 10
11# Redirect 11# Redirect
12include calligra.profile 12include calligra.profile
diff --git a/etc/profile-a-l/calligrasheets.profile b/etc/profile-a-l/calligrasheets.profile
index 7bc296047..b7ac68945 100644
--- a/etc/profile-a-l/calligrasheets.profile
+++ b/etc/profile-a-l/calligrasheets.profile
@@ -6,7 +6,7 @@ include calligrasheets.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.local/share/kxmlgui5/calligrasheets 9nodeny ${HOME}/.local/share/kxmlgui5/calligrasheets
10 10
11# Redirect 11# Redirect
12include calligra.profile 12include calligra.profile
diff --git a/etc/profile-a-l/calligrastage.profile b/etc/profile-a-l/calligrastage.profile
index 7694abbe4..1258fec56 100644
--- a/etc/profile-a-l/calligrastage.profile
+++ b/etc/profile-a-l/calligrastage.profile
@@ -6,7 +6,7 @@ include calligrastage.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.local/share/kxmlgui5/calligrastage 9nodeny ${HOME}/.local/share/kxmlgui5/calligrastage
10 10
11# Redirect 11# Redirect
12include calligra.profile 12include calligra.profile
diff --git a/etc/profile-a-l/calligrawords.profile b/etc/profile-a-l/calligrawords.profile
index d69d56a95..c2b6c8041 100644
--- a/etc/profile-a-l/calligrawords.profile
+++ b/etc/profile-a-l/calligrawords.profile
@@ -6,7 +6,7 @@ include calligrawords.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.local/share/kxmlgui5/calligrawords 9nodeny ${HOME}/.local/share/kxmlgui5/calligrawords
10 10
11# Redirect 11# Redirect
12include calligra.profile 12include calligra.profile
diff --git a/etc/profile-a-l/cameramonitor.profile b/etc/profile-a-l/cameramonitor.profile
index 74c7cc34b..390ae383c 100644
--- a/etc/profile-a-l/cameramonitor.profile
+++ b/etc/profile-a-l/cameramonitor.profile
@@ -20,7 +20,7 @@ include disable-programs.inc
20include disable-shell.inc 20include disable-shell.inc
21include disable-xdg.inc 21include disable-xdg.inc
22 22
23whitelist /usr/share/cameramonitor 23allow /usr/share/cameramonitor
24include whitelist-common.inc 24include whitelist-common.inc
25include whitelist-usr-share-common.inc 25include whitelist-usr-share-common.inc
26include whitelist-var-common.inc 26include whitelist-var-common.inc
diff --git a/etc/profile-a-l/cantata.profile b/etc/profile-a-l/cantata.profile
index 96f88a7c4..77bdc09e0 100644
--- a/etc/profile-a-l/cantata.profile
+++ b/etc/profile-a-l/cantata.profile
@@ -6,10 +6,10 @@ include cantata.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.cache/cantata 9nodeny ${HOME}/.cache/cantata
10noblacklist ${HOME}/.config/cantata 10nodeny ${HOME}/.config/cantata
11noblacklist ${HOME}/.local/share/cantata 11nodeny ${HOME}/.local/share/cantata
12noblacklist ${MUSIC} 12nodeny ${MUSIC}
13 13
14# Allow perl (blacklisted by disable-interpreters.inc) 14# Allow perl (blacklisted by disable-interpreters.inc)
15include allow-perl.inc 15include allow-perl.inc
diff --git a/etc/profile-a-l/cargo.profile b/etc/profile-a-l/cargo.profile
index 7cf04c550..9c53af84f 100644
--- a/etc/profile-a-l/cargo.profile
+++ b/etc/profile-a-l/cargo.profile
@@ -10,11 +10,11 @@ include globals.local
10ignore noexec ${HOME} 10ignore noexec ${HOME}
11ignore noexec /tmp 11ignore noexec /tmp
12 12
13blacklist /tmp/.X11-unix 13deny /tmp/.X11-unix
14blacklist ${RUNUSER} 14deny ${RUNUSER}
15 15
16noblacklist ${HOME}/.cargo/credentials 16nodeny ${HOME}/.cargo/credentials
17noblacklist ${HOME}/.cargo/credentials.toml 17nodeny ${HOME}/.cargo/credentials.toml
18 18
19# Allows files commonly used by IDEs 19# Allows files commonly used by IDEs
20include allow-common-devel.inc 20include allow-common-devel.inc
@@ -34,7 +34,7 @@ include disable-xdg.inc
34#whitelist ${HOME}/.cargo 34#whitelist ${HOME}/.cargo
35#whitelist ${HOME}/.rustup 35#whitelist ${HOME}/.rustup
36#include whitelist-common.inc 36#include whitelist-common.inc
37whitelist /usr/share/pkgconfig 37allow /usr/share/pkgconfig
38include whitelist-runuser-common.inc 38include whitelist-runuser-common.inc
39include whitelist-usr-share-common.inc 39include whitelist-usr-share-common.inc
40include whitelist-var-common.inc 40include whitelist-var-common.inc
diff --git a/etc/profile-a-l/catfish.profile b/etc/profile-a-l/catfish.profile
index 009d3a049..4ea53ea6b 100644
--- a/etc/profile-a-l/catfish.profile
+++ b/etc/profile-a-l/catfish.profile
@@ -9,7 +9,7 @@ include globals.local
9# We can't blacklist much since catfish 9# We can't blacklist much since catfish
10# is for finding files/content 10# is for finding files/content
11 11
12noblacklist ${HOME}/.config/catfish 12nodeny ${HOME}/.config/catfish
13 13
14# Allow python (blacklisted by disable-interpreters.inc) 14# Allow python (blacklisted by disable-interpreters.inc)
15include allow-python2.inc 15include allow-python2.inc
@@ -21,7 +21,7 @@ include disable-interpreters.inc
21include disable-passwdmgr.inc 21include disable-passwdmgr.inc
22# include disable-programs.inc 22# include disable-programs.inc
23 23
24whitelist /var/lib/mlocate 24allow /var/lib/mlocate
25include whitelist-var-common.inc 25include whitelist-var-common.inc
26 26
27apparmor 27apparmor
diff --git a/etc/profile-a-l/cawbird.profile b/etc/profile-a-l/cawbird.profile
index 6e137010c..d7aee1902 100644
--- a/etc/profile-a-l/cawbird.profile
+++ b/etc/profile-a-l/cawbird.profile
@@ -6,7 +6,7 @@ include cawbird.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/cawbird 9nodeny ${HOME}/.config/cawbird
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
diff --git a/etc/profile-a-l/celluloid.profile b/etc/profile-a-l/celluloid.profile
index 1c539cc93..d6f4306ba 100644
--- a/etc/profile-a-l/celluloid.profile
+++ b/etc/profile-a-l/celluloid.profile
@@ -6,9 +6,9 @@ include celluloid.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/celluloid 9nodeny ${HOME}/.config/celluloid
10noblacklist ${HOME}/.config/gnome-mpv 10nodeny ${HOME}/.config/gnome-mpv
11noblacklist ${HOME}/.config/youtube-dl 11nodeny ${HOME}/.config/youtube-dl
12 12
13# Allow lua (blacklisted by disable-interpreters.inc) 13# Allow lua (blacklisted by disable-interpreters.inc)
14include allow-lua.inc 14include allow-lua.inc
@@ -17,7 +17,7 @@ include allow-lua.inc
17include allow-python2.inc 17include allow-python2.inc
18include allow-python3.inc 18include allow-python3.inc
19 19
20blacklist /usr/libexec 20deny /usr/libexec
21 21
22include disable-common.inc 22include disable-common.inc
23include disable-devel.inc 23include disable-devel.inc
@@ -30,9 +30,9 @@ read-only ${DESKTOP}
30mkdir ${HOME}/.config/celluloid 30mkdir ${HOME}/.config/celluloid
31mkdir ${HOME}/.config/gnome-mpv 31mkdir ${HOME}/.config/gnome-mpv
32mkdir ${HOME}/.config/youtube-dl 32mkdir ${HOME}/.config/youtube-dl
33whitelist ${HOME}/.config/celluloid 33allow ${HOME}/.config/celluloid
34whitelist ${HOME}/.config/gnome-mpv 34allow ${HOME}/.config/gnome-mpv
35whitelist ${HOME}/.config/youtube-dl 35allow ${HOME}/.config/youtube-dl
36include whitelist-common.inc 36include whitelist-common.inc
37include whitelist-player-common.inc 37include whitelist-player-common.inc
38include whitelist-runuser-common.inc 38include whitelist-runuser-common.inc
diff --git a/etc/profile-a-l/checkbashisms.profile b/etc/profile-a-l/checkbashisms.profile
index 24939fc70..0f61084e0 100644
--- a/etc/profile-a-l/checkbashisms.profile
+++ b/etc/profile-a-l/checkbashisms.profile
@@ -7,9 +7,9 @@ include checkbashisms.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10blacklist ${RUNUSER}/wayland-* 10deny ${RUNUSER}/wayland-*
11 11
12noblacklist ${DOCUMENTS} 12nodeny ${DOCUMENTS}
13 13
14# Allow perl (blacklisted by disable-interpreters.inc) 14# Allow perl (blacklisted by disable-interpreters.inc)
15include allow-perl.inc 15include allow-perl.inc
diff --git a/etc/profile-a-l/cheese.profile b/etc/profile-a-l/cheese.profile
index aca1f5876..bde3e1311 100644
--- a/etc/profile-a-l/cheese.profile
+++ b/etc/profile-a-l/cheese.profile
@@ -6,8 +6,8 @@ include cheese.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${VIDEOS} 9nodeny ${VIDEOS}
10noblacklist ${PICTURES} 10nodeny ${PICTURES}
11 11
12include disable-common.inc 12include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
@@ -17,9 +17,9 @@ include disable-passwdmgr.inc
17include disable-programs.inc 17include disable-programs.inc
18include disable-xdg.inc 18include disable-xdg.inc
19 19
20whitelist ${VIDEOS} 20allow ${VIDEOS}
21whitelist ${PICTURES} 21allow ${PICTURES}
22whitelist /usr/share/gnome-video-effects 22allow /usr/share/gnome-video-effects
23include whitelist-common.inc 23include whitelist-common.inc
24include whitelist-runuser-common.inc 24include whitelist-runuser-common.inc
25include whitelist-usr-share-common.inc 25include whitelist-usr-share-common.inc
diff --git a/etc/profile-a-l/cherrytree.profile b/etc/profile-a-l/cherrytree.profile
index 7621b3c8c..d5dedd81d 100644
--- a/etc/profile-a-l/cherrytree.profile
+++ b/etc/profile-a-l/cherrytree.profile
@@ -6,8 +6,8 @@ include cherrytree.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/cherrytree 9nodeny ${HOME}/.config/cherrytree
10noblacklist ${DOCUMENTS} 10nodeny ${DOCUMENTS}
11 11
12# Allow python (blacklisted by disable-interpreters.inc) 12# Allow python (blacklisted by disable-interpreters.inc)
13include allow-python2.inc 13include allow-python2.inc
diff --git a/etc/profile-a-l/chromium-browser-privacy.profile b/etc/profile-a-l/chromium-browser-privacy.profile
index 8803a4d9d..64c45772a 100644
--- a/etc/profile-a-l/chromium-browser-privacy.profile
+++ b/etc/profile-a-l/chromium-browser-privacy.profile
@@ -3,15 +3,15 @@
3# Persistent local customizations 3# Persistent local customizations
4include chromium-browser-privacy.local 4include chromium-browser-privacy.local
5 5
6noblacklist ${HOME}/.cache/ungoogled-chromium 6nodeny ${HOME}/.cache/ungoogled-chromium
7noblacklist ${HOME}/.config/ungoogled-chromium 7nodeny ${HOME}/.config/ungoogled-chromium
8 8
9blacklist /usr/libexec 9deny /usr/libexec
10 10
11mkdir ${HOME}/.cache/ungoogled-chromium 11mkdir ${HOME}/.cache/ungoogled-chromium
12mkdir ${HOME}/.config/ungoogled-chromium 12mkdir ${HOME}/.config/ungoogled-chromium
13whitelist ${HOME}/.cache/ungoogled-chromium 13allow ${HOME}/.cache/ungoogled-chromium
14whitelist ${HOME}/.config/ungoogled-chromium 14allow ${HOME}/.config/ungoogled-chromium
15 15
16# private-bin basename,bash,cat,chromium-browser-privacy,dirname,mkdir,readlink,sed,touch,which,xdg-settings 16# private-bin basename,bash,cat,chromium-browser-privacy,dirname,mkdir,readlink,sed,touch,which,xdg-settings
17 17
diff --git a/etc/profile-a-l/chromium-common.profile b/etc/profile-a-l/chromium-common.profile
index b0e0254d4..dbeb715d4 100644
--- a/etc/profile-a-l/chromium-common.profile
+++ b/etc/profile-a-l/chromium-common.profile
@@ -9,8 +9,8 @@ include chromium-common.local
9# noexec ${HOME} breaks DRM binaries. 9# noexec ${HOME} breaks DRM binaries.
10?BROWSER_ALLOW_DRM: ignore noexec ${HOME} 10?BROWSER_ALLOW_DRM: ignore noexec ${HOME}
11 11
12noblacklist ${HOME}/.pki 12nodeny ${HOME}/.pki
13noblacklist ${HOME}/.local/share/pki 13nodeny ${HOME}/.local/share/pki
14 14
15# Add the next line to your chromium-common.local if you want Google Chrome/Chromium browser 15# Add the next line to your chromium-common.local if you want Google Chrome/Chromium browser
16# to have access to Gnome extensions (extensions.gnome.org) via browser connector 16# to have access to Gnome extensions (extensions.gnome.org) via browser connector
@@ -26,9 +26,9 @@ include disable-xdg.inc
26 26
27mkdir ${HOME}/.pki 27mkdir ${HOME}/.pki
28mkdir ${HOME}/.local/share/pki 28mkdir ${HOME}/.local/share/pki
29whitelist ${DOWNLOADS} 29allow ${DOWNLOADS}
30whitelist ${HOME}/.pki 30allow ${HOME}/.pki
31whitelist ${HOME}/.local/share/pki 31allow ${HOME}/.local/share/pki
32include whitelist-common.inc 32include whitelist-common.inc
33include whitelist-runuser-common.inc 33include whitelist-runuser-common.inc
34include whitelist-usr-share-common.inc 34include whitelist-usr-share-common.inc
diff --git a/etc/profile-a-l/chromium.profile b/etc/profile-a-l/chromium.profile
index 9ac33aa1c..ea92e90a8 100644
--- a/etc/profile-a-l/chromium.profile
+++ b/etc/profile-a-l/chromium.profile
@@ -6,17 +6,17 @@ include chromium.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.cache/chromium 9nodeny ${HOME}/.cache/chromium
10noblacklist ${HOME}/.config/chromium 10nodeny ${HOME}/.config/chromium
11noblacklist ${HOME}/.config/chromium-flags.conf 11nodeny ${HOME}/.config/chromium-flags.conf
12 12
13mkdir ${HOME}/.cache/chromium 13mkdir ${HOME}/.cache/chromium
14mkdir ${HOME}/.config/chromium 14mkdir ${HOME}/.config/chromium
15whitelist ${HOME}/.cache/chromium 15allow ${HOME}/.cache/chromium
16whitelist ${HOME}/.config/chromium 16allow ${HOME}/.config/chromium
17whitelist ${HOME}/.config/chromium-flags.conf 17allow ${HOME}/.config/chromium-flags.conf
18whitelist /usr/share/chromium 18allow /usr/share/chromium
19whitelist /usr/share/mozilla/extensions 19allow /usr/share/mozilla/extensions
20 20
21# private-bin chromium,chromium-browser,chromedriver 21# private-bin chromium,chromium-browser,chromedriver
22 22
diff --git a/etc/profile-a-l/cin.profile b/etc/profile-a-l/cin.profile
index e1f9523c4..c967e1c96 100644
--- a/etc/profile-a-l/cin.profile
+++ b/etc/profile-a-l/cin.profile
@@ -5,7 +5,7 @@ include cin.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${HOME}/.bcast5 8nodeny ${HOME}/.bcast5
9 9
10include disable-common.inc 10include disable-common.inc
11include disable-devel.inc 11include disable-devel.inc
diff --git a/etc/profile-a-l/clamav.profile b/etc/profile-a-l/clamav.profile
index e403c2c41..0efbcd4f2 100644
--- a/etc/profile-a-l/clamav.profile
+++ b/etc/profile-a-l/clamav.profile
@@ -7,7 +7,7 @@ include clamav.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10blacklist ${RUNUSER}/wayland-* 10deny ${RUNUSER}/wayland-*
11 11
12include disable-exec.inc 12include disable-exec.inc
13 13
diff --git a/etc/profile-a-l/claws-mail.profile b/etc/profile-a-l/claws-mail.profile
index 691657fa0..3e4e1f2a1 100644
--- a/etc/profile-a-l/claws-mail.profile
+++ b/etc/profile-a-l/claws-mail.profile
@@ -6,17 +6,17 @@ include claws-mail.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.claws-mail 9nodeny ${HOME}/.claws-mail
10 10
11mkdir ${HOME}/.claws-mail 11mkdir ${HOME}/.claws-mail
12whitelist ${HOME}/.claws-mail 12allow ${HOME}/.claws-mail
13 13
14# Add the below lines to your claws-mail.local if you use python-based plugins. 14# Add the below lines to your claws-mail.local if you use python-based plugins.
15# Allow python (blacklisted by disable-interpreters.inc) 15# Allow python (blacklisted by disable-interpreters.inc)
16#include allow-python2.inc 16#include allow-python2.inc
17#include allow-python3.inc 17#include allow-python3.inc
18 18
19whitelist /usr/share/doc/claws-mail 19allow /usr/share/doc/claws-mail
20 20
21# private-bin claws-mail,curl,gpg,gpg2,gpg-agent,gpgsm,gpgme-config,pinentry,pinentry-gtk-2 21# private-bin claws-mail,curl,gpg,gpg2,gpg-agent,gpgsm,gpgme-config,pinentry,pinentry-gtk-2
22 22
diff --git a/etc/profile-a-l/clawsker.profile b/etc/profile-a-l/clawsker.profile
index 9b62a1f73..ee64391d9 100644
--- a/etc/profile-a-l/clawsker.profile
+++ b/etc/profile-a-l/clawsker.profile
@@ -6,7 +6,7 @@ include clawsker.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.claws-mail 9nodeny ${HOME}/.claws-mail
10 10
11# Allow perl (blacklisted by disable-interpreters.inc) 11# Allow perl (blacklisted by disable-interpreters.inc)
12include allow-perl.inc 12include allow-perl.inc
@@ -19,7 +19,7 @@ include disable-passwdmgr.inc
19include disable-programs.inc 19include disable-programs.inc
20 20
21mkdir ${HOME}/.claws-mail 21mkdir ${HOME}/.claws-mail
22whitelist ${HOME}/.claws-mail 22allow ${HOME}/.claws-mail
23include whitelist-common.inc 23include whitelist-common.inc
24include whitelist-usr-share-common.inc 24include whitelist-usr-share-common.inc
25include whitelist-var-common.inc 25include whitelist-var-common.inc
diff --git a/etc/profile-a-l/clementine.profile b/etc/profile-a-l/clementine.profile
index fa33795c1..f9c0006f9 100644
--- a/etc/profile-a-l/clementine.profile
+++ b/etc/profile-a-l/clementine.profile
@@ -6,9 +6,9 @@ include clementine.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.cache/Clementine 9nodeny ${HOME}/.cache/Clementine
10noblacklist ${HOME}/.config/Clementine 10nodeny ${HOME}/.config/Clementine
11noblacklist ${MUSIC} 11nodeny ${MUSIC}
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
diff --git a/etc/profile-a-l/clion.profile b/etc/profile-a-l/clion.profile
index 22cecff09..42903777a 100644
--- a/etc/profile-a-l/clion.profile
+++ b/etc/profile-a-l/clion.profile
@@ -5,13 +5,13 @@ include clion.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${HOME}/.CLion* 8nodeny ${HOME}/.CLion*
9noblacklist ${HOME}/.config/git 9nodeny ${HOME}/.config/git
10noblacklist ${HOME}/.gitconfig 10nodeny ${HOME}/.gitconfig
11noblacklist ${HOME}/.git-credentials 11nodeny ${HOME}/.git-credentials
12noblacklist ${HOME}/.java 12nodeny ${HOME}/.java
13noblacklist ${HOME}/.local/share/JetBrains 13nodeny ${HOME}/.local/share/JetBrains
14noblacklist ${HOME}/.tooling 14nodeny ${HOME}/.tooling
15 15
16# Allow ssh (blacklisted by disable-common.inc) 16# Allow ssh (blacklisted by disable-common.inc)
17include allow-ssh.inc 17include allow-ssh.inc
diff --git a/etc/profile-a-l/clipgrab.profile b/etc/profile-a-l/clipgrab.profile
index c8258da07..89f8d96f0 100644
--- a/etc/profile-a-l/clipgrab.profile
+++ b/etc/profile-a-l/clipgrab.profile
@@ -6,9 +6,9 @@ include clipgrab.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/Philipp Schmieder 9nodeny ${HOME}/.config/Philipp Schmieder
10noblacklist ${HOME}/.pki 10nodeny ${HOME}/.pki
11noblacklist ${VIDEOS} 11nodeny ${VIDEOS}
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
diff --git a/etc/profile-a-l/clipit.profile b/etc/profile-a-l/clipit.profile
index d421903a3..4a2a5171b 100644
--- a/etc/profile-a-l/clipit.profile
+++ b/etc/profile-a-l/clipit.profile
@@ -6,8 +6,8 @@ include clipit.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/clipit 9nodeny ${HOME}/.config/clipit
10noblacklist ${HOME}/.local/share/clipit 10nodeny ${HOME}/.local/share/clipit
11 11
12include disable-common.inc 12include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
@@ -19,8 +19,8 @@ include disable-xdg.inc
19 19
20mkdir ${HOME}/.config/clipit 20mkdir ${HOME}/.config/clipit
21mkdir ${HOME}/.local/share/clipit 21mkdir ${HOME}/.local/share/clipit
22whitelist ${HOME}/.config/clipit 22allow ${HOME}/.config/clipit
23whitelist ${HOME}/.local/share/clipit 23allow ${HOME}/.local/share/clipit
24include whitelist-common.inc 24include whitelist-common.inc
25include whitelist-usr-share-common.inc 25include whitelist-usr-share-common.inc
26include whitelist-var-common.inc 26include whitelist-var-common.inc
diff --git a/etc/profile-a-l/cliqz.profile b/etc/profile-a-l/cliqz.profile
index d0b8cc0ef..22c6ef882 100644
--- a/etc/profile-a-l/cliqz.profile
+++ b/etc/profile-a-l/cliqz.profile
@@ -5,16 +5,16 @@ include cliqz.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${HOME}/.cache/cliqz 8nodeny ${HOME}/.cache/cliqz
9noblacklist ${HOME}/.cliqz 9nodeny ${HOME}/.cliqz
10noblacklist ${HOME}/.config/cliqz 10nodeny ${HOME}/.config/cliqz
11 11
12mkdir ${HOME}/.cache/cliqz 12mkdir ${HOME}/.cache/cliqz
13mkdir ${HOME}/.cliqz 13mkdir ${HOME}/.cliqz
14mkdir ${HOME}/.config/cliqz 14mkdir ${HOME}/.config/cliqz
15whitelist ${HOME}/.cache/cliqz 15allow ${HOME}/.cache/cliqz
16whitelist ${HOME}/.cliqz 16allow ${HOME}/.cliqz
17whitelist ${HOME}/.config/cliqz 17allow ${HOME}/.config/cliqz
18 18
19# private-etc must first be enabled in firefox-common.profile 19# private-etc must first be enabled in firefox-common.profile
20#private-etc cliqz 20#private-etc cliqz
diff --git a/etc/profile-a-l/cmus.profile b/etc/profile-a-l/cmus.profile
index bcd557787..51e53209f 100644
--- a/etc/profile-a-l/cmus.profile
+++ b/etc/profile-a-l/cmus.profile
@@ -6,8 +6,8 @@ include cmus.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/cmus 9nodeny ${HOME}/.config/cmus
10noblacklist ${MUSIC} 10nodeny ${MUSIC}
11 11
12include disable-common.inc 12include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
diff --git a/etc/profile-a-l/code.profile b/etc/profile-a-l/code.profile
index e19b78908..1933c66fa 100644
--- a/etc/profile-a-l/code.profile
+++ b/etc/profile-a-l/code.profile
@@ -5,10 +5,10 @@ include code.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${HOME}/.config/Code 8nodeny ${HOME}/.config/Code
9noblacklist ${HOME}/.config/Code - OSS 9nodeny ${HOME}/.config/Code - OSS
10noblacklist ${HOME}/.vscode 10nodeny ${HOME}/.vscode
11noblacklist ${HOME}/.vscode-oss 11nodeny ${HOME}/.vscode-oss
12 12
13# Allows files commonly used by IDEs 13# Allows files commonly used by IDEs
14include allow-common-devel.inc 14include allow-common-devel.inc
diff --git a/etc/profile-a-l/colorful.profile b/etc/profile-a-l/colorful.profile
index bd6d8f5b0..efa7f516c 100644
--- a/etc/profile-a-l/colorful.profile
+++ b/etc/profile-a-l/colorful.profile
@@ -6,7 +6,7 @@ include colorful.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.suve/colorful 9nodeny ${HOME}/.suve/colorful
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -18,8 +18,8 @@ include disable-shell.inc
18include disable-xdg.inc 18include disable-xdg.inc
19 19
20mkdir ${HOME}/.suve/colorful 20mkdir ${HOME}/.suve/colorful
21whitelist ${HOME}/.suve/colorful 21allow ${HOME}/.suve/colorful
22whitelist /usr/share/suve 22allow /usr/share/suve
23include whitelist-common.inc 23include whitelist-common.inc
24include whitelist-runuser-common.inc 24include whitelist-runuser-common.inc
25include whitelist-usr-share-common.inc 25include whitelist-usr-share-common.inc
diff --git a/etc/profile-a-l/com.github.bleakgrey.tootle.profile b/etc/profile-a-l/com.github.bleakgrey.tootle.profile
index c8bdfec23..34b662959 100644
--- a/etc/profile-a-l/com.github.bleakgrey.tootle.profile
+++ b/etc/profile-a-l/com.github.bleakgrey.tootle.profile
@@ -6,7 +6,7 @@ include com.github.bleakgrey.tootle.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/com.github.bleakgrey.tootle 9nodeny ${HOME}/.config/com.github.bleakgrey.tootle
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -18,8 +18,8 @@ include disable-shell.inc
18include disable-xdg.inc 18include disable-xdg.inc
19 19
20mkdir ${HOME}/.config/com.github.bleakgrey.tootle 20mkdir ${HOME}/.config/com.github.bleakgrey.tootle
21whitelist ${DOWNLOADS} 21allow ${DOWNLOADS}
22whitelist ${HOME}/.config/com.github.bleakgrey.tootle 22allow ${HOME}/.config/com.github.bleakgrey.tootle
23include whitelist-common.inc 23include whitelist-common.inc
24include whitelist-runuser-common.inc 24include whitelist-runuser-common.inc
25include whitelist-usr-share-common.inc 25include whitelist-usr-share-common.inc
diff --git a/etc/profile-a-l/com.github.dahenson.agenda.profile b/etc/profile-a-l/com.github.dahenson.agenda.profile
index b467a0f7a..4e26e4925 100644
--- a/etc/profile-a-l/com.github.dahenson.agenda.profile
+++ b/etc/profile-a-l/com.github.dahenson.agenda.profile
@@ -6,9 +6,9 @@ include com.github.dahenson.agenda.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.cache/agenda 9nodeny ${HOME}/.cache/agenda
10noblacklist ${HOME}/.config/agenda 10nodeny ${HOME}/.config/agenda
11noblacklist ${HOME}/.local/share/agenda 11nodeny ${HOME}/.local/share/agenda
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
@@ -22,9 +22,9 @@ include disable-xdg.inc
22mkdir ${HOME}/.cache/agenda 22mkdir ${HOME}/.cache/agenda
23mkdir ${HOME}/.config/agenda 23mkdir ${HOME}/.config/agenda
24mkdir ${HOME}/.local/share/agenda 24mkdir ${HOME}/.local/share/agenda
25whitelist ${HOME}/.cache/agenda 25allow ${HOME}/.cache/agenda
26whitelist ${HOME}/.config/agenda 26allow ${HOME}/.config/agenda
27whitelist ${HOME}/.local/share/agenda 27allow ${HOME}/.local/share/agenda
28include whitelist-common.inc 28include whitelist-common.inc
29include whitelist-usr-share-common.inc 29include whitelist-usr-share-common.inc
30include whitelist-runuser-common.inc 30include whitelist-runuser-common.inc
diff --git a/etc/profile-a-l/com.github.johnfactotum.Foliate.profile b/etc/profile-a-l/com.github.johnfactotum.Foliate.profile
index c13f9618b..bbfc1fe41 100644
--- a/etc/profile-a-l/com.github.johnfactotum.Foliate.profile
+++ b/etc/profile-a-l/com.github.johnfactotum.Foliate.profile
@@ -6,9 +6,9 @@ include foliate.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${DOCUMENTS} 9nodeny ${DOCUMENTS}
10noblacklist ${HOME}/.cache/com.github.johnfactotum.Foliate 10nodeny ${HOME}/.cache/com.github.johnfactotum.Foliate
11noblacklist ${HOME}/.local/share/com.github.johnfactotum.Foliate 11nodeny ${HOME}/.local/share/com.github.johnfactotum.Foliate
12 12
13# Allow gjs (blacklisted by disable-interpreters.inc) 13# Allow gjs (blacklisted by disable-interpreters.inc)
14include allow-gjs.inc 14include allow-gjs.inc
@@ -24,12 +24,12 @@ include disable-xdg.inc
24 24
25mkdir ${HOME}/.cache/com.github.johnfactotum.Foliate 25mkdir ${HOME}/.cache/com.github.johnfactotum.Foliate
26mkdir ${HOME}/.local/share/com.github.johnfactotum.Foliate 26mkdir ${HOME}/.local/share/com.github.johnfactotum.Foliate
27whitelist ${HOME}/.cache/com.github.johnfactotum.Foliate 27allow ${HOME}/.cache/com.github.johnfactotum.Foliate
28whitelist ${HOME}/.local/share/com.github.johnfactotum.Foliate 28allow ${HOME}/.local/share/com.github.johnfactotum.Foliate
29whitelist ${DOCUMENTS} 29allow ${DOCUMENTS}
30whitelist ${DOWNLOADS} 30allow ${DOWNLOADS}
31whitelist /usr/share/com.github.johnfactotum.Foliate 31allow /usr/share/com.github.johnfactotum.Foliate
32whitelist /usr/share/hyphen 32allow /usr/share/hyphen
33include whitelist-common.inc 33include whitelist-common.inc
34include whitelist-usr-share-common.inc 34include whitelist-usr-share-common.inc
35include whitelist-var-common.inc 35include whitelist-var-common.inc
diff --git a/etc/profile-a-l/com.github.phase1geo.minder.profile b/etc/profile-a-l/com.github.phase1geo.minder.profile
index d0402d188..3e9acc6c8 100644
--- a/etc/profile-a-l/com.github.phase1geo.minder.profile
+++ b/etc/profile-a-l/com.github.phase1geo.minder.profile
@@ -6,9 +6,9 @@ include com.github.phase1geo.minder.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.local/share/minder 9nodeny ${HOME}/.local/share/minder
10noblacklist ${DOCUMENTS} 10nodeny ${DOCUMENTS}
11noblacklist ${PICTURES} 11nodeny ${PICTURES}
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
@@ -20,10 +20,10 @@ include disable-shell.inc
20include disable-xdg.inc 20include disable-xdg.inc
21 21
22mkdir ${HOME}/.local/share/minder 22mkdir ${HOME}/.local/share/minder
23whitelist ${HOME}/.local/share/minder 23allow ${HOME}/.local/share/minder
24whitelist ${DOCUMENTS} 24allow ${DOCUMENTS}
25whitelist ${DOWNLOADS} 25allow ${DOWNLOADS}
26whitelist ${PICTURES} 26allow ${PICTURES}
27include whitelist-common.inc 27include whitelist-common.inc
28include whitelist-runuser-common.inc 28include whitelist-runuser-common.inc
29include whitelist-usr-share-common.inc 29include whitelist-usr-share-common.inc
diff --git a/etc/profile-a-l/conkeror.profile b/etc/profile-a-l/conkeror.profile
index 38edf0d21..6cc9ec551 100644
--- a/etc/profile-a-l/conkeror.profile
+++ b/etc/profile-a-l/conkeror.profile
@@ -5,23 +5,23 @@ include conkeror.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${HOME}/.conkeror.mozdev.org 8nodeny ${HOME}/.conkeror.mozdev.org
9 9
10include disable-common.inc 10include disable-common.inc
11include disable-programs.inc 11include disable-programs.inc
12 12
13mkdir ${HOME}/.conkeror.mozdev.org 13mkdir ${HOME}/.conkeror.mozdev.org
14mkfile ${HOME}/.conkerorrc 14mkfile ${HOME}/.conkerorrc
15whitelist ${HOME}/.conkeror.mozdev.org 15allow ${HOME}/.conkeror.mozdev.org
16whitelist ${HOME}/.conkerorrc 16allow ${HOME}/.conkerorrc
17whitelist ${HOME}/.lastpass 17allow ${HOME}/.lastpass
18whitelist ${HOME}/.pentadactyl 18allow ${HOME}/.pentadactyl
19whitelist ${HOME}/.pentadactylrc 19allow ${HOME}/.pentadactylrc
20whitelist ${HOME}/.vimperator 20allow ${HOME}/.vimperator
21whitelist ${HOME}/.vimperatorrc 21allow ${HOME}/.vimperatorrc
22whitelist ${HOME}/.zotero 22allow ${HOME}/.zotero
23whitelist ${HOME}/dwhelper 23allow ${HOME}/dwhelper
24whitelist ${DOWNLOADS} 24allow ${DOWNLOADS}
25include whitelist-common.inc 25include whitelist-common.inc
26 26
27caps.drop all 27caps.drop all
diff --git a/etc/profile-a-l/conky.profile b/etc/profile-a-l/conky.profile
index eaa18739d..1b3fe6651 100644
--- a/etc/profile-a-l/conky.profile
+++ b/etc/profile-a-l/conky.profile
@@ -6,7 +6,7 @@ include conky.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${PICTURES} 9nodeny ${PICTURES}
10 10
11# Allow lua (blacklisted by disable-interpreters.inc) 11# Allow lua (blacklisted by disable-interpreters.inc)
12include allow-lua.inc 12include allow-lua.inc
diff --git a/etc/profile-a-l/corebird.profile b/etc/profile-a-l/corebird.profile
index 2fb446e2a..266c404ee 100644
--- a/etc/profile-a-l/corebird.profile
+++ b/etc/profile-a-l/corebird.profile
@@ -6,7 +6,7 @@ include corebird.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/corebird 9nodeny ${HOME}/.config/corebird
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
diff --git a/etc/profile-a-l/cower.profile b/etc/profile-a-l/cower.profile
index 1635995dc..0a1353e40 100644
--- a/etc/profile-a-l/cower.profile
+++ b/etc/profile-a-l/cower.profile
@@ -7,8 +7,8 @@ include cower.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10noblacklist ${HOME}/.config/cower 10nodeny ${HOME}/.config/cower
11noblacklist /var/lib/pacman 11nodeny /var/lib/pacman
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
diff --git a/etc/profile-a-l/coyim.profile b/etc/profile-a-l/coyim.profile
index 7ece35c2b..5e48c8022 100644
--- a/etc/profile-a-l/coyim.profile
+++ b/etc/profile-a-l/coyim.profile
@@ -6,7 +6,7 @@ include coyim.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/coyim 9nodeny ${HOME}/.config/coyim
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -18,7 +18,7 @@ include disable-shell.inc
18include disable-xdg.inc 18include disable-xdg.inc
19 19
20mkdir ${HOME}/.config/coyim 20mkdir ${HOME}/.config/coyim
21whitelist ${HOME}/.config/coyim 21allow ${HOME}/.config/coyim
22include whitelist-common.inc 22include whitelist-common.inc
23include whitelist-usr-share-common.inc 23include whitelist-usr-share-common.inc
24include whitelist-runuser-common.inc 24include whitelist-runuser-common.inc
diff --git a/etc/profile-a-l/cpio.profile b/etc/profile-a-l/cpio.profile
index bdc4f21a6..dec8c086b 100644
--- a/etc/profile-a-l/cpio.profile
+++ b/etc/profile-a-l/cpio.profile
@@ -7,8 +7,8 @@ include cpio.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10noblacklist /sbin 10nodeny /sbin
11noblacklist /usr/sbin 11nodeny /usr/sbin
12 12
13# Redirect 13# Redirect
14include archiver-common.profile 14include archiver-common.profile
diff --git a/etc/profile-a-l/crawl.profile b/etc/profile-a-l/crawl.profile
index b10216895..81292c01c 100644
--- a/etc/profile-a-l/crawl.profile
+++ b/etc/profile-a-l/crawl.profile
@@ -6,7 +6,7 @@ include crawl-tiles.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.crawl 9nodeny ${HOME}/.crawl
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -17,7 +17,7 @@ include disable-programs.inc
17include disable-xdg.inc 17include disable-xdg.inc
18 18
19mkdir ${HOME}/.crawl 19mkdir ${HOME}/.crawl
20whitelist ${HOME}/.crawl 20allow ${HOME}/.crawl
21include whitelist-common.inc 21include whitelist-common.inc
22include whitelist-var-common.inc 22include whitelist-var-common.inc
23 23
diff --git a/etc/profile-a-l/crow.profile b/etc/profile-a-l/crow.profile
index 02b15ecc2..36bd93778 100644
--- a/etc/profile-a-l/crow.profile
+++ b/etc/profile-a-l/crow.profile
@@ -8,8 +8,8 @@ include globals.local
8 8
9mkdir ${HOME}/.config/crow 9mkdir ${HOME}/.config/crow
10mkdir ${HOME}/.cache/gstreamer-1.0 10mkdir ${HOME}/.cache/gstreamer-1.0
11whitelist ${HOME}/.config/crow 11allow ${HOME}/.config/crow
12whitelist ${HOME}/.cache/gstreamer-1.0 12allow ${HOME}/.cache/gstreamer-1.0
13 13
14include disable-common.inc 14include disable-common.inc
15include disable-devel.inc 15include disable-devel.inc
diff --git a/etc/profile-a-l/curl.profile b/etc/profile-a-l/curl.profile
index c9867c5d7..4950b7a4c 100644
--- a/etc/profile-a-l/curl.profile
+++ b/etc/profile-a-l/curl.profile
@@ -12,11 +12,11 @@ include globals.local
12# Technically this file can be anywhere but let's assume users have it in ${HOME}/.curl-hsts. 12# Technically this file can be anywhere but let's assume users have it in ${HOME}/.curl-hsts.
13# If your setup diverts, add 'blacklist /path/to/curl/hsts/file' to your disable-programs.local 13# If your setup diverts, add 'blacklist /path/to/curl/hsts/file' to your disable-programs.local
14# and 'noblacklist /path/to/curl/hsts/file' to curl.local to keep the sandbox logic intact. 14# and 'noblacklist /path/to/curl/hsts/file' to curl.local to keep the sandbox logic intact.
15noblacklist ${HOME}/.curl-hsts 15nodeny ${HOME}/.curl-hsts
16noblacklist ${HOME}/.curlrc 16nodeny ${HOME}/.curlrc
17 17
18blacklist /tmp/.X11-unix 18deny /tmp/.X11-unix
19blacklist ${RUNUSER} 19deny ${RUNUSER}
20 20
21include disable-common.inc 21include disable-common.inc
22include disable-exec.inc 22include disable-exec.inc
diff --git a/etc/profile-a-l/cyberfox.profile b/etc/profile-a-l/cyberfox.profile
index d1fff0004..49f972e4a 100644
--- a/etc/profile-a-l/cyberfox.profile
+++ b/etc/profile-a-l/cyberfox.profile
@@ -5,13 +5,13 @@ include cyberfox.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${HOME}/.8pecxstudios 8nodeny ${HOME}/.8pecxstudios
9noblacklist ${HOME}/.cache/8pecxstudios 9nodeny ${HOME}/.cache/8pecxstudios
10 10
11mkdir ${HOME}/.8pecxstudios 11mkdir ${HOME}/.8pecxstudios
12mkdir ${HOME}/.cache/8pecxstudios 12mkdir ${HOME}/.cache/8pecxstudios
13whitelist ${HOME}/.8pecxstudios 13allow ${HOME}/.8pecxstudios
14whitelist ${HOME}/.cache/8pecxstudios 14allow ${HOME}/.cache/8pecxstudios
15 15
16# private-bin cyberfox,dbus-launch,dbus-send,env,sh,which 16# private-bin cyberfox,dbus-launch,dbus-send,env,sh,which
17# private-etc must first be enabled in firefox-common.profile 17# private-etc must first be enabled in firefox-common.profile
diff --git a/etc/profile-a-l/d-feet.profile b/etc/profile-a-l/d-feet.profile
index ba1e7adad..c7ce1730a 100644
--- a/etc/profile-a-l/d-feet.profile
+++ b/etc/profile-a-l/d-feet.profile
@@ -6,7 +6,7 @@ include d-feet.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/d-feet 9nodeny ${HOME}/.config/d-feet
10 10
11# Allow python (disabled by disable-interpreters.inc) 11# Allow python (disabled by disable-interpreters.inc)
12include allow-python2.inc 12include allow-python2.inc
@@ -22,8 +22,8 @@ include disable-shell.inc
22include disable-xdg.inc 22include disable-xdg.inc
23 23
24mkdir ${HOME}/.config/d-feet 24mkdir ${HOME}/.config/d-feet
25whitelist ${HOME}/.config/d-feet 25allow ${HOME}/.config/d-feet
26whitelist /usr/share/d-feet 26allow /usr/share/d-feet
27include whitelist-common.inc 27include whitelist-common.inc
28include whitelist-runuser-common.inc 28include whitelist-runuser-common.inc
29include whitelist-usr-share-common.inc 29include whitelist-usr-share-common.inc
diff --git a/etc/profile-a-l/darktable.profile b/etc/profile-a-l/darktable.profile
index 61fa52928..4d51c255e 100644
--- a/etc/profile-a-l/darktable.profile
+++ b/etc/profile-a-l/darktable.profile
@@ -6,9 +6,9 @@ include darktable.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.cache/darktable 9nodeny ${HOME}/.cache/darktable
10noblacklist ${HOME}/.config/darktable 10nodeny ${HOME}/.config/darktable
11noblacklist ${PICTURES} 11nodeny ${PICTURES}
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
diff --git a/etc/profile-a-l/dbus-send.profile b/etc/profile-a-l/dbus-send.profile
index 67a61bb60..745042d6f 100644
--- a/etc/profile-a-l/dbus-send.profile
+++ b/etc/profile-a-l/dbus-send.profile
@@ -7,8 +7,8 @@ include dbus-send.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10blacklist /tmp/.X11-unix 10deny /tmp/.X11-unix
11blacklist ${RUNUSER}/wayland-* 11deny ${RUNUSER}/wayland-*
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
diff --git a/etc/profile-a-l/dconf-editor.profile b/etc/profile-a-l/dconf-editor.profile
index 0c221850a..c1231c6cf 100644
--- a/etc/profile-a-l/dconf-editor.profile
+++ b/etc/profile-a-l/dconf-editor.profile
@@ -15,7 +15,7 @@ include disable-programs.inc
15include disable-shell.inc 15include disable-shell.inc
16include disable-xdg.inc 16include disable-xdg.inc
17 17
18whitelist ${HOME}/.local/share/glib-2.0 18allow ${HOME}/.local/share/glib-2.0
19include whitelist-common.inc 19include whitelist-common.inc
20include whitelist-runuser-common.inc 20include whitelist-runuser-common.inc
21include whitelist-usr-share-common.inc 21include whitelist-usr-share-common.inc
diff --git a/etc/profile-a-l/dconf.profile b/etc/profile-a-l/dconf.profile
index be7514cbf..b9d385adf 100644
--- a/etc/profile-a-l/dconf.profile
+++ b/etc/profile-a-l/dconf.profile
@@ -6,7 +6,7 @@ include dconf.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9blacklist ${RUNUSER}/wayland-* 9deny ${RUNUSER}/wayland-*
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -16,7 +16,7 @@ include disable-passwdmgr.inc
16include disable-programs.inc 16include disable-programs.inc
17include disable-xdg.inc 17include disable-xdg.inc
18 18
19whitelist ${HOME}/.local/share/glib-2.0 19allow ${HOME}/.local/share/glib-2.0
20# dconf paths are whitelisted by the following 20# dconf paths are whitelisted by the following
21include whitelist-common.inc 21include whitelist-common.inc
22include whitelist-usr-share-common.inc 22include whitelist-usr-share-common.inc
diff --git a/etc/profile-a-l/ddgtk.profile b/etc/profile-a-l/ddgtk.profile
index 5b95b74be..09fa7a07a 100644
--- a/etc/profile-a-l/ddgtk.profile
+++ b/etc/profile-a-l/ddgtk.profile
@@ -18,8 +18,8 @@ include disable-passwdmgr.inc
18include disable-programs.inc 18include disable-programs.inc
19include disable-xdg.inc 19include disable-xdg.inc
20 20
21whitelist ${DOWNLOADS} 21allow ${DOWNLOADS}
22whitelist /usr/share/ddgtk 22allow /usr/share/ddgtk
23include whitelist-common.inc 23include whitelist-common.inc
24include whitelist-usr-share-common.inc 24include whitelist-usr-share-common.inc
25include whitelist-var-common.inc 25include whitelist-var-common.inc
diff --git a/etc/profile-a-l/deadbeef.profile b/etc/profile-a-l/deadbeef.profile
index a221ebbd7..25fa944a1 100644
--- a/etc/profile-a-l/deadbeef.profile
+++ b/etc/profile-a-l/deadbeef.profile
@@ -6,8 +6,8 @@ include deadbeef.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/deadbeef 9nodeny ${HOME}/.config/deadbeef
10noblacklist ${MUSIC} 10nodeny ${MUSIC}
11 11
12include disable-common.inc 12include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
diff --git a/etc/profile-a-l/deluge.profile b/etc/profile-a-l/deluge.profile
index ad7aa6ed5..d41a4a023 100644
--- a/etc/profile-a-l/deluge.profile
+++ b/etc/profile-a-l/deluge.profile
@@ -6,7 +6,7 @@ include deluge.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/deluge 9nodeny ${HOME}/.config/deluge
10 10
11# Allow python (blacklisted by disable-interpreters.inc) 11# Allow python (blacklisted by disable-interpreters.inc)
12include allow-python2.inc 12include allow-python2.inc
@@ -20,8 +20,8 @@ include disable-passwdmgr.inc
20include disable-programs.inc 20include disable-programs.inc
21 21
22mkdir ${HOME}/.config/deluge 22mkdir ${HOME}/.config/deluge
23whitelist ${DOWNLOADS} 23allow ${DOWNLOADS}
24whitelist ${HOME}/.config/deluge 24allow ${HOME}/.config/deluge
25include whitelist-common.inc 25include whitelist-common.inc
26include whitelist-var-common.inc 26include whitelist-var-common.inc
27 27
diff --git a/etc/profile-a-l/desktopeditors.profile b/etc/profile-a-l/desktopeditors.profile
index 212cdab60..aed4355d5 100644
--- a/etc/profile-a-l/desktopeditors.profile
+++ b/etc/profile-a-l/desktopeditors.profile
@@ -6,9 +6,9 @@ include desktopeditors.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/onlyoffice 9nodeny ${HOME}/.config/onlyoffice
10noblacklist ${HOME}/.local/share/onlyoffice 10nodeny ${HOME}/.local/share/onlyoffice
11noblacklist ${HOME}/.pki 11nodeny ${HOME}/.pki
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
diff --git a/etc/profile-a-l/devhelp.profile b/etc/profile-a-l/devhelp.profile
index 5007f8e74..dc0f290fb 100644
--- a/etc/profile-a-l/devhelp.profile
+++ b/etc/profile-a-l/devhelp.profile
@@ -16,9 +16,9 @@ include disable-programs.inc
16include disable-shell.inc 16include disable-shell.inc
17include disable-xdg.inc 17include disable-xdg.inc
18 18
19whitelist /usr/share/devhelp 19allow /usr/share/devhelp
20whitelist /usr/share/doc 20allow /usr/share/doc
21whitelist /usr/share/gtk-doc/html 21allow /usr/share/gtk-doc/html
22include whitelist-common.inc 22include whitelist-common.inc
23include whitelist-usr-share-common.inc 23include whitelist-usr-share-common.inc
24 24
diff --git a/etc/profile-a-l/devilspie.profile b/etc/profile-a-l/devilspie.profile
index 6267b5709..631f15f93 100644
--- a/etc/profile-a-l/devilspie.profile
+++ b/etc/profile-a-l/devilspie.profile
@@ -6,9 +6,9 @@ include devilspie.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9blacklist ${RUNUSER}/wayland-* 9deny ${RUNUSER}/wayland-*
10 10
11noblacklist ${HOME}/.devilspie 11nodeny ${HOME}/.devilspie
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
@@ -19,7 +19,7 @@ include disable-programs.inc
19include disable-xdg.inc 19include disable-xdg.inc
20 20
21mkdir ${HOME}/.devilspie 21mkdir ${HOME}/.devilspie
22whitelist ${HOME}/.devilspie 22allow ${HOME}/.devilspie
23include whitelist-common.inc 23include whitelist-common.inc
24include whitelist-usr-share-common.inc 24include whitelist-usr-share-common.inc
25include whitelist-var-common.inc 25include whitelist-var-common.inc
diff --git a/etc/profile-a-l/devilspie2.profile b/etc/profile-a-l/devilspie2.profile
index 9eab3f536..140c9da0f 100644
--- a/etc/profile-a-l/devilspie2.profile
+++ b/etc/profile-a-l/devilspie2.profile
@@ -6,17 +6,17 @@ include devilspie2.local
6# Persistent global definitions 6# Persistent global definitions
7#include globals.local 7#include globals.local
8 8
9blacklist ${HOME}/.devilspie 9deny ${HOME}/.devilspie
10 10
11blacklist ${RUNUSER}/wayland-* 11deny ${RUNUSER}/wayland-*
12 12
13noblacklist ${HOME}/.config/devilspie2 13nodeny ${HOME}/.config/devilspie2
14 14
15# Allow lua (blacklisted by disable-interpreters.inc) 15# Allow lua (blacklisted by disable-interpreters.inc)
16include allow-lua.inc 16include allow-lua.inc
17 17
18mkdir ${HOME}/.config/devilspie2 18mkdir ${HOME}/.config/devilspie2
19whitelist ${HOME}/.config/devilspie2 19allow ${HOME}/.config/devilspie2
20 20
21private-bin devilspie2 21private-bin devilspie2
22 22
diff --git a/etc/profile-a-l/dia.profile b/etc/profile-a-l/dia.profile
index 531734b7d..2a808238b 100644
--- a/etc/profile-a-l/dia.profile
+++ b/etc/profile-a-l/dia.profile
@@ -6,8 +6,8 @@ include dia.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.dia 9nodeny ${HOME}/.dia
10noblacklist ${DOCUMENTS} 10nodeny ${DOCUMENTS}
11 11
12# Allow python (blacklisted by disable-interpreters.inc) 12# Allow python (blacklisted by disable-interpreters.inc)
13include allow-python2.inc 13include allow-python2.inc
@@ -25,7 +25,7 @@ include disable-xdg.inc
25#whitelist ${HOME}/.dia 25#whitelist ${HOME}/.dia
26#whitelist ${DOCUMENTS} 26#whitelist ${DOCUMENTS}
27#include whitelist-common.inc 27#include whitelist-common.inc
28whitelist /usr/share/dia 28allow /usr/share/dia
29include whitelist-runuser-common.inc 29include whitelist-runuser-common.inc
30include whitelist-usr-share-common.inc 30include whitelist-usr-share-common.inc
31include whitelist-var-common.inc 31include whitelist-var-common.inc
diff --git a/etc/profile-a-l/dig.profile b/etc/profile-a-l/dig.profile
index 247159a8a..2d683b811 100644
--- a/etc/profile-a-l/dig.profile
+++ b/etc/profile-a-l/dig.profile
@@ -7,11 +7,11 @@ include dig.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10noblacklist ${HOME}/.digrc 10nodeny ${HOME}/.digrc
11noblacklist ${PATH}/dig 11nodeny ${PATH}/dig
12 12
13blacklist /tmp/.X11-unix 13deny /tmp/.X11-unix
14blacklist ${RUNUSER} 14deny ${RUNUSER}
15 15
16include disable-common.inc 16include disable-common.inc
17# include disable-devel.inc 17# include disable-devel.inc
@@ -22,7 +22,7 @@ include disable-programs.inc
22include disable-xdg.inc 22include disable-xdg.inc
23 23
24#mkfile ${HOME}/.digrc - see #903 24#mkfile ${HOME}/.digrc - see #903
25whitelist ${HOME}/.digrc 25allow ${HOME}/.digrc
26include whitelist-common.inc 26include whitelist-common.inc
27include whitelist-usr-share-common.inc 27include whitelist-usr-share-common.inc
28include whitelist-var-common.inc 28include whitelist-var-common.inc
diff --git a/etc/profile-a-l/digikam.profile b/etc/profile-a-l/digikam.profile
index 2ca7bd400..124b50952 100644
--- a/etc/profile-a-l/digikam.profile
+++ b/etc/profile-a-l/digikam.profile
@@ -6,12 +6,12 @@ include digikam.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/digikam 9nodeny ${HOME}/.config/digikam
10noblacklist ${HOME}/.config/digikamrc 10nodeny ${HOME}/.config/digikamrc
11noblacklist ${HOME}/.kde/share/apps/digikam 11nodeny ${HOME}/.kde/share/apps/digikam
12noblacklist ${HOME}/.kde4/share/apps/digikam 12nodeny ${HOME}/.kde4/share/apps/digikam
13noblacklist ${HOME}/.local/share/kxmlgui5/digikam 13nodeny ${HOME}/.local/share/kxmlgui5/digikam
14noblacklist ${PICTURES} 14nodeny ${PICTURES}
15 15
16include disable-common.inc 16include disable-common.inc
17include disable-devel.inc 17include disable-devel.inc
diff --git a/etc/profile-a-l/dillo.profile b/etc/profile-a-l/dillo.profile
index 9871a6095..883466f4d 100644
--- a/etc/profile-a-l/dillo.profile
+++ b/etc/profile-a-l/dillo.profile
@@ -6,7 +6,7 @@ include dillo.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.dillo 9nodeny ${HOME}/.dillo
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -16,9 +16,9 @@ include disable-programs.inc
16 16
17mkdir ${HOME}/.dillo 17mkdir ${HOME}/.dillo
18mkdir ${HOME}/.fltk 18mkdir ${HOME}/.fltk
19whitelist ${DOWNLOADS} 19allow ${DOWNLOADS}
20whitelist ${HOME}/.dillo 20allow ${HOME}/.dillo
21whitelist ${HOME}/.fltk 21allow ${HOME}/.fltk
22include whitelist-common.inc 22include whitelist-common.inc
23include whitelist-var-common.inc 23include whitelist-var-common.inc
24 24
diff --git a/etc/profile-a-l/dino.profile b/etc/profile-a-l/dino.profile
index c3174b35f..3078bef71 100644
--- a/etc/profile-a-l/dino.profile
+++ b/etc/profile-a-l/dino.profile
@@ -6,7 +6,7 @@ include dino.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.local/share/dino 9nodeny ${HOME}/.local/share/dino
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -17,8 +17,8 @@ include disable-programs.inc
17include disable-shell.inc 17include disable-shell.inc
18 18
19mkdir ${HOME}/.local/share/dino 19mkdir ${HOME}/.local/share/dino
20whitelist ${HOME}/.local/share/dino 20allow ${HOME}/.local/share/dino
21whitelist ${DOWNLOADS} 21allow ${DOWNLOADS}
22include whitelist-common.inc 22include whitelist-common.inc
23include whitelist-runuser-common.inc 23include whitelist-runuser-common.inc
24include whitelist-usr-share-common.inc 24include whitelist-usr-share-common.inc
diff --git a/etc/profile-a-l/discord-canary.profile b/etc/profile-a-l/discord-canary.profile
index 43db95b8a..1c53cd211 100644
--- a/etc/profile-a-l/discord-canary.profile
+++ b/etc/profile-a-l/discord-canary.profile
@@ -5,10 +5,10 @@ include discord-canary.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${HOME}/.config/discordcanary 8nodeny ${HOME}/.config/discordcanary
9 9
10mkdir ${HOME}/.config/discordcanary 10mkdir ${HOME}/.config/discordcanary
11whitelist ${HOME}/.config/discordcanary 11allow ${HOME}/.config/discordcanary
12 12
13private-bin discord-canary,electron,electron[0-9],electron[0-9][0-9] 13private-bin discord-canary,electron,electron[0-9],electron[0-9][0-9]
14private-opt discord-canary 14private-opt discord-canary
diff --git a/etc/profile-a-l/discord-common.profile b/etc/profile-a-l/discord-common.profile
index 19e7bd9ab..6bee1901c 100644
--- a/etc/profile-a-l/discord-common.profile
+++ b/etc/profile-a-l/discord-common.profile
@@ -20,8 +20,8 @@ ignore dbus-system none
20ignore noexec ${HOME} 20ignore noexec ${HOME}
21ignore novideo 21ignore novideo
22 22
23whitelist ${HOME}/.config/BetterDiscord 23allow ${HOME}/.config/BetterDiscord
24whitelist ${HOME}/.local/share/betterdiscordctl 24allow ${HOME}/.local/share/betterdiscordctl
25 25
26private-bin bash,cut,echo,egrep,fish,grep,head,sed,sh,tclsh,tr,xdg-mime,xdg-open,zsh 26private-bin bash,cut,echo,egrep,fish,grep,head,sed,sh,tclsh,tr,xdg-mime,xdg-open,zsh
27private-etc alternatives,ca-certificates,crypto-policies,fonts,group,ld.so.cache,localtime,login.defs,machine-id,password,pki,pulse,resolv.conf,ssl 27private-etc alternatives,ca-certificates,crypto-policies,fonts,group,ld.so.cache,localtime,login.defs,machine-id,password,pki,pulse,resolv.conf,ssl
diff --git a/etc/profile-a-l/discord.profile b/etc/profile-a-l/discord.profile
index 8ef02a30f..658d3fc83 100644
--- a/etc/profile-a-l/discord.profile
+++ b/etc/profile-a-l/discord.profile
@@ -5,10 +5,10 @@ include discord.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${HOME}/.config/discord 8nodeny ${HOME}/.config/discord
9 9
10mkdir ${HOME}/.config/discord 10mkdir ${HOME}/.config/discord
11whitelist ${HOME}/.config/discord 11allow ${HOME}/.config/discord
12 12
13private-bin discord 13private-bin discord
14private-opt discord 14private-opt discord
diff --git a/etc/profile-a-l/display.profile b/etc/profile-a-l/display.profile
index 11f3fd36e..4474b97d2 100644
--- a/etc/profile-a-l/display.profile
+++ b/etc/profile-a-l/display.profile
@@ -5,7 +5,7 @@ include display.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${PICTURES} 8nodeny ${PICTURES}
9 9
10# Allow python (blacklisted by disable-interpreters.inc) 10# Allow python (blacklisted by disable-interpreters.inc)
11include allow-python2.inc 11include allow-python2.inc
diff --git a/etc/profile-a-l/dnox.profile b/etc/profile-a-l/dnox.profile
index 51ba6f8b7..8c3d6211b 100644
--- a/etc/profile-a-l/dnox.profile
+++ b/etc/profile-a-l/dnox.profile
@@ -10,13 +10,13 @@ ignore whitelist /usr/share/chromium
10ignore include whitelist-runuser-common.inc 10ignore include whitelist-runuser-common.inc
11ignore include whitelist-usr-share-common.inc 11ignore include whitelist-usr-share-common.inc
12 12
13noblacklist ${HOME}/.cache/dnox 13nodeny ${HOME}/.cache/dnox
14noblacklist ${HOME}/.config/dnox 14nodeny ${HOME}/.config/dnox
15 15
16mkdir ${HOME}/.cache/dnox 16mkdir ${HOME}/.cache/dnox
17mkdir ${HOME}/.config/dnox 17mkdir ${HOME}/.config/dnox
18whitelist ${HOME}/.cache/dnox 18allow ${HOME}/.cache/dnox
19whitelist ${HOME}/.config/dnox 19allow ${HOME}/.config/dnox
20 20
21# Redirect 21# Redirect
22include chromium-common.profile 22include chromium-common.profile
diff --git a/etc/profile-a-l/dnscrypt-proxy.profile b/etc/profile-a-l/dnscrypt-proxy.profile
index f8fb1a331..dbcef36f8 100644
--- a/etc/profile-a-l/dnscrypt-proxy.profile
+++ b/etc/profile-a-l/dnscrypt-proxy.profile
@@ -7,11 +7,11 @@ include dnscrypt-proxy.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10blacklist /tmp/.X11-unix 10deny /tmp/.X11-unix
11blacklist ${RUNUSER}/wayland-* 11deny ${RUNUSER}/wayland-*
12 12
13noblacklist /sbin 13nodeny /sbin
14noblacklist /usr/sbin 14nodeny /usr/sbin
15 15
16include disable-common.inc 16include disable-common.inc
17include disable-devel.inc 17include disable-devel.inc
@@ -21,7 +21,7 @@ include disable-passwdmgr.inc
21include disable-programs.inc 21include disable-programs.inc
22include disable-xdg.inc 22include disable-xdg.inc
23 23
24whitelist /usr/share/dnscrypt-proxy 24allow /usr/share/dnscrypt-proxy
25include whitelist-usr-share-common.inc 25include whitelist-usr-share-common.inc
26include whitelist-var-common.inc 26include whitelist-var-common.inc
27 27
diff --git a/etc/profile-a-l/dnsmasq.profile b/etc/profile-a-l/dnsmasq.profile
index 01398c2b2..b1acbf392 100644
--- a/etc/profile-a-l/dnsmasq.profile
+++ b/etc/profile-a-l/dnsmasq.profile
@@ -7,11 +7,11 @@ include dnsmasq.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10noblacklist /sbin 10nodeny /sbin
11noblacklist /usr/sbin 11nodeny /usr/sbin
12 12
13blacklist /tmp/.X11-unix 13deny /tmp/.X11-unix
14blacklist ${RUNUSER}/wayland-* 14deny ${RUNUSER}/wayland-*
15 15
16include disable-common.inc 16include disable-common.inc
17include disable-devel.inc 17include disable-devel.inc
diff --git a/etc/profile-a-l/dolphin-emu.profile b/etc/profile-a-l/dolphin-emu.profile
index 49feec32e..15b312ecb 100644
--- a/etc/profile-a-l/dolphin-emu.profile
+++ b/etc/profile-a-l/dolphin-emu.profile
@@ -8,9 +8,9 @@ include globals.local
8 8
9# Note: you must whitelist your games folder in your dolphin-emu.local. 9# Note: you must whitelist your games folder in your dolphin-emu.local.
10 10
11noblacklist ${HOME}/.cache/dolphin-emu 11nodeny ${HOME}/.cache/dolphin-emu
12noblacklist ${HOME}/.config/dolphin-emu 12nodeny ${HOME}/.config/dolphin-emu
13noblacklist ${HOME}/.local/share/dolphin-emu 13nodeny ${HOME}/.local/share/dolphin-emu
14 14
15include disable-common.inc 15include disable-common.inc
16include disable-devel.inc 16include disable-devel.inc
@@ -24,10 +24,10 @@ include disable-xdg.inc
24mkdir ${HOME}/.cache/dolphin-emu 24mkdir ${HOME}/.cache/dolphin-emu
25mkdir ${HOME}/.config/dolphin-emu 25mkdir ${HOME}/.config/dolphin-emu
26mkdir ${HOME}/.local/share/dolphin-emu 26mkdir ${HOME}/.local/share/dolphin-emu
27whitelist ${HOME}/.cache/dolphin-emu 27allow ${HOME}/.cache/dolphin-emu
28whitelist ${HOME}/.config/dolphin-emu 28allow ${HOME}/.config/dolphin-emu
29whitelist ${HOME}/.local/share/dolphin-emu 29allow ${HOME}/.local/share/dolphin-emu
30whitelist /usr/share/dolphin-emu 30allow /usr/share/dolphin-emu
31include whitelist-common.inc 31include whitelist-common.inc
32include whitelist-runuser-common.inc 32include whitelist-runuser-common.inc
33include whitelist-usr-share-common.inc 33include whitelist-usr-share-common.inc
diff --git a/etc/profile-a-l/dooble.profile b/etc/profile-a-l/dooble.profile
index 37a4113cb..3b0adcc36 100644
--- a/etc/profile-a-l/dooble.profile
+++ b/etc/profile-a-l/dooble.profile
@@ -7,7 +7,7 @@ include dooble-qt4.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10noblacklist ${HOME}/.dooble 10nodeny ${HOME}/.dooble
11 11
12include disable-common.inc 12include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
@@ -17,8 +17,8 @@ include disable-passwdmgr.inc
17include disable-programs.inc 17include disable-programs.inc
18 18
19mkdir ${HOME}/.dooble 19mkdir ${HOME}/.dooble
20whitelist ${DOWNLOADS} 20allow ${DOWNLOADS}
21whitelist ${HOME}/.dooble 21allow ${HOME}/.dooble
22include whitelist-common.inc 22include whitelist-common.inc
23 23
24caps.drop all 24caps.drop all
diff --git a/etc/profile-a-l/dosbox.profile b/etc/profile-a-l/dosbox.profile
index 988f66f28..29e506764 100644
--- a/etc/profile-a-l/dosbox.profile
+++ b/etc/profile-a-l/dosbox.profile
@@ -6,8 +6,8 @@ include dosbox.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.dosbox 9nodeny ${HOME}/.dosbox
10noblacklist ${DOCUMENTS} 10nodeny ${DOCUMENTS}
11 11
12include disable-common.inc 12include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
diff --git a/etc/profile-a-l/dragon.profile b/etc/profile-a-l/dragon.profile
index 8fa01d504..90ca11774 100644
--- a/etc/profile-a-l/dragon.profile
+++ b/etc/profile-a-l/dragon.profile
@@ -6,9 +6,9 @@ include dragon.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/dragonplayerrc 9nodeny ${HOME}/.config/dragonplayerrc
10noblacklist ${MUSIC} 10nodeny ${MUSIC}
11noblacklist ${VIDEOS} 11nodeny ${VIDEOS}
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
@@ -19,7 +19,7 @@ include disable-programs.inc
19include disable-shell.inc 19include disable-shell.inc
20include disable-xdg.inc 20include disable-xdg.inc
21 21
22whitelist /usr/share/dragonplayer 22allow /usr/share/dragonplayer
23include whitelist-usr-share-common.inc 23include whitelist-usr-share-common.inc
24include whitelist-var-common.inc 24include whitelist-var-common.inc
25 25
diff --git a/etc/profile-a-l/drawio.profile b/etc/profile-a-l/drawio.profile
index 82d96e405..84a77ce34 100644
--- a/etc/profile-a-l/drawio.profile
+++ b/etc/profile-a-l/drawio.profile
@@ -6,7 +6,7 @@ include drawio.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/draw.io 9nodeny ${HOME}/.config/draw.io
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -18,8 +18,8 @@ include disable-shell.inc
18include disable-xdg.inc 18include disable-xdg.inc
19 19
20mkdir ${HOME}/.config/draw.io 20mkdir ${HOME}/.config/draw.io
21whitelist ${HOME}/.config/draw.io 21allow ${HOME}/.config/draw.io
22whitelist ${DOWNLOADS} 22allow ${DOWNLOADS}
23include whitelist-common.inc 23include whitelist-common.inc
24include whitelist-usr-share-common.inc 24include whitelist-usr-share-common.inc
25include whitelist-var-common.inc 25include whitelist-var-common.inc
diff --git a/etc/profile-a-l/drill.profile b/etc/profile-a-l/drill.profile
index 068bd88d8..e177fd60e 100644
--- a/etc/profile-a-l/drill.profile
+++ b/etc/profile-a-l/drill.profile
@@ -7,10 +7,10 @@ include drill.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10noblacklist ${PATH}/drill 10nodeny ${PATH}/drill
11 11
12blacklist /tmp/.X11-unix 12deny /tmp/.X11-unix
13blacklist ${RUNUSER} 13deny ${RUNUSER}
14 14
15include disable-common.inc 15include disable-common.inc
16# include disable-devel.inc 16# include disable-devel.inc
diff --git a/etc/profile-a-l/dropbox.profile b/etc/profile-a-l/dropbox.profile
index b3b2aaf40..274cdd478 100644
--- a/etc/profile-a-l/dropbox.profile
+++ b/etc/profile-a-l/dropbox.profile
@@ -5,9 +5,9 @@ include dropbox.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${HOME}/.config/autostart 8nodeny ${HOME}/.config/autostart
9noblacklist ${HOME}/.dropbox 9nodeny ${HOME}/.dropbox
10noblacklist ${HOME}/.dropbox-dist 10nodeny ${HOME}/.dropbox-dist
11 11
12# Allow python3 (blacklisted by disable-interpreters.inc) 12# Allow python3 (blacklisted by disable-interpreters.inc)
13include allow-python3.inc 13include allow-python3.inc
@@ -22,10 +22,10 @@ mkdir ${HOME}/.dropbox
22mkdir ${HOME}/.dropbox-dist 22mkdir ${HOME}/.dropbox-dist
23mkdir ${HOME}/Dropbox 23mkdir ${HOME}/Dropbox
24mkfile ${HOME}/.config/autostart/dropbox.desktop 24mkfile ${HOME}/.config/autostart/dropbox.desktop
25whitelist ${HOME}/.config/autostart/dropbox.desktop 25allow ${HOME}/.config/autostart/dropbox.desktop
26whitelist ${HOME}/.dropbox 26allow ${HOME}/.dropbox
27whitelist ${HOME}/.dropbox-dist 27allow ${HOME}/.dropbox-dist
28whitelist ${HOME}/Dropbox 28allow ${HOME}/Dropbox
29include whitelist-common.inc 29include whitelist-common.inc
30 30
31caps.drop all 31caps.drop all
diff --git a/etc/profile-a-l/easystroke.profile b/etc/profile-a-l/easystroke.profile
index 38e4b16f7..da54fec34 100644
--- a/etc/profile-a-l/easystroke.profile
+++ b/etc/profile-a-l/easystroke.profile
@@ -6,7 +6,7 @@ include easystroke.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.easystroke 9nodeny ${HOME}/.easystroke
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -17,7 +17,7 @@ include disable-programs.inc
17include disable-xdg.inc 17include disable-xdg.inc
18 18
19mkdir ${HOME}/.easystroke 19mkdir ${HOME}/.easystroke
20whitelist ${HOME}/.easystroke 20allow ${HOME}/.easystroke
21include whitelist-common.inc 21include whitelist-common.inc
22include whitelist-usr-share-common.inc 22include whitelist-usr-share-common.inc
23include whitelist-var-common.inc 23include whitelist-var-common.inc
diff --git a/etc/profile-a-l/electron-mail.profile b/etc/profile-a-l/electron-mail.profile
index 278dd6cbd..10e57371e 100644
--- a/etc/profile-a-l/electron-mail.profile
+++ b/etc/profile-a-l/electron-mail.profile
@@ -6,7 +6,7 @@ include electron-mail.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/electron-mail 9nodeny ${HOME}/.config/electron-mail
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -18,8 +18,8 @@ include disable-shell.inc
18include disable-xdg.inc 18include disable-xdg.inc
19 19
20mkdir ${HOME}/.config/electron-mail 20mkdir ${HOME}/.config/electron-mail
21whitelist ${HOME}/.config/electron-mail 21allow ${HOME}/.config/electron-mail
22whitelist ${DOWNLOADS} 22allow ${DOWNLOADS}
23 23
24include whitelist-common.inc 24include whitelist-common.inc
25include whitelist-runuser-common.inc 25include whitelist-runuser-common.inc
diff --git a/etc/profile-a-l/electron.profile b/etc/profile-a-l/electron.profile
index 493af79d4..e8d8d35c4 100644
--- a/etc/profile-a-l/electron.profile
+++ b/etc/profile-a-l/electron.profile
@@ -12,7 +12,7 @@ include disable-passwdmgr.inc
12include disable-programs.inc 12include disable-programs.inc
13include disable-xdg.inc 13include disable-xdg.inc
14 14
15whitelist ${DOWNLOADS} 15allow ${DOWNLOADS}
16include whitelist-common.inc 16include whitelist-common.inc
17include whitelist-runuser-common.inc 17include whitelist-runuser-common.inc
18include whitelist-usr-share-common.inc 18include whitelist-usr-share-common.inc
diff --git a/etc/profile-a-l/electrum.profile b/etc/profile-a-l/electrum.profile
index ad636d71a..f6691017c 100644
--- a/etc/profile-a-l/electrum.profile
+++ b/etc/profile-a-l/electrum.profile
@@ -6,7 +6,7 @@ include electrum.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.electrum 9nodeny ${HOME}/.electrum
10 10
11# Allow python (blacklisted by disable-interpreters.inc) 11# Allow python (blacklisted by disable-interpreters.inc)
12include allow-python2.inc 12include allow-python2.inc
@@ -22,7 +22,7 @@ include disable-shell.inc
22include disable-xdg.inc 22include disable-xdg.inc
23 23
24mkdir ${HOME}/.electrum 24mkdir ${HOME}/.electrum
25whitelist ${HOME}/.electrum 25allow ${HOME}/.electrum
26include whitelist-common.inc 26include whitelist-common.inc
27include whitelist-var-common.inc 27include whitelist-var-common.inc
28 28
diff --git a/etc/profile-a-l/element-desktop.profile b/etc/profile-a-l/element-desktop.profile
index 48a826f2e..ec28866b8 100644
--- a/etc/profile-a-l/element-desktop.profile
+++ b/etc/profile-a-l/element-desktop.profile
@@ -9,11 +9,11 @@ include element-desktop.local
9 9
10ignore dbus-user none 10ignore dbus-user none
11 11
12noblacklist ${HOME}/.config/Element 12nodeny ${HOME}/.config/Element
13 13
14mkdir ${HOME}/.config/Element 14mkdir ${HOME}/.config/Element
15whitelist ${HOME}/.config/Element 15allow ${HOME}/.config/Element
16whitelist /opt/Element 16allow /opt/Element
17 17
18private-opt Element 18private-opt Element
19 19
diff --git a/etc/profile-a-l/elinks.profile b/etc/profile-a-l/elinks.profile
index 5a29eb24b..30dca05cb 100644
--- a/etc/profile-a-l/elinks.profile
+++ b/etc/profile-a-l/elinks.profile
@@ -7,10 +7,10 @@ include elinks.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10noblacklist ${HOME}/.elinks 10nodeny ${HOME}/.elinks
11 11
12mkdir ${HOME}/.elinks 12mkdir ${HOME}/.elinks
13whitelist ${HOME}/.elinks 13allow ${HOME}/.elinks
14 14
15private-bin elinks 15private-bin elinks
16 16
diff --git a/etc/profile-a-l/emacs.profile b/etc/profile-a-l/emacs.profile
index 55bf743ef..f0e0e2830 100644
--- a/etc/profile-a-l/emacs.profile
+++ b/etc/profile-a-l/emacs.profile
@@ -6,8 +6,8 @@ include emacs.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.emacs 9nodeny ${HOME}/.emacs
10noblacklist ${HOME}/.emacs.d 10nodeny ${HOME}/.emacs.d
11# Add the next line to your emacs.local if you need gpg support. 11# Add the next line to your emacs.local if you need gpg support.
12#noblacklist ${HOME}/.gnupg 12#noblacklist ${HOME}/.gnupg
13 13
diff --git a/etc/profile-a-l/email-common.profile b/etc/profile-a-l/email-common.profile
index 6c9a8a6ea..5fc72d340 100644
--- a/etc/profile-a-l/email-common.profile
+++ b/etc/profile-a-l/email-common.profile
@@ -7,14 +7,14 @@ include email-common.local
7# added by caller profile 7# added by caller profile
8#include globals.local 8#include globals.local
9 9
10noblacklist ${HOME}/.gnupg 10nodeny ${HOME}/.gnupg
11noblacklist ${HOME}/.mozilla 11nodeny ${HOME}/.mozilla
12noblacklist ${HOME}/.signature 12nodeny ${HOME}/.signature
13# when storing mail outside the default ${HOME}/Mail path, 'noblacklist' the custom path in your email-common.local 13# when storing mail outside the default ${HOME}/Mail path, 'noblacklist' the custom path in your email-common.local
14# and 'blacklist' it in your disable-common.local too so it is kept hidden from other applications 14# and 'blacklist' it in your disable-common.local too so it is kept hidden from other applications
15noblacklist ${HOME}/Mail 15nodeny ${HOME}/Mail
16 16
17noblacklist ${DOCUMENTS} 17nodeny ${DOCUMENTS}
18 18
19include disable-common.inc 19include disable-common.inc
20include disable-devel.inc 20include disable-devel.inc
@@ -27,17 +27,17 @@ include disable-xdg.inc
27mkdir ${HOME}/.gnupg 27mkdir ${HOME}/.gnupg
28mkfile ${HOME}/.config/mimeapps.list 28mkfile ${HOME}/.config/mimeapps.list
29mkfile ${HOME}/.signature 29mkfile ${HOME}/.signature
30whitelist ${HOME}/.config/mimeapps.list 30allow ${HOME}/.config/mimeapps.list
31whitelist ${HOME}/.mozilla/firefox/profiles.ini 31allow ${HOME}/.mozilla/firefox/profiles.ini
32whitelist ${HOME}/.gnupg 32allow ${HOME}/.gnupg
33whitelist ${HOME}/.signature 33allow ${HOME}/.signature
34whitelist ${DOCUMENTS} 34allow ${DOCUMENTS}
35whitelist ${DOWNLOADS} 35allow ${DOWNLOADS}
36# when storing mail outside the default ${HOME}/Mail path, 'whitelist' the custom path in your email-common.local 36# when storing mail outside the default ${HOME}/Mail path, 'whitelist' the custom path in your email-common.local
37whitelist ${HOME}/Mail 37allow ${HOME}/Mail
38whitelist ${RUNUSER}/gnupg 38allow ${RUNUSER}/gnupg
39whitelist /usr/share/gnupg 39allow /usr/share/gnupg
40whitelist /usr/share/gnupg2 40allow /usr/share/gnupg2
41include whitelist-common.inc 41include whitelist-common.inc
42include whitelist-runuser-common.inc 42include whitelist-runuser-common.inc
43include whitelist-usr-share-common.inc 43include whitelist-usr-share-common.inc
diff --git a/etc/profile-a-l/enchant.profile b/etc/profile-a-l/enchant.profile
index ac17b1726..36015b702 100644
--- a/etc/profile-a-l/enchant.profile
+++ b/etc/profile-a-l/enchant.profile
@@ -6,9 +6,9 @@ include enchant.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9blacklist ${RUNUSER}/wayland-* 9deny ${RUNUSER}/wayland-*
10 10
11noblacklist ${HOME}/.config/enchant 11nodeny ${HOME}/.config/enchant
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
@@ -19,7 +19,7 @@ include disable-programs.inc
19include disable-xdg.inc 19include disable-xdg.inc
20 20
21mkdir ${HOME}/.config/enchant 21mkdir ${HOME}/.config/enchant
22whitelist ${HOME}/.config/enchant 22allow ${HOME}/.config/enchant
23include whitelist-common.inc 23include whitelist-common.inc
24include whitelist-runuser-common.inc 24include whitelist-runuser-common.inc
25include whitelist-usr-share-common.inc 25include whitelist-usr-share-common.inc
diff --git a/etc/profile-a-l/enox.profile b/etc/profile-a-l/enox.profile
index d982433e2..9a1d89bba 100644
--- a/etc/profile-a-l/enox.profile
+++ b/etc/profile-a-l/enox.profile
@@ -10,15 +10,15 @@ ignore whitelist /usr/share/chromium
10ignore include whitelist-runuser-common.inc 10ignore include whitelist-runuser-common.inc
11ignore include whitelist-usr-share-common.inc 11ignore include whitelist-usr-share-common.inc
12 12
13noblacklist ${HOME}/.cache/Enox 13nodeny ${HOME}/.cache/Enox
14noblacklist ${HOME}/.config/Enox 14nodeny ${HOME}/.config/Enox
15 15
16#mkdir ${HOME}/.cache/dnox 16#mkdir ${HOME}/.cache/dnox
17#mkdir ${HOME}/.config/dnox 17#mkdir ${HOME}/.config/dnox
18mkdir ${HOME}/.cache/Enox 18mkdir ${HOME}/.cache/Enox
19mkdir ${HOME}/.config/Enox 19mkdir ${HOME}/.config/Enox
20whitelist ${HOME}/.cache/Enox 20allow ${HOME}/.cache/Enox
21whitelist ${HOME}/.config/Enox 21allow ${HOME}/.config/Enox
22 22
23# Redirect 23# Redirect
24include chromium-common.profile 24include chromium-common.profile
diff --git a/etc/profile-a-l/enpass.profile b/etc/profile-a-l/enpass.profile
index c4123b4c2..5d8f8a0b9 100644
--- a/etc/profile-a-l/enpass.profile
+++ b/etc/profile-a-l/enpass.profile
@@ -6,11 +6,11 @@ include enpass.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.cache/Enpass 9nodeny ${HOME}/.cache/Enpass
10noblacklist ${HOME}/.config/sinew.in 10nodeny ${HOME}/.config/sinew.in
11noblacklist ${HOME}/.config/Sinew Software Systems 11nodeny ${HOME}/.config/Sinew Software Systems
12noblacklist ${HOME}/.local/share/Enpass 12nodeny ${HOME}/.local/share/Enpass
13noblacklist ${DOCUMENTS} 13nodeny ${DOCUMENTS}
14 14
15include disable-common.inc 15include disable-common.inc
16include disable-devel.inc 16include disable-devel.inc
@@ -24,11 +24,11 @@ mkdir ${HOME}/.cache/Enpass
24mkfile ${HOME}/.config/sinew.in 24mkfile ${HOME}/.config/sinew.in
25mkdir ${HOME}/.config/Sinew Software Systems 25mkdir ${HOME}/.config/Sinew Software Systems
26mkdir ${HOME}/.local/share/Enpass 26mkdir ${HOME}/.local/share/Enpass
27whitelist ${HOME}/.cache/Enpass 27allow ${HOME}/.cache/Enpass
28whitelist ${HOME}/.config/sinew.in 28allow ${HOME}/.config/sinew.in
29whitelist ${HOME}/.config/Sinew Software Systems 29allow ${HOME}/.config/Sinew Software Systems
30whitelist ${HOME}/.local/share/Enpass 30allow ${HOME}/.local/share/Enpass
31whitelist ${DOCUMENTS} 31allow ${DOCUMENTS}
32include whitelist-common.inc 32include whitelist-common.inc
33include whitelist-var-common.inc 33include whitelist-var-common.inc
34 34
diff --git a/etc/profile-a-l/eo-common.profile b/etc/profile-a-l/eo-common.profile
index fe7913e77..ff7040e5c 100644
--- a/etc/profile-a-l/eo-common.profile
+++ b/etc/profile-a-l/eo-common.profile
@@ -7,11 +7,11 @@ include eo-common.local
7# added by caller profile 7# added by caller profile
8#include globals.local 8#include globals.local
9 9
10noblacklist ${HOME}/.local/share/Trash 10nodeny ${HOME}/.local/share/Trash
11noblacklist ${HOME}/.Steam 11nodeny ${HOME}/.Steam
12noblacklist ${HOME}/.steam 12nodeny ${HOME}/.steam
13 13
14blacklist /usr/libexec 14deny /usr/libexec
15 15
16include disable-common.inc 16include disable-common.inc
17include disable-devel.inc 17include disable-devel.inc
diff --git a/etc/profile-a-l/eog.profile b/etc/profile-a-l/eog.profile
index 5892374bd..e8592c7df 100644
--- a/etc/profile-a-l/eog.profile
+++ b/etc/profile-a-l/eog.profile
@@ -6,9 +6,9 @@ include eog.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/eog 9nodeny ${HOME}/.config/eog
10 10
11whitelist /usr/share/eog 11allow /usr/share/eog
12 12
13# private-bin, private-etc and private-lib break 'Open With' / 'Open in file manager'. 13# private-bin, private-etc and private-lib break 'Open With' / 'Open in file manager'.
14# Add the next lines to your eog.local if you need that functionality. 14# Add the next lines to your eog.local if you need that functionality.
diff --git a/etc/profile-a-l/eom.profile b/etc/profile-a-l/eom.profile
index 7143a8e03..323f5ade2 100644
--- a/etc/profile-a-l/eom.profile
+++ b/etc/profile-a-l/eom.profile
@@ -6,9 +6,9 @@ include eom.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/mate/eom 9nodeny ${HOME}/.config/mate/eom
10 10
11whitelist /usr/share/eom 11allow /usr/share/eom
12 12
13# private-bin, private-etc and private-lib break 'Open With' / 'Open in file manager'. 13# private-bin, private-etc and private-lib break 'Open With' / 'Open in file manager'.
14# Add the next lines to your eom.local if you need that functionality. 14# Add the next lines to your eom.local if you need that functionality.
diff --git a/etc/profile-a-l/ephemeral.profile b/etc/profile-a-l/ephemeral.profile
index 131d68951..3657742b9 100644
--- a/etc/profile-a-l/ephemeral.profile
+++ b/etc/profile-a-l/ephemeral.profile
@@ -9,8 +9,8 @@ include globals.local
9# enforce private-cache 9# enforce private-cache
10#noblacklist ${HOME}/.cache/ephemeral 10#noblacklist ${HOME}/.cache/ephemeral
11 11
12noblacklist ${HOME}/.pki 12nodeny ${HOME}/.pki
13noblacklist ${HOME}/.local/share/pki 13nodeny ${HOME}/.local/share/pki
14 14
15# noexec ${HOME} breaks DRM binaries. 15# noexec ${HOME} breaks DRM binaries.
16?BROWSER_ALLOW_DRM: ignore noexec ${HOME} 16?BROWSER_ALLOW_DRM: ignore noexec ${HOME}
@@ -27,9 +27,9 @@ mkdir ${HOME}/.pki
27mkdir ${HOME}/.local/share/pki 27mkdir ${HOME}/.local/share/pki
28# enforce private-cache 28# enforce private-cache
29#whitelist ${HOME}/.cache/ephemeral 29#whitelist ${HOME}/.cache/ephemeral
30whitelist ${HOME}/.pki 30allow ${HOME}/.pki
31whitelist ${HOME}/.local/share/pki 31allow ${HOME}/.local/share/pki
32whitelist ${DOWNLOADS} 32allow ${DOWNLOADS}
33include whitelist-common.inc 33include whitelist-common.inc
34include whitelist-usr-share-common.inc 34include whitelist-usr-share-common.inc
35include whitelist-var-common.inc 35include whitelist-var-common.inc
diff --git a/etc/profile-a-l/epiphany.profile b/etc/profile-a-l/epiphany.profile
index 225811226..daedb2193 100644
--- a/etc/profile-a-l/epiphany.profile
+++ b/etc/profile-a-l/epiphany.profile
@@ -9,9 +9,9 @@ include globals.local
9# Note: Epiphany use bwrap since 3.34 and can not be firejailed any more. 9# Note: Epiphany use bwrap since 3.34 and can not be firejailed any more.
10# See https://github.com/netblue30/firejail/issues/2995 10# See https://github.com/netblue30/firejail/issues/2995
11 11
12noblacklist ${HOME}/.cache/epiphany 12nodeny ${HOME}/.cache/epiphany
13noblacklist ${HOME}/.config/epiphany 13nodeny ${HOME}/.config/epiphany
14noblacklist ${HOME}/.local/share/epiphany 14nodeny ${HOME}/.local/share/epiphany
15 15
16include disable-common.inc 16include disable-common.inc
17include disable-devel.inc 17include disable-devel.inc
@@ -21,10 +21,10 @@ include disable-programs.inc
21mkdir ${HOME}/.cache/epiphany 21mkdir ${HOME}/.cache/epiphany
22mkdir ${HOME}/.config/epiphany 22mkdir ${HOME}/.config/epiphany
23mkdir ${HOME}/.local/share/epiphany 23mkdir ${HOME}/.local/share/epiphany
24whitelist ${DOWNLOADS} 24allow ${DOWNLOADS}
25whitelist ${HOME}/.cache/epiphany 25allow ${HOME}/.cache/epiphany
26whitelist ${HOME}/.config/epiphany 26allow ${HOME}/.config/epiphany
27whitelist ${HOME}/.local/share/epiphany 27allow ${HOME}/.local/share/epiphany
28include whitelist-common.inc 28include whitelist-common.inc
29 29
30caps.drop all 30caps.drop all
diff --git a/etc/profile-a-l/equalx.profile b/etc/profile-a-l/equalx.profile
index 964d3b7ca..ac957870c 100644
--- a/etc/profile-a-l/equalx.profile
+++ b/etc/profile-a-l/equalx.profile
@@ -6,8 +6,8 @@ include equalx.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/equalx 9nodeny ${HOME}/.config/equalx
10noblacklist ${HOME}/.equalx 10nodeny ${HOME}/.equalx
11 11
12include disable-common.inc 12include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
@@ -20,13 +20,13 @@ include disable-xdg.inc
20 20
21mkdir ${HOME}/.config/equalx 21mkdir ${HOME}/.config/equalx
22mkdir ${HOME}/.equalx 22mkdir ${HOME}/.equalx
23whitelist ${HOME}/.config/equalx 23allow ${HOME}/.config/equalx
24whitelist ${HOME}/.equalx 24allow ${HOME}/.equalx
25whitelist /usr/share/poppler 25allow /usr/share/poppler
26whitelist /usr/share/ghostscript 26allow /usr/share/ghostscript
27whitelist /usr/share/texlive 27allow /usr/share/texlive
28whitelist /usr/share/equalx 28allow /usr/share/equalx
29whitelist /var/lib/texmf 29allow /var/lib/texmf
30include whitelist-common.inc 30include whitelist-common.inc
31include whitelist-runuser-common.inc 31include whitelist-runuser-common.inc
32include whitelist-usr-share-common.inc 32include whitelist-usr-share-common.inc
diff --git a/etc/profile-a-l/etr.profile b/etc/profile-a-l/etr.profile
index fdff1e4b5..a2f46b757 100644
--- a/etc/profile-a-l/etr.profile
+++ b/etc/profile-a-l/etr.profile
@@ -6,9 +6,9 @@ include etr.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.etr 9nodeny ${HOME}/.etr
10 10
11blacklist /usr/libexec 11deny /usr/libexec
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
@@ -20,10 +20,10 @@ include disable-shell.inc
20include disable-xdg.inc 20include disable-xdg.inc
21 21
22mkdir ${HOME}/.etr 22mkdir ${HOME}/.etr
23whitelist ${HOME}/.etr 23allow ${HOME}/.etr
24whitelist /usr/share/etr 24allow /usr/share/etr
25# Debian version 25# Debian version
26whitelist /usr/share/games/etr 26allow /usr/share/games/etr
27include whitelist-common.inc 27include whitelist-common.inc
28include whitelist-runuser-common.inc 28include whitelist-runuser-common.inc
29include whitelist-usr-share-common.inc 29include whitelist-usr-share-common.inc
diff --git a/etc/profile-a-l/evince.profile b/etc/profile-a-l/evince.profile
index a9e39b15c..ce2617ad6 100644
--- a/etc/profile-a-l/evince.profile
+++ b/etc/profile-a-l/evince.profile
@@ -10,10 +10,10 @@ include globals.local
10# Add the next line to your evince.local if you need bookmarks support. This also needs additional dbus-user filtering (see below). 10# Add the next line to your evince.local if you need bookmarks support. This also needs additional dbus-user filtering (see below).
11#noblacklist ${HOME}/.local/share/gvfs-metadata 11#noblacklist ${HOME}/.local/share/gvfs-metadata
12 12
13noblacklist ${HOME}/.config/evince 13nodeny ${HOME}/.config/evince
14noblacklist ${DOCUMENTS} 14nodeny ${DOCUMENTS}
15 15
16blacklist /usr/libexec 16deny /usr/libexec
17 17
18include disable-common.inc 18include disable-common.inc
19include disable-devel.inc 19include disable-devel.inc
@@ -24,10 +24,10 @@ include disable-programs.inc
24include disable-shell.inc 24include disable-shell.inc
25include disable-xdg.inc 25include disable-xdg.inc
26 26
27whitelist /usr/share/doc 27allow /usr/share/doc
28whitelist /usr/share/evince 28allow /usr/share/evince
29whitelist /usr/share/poppler 29allow /usr/share/poppler
30whitelist /usr/share/tracker 30allow /usr/share/tracker
31include whitelist-runuser-common.inc 31include whitelist-runuser-common.inc
32include whitelist-usr-share-common.inc 32include whitelist-usr-share-common.inc
33include whitelist-var-common.inc 33include whitelist-var-common.inc
diff --git a/etc/profile-a-l/evolution.profile b/etc/profile-a-l/evolution.profile
index 7222493ac..142498a28 100644
--- a/etc/profile-a-l/evolution.profile
+++ b/etc/profile-a-l/evolution.profile
@@ -6,15 +6,15 @@ include evolution.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist /var/mail 9nodeny /var/mail
10noblacklist /var/spool/mail 10nodeny /var/spool/mail
11noblacklist ${HOME}/.bogofilter 11nodeny ${HOME}/.bogofilter
12noblacklist ${HOME}/.cache/evolution 12nodeny ${HOME}/.cache/evolution
13noblacklist ${HOME}/.config/evolution 13nodeny ${HOME}/.config/evolution
14noblacklist ${HOME}/.gnupg 14nodeny ${HOME}/.gnupg
15noblacklist ${HOME}/.local/share/evolution 15nodeny ${HOME}/.local/share/evolution
16noblacklist ${HOME}/.pki 16nodeny ${HOME}/.pki
17noblacklist ${HOME}/.local/share/pki 17nodeny ${HOME}/.local/share/pki
18 18
19include disable-common.inc 19include disable-common.inc
20include disable-devel.inc 20include disable-devel.inc
diff --git a/etc/profile-a-l/exiftool.profile b/etc/profile-a-l/exiftool.profile
index 7b09a2c64..216814989 100644
--- a/etc/profile-a-l/exiftool.profile
+++ b/etc/profile-a-l/exiftool.profile
@@ -6,7 +6,7 @@ include exiftool.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9blacklist ${RUNUSER}/wayland-* 9deny ${RUNUSER}/wayland-*
10 10
11# Allow perl (blacklisted by disable-interpreters.inc) 11# Allow perl (blacklisted by disable-interpreters.inc)
12include allow-perl.inc 12include allow-perl.inc
@@ -18,7 +18,7 @@ include disable-interpreters.inc
18include disable-passwdmgr.inc 18include disable-passwdmgr.inc
19include disable-programs.inc 19include disable-programs.inc
20 20
21whitelist /usr/share/perl-image-exiftool 21allow /usr/share/perl-image-exiftool
22include whitelist-usr-share-common.inc 22include whitelist-usr-share-common.inc
23include whitelist-var-common.inc 23include whitelist-var-common.inc
24 24
diff --git a/etc/profile-a-l/falkon.profile b/etc/profile-a-l/falkon.profile
index b2061db79..9bb42945b 100644
--- a/etc/profile-a-l/falkon.profile
+++ b/etc/profile-a-l/falkon.profile
@@ -6,8 +6,8 @@ include falkon.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.cache/falkon 9nodeny ${HOME}/.cache/falkon
10noblacklist ${HOME}/.config/falkon 10nodeny ${HOME}/.config/falkon
11 11
12include disable-common.inc 12include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
@@ -19,10 +19,10 @@ include disable-xdg.inc
19 19
20mkdir ${HOME}/.cache/falkon 20mkdir ${HOME}/.cache/falkon
21mkdir ${HOME}/.config/falkon 21mkdir ${HOME}/.config/falkon
22whitelist ${DOWNLOADS} 22allow ${DOWNLOADS}
23whitelist ${HOME}/.cache/falkon 23allow ${HOME}/.cache/falkon
24whitelist ${HOME}/.config/falkon 24allow ${HOME}/.config/falkon
25whitelist /usr/share/falkon 25allow /usr/share/falkon
26include whitelist-common.inc 26include whitelist-common.inc
27include whitelist-runuser-common.inc 27include whitelist-runuser-common.inc
28include whitelist-usr-share-common.inc 28include whitelist-usr-share-common.inc
diff --git a/etc/profile-a-l/fbreader.profile b/etc/profile-a-l/fbreader.profile
index 8e81000fd..d141c6ed5 100644
--- a/etc/profile-a-l/fbreader.profile
+++ b/etc/profile-a-l/fbreader.profile
@@ -6,8 +6,8 @@ include fbreader.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.FBReader 9nodeny ${HOME}/.FBReader
10noblacklist ${DOCUMENTS} 10nodeny ${DOCUMENTS}
11 11
12include disable-common.inc 12include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
diff --git a/etc/profile-a-l/fdns.profile b/etc/profile-a-l/fdns.profile
index 31cb1776c..17a365053 100644
--- a/etc/profile-a-l/fdns.profile
+++ b/etc/profile-a-l/fdns.profile
@@ -5,11 +5,11 @@ include fdns.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist /sbin 8nodeny /sbin
9noblacklist /usr/sbin 9nodeny /usr/sbin
10 10
11blacklist /tmp/.X11-unix 11deny /tmp/.X11-unix
12blacklist ${RUNUSER}/wayland-* 12deny ${RUNUSER}/wayland-*
13 13
14include disable-common.inc 14include disable-common.inc
15include disable-devel.inc 15include disable-devel.inc
diff --git a/etc/profile-a-l/feedreader.profile b/etc/profile-a-l/feedreader.profile
index 664ec2da6..359be083e 100644
--- a/etc/profile-a-l/feedreader.profile
+++ b/etc/profile-a-l/feedreader.profile
@@ -6,8 +6,8 @@ include feedreader.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.cache/feedreader 9nodeny ${HOME}/.cache/feedreader
10noblacklist ${HOME}/.local/share/feedreader 10nodeny ${HOME}/.local/share/feedreader
11 11
12include disable-common.inc 12include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
@@ -20,9 +20,9 @@ include disable-xdg.inc
20 20
21mkdir ${HOME}/.cache/feedreader 21mkdir ${HOME}/.cache/feedreader
22mkdir ${HOME}/.local/share/feedreader 22mkdir ${HOME}/.local/share/feedreader
23whitelist ${HOME}/.cache/feedreader 23allow ${HOME}/.cache/feedreader
24whitelist ${HOME}/.local/share/feedreader 24allow ${HOME}/.local/share/feedreader
25whitelist /usr/share/feedreader 25allow /usr/share/feedreader
26include whitelist-common.inc 26include whitelist-common.inc
27include whitelist-runuser-common.inc 27include whitelist-runuser-common.inc
28include whitelist-usr-share-common.inc 28include whitelist-usr-share-common.inc
diff --git a/etc/profile-a-l/ferdi.profile b/etc/profile-a-l/ferdi.profile
index a2372ec8a..f60055f37 100644
--- a/etc/profile-a-l/ferdi.profile
+++ b/etc/profile-a-l/ferdi.profile
@@ -7,10 +7,10 @@ include globals.local
7 7
8ignore noexec /tmp 8ignore noexec /tmp
9 9
10noblacklist ${HOME}/.cache/Ferdi 10nodeny ${HOME}/.cache/Ferdi
11noblacklist ${HOME}/.config/Ferdi 11nodeny ${HOME}/.config/Ferdi
12noblacklist ${HOME}/.pki 12nodeny ${HOME}/.pki
13noblacklist ${HOME}/.local/share/pki 13nodeny ${HOME}/.local/share/pki
14 14
15include disable-common.inc 15include disable-common.inc
16include disable-devel.inc 16include disable-devel.inc
@@ -22,11 +22,11 @@ mkdir ${HOME}/.cache/Ferdi
22mkdir ${HOME}/.config/Ferdi 22mkdir ${HOME}/.config/Ferdi
23mkdir ${HOME}/.pki 23mkdir ${HOME}/.pki
24mkdir ${HOME}/.local/share/pki 24mkdir ${HOME}/.local/share/pki
25whitelist ${DOWNLOADS} 25allow ${DOWNLOADS}
26whitelist ${HOME}/.cache/Ferdi 26allow ${HOME}/.cache/Ferdi
27whitelist ${HOME}/.config/Ferdi 27allow ${HOME}/.config/Ferdi
28whitelist ${HOME}/.pki 28allow ${HOME}/.pki
29whitelist ${HOME}/.local/share/pki 29allow ${HOME}/.local/share/pki
30include whitelist-common.inc 30include whitelist-common.inc
31 31
32caps.drop all 32caps.drop all
diff --git a/etc/profile-a-l/fetchmail.profile b/etc/profile-a-l/fetchmail.profile
index 7358ed5c7..1e06ec29a 100644
--- a/etc/profile-a-l/fetchmail.profile
+++ b/etc/profile-a-l/fetchmail.profile
@@ -6,8 +6,8 @@ include fetchmail.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.fetchmailrc 9nodeny ${HOME}/.fetchmailrc
10noblacklist ${HOME}/.netrc 10nodeny ${HOME}/.netrc
11 11
12include disable-common.inc 12include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
diff --git a/etc/profile-a-l/ffmpeg.profile b/etc/profile-a-l/ffmpeg.profile
index 13ef1beb9..1a64183ab 100644
--- a/etc/profile-a-l/ffmpeg.profile
+++ b/etc/profile-a-l/ffmpeg.profile
@@ -7,8 +7,8 @@ include ffmpeg.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10noblacklist ${MUSIC} 10nodeny ${MUSIC}
11noblacklist ${VIDEOS} 11nodeny ${VIDEOS}
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
@@ -19,9 +19,9 @@ include disable-programs.inc
19include disable-shell.inc 19include disable-shell.inc
20include disable-xdg.inc 20include disable-xdg.inc
21 21
22whitelist /usr/share/devedeng 22allow /usr/share/devedeng
23whitelist /usr/share/ffmpeg 23allow /usr/share/ffmpeg
24whitelist /usr/share/qtchooser 24allow /usr/share/qtchooser
25include whitelist-usr-share-common.inc 25include whitelist-usr-share-common.inc
26include whitelist-var-common.inc 26include whitelist-var-common.inc
27 27
diff --git a/etc/profile-a-l/file-roller.profile b/etc/profile-a-l/file-roller.profile
index 4e651ed61..9f140850f 100644
--- a/etc/profile-a-l/file-roller.profile
+++ b/etc/profile-a-l/file-roller.profile
@@ -13,8 +13,8 @@ include disable-interpreters.inc
13include disable-passwdmgr.inc 13include disable-passwdmgr.inc
14include disable-programs.inc 14include disable-programs.inc
15 15
16whitelist /usr/libexec/file-roller 16allow /usr/libexec/file-roller
17whitelist /usr/share/file-roller 17allow /usr/share/file-roller
18include whitelist-runuser-common.inc 18include whitelist-runuser-common.inc
19include whitelist-usr-share-common.inc 19include whitelist-usr-share-common.inc
20include whitelist-var-common.inc 20include whitelist-var-common.inc
diff --git a/etc/profile-a-l/file.profile b/etc/profile-a-l/file.profile
index 5c7583605..426d1e72d 100644
--- a/etc/profile-a-l/file.profile
+++ b/etc/profile-a-l/file.profile
@@ -7,7 +7,7 @@ include file.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10blacklist ${RUNUSER} 10deny ${RUNUSER}
11 11
12include disable-common.inc 12include disable-common.inc
13include disable-exec.inc 13include disable-exec.inc
diff --git a/etc/profile-a-l/filezilla.profile b/etc/profile-a-l/filezilla.profile
index dc5def54f..d9e0e9da0 100644
--- a/etc/profile-a-l/filezilla.profile
+++ b/etc/profile-a-l/filezilla.profile
@@ -6,8 +6,8 @@ include filezilla.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/filezilla 9nodeny ${HOME}/.config/filezilla
10noblacklist ${HOME}/.filezilla 10nodeny ${HOME}/.filezilla
11 11
12# Allow python (blacklisted by disable-interpreters.inc) 12# Allow python (blacklisted by disable-interpreters.inc)
13include allow-python2.inc 13include allow-python2.inc
diff --git a/etc/profile-a-l/firedragon.profile b/etc/profile-a-l/firedragon.profile
index 77487161e..e22424794 100644
--- a/etc/profile-a-l/firedragon.profile
+++ b/etc/profile-a-l/firedragon.profile
@@ -6,13 +6,13 @@ include firedragon.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.cache/firedragon 9nodeny ${HOME}/.cache/firedragon
10noblacklist ${HOME}/.firedragon 10nodeny ${HOME}/.firedragon
11 11
12mkdir ${HOME}/.cache/firedragon 12mkdir ${HOME}/.cache/firedragon
13mkdir ${HOME}/.firedragon 13mkdir ${HOME}/.firedragon
14whitelist ${HOME}/.cache/firedragon 14allow ${HOME}/.cache/firedragon
15whitelist ${HOME}/.firedragon 15allow ${HOME}/.firedragon
16 16
17# Add the next lines to your firedragon.local if you want to use the migration wizard. 17# Add the next lines to your firedragon.local if you want to use the migration wizard.
18#noblacklist ${HOME}/.mozilla 18#noblacklist ${HOME}/.mozilla
diff --git a/etc/profile-a-l/firefox-common-addons.profile b/etc/profile-a-l/firefox-common-addons.profile
index d282f9a60..7e2e8760d 100644
--- a/etc/profile-a-l/firefox-common-addons.profile
+++ b/etc/profile-a-l/firefox-common-addons.profile
@@ -5,74 +5,74 @@ include firefox-common-addons.local
5ignore include whitelist-runuser-common.inc 5ignore include whitelist-runuser-common.inc
6ignore private-cache 6ignore private-cache
7 7
8noblacklist ${HOME}/.cache/youtube-dl 8nodeny ${HOME}/.cache/youtube-dl
9noblacklist ${HOME}/.config/kgetrc 9nodeny ${HOME}/.config/kgetrc
10noblacklist ${HOME}/.config/mpv 10nodeny ${HOME}/.config/mpv
11noblacklist ${HOME}/.config/okularpartrc 11nodeny ${HOME}/.config/okularpartrc
12noblacklist ${HOME}/.config/okularrc 12nodeny ${HOME}/.config/okularrc
13noblacklist ${HOME}/.config/qpdfview 13nodeny ${HOME}/.config/qpdfview
14noblacklist ${HOME}/.config/youtube-dl 14nodeny ${HOME}/.config/youtube-dl
15noblacklist ${HOME}/.kde/share/apps/kget 15nodeny ${HOME}/.kde/share/apps/kget
16noblacklist ${HOME}/.kde/share/apps/okular 16nodeny ${HOME}/.kde/share/apps/okular
17noblacklist ${HOME}/.kde/share/config/kgetrc 17nodeny ${HOME}/.kde/share/config/kgetrc
18noblacklist ${HOME}/.kde/share/config/okularpartrc 18nodeny ${HOME}/.kde/share/config/okularpartrc
19noblacklist ${HOME}/.kde/share/config/okularrc 19nodeny ${HOME}/.kde/share/config/okularrc
20noblacklist ${HOME}/.kde4/share/apps/kget 20nodeny ${HOME}/.kde4/share/apps/kget
21noblacklist ${HOME}/.kde4/share/apps/okular 21nodeny ${HOME}/.kde4/share/apps/okular
22noblacklist ${HOME}/.kde4/share/config/kgetrc 22nodeny ${HOME}/.kde4/share/config/kgetrc
23noblacklist ${HOME}/.kde4/share/config/okularpartrc 23nodeny ${HOME}/.kde4/share/config/okularpartrc
24noblacklist ${HOME}/.kde4/share/config/okularrc 24nodeny ${HOME}/.kde4/share/config/okularrc
25noblacklist ${HOME}/.local/share/kget 25nodeny ${HOME}/.local/share/kget
26noblacklist ${HOME}/.local/share/kxmlgui5/okular 26nodeny ${HOME}/.local/share/kxmlgui5/okular
27noblacklist ${HOME}/.local/share/okular 27nodeny ${HOME}/.local/share/okular
28noblacklist ${HOME}/.local/share/qpdfview 28nodeny ${HOME}/.local/share/qpdfview
29noblacklist ${HOME}/.netrc 29nodeny ${HOME}/.netrc
30 30
31whitelist ${HOME}/.cache/gnome-mplayer/plugin 31allow ${HOME}/.cache/gnome-mplayer/plugin
32whitelist ${HOME}/.cache/youtube-dl/youtube-sigfuncs 32allow ${HOME}/.cache/youtube-dl/youtube-sigfuncs
33whitelist ${HOME}/.config/gnome-mplayer 33allow ${HOME}/.config/gnome-mplayer
34whitelist ${HOME}/.config/kgetrc 34allow ${HOME}/.config/kgetrc
35whitelist ${HOME}/.config/mpv 35allow ${HOME}/.config/mpv
36whitelist ${HOME}/.config/okularpartrc 36allow ${HOME}/.config/okularpartrc
37whitelist ${HOME}/.config/okularrc 37allow ${HOME}/.config/okularrc
38whitelist ${HOME}/.config/pipelight-silverlight5.1 38allow ${HOME}/.config/pipelight-silverlight5.1
39whitelist ${HOME}/.config/pipelight-widevine 39allow ${HOME}/.config/pipelight-widevine
40whitelist ${HOME}/.config/qpdfview 40allow ${HOME}/.config/qpdfview
41whitelist ${HOME}/.config/youtube-dl 41allow ${HOME}/.config/youtube-dl
42whitelist ${HOME}/.kde/share/apps/kget 42allow ${HOME}/.kde/share/apps/kget
43whitelist ${HOME}/.kde/share/apps/okular 43allow ${HOME}/.kde/share/apps/okular
44whitelist ${HOME}/.kde/share/config/kgetrc 44allow ${HOME}/.kde/share/config/kgetrc
45whitelist ${HOME}/.kde/share/config/okularpartrc 45allow ${HOME}/.kde/share/config/okularpartrc
46whitelist ${HOME}/.kde/share/config/okularrc 46allow ${HOME}/.kde/share/config/okularrc
47whitelist ${HOME}/.kde4/share/apps/kget 47allow ${HOME}/.kde4/share/apps/kget
48whitelist ${HOME}/.kde4/share/apps/okular 48allow ${HOME}/.kde4/share/apps/okular
49whitelist ${HOME}/.kde4/share/config/kgetrc 49allow ${HOME}/.kde4/share/config/kgetrc
50whitelist ${HOME}/.kde4/share/config/okularpartrc 50allow ${HOME}/.kde4/share/config/okularpartrc
51whitelist ${HOME}/.kde4/share/config/okularrc 51allow ${HOME}/.kde4/share/config/okularrc
52whitelist ${HOME}/.keysnail.js 52allow ${HOME}/.keysnail.js
53whitelist ${HOME}/.lastpass 53allow ${HOME}/.lastpass
54whitelist ${HOME}/.local/share/kget 54allow ${HOME}/.local/share/kget
55whitelist ${HOME}/.local/share/kxmlgui5/okular 55allow ${HOME}/.local/share/kxmlgui5/okular
56whitelist ${HOME}/.local/share/okular 56allow ${HOME}/.local/share/okular
57whitelist ${HOME}/.local/share/qpdfview 57allow ${HOME}/.local/share/qpdfview
58whitelist ${HOME}/.local/share/tridactyl 58allow ${HOME}/.local/share/tridactyl
59whitelist ${HOME}/.netrc 59allow ${HOME}/.netrc
60whitelist ${HOME}/.pentadactyl 60allow ${HOME}/.pentadactyl
61whitelist ${HOME}/.pentadactylrc 61allow ${HOME}/.pentadactylrc
62whitelist ${HOME}/.tridactylrc 62allow ${HOME}/.tridactylrc
63whitelist ${HOME}/.vimperator 63allow ${HOME}/.vimperator
64whitelist ${HOME}/.vimperatorrc 64allow ${HOME}/.vimperatorrc
65whitelist ${HOME}/.wine-pipelight 65allow ${HOME}/.wine-pipelight
66whitelist ${HOME}/.wine-pipelight64 66allow ${HOME}/.wine-pipelight64
67whitelist ${HOME}/.zotero 67allow ${HOME}/.zotero
68whitelist ${HOME}/dwhelper 68allow ${HOME}/dwhelper
69whitelist /usr/share/lua 69allow /usr/share/lua
70whitelist /usr/share/lua* 70allow /usr/share/lua*
71whitelist /usr/share/vulkan 71allow /usr/share/vulkan
72 72
73# GNOME Shell integration (chrome-gnome-shell) needs dbus and python 73# GNOME Shell integration (chrome-gnome-shell) needs dbus and python
74noblacklist ${HOME}/.local/share/gnome-shell 74nodeny ${HOME}/.local/share/gnome-shell
75whitelist ${HOME}/.local/share/gnome-shell 75allow ${HOME}/.local/share/gnome-shell
76dbus-user.talk ca.desrt.dconf 76dbus-user.talk ca.desrt.dconf
77dbus-user.talk org.gnome.ChromeGnomeShell 77dbus-user.talk org.gnome.ChromeGnomeShell
78dbus-user.talk org.gnome.Shell 78dbus-user.talk org.gnome.Shell
diff --git a/etc/profile-a-l/firefox-common.profile b/etc/profile-a-l/firefox-common.profile
index 8b74ed979..cb0fae5dc 100644
--- a/etc/profile-a-l/firefox-common.profile
+++ b/etc/profile-a-l/firefox-common.profile
@@ -12,8 +12,8 @@ include firefox-common.local
12# Add the next line to your firefox-common.local to allow access to common programs/addons/plugins. 12# Add the next line to your firefox-common.local to allow access to common programs/addons/plugins.
13#include firefox-common-addons.profile 13#include firefox-common-addons.profile
14 14
15noblacklist ${HOME}/.pki 15nodeny ${HOME}/.pki
16noblacklist ${HOME}/.local/share/pki 16nodeny ${HOME}/.local/share/pki
17 17
18include disable-common.inc 18include disable-common.inc
19include disable-devel.inc 19include disable-devel.inc
@@ -23,9 +23,9 @@ include disable-programs.inc
23 23
24mkdir ${HOME}/.pki 24mkdir ${HOME}/.pki
25mkdir ${HOME}/.local/share/pki 25mkdir ${HOME}/.local/share/pki
26whitelist ${DOWNLOADS} 26allow ${DOWNLOADS}
27whitelist ${HOME}/.pki 27allow ${HOME}/.pki
28whitelist ${HOME}/.local/share/pki 28allow ${HOME}/.local/share/pki
29include whitelist-common.inc 29include whitelist-common.inc
30include whitelist-runuser-common.inc 30include whitelist-runuser-common.inc
31include whitelist-var-common.inc 31include whitelist-var-common.inc
diff --git a/etc/profile-a-l/firefox-esr.profile b/etc/profile-a-l/firefox-esr.profile
index 5e69fdb51..4fd315fdf 100644
--- a/etc/profile-a-l/firefox-esr.profile
+++ b/etc/profile-a-l/firefox-esr.profile
@@ -6,7 +6,7 @@ include firefox-esr.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9whitelist /usr/share/firefox-esr 9allow /usr/share/firefox-esr
10 10
11# Redirect 11# Redirect
12include firefox.profile 12include firefox.profile
diff --git a/etc/profile-a-l/firefox.profile b/etc/profile-a-l/firefox.profile
index 3ad67734d..8acfe7c2a 100644
--- a/etc/profile-a-l/firefox.profile
+++ b/etc/profile-a-l/firefox.profile
@@ -14,27 +14,27 @@ include globals.local
14# https://github.com/netblue30/firejail/wiki/Frequently-Asked-Questions#how-do-i-run-two-instances-of-firefox 14# https://github.com/netblue30/firejail/wiki/Frequently-Asked-Questions#how-do-i-run-two-instances-of-firefox
15# https://github.com/netblue30/firejail/issues/4206#issuecomment-824806968 15# https://github.com/netblue30/firejail/issues/4206#issuecomment-824806968
16 16
17noblacklist ${HOME}/.cache/mozilla 17nodeny ${HOME}/.cache/mozilla
18noblacklist ${HOME}/.mozilla 18nodeny ${HOME}/.mozilla
19 19
20blacklist /usr/libexec 20deny /usr/libexec
21 21
22mkdir ${HOME}/.cache/mozilla/firefox 22mkdir ${HOME}/.cache/mozilla/firefox
23mkdir ${HOME}/.mozilla 23mkdir ${HOME}/.mozilla
24whitelist ${HOME}/.cache/mozilla/firefox 24allow ${HOME}/.cache/mozilla/firefox
25whitelist ${HOME}/.mozilla 25allow ${HOME}/.mozilla
26 26
27# Add one of the following whitelist options to your firefox.local to enable KeePassXC Plugin support. 27# Add one of the following whitelist options to your firefox.local to enable KeePassXC Plugin support.
28# NOTE: start KeePassXC before Firefox and keep it open to allow communication between them. 28# NOTE: start KeePassXC before Firefox and keep it open to allow communication between them.
29#whitelist ${RUNUSER}/kpxc_server 29#whitelist ${RUNUSER}/kpxc_server
30#whitelist ${RUNUSER}/org.keepassxc.KeePassXC.BrowserServer 30#whitelist ${RUNUSER}/org.keepassxc.KeePassXC.BrowserServer
31 31
32whitelist /usr/share/doc 32allow /usr/share/doc
33whitelist /usr/share/firefox 33allow /usr/share/firefox
34whitelist /usr/share/gnome-shell/search-providers/firefox-search-provider.ini 34allow /usr/share/gnome-shell/search-providers/firefox-search-provider.ini
35whitelist /usr/share/gtk-doc/html 35allow /usr/share/gtk-doc/html
36whitelist /usr/share/mozilla 36allow /usr/share/mozilla
37whitelist /usr/share/webext 37allow /usr/share/webext
38include whitelist-usr-share-common.inc 38include whitelist-usr-share-common.inc
39 39
40# firefox requires a shell to launch on Arch - add the next line to your firefox.local to enable private-bin. 40# firefox requires a shell to launch on Arch - add the next line to your firefox.local to enable private-bin.
diff --git a/etc/profile-a-l/five-or-more.profile b/etc/profile-a-l/five-or-more.profile
index 2c86d3ac7..bd1becaf0 100644
--- a/etc/profile-a-l/five-or-more.profile
+++ b/etc/profile-a-l/five-or-more.profile
@@ -6,12 +6,12 @@ include five-or-more.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.local/share/five-or-more 9nodeny ${HOME}/.local/share/five-or-more
10 10
11mkdir ${HOME}/.local/share/five-or-more 11mkdir ${HOME}/.local/share/five-or-more
12whitelist ${HOME}/.local/share/five-or-more 12allow ${HOME}/.local/share/five-or-more
13 13
14whitelist /usr/share/five-or-more 14allow /usr/share/five-or-more
15 15
16private-bin five-or-more 16private-bin five-or-more
17 17
diff --git a/etc/profile-a-l/flameshot.profile b/etc/profile-a-l/flameshot.profile
index 55af96c84..f16a65536 100644
--- a/etc/profile-a-l/flameshot.profile
+++ b/etc/profile-a-l/flameshot.profile
@@ -7,9 +7,9 @@ include flameshot.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10noblacklist ${PICTURES} 10nodeny ${PICTURES}
11noblacklist ${HOME}/.config/Dharkael 11nodeny ${HOME}/.config/Dharkael
12noblacklist ${HOME}/.config/flameshot 12nodeny ${HOME}/.config/flameshot
13 13
14include disable-common.inc 14include disable-common.inc
15include disable-devel.inc 15include disable-devel.inc
@@ -25,7 +25,7 @@ include disable-xdg.inc
25#whitelist ${PICTURES} 25#whitelist ${PICTURES}
26#whitelist ${HOME}/.config/Dharkael 26#whitelist ${HOME}/.config/Dharkael
27#whitelist ${HOME}/.config/flameshot 27#whitelist ${HOME}/.config/flameshot
28whitelist /usr/share/flameshot 28allow /usr/share/flameshot
29#include whitelist-common.inc 29#include whitelist-common.inc
30include whitelist-runuser-common.inc 30include whitelist-runuser-common.inc
31include whitelist-usr-share-common.inc 31include whitelist-usr-share-common.inc
diff --git a/etc/profile-a-l/flashpeak-slimjet.profile b/etc/profile-a-l/flashpeak-slimjet.profile
index 310fb378f..af114e129 100644
--- a/etc/profile-a-l/flashpeak-slimjet.profile
+++ b/etc/profile-a-l/flashpeak-slimjet.profile
@@ -10,13 +10,13 @@ ignore whitelist /usr/share/chromium
10ignore include whitelist-runuser-common.inc 10ignore include whitelist-runuser-common.inc
11ignore include whitelist-usr-share-common.inc 11ignore include whitelist-usr-share-common.inc
12 12
13noblacklist ${HOME}/.cache/slimjet 13nodeny ${HOME}/.cache/slimjet
14noblacklist ${HOME}/.config/slimjet 14nodeny ${HOME}/.config/slimjet
15 15
16mkdir ${HOME}/.cache/slimjet 16mkdir ${HOME}/.cache/slimjet
17mkdir ${HOME}/.config/slimjet 17mkdir ${HOME}/.config/slimjet
18whitelist ${HOME}/.cache/slimjet 18allow ${HOME}/.cache/slimjet
19whitelist ${HOME}/.config/slimjet 19allow ${HOME}/.config/slimjet
20 20
21# Redirect 21# Redirect
22include chromium-common.profile 22include chromium-common.profile
diff --git a/etc/profile-a-l/flowblade.profile b/etc/profile-a-l/flowblade.profile
index a4421e3ce..505763fb9 100644
--- a/etc/profile-a-l/flowblade.profile
+++ b/etc/profile-a-l/flowblade.profile
@@ -6,8 +6,8 @@ include flowblade.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/flowblade 9nodeny ${HOME}/.config/flowblade
10noblacklist ${HOME}/.flowblade 10nodeny ${HOME}/.flowblade
11 11
12# Allow python (blacklisted by disable-interpreters.inc) 12# Allow python (blacklisted by disable-interpreters.inc)
13include allow-python2.inc 13include allow-python2.inc
diff --git a/etc/profile-a-l/fluxbox.profile b/etc/profile-a-l/fluxbox.profile
index 1210f365c..a22c0e103 100644
--- a/etc/profile-a-l/fluxbox.profile
+++ b/etc/profile-a-l/fluxbox.profile
@@ -7,7 +7,7 @@ include fluxbox.local
7include globals.local 7include globals.local
8 8
9# all applications started in fluxbox will run in this profile 9# all applications started in fluxbox will run in this profile
10noblacklist ${HOME}/.fluxbox 10nodeny ${HOME}/.fluxbox
11include disable-common.inc 11include disable-common.inc
12 12
13caps.drop all 13caps.drop all
diff --git a/etc/profile-a-l/font-manager.profile b/etc/profile-a-l/font-manager.profile
index cd0129436..ff9167c1a 100644
--- a/etc/profile-a-l/font-manager.profile
+++ b/etc/profile-a-l/font-manager.profile
@@ -6,8 +6,8 @@ include font-manager.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.cache/font-manager 9nodeny ${HOME}/.cache/font-manager
10noblacklist ${HOME}/.config/font-manager 10nodeny ${HOME}/.config/font-manager
11 11
12# Allow python (blacklisted by disable-interpreters.inc) 12# Allow python (blacklisted by disable-interpreters.inc)
13include allow-python2.inc 13include allow-python2.inc
@@ -24,9 +24,9 @@ include disable-xdg.inc
24 24
25mkdir ${HOME}/.cache/font-manager 25mkdir ${HOME}/.cache/font-manager
26mkdir ${HOME}/.config/font-manager 26mkdir ${HOME}/.config/font-manager
27whitelist ${HOME}/.cache/font-manager 27allow ${HOME}/.cache/font-manager
28whitelist ${HOME}/.config/font-manager 28allow ${HOME}/.config/font-manager
29whitelist /usr/share/font-manager 29allow /usr/share/font-manager
30include whitelist-common.inc 30include whitelist-common.inc
31include whitelist-usr-share-common.inc 31include whitelist-usr-share-common.inc
32include whitelist-var-common.inc 32include whitelist-var-common.inc
diff --git a/etc/profile-a-l/fontforge.profile b/etc/profile-a-l/fontforge.profile
index bd1495877..64c7655e2 100644
--- a/etc/profile-a-l/fontforge.profile
+++ b/etc/profile-a-l/fontforge.profile
@@ -6,8 +6,8 @@ include fontforge.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.FontForge 9nodeny ${HOME}/.FontForge
10noblacklist ${DOCUMENTS} 10nodeny ${DOCUMENTS}
11 11
12# Allow python (blacklisted by disable-interpreters.inc) 12# Allow python (blacklisted by disable-interpreters.inc)
13include allow-python2.inc 13include allow-python2.inc
diff --git a/etc/profile-a-l/fossamail.profile b/etc/profile-a-l/fossamail.profile
index 2d700d336..5e5a12794 100644
--- a/etc/profile-a-l/fossamail.profile
+++ b/etc/profile-a-l/fossamail.profile
@@ -6,16 +6,16 @@ include fossamail.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.cache/fossamail 9nodeny ${HOME}/.cache/fossamail
10noblacklist ${HOME}/.fossamail 10nodeny ${HOME}/.fossamail
11noblacklist ${HOME}/.gnupg 11nodeny ${HOME}/.gnupg
12 12
13mkdir ${HOME}/.cache/fossamail 13mkdir ${HOME}/.cache/fossamail
14mkdir ${HOME}/.fossamail 14mkdir ${HOME}/.fossamail
15mkdir ${HOME}/.gnupg 15mkdir ${HOME}/.gnupg
16whitelist ${HOME}/.cache/fossamail 16allow ${HOME}/.cache/fossamail
17whitelist ${HOME}/.fossamail 17allow ${HOME}/.fossamail
18whitelist ${HOME}/.gnupg 18allow ${HOME}/.gnupg
19include whitelist-common.inc 19include whitelist-common.inc
20 20
21# allow browsers 21# allow browsers
diff --git a/etc/profile-a-l/four-in-a-row.profile b/etc/profile-a-l/four-in-a-row.profile
index eb0c43ca5..97fd4a626 100644
--- a/etc/profile-a-l/four-in-a-row.profile
+++ b/etc/profile-a-l/four-in-a-row.profile
@@ -9,7 +9,7 @@ include globals.local
9ignore machine-id 9ignore machine-id
10ignore nosound 10ignore nosound
11 11
12whitelist /usr/share/four-in-a-row 12allow /usr/share/four-in-a-row
13 13
14private-bin four-in-a-row 14private-bin four-in-a-row
15 15
diff --git a/etc/profile-a-l/fractal.profile b/etc/profile-a-l/fractal.profile
index 1b1d031b4..8edc9b02d 100644
--- a/etc/profile-a-l/fractal.profile
+++ b/etc/profile-a-l/fractal.profile
@@ -6,7 +6,7 @@ include fractal.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.cache/fractal 9nodeny ${HOME}/.cache/fractal
10 10
11# Allow python (blacklisted by disable-interpreters.inc) 11# Allow python (blacklisted by disable-interpreters.inc)
12include allow-python2.inc 12include allow-python2.inc
@@ -22,8 +22,8 @@ include disable-shell.inc
22include disable-xdg.inc 22include disable-xdg.inc
23 23
24mkdir ${HOME}/.cache/fractal 24mkdir ${HOME}/.cache/fractal
25whitelist ${HOME}/.cache/fractal 25allow ${HOME}/.cache/fractal
26whitelist ${DOWNLOADS} 26allow ${DOWNLOADS}
27include whitelist-common.inc 27include whitelist-common.inc
28include whitelist-runuser-common.inc 28include whitelist-runuser-common.inc
29include whitelist-usr-share-common.inc 29include whitelist-usr-share-common.inc
diff --git a/etc/profile-a-l/franz.profile b/etc/profile-a-l/franz.profile
index 9b780a572..1a8ec8f99 100644
--- a/etc/profile-a-l/franz.profile
+++ b/etc/profile-a-l/franz.profile
@@ -7,10 +7,10 @@ include globals.local
7 7
8ignore noexec /tmp 8ignore noexec /tmp
9 9
10noblacklist ${HOME}/.cache/Franz 10nodeny ${HOME}/.cache/Franz
11noblacklist ${HOME}/.config/Franz 11nodeny ${HOME}/.config/Franz
12noblacklist ${HOME}/.pki 12nodeny ${HOME}/.pki
13noblacklist ${HOME}/.local/share/pki 13nodeny ${HOME}/.local/share/pki
14 14
15include disable-common.inc 15include disable-common.inc
16include disable-devel.inc 16include disable-devel.inc
@@ -22,11 +22,11 @@ mkdir ${HOME}/.cache/Franz
22mkdir ${HOME}/.config/Franz 22mkdir ${HOME}/.config/Franz
23mkdir ${HOME}/.pki 23mkdir ${HOME}/.pki
24mkdir ${HOME}/.local/share/pki 24mkdir ${HOME}/.local/share/pki
25whitelist ${DOWNLOADS} 25allow ${DOWNLOADS}
26whitelist ${HOME}/.cache/Franz 26allow ${HOME}/.cache/Franz
27whitelist ${HOME}/.config/Franz 27allow ${HOME}/.config/Franz
28whitelist ${HOME}/.pki 28allow ${HOME}/.pki
29whitelist ${HOME}/.local/share/pki 29allow ${HOME}/.local/share/pki
30include whitelist-common.inc 30include whitelist-common.inc
31 31
32caps.drop all 32caps.drop all
diff --git a/etc/profile-a-l/freecad.profile b/etc/profile-a-l/freecad.profile
index 8043d0530..a45ad4c7a 100644
--- a/etc/profile-a-l/freecad.profile
+++ b/etc/profile-a-l/freecad.profile
@@ -6,8 +6,8 @@ include freecad.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/FreeCAD 9nodeny ${HOME}/.config/FreeCAD
10noblacklist ${DOCUMENTS} 10nodeny ${DOCUMENTS}
11 11
12# Allow python (blacklisted by disable-interpreters.inc) 12# Allow python (blacklisted by disable-interpreters.inc)
13include allow-python2.inc 13include allow-python2.inc
diff --git a/etc/profile-a-l/freeciv.profile b/etc/profile-a-l/freeciv.profile
index 23c19682c..20abd4056 100644
--- a/etc/profile-a-l/freeciv.profile
+++ b/etc/profile-a-l/freeciv.profile
@@ -6,7 +6,7 @@ include freeciv.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.freeciv 9nodeny ${HOME}/.freeciv
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -17,7 +17,7 @@ include disable-programs.inc
17include disable-xdg.inc 17include disable-xdg.inc
18 18
19mkdir ${HOME}/.freeciv 19mkdir ${HOME}/.freeciv
20whitelist ${HOME}/.freeciv 20allow ${HOME}/.freeciv
21include whitelist-common.inc 21include whitelist-common.inc
22include whitelist-var-common.inc 22include whitelist-var-common.inc
23 23
diff --git a/etc/profile-a-l/freecol.profile b/etc/profile-a-l/freecol.profile
index 93fa7da03..79ccf4101 100644
--- a/etc/profile-a-l/freecol.profile
+++ b/etc/profile-a-l/freecol.profile
@@ -6,10 +6,10 @@ include freecol.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.freecol 9nodeny ${HOME}/.freecol
10noblacklist ${HOME}/.cache/freecol 10nodeny ${HOME}/.cache/freecol
11noblacklist ${HOME}/.config/freecol 11nodeny ${HOME}/.config/freecol
12noblacklist ${HOME}/.local/share/freecol 12nodeny ${HOME}/.local/share/freecol
13 13
14# Allow java (blacklisted by disable-devel.inc) 14# Allow java (blacklisted by disable-devel.inc)
15include allow-java.inc 15include allow-java.inc
@@ -26,11 +26,11 @@ mkdir ${HOME}/.java
26mkdir ${HOME}/.cache/freecol 26mkdir ${HOME}/.cache/freecol
27mkdir ${HOME}/.config/freecol 27mkdir ${HOME}/.config/freecol
28mkdir ${HOME}/.local/share/freecol 28mkdir ${HOME}/.local/share/freecol
29whitelist ${HOME}/.freecol 29allow ${HOME}/.freecol
30whitelist ${HOME}/.java 30allow ${HOME}/.java
31whitelist ${HOME}/.cache/freecol 31allow ${HOME}/.cache/freecol
32whitelist ${HOME}/.config/freecol 32allow ${HOME}/.config/freecol
33whitelist ${HOME}/.local/share/freecol 33allow ${HOME}/.local/share/freecol
34include whitelist-common.inc 34include whitelist-common.inc
35include whitelist-var-common.inc 35include whitelist-var-common.inc
36 36
diff --git a/etc/profile-a-l/freemind.profile b/etc/profile-a-l/freemind.profile
index 699177039..ba52dd208 100644
--- a/etc/profile-a-l/freemind.profile
+++ b/etc/profile-a-l/freemind.profile
@@ -6,8 +6,8 @@ include freemind.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${DOCUMENTS} 9nodeny ${DOCUMENTS}
10noblacklist ${HOME}/.freemind 10nodeny ${HOME}/.freemind
11 11
12# Allow java (blacklisted by disable-devel.inc) 12# Allow java (blacklisted by disable-devel.inc)
13include allow-java.inc 13include allow-java.inc
diff --git a/etc/profile-a-l/freetube.profile b/etc/profile-a-l/freetube.profile
index e6aff533d..4c321322c 100644
--- a/etc/profile-a-l/freetube.profile
+++ b/etc/profile-a-l/freetube.profile
@@ -6,12 +6,12 @@ include freetube.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/FreeTube 9nodeny ${HOME}/.config/FreeTube
10 10
11include disable-shell.inc 11include disable-shell.inc
12 12
13mkdir ${HOME}/.config/FreeTube 13mkdir ${HOME}/.config/FreeTube
14whitelist ${HOME}/.config/FreeTube 14allow ${HOME}/.config/FreeTube
15 15
16private-bin freetube 16private-bin freetube
17private-etc alsa,alternatives,asound.conf,ca-certificates,crypto-policies,fonts,gtk-2.0,gtk-3.0,host.conf,hostname,hosts,mime.types,nsswitch.conf,pki,pulse,resolv.conf,ssl,X11,xdg 17private-etc alsa,alternatives,asound.conf,ca-certificates,crypto-policies,fonts,gtk-2.0,gtk-3.0,host.conf,hostname,hosts,mime.types,nsswitch.conf,pki,pulse,resolv.conf,ssl,X11,xdg
diff --git a/etc/profile-a-l/frogatto.profile b/etc/profile-a-l/frogatto.profile
index b4ad81046..3a6dfcfd6 100644
--- a/etc/profile-a-l/frogatto.profile
+++ b/etc/profile-a-l/frogatto.profile
@@ -6,7 +6,7 @@ include frogatto.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.frogatto 9nodeny ${HOME}/.frogatto
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -17,9 +17,9 @@ include disable-programs.inc
17include disable-xdg.inc 17include disable-xdg.inc
18 18
19mkdir ${HOME}/.frogatto 19mkdir ${HOME}/.frogatto
20whitelist ${HOME}/.frogatto 20allow ${HOME}/.frogatto
21whitelist /usr/libexec/frogatto 21allow /usr/libexec/frogatto
22whitelist /usr/share/frogatto 22allow /usr/share/frogatto
23include whitelist-common.inc 23include whitelist-common.inc
24include whitelist-runuser-common.inc 24include whitelist-runuser-common.inc
25include whitelist-usr-share-common.inc 25include whitelist-usr-share-common.inc
diff --git a/etc/profile-a-l/frozen-bubble.profile b/etc/profile-a-l/frozen-bubble.profile
index 76352e41e..12eca8eb0 100644
--- a/etc/profile-a-l/frozen-bubble.profile
+++ b/etc/profile-a-l/frozen-bubble.profile
@@ -6,7 +6,7 @@ include frozen-bubble.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.frozen-bubble 9nodeny ${HOME}/.frozen-bubble
10 10
11# Allow perl (blacklisted by disable-interpreters.inc) 11# Allow perl (blacklisted by disable-interpreters.inc)
12include allow-perl.inc 12include allow-perl.inc
@@ -20,7 +20,7 @@ include disable-programs.inc
20include disable-xdg.inc 20include disable-xdg.inc
21 21
22mkdir ${HOME}/.frozen-bubble 22mkdir ${HOME}/.frozen-bubble
23whitelist ${HOME}/.frozen-bubble 23allow ${HOME}/.frozen-bubble
24include whitelist-common.inc 24include whitelist-common.inc
25include whitelist-runuser-common.inc 25include whitelist-runuser-common.inc
26include whitelist-usr-share-common.inc 26include whitelist-usr-share-common.inc
diff --git a/etc/profile-a-l/funnyboat.profile b/etc/profile-a-l/funnyboat.profile
index 8852925b1..07030df4b 100644
--- a/etc/profile-a-l/funnyboat.profile
+++ b/etc/profile-a-l/funnyboat.profile
@@ -5,7 +5,7 @@ include funnyboat.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${HOME}/.funnyboat 8nodeny ${HOME}/.funnyboat
9 9
10ignore noexec /dev/shm 10ignore noexec /dev/shm
11include allow-python2.inc 11include allow-python2.inc
@@ -21,12 +21,12 @@ include disable-programs.inc
21include disable-xdg.inc 21include disable-xdg.inc
22 22
23mkdir ${HOME}/.funnyboat 23mkdir ${HOME}/.funnyboat
24whitelist ${HOME}/.funnyboat 24allow ${HOME}/.funnyboat
25include whitelist-common.inc 25include whitelist-common.inc
26include whitelist-runuser-common.inc 26include whitelist-runuser-common.inc
27whitelist /usr/share/funnyboat 27allow /usr/share/funnyboat
28# Debian: 28# Debian:
29whitelist /usr/share/games/funnyboat 29allow /usr/share/games/funnyboat
30include whitelist-usr-share-common.inc 30include whitelist-usr-share-common.inc
31include whitelist-var-common.inc 31include whitelist-var-common.inc
32 32
diff --git a/etc/profile-a-l/gajim.profile b/etc/profile-a-l/gajim.profile
index ed3f0357d..4cd2cb1e6 100644
--- a/etc/profile-a-l/gajim.profile
+++ b/etc/profile-a-l/gajim.profile
@@ -6,10 +6,10 @@ include gajim.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.gnupg 9nodeny ${HOME}/.gnupg
10noblacklist ${HOME}/.cache/gajim 10nodeny ${HOME}/.cache/gajim
11noblacklist ${HOME}/.config/gajim 11nodeny ${HOME}/.config/gajim
12noblacklist ${HOME}/.local/share/gajim 12nodeny ${HOME}/.local/share/gajim
13 13
14# Allow python (blacklisted by disable-interpreters.inc) 14# Allow python (blacklisted by disable-interpreters.inc)
15#include allow-python2.inc 15#include allow-python2.inc
@@ -28,14 +28,14 @@ mkdir ${HOME}/.gnupg
28mkdir ${HOME}/.cache/gajim 28mkdir ${HOME}/.cache/gajim
29mkdir ${HOME}/.config/gajim 29mkdir ${HOME}/.config/gajim
30mkdir ${HOME}/.local/share/gajim 30mkdir ${HOME}/.local/share/gajim
31whitelist ${HOME}/.gnupg 31allow ${HOME}/.gnupg
32whitelist ${HOME}/.cache/gajim 32allow ${HOME}/.cache/gajim
33whitelist ${HOME}/.config/gajim 33allow ${HOME}/.config/gajim
34whitelist ${HOME}/.local/share/gajim 34allow ${HOME}/.local/share/gajim
35whitelist ${DOWNLOADS} 35allow ${DOWNLOADS}
36whitelist ${RUNUSER}/gnupg 36allow ${RUNUSER}/gnupg
37whitelist /usr/share/gnupg 37allow /usr/share/gnupg
38whitelist /usr/share/gnupg2 38allow /usr/share/gnupg2
39include whitelist-common.inc 39include whitelist-common.inc
40include whitelist-runuser-common.inc 40include whitelist-runuser-common.inc
41include whitelist-usr-share-common.inc 41include whitelist-usr-share-common.inc
diff --git a/etc/profile-a-l/galculator.profile b/etc/profile-a-l/galculator.profile
index 550b3808b..0b1b595a6 100644
--- a/etc/profile-a-l/galculator.profile
+++ b/etc/profile-a-l/galculator.profile
@@ -6,7 +6,7 @@ include galculator.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/galculator 9nodeny ${HOME}/.config/galculator
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -18,7 +18,7 @@ include disable-shell.inc
18include disable-xdg.inc 18include disable-xdg.inc
19 19
20mkdir ${HOME}/.config/galculator 20mkdir ${HOME}/.config/galculator
21whitelist ${HOME}/.config/galculator 21allow ${HOME}/.config/galculator
22include whitelist-common.inc 22include whitelist-common.inc
23include whitelist-var-common.inc 23include whitelist-var-common.inc
24 24
diff --git a/etc/profile-a-l/gapplication.profile b/etc/profile-a-l/gapplication.profile
index 3a8c055f2..00b830234 100644
--- a/etc/profile-a-l/gapplication.profile
+++ b/etc/profile-a-l/gapplication.profile
@@ -6,8 +6,8 @@ include gapplication.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9blacklist ${RUNUSER}/wayland-* 9deny ${RUNUSER}/wayland-*
10blacklist /usr/libexec 10deny /usr/libexec
11 11
12include disable-common.inc 12include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
diff --git a/etc/profile-a-l/gcloud.profile b/etc/profile-a-l/gcloud.profile
index 388f4c0df..896a100fc 100644
--- a/etc/profile-a-l/gcloud.profile
+++ b/etc/profile-a-l/gcloud.profile
@@ -8,9 +8,9 @@ include globals.local
8# noexec ${HOME} will break user-local installs of gcloud tooling 8# noexec ${HOME} will break user-local installs of gcloud tooling
9ignore noexec ${HOME} 9ignore noexec ${HOME}
10 10
11noblacklist ${HOME}/.boto 11nodeny ${HOME}/.boto
12noblacklist ${HOME}/.config/gcloud 12nodeny ${HOME}/.config/gcloud
13noblacklist /var/run/docker.sock 13nodeny /var/run/docker.sock
14 14
15include disable-common.inc 15include disable-common.inc
16include disable-devel.inc 16include disable-devel.inc
diff --git a/etc/profile-a-l/gconf-editor.profile b/etc/profile-a-l/gconf-editor.profile
index cb39174e5..8f72f0b34 100644
--- a/etc/profile-a-l/gconf-editor.profile
+++ b/etc/profile-a-l/gconf-editor.profile
@@ -7,9 +7,9 @@ include gconf-editor.local
7# added by included profile 7# added by included profile
8#include globals.local 8#include globals.local
9 9
10blacklist /tmp/.X11-unix 10deny /tmp/.X11-unix
11 11
12whitelist /usr/share/gconf-editor 12allow /usr/share/gconf-editor
13 13
14ignore x11 none 14ignore x11 none
15 15
diff --git a/etc/profile-a-l/gconf.profile b/etc/profile-a-l/gconf.profile
index fec1a555a..8c7013574 100644
--- a/etc/profile-a-l/gconf.profile
+++ b/etc/profile-a-l/gconf.profile
@@ -6,9 +6,9 @@ include gconf.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9blacklist ${RUNUSER}/wayland-* 9deny ${RUNUSER}/wayland-*
10 10
11noblacklist ${HOME}/.config/gconf 11nodeny ${HOME}/.config/gconf
12 12
13# Allow python (blacklisted by disable-interpreters.inc) 13# Allow python (blacklisted by disable-interpreters.inc)
14include allow-python2.inc 14include allow-python2.inc
@@ -23,9 +23,9 @@ include disable-programs.inc
23include disable-xdg.inc 23include disable-xdg.inc
24 24
25mkdir ${HOME}/.config/gconf 25mkdir ${HOME}/.config/gconf
26whitelist ${HOME}/.config/gconf 26allow ${HOME}/.config/gconf
27whitelist /usr/share/GConf 27allow /usr/share/GConf
28whitelist /usr/share/gconf 28allow /usr/share/gconf
29include whitelist-common.inc 29include whitelist-common.inc
30include whitelist-usr-share-common.inc 30include whitelist-usr-share-common.inc
31include whitelist-var-common.inc 31include whitelist-var-common.inc
diff --git a/etc/profile-a-l/geany.profile b/etc/profile-a-l/geany.profile
index 6fdb9b37a..706a85c75 100644
--- a/etc/profile-a-l/geany.profile
+++ b/etc/profile-a-l/geany.profile
@@ -6,7 +6,7 @@ include geany.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/geany 9nodeny ${HOME}/.config/geany
10 10
11# Allows files commonly used by IDEs 11# Allows files commonly used by IDEs
12include allow-common-devel.inc 12include allow-common-devel.inc
diff --git a/etc/profile-a-l/geary.profile b/etc/profile-a-l/geary.profile
index 74e135a7c..512fc1e59 100644
--- a/etc/profile-a-l/geary.profile
+++ b/etc/profile-a-l/geary.profile
@@ -6,14 +6,14 @@ include geary.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.cache/evolution 9nodeny ${HOME}/.cache/evolution
10noblacklist ${HOME}/.cache/folks 10nodeny ${HOME}/.cache/folks
11noblacklist ${HOME}/.cache/geary 11nodeny ${HOME}/.cache/geary
12noblacklist ${HOME}/.config/evolution 12nodeny ${HOME}/.config/evolution
13noblacklist ${HOME}/.config/geary 13nodeny ${HOME}/.config/geary
14noblacklist ${HOME}/.local/share/evolution 14nodeny ${HOME}/.local/share/evolution
15noblacklist ${HOME}/.local/share/geary 15nodeny ${HOME}/.local/share/geary
16noblacklist ${HOME}/.mozilla 16nodeny ${HOME}/.mozilla
17 17
18include disable-common.inc 18include disable-common.inc
19include disable-devel.inc 19include disable-devel.inc
@@ -31,16 +31,16 @@ mkdir ${HOME}/.config/evolution
31mkdir ${HOME}/.config/geary 31mkdir ${HOME}/.config/geary
32mkdir ${HOME}/.local/share/evolution 32mkdir ${HOME}/.local/share/evolution
33mkdir ${HOME}/.local/share/geary 33mkdir ${HOME}/.local/share/geary
34whitelist ${DOWNLOADS} 34allow ${DOWNLOADS}
35whitelist ${HOME}/.cache/evolution 35allow ${HOME}/.cache/evolution
36whitelist ${HOME}/.cache/folks 36allow ${HOME}/.cache/folks
37whitelist ${HOME}/.cache/geary 37allow ${HOME}/.cache/geary
38whitelist ${HOME}/.config/evolution 38allow ${HOME}/.config/evolution
39whitelist ${HOME}/.config/geary 39allow ${HOME}/.config/geary
40whitelist ${HOME}/.local/share/evolution 40allow ${HOME}/.local/share/evolution
41whitelist ${HOME}/.local/share/geary 41allow ${HOME}/.local/share/geary
42whitelist ${HOME}/.mozilla/firefox/profiles.ini 42allow ${HOME}/.mozilla/firefox/profiles.ini
43whitelist /usr/share/geary 43allow /usr/share/geary
44include whitelist-common.inc 44include whitelist-common.inc
45include whitelist-runuser-common.inc 45include whitelist-runuser-common.inc
46include whitelist-usr-share-common.inc 46include whitelist-usr-share-common.inc
diff --git a/etc/profile-a-l/gedit.profile b/etc/profile-a-l/gedit.profile
index 108b7041d..f11540374 100644
--- a/etc/profile-a-l/gedit.profile
+++ b/etc/profile-a-l/gedit.profile
@@ -6,8 +6,8 @@ include gedit.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/enchant 9nodeny ${HOME}/.config/enchant
10noblacklist ${HOME}/.config/gedit 10nodeny ${HOME}/.config/gedit
11 11
12# Allows files commonly used by IDEs 12# Allows files commonly used by IDEs
13include allow-common-devel.inc 13include allow-common-devel.inc
diff --git a/etc/profile-a-l/geeqie.profile b/etc/profile-a-l/geeqie.profile
index dd33b3fb5..8ec3bbaf9 100644
--- a/etc/profile-a-l/geeqie.profile
+++ b/etc/profile-a-l/geeqie.profile
@@ -6,9 +6,9 @@ include geeqie.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.cache/geeqie 9nodeny ${HOME}/.cache/geeqie
10noblacklist ${HOME}/.config/geeqie 10nodeny ${HOME}/.config/geeqie
11noblacklist ${HOME}/.local/share/geeqie 11nodeny ${HOME}/.local/share/geeqie
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
diff --git a/etc/profile-a-l/gfeeds.profile b/etc/profile-a-l/gfeeds.profile
index f894a42ca..1661da639 100644
--- a/etc/profile-a-l/gfeeds.profile
+++ b/etc/profile-a-l/gfeeds.profile
@@ -6,10 +6,10 @@ include gfeeds.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.cache/gfeeds 9nodeny ${HOME}/.cache/gfeeds
10noblacklist ${HOME}/.cache/org.gabmus.gfeeds 10nodeny ${HOME}/.cache/org.gabmus.gfeeds
11noblacklist ${HOME}/.config/org.gabmus.gfeeds.json 11nodeny ${HOME}/.config/org.gabmus.gfeeds.json
12noblacklist ${HOME}/.config/org.gabmus.gfeeds.saved_articles 12nodeny ${HOME}/.config/org.gabmus.gfeeds.saved_articles
13 13
14# Allow python (blacklisted by disable-interpreters.inc) 14# Allow python (blacklisted by disable-interpreters.inc)
15include allow-python3.inc 15include allow-python3.inc
@@ -27,12 +27,12 @@ mkdir ${HOME}/.cache/gfeeds
27mkdir ${HOME}/.cache/org.gabmus.gfeeds 27mkdir ${HOME}/.cache/org.gabmus.gfeeds
28mkfile ${HOME}/.config/org.gabmus.gfeeds.json 28mkfile ${HOME}/.config/org.gabmus.gfeeds.json
29mkdir ${HOME}/.config/org.gabmus.gfeeds.saved_articles 29mkdir ${HOME}/.config/org.gabmus.gfeeds.saved_articles
30whitelist ${HOME}/.cache/gfeeds 30allow ${HOME}/.cache/gfeeds
31whitelist ${HOME}/.cache/org.gabmus.gfeeds 31allow ${HOME}/.cache/org.gabmus.gfeeds
32whitelist ${HOME}/.config/org.gabmus.gfeeds.json 32allow ${HOME}/.config/org.gabmus.gfeeds.json
33whitelist ${HOME}/.config/org.gabmus.gfeeds.saved_articles 33allow ${HOME}/.config/org.gabmus.gfeeds.saved_articles
34whitelist /usr/libexec/webkit2gtk-4.0 34allow /usr/libexec/webkit2gtk-4.0
35whitelist /usr/share/gfeeds 35allow /usr/share/gfeeds
36include whitelist-common.inc 36include whitelist-common.inc
37include whitelist-runuser-common.inc 37include whitelist-runuser-common.inc
38include whitelist-usr-share-common.inc 38include whitelist-usr-share-common.inc
diff --git a/etc/profile-a-l/gget.profile b/etc/profile-a-l/gget.profile
index d9c5a0d9a..06929dbe3 100644
--- a/etc/profile-a-l/gget.profile
+++ b/etc/profile-a-l/gget.profile
@@ -7,8 +7,8 @@ include gget.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10blacklist /tmp/.X11-unix 10deny /tmp/.X11-unix
11blacklist ${RUNUSER} 11deny ${RUNUSER}
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
@@ -19,7 +19,7 @@ include disable-programs.inc
19include disable-shell.inc 19include disable-shell.inc
20include disable-xdg.inc 20include disable-xdg.inc
21 21
22whitelist ${DOWNLOADS} 22allow ${DOWNLOADS}
23include whitelist-common.inc 23include whitelist-common.inc
24include whitelist-runuser-common.inc 24include whitelist-runuser-common.inc
25include whitelist-usr-share-common.inc 25include whitelist-usr-share-common.inc
diff --git a/etc/profile-a-l/ghostwriter.profile b/etc/profile-a-l/ghostwriter.profile
index 276ab76df..0577fe24f 100644
--- a/etc/profile-a-l/ghostwriter.profile
+++ b/etc/profile-a-l/ghostwriter.profile
@@ -6,10 +6,10 @@ include ghostwriter.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/ghostwriter 9nodeny ${HOME}/.config/ghostwriter
10noblacklist ${HOME}/.local/share/ghostwriter 10nodeny ${HOME}/.local/share/ghostwriter
11noblacklist ${DOCUMENTS} 11nodeny ${DOCUMENTS}
12noblacklist ${PICTURES} 12nodeny ${PICTURES}
13 13
14include allow-lua.inc 14include allow-lua.inc
15 15
@@ -22,10 +22,10 @@ include disable-programs.inc
22include disable-shell.inc 22include disable-shell.inc
23include disable-xdg.inc 23include disable-xdg.inc
24 24
25whitelist /usr/share/ghostwriter 25allow /usr/share/ghostwriter
26whitelist /usr/share/mozilla-dicts 26allow /usr/share/mozilla-dicts
27whitelist /usr/share/texlive 27allow /usr/share/texlive
28whitelist /usr/share/pandoc* 28allow /usr/share/pandoc*
29include whitelist-runuser-common.inc 29include whitelist-runuser-common.inc
30include whitelist-usr-share-common.inc 30include whitelist-usr-share-common.inc
31include whitelist-var-common.inc 31include whitelist-var-common.inc
diff --git a/etc/profile-a-l/gimp.profile b/etc/profile-a-l/gimp.profile
index dfc1304d1..de9db8d0f 100644
--- a/etc/profile-a-l/gimp.profile
+++ b/etc/profile-a-l/gimp.profile
@@ -18,13 +18,13 @@ include globals.local
18# If you are not using external plugins, you can add 'noexec ${HOME}' to your gimp.local. 18# If you are not using external plugins, you can add 'noexec ${HOME}' to your gimp.local.
19ignore noexec ${HOME} 19ignore noexec ${HOME}
20 20
21noblacklist ${HOME}/.cache/babl 21nodeny ${HOME}/.cache/babl
22noblacklist ${HOME}/.cache/gegl-0.4 22nodeny ${HOME}/.cache/gegl-0.4
23noblacklist ${HOME}/.cache/gimp 23nodeny ${HOME}/.cache/gimp
24noblacklist ${HOME}/.config/GIMP 24nodeny ${HOME}/.config/GIMP
25noblacklist ${HOME}/.gimp* 25nodeny ${HOME}/.gimp*
26noblacklist ${DOCUMENTS} 26nodeny ${DOCUMENTS}
27noblacklist ${PICTURES} 27nodeny ${PICTURES}
28 28
29include disable-common.inc 29include disable-common.inc
30include disable-exec.inc 30include disable-exec.inc
@@ -33,10 +33,10 @@ include disable-passwdmgr.inc
33include disable-programs.inc 33include disable-programs.inc
34include disable-xdg.inc 34include disable-xdg.inc
35 35
36whitelist /usr/share/gegl-0.4 36allow /usr/share/gegl-0.4
37whitelist /usr/share/gimp 37allow /usr/share/gimp
38whitelist /usr/share/mypaint-data 38allow /usr/share/mypaint-data
39whitelist /usr/share/lensfun 39allow /usr/share/lensfun
40include whitelist-usr-share-common.inc 40include whitelist-usr-share-common.inc
41include whitelist-var-common.inc 41include whitelist-var-common.inc
42 42
diff --git a/etc/profile-a-l/gist.profile b/etc/profile-a-l/gist.profile
index 661c3a375..e601d3ab0 100644
--- a/etc/profile-a-l/gist.profile
+++ b/etc/profile-a-l/gist.profile
@@ -7,10 +7,10 @@ include gist.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10blacklist /tmp/.X11-unix 10deny /tmp/.X11-unix
11blacklist ${RUNUSER}/wayland-* 11deny ${RUNUSER}/wayland-*
12 12
13noblacklist ${HOME}/.gist 13nodeny ${HOME}/.gist
14 14
15# Allow ruby (blacklisted by disable-interpreters.inc) 15# Allow ruby (blacklisted by disable-interpreters.inc)
16include allow-ruby.inc 16include allow-ruby.inc
@@ -24,8 +24,8 @@ include disable-programs.inc
24include disable-xdg.inc 24include disable-xdg.inc
25 25
26mkdir ${HOME}/.gist 26mkdir ${HOME}/.gist
27whitelist ${HOME}/.gist 27allow ${HOME}/.gist
28whitelist ${DOWNLOADS} 28allow ${DOWNLOADS}
29include whitelist-common.inc 29include whitelist-common.inc
30include whitelist-usr-share-common.inc 30include whitelist-usr-share-common.inc
31include whitelist-var-common.inc 31include whitelist-var-common.inc
diff --git a/etc/profile-a-l/git-cola.profile b/etc/profile-a-l/git-cola.profile
index 5e4249376..74b7506cf 100644
--- a/etc/profile-a-l/git-cola.profile
+++ b/etc/profile-a-l/git-cola.profile
@@ -8,12 +8,12 @@ include globals.local
8 8
9ignore noexec ${HOME} 9ignore noexec ${HOME}
10 10
11noblacklist ${HOME}/.gitconfig 11nodeny ${HOME}/.gitconfig
12noblacklist ${HOME}/.git-credentials 12nodeny ${HOME}/.git-credentials
13noblacklist ${HOME}/.gnupg 13nodeny ${HOME}/.gnupg
14noblacklist ${HOME}/.subversion 14nodeny ${HOME}/.subversion
15noblacklist ${HOME}/.config/git 15nodeny ${HOME}/.config/git
16noblacklist ${HOME}/.config/git-cola 16nodeny ${HOME}/.config/git-cola
17# Add your editor/diff viewer config paths and the next line to your git-cola.local to load settings. 17# Add your editor/diff viewer config paths and the next line to your git-cola.local to load settings.
18#noblacklist ${HOME}/ 18#noblacklist ${HOME}/
19 19
@@ -32,17 +32,17 @@ include disable-passwdmgr.inc
32include disable-programs.inc 32include disable-programs.inc
33include disable-xdg.inc 33include disable-xdg.inc
34 34
35whitelist ${RUNUSER}/gnupg 35allow ${RUNUSER}/gnupg
36whitelist ${RUNUSER}/keyring 36allow ${RUNUSER}/keyring
37# Add additional whitelist paths below /usr/share to your git-cola.local to support your editor/diff viewer. 37# Add additional whitelist paths below /usr/share to your git-cola.local to support your editor/diff viewer.
38whitelist /usr/share/git 38allow /usr/share/git
39whitelist /usr/share/git-cola 39allow /usr/share/git-cola
40whitelist /usr/share/git-core 40allow /usr/share/git-core
41whitelist /usr/share/git-gui 41allow /usr/share/git-gui
42whitelist /usr/share/gitk 42allow /usr/share/gitk
43whitelist /usr/share/gitweb 43allow /usr/share/gitweb
44whitelist /usr/share/gnupg 44allow /usr/share/gnupg
45whitelist /usr/share/gnupg2 45allow /usr/share/gnupg2
46include whitelist-runuser-common.inc 46include whitelist-runuser-common.inc
47include whitelist-usr-share-common.inc 47include whitelist-usr-share-common.inc
48include whitelist-var-common.inc 48include whitelist-var-common.inc
diff --git a/etc/profile-a-l/git.profile b/etc/profile-a-l/git.profile
index bfa0081c6..680e91085 100644
--- a/etc/profile-a-l/git.profile
+++ b/etc/profile-a-l/git.profile
@@ -7,33 +7,33 @@ include git.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10noblacklist ${HOME}/.config/git 10nodeny ${HOME}/.config/git
11noblacklist ${HOME}/.config/nano 11nodeny ${HOME}/.config/nano
12noblacklist ${HOME}/.emacs 12nodeny ${HOME}/.emacs
13noblacklist ${HOME}/.emacs.d 13nodeny ${HOME}/.emacs.d
14noblacklist ${HOME}/.gitconfig 14nodeny ${HOME}/.gitconfig
15noblacklist ${HOME}/.git-credentials 15nodeny ${HOME}/.git-credentials
16noblacklist ${HOME}/.gnupg 16nodeny ${HOME}/.gnupg
17noblacklist ${HOME}/.nanorc 17nodeny ${HOME}/.nanorc
18noblacklist ${HOME}/.vim 18nodeny ${HOME}/.vim
19noblacklist ${HOME}/.viminfo 19nodeny ${HOME}/.viminfo
20 20
21# Allow ssh (blacklisted by disable-common.inc) 21# Allow ssh (blacklisted by disable-common.inc)
22include allow-ssh.inc 22include allow-ssh.inc
23 23
24blacklist /tmp/.X11-unix 24deny /tmp/.X11-unix
25blacklist ${RUNUSER}/wayland-* 25deny ${RUNUSER}/wayland-*
26 26
27include disable-common.inc 27include disable-common.inc
28include disable-exec.inc 28include disable-exec.inc
29include disable-passwdmgr.inc 29include disable-passwdmgr.inc
30include disable-programs.inc 30include disable-programs.inc
31 31
32whitelist /usr/share/git 32allow /usr/share/git
33whitelist /usr/share/git-core 33allow /usr/share/git-core
34whitelist /usr/share/gitgui 34allow /usr/share/gitgui
35whitelist /usr/share/gitweb 35allow /usr/share/gitweb
36whitelist /usr/share/nano 36allow /usr/share/nano
37include whitelist-usr-share-common.inc 37include whitelist-usr-share-common.inc
38include whitelist-var-common.inc 38include whitelist-var-common.inc
39 39
diff --git a/etc/profile-a-l/gitg.profile b/etc/profile-a-l/gitg.profile
index 05d7dffa9..d313b5022 100644
--- a/etc/profile-a-l/gitg.profile
+++ b/etc/profile-a-l/gitg.profile
@@ -6,10 +6,10 @@ include gitg.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/git 9nodeny ${HOME}/.config/git
10noblacklist ${HOME}/.gitconfig 10nodeny ${HOME}/.gitconfig
11noblacklist ${HOME}/.git-credentials 11nodeny ${HOME}/.git-credentials
12noblacklist ${HOME}/.local/share/gitg 12nodeny ${HOME}/.local/share/gitg
13 13
14# Allow ssh (blacklisted by disable-common.inc) 14# Allow ssh (blacklisted by disable-common.inc)
15include allow-ssh.inc 15include allow-ssh.inc
@@ -29,7 +29,7 @@ include disable-programs.inc
29#whitelist ${HOME}/.ssh 29#whitelist ${HOME}/.ssh
30#include whitelist-common.inc 30#include whitelist-common.inc
31 31
32whitelist /usr/share/gitg 32allow /usr/share/gitg
33include whitelist-runuser-common.inc 33include whitelist-runuser-common.inc
34include whitelist-usr-share-common.inc 34include whitelist-usr-share-common.inc
35include whitelist-var-common.inc 35include whitelist-var-common.inc
diff --git a/etc/profile-a-l/github-desktop.profile b/etc/profile-a-l/github-desktop.profile
index 325c54ced..81b534a74 100644
--- a/etc/profile-a-l/github-desktop.profile
+++ b/etc/profile-a-l/github-desktop.profile
@@ -22,10 +22,10 @@ ignore apparmor
22ignore dbus-user none 22ignore dbus-user none
23ignore dbus-system none 23ignore dbus-system none
24 24
25noblacklist ${HOME}/.config/GitHub Desktop 25nodeny ${HOME}/.config/GitHub Desktop
26noblacklist ${HOME}/.config/git 26nodeny ${HOME}/.config/git
27noblacklist ${HOME}/.gitconfig 27nodeny ${HOME}/.gitconfig
28noblacklist ${HOME}/.git-credentials 28nodeny ${HOME}/.git-credentials
29 29
30# no3d 30# no3d
31nosound 31nosound
diff --git a/etc/profile-a-l/gitter.profile b/etc/profile-a-l/gitter.profile
index 460e2b990..2d1694ef7 100644
--- a/etc/profile-a-l/gitter.profile
+++ b/etc/profile-a-l/gitter.profile
@@ -5,8 +5,8 @@ include gitter.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${HOME}/.config/autostart 8nodeny ${HOME}/.config/autostart
9noblacklist ${HOME}/.config/Gitter 9nodeny ${HOME}/.config/Gitter
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -16,9 +16,9 @@ include disable-passwdmgr.inc
16include disable-programs.inc 16include disable-programs.inc
17 17
18mkdir ${HOME}/.config/Gitter 18mkdir ${HOME}/.config/Gitter
19whitelist ${DOWNLOADS} 19allow ${DOWNLOADS}
20whitelist ${HOME}/.config/autostart 20allow ${HOME}/.config/autostart
21whitelist ${HOME}/.config/Gitter 21allow ${HOME}/.config/Gitter
22include whitelist-var-common.inc 22include whitelist-var-common.inc
23 23
24caps.drop all 24caps.drop all
diff --git a/etc/profile-a-l/gjs.profile b/etc/profile-a-l/gjs.profile
index ed68b3c2d..e00bb1dbf 100644
--- a/etc/profile-a-l/gjs.profile
+++ b/etc/profile-a-l/gjs.profile
@@ -8,10 +8,10 @@ include globals.local
8 8
9# when gjs apps are started via gnome-shell, firejail is not applied because systemd will start them 9# when gjs apps are started via gnome-shell, firejail is not applied because systemd will start them
10 10
11noblacklist ${HOME}/.cache/libgweather 11nodeny ${HOME}/.cache/libgweather
12noblacklist ${HOME}/.cache/org.gnome.Books 12nodeny ${HOME}/.cache/org.gnome.Books
13noblacklist ${HOME}/.config/libreoffice 13nodeny ${HOME}/.config/libreoffice
14noblacklist ${HOME}/.local/share/gnome-photos 14nodeny ${HOME}/.local/share/gnome-photos
15 15
16# Allow gjs (blacklisted by disable-interpreters.inc) 16# Allow gjs (blacklisted by disable-interpreters.inc)
17include allow-gjs.inc 17include allow-gjs.inc
diff --git a/etc/profile-a-l/gl-117.profile b/etc/profile-a-l/gl-117.profile
index c8cefc67e..a3236c2be 100644
--- a/etc/profile-a-l/gl-117.profile
+++ b/etc/profile-a-l/gl-117.profile
@@ -6,7 +6,7 @@ include gl-117.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.gl-117 9nodeny ${HOME}/.gl-117
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -18,8 +18,8 @@ include disable-shell.inc
18include disable-xdg.inc 18include disable-xdg.inc
19 19
20mkdir ${HOME}/.gl-117 20mkdir ${HOME}/.gl-117
21whitelist ${HOME}/.gl-117 21allow ${HOME}/.gl-117
22whitelist /usr/share/gl-117 22allow /usr/share/gl-117
23include whitelist-common.inc 23include whitelist-common.inc
24include whitelist-runuser-common.inc 24include whitelist-runuser-common.inc
25include whitelist-usr-share-common.inc 25include whitelist-usr-share-common.inc
diff --git a/etc/profile-a-l/glaxium.profile b/etc/profile-a-l/glaxium.profile
index ee7af0546..ec894a5f3 100644
--- a/etc/profile-a-l/glaxium.profile
+++ b/etc/profile-a-l/glaxium.profile
@@ -6,7 +6,7 @@ include glaxium.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.glaxiumrc 9nodeny ${HOME}/.glaxiumrc
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -18,8 +18,8 @@ include disable-shell.inc
18include disable-xdg.inc 18include disable-xdg.inc
19 19
20mkfile ${HOME}/.glaxiumrc 20mkfile ${HOME}/.glaxiumrc
21whitelist ${HOME}/.glaxiumrc 21allow ${HOME}/.glaxiumrc
22whitelist /usr/share/glaxium 22allow /usr/share/glaxium
23include whitelist-common.inc 23include whitelist-common.inc
24include whitelist-runuser-common.inc 24include whitelist-runuser-common.inc
25include whitelist-usr-share-common.inc 25include whitelist-usr-share-common.inc
diff --git a/etc/profile-a-l/globaltime.profile b/etc/profile-a-l/globaltime.profile
index 14b3ef811..e091b811f 100644
--- a/etc/profile-a-l/globaltime.profile
+++ b/etc/profile-a-l/globaltime.profile
@@ -5,7 +5,7 @@ include globaltime.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${HOME}/.config/globaltime 8nodeny ${HOME}/.config/globaltime
9 9
10include disable-common.inc 10include disable-common.inc
11include disable-devel.inc 11include disable-devel.inc
diff --git a/etc/profile-a-l/gmpc.profile b/etc/profile-a-l/gmpc.profile
index b3aad8b2c..79397d28f 100644
--- a/etc/profile-a-l/gmpc.profile
+++ b/etc/profile-a-l/gmpc.profile
@@ -6,8 +6,8 @@ include gmpc.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/gmpc 9nodeny ${HOME}/.config/gmpc
10noblacklist ${MUSIC} 10nodeny ${MUSIC}
11 11
12include disable-common.inc 12include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
@@ -18,9 +18,9 @@ include disable-programs.inc
18include disable-xdg.inc 18include disable-xdg.inc
19 19
20mkdir ${HOME}/.config/gmpc 20mkdir ${HOME}/.config/gmpc
21whitelist ${HOME}/.config/gmpc 21allow ${HOME}/.config/gmpc
22whitelist ${MUSIC} 22allow ${MUSIC}
23whitelist /usr/share/gmpc 23allow /usr/share/gmpc
24include whitelist-common.inc 24include whitelist-common.inc
25include whitelist-usr-share-common.inc 25include whitelist-usr-share-common.inc
26include whitelist-var-common.inc 26include whitelist-var-common.inc
diff --git a/etc/profile-a-l/gnome-2048.profile b/etc/profile-a-l/gnome-2048.profile
index 777c81dbe..c723f6e46 100644
--- a/etc/profile-a-l/gnome-2048.profile
+++ b/etc/profile-a-l/gnome-2048.profile
@@ -6,10 +6,10 @@ include gnome-2048.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.local/share/gnome-2048 9nodeny ${HOME}/.local/share/gnome-2048
10 10
11mkdir ${HOME}/.local/share/gnome-2048 11mkdir ${HOME}/.local/share/gnome-2048
12whitelist ${HOME}/.local/share/gnome-2048 12allow ${HOME}/.local/share/gnome-2048
13 13
14private-bin gnome-2048 14private-bin gnome-2048
15 15
diff --git a/etc/profile-a-l/gnome-books.profile b/etc/profile-a-l/gnome-books.profile
index 34a7f557c..2ed5fa76b 100644
--- a/etc/profile-a-l/gnome-books.profile
+++ b/etc/profile-a-l/gnome-books.profile
@@ -7,8 +7,8 @@ include globals.local
7 7
8# when gjs apps are started via gnome-shell, firejail is not applied because systemd will start them 8# when gjs apps are started via gnome-shell, firejail is not applied because systemd will start them
9 9
10noblacklist ${HOME}/.cache/org.gnome.Books 10nodeny ${HOME}/.cache/org.gnome.Books
11noblacklist ${DOCUMENTS} 11nodeny ${DOCUMENTS}
12 12
13# Allow gjs (blacklisted by disable-interpreters.inc) 13# Allow gjs (blacklisted by disable-interpreters.inc)
14include allow-gjs.inc 14include allow-gjs.inc
diff --git a/etc/profile-a-l/gnome-builder.profile b/etc/profile-a-l/gnome-builder.profile
index 37ca5aeff..7dd1c6e22 100644
--- a/etc/profile-a-l/gnome-builder.profile
+++ b/etc/profile-a-l/gnome-builder.profile
@@ -6,11 +6,11 @@ include gnome-builder.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.bash_history 9nodeny ${HOME}/.bash_history
10 10
11noblacklist ${HOME}/.cache/gnome-builder 11nodeny ${HOME}/.cache/gnome-builder
12noblacklist ${HOME}/.config/gnome-builder 12nodeny ${HOME}/.config/gnome-builder
13noblacklist ${HOME}/.local/share/gnome-builder 13nodeny ${HOME}/.local/share/gnome-builder
14 14
15# Allows files commonly used by IDEs 15# Allows files commonly used by IDEs
16include allow-common-devel.inc 16include allow-common-devel.inc
diff --git a/etc/profile-a-l/gnome-calendar.profile b/etc/profile-a-l/gnome-calendar.profile
index 03acd66aa..d91fbaa4b 100644
--- a/etc/profile-a-l/gnome-calendar.profile
+++ b/etc/profile-a-l/gnome-calendar.profile
@@ -15,7 +15,7 @@ include disable-programs.inc
15include disable-shell.inc 15include disable-shell.inc
16include disable-xdg.inc 16include disable-xdg.inc
17 17
18whitelist /usr/share/libgweather 18allow /usr/share/libgweather
19include whitelist-common.inc 19include whitelist-common.inc
20include whitelist-runuser-common.inc 20include whitelist-runuser-common.inc
21include whitelist-usr-share-common.inc 21include whitelist-usr-share-common.inc
diff --git a/etc/profile-a-l/gnome-characters.profile b/etc/profile-a-l/gnome-characters.profile
index 741fe9bf7..806d7e571 100644
--- a/etc/profile-a-l/gnome-characters.profile
+++ b/etc/profile-a-l/gnome-characters.profile
@@ -18,7 +18,7 @@ include disable-programs.inc
18include disable-shell.inc 18include disable-shell.inc
19include disable-xdg.inc 19include disable-xdg.inc
20 20
21whitelist /usr/share/org.gnome.Characters 21allow /usr/share/org.gnome.Characters
22include whitelist-common.inc 22include whitelist-common.inc
23include whitelist-runuser-common.inc 23include whitelist-runuser-common.inc
24include whitelist-usr-share-common.inc 24include whitelist-usr-share-common.inc
diff --git a/etc/profile-a-l/gnome-chess.profile b/etc/profile-a-l/gnome-chess.profile
index bd39f625c..095210565 100644
--- a/etc/profile-a-l/gnome-chess.profile
+++ b/etc/profile-a-l/gnome-chess.profile
@@ -6,8 +6,8 @@ include gnome-chess.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/gnome-chess 9nodeny ${HOME}/.config/gnome-chess
10noblacklist ${HOME}/.local/share/gnome-chess 10nodeny ${HOME}/.local/share/gnome-chess
11 11
12include disable-common.inc 12include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
@@ -22,8 +22,8 @@ include disable-xdg.inc
22#whitelist ${HOME}/.local/share/gnome-chess 22#whitelist ${HOME}/.local/share/gnome-chess
23#include whitelist-common.inc 23#include whitelist-common.inc
24 24
25whitelist /usr/share/gnuchess 25allow /usr/share/gnuchess
26whitelist /usr/share/gnome-chess 26allow /usr/share/gnome-chess
27include whitelist-runuser-common.inc 27include whitelist-runuser-common.inc
28include whitelist-usr-share-common.inc 28include whitelist-usr-share-common.inc
29include whitelist-var-common.inc 29include whitelist-var-common.inc
diff --git a/etc/profile-a-l/gnome-clocks.profile b/etc/profile-a-l/gnome-clocks.profile
index 1e7c70b84..7e2d458fd 100644
--- a/etc/profile-a-l/gnome-clocks.profile
+++ b/etc/profile-a-l/gnome-clocks.profile
@@ -15,8 +15,8 @@ include disable-programs.inc
15include disable-shell.inc 15include disable-shell.inc
16include disable-xdg.inc 16include disable-xdg.inc
17 17
18whitelist /usr/share/gnome-clocks 18allow /usr/share/gnome-clocks
19whitelist /usr/share/libgweather 19allow /usr/share/libgweather
20include whitelist-common.inc 20include whitelist-common.inc
21include whitelist-runuser-common.inc 21include whitelist-runuser-common.inc
22include whitelist-usr-share-common.inc 22include whitelist-usr-share-common.inc
diff --git a/etc/profile-a-l/gnome-contacts.profile b/etc/profile-a-l/gnome-contacts.profile
index dcc6163b6..7902fa169 100644
--- a/etc/profile-a-l/gnome-contacts.profile
+++ b/etc/profile-a-l/gnome-contacts.profile
@@ -6,7 +6,7 @@ include gnome-contacts.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${DOCUMENTS} 9nodeny ${DOCUMENTS}
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
diff --git a/etc/profile-a-l/gnome-documents.profile b/etc/profile-a-l/gnome-documents.profile
index 29ad67af8..0f601149f 100644
--- a/etc/profile-a-l/gnome-documents.profile
+++ b/etc/profile-a-l/gnome-documents.profile
@@ -8,8 +8,8 @@ include globals.local
8 8
9# when gjs apps are started via gnome-shell, firejail is not applied because systemd will start them 9# when gjs apps are started via gnome-shell, firejail is not applied because systemd will start them
10 10
11noblacklist ${HOME}/.config/libreoffice 11nodeny ${HOME}/.config/libreoffice
12noblacklist ${DOCUMENTS} 12nodeny ${DOCUMENTS}
13 13
14# Allow gjs (blacklisted by disable-interpreters.inc) 14# Allow gjs (blacklisted by disable-interpreters.inc)
15include allow-gjs.inc 15include allow-gjs.inc
diff --git a/etc/profile-a-l/gnome-hexgl.profile b/etc/profile-a-l/gnome-hexgl.profile
index 2db956faf..50c3e2c6f 100644
--- a/etc/profile-a-l/gnome-hexgl.profile
+++ b/etc/profile-a-l/gnome-hexgl.profile
@@ -16,7 +16,7 @@ include disable-shell.inc
16include disable-xdg.inc 16include disable-xdg.inc
17 17
18mkdir ${HOME}/.cache/mesa_shader_cache 18mkdir ${HOME}/.cache/mesa_shader_cache
19whitelist /usr/share/gnome-hexgl 19allow /usr/share/gnome-hexgl
20include whitelist-runuser-common.inc 20include whitelist-runuser-common.inc
21include whitelist-usr-share-common.inc 21include whitelist-usr-share-common.inc
22include whitelist-var-common.inc 22include whitelist-var-common.inc
diff --git a/etc/profile-a-l/gnome-keyring.profile b/etc/profile-a-l/gnome-keyring.profile
index 25b4c47de..62a5a34ea 100644
--- a/etc/profile-a-l/gnome-keyring.profile
+++ b/etc/profile-a-l/gnome-keyring.profile
@@ -7,7 +7,7 @@ include gnome-keyring.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10noblacklist ${HOME}/.gnupg 10nodeny ${HOME}/.gnupg
11 11
12include disable-common.inc 12include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
@@ -18,12 +18,12 @@ include disable-programs.inc
18include disable-xdg.inc 18include disable-xdg.inc
19 19
20mkdir ${HOME}/.gnupg 20mkdir ${HOME}/.gnupg
21whitelist ${HOME}/.gnupg 21allow ${HOME}/.gnupg
22whitelist ${DOWNLOADS} 22allow ${DOWNLOADS}
23whitelist ${RUNUSER}/gnupg 23allow ${RUNUSER}/gnupg
24whitelist ${RUNUSER}/keyring 24allow ${RUNUSER}/keyring
25whitelist /usr/share/gnupg 25allow /usr/share/gnupg
26whitelist /usr/share/gnupg2 26allow /usr/share/gnupg2
27include whitelist-common.inc 27include whitelist-common.inc
28include whitelist-runuser-common.inc 28include whitelist-runuser-common.inc
29include whitelist-usr-share-common.inc 29include whitelist-usr-share-common.inc
diff --git a/etc/profile-a-l/gnome-klotski.profile b/etc/profile-a-l/gnome-klotski.profile
index c67a5c0da..ed074f944 100644
--- a/etc/profile-a-l/gnome-klotski.profile
+++ b/etc/profile-a-l/gnome-klotski.profile
@@ -6,10 +6,10 @@ include gnome-klotski.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.local/share/gnome-klotski 9nodeny ${HOME}/.local/share/gnome-klotski
10 10
11mkdir ${HOME}/.local/share/gnome-klotski 11mkdir ${HOME}/.local/share/gnome-klotski
12whitelist ${HOME}/.local/share/gnome-klotski 12allow ${HOME}/.local/share/gnome-klotski
13 13
14private-bin gnome-klotski 14private-bin gnome-klotski
15 15
diff --git a/etc/profile-a-l/gnome-latex.profile b/etc/profile-a-l/gnome-latex.profile
index 1a7eafeca..4a03a7ff5 100644
--- a/etc/profile-a-l/gnome-latex.profile
+++ b/etc/profile-a-l/gnome-latex.profile
@@ -6,8 +6,8 @@ include gnome-latex.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/gnome-latex 9nodeny ${HOME}/.config/gnome-latex
10noblacklist ${HOME}/.local/share/gnome-latex 10nodeny ${HOME}/.local/share/gnome-latex
11 11
12# Allow perl (blacklisted by disable-interpreters.inc) 12# Allow perl (blacklisted by disable-interpreters.inc)
13include allow-perl.inc 13include allow-perl.inc
@@ -19,8 +19,8 @@ include disable-interpreters.inc
19include disable-passwdmgr.inc 19include disable-passwdmgr.inc
20include disable-programs.inc 20include disable-programs.inc
21 21
22whitelist /usr/share/gnome-latex 22allow /usr/share/gnome-latex
23whitelist /usr/share/texlive 23allow /usr/share/texlive
24include whitelist-runuser-common.inc 24include whitelist-runuser-common.inc
25include whitelist-usr-share-common.inc 25include whitelist-usr-share-common.inc
26# May cause issues. 26# May cause issues.
diff --git a/etc/profile-a-l/gnome-logs.profile b/etc/profile-a-l/gnome-logs.profile
index 9d2ea7b7b..fcc02dc76 100644
--- a/etc/profile-a-l/gnome-logs.profile
+++ b/etc/profile-a-l/gnome-logs.profile
@@ -15,7 +15,7 @@ include disable-programs.inc
15include disable-shell.inc 15include disable-shell.inc
16include disable-xdg.inc 16include disable-xdg.inc
17 17
18whitelist /var/log/journal 18allow /var/log/journal
19include whitelist-runuser-common.inc 19include whitelist-runuser-common.inc
20include whitelist-usr-share-common.inc 20include whitelist-usr-share-common.inc
21include whitelist-var-common.inc 21include whitelist-var-common.inc
diff --git a/etc/profile-a-l/gnome-mahjongg.profile b/etc/profile-a-l/gnome-mahjongg.profile
index 42409dce8..e21f03efe 100644
--- a/etc/profile-a-l/gnome-mahjongg.profile
+++ b/etc/profile-a-l/gnome-mahjongg.profile
@@ -6,7 +6,7 @@ include gnome-mahjongg.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9whitelist /usr/share/gnome-mahjongg 9allow /usr/share/gnome-mahjongg
10 10
11private-bin gnome-mahjongg 11private-bin gnome-mahjongg
12 12
diff --git a/etc/profile-a-l/gnome-maps.profile b/etc/profile-a-l/gnome-maps.profile
index 23aab343f..cf4eceee3 100644
--- a/etc/profile-a-l/gnome-maps.profile
+++ b/etc/profile-a-l/gnome-maps.profile
@@ -11,14 +11,14 @@ include globals.local
11 11
12# when gjs apps are started via gnome-shell, firejail is not applied because systemd will start them 12# when gjs apps are started via gnome-shell, firejail is not applied because systemd will start them
13 13
14noblacklist ${HOME}/.cache/champlain 14nodeny ${HOME}/.cache/champlain
15noblacklist ${HOME}/.cache/org.gnome.Maps 15nodeny ${HOME}/.cache/org.gnome.Maps
16noblacklist ${HOME}/.local/share/maps-places.json 16nodeny ${HOME}/.local/share/maps-places.json
17 17
18# Allow gjs (blacklisted by disable-interpreters.inc) 18# Allow gjs (blacklisted by disable-interpreters.inc)
19include allow-gjs.inc 19include allow-gjs.inc
20 20
21blacklist /usr/libexec 21deny /usr/libexec
22 22
23include disable-common.inc 23include disable-common.inc
24include disable-devel.inc 24include disable-devel.inc
@@ -31,12 +31,12 @@ include disable-xdg.inc
31 31
32mkdir ${HOME}/.cache/champlain 32mkdir ${HOME}/.cache/champlain
33mkfile ${HOME}/.local/share/maps-places.json 33mkfile ${HOME}/.local/share/maps-places.json
34whitelist ${HOME}/.cache/champlain 34allow ${HOME}/.cache/champlain
35whitelist ${HOME}/.local/share/maps-places.json 35allow ${HOME}/.local/share/maps-places.json
36whitelist ${DOWNLOADS} 36allow ${DOWNLOADS}
37whitelist ${PICTURES} 37allow ${PICTURES}
38whitelist /usr/share/gnome-maps 38allow /usr/share/gnome-maps
39whitelist /usr/share/libgweather 39allow /usr/share/libgweather
40include whitelist-common.inc 40include whitelist-common.inc
41include whitelist-runuser-common.inc 41include whitelist-runuser-common.inc
42include whitelist-usr-share-common.inc 42include whitelist-usr-share-common.inc
diff --git a/etc/profile-a-l/gnome-mines.profile b/etc/profile-a-l/gnome-mines.profile
index 4fe8986c2..1b2949bc5 100644
--- a/etc/profile-a-l/gnome-mines.profile
+++ b/etc/profile-a-l/gnome-mines.profile
@@ -6,11 +6,11 @@ include gnome-mines.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.local/share/gnome-mines 9nodeny ${HOME}/.local/share/gnome-mines
10 10
11mkdir ${HOME}/.local/share/gnome-mines 11mkdir ${HOME}/.local/share/gnome-mines
12whitelist ${HOME}/.local/share/gnome-mines 12allow ${HOME}/.local/share/gnome-mines
13whitelist /usr/share/gnome-mines 13allow /usr/share/gnome-mines
14 14
15private-bin gnome-mines 15private-bin gnome-mines
16 16
diff --git a/etc/profile-a-l/gnome-mplayer.profile b/etc/profile-a-l/gnome-mplayer.profile
index 43fe71f5e..c1cbc796a 100644
--- a/etc/profile-a-l/gnome-mplayer.profile
+++ b/etc/profile-a-l/gnome-mplayer.profile
@@ -6,9 +6,9 @@ include gnome-mplayer.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/gnome-mplayer 9nodeny ${HOME}/.config/gnome-mplayer
10noblacklist ${MUSIC} 10nodeny ${MUSIC}
11noblacklist ${VIDEOS} 11nodeny ${VIDEOS}
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
diff --git a/etc/profile-a-l/gnome-music.profile b/etc/profile-a-l/gnome-music.profile
index 2fcbe9910..8fd0826c4 100644
--- a/etc/profile-a-l/gnome-music.profile
+++ b/etc/profile-a-l/gnome-music.profile
@@ -6,8 +6,8 @@ include gnome-music.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.local/share/gnome-music 9nodeny ${HOME}/.local/share/gnome-music
10noblacklist ${MUSIC} 10nodeny ${MUSIC}
11 11
12# Allow python (blacklisted by disable-interpreters.inc) 12# Allow python (blacklisted by disable-interpreters.inc)
13include allow-python2.inc 13include allow-python2.inc
diff --git a/etc/profile-a-l/gnome-nettool.profile b/etc/profile-a-l/gnome-nettool.profile
index 814751db3..a929582f8 100644
--- a/etc/profile-a-l/gnome-nettool.profile
+++ b/etc/profile-a-l/gnome-nettool.profile
@@ -14,7 +14,7 @@ include disable-passwdmgr.inc
14include disable-programs.inc 14include disable-programs.inc
15include disable-xdg.inc 15include disable-xdg.inc
16 16
17whitelist /usr/share/gnome-nettool 17allow /usr/share/gnome-nettool
18#include whitelist-common.inc -- see #903 18#include whitelist-common.inc -- see #903
19include whitelist-runuser-common.inc 19include whitelist-runuser-common.inc
20include whitelist-usr-share-common.inc 20include whitelist-usr-share-common.inc
diff --git a/etc/profile-a-l/gnome-nibbles.profile b/etc/profile-a-l/gnome-nibbles.profile
index b22810d34..d4c037a41 100644
--- a/etc/profile-a-l/gnome-nibbles.profile
+++ b/etc/profile-a-l/gnome-nibbles.profile
@@ -9,11 +9,11 @@ include globals.local
9ignore machine-id 9ignore machine-id
10ignore nosound 10ignore nosound
11 11
12noblacklist ${HOME}/.local/share/gnome-nibbles 12nodeny ${HOME}/.local/share/gnome-nibbles
13 13
14mkdir ${HOME}/.local/share/gnome-nibbles 14mkdir ${HOME}/.local/share/gnome-nibbles
15whitelist ${HOME}/.local/share/gnome-nibbles 15allow ${HOME}/.local/share/gnome-nibbles
16whitelist /usr/share/gnome-nibbles 16allow /usr/share/gnome-nibbles
17 17
18private-bin gnome-nibbles 18private-bin gnome-nibbles
19 19
diff --git a/etc/profile-a-l/gnome-passwordsafe.profile b/etc/profile-a-l/gnome-passwordsafe.profile
index fee5f88b9..d2cf828cc 100644
--- a/etc/profile-a-l/gnome-passwordsafe.profile
+++ b/etc/profile-a-l/gnome-passwordsafe.profile
@@ -6,14 +6,14 @@ include gnome-passwordsafe.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${DOCUMENTS} 9nodeny ${DOCUMENTS}
10noblacklist ${HOME}/*.kdb 10nodeny ${HOME}/*.kdb
11noblacklist ${HOME}/*.kdbx 11nodeny ${HOME}/*.kdbx
12 12
13# Allow python (blacklisted by disable-interpreters.inc) 13# Allow python (blacklisted by disable-interpreters.inc)
14include allow-python3.inc 14include allow-python3.inc
15 15
16blacklist /usr/libexec 16deny /usr/libexec
17 17
18include disable-common.inc 18include disable-common.inc
19include disable-devel.inc 19include disable-devel.inc
@@ -24,8 +24,8 @@ include disable-programs.inc
24include disable-shell.inc 24include disable-shell.inc
25include disable-xdg.inc 25include disable-xdg.inc
26 26
27whitelist /usr/share/cracklib 27allow /usr/share/cracklib
28whitelist /usr/share/passwordsafe 28allow /usr/share/passwordsafe
29include whitelist-runuser-common.inc 29include whitelist-runuser-common.inc
30include whitelist-usr-share-common.inc 30include whitelist-usr-share-common.inc
31include whitelist-var-common.inc 31include whitelist-var-common.inc
diff --git a/etc/profile-a-l/gnome-photos.profile b/etc/profile-a-l/gnome-photos.profile
index 58bf3f349..3702da2c7 100644
--- a/etc/profile-a-l/gnome-photos.profile
+++ b/etc/profile-a-l/gnome-photos.profile
@@ -8,7 +8,7 @@ include globals.local
8 8
9# when gjs apps are started via gnome-shell, firejail is not applied because systemd will start them 9# when gjs apps are started via gnome-shell, firejail is not applied because systemd will start them
10 10
11noblacklist ${HOME}/.local/share/gnome-photos 11nodeny ${HOME}/.local/share/gnome-photos
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
diff --git a/etc/profile-a-l/gnome-pie.profile b/etc/profile-a-l/gnome-pie.profile
index 41903b136..e9ae2bcb0 100644
--- a/etc/profile-a-l/gnome-pie.profile
+++ b/etc/profile-a-l/gnome-pie.profile
@@ -6,7 +6,7 @@ include gnome-pie.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/gnome-pie 9nodeny ${HOME}/.config/gnome-pie
10 10
11#include disable-common.inc 11#include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
diff --git a/etc/profile-a-l/gnome-pomodoro.profile b/etc/profile-a-l/gnome-pomodoro.profile
index c2ba7556d..bec23910c 100644
--- a/etc/profile-a-l/gnome-pomodoro.profile
+++ b/etc/profile-a-l/gnome-pomodoro.profile
@@ -6,7 +6,7 @@ include gnome-pomodoro.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.local/share/gnome-pomodoro 9nodeny ${HOME}/.local/share/gnome-pomodoro
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -17,8 +17,8 @@ include disable-programs.inc
17include disable-xdg.inc 17include disable-xdg.inc
18 18
19mkdir ${HOME}/.local/share/gnome-pomodoro 19mkdir ${HOME}/.local/share/gnome-pomodoro
20whitelist ${HOME}/.local/share/gnome-pomodoro 20allow ${HOME}/.local/share/gnome-pomodoro
21whitelist /usr/share/gnome-pomodoro 21allow /usr/share/gnome-pomodoro
22include whitelist-common.inc 22include whitelist-common.inc
23include whitelist-usr-share-common.inc 23include whitelist-usr-share-common.inc
24include whitelist-runuser-common.inc 24include whitelist-runuser-common.inc
diff --git a/etc/profile-a-l/gnome-recipes.profile b/etc/profile-a-l/gnome-recipes.profile
index 48c98ebe0..5ef33fdd8 100644
--- a/etc/profile-a-l/gnome-recipes.profile
+++ b/etc/profile-a-l/gnome-recipes.profile
@@ -7,8 +7,8 @@ include gnome-recipes.local
7include globals.local 7include globals.local
8 8
9 9
10noblacklist ${HOME}/.cache/gnome-recipes 10nodeny ${HOME}/.cache/gnome-recipes
11noblacklist ${HOME}/.local/share/gnome-recipes 11nodeny ${HOME}/.local/share/gnome-recipes
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
@@ -20,9 +20,9 @@ include disable-shell.inc
20 20
21mkdir ${HOME}/.cache/gnome-recipes 21mkdir ${HOME}/.cache/gnome-recipes
22mkdir ${HOME}/.local/share/gnome-recipes 22mkdir ${HOME}/.local/share/gnome-recipes
23whitelist ${HOME}/.cache/gnome-recipes 23allow ${HOME}/.cache/gnome-recipes
24whitelist ${HOME}/.local/share/gnome-recipes 24allow ${HOME}/.local/share/gnome-recipes
25whitelist /usr/share/gnome-recipes 25allow /usr/share/gnome-recipes
26include whitelist-common.inc 26include whitelist-common.inc
27include whitelist-usr-share-common.inc 27include whitelist-usr-share-common.inc
28include whitelist-var-common.inc 28include whitelist-var-common.inc
diff --git a/etc/profile-a-l/gnome-ring.profile b/etc/profile-a-l/gnome-ring.profile
index 78ceb9c4f..b34d264f4 100644
--- a/etc/profile-a-l/gnome-ring.profile
+++ b/etc/profile-a-l/gnome-ring.profile
@@ -5,7 +5,7 @@ include gnome-ring.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${HOME}/.local/share/gnome-ring 8nodeny ${HOME}/.local/share/gnome-ring
9 9
10include disable-common.inc 10include disable-common.inc
11include disable-devel.inc 11include disable-devel.inc
diff --git a/etc/profile-a-l/gnome-robots.profile b/etc/profile-a-l/gnome-robots.profile
index 8835f2b93..836d4e2b2 100644
--- a/etc/profile-a-l/gnome-robots.profile
+++ b/etc/profile-a-l/gnome-robots.profile
@@ -9,7 +9,7 @@ include globals.local
9ignore machine-id 9ignore machine-id
10ignore nosound 10ignore nosound
11 11
12whitelist /usr/share/gnome-robots 12allow /usr/share/gnome-robots
13 13
14private-bin gnome-robots 14private-bin gnome-robots
15 15
diff --git a/etc/profile-a-l/gnome-schedule.profile b/etc/profile-a-l/gnome-schedule.profile
index 69c90b33d..146f8bc4e 100644
--- a/etc/profile-a-l/gnome-schedule.profile
+++ b/etc/profile-a-l/gnome-schedule.profile
@@ -6,17 +6,17 @@ include gnome-schedule.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.gnome/gnome-schedule 9nodeny ${HOME}/.gnome/gnome-schedule
10 10
11# Needs at and crontab to read/write user cron 11# Needs at and crontab to read/write user cron
12noblacklist ${PATH}/at 12nodeny ${PATH}/at
13noblacklist ${PATH}/crontab 13nodeny ${PATH}/crontab
14 14
15# Needs access to these files/dirs 15# Needs access to these files/dirs
16noblacklist /etc/cron.allow 16nodeny /etc/cron.allow
17noblacklist /etc/cron.deny 17nodeny /etc/cron.deny
18noblacklist /etc/shadow 18nodeny /etc/shadow
19noblacklist /var/spool/cron 19nodeny /var/spool/cron
20 20
21# cron job testing needs a terminal, resulting in sandbox escape (see disable-common.inc) 21# cron job testing needs a terminal, resulting in sandbox escape (see disable-common.inc)
22# add 'noblacklist ${PATH}/your-terminal' to gnome-schedule.local if you need that functionality 22# add 'noblacklist ${PATH}/your-terminal' to gnome-schedule.local if you need that functionality
@@ -34,10 +34,10 @@ include disable-programs.inc
34include disable-xdg.inc 34include disable-xdg.inc
35 35
36mkfile ${HOME}/.gnome/gnome-schedule 36mkfile ${HOME}/.gnome/gnome-schedule
37whitelist ${HOME}/.gnome/gnome-schedule 37allow ${HOME}/.gnome/gnome-schedule
38whitelist /usr/share/gnome-schedule 38allow /usr/share/gnome-schedule
39whitelist /var/spool/atd 39allow /var/spool/atd
40whitelist /var/spool/cron 40allow /var/spool/cron
41include whitelist-common.inc 41include whitelist-common.inc
42include whitelist-runuser-common.inc 42include whitelist-runuser-common.inc
43include whitelist-usr-share-common.inc 43include whitelist-usr-share-common.inc
diff --git a/etc/profile-a-l/gnome-screenshot.profile b/etc/profile-a-l/gnome-screenshot.profile
index b683b6f6c..175549e99 100644
--- a/etc/profile-a-l/gnome-screenshot.profile
+++ b/etc/profile-a-l/gnome-screenshot.profile
@@ -6,8 +6,8 @@ include gnome-screenshot.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${PICTURES} 9nodeny ${PICTURES}
10noblacklist ${HOME}/.cache/gnome-screenshot 10nodeny ${HOME}/.cache/gnome-screenshot
11 11
12include disable-common.inc 12include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
diff --git a/etc/profile-a-l/gnome-sound-recorder.profile b/etc/profile-a-l/gnome-sound-recorder.profile
index 34f5fdeff..c2fb14fa4 100644
--- a/etc/profile-a-l/gnome-sound-recorder.profile
+++ b/etc/profile-a-l/gnome-sound-recorder.profile
@@ -6,8 +6,8 @@ include gnome-sound-recorder.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${MUSIC} 9nodeny ${MUSIC}
10noblacklist ${HOME}/.local/share/Trash 10nodeny ${HOME}/.local/share/Trash
11 11
12# Allow gjs (blacklisted by disable-interpreters.inc) 12# Allow gjs (blacklisted by disable-interpreters.inc)
13include allow-gjs.inc 13include allow-gjs.inc
diff --git a/etc/profile-a-l/gnome-sudoku.profile b/etc/profile-a-l/gnome-sudoku.profile
index 12fd48a86..3b7835e52 100644
--- a/etc/profile-a-l/gnome-sudoku.profile
+++ b/etc/profile-a-l/gnome-sudoku.profile
@@ -6,10 +6,10 @@ include gnome-sudoku.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.local/share/gnome-sudoku 9nodeny ${HOME}/.local/share/gnome-sudoku
10 10
11mkdir ${HOME}/.local/share/gnome-sudoku 11mkdir ${HOME}/.local/share/gnome-sudoku
12whitelist ${HOME}/.local/share/gnome-sudoku 12allow ${HOME}/.local/share/gnome-sudoku
13 13
14private-bin gnome-sudoku 14private-bin gnome-sudoku
15 15
diff --git a/etc/profile-a-l/gnome-system-log.profile b/etc/profile-a-l/gnome-system-log.profile
index 8a818695d..6978f7cab 100644
--- a/etc/profile-a-l/gnome-system-log.profile
+++ b/etc/profile-a-l/gnome-system-log.profile
@@ -15,7 +15,7 @@ include disable-programs.inc
15include disable-shell.inc 15include disable-shell.inc
16include disable-xdg.inc 16include disable-xdg.inc
17 17
18whitelist /var/log 18allow /var/log
19include whitelist-common.inc 19include whitelist-common.inc
20include whitelist-usr-share-common.inc 20include whitelist-usr-share-common.inc
21include whitelist-var-common.inc 21include whitelist-var-common.inc
diff --git a/etc/profile-a-l/gnome-taquin.profile b/etc/profile-a-l/gnome-taquin.profile
index 2341334f7..ac87cf70f 100644
--- a/etc/profile-a-l/gnome-taquin.profile
+++ b/etc/profile-a-l/gnome-taquin.profile
@@ -9,7 +9,7 @@ include globals.local
9ignore machine-id 9ignore machine-id
10ignore nosound 10ignore nosound
11 11
12whitelist /usr/share/gnome-taquin 12allow /usr/share/gnome-taquin
13 13
14private-bin gnome-taquin 14private-bin gnome-taquin
15 15
diff --git a/etc/profile-a-l/gnome-todo.profile b/etc/profile-a-l/gnome-todo.profile
index 3b147cd48..092fd58a3 100644
--- a/etc/profile-a-l/gnome-todo.profile
+++ b/etc/profile-a-l/gnome-todo.profile
@@ -18,7 +18,7 @@ include disable-programs.inc
18include disable-shell.inc 18include disable-shell.inc
19include disable-xdg.inc 19include disable-xdg.inc
20 20
21whitelist /usr/share/gnome-todo 21allow /usr/share/gnome-todo
22include whitelist-common.inc 22include whitelist-common.inc
23include whitelist-usr-share-common.inc 23include whitelist-usr-share-common.inc
24include whitelist-runuser-common.inc 24include whitelist-runuser-common.inc
diff --git a/etc/profile-a-l/gnome-twitch.profile b/etc/profile-a-l/gnome-twitch.profile
index b8ec195d3..d76872ea6 100644
--- a/etc/profile-a-l/gnome-twitch.profile
+++ b/etc/profile-a-l/gnome-twitch.profile
@@ -6,8 +6,8 @@ include gnome-twitch.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.cache/gnome-twitch 9nodeny ${HOME}/.cache/gnome-twitch
10noblacklist ${HOME}/.local/share/gnome-twitch 10nodeny ${HOME}/.local/share/gnome-twitch
11 11
12include disable-common.inc 12include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
@@ -18,8 +18,8 @@ include disable-programs.inc
18 18
19mkdir ${HOME}/.cache/gnome-twitch 19mkdir ${HOME}/.cache/gnome-twitch
20mkdir ${HOME}/.local/share/gnome-twitch 20mkdir ${HOME}/.local/share/gnome-twitch
21whitelist ${HOME}/.cache/gnome-twitch 21allow ${HOME}/.cache/gnome-twitch
22whitelist ${HOME}/.local/share/gnome-twitch 22allow ${HOME}/.local/share/gnome-twitch
23include whitelist-common.inc 23include whitelist-common.inc
24 24
25caps.drop all 25caps.drop all
diff --git a/etc/profile-a-l/gnome-weather.profile b/etc/profile-a-l/gnome-weather.profile
index 2e08fa41d..6f557ff8d 100644
--- a/etc/profile-a-l/gnome-weather.profile
+++ b/etc/profile-a-l/gnome-weather.profile
@@ -8,7 +8,7 @@ include globals.local
8 8
9# when gjs apps are started via gnome-shell, firejail is not applied because systemd will start them 9# when gjs apps are started via gnome-shell, firejail is not applied because systemd will start them
10 10
11noblacklist ${HOME}/.cache/libgweather 11nodeny ${HOME}/.cache/libgweather
12 12
13# Allow gjs (blacklisted by disable-interpreters.inc) 13# Allow gjs (blacklisted by disable-interpreters.inc)
14include allow-gjs.inc 14include allow-gjs.inc
diff --git a/etc/profile-a-l/gnote.profile b/etc/profile-a-l/gnote.profile
index c3014a288..261efefac 100644
--- a/etc/profile-a-l/gnote.profile
+++ b/etc/profile-a-l/gnote.profile
@@ -6,8 +6,8 @@ include gnote.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/gnote 9nodeny ${HOME}/.config/gnote
10noblacklist ${HOME}/.local/share/gnote 10nodeny ${HOME}/.local/share/gnote
11 11
12include disable-common.inc 12include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
@@ -20,9 +20,9 @@ include disable-xdg.inc
20 20
21mkdir ${HOME}/.config/gnote 21mkdir ${HOME}/.config/gnote
22mkdir ${HOME}/.local/share/gnote 22mkdir ${HOME}/.local/share/gnote
23whitelist ${HOME}/.config/gnote 23allow ${HOME}/.config/gnote
24whitelist ${HOME}/.local/share/gnote 24allow ${HOME}/.local/share/gnote
25whitelist /usr/share/gnote 25allow /usr/share/gnote
26include whitelist-common.inc 26include whitelist-common.inc
27include whitelist-runuser-common.inc 27include whitelist-runuser-common.inc
28include whitelist-usr-share-common.inc 28include whitelist-usr-share-common.inc
diff --git a/etc/profile-a-l/gnubik.profile b/etc/profile-a-l/gnubik.profile
index 22851ce9f..e6fbca26f 100644
--- a/etc/profile-a-l/gnubik.profile
+++ b/etc/profile-a-l/gnubik.profile
@@ -15,7 +15,7 @@ include disable-programs.inc
15include disable-shell.inc 15include disable-shell.inc
16include disable-xdg.inc 16include disable-xdg.inc
17 17
18whitelist /usr/share/gnubik 18allow /usr/share/gnubik
19include whitelist-common.inc 19include whitelist-common.inc
20include whitelist-runuser-common.inc 20include whitelist-runuser-common.inc
21include whitelist-usr-share-common.inc 21include whitelist-usr-share-common.inc
diff --git a/etc/profile-a-l/godot.profile b/etc/profile-a-l/godot.profile
index 09ca17caa..f35a53ca4 100644
--- a/etc/profile-a-l/godot.profile
+++ b/etc/profile-a-l/godot.profile
@@ -6,9 +6,9 @@ include godot.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.cache/godot 9nodeny ${HOME}/.cache/godot
10noblacklist ${HOME}/.config/godot 10nodeny ${HOME}/.config/godot
11noblacklist ${HOME}/.local/share/godot 11nodeny ${HOME}/.local/share/godot
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
diff --git a/etc/profile-a-l/goobox.profile b/etc/profile-a-l/goobox.profile
index 8399d77c4..95dd41c2a 100644
--- a/etc/profile-a-l/goobox.profile
+++ b/etc/profile-a-l/goobox.profile
@@ -6,7 +6,7 @@ include goobox.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${MUSIC} 9nodeny ${MUSIC}
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
diff --git a/etc/profile-a-l/google-chrome-beta.profile b/etc/profile-a-l/google-chrome-beta.profile
index ebe5e870b..07f0e587d 100644
--- a/etc/profile-a-l/google-chrome-beta.profile
+++ b/etc/profile-a-l/google-chrome-beta.profile
@@ -10,19 +10,19 @@ ignore whitelist /usr/share/chromium
10ignore include whitelist-runuser-common.inc 10ignore include whitelist-runuser-common.inc
11ignore include whitelist-usr-share-common.inc 11ignore include whitelist-usr-share-common.inc
12 12
13noblacklist ${HOME}/.cache/google-chrome-beta 13nodeny ${HOME}/.cache/google-chrome-beta
14noblacklist ${HOME}/.config/google-chrome-beta 14nodeny ${HOME}/.config/google-chrome-beta
15 15
16noblacklist ${HOME}/.config/chrome-beta-flags.conf 16nodeny ${HOME}/.config/chrome-beta-flags.conf
17noblacklist ${HOME}/.config/chrome-beta-flags.config 17nodeny ${HOME}/.config/chrome-beta-flags.config
18 18
19mkdir ${HOME}/.cache/google-chrome-beta 19mkdir ${HOME}/.cache/google-chrome-beta
20mkdir ${HOME}/.config/google-chrome-beta 20mkdir ${HOME}/.config/google-chrome-beta
21whitelist ${HOME}/.cache/google-chrome-beta 21allow ${HOME}/.cache/google-chrome-beta
22whitelist ${HOME}/.config/google-chrome-beta 22allow ${HOME}/.config/google-chrome-beta
23 23
24whitelist ${HOME}/.config/chrome-beta-flags.conf 24allow ${HOME}/.config/chrome-beta-flags.conf
25whitelist ${HOME}/.config/chrome-beta-flags.config 25allow ${HOME}/.config/chrome-beta-flags.config
26 26
27# Redirect 27# Redirect
28include chromium-common.profile 28include chromium-common.profile
diff --git a/etc/profile-a-l/google-chrome-unstable.profile b/etc/profile-a-l/google-chrome-unstable.profile
index 4d303f71b..229904411 100644
--- a/etc/profile-a-l/google-chrome-unstable.profile
+++ b/etc/profile-a-l/google-chrome-unstable.profile
@@ -10,19 +10,19 @@ ignore whitelist /usr/share/chromium
10ignore include whitelist-runuser-common.inc 10ignore include whitelist-runuser-common.inc
11ignore include whitelist-usr-share-common.inc 11ignore include whitelist-usr-share-common.inc
12 12
13noblacklist ${HOME}/.cache/google-chrome-unstable 13nodeny ${HOME}/.cache/google-chrome-unstable
14noblacklist ${HOME}/.config/google-chrome-unstable 14nodeny ${HOME}/.config/google-chrome-unstable
15 15
16noblacklist ${HOME}/.config/chrome-unstable-flags.conf 16nodeny ${HOME}/.config/chrome-unstable-flags.conf
17noblacklist ${HOME}/.config/chrome-unstable-flags.config 17nodeny ${HOME}/.config/chrome-unstable-flags.config
18 18
19mkdir ${HOME}/.cache/google-chrome-unstable 19mkdir ${HOME}/.cache/google-chrome-unstable
20mkdir ${HOME}/.config/google-chrome-unstable 20mkdir ${HOME}/.config/google-chrome-unstable
21whitelist ${HOME}/.cache/google-chrome-unstable 21allow ${HOME}/.cache/google-chrome-unstable
22whitelist ${HOME}/.config/google-chrome-unstable 22allow ${HOME}/.config/google-chrome-unstable
23 23
24whitelist ${HOME}/.config/chrome-unstable-flags.conf 24allow ${HOME}/.config/chrome-unstable-flags.conf
25whitelist ${HOME}/.config/chrome-unstable-flags.config 25allow ${HOME}/.config/chrome-unstable-flags.config
26 26
27# Redirect 27# Redirect
28include chromium-common.profile 28include chromium-common.profile
diff --git a/etc/profile-a-l/google-chrome.profile b/etc/profile-a-l/google-chrome.profile
index ed2595f72..f61642f17 100644
--- a/etc/profile-a-l/google-chrome.profile
+++ b/etc/profile-a-l/google-chrome.profile
@@ -10,19 +10,19 @@ ignore whitelist /usr/share/chromium
10ignore include whitelist-runuser-common.inc 10ignore include whitelist-runuser-common.inc
11ignore include whitelist-usr-share-common.inc 11ignore include whitelist-usr-share-common.inc
12 12
13noblacklist ${HOME}/.cache/google-chrome 13nodeny ${HOME}/.cache/google-chrome
14noblacklist ${HOME}/.config/google-chrome 14nodeny ${HOME}/.config/google-chrome
15 15
16noblacklist ${HOME}/.config/chrome-flags.conf 16nodeny ${HOME}/.config/chrome-flags.conf
17noblacklist ${HOME}/.config/chrome-flags.config 17nodeny ${HOME}/.config/chrome-flags.config
18 18
19mkdir ${HOME}/.cache/google-chrome 19mkdir ${HOME}/.cache/google-chrome
20mkdir ${HOME}/.config/google-chrome 20mkdir ${HOME}/.config/google-chrome
21whitelist ${HOME}/.cache/google-chrome 21allow ${HOME}/.cache/google-chrome
22whitelist ${HOME}/.config/google-chrome 22allow ${HOME}/.config/google-chrome
23 23
24whitelist ${HOME}/.config/chrome-flags.conf 24allow ${HOME}/.config/chrome-flags.conf
25whitelist ${HOME}/.config/chrome-flags.config 25allow ${HOME}/.config/chrome-flags.config
26 26
27# Redirect 27# Redirect
28include chromium-common.profile 28include chromium-common.profile
diff --git a/etc/profile-a-l/google-earth.profile b/etc/profile-a-l/google-earth.profile
index 65ac04771..6039f7cbd 100644
--- a/etc/profile-a-l/google-earth.profile
+++ b/etc/profile-a-l/google-earth.profile
@@ -5,8 +5,8 @@ include google-earth.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${HOME}/.config/Google 8nodeny ${HOME}/.config/Google
9noblacklist ${HOME}/.googleearth 9nodeny ${HOME}/.googleearth
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -17,8 +17,8 @@ include disable-programs.inc
17 17
18mkdir ${HOME}/.config/Google 18mkdir ${HOME}/.config/Google
19mkdir ${HOME}/.googleearth 19mkdir ${HOME}/.googleearth
20whitelist ${HOME}/.config/Google 20allow ${HOME}/.config/Google
21whitelist ${HOME}/.googleearth 21allow ${HOME}/.googleearth
22include whitelist-common.inc 22include whitelist-common.inc
23 23
24caps.drop all 24caps.drop all
diff --git a/etc/profile-a-l/google-play-music-desktop-player.profile b/etc/profile-a-l/google-play-music-desktop-player.profile
index a7aabe105..fdb65b93c 100644
--- a/etc/profile-a-l/google-play-music-desktop-player.profile
+++ b/etc/profile-a-l/google-play-music-desktop-player.profile
@@ -8,7 +8,7 @@ include globals.local
8# noexec /tmp breaks mpris support 8# noexec /tmp breaks mpris support
9ignore noexec /tmp 9ignore noexec /tmp
10 10
11noblacklist ${HOME}/.config/Google Play Music Desktop Player 11nodeny ${HOME}/.config/Google Play Music Desktop Player
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
@@ -20,7 +20,7 @@ include disable-programs.inc
20mkdir ${HOME}/.config/Google Play Music Desktop Player 20mkdir ${HOME}/.config/Google Play Music Desktop Player
21# whitelist ${HOME}/.config/pulse 21# whitelist ${HOME}/.config/pulse
22# whitelist ${HOME}/.pulse 22# whitelist ${HOME}/.pulse
23whitelist ${HOME}/.config/Google Play Music Desktop Player 23allow ${HOME}/.config/Google Play Music Desktop Player
24include whitelist-common.inc 24include whitelist-common.inc
25 25
26caps.drop all 26caps.drop all
diff --git a/etc/profile-a-l/googler-common.profile b/etc/profile-a-l/googler-common.profile
index 2d0bce52b..952c9c1d4 100644
--- a/etc/profile-a-l/googler-common.profile
+++ b/etc/profile-a-l/googler-common.profile
@@ -7,10 +7,10 @@ include googler-common.local
7# added by caller profile 7# added by caller profile
8#include globals.local 8#include globals.local
9 9
10blacklist /tmp/.X11-unix 10deny /tmp/.X11-unix
11blacklist ${RUNUSER} 11deny ${RUNUSER}
12 12
13noblacklist ${HOME}/.w3m 13nodeny ${HOME}/.w3m
14 14
15# Allow /bin/sh (blacklisted by disable-shell.inc) 15# Allow /bin/sh (blacklisted by disable-shell.inc)
16include allow-bin-sh.inc 16include allow-bin-sh.inc
@@ -26,7 +26,7 @@ include disable-programs.inc
26include disable-shell.inc 26include disable-shell.inc
27include disable-xdg.inc 27include disable-xdg.inc
28 28
29whitelist ${HOME}/.w3m 29allow ${HOME}/.w3m
30include whitelist-usr-share-common.inc 30include whitelist-usr-share-common.inc
31include whitelist-var-common.inc 31include whitelist-var-common.inc
32 32
diff --git a/etc/profile-a-l/gpa.profile b/etc/profile-a-l/gpa.profile
index 37b4f0b1c..9b8da361b 100644
--- a/etc/profile-a-l/gpa.profile
+++ b/etc/profile-a-l/gpa.profile
@@ -6,7 +6,7 @@ include gpa.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.gnupg 9nodeny ${HOME}/.gnupg
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
diff --git a/etc/profile-a-l/gpg-agent.profile b/etc/profile-a-l/gpg-agent.profile
index 7f0b614b1..5fa66bb55 100644
--- a/etc/profile-a-l/gpg-agent.profile
+++ b/etc/profile-a-l/gpg-agent.profile
@@ -7,10 +7,10 @@ include gpg-agent.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10noblacklist ${HOME}/.gnupg 10nodeny ${HOME}/.gnupg
11 11
12blacklist /tmp/.X11-unix 12deny /tmp/.X11-unix
13blacklist ${RUNUSER}/wayland-* 13deny ${RUNUSER}/wayland-*
14 14
15include disable-common.inc 15include disable-common.inc
16include disable-devel.inc 16include disable-devel.inc
@@ -20,11 +20,11 @@ include disable-programs.inc
20include disable-xdg.inc 20include disable-xdg.inc
21 21
22mkdir ${HOME}/.gnupg 22mkdir ${HOME}/.gnupg
23whitelist ${HOME}/.gnupg 23allow ${HOME}/.gnupg
24whitelist ${RUNUSER}/gnupg 24allow ${RUNUSER}/gnupg
25whitelist ${RUNUSER}/keyring 25allow ${RUNUSER}/keyring
26whitelist /usr/share/gnupg 26allow /usr/share/gnupg
27whitelist /usr/share/gnupg2 27allow /usr/share/gnupg2
28include whitelist-common.inc 28include whitelist-common.inc
29include whitelist-runuser-common.inc 29include whitelist-runuser-common.inc
30include whitelist-usr-share-common.inc 30include whitelist-usr-share-common.inc
diff --git a/etc/profile-a-l/gpg.profile b/etc/profile-a-l/gpg.profile
index 4a4d6527c..2ad896abe 100644
--- a/etc/profile-a-l/gpg.profile
+++ b/etc/profile-a-l/gpg.profile
@@ -7,10 +7,10 @@ include gpg.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10noblacklist ${HOME}/.gnupg 10nodeny ${HOME}/.gnupg
11 11
12blacklist /tmp/.X11-unix 12deny /tmp/.X11-unix
13blacklist ${RUNUSER}/wayland-* 13deny ${RUNUSER}/wayland-*
14 14
15include disable-common.inc 15include disable-common.inc
16include disable-devel.inc 16include disable-devel.inc
@@ -18,11 +18,11 @@ include disable-interpreters.inc
18include disable-passwdmgr.inc 18include disable-passwdmgr.inc
19include disable-programs.inc 19include disable-programs.inc
20 20
21whitelist ${RUNUSER}/gnupg 21allow ${RUNUSER}/gnupg
22whitelist ${RUNUSER}/keyring 22allow ${RUNUSER}/keyring
23whitelist /usr/share/gnupg 23allow /usr/share/gnupg
24whitelist /usr/share/gnupg2 24allow /usr/share/gnupg2
25whitelist /usr/share/pacman/keyrings 25allow /usr/share/pacman/keyrings
26include whitelist-runuser-common.inc 26include whitelist-runuser-common.inc
27include whitelist-usr-share-common.inc 27include whitelist-usr-share-common.inc
28include whitelist-var-common.inc 28include whitelist-var-common.inc
diff --git a/etc/profile-a-l/gpicview.profile b/etc/profile-a-l/gpicview.profile
index fa53c26c8..0552dc3d7 100644
--- a/etc/profile-a-l/gpicview.profile
+++ b/etc/profile-a-l/gpicview.profile
@@ -6,7 +6,7 @@ include gpicview.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/gpicview 9nodeny ${HOME}/.config/gpicview
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -16,7 +16,7 @@ include disable-passwdmgr.inc
16include disable-programs.inc 16include disable-programs.inc
17include disable-shell.inc 17include disable-shell.inc
18 18
19whitelist /usr/share/gpicview 19allow /usr/share/gpicview
20include whitelist-usr-share-common.inc 20include whitelist-usr-share-common.inc
21include whitelist-var-common.inc 21include whitelist-var-common.inc
22 22
diff --git a/etc/profile-a-l/gpredict.profile b/etc/profile-a-l/gpredict.profile
index 253d644f1..c9e62a73f 100644
--- a/etc/profile-a-l/gpredict.profile
+++ b/etc/profile-a-l/gpredict.profile
@@ -6,7 +6,7 @@ include gpredict.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/Gpredict 9nodeny ${HOME}/.config/Gpredict
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -17,7 +17,7 @@ include disable-programs.inc
17include disable-shell.inc 17include disable-shell.inc
18 18
19mkdir ${HOME}/.config/Gpredict 19mkdir ${HOME}/.config/Gpredict
20whitelist ${HOME}/.config/Gpredict 20allow ${HOME}/.config/Gpredict
21include whitelist-common.inc 21include whitelist-common.inc
22 22
23caps.drop all 23caps.drop all
diff --git a/etc/profile-a-l/gradio.profile b/etc/profile-a-l/gradio.profile
index 2b4c536d2..2aebe2338 100644
--- a/etc/profile-a-l/gradio.profile
+++ b/etc/profile-a-l/gradio.profile
@@ -5,8 +5,8 @@ include gradio.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${HOME}/.cache/gradio 8nodeny ${HOME}/.cache/gradio
9noblacklist ${HOME}/.local/share/gradio 9nodeny ${HOME}/.local/share/gradio
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -18,8 +18,8 @@ include disable-xdg.inc
18 18
19mkdir ${HOME}/.cache/gradio 19mkdir ${HOME}/.cache/gradio
20mkdir ${HOME}/.local/share/gradio 20mkdir ${HOME}/.local/share/gradio
21whitelist ${HOME}/.cache/gradio 21allow ${HOME}/.cache/gradio
22whitelist ${HOME}/.local/share/gradio 22allow ${HOME}/.local/share/gradio
23include whitelist-common.inc 23include whitelist-common.inc
24include whitelist-runuser-common.inc 24include whitelist-runuser-common.inc
25include whitelist-usr-share-common.inc 25include whitelist-usr-share-common.inc
diff --git a/etc/profile-a-l/gramps.profile b/etc/profile-a-l/gramps.profile
index c7e0c2977..53f0baccb 100644
--- a/etc/profile-a-l/gramps.profile
+++ b/etc/profile-a-l/gramps.profile
@@ -6,7 +6,7 @@ include gramps.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.gramps 9nodeny ${HOME}/.gramps
10 10
11# Allow python (blacklisted by disable-interpreters.inc) 11# Allow python (blacklisted by disable-interpreters.inc)
12#include allow-python2.inc 12#include allow-python2.inc
@@ -21,7 +21,7 @@ include disable-programs.inc
21include disable-xdg.inc 21include disable-xdg.inc
22 22
23mkdir ${HOME}/.gramps 23mkdir ${HOME}/.gramps
24whitelist ${HOME}/.gramps 24allow ${HOME}/.gramps
25include whitelist-common.inc 25include whitelist-common.inc
26include whitelist-var-common.inc 26include whitelist-var-common.inc
27 27
diff --git a/etc/profile-a-l/gravity-beams-and-evaporating-stars.profile b/etc/profile-a-l/gravity-beams-and-evaporating-stars.profile
index 890ba2560..ecc871c2e 100644
--- a/etc/profile-a-l/gravity-beams-and-evaporating-stars.profile
+++ b/etc/profile-a-l/gravity-beams-and-evaporating-stars.profile
@@ -15,7 +15,7 @@ include disable-programs.inc
15include disable-shell.inc 15include disable-shell.inc
16include disable-xdg.inc 16include disable-xdg.inc
17 17
18whitelist /usr/share/gravity-beams-and-evaporating-stars 18allow /usr/share/gravity-beams-and-evaporating-stars
19include whitelist-common.inc 19include whitelist-common.inc
20include whitelist-usr-share-common.inc 20include whitelist-usr-share-common.inc
21include whitelist-var-common.inc 21include whitelist-var-common.inc
diff --git a/etc/profile-a-l/gthumb.profile b/etc/profile-a-l/gthumb.profile
index 5927e8c4d..9a4f7b4fb 100644
--- a/etc/profile-a-l/gthumb.profile
+++ b/etc/profile-a-l/gthumb.profile
@@ -6,9 +6,9 @@ include gthumb.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/gthumb 9nodeny ${HOME}/.config/gthumb
10noblacklist ${HOME}/.Steam 10nodeny ${HOME}/.Steam
11noblacklist ${HOME}/.steam 11nodeny ${HOME}/.steam
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
diff --git a/etc/profile-a-l/gtk-update-icon-cache.profile b/etc/profile-a-l/gtk-update-icon-cache.profile
index c8addae75..d6bb9902a 100644
--- a/etc/profile-a-l/gtk-update-icon-cache.profile
+++ b/etc/profile-a-l/gtk-update-icon-cache.profile
@@ -7,7 +7,7 @@ include gtk-update-icon-cache.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10blacklist ${RUNUSER}/wayland-* 10deny ${RUNUSER}/wayland-*
11 11
12include disable-common.inc 12include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
diff --git a/etc/profile-a-l/gtk2-youtube-viewer.profile b/etc/profile-a-l/gtk2-youtube-viewer.profile
index 787c7bd90..8241de43a 100644
--- a/etc/profile-a-l/gtk2-youtube-viewer.profile
+++ b/etc/profile-a-l/gtk2-youtube-viewer.profile
@@ -8,8 +8,8 @@ include gtk2-youtube-viewer.local
8 8
9ignore quiet 9ignore quiet
10 10
11noblacklist /tmp/.X11-unix 11nodeny /tmp/.X11-unix
12noblacklist ${RUNUSER} 12nodeny ${RUNUSER}
13 13
14include whitelist-runuser-common.inc 14include whitelist-runuser-common.inc
15 15
diff --git a/etc/profile-a-l/gtk3-youtube-viewer.profile b/etc/profile-a-l/gtk3-youtube-viewer.profile
index 988882622..6ea4ebbdc 100644
--- a/etc/profile-a-l/gtk3-youtube-viewer.profile
+++ b/etc/profile-a-l/gtk3-youtube-viewer.profile
@@ -8,8 +8,8 @@ include gtk3-youtube-viewer.local
8 8
9ignore quiet 9ignore quiet
10 10
11noblacklist /tmp/.X11-unix 11nodeny /tmp/.X11-unix
12noblacklist ${RUNUSER} 12nodeny ${RUNUSER}
13 13
14include whitelist-runuser-common.inc 14include whitelist-runuser-common.inc
15 15
diff --git a/etc/profile-a-l/guayadeque.profile b/etc/profile-a-l/guayadeque.profile
index 3d2b71e9d..731bcad1d 100644
--- a/etc/profile-a-l/guayadeque.profile
+++ b/etc/profile-a-l/guayadeque.profile
@@ -5,8 +5,8 @@ include guayadeque.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${HOME}/.guayadeque 8nodeny ${HOME}/.guayadeque
9noblacklist ${MUSIC} 9nodeny ${MUSIC}
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
diff --git a/etc/profile-a-l/gummi.profile b/etc/profile-a-l/gummi.profile
index 2223c37a1..5cdc2cc18 100644
--- a/etc/profile-a-l/gummi.profile
+++ b/etc/profile-a-l/gummi.profile
@@ -5,8 +5,8 @@ include gummi.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${HOME}/.cache/gummi 8nodeny ${HOME}/.cache/gummi
9noblacklist ${HOME}/.config/gummi 9nodeny ${HOME}/.config/gummi
10 10
11# Allow lua (blacklisted by disable-interpreters.inc) 11# Allow lua (blacklisted by disable-interpreters.inc)
12include allow-lua.inc 12include allow-lua.inc
diff --git a/etc/profile-a-l/guvcview.profile b/etc/profile-a-l/guvcview.profile
index 9221ca31c..3404f5177 100644
--- a/etc/profile-a-l/guvcview.profile
+++ b/etc/profile-a-l/guvcview.profile
@@ -6,10 +6,10 @@ include guvcview.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/guvcview2 9nodeny ${HOME}/.config/guvcview2
10 10
11noblacklist ${PICTURES} 11nodeny ${PICTURES}
12noblacklist ${VIDEOS} 12nodeny ${VIDEOS}
13 13
14include disable-common.inc 14include disable-common.inc
15include disable-devel.inc 15include disable-devel.inc
@@ -21,9 +21,9 @@ include disable-shell.inc
21include disable-xdg.inc 21include disable-xdg.inc
22 22
23mkdir ${HOME}/.config/guvcview2 23mkdir ${HOME}/.config/guvcview2
24whitelist ${HOME}/.config/guvcview2 24allow ${HOME}/.config/guvcview2
25whitelist ${PICTURES} 25allow ${PICTURES}
26whitelist ${VIDEOS} 26allow ${VIDEOS}
27include whitelist-common.inc 27include whitelist-common.inc
28include whitelist-runuser-common.inc 28include whitelist-runuser-common.inc
29include whitelist-usr-share-common.inc 29include whitelist-usr-share-common.inc
diff --git a/etc/profile-a-l/gwenview.profile b/etc/profile-a-l/gwenview.profile
index d33e2a673..132b5a2e2 100644
--- a/etc/profile-a-l/gwenview.profile
+++ b/etc/profile-a-l/gwenview.profile
@@ -6,17 +6,17 @@ include gwenview.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/GIMP 9nodeny ${HOME}/.config/GIMP
10noblacklist ${HOME}/.config/gwenviewrc 10nodeny ${HOME}/.config/gwenviewrc
11noblacklist ${HOME}/.config/org.kde.gwenviewrc 11nodeny ${HOME}/.config/org.kde.gwenviewrc
12noblacklist ${HOME}/.gimp* 12nodeny ${HOME}/.gimp*
13noblacklist ${HOME}/.kde/share/apps/gwenview 13nodeny ${HOME}/.kde/share/apps/gwenview
14noblacklist ${HOME}/.kde/share/config/gwenviewrc 14nodeny ${HOME}/.kde/share/config/gwenviewrc
15noblacklist ${HOME}/.kde4/share/apps/gwenview 15nodeny ${HOME}/.kde4/share/apps/gwenview
16noblacklist ${HOME}/.kde4/share/config/gwenviewrc 16nodeny ${HOME}/.kde4/share/config/gwenviewrc
17noblacklist ${HOME}/.local/share/gwenview 17nodeny ${HOME}/.local/share/gwenview
18noblacklist ${HOME}/.local/share/kxmlgui5/gwenview 18nodeny ${HOME}/.local/share/kxmlgui5/gwenview
19noblacklist ${HOME}/.local/share/org.kde.gwenview 19nodeny ${HOME}/.local/share/org.kde.gwenview
20 20
21include disable-common.inc 21include disable-common.inc
22include disable-devel.inc 22include disable-devel.inc
diff --git a/etc/profile-a-l/gzip.profile b/etc/profile-a-l/gzip.profile
index b261c16f4..46c98bdc2 100644
--- a/etc/profile-a-l/gzip.profile
+++ b/etc/profile-a-l/gzip.profile
@@ -9,7 +9,7 @@ include globals.local
9 9
10# Arch Linux (based distributions) need access to /var/lib/pacman. As we drop 10# Arch Linux (based distributions) need access to /var/lib/pacman. As we drop
11# all capabilities this is automatically read-only. 11# all capabilities this is automatically read-only.
12noblacklist /var/lib/pacman 12nodeny /var/lib/pacman
13 13
14# Redirect 14# Redirect
15include archiver-common.profile 15include archiver-common.profile
diff --git a/etc/profile-a-l/handbrake.profile b/etc/profile-a-l/handbrake.profile
index 847e1ec1e..c102ac4cb 100644
--- a/etc/profile-a-l/handbrake.profile
+++ b/etc/profile-a-l/handbrake.profile
@@ -6,9 +6,9 @@ include handbrake.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/ghb 9nodeny ${HOME}/.config/ghb
10noblacklist ${MUSIC} 10nodeny ${MUSIC}
11noblacklist ${VIDEOS} 11nodeny ${VIDEOS}
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
diff --git a/etc/profile-a-l/hashcat.profile b/etc/profile-a-l/hashcat.profile
index aab4b0c21..d98a1b554 100644
--- a/etc/profile-a-l/hashcat.profile
+++ b/etc/profile-a-l/hashcat.profile
@@ -7,11 +7,11 @@ include hashcat.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10blacklist ${RUNUSER}/wayland-* 10deny ${RUNUSER}/wayland-*
11 11
12noblacklist ${HOME}/.hashcat 12nodeny ${HOME}/.hashcat
13noblacklist /usr/include 13nodeny /usr/include
14noblacklist ${DOCUMENTS} 14nodeny ${DOCUMENTS}
15 15
16include disable-common.inc 16include disable-common.inc
17include disable-devel.inc 17include disable-devel.inc
diff --git a/etc/profile-a-l/hasher-common.profile b/etc/profile-a-l/hasher-common.profile
index 44584f26b..1c2a44e06 100644
--- a/etc/profile-a-l/hasher-common.profile
+++ b/etc/profile-a-l/hasher-common.profile
@@ -4,7 +4,7 @@ include hasher-common.local
4 4
5# common profile for hasher/checksum tools 5# common profile for hasher/checksum tools
6 6
7blacklist ${RUNUSER} 7deny ${RUNUSER}
8 8
9# Comment/uncomment the relevant include file(s) in your hasher-common.local 9# Comment/uncomment the relevant include file(s) in your hasher-common.local
10# to (un)restrict file access for **all** hashers. Another option is to do this **per hasher** 10# to (un)restrict file access for **all** hashers. Another option is to do this **per hasher**
diff --git a/etc/profile-a-l/hedgewars.profile b/etc/profile-a-l/hedgewars.profile
index c0675d8ec..90833af91 100644
--- a/etc/profile-a-l/hedgewars.profile
+++ b/etc/profile-a-l/hedgewars.profile
@@ -6,7 +6,7 @@ include hedgewars.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.hedgewars 9nodeny ${HOME}/.hedgewars
10 10
11include allow-lua.inc 11include allow-lua.inc
12 12
@@ -17,7 +17,7 @@ include disable-passwdmgr.inc
17include disable-programs.inc 17include disable-programs.inc
18 18
19mkdir ${HOME}/.hedgewars 19mkdir ${HOME}/.hedgewars
20whitelist ${HOME}/.hedgewars 20allow ${HOME}/.hedgewars
21include whitelist-common.inc 21include whitelist-common.inc
22 22
23caps.drop all 23caps.drop all
diff --git a/etc/profile-a-l/hexchat.profile b/etc/profile-a-l/hexchat.profile
index b887de147..993efb591 100644
--- a/etc/profile-a-l/hexchat.profile
+++ b/etc/profile-a-l/hexchat.profile
@@ -6,7 +6,7 @@ include hexchat.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/hexchat 9nodeny ${HOME}/.config/hexchat
10 10
11# Allow /bin/sh (blacklisted by disable-shell.inc) 11# Allow /bin/sh (blacklisted by disable-shell.inc)
12include allow-bin-sh.inc 12include allow-bin-sh.inc
@@ -28,7 +28,7 @@ include disable-shell.inc
28include disable-xdg.inc 28include disable-xdg.inc
29 29
30mkdir ${HOME}/.config/hexchat 30mkdir ${HOME}/.config/hexchat
31whitelist ${HOME}/.config/hexchat 31allow ${HOME}/.config/hexchat
32include whitelist-common.inc 32include whitelist-common.inc
33include whitelist-var-common.inc 33include whitelist-var-common.inc
34 34
diff --git a/etc/profile-a-l/highlight.profile b/etc/profile-a-l/highlight.profile
index 643736ac7..53db642dc 100644
--- a/etc/profile-a-l/highlight.profile
+++ b/etc/profile-a-l/highlight.profile
@@ -6,7 +6,7 @@ include highlight.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9blacklist ${RUNUSER} 9deny ${RUNUSER}
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
diff --git a/etc/profile-a-l/homebank.profile b/etc/profile-a-l/homebank.profile
index 199b1a5e5..ef259cc00 100644
--- a/etc/profile-a-l/homebank.profile
+++ b/etc/profile-a-l/homebank.profile
@@ -6,7 +6,7 @@ include homebank.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/homebank 9nodeny ${HOME}/.config/homebank
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -18,9 +18,9 @@ include disable-shell.inc
18include disable-xdg.inc 18include disable-xdg.inc
19 19
20mkdir ${HOME}/.config/homebank 20mkdir ${HOME}/.config/homebank
21whitelist ${DOWNLOADS} 21allow ${DOWNLOADS}
22whitelist ${HOME}/.config/homebank 22allow ${HOME}/.config/homebank
23whitelist /usr/share/homebank 23allow /usr/share/homebank
24include whitelist-common.inc 24include whitelist-common.inc
25include whitelist-runuser-common.inc 25include whitelist-runuser-common.inc
26include whitelist-usr-share-common.inc 26include whitelist-usr-share-common.inc
diff --git a/etc/profile-a-l/host.profile b/etc/profile-a-l/host.profile
index 00d9f7a76..63e1be259 100644
--- a/etc/profile-a-l/host.profile
+++ b/etc/profile-a-l/host.profile
@@ -7,8 +7,8 @@ include host.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10blacklist ${RUNUSER} 10deny ${RUNUSER}
11noblacklist ${PATH}/host 11nodeny ${PATH}/host
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
diff --git a/etc/profile-a-l/hugin.profile b/etc/profile-a-l/hugin.profile
index 267712c87..db5cd29cc 100644
--- a/etc/profile-a-l/hugin.profile
+++ b/etc/profile-a-l/hugin.profile
@@ -6,9 +6,9 @@ include hugin.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.hugin 9nodeny ${HOME}/.hugin
10noblacklist ${DOCUMENTS} 10nodeny ${DOCUMENTS}
11noblacklist ${PICTURES} 11nodeny ${PICTURES}
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
diff --git a/etc/profile-a-l/hyperrogue.profile b/etc/profile-a-l/hyperrogue.profile
index e66ffd7e1..1fb33ceb8 100644
--- a/etc/profile-a-l/hyperrogue.profile
+++ b/etc/profile-a-l/hyperrogue.profile
@@ -6,7 +6,7 @@ include hyperrogue.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/hyperrogue.ini 9nodeny ${HOME}/hyperrogue.ini
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -18,8 +18,8 @@ include disable-shell.inc
18include disable-xdg.inc 18include disable-xdg.inc
19 19
20mkfile ${HOME}/hyperrogue.ini 20mkfile ${HOME}/hyperrogue.ini
21whitelist ${HOME}/hyperrogue.ini 21allow ${HOME}/hyperrogue.ini
22whitelist /usr/share/hyperrogue 22allow /usr/share/hyperrogue
23include whitelist-common.inc 23include whitelist-common.inc
24include whitelist-usr-share-common.inc 24include whitelist-usr-share-common.inc
25include whitelist-var-common.inc 25include whitelist-var-common.inc
diff --git a/etc/profile-a-l/i2prouter.profile b/etc/profile-a-l/i2prouter.profile
index 47c984175..c8a2e8a04 100644
--- a/etc/profile-a-l/i2prouter.profile
+++ b/etc/profile-a-l/i2prouter.profile
@@ -14,12 +14,12 @@ include globals.local
14# Only needed when i2prouter binary resides in home directory (official I2P java installer does so). 14# Only needed when i2prouter binary resides in home directory (official I2P java installer does so).
15ignore noexec ${HOME} 15ignore noexec ${HOME}
16 16
17noblacklist ${HOME}/.config/i2p 17nodeny ${HOME}/.config/i2p
18noblacklist ${HOME}/.i2p 18nodeny ${HOME}/.i2p
19noblacklist ${HOME}/.local/share/i2p 19nodeny ${HOME}/.local/share/i2p
20noblacklist ${HOME}/i2p 20nodeny ${HOME}/i2p
21# Only needed when wrapper resides in /usr/sbin/ (Ubuntu official I2P PPA package does so). 21# Only needed when wrapper resides in /usr/sbin/ (Ubuntu official I2P PPA package does so).
22noblacklist /usr/sbin 22nodeny /usr/sbin
23 23
24# Allow java (blacklisted by disable-devel.inc) 24# Allow java (blacklisted by disable-devel.inc)
25include allow-java.inc 25include allow-java.inc
@@ -36,12 +36,12 @@ mkdir ${HOME}/.config/i2p
36mkdir ${HOME}/.i2p 36mkdir ${HOME}/.i2p
37mkdir ${HOME}/.local/share/i2p 37mkdir ${HOME}/.local/share/i2p
38mkdir ${HOME}/i2p 38mkdir ${HOME}/i2p
39whitelist ${HOME}/.config/i2p 39allow ${HOME}/.config/i2p
40whitelist ${HOME}/.i2p 40allow ${HOME}/.i2p
41whitelist ${HOME}/.local/share/i2p 41allow ${HOME}/.local/share/i2p
42whitelist ${HOME}/i2p 42allow ${HOME}/i2p
43# Only needed when wrapper resides in /usr/sbin/ (Ubuntu official I2P PPA package does so). 43# Only needed when wrapper resides in /usr/sbin/ (Ubuntu official I2P PPA package does so).
44whitelist /usr/sbin/wrapper* 44allow /usr/sbin/wrapper*
45 45
46include whitelist-common.inc 46include whitelist-common.inc
47 47
diff --git a/etc/profile-a-l/i3.profile b/etc/profile-a-l/i3.profile
index e96b1843c..95ddad221 100644
--- a/etc/profile-a-l/i3.profile
+++ b/etc/profile-a-l/i3.profile
@@ -7,7 +7,7 @@ include i3.local
7include globals.local 7include globals.local
8 8
9# all applications started in i3 will run in this profile 9# all applications started in i3 will run in this profile
10noblacklist ${HOME}/.config/i3 10nodeny ${HOME}/.config/i3
11include disable-common.inc 11include disable-common.inc
12 12
13caps.drop all 13caps.drop all
diff --git a/etc/profile-a-l/icecat.profile b/etc/profile-a-l/icecat.profile
index 660343a29..0de2f658b 100644
--- a/etc/profile-a-l/icecat.profile
+++ b/etc/profile-a-l/icecat.profile
@@ -5,13 +5,13 @@ include icecat.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${HOME}/.cache/mozilla 8nodeny ${HOME}/.cache/mozilla
9noblacklist ${HOME}/.mozilla 9nodeny ${HOME}/.mozilla
10 10
11mkdir ${HOME}/.cache/mozilla/icecat 11mkdir ${HOME}/.cache/mozilla/icecat
12mkdir ${HOME}/.mozilla 12mkdir ${HOME}/.mozilla
13whitelist ${HOME}/.cache/mozilla/icecat 13allow ${HOME}/.cache/mozilla/icecat
14whitelist ${HOME}/.mozilla 14allow ${HOME}/.mozilla
15 15
16# private-etc must first be enabled in firefox-common.profile 16# private-etc must first be enabled in firefox-common.profile
17#private-etc icecat 17#private-etc icecat
diff --git a/etc/profile-a-l/icedove.profile b/etc/profile-a-l/icedove.profile
index 19690cd5a..0c22d87d0 100644
--- a/etc/profile-a-l/icedove.profile
+++ b/etc/profile-a-l/icedove.profile
@@ -9,16 +9,16 @@ include icedove.local
9# Users have icedove set to open a browser by clicking a link in an email 9# Users have icedove set to open a browser by clicking a link in an email
10# We are not allowed to blacklist browser-specific directories 10# We are not allowed to blacklist browser-specific directories
11 11
12noblacklist ${HOME}/.cache/icedove 12nodeny ${HOME}/.cache/icedove
13noblacklist ${HOME}/.gnupg 13nodeny ${HOME}/.gnupg
14noblacklist ${HOME}/.icedove 14nodeny ${HOME}/.icedove
15 15
16mkdir ${HOME}/.cache/icedove 16mkdir ${HOME}/.cache/icedove
17mkdir ${HOME}/.gnupg 17mkdir ${HOME}/.gnupg
18mkdir ${HOME}/.icedove 18mkdir ${HOME}/.icedove
19whitelist ${HOME}/.cache/icedove 19allow ${HOME}/.cache/icedove
20whitelist ${HOME}/.gnupg 20allow ${HOME}/.gnupg
21whitelist ${HOME}/.icedove 21allow ${HOME}/.icedove
22include whitelist-common.inc 22include whitelist-common.inc
23 23
24ignore private-tmp 24ignore private-tmp
diff --git a/etc/profile-a-l/idea.sh.profile b/etc/profile-a-l/idea.sh.profile
index 680b8e777..180b62ec2 100644
--- a/etc/profile-a-l/idea.sh.profile
+++ b/etc/profile-a-l/idea.sh.profile
@@ -5,12 +5,12 @@ include idea.sh.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${HOME}/.IdeaIC* 8nodeny ${HOME}/.IdeaIC*
9noblacklist ${HOME}/.android 9nodeny ${HOME}/.android
10noblacklist ${HOME}/.jack-server 10nodeny ${HOME}/.jack-server
11noblacklist ${HOME}/.jack-settings 11nodeny ${HOME}/.jack-settings
12noblacklist ${HOME}/.local/share/JetBrains 12nodeny ${HOME}/.local/share/JetBrains
13noblacklist ${HOME}/.tooling 13nodeny ${HOME}/.tooling
14 14
15# Allows files commonly used by IDEs 15# Allows files commonly used by IDEs
16include allow-common-devel.inc 16include allow-common-devel.inc
diff --git a/etc/profile-a-l/imagej.profile b/etc/profile-a-l/imagej.profile
index 12ce7976b..5d28e7aca 100644
--- a/etc/profile-a-l/imagej.profile
+++ b/etc/profile-a-l/imagej.profile
@@ -6,7 +6,7 @@ include imagej.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.imagej 9nodeny ${HOME}/.imagej
10 10
11# Allow java (blacklisted by disable-devel.inc) 11# Allow java (blacklisted by disable-devel.inc)
12include allow-java.inc 12include allow-java.inc
diff --git a/etc/profile-a-l/img2txt.profile b/etc/profile-a-l/img2txt.profile
index c26958d06..70d56a7dc 100644
--- a/etc/profile-a-l/img2txt.profile
+++ b/etc/profile-a-l/img2txt.profile
@@ -5,10 +5,10 @@ include img2txt.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8blacklist ${RUNUSER}/wayland-* 8deny ${RUNUSER}/wayland-*
9 9
10noblacklist ${DOCUMENTS} 10nodeny ${DOCUMENTS}
11noblacklist ${PICTURES} 11nodeny ${PICTURES}
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
@@ -18,7 +18,7 @@ include disable-passwdmgr.inc
18include disable-programs.inc 18include disable-programs.inc
19include disable-xdg.inc 19include disable-xdg.inc
20 20
21whitelist /usr/share/imlib2 21allow /usr/share/imlib2
22include whitelist-usr-share-common.inc 22include whitelist-usr-share-common.inc
23include whitelist-var-common.inc 23include whitelist-var-common.inc
24 24
diff --git a/etc/profile-a-l/impressive.profile b/etc/profile-a-l/impressive.profile
index c152be01c..4914cd9d0 100644
--- a/etc/profile-a-l/impressive.profile
+++ b/etc/profile-a-l/impressive.profile
@@ -6,9 +6,9 @@ include impressive.local
6# Persistent global definitions 6# Persistent global definitions
7#include globals.local 7#include globals.local
8 8
9noblacklist ${DOCUMENTS} 9nodeny ${DOCUMENTS}
10noblacklist /sbin 10nodeny /sbin
11noblacklist /usr/sbin 11nodeny /usr/sbin
12 12
13# Allow python (blacklisted by disable-interpreters.inc) 13# Allow python (blacklisted by disable-interpreters.inc)
14#include allow-python2.inc 14#include allow-python2.inc
@@ -23,8 +23,8 @@ include disable-programs.inc
23include disable-xdg.inc 23include disable-xdg.inc
24 24
25mkdir ${HOME}/.cache/mesa_shader_cache 25mkdir ${HOME}/.cache/mesa_shader_cache
26whitelist /usr/share/opengl-games-utils 26allow /usr/share/opengl-games-utils
27whitelist /usr/share/zenity 27allow /usr/share/zenity
28include whitelist-usr-share-common.inc 28include whitelist-usr-share-common.inc
29include whitelist-var-common.inc 29include whitelist-var-common.inc
30 30
diff --git a/etc/profile-a-l/inkscape.profile b/etc/profile-a-l/inkscape.profile
index 35dd86b32..1a949b300 100644
--- a/etc/profile-a-l/inkscape.profile
+++ b/etc/profile-a-l/inkscape.profile
@@ -6,14 +6,14 @@ include inkscape.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.cache/inkscape 9nodeny ${HOME}/.cache/inkscape
10noblacklist ${HOME}/.config/inkscape 10nodeny ${HOME}/.config/inkscape
11noblacklist ${HOME}/.inkscape 11nodeny ${HOME}/.inkscape
12noblacklist ${DOCUMENTS} 12nodeny ${DOCUMENTS}
13noblacklist ${PICTURES} 13nodeny ${PICTURES}
14# Allow exporting .xcf files 14# Allow exporting .xcf files
15noblacklist ${HOME}/.config/GIMP 15nodeny ${HOME}/.config/GIMP
16noblacklist ${HOME}/.gimp* 16nodeny ${HOME}/.gimp*
17 17
18 18
19# Allow python (blacklisted by disable-interpreters.inc) 19# Allow python (blacklisted by disable-interpreters.inc)
@@ -28,7 +28,7 @@ include disable-passwdmgr.inc
28include disable-programs.inc 28include disable-programs.inc
29include disable-xdg.inc 29include disable-xdg.inc
30 30
31whitelist /usr/share/inkscape 31allow /usr/share/inkscape
32include whitelist-usr-share-common.inc 32include whitelist-usr-share-common.inc
33include whitelist-var-common.inc 33include whitelist-var-common.inc
34 34
diff --git a/etc/profile-a-l/inox.profile b/etc/profile-a-l/inox.profile
index a5cac12f2..1591ed7ea 100644
--- a/etc/profile-a-l/inox.profile
+++ b/etc/profile-a-l/inox.profile
@@ -10,13 +10,13 @@ ignore whitelist /usr/share/chromium
10ignore include whitelist-runuser-common.inc 10ignore include whitelist-runuser-common.inc
11ignore include whitelist-usr-share-common.inc 11ignore include whitelist-usr-share-common.inc
12 12
13noblacklist ${HOME}/.cache/inox 13nodeny ${HOME}/.cache/inox
14noblacklist ${HOME}/.config/inox 14nodeny ${HOME}/.config/inox
15 15
16mkdir ${HOME}/.cache/inox 16mkdir ${HOME}/.cache/inox
17mkdir ${HOME}/.config/inox 17mkdir ${HOME}/.config/inox
18whitelist ${HOME}/.cache/inox 18allow ${HOME}/.cache/inox
19whitelist ${HOME}/.config/inox 19allow ${HOME}/.config/inox
20 20
21# Redirect 21# Redirect
22include chromium-common.profile 22include chromium-common.profile
diff --git a/etc/profile-a-l/iridium.profile b/etc/profile-a-l/iridium.profile
index 3037d00e9..f361fd663 100644
--- a/etc/profile-a-l/iridium.profile
+++ b/etc/profile-a-l/iridium.profile
@@ -10,13 +10,13 @@ ignore whitelist /usr/share/chromium
10ignore include whitelist-runuser-common.inc 10ignore include whitelist-runuser-common.inc
11ignore include whitelist-usr-share-common.inc 11ignore include whitelist-usr-share-common.inc
12 12
13noblacklist ${HOME}/.cache/iridium 13nodeny ${HOME}/.cache/iridium
14noblacklist ${HOME}/.config/iridium 14nodeny ${HOME}/.config/iridium
15 15
16mkdir ${HOME}/.cache/iridium 16mkdir ${HOME}/.cache/iridium
17mkdir ${HOME}/.config/iridium 17mkdir ${HOME}/.config/iridium
18whitelist ${HOME}/.cache/iridium 18allow ${HOME}/.cache/iridium
19whitelist ${HOME}/.config/iridium 19allow ${HOME}/.config/iridium
20 20
21# Redirect 21# Redirect
22include chromium-common.profile 22include chromium-common.profile
diff --git a/etc/profile-a-l/itch.profile b/etc/profile-a-l/itch.profile
index e02dcbdb1..fa0bcf986 100644
--- a/etc/profile-a-l/itch.profile
+++ b/etc/profile-a-l/itch.profile
@@ -8,8 +8,8 @@ include globals.local
8# itch.io has native firejail/sandboxing support bundled in 8# itch.io has native firejail/sandboxing support bundled in
9# See https://itch.io/docs/itch/using/sandbox/linux.html 9# See https://itch.io/docs/itch/using/sandbox/linux.html
10 10
11noblacklist ${HOME}/.itch 11nodeny ${HOME}/.itch
12noblacklist ${HOME}/.config/itch 12nodeny ${HOME}/.config/itch
13 13
14include disable-common.inc 14include disable-common.inc
15include disable-devel.inc 15include disable-devel.inc
@@ -19,8 +19,8 @@ include disable-programs.inc
19 19
20mkdir ${HOME}/.itch 20mkdir ${HOME}/.itch
21mkdir ${HOME}/.config/itch 21mkdir ${HOME}/.config/itch
22whitelist ${HOME}/.itch 22allow ${HOME}/.itch
23whitelist ${HOME}/.config/itch 23allow ${HOME}/.config/itch
24include whitelist-common.inc 24include whitelist-common.inc
25 25
26caps.drop all 26caps.drop all
diff --git a/etc/profile-a-l/jami-gnome.profile b/etc/profile-a-l/jami-gnome.profile
index 3e9abf369..e4be574df 100644
--- a/etc/profile-a-l/jami-gnome.profile
+++ b/etc/profile-a-l/jami-gnome.profile
@@ -6,8 +6,8 @@ include jami-gnome.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/jami 9nodeny ${HOME}/.config/jami
10noblacklist ${HOME}/.local/share/jami 10nodeny ${HOME}/.local/share/jami
11 11
12include disable-common.inc 12include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
@@ -18,8 +18,8 @@ include disable-programs.inc
18 18
19mkdir ${HOME}/.config/jami 19mkdir ${HOME}/.config/jami
20mkdir ${HOME}/.local/share/jami 20mkdir ${HOME}/.local/share/jami
21whitelist ${HOME}/.config/jami 21allow ${HOME}/.config/jami
22whitelist ${HOME}/.local/share/jami 22allow ${HOME}/.local/share/jami
23include whitelist-common.inc 23include whitelist-common.inc
24include whitelist-var-common.inc 24include whitelist-var-common.inc
25 25
diff --git a/etc/profile-a-l/jd-gui.profile b/etc/profile-a-l/jd-gui.profile
index 7d29f1068..bfea84c69 100644
--- a/etc/profile-a-l/jd-gui.profile
+++ b/etc/profile-a-l/jd-gui.profile
@@ -5,7 +5,7 @@ include jd-gui.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${HOME}/.config/jd-gui.cfg 8nodeny ${HOME}/.config/jd-gui.cfg
9 9
10# Allow java (blacklisted by disable-devel.inc) 10# Allow java (blacklisted by disable-devel.inc)
11include allow-java.inc 11include allow-java.inc
diff --git a/etc/profile-a-l/jerry.profile b/etc/profile-a-l/jerry.profile
index 85b1f2120..c41027618 100644
--- a/etc/profile-a-l/jerry.profile
+++ b/etc/profile-a-l/jerry.profile
@@ -6,7 +6,7 @@ include jerry.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/dkl 9nodeny ${HOME}/.config/dkl
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
diff --git a/etc/profile-a-l/jitsi-meet-desktop.profile b/etc/profile-a-l/jitsi-meet-desktop.profile
index edb7ed840..9ca30c36d 100644
--- a/etc/profile-a-l/jitsi-meet-desktop.profile
+++ b/etc/profile-a-l/jitsi-meet-desktop.profile
@@ -13,12 +13,12 @@ ignore shell none
13 13
14ignore noexec /tmp 14ignore noexec /tmp
15 15
16noblacklist ${HOME}/.config/Jitsi Meet 16nodeny ${HOME}/.config/Jitsi Meet
17 17
18nowhitelist ${DOWNLOADS} 18noallow ${DOWNLOADS}
19 19
20mkdir ${HOME}/.config/Jitsi Meet 20mkdir ${HOME}/.config/Jitsi Meet
21whitelist ${HOME}/.config/Jitsi Meet 21allow ${HOME}/.config/Jitsi Meet
22 22
23private-bin bash,electron,electron[0-9],electron[0-9][0-9],jitsi-meet-desktop,sh 23private-bin bash,electron,electron[0-9],electron[0-9][0-9],jitsi-meet-desktop,sh
24private-etc alsa,alternatives,asound.conf,bumblebee,ca-certificates,crypto-policies,drirc,fonts,glvnd,group,host.conf,hostname,hosts,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,locale,locale.alias,locale.conf,localtime,machine-id,mime.types,nsswitch.conf,nvidia,pango,passwd,pki,protocols,pulse,resolv.conf,rpc,services,ssl,X11,xdg 24private-etc alsa,alternatives,asound.conf,bumblebee,ca-certificates,crypto-policies,drirc,fonts,glvnd,group,host.conf,hostname,hosts,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,locale,locale.alias,locale.conf,localtime,machine-id,mime.types,nsswitch.conf,nvidia,pango,passwd,pki,protocols,pulse,resolv.conf,rpc,services,ssl,X11,xdg
diff --git a/etc/profile-a-l/jitsi.profile b/etc/profile-a-l/jitsi.profile
index 223c360b8..f53e6ca32 100644
--- a/etc/profile-a-l/jitsi.profile
+++ b/etc/profile-a-l/jitsi.profile
@@ -5,7 +5,7 @@ include jitsi.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${HOME}/.jitsi 8nodeny ${HOME}/.jitsi
9 9
10# Allow java (blacklisted by disable-devel.inc) 10# Allow java (blacklisted by disable-devel.inc)
11include allow-java.inc 11include allow-java.inc
diff --git a/etc/profile-a-l/jumpnbump.profile b/etc/profile-a-l/jumpnbump.profile
index 9954b8aea..c0a78ecc0 100644
--- a/etc/profile-a-l/jumpnbump.profile
+++ b/etc/profile-a-l/jumpnbump.profile
@@ -6,7 +6,7 @@ include jumpnbump.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.jumpnbump 9nodeny ${HOME}/.jumpnbump
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -17,8 +17,8 @@ include disable-programs.inc
17include disable-xdg.inc 17include disable-xdg.inc
18 18
19mkdir ${HOME}/.jumpnbump 19mkdir ${HOME}/.jumpnbump
20whitelist ${HOME}/.jumpnbump 20allow ${HOME}/.jumpnbump
21whitelist /usr/share/jumpnbump 21allow /usr/share/jumpnbump
22include whitelist-common.inc 22include whitelist-common.inc
23include whitelist-usr-share-common.inc 23include whitelist-usr-share-common.inc
24include whitelist-var-common.inc 24include whitelist-var-common.inc
diff --git a/etc/profile-a-l/k3b.profile b/etc/profile-a-l/k3b.profile
index 5ae90dff6..73ce8670f 100644
--- a/etc/profile-a-l/k3b.profile
+++ b/etc/profile-a-l/k3b.profile
@@ -6,11 +6,11 @@ include k3b.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/k3brc 9nodeny ${HOME}/.config/k3brc
10noblacklist ${HOME}/.kde/share/config/k3brc 10nodeny ${HOME}/.kde/share/config/k3brc
11noblacklist ${HOME}/.kde4/share/config/k3brc 11nodeny ${HOME}/.kde4/share/config/k3brc
12noblacklist ${HOME}/.local/share/kxmlgui5/k3b 12nodeny ${HOME}/.local/share/kxmlgui5/k3b
13noblacklist ${MUSIC} 13nodeny ${MUSIC}
14 14
15include disable-common.inc 15include disable-common.inc
16include disable-devel.inc 16include disable-devel.inc
diff --git a/etc/profile-a-l/kaffeine.profile b/etc/profile-a-l/kaffeine.profile
index d55fd22cb..e6a00e350 100644
--- a/etc/profile-a-l/kaffeine.profile
+++ b/etc/profile-a-l/kaffeine.profile
@@ -6,14 +6,14 @@ include kaffeine.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/kaffeinerc 9nodeny ${HOME}/.config/kaffeinerc
10noblacklist ${HOME}/.kde/share/apps/kaffeine 10nodeny ${HOME}/.kde/share/apps/kaffeine
11noblacklist ${HOME}/.kde/share/config/kaffeinerc 11nodeny ${HOME}/.kde/share/config/kaffeinerc
12noblacklist ${HOME}/.kde4/share/apps/kaffeine 12nodeny ${HOME}/.kde4/share/apps/kaffeine
13noblacklist ${HOME}/.kde4/share/config/kaffeinerc 13nodeny ${HOME}/.kde4/share/config/kaffeinerc
14noblacklist ${HOME}/.local/share/kaffeine 14nodeny ${HOME}/.local/share/kaffeine
15noblacklist ${MUSIC} 15nodeny ${MUSIC}
16noblacklist ${VIDEOS} 16nodeny ${VIDEOS}
17 17
18include disable-common.inc 18include disable-common.inc
19include disable-devel.inc 19include disable-devel.inc
diff --git a/etc/profile-a-l/kalgebra.profile b/etc/profile-a-l/kalgebra.profile
index 503dac4b6..98b04353e 100644
--- a/etc/profile-a-l/kalgebra.profile
+++ b/etc/profile-a-l/kalgebra.profile
@@ -6,8 +6,8 @@ include kalgebra.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/kalgebrarc 9nodeny ${HOME}/.config/kalgebrarc
10noblacklist ${HOME}/.local/share/kalgebra 10nodeny ${HOME}/.local/share/kalgebra
11 11
12include disable-common.inc 12include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
@@ -17,7 +17,7 @@ include disable-passwdmgr.inc
17include disable-programs.inc 17include disable-programs.inc
18include disable-xdg.inc 18include disable-xdg.inc
19 19
20whitelist /usr/share/kalgebramobile 20allow /usr/share/kalgebramobile
21include whitelist-usr-share-common.inc 21include whitelist-usr-share-common.inc
22include whitelist-var-common.inc 22include whitelist-var-common.inc
23 23
diff --git a/etc/profile-a-l/karbon.profile b/etc/profile-a-l/karbon.profile
index 231299a2f..db5394550 100644
--- a/etc/profile-a-l/karbon.profile
+++ b/etc/profile-a-l/karbon.profile
@@ -6,7 +6,7 @@ include karbon.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.local/share/kxmlgui5/karbon 9nodeny ${HOME}/.local/share/kxmlgui5/karbon
10 10
11# Redirect 11# Redirect
12include krita.profile 12include krita.profile
diff --git a/etc/profile-a-l/kate.profile b/etc/profile-a-l/kate.profile
index 27b87e7c3..d2b180492 100644
--- a/etc/profile-a-l/kate.profile
+++ b/etc/profile-a-l/kate.profile
@@ -8,20 +8,20 @@ include globals.local
8 8
9ignore noexec ${HOME} 9ignore noexec ${HOME}
10 10
11noblacklist ${HOME}/.config/katemetainfos 11nodeny ${HOME}/.config/katemetainfos
12noblacklist ${HOME}/.config/katepartrc 12nodeny ${HOME}/.config/katepartrc
13noblacklist ${HOME}/.config/katerc 13nodeny ${HOME}/.config/katerc
14noblacklist ${HOME}/.config/kateschemarc 14nodeny ${HOME}/.config/kateschemarc
15noblacklist ${HOME}/.config/katesyntaxhighlightingrc 15nodeny ${HOME}/.config/katesyntaxhighlightingrc
16noblacklist ${HOME}/.config/katevirc 16nodeny ${HOME}/.config/katevirc
17noblacklist ${HOME}/.local/share/kate 17nodeny ${HOME}/.local/share/kate
18noblacklist ${HOME}/.local/share/kxmlgui5/kate 18nodeny ${HOME}/.local/share/kxmlgui5/kate
19noblacklist ${HOME}/.local/share/kxmlgui5/katefiletree 19nodeny ${HOME}/.local/share/kxmlgui5/katefiletree
20noblacklist ${HOME}/.local/share/kxmlgui5/katekonsole 20nodeny ${HOME}/.local/share/kxmlgui5/katekonsole
21noblacklist ${HOME}/.local/share/kxmlgui5/kateopenheaderplugin 21nodeny ${HOME}/.local/share/kxmlgui5/kateopenheaderplugin
22noblacklist ${HOME}/.local/share/kxmlgui5/katepart 22nodeny ${HOME}/.local/share/kxmlgui5/katepart
23noblacklist ${HOME}/.local/share/kxmlgui5/kateproject 23nodeny ${HOME}/.local/share/kxmlgui5/kateproject
24noblacklist ${HOME}/.local/share/kxmlgui5/katesearch 24nodeny ${HOME}/.local/share/kxmlgui5/katesearch
25 25
26include disable-common.inc 26include disable-common.inc
27# include disable-devel.inc 27# include disable-devel.inc
diff --git a/etc/profile-a-l/kazam.profile b/etc/profile-a-l/kazam.profile
index 9795cf168..a4e2e64f4 100644
--- a/etc/profile-a-l/kazam.profile
+++ b/etc/profile-a-l/kazam.profile
@@ -8,9 +8,9 @@ include globals.local
8 8
9ignore noexec ${HOME} 9ignore noexec ${HOME}
10 10
11noblacklist ${PICTURES} 11nodeny ${PICTURES}
12noblacklist ${VIDEOS} 12nodeny ${VIDEOS}
13noblacklist ${HOME}/.config/kazam 13nodeny ${HOME}/.config/kazam
14 14
15# Allow python (blacklisted by disable-interpreters.inc) 15# Allow python (blacklisted by disable-interpreters.inc)
16include allow-python2.inc 16include allow-python2.inc
@@ -25,7 +25,7 @@ include disable-passwdmgr.inc
25include disable-shell.inc 25include disable-shell.inc
26include disable-xdg.inc 26include disable-xdg.inc
27 27
28whitelist /usr/share/kazam 28allow /usr/share/kazam
29include whitelist-runuser-common.inc 29include whitelist-runuser-common.inc
30include whitelist-usr-share-common.inc 30include whitelist-usr-share-common.inc
31include whitelist-var-common.inc 31include whitelist-var-common.inc
diff --git a/etc/profile-a-l/kcalc.profile b/etc/profile-a-l/kcalc.profile
index e36ee5ed2..fcb168d4d 100644
--- a/etc/profile-a-l/kcalc.profile
+++ b/etc/profile-a-l/kcalc.profile
@@ -6,7 +6,7 @@ include kcalc.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.local/share/kxmlgui5/kcalc 9nodeny ${HOME}/.local/share/kxmlgui5/kcalc
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -21,13 +21,13 @@ mkdir ${HOME}/.local/share/kxmlgui5/kcalc
21mkfile ${HOME}/.config/kcalcrc 21mkfile ${HOME}/.config/kcalcrc
22mkfile ${HOME}/.kde/share/config/kcalcrc 22mkfile ${HOME}/.kde/share/config/kcalcrc
23mkfile ${HOME}/.kde4/share/config/kcalcrc 23mkfile ${HOME}/.kde4/share/config/kcalcrc
24whitelist ${HOME}/.config/kcalcrc 24allow ${HOME}/.config/kcalcrc
25whitelist ${HOME}/.kde/share/config/kcalcrc 25allow ${HOME}/.kde/share/config/kcalcrc
26whitelist ${HOME}/.kde4/share/config/kcalcrc 26allow ${HOME}/.kde4/share/config/kcalcrc
27whitelist ${HOME}/.local/share/kxmlgui5/kcalc 27allow ${HOME}/.local/share/kxmlgui5/kcalc
28whitelist /usr/share/config.kcfg/kcalc.kcfg 28allow /usr/share/config.kcfg/kcalc.kcfg
29whitelist /usr/share/kcalc 29allow /usr/share/kcalc
30whitelist /usr/share/kconf_update/kcalcrc.upd 30allow /usr/share/kconf_update/kcalcrc.upd
31include whitelist-common.inc 31include whitelist-common.inc
32include whitelist-runuser-common.inc 32include whitelist-runuser-common.inc
33include whitelist-usr-share-common.inc 33include whitelist-usr-share-common.inc
diff --git a/etc/profile-a-l/kdenlive.profile b/etc/profile-a-l/kdenlive.profile
index d2a08a269..4acafbf2a 100644
--- a/etc/profile-a-l/kdenlive.profile
+++ b/etc/profile-a-l/kdenlive.profile
@@ -8,10 +8,10 @@ include globals.local
8 8
9ignore noexec ${HOME} 9ignore noexec ${HOME}
10 10
11noblacklist ${HOME}/.cache/kdenlive 11nodeny ${HOME}/.cache/kdenlive
12noblacklist ${HOME}/.config/kdenliverc 12nodeny ${HOME}/.config/kdenliverc
13noblacklist ${HOME}/.local/share/kdenlive 13nodeny ${HOME}/.local/share/kdenlive
14noblacklist ${HOME}/.local/share/kxmlgui5/kdenlive 14nodeny ${HOME}/.local/share/kxmlgui5/kdenlive
15 15
16include disable-common.inc 16include disable-common.inc
17include disable-devel.inc 17include disable-devel.inc
diff --git a/etc/profile-a-l/kdiff3.profile b/etc/profile-a-l/kdiff3.profile
index 7c1cb2294..0c37f7968 100644
--- a/etc/profile-a-l/kdiff3.profile
+++ b/etc/profile-a-l/kdiff3.profile
@@ -6,14 +6,14 @@ include kdiff3.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/kdiff3fileitemactionrc 9nodeny ${HOME}/.config/kdiff3fileitemactionrc
10noblacklist ${HOME}/.config/kdiff3rc 10nodeny ${HOME}/.config/kdiff3rc
11 11
12# Add the next line to your kdiff3.local if you don't need to compare files in disable-common.inc. 12# Add the next line to your kdiff3.local if you don't need to compare files in disable-common.inc.
13# By default we deny access only to .ssh and .gnupg. 13# By default we deny access only to .ssh and .gnupg.
14#include disable-common.inc 14#include disable-common.inc
15blacklist ${HOME}/.ssh 15deny ${HOME}/.ssh
16blacklist ${HOME}/.gnupg 16deny ${HOME}/.gnupg
17 17
18include disable-devel.inc 18include disable-devel.inc
19include disable-exec.inc 19include disable-exec.inc
diff --git a/etc/profile-a-l/keepass.profile b/etc/profile-a-l/keepass.profile
index ae8971ab4..9c06962bc 100644
--- a/etc/profile-a-l/keepass.profile
+++ b/etc/profile-a-l/keepass.profile
@@ -6,14 +6,14 @@ include keepass.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/*.kdb 9nodeny ${HOME}/*.kdb
10noblacklist ${HOME}/*.kdbx 10nodeny ${HOME}/*.kdbx
11noblacklist ${HOME}/.config/KeePass 11nodeny ${HOME}/.config/KeePass
12noblacklist ${HOME}/.config/keepass 12nodeny ${HOME}/.config/keepass
13noblacklist ${HOME}/.keepass 13nodeny ${HOME}/.keepass
14noblacklist ${HOME}/.local/share/KeePass 14nodeny ${HOME}/.local/share/KeePass
15noblacklist ${HOME}/.local/share/keepass 15nodeny ${HOME}/.local/share/keepass
16noblacklist ${DOCUMENTS} 16nodeny ${DOCUMENTS}
17 17
18include disable-common.inc 18include disable-common.inc
19include disable-devel.inc 19include disable-devel.inc
diff --git a/etc/profile-a-l/keepassx.profile b/etc/profile-a-l/keepassx.profile
index ac364986d..2772fa8bf 100644
--- a/etc/profile-a-l/keepassx.profile
+++ b/etc/profile-a-l/keepassx.profile
@@ -6,11 +6,11 @@ include keepassx.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/*.kdb 9nodeny ${HOME}/*.kdb
10noblacklist ${HOME}/*.kdbx 10nodeny ${HOME}/*.kdbx
11noblacklist ${HOME}/.config/keepassx 11nodeny ${HOME}/.config/keepassx
12noblacklist ${HOME}/.keepassx 12nodeny ${HOME}/.keepassx
13noblacklist ${DOCUMENTS} 13nodeny ${DOCUMENTS}
14 14
15include disable-common.inc 15include disable-common.inc
16include disable-devel.inc 16include disable-devel.inc
diff --git a/etc/profile-a-l/keepassxc.profile b/etc/profile-a-l/keepassxc.profile
index f71dcf82b..9c530b20d 100644
--- a/etc/profile-a-l/keepassxc.profile
+++ b/etc/profile-a-l/keepassxc.profile
@@ -6,23 +6,23 @@ include keepassxc.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/*.kdb 9nodeny ${HOME}/*.kdb
10noblacklist ${HOME}/*.kdbx 10nodeny ${HOME}/*.kdbx
11noblacklist ${HOME}/.cache/keepassxc 11nodeny ${HOME}/.cache/keepassxc
12noblacklist ${HOME}/.config/keepassxc 12nodeny ${HOME}/.config/keepassxc
13noblacklist ${HOME}/.config/KeePassXCrc 13nodeny ${HOME}/.config/KeePassXCrc
14noblacklist ${HOME}/.keepassxc 14nodeny ${HOME}/.keepassxc
15noblacklist ${DOCUMENTS} 15nodeny ${DOCUMENTS}
16 16
17# Allow browser profiles, required for browser integration. 17# Allow browser profiles, required for browser integration.
18noblacklist ${HOME}/.config/BraveSoftware 18nodeny ${HOME}/.config/BraveSoftware
19noblacklist ${HOME}/.config/chromium 19nodeny ${HOME}/.config/chromium
20noblacklist ${HOME}/.config/google-chrome 20nodeny ${HOME}/.config/google-chrome
21noblacklist ${HOME}/.config/vivaldi 21nodeny ${HOME}/.config/vivaldi
22noblacklist ${HOME}/.local/share/torbrowser 22nodeny ${HOME}/.local/share/torbrowser
23noblacklist ${HOME}/.mozilla 23nodeny ${HOME}/.mozilla
24 24
25blacklist /usr/libexec 25deny /usr/libexec
26 26
27include disable-common.inc 27include disable-common.inc
28include disable-devel.inc 28include disable-devel.inc
@@ -57,7 +57,7 @@ include disable-xdg.inc
57#whitelist ${HOME}/.config/KeePassXCrc 57#whitelist ${HOME}/.config/KeePassXCrc
58#include whitelist-common.inc 58#include whitelist-common.inc
59 59
60whitelist /usr/share/keepassxc 60allow /usr/share/keepassxc
61include whitelist-usr-share-common.inc 61include whitelist-usr-share-common.inc
62include whitelist-var-common.inc 62include whitelist-var-common.inc
63 63
diff --git a/etc/profile-a-l/kget.profile b/etc/profile-a-l/kget.profile
index 2c684504b..30c041cbc 100644
--- a/etc/profile-a-l/kget.profile
+++ b/etc/profile-a-l/kget.profile
@@ -6,13 +6,13 @@ include kget.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/kgetrc 9nodeny ${HOME}/.config/kgetrc
10noblacklist ${HOME}/.kde/share/apps/kget 10nodeny ${HOME}/.kde/share/apps/kget
11noblacklist ${HOME}/.kde/share/config/kgetrc 11nodeny ${HOME}/.kde/share/config/kgetrc
12noblacklist ${HOME}/.kde4/share/apps/kget 12nodeny ${HOME}/.kde4/share/apps/kget
13noblacklist ${HOME}/.kde4/share/config/kgetrc 13nodeny ${HOME}/.kde4/share/config/kgetrc
14noblacklist ${HOME}/.local/share/kget 14nodeny ${HOME}/.local/share/kget
15noblacklist ${HOME}/.local/share/kxmlgui5/kget 15nodeny ${HOME}/.local/share/kxmlgui5/kget
16 16
17include disable-common.inc 17include disable-common.inc
18include disable-devel.inc 18include disable-devel.inc
diff --git a/etc/profile-a-l/kid3-qt.profile b/etc/profile-a-l/kid3-qt.profile
index 9bcede077..84d135fc3 100644
--- a/etc/profile-a-l/kid3-qt.profile
+++ b/etc/profile-a-l/kid3-qt.profile
@@ -2,7 +2,7 @@
2# This file is overwritten after every install/update 2# This file is overwritten after every install/update
3include kid3-qt.local 3include kid3-qt.local
4 4
5noblacklist ${HOME}/.config/Kid3 5nodeny ${HOME}/.config/Kid3
6 6
7# Redirect 7# Redirect
8include kid3.profile 8include kid3.profile
diff --git a/etc/profile-a-l/kid3.profile b/etc/profile-a-l/kid3.profile
index e18292e99..0ef2a7845 100644
--- a/etc/profile-a-l/kid3.profile
+++ b/etc/profile-a-l/kid3.profile
@@ -6,9 +6,9 @@ include kid3.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${MUSIC} 9nodeny ${MUSIC}
10noblacklist ${HOME}/.config/kid3rc 10nodeny ${HOME}/.config/kid3rc
11noblacklist ${HOME}/.local/share/kxmlgui5/kid3 11nodeny ${HOME}/.local/share/kxmlgui5/kid3
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
diff --git a/etc/profile-a-l/kino.profile b/etc/profile-a-l/kino.profile
index 74014ffe6..833c1d22a 100644
--- a/etc/profile-a-l/kino.profile
+++ b/etc/profile-a-l/kino.profile
@@ -6,8 +6,8 @@ include kino.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.kino-history 9nodeny ${HOME}/.kino-history
10noblacklist ${HOME}/.kinorc 10nodeny ${HOME}/.kinorc
11 11
12include disable-common.inc 12include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
diff --git a/etc/profile-a-l/kiwix-desktop.profile b/etc/profile-a-l/kiwix-desktop.profile
index 40ee0bbc7..b188ba0e3 100644
--- a/etc/profile-a-l/kiwix-desktop.profile
+++ b/etc/profile-a-l/kiwix-desktop.profile
@@ -6,8 +6,8 @@ include kiwix-desktop.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.local/share/kiwix 9nodeny ${HOME}/.local/share/kiwix
10noblacklist ${HOME}/.local/share/kiwix-desktop 10nodeny ${HOME}/.local/share/kiwix-desktop
11 11
12include disable-common.inc 12include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
@@ -19,8 +19,8 @@ include disable-xdg.inc
19 19
20mkdir ${HOME}/.local/share/kiwix 20mkdir ${HOME}/.local/share/kiwix
21mkdir ${HOME}/.local/share/kiwix-desktop 21mkdir ${HOME}/.local/share/kiwix-desktop
22whitelist ${HOME}/.local/share/kiwix 22allow ${HOME}/.local/share/kiwix
23whitelist ${HOME}/.local/share/kiwix-desktop 23allow ${HOME}/.local/share/kiwix-desktop
24include whitelist-common.inc 24include whitelist-common.inc
25include whitelist-var-common.inc 25include whitelist-var-common.inc
26 26
diff --git a/etc/profile-a-l/klatexformula.profile b/etc/profile-a-l/klatexformula.profile
index c6a9023f1..e087e4973 100644
--- a/etc/profile-a-l/klatexformula.profile
+++ b/etc/profile-a-l/klatexformula.profile
@@ -6,8 +6,8 @@ include klatexformula.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.kde/share/apps/klatexformula 9nodeny ${HOME}/.kde/share/apps/klatexformula
10noblacklist ${HOME}/.klatexformula 10nodeny ${HOME}/.klatexformula
11 11
12# Allow python (blacklisted by disable-interpreters.inc) 12# Allow python (blacklisted by disable-interpreters.inc)
13include allow-python2.inc 13include allow-python2.inc
diff --git a/etc/profile-a-l/klavaro.profile b/etc/profile-a-l/klavaro.profile
index f5cd3a48c..ec3912419 100644
--- a/etc/profile-a-l/klavaro.profile
+++ b/etc/profile-a-l/klavaro.profile
@@ -6,8 +6,8 @@ include klavaro.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/klavaro 9nodeny ${HOME}/.config/klavaro
10noblacklist ${HOME}/.local/share/klavaro 10nodeny ${HOME}/.local/share/klavaro
11 11
12include disable-common.inc 12include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
@@ -19,8 +19,8 @@ include disable-xdg.inc
19 19
20mkdir ${HOME}/.local/share/klavaro 20mkdir ${HOME}/.local/share/klavaro
21mkdir ${HOME}/.config/klavaro 21mkdir ${HOME}/.config/klavaro
22whitelist ${HOME}/.local/share/klavaro 22allow ${HOME}/.local/share/klavaro
23whitelist ${HOME}/.config/klavaro 23allow ${HOME}/.config/klavaro
24include whitelist-common.inc 24include whitelist-common.inc
25include whitelist-var-common.inc 25include whitelist-var-common.inc
26 26
diff --git a/etc/profile-a-l/kmail.profile b/etc/profile-a-l/kmail.profile
index 95ae98e53..3c582c08c 100644
--- a/etc/profile-a-l/kmail.profile
+++ b/etc/profile-a-l/kmail.profile
@@ -9,27 +9,27 @@ include globals.local
9# kmail has problems launching akonadi in debian and ubuntu. 9# kmail has problems launching akonadi in debian and ubuntu.
10# one solution is to have akonadi already running when kmail is started 10# one solution is to have akonadi already running when kmail is started
11 11
12noblacklist ${HOME}/.cache/akonadi* 12nodeny ${HOME}/.cache/akonadi*
13noblacklist ${HOME}/.cache/kmail2 13nodeny ${HOME}/.cache/kmail2
14noblacklist ${HOME}/.config/akonadi* 14nodeny ${HOME}/.config/akonadi*
15noblacklist ${HOME}/.config/baloorc 15nodeny ${HOME}/.config/baloorc
16noblacklist ${HOME}/.config/emaildefaults 16nodeny ${HOME}/.config/emaildefaults
17noblacklist ${HOME}/.config/emailidentities 17nodeny ${HOME}/.config/emailidentities
18noblacklist ${HOME}/.config/kmail2rc 18nodeny ${HOME}/.config/kmail2rc
19noblacklist ${HOME}/.config/kmailsearchindexingrc 19nodeny ${HOME}/.config/kmailsearchindexingrc
20noblacklist ${HOME}/.config/mailtransports 20nodeny ${HOME}/.config/mailtransports
21noblacklist ${HOME}/.config/specialmailcollectionsrc 21nodeny ${HOME}/.config/specialmailcollectionsrc
22noblacklist ${HOME}/.gnupg 22nodeny ${HOME}/.gnupg
23noblacklist ${HOME}/.local/share/akonadi* 23nodeny ${HOME}/.local/share/akonadi*
24noblacklist ${HOME}/.local/share/apps/korganizer 24nodeny ${HOME}/.local/share/apps/korganizer
25noblacklist ${HOME}/.local/share/contacts 25nodeny ${HOME}/.local/share/contacts
26noblacklist ${HOME}/.local/share/emailidentities 26nodeny ${HOME}/.local/share/emailidentities
27noblacklist ${HOME}/.local/share/kmail2 27nodeny ${HOME}/.local/share/kmail2
28noblacklist ${HOME}/.local/share/kxmlgui5/kmail 28nodeny ${HOME}/.local/share/kxmlgui5/kmail
29noblacklist ${HOME}/.local/share/kxmlgui5/kmail2 29nodeny ${HOME}/.local/share/kxmlgui5/kmail2
30noblacklist ${HOME}/.local/share/local-mail 30nodeny ${HOME}/.local/share/local-mail
31noblacklist ${HOME}/.local/share/notes 31nodeny ${HOME}/.local/share/notes
32noblacklist /tmp/akonadi-* 32nodeny /tmp/akonadi-*
33 33
34include disable-common.inc 34include disable-common.inc
35include disable-devel.inc 35include disable-devel.inc
diff --git a/etc/profile-a-l/kmplayer.profile b/etc/profile-a-l/kmplayer.profile
index e88b53499..d2ce14ab6 100644
--- a/etc/profile-a-l/kmplayer.profile
+++ b/etc/profile-a-l/kmplayer.profile
@@ -6,11 +6,11 @@ include kmplayer.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/kmplayerrc 9nodeny ${HOME}/.config/kmplayerrc
10noblacklist ${HOME}/.kde/share/config/kmplayerrc 10nodeny ${HOME}/.kde/share/config/kmplayerrc
11noblacklist ${HOME}/.local/share/kmplayer 11nodeny ${HOME}/.local/share/kmplayer
12noblacklist ${MUSIC} 12nodeny ${MUSIC}
13noblacklist ${VIDEOS} 13nodeny ${VIDEOS}
14 14
15include disable-common.inc 15include disable-common.inc
16include disable-devel.inc 16include disable-devel.inc
diff --git a/etc/profile-a-l/knotes.profile b/etc/profile-a-l/knotes.profile
index f155d0ad6..5a9ac34da 100644
--- a/etc/profile-a-l/knotes.profile
+++ b/etc/profile-a-l/knotes.profile
@@ -10,9 +10,9 @@ include knotes.local
10# knotes has problems launching akonadi in debian and ubuntu. 10# knotes has problems launching akonadi in debian and ubuntu.
11# one solution is to have akonadi already running when knotes is started 11# one solution is to have akonadi already running when knotes is started
12 12
13noblacklist ${HOME}/.config/knotesrc 13nodeny ${HOME}/.config/knotesrc
14noblacklist ${HOME}/.local/share/knotes 14nodeny ${HOME}/.local/share/knotes
15noblacklist ${HOME}/.local/share/kxmlgui5/knotes 15nodeny ${HOME}/.local/share/kxmlgui5/knotes
16 16
17# Redirect 17# Redirect
18include kmail.profile 18include kmail.profile
diff --git a/etc/profile-a-l/kodi.profile b/etc/profile-a-l/kodi.profile
index b7091f1fc..2725c87be 100644
--- a/etc/profile-a-l/kodi.profile
+++ b/etc/profile-a-l/kodi.profile
@@ -13,10 +13,10 @@ ignore noexec ${HOME}
13#ignore noroot 13#ignore noroot
14#ignore private-dev 14#ignore private-dev
15 15
16noblacklist ${HOME}/.kodi 16nodeny ${HOME}/.kodi
17noblacklist ${MUSIC} 17nodeny ${MUSIC}
18noblacklist ${PICTURES} 18nodeny ${PICTURES}
19noblacklist ${VIDEOS} 19nodeny ${VIDEOS}
20 20
21# Allow python (blacklisted by disable-interpreters.inc) 21# Allow python (blacklisted by disable-interpreters.inc)
22include allow-python2.inc 22include allow-python2.inc
diff --git a/etc/profile-a-l/konversation.profile b/etc/profile-a-l/konversation.profile
index 5b5ed6e24..d8ce33838 100644
--- a/etc/profile-a-l/konversation.profile
+++ b/etc/profile-a-l/konversation.profile
@@ -6,11 +6,11 @@ include konversation.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/konversationrc 9nodeny ${HOME}/.config/konversationrc
10noblacklist ${HOME}/.config/konversation.notifyrc 10nodeny ${HOME}/.config/konversation.notifyrc
11noblacklist ${HOME}/.kde/share/config/konversationrc 11nodeny ${HOME}/.kde/share/config/konversationrc
12noblacklist ${HOME}/.kde4/share/config/konversationrc 12nodeny ${HOME}/.kde4/share/config/konversationrc
13noblacklist ${HOME}/.local/share/kxmlgui5/konversation 13nodeny ${HOME}/.local/share/kxmlgui5/konversation
14 14
15include disable-common.inc 15include disable-common.inc
16include disable-devel.inc 16include disable-devel.inc
diff --git a/etc/profile-a-l/kopete.profile b/etc/profile-a-l/kopete.profile
index 88f47d1bf..749591f32 100644
--- a/etc/profile-a-l/kopete.profile
+++ b/etc/profile-a-l/kopete.profile
@@ -6,11 +6,11 @@ include kopete.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.kde/share/apps/kopete 9nodeny ${HOME}/.kde/share/apps/kopete
10noblacklist ${HOME}/.kde/share/config/kopeterc 10nodeny ${HOME}/.kde/share/config/kopeterc
11noblacklist ${HOME}/.kde4/share/apps/kopete 11nodeny ${HOME}/.kde4/share/apps/kopete
12noblacklist ${HOME}/.kde4/share/config/kopeterc 12nodeny ${HOME}/.kde4/share/config/kopeterc
13noblacklist ${HOME}/.local/share/kxmlgui5/kopete 13nodeny ${HOME}/.local/share/kxmlgui5/kopete
14 14
15include disable-common.inc 15include disable-common.inc
16include disable-devel.inc 16include disable-devel.inc
@@ -19,7 +19,7 @@ include disable-interpreters.inc
19include disable-passwdmgr.inc 19include disable-passwdmgr.inc
20include disable-programs.inc 20include disable-programs.inc
21 21
22whitelist /var/lib/winpopup 22allow /var/lib/winpopup
23include whitelist-var-common.inc 23include whitelist-var-common.inc
24 24
25caps.drop all 25caps.drop all
diff --git a/etc/profile-a-l/krita.profile b/etc/profile-a-l/krita.profile
index 8604e63d0..950341def 100644
--- a/etc/profile-a-l/krita.profile
+++ b/etc/profile-a-l/krita.profile
@@ -9,10 +9,10 @@ include globals.local
9# noexec ${HOME} may break krita, see issue #1953 9# noexec ${HOME} may break krita, see issue #1953
10ignore noexec ${HOME} 10ignore noexec ${HOME}
11 11
12noblacklist ${HOME}/.config/kritarc 12nodeny ${HOME}/.config/kritarc
13noblacklist ${HOME}/.local/share/krita 13nodeny ${HOME}/.local/share/krita
14noblacklist ${DOCUMENTS} 14nodeny ${DOCUMENTS}
15noblacklist ${PICTURES} 15nodeny ${PICTURES}
16 16
17# Allow python (blacklisted by disable-interpreters.inc) 17# Allow python (blacklisted by disable-interpreters.inc)
18include allow-python2.inc 18include allow-python2.inc
diff --git a/etc/profile-a-l/krunner.profile b/etc/profile-a-l/krunner.profile
index 9cb5eff87..7b325d273 100644
--- a/etc/profile-a-l/krunner.profile
+++ b/etc/profile-a-l/krunner.profile
@@ -13,9 +13,9 @@ include globals.local
13# noblacklist ${HOME}/.cache/krunner 13# noblacklist ${HOME}/.cache/krunner
14# noblacklist ${HOME}/.cache/krunnerbookmarkrunnerfirefoxdbfile.sqlite* 14# noblacklist ${HOME}/.cache/krunnerbookmarkrunnerfirefoxdbfile.sqlite*
15# noblacklist ${HOME}/.config/chromium 15# noblacklist ${HOME}/.config/chromium
16noblacklist ${HOME}/.config/krunnerrc 16nodeny ${HOME}/.config/krunnerrc
17noblacklist ${HOME}/.kde/share/config/krunnerrc 17nodeny ${HOME}/.kde/share/config/krunnerrc
18noblacklist ${HOME}/.kde4/share/config/krunnerrc 18nodeny ${HOME}/.kde4/share/config/krunnerrc
19# noblacklist ${HOME}/.local/share/baloo 19# noblacklist ${HOME}/.local/share/baloo
20# noblacklist ${HOME}/.mozilla 20# noblacklist ${HOME}/.mozilla
21 21
diff --git a/etc/profile-a-l/ktorrent.profile b/etc/profile-a-l/ktorrent.profile
index 5a85194e0..ac9fee585 100644
--- a/etc/profile-a-l/ktorrent.profile
+++ b/etc/profile-a-l/ktorrent.profile
@@ -6,13 +6,13 @@ include ktorrent.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/ktorrentrc 9nodeny ${HOME}/.config/ktorrentrc
10noblacklist ${HOME}/.kde/share/apps/ktorrent 10nodeny ${HOME}/.kde/share/apps/ktorrent
11noblacklist ${HOME}/.kde/share/config/ktorrentrc 11nodeny ${HOME}/.kde/share/config/ktorrentrc
12noblacklist ${HOME}/.kde4/share/apps/ktorrent 12nodeny ${HOME}/.kde4/share/apps/ktorrent
13noblacklist ${HOME}/.kde4/share/config/ktorrentrc 13nodeny ${HOME}/.kde4/share/config/ktorrentrc
14noblacklist ${HOME}/.local/share/ktorrent 14nodeny ${HOME}/.local/share/ktorrent
15noblacklist ${HOME}/.local/share/kxmlgui5/ktorrent 15nodeny ${HOME}/.local/share/kxmlgui5/ktorrent
16 16
17include disable-common.inc 17include disable-common.inc
18include disable-devel.inc 18include disable-devel.inc
@@ -29,14 +29,14 @@ mkdir ${HOME}/.local/share/kxmlgui5/ktorrent
29mkfile ${HOME}/.config/ktorrentrc 29mkfile ${HOME}/.config/ktorrentrc
30mkfile ${HOME}/.kde/share/config/ktorrentrc 30mkfile ${HOME}/.kde/share/config/ktorrentrc
31mkfile ${HOME}/.kde4/share/config/ktorrentrc 31mkfile ${HOME}/.kde4/share/config/ktorrentrc
32whitelist ${DOWNLOADS} 32allow ${DOWNLOADS}
33whitelist ${HOME}/.config/ktorrentrc 33allow ${HOME}/.config/ktorrentrc
34whitelist ${HOME}/.kde/share/apps/ktorrent 34allow ${HOME}/.kde/share/apps/ktorrent
35whitelist ${HOME}/.kde/share/config/ktorrentrc 35allow ${HOME}/.kde/share/config/ktorrentrc
36whitelist ${HOME}/.kde4/share/apps/ktorrent 36allow ${HOME}/.kde4/share/apps/ktorrent
37whitelist ${HOME}/.kde4/share/config/ktorrentrc 37allow ${HOME}/.kde4/share/config/ktorrentrc
38whitelist ${HOME}/.local/share/ktorrent 38allow ${HOME}/.local/share/ktorrent
39whitelist ${HOME}/.local/share/kxmlgui5/ktorrent 39allow ${HOME}/.local/share/kxmlgui5/ktorrent
40include whitelist-common.inc 40include whitelist-common.inc
41include whitelist-var-common.inc 41include whitelist-var-common.inc
42 42
diff --git a/etc/profile-a-l/ktouch.profile b/etc/profile-a-l/ktouch.profile
index 4cf72b74c..71f8e4977 100644
--- a/etc/profile-a-l/ktouch.profile
+++ b/etc/profile-a-l/ktouch.profile
@@ -6,8 +6,8 @@ include ktouch.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/ktouch2rc 9nodeny ${HOME}/.config/ktouch2rc
10noblacklist ${HOME}/.local/share/ktouch 10nodeny ${HOME}/.local/share/ktouch
11 11
12include disable-common.inc 12include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
@@ -20,8 +20,8 @@ include disable-xdg.inc
20 20
21mkfile ${HOME}/.config/ktouch2rc 21mkfile ${HOME}/.config/ktouch2rc
22mkdir ${HOME}/.local/share/ktouch 22mkdir ${HOME}/.local/share/ktouch
23whitelist ${HOME}/.config/ktouch2rc 23allow ${HOME}/.config/ktouch2rc
24whitelist ${HOME}/.local/share/ktouch 24allow ${HOME}/.local/share/ktouch
25include whitelist-common.inc 25include whitelist-common.inc
26include whitelist-var-common.inc 26include whitelist-var-common.inc
27 27
diff --git a/etc/profile-a-l/kube.profile b/etc/profile-a-l/kube.profile
index 4e9a12e5f..74ffd1162 100644
--- a/etc/profile-a-l/kube.profile
+++ b/etc/profile-a-l/kube.profile
@@ -6,13 +6,13 @@ include kube.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.gnupg 9nodeny ${HOME}/.gnupg
10noblacklist ${HOME}/.mozilla 10nodeny ${HOME}/.mozilla
11noblacklist ${HOME}/.cache/kube 11nodeny ${HOME}/.cache/kube
12noblacklist ${HOME}/.config/kube 12nodeny ${HOME}/.config/kube
13noblacklist ${HOME}/.config/sink 13nodeny ${HOME}/.config/sink
14noblacklist ${HOME}/.local/share/kube 14nodeny ${HOME}/.local/share/kube
15noblacklist ${HOME}/.local/share/sink 15nodeny ${HOME}/.local/share/sink
16 16
17include disable-common.inc 17include disable-common.inc
18include disable-devel.inc 18include disable-devel.inc
@@ -29,17 +29,17 @@ mkdir ${HOME}/.config/kube
29mkdir ${HOME}/.config/sink 29mkdir ${HOME}/.config/sink
30mkdir ${HOME}/.local/share/kube 30mkdir ${HOME}/.local/share/kube
31mkdir ${HOME}/.local/share/sink 31mkdir ${HOME}/.local/share/sink
32whitelist ${HOME}/.gnupg 32allow ${HOME}/.gnupg
33whitelist ${HOME}/.mozilla/firefox/profiles.ini 33allow ${HOME}/.mozilla/firefox/profiles.ini
34whitelist ${HOME}/.cache/kube 34allow ${HOME}/.cache/kube
35whitelist ${HOME}/.config/kube 35allow ${HOME}/.config/kube
36whitelist ${HOME}/.config/sink 36allow ${HOME}/.config/sink
37whitelist ${HOME}/.local/share/kube 37allow ${HOME}/.local/share/kube
38whitelist ${HOME}/.local/share/sink 38allow ${HOME}/.local/share/sink
39whitelist ${RUNUSER}/gnupg 39allow ${RUNUSER}/gnupg
40whitelist /usr/share/kube 40allow /usr/share/kube
41whitelist /usr/share/gnupg 41allow /usr/share/gnupg
42whitelist /usr/share/gnupg2 42allow /usr/share/gnupg2
43include whitelist-common.inc 43include whitelist-common.inc
44include whitelist-runuser-common.inc 44include whitelist-runuser-common.inc
45include whitelist-usr-share-common.inc 45include whitelist-usr-share-common.inc
diff --git a/etc/profile-a-l/kwin_x11.profile b/etc/profile-a-l/kwin_x11.profile
index 15e7ceb17..580f93736 100644
--- a/etc/profile-a-l/kwin_x11.profile
+++ b/etc/profile-a-l/kwin_x11.profile
@@ -8,10 +8,10 @@ include globals.local
8# fix automatical kwin_x11 sandboxing: 8# fix automatical kwin_x11 sandboxing:
9# echo KDEWM=kwin_x11 >> ~/.pam_environment 9# echo KDEWM=kwin_x11 >> ~/.pam_environment
10 10
11noblacklist ${HOME}/.cache/kwin 11nodeny ${HOME}/.cache/kwin
12noblacklist ${HOME}/.config/kwinrc 12nodeny ${HOME}/.config/kwinrc
13noblacklist ${HOME}/.config/kwinrulesrc 13nodeny ${HOME}/.config/kwinrulesrc
14noblacklist ${HOME}/.local/share/kwin 14nodeny ${HOME}/.local/share/kwin
15 15
16include disable-common.inc 16include disable-common.inc
17include disable-devel.inc 17include disable-devel.inc
diff --git a/etc/profile-a-l/kwrite.profile b/etc/profile-a-l/kwrite.profile
index 804ffafeb..08b0e0224 100644
--- a/etc/profile-a-l/kwrite.profile
+++ b/etc/profile-a-l/kwrite.profile
@@ -6,15 +6,15 @@ include kwrite.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/katepartrc 9nodeny ${HOME}/.config/katepartrc
10noblacklist ${HOME}/.config/katerc 10nodeny ${HOME}/.config/katerc
11noblacklist ${HOME}/.config/kateschemarc 11nodeny ${HOME}/.config/kateschemarc
12noblacklist ${HOME}/.config/katesyntaxhighlightingrc 12nodeny ${HOME}/.config/katesyntaxhighlightingrc
13noblacklist ${HOME}/.config/katevirc 13nodeny ${HOME}/.config/katevirc
14noblacklist ${HOME}/.config/kwriterc 14nodeny ${HOME}/.config/kwriterc
15noblacklist ${HOME}/.local/share/kwrite 15nodeny ${HOME}/.local/share/kwrite
16noblacklist ${HOME}/.local/share/kxmlgui5/kwrite 16nodeny ${HOME}/.local/share/kxmlgui5/kwrite
17noblacklist ${DOCUMENTS} 17nodeny ${DOCUMENTS}
18 18
19include disable-common.inc 19include disable-common.inc
20include disable-devel.inc 20include disable-devel.inc
diff --git a/etc/profile-a-l/latex-common.profile b/etc/profile-a-l/latex-common.profile
index ac1b8785d..91693bfc1 100644
--- a/etc/profile-a-l/latex-common.profile
+++ b/etc/profile-a-l/latex-common.profile
@@ -13,7 +13,7 @@ include disable-interpreters.inc
13include disable-passwdmgr.inc 13include disable-passwdmgr.inc
14include disable-programs.inc 14include disable-programs.inc
15 15
16whitelist /var/lib 16allow /var/lib
17include whitelist-runuser-common.inc 17include whitelist-runuser-common.inc
18include whitelist-var-common.inc 18include whitelist-var-common.inc
19 19
diff --git a/etc/profile-a-l/leafpad.profile b/etc/profile-a-l/leafpad.profile
index 4bbb0a86d..e154708eb 100644
--- a/etc/profile-a-l/leafpad.profile
+++ b/etc/profile-a-l/leafpad.profile
@@ -6,7 +6,7 @@ include leafpad.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/leafpad 9nodeny ${HOME}/.config/leafpad
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
diff --git a/etc/profile-a-l/less.profile b/etc/profile-a-l/less.profile
index 8eb5ad0c2..abee392de 100644
--- a/etc/profile-a-l/less.profile
+++ b/etc/profile-a-l/less.profile
@@ -7,9 +7,9 @@ include less.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10blacklist ${RUNUSER} 10deny ${RUNUSER}
11 11
12noblacklist ${HOME}/.lesshst 12nodeny ${HOME}/.lesshst
13 13
14include disable-devel.inc 14include disable-devel.inc
15include disable-exec.inc 15include disable-exec.inc
diff --git a/etc/profile-a-l/librecad.profile b/etc/profile-a-l/librecad.profile
index c57eae73d..8ec41eee3 100644
--- a/etc/profile-a-l/librecad.profile
+++ b/etc/profile-a-l/librecad.profile
@@ -4,8 +4,8 @@ include librecad.local
4# Persistent global definitions 4# Persistent global definitions
5include globals.local 5include globals.local
6 6
7noblacklist ${HOME}/.config/LibreCAD 7nodeny ${HOME}/.config/LibreCAD
8noblacklist ${HOME}/.local/share/LibreCAD 8nodeny ${HOME}/.local/share/LibreCAD
9 9
10include disable-common.inc 10include disable-common.inc
11include disable-devel.inc 11include disable-devel.inc
@@ -16,7 +16,7 @@ include disable-programs.inc
16include disable-shell.inc 16include disable-shell.inc
17include disable-xdg.inc 17include disable-xdg.inc
18 18
19whitelist /usr/share/librecad 19allow /usr/share/librecad
20include whitelist-usr-share-common.inc 20include whitelist-usr-share-common.inc
21include whitelist-var-common.inc 21include whitelist-var-common.inc
22 22
diff --git a/etc/profile-a-l/libreoffice.profile b/etc/profile-a-l/libreoffice.profile
index b1a24888c..ae01d39b8 100644
--- a/etc/profile-a-l/libreoffice.profile
+++ b/etc/profile-a-l/libreoffice.profile
@@ -6,15 +6,15 @@ include libreoffice.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist /usr/local/sbin 9nodeny /usr/local/sbin
10noblacklist ${HOME}/.config/libreoffice 10nodeny ${HOME}/.config/libreoffice
11 11
12# libreoffice uses java for some functionality. 12# libreoffice uses java for some functionality.
13# Add 'ignore include allow-java.inc' to your libreoffice.local if you don't need that functionality. 13# Add 'ignore include allow-java.inc' to your libreoffice.local if you don't need that functionality.
14# Allow java (blacklisted by disable-devel.inc) 14# Allow java (blacklisted by disable-devel.inc)
15include allow-java.inc 15include allow-java.inc
16 16
17blacklist /usr/libexec 17deny /usr/libexec
18 18
19include disable-common.inc 19include disable-common.inc
20include disable-devel.inc 20include disable-devel.inc
diff --git a/etc/profile-a-l/librewolf.profile b/etc/profile-a-l/librewolf.profile
index da047357a..5c614ab8e 100644
--- a/etc/profile-a-l/librewolf.profile
+++ b/etc/profile-a-l/librewolf.profile
@@ -6,13 +6,13 @@ include librewolf.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.cache/librewolf 9nodeny ${HOME}/.cache/librewolf
10noblacklist ${HOME}/.librewolf 10nodeny ${HOME}/.librewolf
11 11
12mkdir ${HOME}/.cache/librewolf 12mkdir ${HOME}/.cache/librewolf
13mkdir ${HOME}/.librewolf 13mkdir ${HOME}/.librewolf
14whitelist ${HOME}/.cache/librewolf 14allow ${HOME}/.cache/librewolf
15whitelist ${HOME}/.librewolf 15allow ${HOME}/.librewolf
16 16
17# Add the next lines to your librewolf.local if you want to use the migration wizard. 17# Add the next lines to your librewolf.local if you want to use the migration wizard.
18#noblacklist ${HOME}/.mozilla 18#noblacklist ${HOME}/.mozilla
@@ -23,10 +23,10 @@ whitelist ${HOME}/.librewolf
23#whitelist ${RUNUSER}/kpxc_server 23#whitelist ${RUNUSER}/kpxc_server
24#whitelist ${RUNUSER}/org.keepassxc.KeePassXC.BrowserServer 24#whitelist ${RUNUSER}/org.keepassxc.KeePassXC.BrowserServer
25 25
26whitelist /usr/share/doc 26allow /usr/share/doc
27whitelist /usr/share/gtk-doc/html 27allow /usr/share/gtk-doc/html
28whitelist /usr/share/mozilla 28allow /usr/share/mozilla
29whitelist /usr/share/webext 29allow /usr/share/webext
30include whitelist-usr-share-common.inc 30include whitelist-usr-share-common.inc
31 31
32# Add the next line to your librewolf.local to enable private-bin (Arch Linux). 32# Add the next line to your librewolf.local to enable private-bin (Arch Linux).
diff --git a/etc/profile-a-l/liferea.profile b/etc/profile-a-l/liferea.profile
index 7afca1d5f..595ecc257 100644
--- a/etc/profile-a-l/liferea.profile
+++ b/etc/profile-a-l/liferea.profile
@@ -6,9 +6,9 @@ include liferea.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.cache/liferea 9nodeny ${HOME}/.cache/liferea
10noblacklist ${HOME}/.config/liferea 10nodeny ${HOME}/.config/liferea
11noblacklist ${HOME}/.local/share/liferea 11nodeny ${HOME}/.local/share/liferea
12 12
13# Allow python (blacklisted by disable-interpreters.inc) 13# Allow python (blacklisted by disable-interpreters.inc)
14include allow-python2.inc 14include allow-python2.inc
@@ -24,10 +24,10 @@ include disable-programs.inc
24mkdir ${HOME}/.cache/liferea 24mkdir ${HOME}/.cache/liferea
25mkdir ${HOME}/.config/liferea 25mkdir ${HOME}/.config/liferea
26mkdir ${HOME}/.local/share/liferea 26mkdir ${HOME}/.local/share/liferea
27whitelist ${HOME}/.cache/liferea 27allow ${HOME}/.cache/liferea
28whitelist ${HOME}/.config/liferea 28allow ${HOME}/.config/liferea
29whitelist ${HOME}/.local/share/liferea 29allow ${HOME}/.local/share/liferea
30whitelist /usr/share/liferea 30allow /usr/share/liferea
31include whitelist-common.inc 31include whitelist-common.inc
32include whitelist-usr-share-common.inc 32include whitelist-usr-share-common.inc
33include whitelist-var-common.inc 33include whitelist-var-common.inc
diff --git a/etc/profile-a-l/lightsoff.profile b/etc/profile-a-l/lightsoff.profile
index c065c44a9..58d5bcd6d 100644
--- a/etc/profile-a-l/lightsoff.profile
+++ b/etc/profile-a-l/lightsoff.profile
@@ -6,7 +6,7 @@ include lightsoff.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9whitelist /usr/share/lightsoff 9allow /usr/share/lightsoff
10 10
11private-bin lightsoff 11private-bin lightsoff
12 12
diff --git a/etc/profile-a-l/lincity-ng.profile b/etc/profile-a-l/lincity-ng.profile
index 4254b7f33..e14c50d77 100644
--- a/etc/profile-a-l/lincity-ng.profile
+++ b/etc/profile-a-l/lincity-ng.profile
@@ -6,7 +6,7 @@ include lincity-ng.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.lincity-ng 9nodeny ${HOME}/.lincity-ng
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -18,7 +18,7 @@ include disable-shell.inc
18include disable-xdg.inc 18include disable-xdg.inc
19 19
20mkdir ${HOME}/.lincity-ng 20mkdir ${HOME}/.lincity-ng
21whitelist ${HOME}/.lincity-ng 21allow ${HOME}/.lincity-ng
22include whitelist-common.inc 22include whitelist-common.inc
23include whitelist-var-common.inc 23include whitelist-var-common.inc
24 24
diff --git a/etc/profile-a-l/links-common.profile b/etc/profile-a-l/links-common.profile
index cd885b1d4..51e3d5b94 100644
--- a/etc/profile-a-l/links-common.profile
+++ b/etc/profile-a-l/links-common.profile
@@ -4,8 +4,8 @@ include links-common.local
4 4
5# common profile for links browsers 5# common profile for links browsers
6 6
7blacklist /tmp/.X11-unix 7deny /tmp/.X11-unix
8blacklist ${RUNUSER}/wayland-* 8deny ${RUNUSER}/wayland-*
9 9
10include disable-common.inc 10include disable-common.inc
11include disable-devel.inc 11include disable-devel.inc
@@ -17,7 +17,7 @@ include disable-passwdmgr.inc
17include disable-programs.inc 17include disable-programs.inc
18include disable-xdg.inc 18include disable-xdg.inc
19 19
20whitelist ${DOWNLOADS} 20allow ${DOWNLOADS}
21include whitelist-runuser-common.inc 21include whitelist-runuser-common.inc
22include whitelist-usr-share-common.inc 22include whitelist-usr-share-common.inc
23include whitelist-var-common.inc 23include whitelist-var-common.inc
diff --git a/etc/profile-a-l/links.profile b/etc/profile-a-l/links.profile
index 8ce39cc7f..ae57601ca 100644
--- a/etc/profile-a-l/links.profile
+++ b/etc/profile-a-l/links.profile
@@ -7,10 +7,10 @@ include links.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10noblacklist ${HOME}/.links 10nodeny ${HOME}/.links
11 11
12mkdir ${HOME}/.links 12mkdir ${HOME}/.links
13whitelist ${HOME}/.links 13allow ${HOME}/.links
14 14
15private-bin links 15private-bin links
16 16
diff --git a/etc/profile-a-l/links2.profile b/etc/profile-a-l/links2.profile
index 5f91dfcd2..eb349c73a 100644
--- a/etc/profile-a-l/links2.profile
+++ b/etc/profile-a-l/links2.profile
@@ -7,10 +7,10 @@ include links2.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10noblacklist ${HOME}/.links2 10nodeny ${HOME}/.links2
11 11
12mkdir ${HOME}/.links2 12mkdir ${HOME}/.links2
13whitelist ${HOME}/.links2 13allow ${HOME}/.links2
14 14
15private-bin links2 15private-bin links2
16 16
diff --git a/etc/profile-a-l/linphone.profile b/etc/profile-a-l/linphone.profile
index 7ebdbef4c..dd1dac05b 100644
--- a/etc/profile-a-l/linphone.profile
+++ b/etc/profile-a-l/linphone.profile
@@ -6,10 +6,10 @@ include linphone.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/linphone 9nodeny ${HOME}/.config/linphone
10noblacklist ${HOME}/.linphone-history.db 10nodeny ${HOME}/.linphone-history.db
11noblacklist ${HOME}/.linphonerc 11nodeny ${HOME}/.linphonerc
12noblacklist ${HOME}/.local/share/linphone 12nodeny ${HOME}/.local/share/linphone
13 13
14include disable-common.inc 14include disable-common.inc
15include disable-devel.inc 15include disable-devel.inc
@@ -23,11 +23,11 @@ include disable-programs.inc
23# ${HOME}/.linphone-history.db and ${HOME}/.linphonerc but no longer mkfile. 23# ${HOME}/.linphone-history.db and ${HOME}/.linphonerc but no longer mkfile.
24mkdir ${HOME}/.config/linphone 24mkdir ${HOME}/.config/linphone
25mkdir ${HOME}/.local/share/linphone 25mkdir ${HOME}/.local/share/linphone
26whitelist ${HOME}/.config/linphone 26allow ${HOME}/.config/linphone
27whitelist ${HOME}/.linphone-history.db 27allow ${HOME}/.linphone-history.db
28whitelist ${HOME}/.linphonerc 28allow ${HOME}/.linphonerc
29whitelist ${HOME}/.local/share/linphone 29allow ${HOME}/.local/share/linphone
30whitelist ${DOWNLOADS} 30allow ${DOWNLOADS}
31include whitelist-common.inc 31include whitelist-common.inc
32 32
33caps.drop all 33caps.drop all
diff --git a/etc/profile-a-l/lmms.profile b/etc/profile-a-l/lmms.profile
index 48b0e14dc..b22110fdc 100644
--- a/etc/profile-a-l/lmms.profile
+++ b/etc/profile-a-l/lmms.profile
@@ -6,9 +6,9 @@ include lmms.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.lmmsrc.xml 9nodeny ${HOME}/.lmmsrc.xml
10noblacklist ${DOCUMENTS} 10nodeny ${DOCUMENTS}
11noblacklist ${MUSIC} 11nodeny ${MUSIC}
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
diff --git a/etc/profile-a-l/lollypop.profile b/etc/profile-a-l/lollypop.profile
index f2676fec5..0a7ce86e8 100644
--- a/etc/profile-a-l/lollypop.profile
+++ b/etc/profile-a-l/lollypop.profile
@@ -6,8 +6,8 @@ include lollypop.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.local/share/lollypop 9nodeny ${HOME}/.local/share/lollypop
10noblacklist ${MUSIC} 10nodeny ${MUSIC}
11 11
12# Allow python (blacklisted by disable-interpreters.inc) 12# Allow python (blacklisted by disable-interpreters.inc)
13include allow-python2.inc 13include allow-python2.inc
diff --git a/etc/profile-a-l/lugaru.profile b/etc/profile-a-l/lugaru.profile
index 174c65a65..30802b3b7 100644
--- a/etc/profile-a-l/lugaru.profile
+++ b/etc/profile-a-l/lugaru.profile
@@ -8,8 +8,8 @@ include globals.local
8 8
9# note: crashes after entering 9# note: crashes after entering
10 10
11noblacklist ${HOME}/.config/lugaru 11nodeny ${HOME}/.config/lugaru
12noblacklist ${HOME}/.local/share/lugaru 12nodeny ${HOME}/.local/share/lugaru
13 13
14include disable-common.inc 14include disable-common.inc
15include disable-devel.inc 15include disable-devel.inc
@@ -22,8 +22,8 @@ include disable-xdg.inc
22 22
23mkdir ${HOME}/.config/lugaru 23mkdir ${HOME}/.config/lugaru
24mkdir ${HOME}/.local/share/lugaru 24mkdir ${HOME}/.local/share/lugaru
25whitelist ${HOME}/.config/lugaru 25allow ${HOME}/.config/lugaru
26whitelist ${HOME}/.local/share/lugaru 26allow ${HOME}/.local/share/lugaru
27include whitelist-common.inc 27include whitelist-common.inc
28include whitelist-var-common.inc 28include whitelist-var-common.inc
29 29
diff --git a/etc/profile-a-l/luminance-hdr.profile b/etc/profile-a-l/luminance-hdr.profile
index 31067034e..73400dbd6 100644
--- a/etc/profile-a-l/luminance-hdr.profile
+++ b/etc/profile-a-l/luminance-hdr.profile
@@ -6,8 +6,8 @@ include luminance-hdr.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/Luminance 9nodeny ${HOME}/.config/Luminance
10noblacklist ${PICTURES} 10nodeny ${PICTURES}
11 11
12include disable-common.inc 12include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
diff --git a/etc/profile-a-l/lutris.profile b/etc/profile-a-l/lutris.profile
index 80a3aba86..9d5169b80 100644
--- a/etc/profile-a-l/lutris.profile
+++ b/etc/profile-a-l/lutris.profile
@@ -6,18 +6,18 @@ include lutris.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${PATH}/llvm* 9nodeny ${PATH}/llvm*
10noblacklist ${HOME}/Games 10nodeny ${HOME}/Games
11noblacklist ${HOME}/.cache/lutris 11nodeny ${HOME}/.cache/lutris
12noblacklist ${HOME}/.cache/winetricks 12nodeny ${HOME}/.cache/winetricks
13noblacklist ${HOME}/.config/lutris 13nodeny ${HOME}/.config/lutris
14noblacklist ${HOME}/.local/share/lutris 14nodeny ${HOME}/.local/share/lutris
15# noblacklist ${HOME}/.wine 15# noblacklist ${HOME}/.wine
16noblacklist /tmp/.wine-* 16nodeny /tmp/.wine-*
17# Don't block access to /sbin and /usr/sbin to allow using ldconfig. Otherwise 17# Don't block access to /sbin and /usr/sbin to allow using ldconfig. Otherwise
18# Lutris won't even start. 18# Lutris won't even start.
19noblacklist /sbin 19nodeny /sbin
20noblacklist /usr/sbin 20nodeny /usr/sbin
21 21
22ignore noexec ${HOME} 22ignore noexec ${HOME}
23 23
@@ -39,15 +39,15 @@ mkdir ${HOME}/.cache/winetricks
39mkdir ${HOME}/.config/lutris 39mkdir ${HOME}/.config/lutris
40mkdir ${HOME}/.local/share/lutris 40mkdir ${HOME}/.local/share/lutris
41# mkdir ${HOME}/.wine 41# mkdir ${HOME}/.wine
42whitelist ${DOWNLOADS} 42allow ${DOWNLOADS}
43whitelist ${HOME}/Games 43allow ${HOME}/Games
44whitelist ${HOME}/.cache/lutris 44allow ${HOME}/.cache/lutris
45whitelist ${HOME}/.cache/winetricks 45allow ${HOME}/.cache/winetricks
46whitelist ${HOME}/.config/lutris 46allow ${HOME}/.config/lutris
47whitelist ${HOME}/.local/share/lutris 47allow ${HOME}/.local/share/lutris
48# whitelist ${HOME}/.wine 48# whitelist ${HOME}/.wine
49whitelist /usr/share/lutris 49allow /usr/share/lutris
50whitelist /usr/share/wine 50allow /usr/share/wine
51include whitelist-common.inc 51include whitelist-common.inc
52include whitelist-usr-share-common.inc 52include whitelist-usr-share-common.inc
53include whitelist-runuser-common.inc 53include whitelist-runuser-common.inc
diff --git a/etc/profile-a-l/lximage-qt.profile b/etc/profile-a-l/lximage-qt.profile
index b2a56012e..43147211b 100644
--- a/etc/profile-a-l/lximage-qt.profile
+++ b/etc/profile-a-l/lximage-qt.profile
@@ -6,7 +6,7 @@ include lximage-qt.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/lximage-qt 9nodeny ${HOME}/.config/lximage-qt
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
diff --git a/etc/profile-a-l/lxmusic.profile b/etc/profile-a-l/lxmusic.profile
index cc4b95551..c849f2ad2 100644
--- a/etc/profile-a-l/lxmusic.profile
+++ b/etc/profile-a-l/lxmusic.profile
@@ -6,9 +6,9 @@ include lxmusic.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.cache/xmms2 9nodeny ${HOME}/.cache/xmms2
10noblacklist ${HOME}/.config/xmms2 10nodeny ${HOME}/.config/xmms2
11noblacklist ${MUSIC} 11nodeny ${MUSIC}
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
diff --git a/etc/profile-a-l/lynx.profile b/etc/profile-a-l/lynx.profile
index a919e924b..15c8f1faa 100644
--- a/etc/profile-a-l/lynx.profile
+++ b/etc/profile-a-l/lynx.profile
@@ -7,8 +7,8 @@ include lynx.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10blacklist /tmp/.X11-unix 10deny /tmp/.X11-unix
11blacklist ${RUNUSER}/wayland-* 11deny ${RUNUSER}/wayland-*
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
diff --git a/etc/profile-a-l/lyx.profile b/etc/profile-a-l/lyx.profile
index fa69463d1..358dbf2f2 100644
--- a/etc/profile-a-l/lyx.profile
+++ b/etc/profile-a-l/lyx.profile
@@ -8,8 +8,8 @@ include globals.local
8 8
9ignore private-tmp 9ignore private-tmp
10 10
11noblacklist ${HOME}/.config/LyX 11nodeny ${HOME}/.config/LyX
12noblacklist ${HOME}/.lyx 12nodeny ${HOME}/.lyx
13 13
14# Allow lua (blacklisted by disable-interpreters.inc) 14# Allow lua (blacklisted by disable-interpreters.inc)
15include allow-lua.inc 15include allow-lua.inc
@@ -21,11 +21,11 @@ include allow-perl.inc
21include allow-python2.inc 21include allow-python2.inc
22include allow-python3.inc 22include allow-python3.inc
23 23
24whitelist /usr/share/lyx 24allow /usr/share/lyx
25whitelist /usr/share/texinfo 25allow /usr/share/texinfo
26whitelist /usr/share/texlive 26allow /usr/share/texlive
27whitelist /usr/share/texmf-dist 27allow /usr/share/texmf-dist
28whitelist /usr/share/tlpkg 28allow /usr/share/tlpkg
29include whitelist-usr-share-common.inc 29include whitelist-usr-share-common.inc
30 30
31apparmor 31apparmor
diff --git a/etc/profile-a-l/sway.profile b/etc/profile-a-l/sway.profile
index 4637419bf..3a4edcf69 100644
--- a/etc/profile-a-l/sway.profile
+++ b/etc/profile-a-l/sway.profile
@@ -7,9 +7,9 @@ include sway.local
7include globals.local 7include globals.local
8 8
9# all applications started in sway will run in this profile 9# all applications started in sway will run in this profile
10noblacklist ${HOME}/.config/sway 10nodeny ${HOME}/.config/sway
11# sway uses ~/.config/i3 as fallback if there is no ~/.config/sway 11# sway uses ~/.config/i3 as fallback if there is no ~/.config/sway
12noblacklist ${HOME}/.config/i3 12nodeny ${HOME}/.config/i3
13include disable-common.inc 13include disable-common.inc
14 14
15caps.drop all 15caps.drop all
diff --git a/etc/profile-m-z/Maelstrom.profile b/etc/profile-m-z/Maelstrom.profile
index 62d0a8b3a..e6c43007d 100644
--- a/etc/profile-m-z/Maelstrom.profile
+++ b/etc/profile-m-z/Maelstrom.profile
@@ -6,7 +6,7 @@ include Maelstrom.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist /var/lib/games/Maelstrom-Scores 9nodeny /var/lib/games/Maelstrom-Scores
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -17,7 +17,7 @@ include disable-programs.inc
17include disable-shell.inc 17include disable-shell.inc
18include disable-xdg.inc 18include disable-xdg.inc
19 19
20whitelist /var/lib/games 20allow /var/lib/games
21include whitelist-common.inc 21include whitelist-common.inc
22include whitelist-var-common.inc 22include whitelist-var-common.inc
23 23
diff --git a/etc/profile-m-z/Mathematica.profile b/etc/profile-m-z/Mathematica.profile
index c2734b1c1..bd929d21a 100644
--- a/etc/profile-m-z/Mathematica.profile
+++ b/etc/profile-m-z/Mathematica.profile
@@ -5,8 +5,8 @@ include Mathematica.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${HOME}/.Mathematica 8nodeny ${HOME}/.Mathematica
9noblacklist ${HOME}/.Wolfram Research 9nodeny ${HOME}/.Wolfram Research
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -17,9 +17,9 @@ include disable-programs.inc
17mkdir ${HOME}/.Mathematica 17mkdir ${HOME}/.Mathematica
18mkdir ${HOME}/.Wolfram Research 18mkdir ${HOME}/.Wolfram Research
19mkdir ${HOME}/Documents/Wolfram Mathematica 19mkdir ${HOME}/Documents/Wolfram Mathematica
20whitelist ${HOME}/.Mathematica 20allow ${HOME}/.Mathematica
21whitelist ${HOME}/.Wolfram Research 21allow ${HOME}/.Wolfram Research
22whitelist ${HOME}/Documents/Wolfram Mathematica 22allow ${HOME}/Documents/Wolfram Mathematica
23include whitelist-common.inc 23include whitelist-common.inc
24 24
25caps.drop all 25caps.drop all
diff --git a/etc/profile-m-z/PCSX2.profile b/etc/profile-m-z/PCSX2.profile
index e678b7204..f833b9446 100644
--- a/etc/profile-m-z/PCSX2.profile
+++ b/etc/profile-m-z/PCSX2.profile
@@ -8,7 +8,7 @@ include globals.local
8 8
9# Note: you must whitelist your games folder in your PCSX2.local. 9# Note: you must whitelist your games folder in your PCSX2.local.
10 10
11noblacklist ${HOME}/.config/PCSX2 11nodeny ${HOME}/.config/PCSX2
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
@@ -21,7 +21,7 @@ include disable-write-mnt.inc
21include disable-xdg.inc 21include disable-xdg.inc
22 22
23mkdir ${HOME}/.config/PCSX2 23mkdir ${HOME}/.config/PCSX2
24whitelist ${HOME}/.config/PCSX2 24allow ${HOME}/.config/PCSX2
25include whitelist-common.inc 25include whitelist-common.inc
26include whitelist-runuser-common.inc 26include whitelist-runuser-common.inc
27include whitelist-usr-share-common.inc 27include whitelist-usr-share-common.inc
diff --git a/etc/profile-m-z/QMediathekView.profile b/etc/profile-m-z/QMediathekView.profile
index 86120587b..d7b01fe06 100644
--- a/etc/profile-m-z/QMediathekView.profile
+++ b/etc/profile-m-z/QMediathekView.profile
@@ -6,18 +6,18 @@ include QMediathekView.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/QMediathekView 9nodeny ${HOME}/.config/QMediathekView
10noblacklist ${HOME}/.local/share/QMediathekView 10nodeny ${HOME}/.local/share/QMediathekView
11 11
12noblacklist ${HOME}/.config/mpv 12nodeny ${HOME}/.config/mpv
13noblacklist ${HOME}/.config/smplayer 13nodeny ${HOME}/.config/smplayer
14noblacklist ${HOME}/.config/totem 14nodeny ${HOME}/.config/totem
15noblacklist ${HOME}/.config/vlc 15nodeny ${HOME}/.config/vlc
16noblacklist ${HOME}/.config/xplayer 16nodeny ${HOME}/.config/xplayer
17noblacklist ${HOME}/.local/share/totem 17nodeny ${HOME}/.local/share/totem
18noblacklist ${HOME}/.local/share/xplayer 18nodeny ${HOME}/.local/share/xplayer
19noblacklist ${HOME}/.mplayer 19nodeny ${HOME}/.mplayer
20noblacklist ${VIDEOS} 20nodeny ${VIDEOS}
21 21
22include disable-common.inc 22include disable-common.inc
23include disable-devel.inc 23include disable-devel.inc
@@ -28,7 +28,7 @@ include disable-programs.inc
28include disable-shell.inc 28include disable-shell.inc
29include disable-xdg.inc 29include disable-xdg.inc
30 30
31whitelist /usr/share/qtchooser 31allow /usr/share/qtchooser
32include whitelist-usr-share-common.inc 32include whitelist-usr-share-common.inc
33include whitelist-var-common.inc 33include whitelist-var-common.inc
34 34
diff --git a/etc/profile-m-z/QOwnNotes.profile b/etc/profile-m-z/QOwnNotes.profile
index 660378089..4ca42730a 100644
--- a/etc/profile-m-z/QOwnNotes.profile
+++ b/etc/profile-m-z/QOwnNotes.profile
@@ -6,10 +6,10 @@ include QOwnNotes.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${DOCUMENTS} 9nodeny ${DOCUMENTS}
10noblacklist ${HOME}/Nextcloud/Notes 10nodeny ${HOME}/Nextcloud/Notes
11noblacklist ${HOME}/.config/PBE 11nodeny ${HOME}/.config/PBE
12noblacklist ${HOME}/.local/share/PBE 12nodeny ${HOME}/.local/share/PBE
13 13
14include disable-common.inc 14include disable-common.inc
15include disable-devel.inc 15include disable-devel.inc
@@ -23,10 +23,10 @@ include disable-xdg.inc
23mkdir ${HOME}/Nextcloud/Notes 23mkdir ${HOME}/Nextcloud/Notes
24mkdir ${HOME}/.config/PBE 24mkdir ${HOME}/.config/PBE
25mkdir ${HOME}/.local/share/PBE 25mkdir ${HOME}/.local/share/PBE
26whitelist ${DOCUMENTS} 26allow ${DOCUMENTS}
27whitelist ${HOME}/Nextcloud/Notes 27allow ${HOME}/Nextcloud/Notes
28whitelist ${HOME}/.config/PBE 28allow ${HOME}/.config/PBE
29whitelist ${HOME}/.local/share/PBE 29allow ${HOME}/.local/share/PBE
30include whitelist-common.inc 30include whitelist-common.inc
31include whitelist-var-common.inc 31include whitelist-var-common.inc
32 32
diff --git a/etc/profile-m-z/Viber.profile b/etc/profile-m-z/Viber.profile
index 3195e39fa..b98847d3a 100644
--- a/etc/profile-m-z/Viber.profile
+++ b/etc/profile-m-z/Viber.profile
@@ -5,8 +5,8 @@ include Viber.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${HOME}/.ViberPC 8nodeny ${HOME}/.ViberPC
9noblacklist ${PATH}/dig 9nodeny ${PATH}/dig
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -16,8 +16,8 @@ include disable-passwdmgr.inc
16include disable-programs.inc 16include disable-programs.inc
17 17
18mkdir ${HOME}/.ViberPC 18mkdir ${HOME}/.ViberPC
19whitelist ${DOWNLOADS} 19allow ${DOWNLOADS}
20whitelist ${HOME}/.ViberPC 20allow ${HOME}/.ViberPC
21include whitelist-common.inc 21include whitelist-common.inc
22 22
23caps.drop all 23caps.drop all
diff --git a/etc/profile-m-z/XMind.profile b/etc/profile-m-z/XMind.profile
index d78e04595..c9cf7adf7 100644
--- a/etc/profile-m-z/XMind.profile
+++ b/etc/profile-m-z/XMind.profile
@@ -5,7 +5,7 @@ include XMind.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${HOME}/.xmind 8nodeny ${HOME}/.xmind
9 9
10include disable-common.inc 10include disable-common.inc
11include disable-devel.inc 11include disable-devel.inc
@@ -15,8 +15,8 @@ include disable-passwdmgr.inc
15include disable-programs.inc 15include disable-programs.inc
16 16
17mkdir ${HOME}/.xmind 17mkdir ${HOME}/.xmind
18whitelist ${HOME}/.xmind 18allow ${HOME}/.xmind
19whitelist ${DOWNLOADS} 19allow ${DOWNLOADS}
20include whitelist-common.inc 20include whitelist-common.inc
21 21
22caps.drop all 22caps.drop all
diff --git a/etc/profile-m-z/Xephyr.profile b/etc/profile-m-z/Xephyr.profile
index 5cf5161ce..7ba1cdac9 100644
--- a/etc/profile-m-z/Xephyr.profile
+++ b/etc/profile-m-z/Xephyr.profile
@@ -15,7 +15,7 @@ include globals.local
15# or run "sudo firecfg" 15# or run "sudo firecfg"
16# 16#
17 17
18whitelist /var/lib/xkb 18allow /var/lib/xkb
19include whitelist-common.inc 19include whitelist-common.inc
20 20
21caps.drop all 21caps.drop all
diff --git a/etc/profile-m-z/Xvfb.profile b/etc/profile-m-z/Xvfb.profile
index 1acd43023..a246ccb23 100644
--- a/etc/profile-m-z/Xvfb.profile
+++ b/etc/profile-m-z/Xvfb.profile
@@ -18,7 +18,7 @@ include globals.local
18# some Linux distributions. Also, older versions of Xpra use Xvfb. 18# some Linux distributions. Also, older versions of Xpra use Xvfb.
19# 19#
20 20
21whitelist /var/lib/xkb 21allow /var/lib/xkb
22include whitelist-common.inc 22include whitelist-common.inc
23 23
24caps.drop all 24caps.drop all
diff --git a/etc/profile-m-z/ZeGrapher.profile b/etc/profile-m-z/ZeGrapher.profile
index 7686c3442..4f65ad7d1 100644
--- a/etc/profile-m-z/ZeGrapher.profile
+++ b/etc/profile-m-z/ZeGrapher.profile
@@ -6,7 +6,7 @@ include ZeGrapher.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/ZeGrapher Project 9nodeny ${HOME}/.config/ZeGrapher Project
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -16,7 +16,7 @@ include disable-passwdmgr.inc
16include disable-programs.inc 16include disable-programs.inc
17include disable-shell.inc 17include disable-shell.inc
18 18
19whitelist /usr/share/ZeGrapher 19allow /usr/share/ZeGrapher
20include whitelist-runuser-common.inc 20include whitelist-runuser-common.inc
21include whitelist-usr-share-common.inc 21include whitelist-usr-share-common.inc
22include whitelist-var-common.inc 22include whitelist-var-common.inc
diff --git a/etc/profile-m-z/macrofusion.profile b/etc/profile-m-z/macrofusion.profile
index d1dcb6fe0..763d475bb 100644
--- a/etc/profile-m-z/macrofusion.profile
+++ b/etc/profile-m-z/macrofusion.profile
@@ -5,8 +5,8 @@ include macrofusion.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${HOME}/.config/mfusion 8nodeny ${HOME}/.config/mfusion
9noblacklist ${PICTURES} 9nodeny ${PICTURES}
10 10
11# Allow python (blacklisted by disable-interpreters.inc) 11# Allow python (blacklisted by disable-interpreters.inc)
12include allow-python2.inc 12include allow-python2.inc
diff --git a/etc/profile-m-z/magicor.profile b/etc/profile-m-z/magicor.profile
index 8a27b2626..d561a5095 100644
--- a/etc/profile-m-z/magicor.profile
+++ b/etc/profile-m-z/magicor.profile
@@ -6,7 +6,7 @@ include magicor.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.magicor 9nodeny ${HOME}/.magicor
10 10
11# Allow python (blacklisted by disable-interpreters.inc) 11# Allow python (blacklisted by disable-interpreters.inc)
12include allow-python2.inc 12include allow-python2.inc
@@ -21,8 +21,8 @@ include disable-shell.inc
21include disable-xdg.inc 21include disable-xdg.inc
22 22
23mkdir ${HOME}/.magicor 23mkdir ${HOME}/.magicor
24whitelist ${HOME}/.magicor 24allow ${HOME}/.magicor
25whitelist /usr/share/magicor 25allow /usr/share/magicor
26include whitelist-common.inc 26include whitelist-common.inc
27include whitelist-usr-share-common.inc 27include whitelist-usr-share-common.inc
28include whitelist-var-common.inc 28include whitelist-var-common.inc
diff --git a/etc/profile-m-z/makepkg.profile b/etc/profile-m-z/makepkg.profile
index 513fcae55..a7c486c9f 100644
--- a/etc/profile-m-z/makepkg.profile
+++ b/etc/profile-m-z/makepkg.profile
@@ -6,8 +6,8 @@ include makepkg.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9blacklist /tmp/.X11-unix 9deny /tmp/.X11-unix
10blacklist ${RUNUSER}/wayland-* 10deny ${RUNUSER}/wayland-*
11 11
12# Note: see this Arch forum discussion https://bbs.archlinux.org/viewtopic.php?pid=1743138 12# Note: see this Arch forum discussion https://bbs.archlinux.org/viewtopic.php?pid=1743138
13# for potential issues and their solutions when Firejailing makepkg 13# for potential issues and their solutions when Firejailing makepkg
@@ -17,18 +17,18 @@ blacklist ${RUNUSER}/wayland-*
17# whitelist ${HOME}/.gnupg 17# whitelist ${HOME}/.gnupg
18 18
19# Enable severely restricted access to ${HOME}/.gnupg 19# Enable severely restricted access to ${HOME}/.gnupg
20noblacklist ${HOME}/.gnupg 20nodeny ${HOME}/.gnupg
21read-only ${HOME}/.gnupg/gpg.conf 21read-only ${HOME}/.gnupg/gpg.conf
22read-only ${HOME}/.gnupg/trustdb.gpg 22read-only ${HOME}/.gnupg/trustdb.gpg
23read-only ${HOME}/.gnupg/pubring.kbx 23read-only ${HOME}/.gnupg/pubring.kbx
24blacklist ${HOME}/.gnupg/random_seed 24deny ${HOME}/.gnupg/random_seed
25blacklist ${HOME}/.gnupg/pubring.kbx~ 25deny ${HOME}/.gnupg/pubring.kbx~
26blacklist ${HOME}/.gnupg/private-keys-v1.d 26deny ${HOME}/.gnupg/private-keys-v1.d
27blacklist ${HOME}/.gnupg/crls.d 27deny ${HOME}/.gnupg/crls.d
28blacklist ${HOME}/.gnupg/openpgp-revocs.d 28deny ${HOME}/.gnupg/openpgp-revocs.d
29 29
30# Arch Linux (based distributions) need access to /var/lib/pacman. As we drop all capabilities this is automatically read-only. 30# Arch Linux (based distributions) need access to /var/lib/pacman. As we drop all capabilities this is automatically read-only.
31noblacklist /var/lib/pacman 31nodeny /var/lib/pacman
32 32
33include disable-common.inc 33include disable-common.inc
34include disable-exec.inc 34include disable-exec.inc
diff --git a/etc/profile-m-z/man.profile b/etc/profile-m-z/man.profile
index bd510fcac..383eeeeb7 100644
--- a/etc/profile-m-z/man.profile
+++ b/etc/profile-m-z/man.profile
@@ -7,10 +7,10 @@ include man.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10blacklist ${RUNUSER} 10deny ${RUNUSER}
11 11
12noblacklist ${HOME}/.local/share/man 12nodeny ${HOME}/.local/share/man
13noblacklist ${HOME}/.rustup 13nodeny ${HOME}/.rustup
14 14
15include disable-common.inc 15include disable-common.inc
16include disable-devel.inc 16include disable-devel.inc
@@ -23,12 +23,12 @@ include disable-xdg.inc
23#mkdir ${HOME}/.local/share/man 23#mkdir ${HOME}/.local/share/man
24#whitelist ${HOME}/.local/share/man 24#whitelist ${HOME}/.local/share/man
25#whitelist ${HOME}/.manpath 25#whitelist ${HOME}/.manpath
26whitelist /usr/share/groff 26allow /usr/share/groff
27whitelist /usr/share/info 27allow /usr/share/info
28whitelist /usr/share/lintian 28allow /usr/share/lintian
29whitelist /usr/share/locale 29allow /usr/share/locale
30whitelist /usr/share/man 30allow /usr/share/man
31whitelist /var/cache/man 31allow /var/cache/man
32#include whitelist-common.inc 32#include whitelist-common.inc
33include whitelist-runuser-common.inc 33include whitelist-runuser-common.inc
34include whitelist-usr-share-common.inc 34include whitelist-usr-share-common.inc
diff --git a/etc/profile-m-z/manaplus.profile b/etc/profile-m-z/manaplus.profile
index f59a56ac6..67ee783a6 100644
--- a/etc/profile-m-z/manaplus.profile
+++ b/etc/profile-m-z/manaplus.profile
@@ -6,8 +6,8 @@ include manaplus.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/mana 9nodeny ${HOME}/.config/mana
10noblacklist ${HOME}/.local/share/mana 10nodeny ${HOME}/.local/share/mana
11 11
12include disable-common.inc 12include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
@@ -21,8 +21,8 @@ include disable-xdg.inc
21mkdir ${HOME}/.config/mana 21mkdir ${HOME}/.config/mana
22mkdir ${HOME}/.config/mana/mana 22mkdir ${HOME}/.config/mana/mana
23mkdir ${HOME}/.local/share/mana 23mkdir ${HOME}/.local/share/mana
24whitelist ${HOME}/.config/mana 24allow ${HOME}/.config/mana
25whitelist ${HOME}/.local/share/mana 25allow ${HOME}/.local/share/mana
26include whitelist-common.inc 26include whitelist-common.inc
27include whitelist-var-common.inc 27include whitelist-var-common.inc
28 28
diff --git a/etc/profile-m-z/marker.profile b/etc/profile-m-z/marker.profile
index bd56a8221..7645ad335 100644
--- a/etc/profile-m-z/marker.profile
+++ b/etc/profile-m-z/marker.profile
@@ -11,8 +11,8 @@ include globals.local
11#protocol unix,inet,inet6 11#protocol unix,inet,inet6
12#private-etc ca-certificates,ssl,pki,crypto-policies,nsswitch.conf,resolv.conf 12#private-etc ca-certificates,ssl,pki,crypto-policies,nsswitch.conf,resolv.conf
13 13
14noblacklist ${HOME}/.cache/marker 14nodeny ${HOME}/.cache/marker
15noblacklist ${DOCUMENTS} 15nodeny ${DOCUMENTS}
16 16
17include allow-python3.inc 17include allow-python3.inc
18 18
@@ -25,8 +25,8 @@ include disable-programs.inc
25include disable-shell.inc 25include disable-shell.inc
26include disable-xdg.inc 26include disable-xdg.inc
27 27
28whitelist /usr/libexec/webkit2gtk-4.0 28allow /usr/libexec/webkit2gtk-4.0
29whitelist /usr/share/com.github.fabiocolacio.marker 29allow /usr/share/com.github.fabiocolacio.marker
30include whitelist-runuser-common.inc 30include whitelist-runuser-common.inc
31include whitelist-usr-share-common.inc 31include whitelist-usr-share-common.inc
32include whitelist-var-common.inc 32include whitelist-var-common.inc
diff --git a/etc/profile-m-z/masterpdfeditor.profile b/etc/profile-m-z/masterpdfeditor.profile
index de1135071..d8b215b7f 100644
--- a/etc/profile-m-z/masterpdfeditor.profile
+++ b/etc/profile-m-z/masterpdfeditor.profile
@@ -6,8 +6,8 @@ include masterpdfeditor.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/Code Industry 9nodeny ${HOME}/.config/Code Industry
10noblacklist ${HOME}/.masterpdfeditor 10nodeny ${HOME}/.masterpdfeditor
11 11
12include disable-common.inc 12include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
diff --git a/etc/profile-m-z/mate-calc.profile b/etc/profile-m-z/mate-calc.profile
index 39ee7439d..92832783e 100644
--- a/etc/profile-m-z/mate-calc.profile
+++ b/etc/profile-m-z/mate-calc.profile
@@ -6,7 +6,7 @@ include mate-calc.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/mate-calc 9nodeny ${HOME}/.config/mate-calc
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -18,9 +18,9 @@ include disable-programs.inc
18mkdir ${HOME}/.cache/mate-calc 18mkdir ${HOME}/.cache/mate-calc
19mkdir ${HOME}/.config/caja 19mkdir ${HOME}/.config/caja
20mkdir ${HOME}/.config/mate-menu 20mkdir ${HOME}/.config/mate-menu
21whitelist ${HOME}/.cache/mate-calc 21allow ${HOME}/.cache/mate-calc
22whitelist ${HOME}/.config/caja 22allow ${HOME}/.config/caja
23whitelist ${HOME}/.config/mate-menu 23allow ${HOME}/.config/mate-menu
24include whitelist-common.inc 24include whitelist-common.inc
25include whitelist-var-common.inc 25include whitelist-var-common.inc
26 26
diff --git a/etc/profile-m-z/mate-dictionary.profile b/etc/profile-m-z/mate-dictionary.profile
index ae1fcbf62..90c9d0993 100644
--- a/etc/profile-m-z/mate-dictionary.profile
+++ b/etc/profile-m-z/mate-dictionary.profile
@@ -5,7 +5,7 @@ include mate-dictionary.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${HOME}/.config/mate/mate-dictionary 8nodeny ${HOME}/.config/mate/mate-dictionary
9 9
10include disable-common.inc 10include disable-common.inc
11include disable-devel.inc 11include disable-devel.inc
@@ -16,7 +16,7 @@ include disable-programs.inc
16include disable-shell.inc 16include disable-shell.inc
17 17
18mkdir ${HOME}/.config/mate/mate-dictionary 18mkdir ${HOME}/.config/mate/mate-dictionary
19whitelist ${HOME}/.config/mate/mate-dictionary 19allow ${HOME}/.config/mate/mate-dictionary
20include whitelist-common.inc 20include whitelist-common.inc
21 21
22apparmor 22apparmor
diff --git a/etc/profile-m-z/matrix-mirage.profile b/etc/profile-m-z/matrix-mirage.profile
index b3080df88..8ee470a50 100644
--- a/etc/profile-m-z/matrix-mirage.profile
+++ b/etc/profile-m-z/matrix-mirage.profile
@@ -7,16 +7,16 @@ include matrix-mirage.local
7# added by included profile 7# added by included profile
8#include globals.local 8#include globals.local
9 9
10noblacklist ${HOME}/.cache/matrix-mirage 10nodeny ${HOME}/.cache/matrix-mirage
11noblacklist ${HOME}/.config/matrix-mirage 11nodeny ${HOME}/.config/matrix-mirage
12noblacklist ${HOME}/.local/share/matrix-mirage 12nodeny ${HOME}/.local/share/matrix-mirage
13 13
14mkdir ${HOME}/.cache/matrix-mirage 14mkdir ${HOME}/.cache/matrix-mirage
15mkdir ${HOME}/.config/matrix-mirage 15mkdir ${HOME}/.config/matrix-mirage
16mkdir ${HOME}/.local/share/matrix-mirage 16mkdir ${HOME}/.local/share/matrix-mirage
17whitelist ${HOME}/.cache/matrix-mirage 17allow ${HOME}/.cache/matrix-mirage
18whitelist ${HOME}/.config/matrix-mirage 18allow ${HOME}/.config/matrix-mirage
19whitelist ${HOME}/.local/share/matrix-mirage 19allow ${HOME}/.local/share/matrix-mirage
20 20
21private-bin matrix-mirage 21private-bin matrix-mirage
22 22
diff --git a/etc/profile-m-z/mattermost-desktop.profile b/etc/profile-m-z/mattermost-desktop.profile
index 3c2bf4fa3..01076a90a 100644
--- a/etc/profile-m-z/mattermost-desktop.profile
+++ b/etc/profile-m-z/mattermost-desktop.profile
@@ -10,12 +10,12 @@ ignore apparmor
10ignore dbus-user none 10ignore dbus-user none
11ignore dbus-system none 11ignore dbus-system none
12 12
13noblacklist ${HOME}/.config/Mattermost 13nodeny ${HOME}/.config/Mattermost
14 14
15include disable-shell.inc 15include disable-shell.inc
16 16
17mkdir ${HOME}/.config/Mattermost 17mkdir ${HOME}/.config/Mattermost
18whitelist ${HOME}/.config/Mattermost 18allow ${HOME}/.config/Mattermost
19 19
20private-etc alternatives,ca-certificates,crypto-policies,fonts,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,machine-id,nsswitch.conf,pki,resolv.conf,ssl 20private-etc alternatives,ca-certificates,crypto-policies,fonts,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,machine-id,nsswitch.conf,pki,resolv.conf,ssl
21 21
diff --git a/etc/profile-m-z/mcabber.profile b/etc/profile-m-z/mcabber.profile
index 38d2d8d63..ae749114a 100644
--- a/etc/profile-m-z/mcabber.profile
+++ b/etc/profile-m-z/mcabber.profile
@@ -6,8 +6,8 @@ include mcabber.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.mcabber 9nodeny ${HOME}/.mcabber
10noblacklist ${HOME}/.mcabberrc 10nodeny ${HOME}/.mcabberrc
11 11
12include disable-common.inc 12include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
diff --git a/etc/profile-m-z/mcomix.profile b/etc/profile-m-z/mcomix.profile
index fcd1e24e5..d9e12fb5d 100644
--- a/etc/profile-m-z/mcomix.profile
+++ b/etc/profile-m-z/mcomix.profile
@@ -6,9 +6,9 @@ include mcomix.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/mcomix 9nodeny ${HOME}/.config/mcomix
10noblacklist ${HOME}/.local/share/mcomix 10nodeny ${HOME}/.local/share/mcomix
11noblacklist ${DOCUMENTS} 11nodeny ${DOCUMENTS}
12 12
13# Allow /bin/sh (blacklisted by disable-shell.inc) 13# Allow /bin/sh (blacklisted by disable-shell.inc)
14include allow-bin-sh.inc 14include allow-bin-sh.inc
@@ -30,7 +30,7 @@ include disable-xdg.inc
30 30
31mkdir ${HOME}/.config/mcomix 31mkdir ${HOME}/.config/mcomix
32mkdir ${HOME}/.local/share/mcomix 32mkdir ${HOME}/.local/share/mcomix
33whitelist /usr/share/mcomix 33allow /usr/share/mcomix
34include whitelist-usr-share-common.inc 34include whitelist-usr-share-common.inc
35include whitelist-var-common.inc 35include whitelist-var-common.inc
36include whitelist-runuser-common.inc 36include whitelist-runuser-common.inc
diff --git a/etc/profile-m-z/mdr.profile b/etc/profile-m-z/mdr.profile
index 5d3f8dc41..9e8656290 100644
--- a/etc/profile-m-z/mdr.profile
+++ b/etc/profile-m-z/mdr.profile
@@ -5,7 +5,7 @@ include mdr.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8blacklist ${RUNUSER}/wayland-* 8deny ${RUNUSER}/wayland-*
9 9
10include disable-common.inc 10include disable-common.inc
11include disable-devel.inc 11include disable-devel.inc
@@ -16,7 +16,7 @@ include disable-programs.inc
16include disable-shell.inc 16include disable-shell.inc
17include disable-xdg.inc 17include disable-xdg.inc
18 18
19whitelist ${DOWNLOADS} 19allow ${DOWNLOADS}
20include whitelist-usr-share-common.inc 20include whitelist-usr-share-common.inc
21include whitelist-var-common.inc 21include whitelist-var-common.inc
22 22
diff --git a/etc/profile-m-z/mediainfo.profile b/etc/profile-m-z/mediainfo.profile
index 17363624f..ae34ea321 100644
--- a/etc/profile-m-z/mediainfo.profile
+++ b/etc/profile-m-z/mediainfo.profile
@@ -6,7 +6,7 @@ include mediainfo.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9blacklist ${RUNUSER}/wayland-* 9deny ${RUNUSER}/wayland-*
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
diff --git a/etc/profile-m-z/mediathekview.profile b/etc/profile-m-z/mediathekview.profile
index 0063badd8..3459ad4cf 100644
--- a/etc/profile-m-z/mediathekview.profile
+++ b/etc/profile-m-z/mediathekview.profile
@@ -6,16 +6,16 @@ include mediathekview.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/mpv 9nodeny ${HOME}/.config/mpv
10noblacklist ${HOME}/.config/smplayer 10nodeny ${HOME}/.config/smplayer
11noblacklist ${HOME}/.config/totem 11nodeny ${HOME}/.config/totem
12noblacklist ${HOME}/.config/vlc 12nodeny ${HOME}/.config/vlc
13noblacklist ${HOME}/.config/xplayer 13nodeny ${HOME}/.config/xplayer
14noblacklist ${HOME}/.local/share/totem 14nodeny ${HOME}/.local/share/totem
15noblacklist ${HOME}/.local/share/xplayer 15nodeny ${HOME}/.local/share/xplayer
16noblacklist ${HOME}/.mediathek3 16nodeny ${HOME}/.mediathek3
17noblacklist ${HOME}/.mplayer 17nodeny ${HOME}/.mplayer
18noblacklist ${VIDEOS} 18nodeny ${VIDEOS}
19 19
20# Allow java (blacklisted by disable-devel.inc) 20# Allow java (blacklisted by disable-devel.inc)
21include allow-java.inc 21include allow-java.inc
diff --git a/etc/profile-m-z/megaglest.profile b/etc/profile-m-z/megaglest.profile
index f07b9166a..ad9094ddf 100644
--- a/etc/profile-m-z/megaglest.profile
+++ b/etc/profile-m-z/megaglest.profile
@@ -6,7 +6,7 @@ include megaglest.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.megaglest 9nodeny ${HOME}/.megaglest
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -18,9 +18,9 @@ include disable-shell.inc
18include disable-xdg.inc 18include disable-xdg.inc
19 19
20mkdir ${HOME}/.megaglest 20mkdir ${HOME}/.megaglest
21whitelist ${HOME}/.megaglest 21allow ${HOME}/.megaglest
22whitelist /usr/share/megaglest 22allow /usr/share/megaglest
23whitelist /usr/share/games/megaglest # Debian version 23allow /usr/share/games/megaglest # Debian version
24include whitelist-common.inc 24include whitelist-common.inc
25include whitelist-runuser-common.inc 25include whitelist-runuser-common.inc
26include whitelist-usr-share-common.inc 26include whitelist-usr-share-common.inc
diff --git a/etc/profile-m-z/meld.profile b/etc/profile-m-z/meld.profile
index 2a8bb3acf..06ee572c9 100644
--- a/etc/profile-m-z/meld.profile
+++ b/etc/profile-m-z/meld.profile
@@ -13,12 +13,12 @@ include globals.local
13# Calling it by its absolute path (example for git mergetool): 13# Calling it by its absolute path (example for git mergetool):
14# $ git config --global mergetool.meld.cmd /usr/bin/meld 14# $ git config --global mergetool.meld.cmd /usr/bin/meld
15 15
16noblacklist ${HOME}/.config/meld 16nodeny ${HOME}/.config/meld
17noblacklist ${HOME}/.config/git 17nodeny ${HOME}/.config/git
18noblacklist ${HOME}/.gitconfig 18nodeny ${HOME}/.gitconfig
19noblacklist ${HOME}/.git-credentials 19nodeny ${HOME}/.git-credentials
20noblacklist ${HOME}/.local/share/meld 20nodeny ${HOME}/.local/share/meld
21noblacklist ${HOME}/.subversion 21nodeny ${HOME}/.subversion
22 22
23# Allow python (blacklisted by disable-interpreters.inc) 23# Allow python (blacklisted by disable-interpreters.inc)
24# Python 2 is EOL (see #3164). Add the next line to your meld.local if you understand the risks 24# Python 2 is EOL (see #3164). Add the next line to your meld.local if you understand the risks
@@ -29,7 +29,7 @@ include allow-python3.inc
29# Allow ssh (blacklisted by disable-common.inc) 29# Allow ssh (blacklisted by disable-common.inc)
30include allow-ssh.inc 30include allow-ssh.inc
31 31
32blacklist /usr/libexec 32deny /usr/libexec
33 33
34# Add the next line to your meld.local if you don't need to compare files in disable-common.inc. 34# Add the next line to your meld.local if you don't need to compare files in disable-common.inc.
35#include disable-common.inc 35#include disable-common.inc
diff --git a/etc/profile-m-z/mendeleydesktop.profile b/etc/profile-m-z/mendeleydesktop.profile
index c0bdbb230..e33d6c157 100644
--- a/etc/profile-m-z/mendeleydesktop.profile
+++ b/etc/profile-m-z/mendeleydesktop.profile
@@ -6,13 +6,13 @@ include mendeleydesktop.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${DOCUMENTS} 9nodeny ${DOCUMENTS}
10noblacklist ${HOME}/.cache/Mendeley Ltd. 10nodeny ${HOME}/.cache/Mendeley Ltd.
11noblacklist ${HOME}/.config/Mendeley Ltd. 11nodeny ${HOME}/.config/Mendeley Ltd.
12noblacklist ${HOME}/.local/share/Mendeley Ltd. 12nodeny ${HOME}/.local/share/Mendeley Ltd.
13noblacklist ${HOME}/.local/share/data/Mendeley Ltd. 13nodeny ${HOME}/.local/share/data/Mendeley Ltd.
14noblacklist ${HOME}/.pki 14nodeny ${HOME}/.pki
15noblacklist ${HOME}/.local/share/pki 15nodeny ${HOME}/.local/share/pki
16 16
17# Allow python (blacklisted by disable-interpreters.inc) 17# Allow python (blacklisted by disable-interpreters.inc)
18include allow-python2.inc 18include allow-python2.inc
diff --git a/etc/profile-m-z/menulibre.profile b/etc/profile-m-z/menulibre.profile
index 2081b8c96..52808a5b5 100644
--- a/etc/profile-m-z/menulibre.profile
+++ b/etc/profile-m-z/menulibre.profile
@@ -19,13 +19,13 @@ include disable-passwdmgr.inc
19include disable-xdg.inc 19include disable-xdg.inc
20 20
21# Whitelist your system icon directory,varies by distro 21# Whitelist your system icon directory,varies by distro
22whitelist /usr/share/app-info 22allow /usr/share/app-info
23whitelist /usr/share/desktop-directories 23allow /usr/share/desktop-directories
24whitelist /usr/share/icons 24allow /usr/share/icons
25whitelist /usr/share/menulibre 25allow /usr/share/menulibre
26whitelist /var/lib/app-info/icons 26allow /var/lib/app-info/icons
27whitelist /var/lib/flatpak/exports/share/applications 27allow /var/lib/flatpak/exports/share/applications
28whitelist /var/lib/flatpak/exports/share/icons 28allow /var/lib/flatpak/exports/share/icons
29include whitelist-runuser-common.inc 29include whitelist-runuser-common.inc
30include whitelist-usr-share-common.inc 30include whitelist-usr-share-common.inc
31include whitelist-var-common.inc 31include whitelist-var-common.inc
diff --git a/etc/profile-m-z/meteo-qt.profile b/etc/profile-m-z/meteo-qt.profile
index 85ed7bc74..48f936632 100644
--- a/etc/profile-m-z/meteo-qt.profile
+++ b/etc/profile-m-z/meteo-qt.profile
@@ -6,8 +6,8 @@ include meteo-qt.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/autostart 9nodeny ${HOME}/.config/autostart
10noblacklist ${HOME}/.config/meteo-qt 10nodeny ${HOME}/.config/meteo-qt
11 11
12# Allow python (blacklisted by disable-interpreters.inc) 12# Allow python (blacklisted by disable-interpreters.inc)
13include allow-python3.inc 13include allow-python3.inc
@@ -22,8 +22,8 @@ include disable-shell.inc
22include disable-xdg.inc 22include disable-xdg.inc
23 23
24mkdir ${HOME}/.config/meteo-qt 24mkdir ${HOME}/.config/meteo-qt
25whitelist ${HOME}/.config/autostart 25allow ${HOME}/.config/autostart
26whitelist ${HOME}/.config/meteo-qt 26allow ${HOME}/.config/meteo-qt
27include whitelist-common.inc 27include whitelist-common.inc
28include whitelist-var-common.inc 28include whitelist-var-common.inc
29 29
diff --git a/etc/profile-m-z/microsoft-edge-dev.profile b/etc/profile-m-z/microsoft-edge-dev.profile
index 039cd36a8..96465866c 100644
--- a/etc/profile-m-z/microsoft-edge-dev.profile
+++ b/etc/profile-m-z/microsoft-edge-dev.profile
@@ -6,13 +6,13 @@ include microsoft-edge-dev.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.cache/microsoft-edge-dev 9nodeny ${HOME}/.cache/microsoft-edge-dev
10noblacklist ${HOME}/.config/microsoft-edge-dev 10nodeny ${HOME}/.config/microsoft-edge-dev
11 11
12mkdir ${HOME}/.cache/microsoft-edge-dev 12mkdir ${HOME}/.cache/microsoft-edge-dev
13mkdir ${HOME}/.config/microsoft-edge-dev 13mkdir ${HOME}/.config/microsoft-edge-dev
14whitelist ${HOME}/.cache/microsoft-edge-dev 14allow ${HOME}/.cache/microsoft-edge-dev
15whitelist ${HOME}/.config/microsoft-edge-dev 15allow ${HOME}/.config/microsoft-edge-dev
16 16
17private-opt microsoft 17private-opt microsoft
18 18
diff --git a/etc/profile-m-z/midori.profile b/etc/profile-m-z/midori.profile
index e15259608..c4a444e0d 100644
--- a/etc/profile-m-z/midori.profile
+++ b/etc/profile-m-z/midori.profile
@@ -9,17 +9,17 @@ include globals.local
9# noexec ${HOME} breaks DRM binaries. 9# noexec ${HOME} breaks DRM binaries.
10?BROWSER_ALLOW_DRM: ignore noexec ${HOME} 10?BROWSER_ALLOW_DRM: ignore noexec ${HOME}
11 11
12noblacklist ${HOME}/.cache/midori 12nodeny ${HOME}/.cache/midori
13noblacklist ${HOME}/.config/midori 13nodeny ${HOME}/.config/midori
14noblacklist ${HOME}/.local/share/midori 14nodeny ${HOME}/.local/share/midori
15# noblacklist ${HOME}/.local/share/webkit 15# noblacklist ${HOME}/.local/share/webkit
16# noblacklist ${HOME}/.local/share/webkitgtk 16# noblacklist ${HOME}/.local/share/webkitgtk
17noblacklist ${HOME}/.pki 17nodeny ${HOME}/.pki
18noblacklist ${HOME}/.local/share/pki 18nodeny ${HOME}/.local/share/pki
19 19
20noblacklist ${HOME}/.cache/gnome-mplayer 20nodeny ${HOME}/.cache/gnome-mplayer
21noblacklist ${HOME}/.config/gnome-mplayer 21nodeny ${HOME}/.config/gnome-mplayer
22noblacklist ${HOME}/.lastpass 22nodeny ${HOME}/.lastpass
23 23
24include disable-common.inc 24include disable-common.inc
25include disable-devel.inc 25include disable-devel.inc
@@ -36,17 +36,17 @@ mkdir ${HOME}/.local/share/webkit
36mkdir ${HOME}/.local/share/webkitgtk 36mkdir ${HOME}/.local/share/webkitgtk
37mkdir ${HOME}/.pki 37mkdir ${HOME}/.pki
38mkdir ${HOME}/.local/share/pki 38mkdir ${HOME}/.local/share/pki
39whitelist ${DOWNLOADS} 39allow ${DOWNLOADS}
40whitelist ${HOME}/.cache/gnome-mplayer/plugin 40allow ${HOME}/.cache/gnome-mplayer/plugin
41whitelist ${HOME}/.cache/midori 41allow ${HOME}/.cache/midori
42whitelist ${HOME}/.config/gnome-mplayer 42allow ${HOME}/.config/gnome-mplayer
43whitelist ${HOME}/.config/midori 43allow ${HOME}/.config/midori
44whitelist ${HOME}/.lastpass 44allow ${HOME}/.lastpass
45whitelist ${HOME}/.local/share/midori 45allow ${HOME}/.local/share/midori
46whitelist ${HOME}/.local/share/webkit 46allow ${HOME}/.local/share/webkit
47whitelist ${HOME}/.local/share/webkitgtk 47allow ${HOME}/.local/share/webkitgtk
48whitelist ${HOME}/.pki 48allow ${HOME}/.pki
49whitelist ${HOME}/.local/share/pki 49allow ${HOME}/.local/share/pki
50include whitelist-common.inc 50include whitelist-common.inc
51include whitelist-var-common.inc 51include whitelist-var-common.inc
52 52
diff --git a/etc/profile-m-z/min.profile b/etc/profile-m-z/min.profile
index 7f3aeab44..214332184 100644
--- a/etc/profile-m-z/min.profile
+++ b/etc/profile-m-z/min.profile
@@ -6,10 +6,10 @@ include min.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/Min 9nodeny ${HOME}/.config/Min
10 10
11mkdir ${HOME}/.config/Min 11mkdir ${HOME}/.config/Min
12whitelist ${HOME}/.config/Min 12allow ${HOME}/.config/Min
13 13
14# Redirect 14# Redirect
15include chromium-common.profile 15include chromium-common.profile
diff --git a/etc/profile-m-z/mindless.profile b/etc/profile-m-z/mindless.profile
index fbf6b58e8..ee8402b87 100644
--- a/etc/profile-m-z/mindless.profile
+++ b/etc/profile-m-z/mindless.profile
@@ -15,7 +15,7 @@ include disable-programs.inc
15include disable-shell.inc 15include disable-shell.inc
16include disable-xdg.inc 16include disable-xdg.inc
17 17
18whitelist /usr/share/mindless 18allow /usr/share/mindless
19include whitelist-usr-share-common.inc 19include whitelist-usr-share-common.inc
20include whitelist-var-common.inc 20include whitelist-var-common.inc
21 21
diff --git a/etc/profile-m-z/minecraft-launcher.profile b/etc/profile-m-z/minecraft-launcher.profile
index 1028e374a..595313851 100644
--- a/etc/profile-m-z/minecraft-launcher.profile
+++ b/etc/profile-m-z/minecraft-launcher.profile
@@ -11,7 +11,7 @@ include globals.local
11 11
12ignore noexec ${HOME} 12ignore noexec ${HOME}
13 13
14noblacklist ${HOME}/.minecraft 14nodeny ${HOME}/.minecraft
15 15
16include allow-java.inc 16include allow-java.inc
17 17
@@ -25,7 +25,7 @@ include disable-shell.inc
25include disable-xdg.inc 25include disable-xdg.inc
26 26
27mkdir ${HOME}/.minecraft 27mkdir ${HOME}/.minecraft
28whitelist ${HOME}/.minecraft 28allow ${HOME}/.minecraft
29include whitelist-common.inc 29include whitelist-common.inc
30include whitelist-runuser-common.inc 30include whitelist-runuser-common.inc
31include whitelist-usr-share-common.inc 31include whitelist-usr-share-common.inc
diff --git a/etc/profile-m-z/minetest.profile b/etc/profile-m-z/minetest.profile
index cad1adbda..11d0859b7 100644
--- a/etc/profile-m-z/minetest.profile
+++ b/etc/profile-m-z/minetest.profile
@@ -9,8 +9,8 @@ include globals.local
9# In order to save in-game screenshots to a persistent location edit ~/.minetest/minetest.conf: 9# In order to save in-game screenshots to a persistent location edit ~/.minetest/minetest.conf:
10# screenshot_path = /home/<USER>/.minetest/screenshots 10# screenshot_path = /home/<USER>/.minetest/screenshots
11 11
12noblacklist ${HOME}/.cache/minetest 12nodeny ${HOME}/.cache/minetest
13noblacklist ${HOME}/.minetest 13nodeny ${HOME}/.minetest
14 14
15# Allow lua (blacklisted by disable-interpreters.inc) 15# Allow lua (blacklisted by disable-interpreters.inc)
16include allow-lua.inc 16include allow-lua.inc
@@ -26,10 +26,10 @@ include disable-xdg.inc
26 26
27mkdir ${HOME}/.cache/minetest 27mkdir ${HOME}/.cache/minetest
28mkdir ${HOME}/.minetest 28mkdir ${HOME}/.minetest
29whitelist ${HOME}/.cache/minetest 29allow ${HOME}/.cache/minetest
30whitelist ${HOME}/.minetest 30allow ${HOME}/.minetest
31whitelist /usr/share/games/minetest 31allow /usr/share/games/minetest
32whitelist /usr/share/minetest 32allow /usr/share/minetest
33include whitelist-common.inc 33include whitelist-common.inc
34include whitelist-runuser-common.inc 34include whitelist-runuser-common.inc
35include whitelist-usr-share-common.inc 35include whitelist-usr-share-common.inc
diff --git a/etc/profile-m-z/minitube.profile b/etc/profile-m-z/minitube.profile
index 3fe3428d0..192913dbf 100644
--- a/etc/profile-m-z/minitube.profile
+++ b/etc/profile-m-z/minitube.profile
@@ -6,10 +6,10 @@ include minitube.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${PICTURES} 9nodeny ${PICTURES}
10noblacklist ${HOME}/.cache/Flavio Tordini 10nodeny ${HOME}/.cache/Flavio Tordini
11noblacklist ${HOME}/.config/Flavio Tordini 11nodeny ${HOME}/.config/Flavio Tordini
12noblacklist ${HOME}/.local/share/Flavio Tordini 12nodeny ${HOME}/.local/share/Flavio Tordini
13 13
14include allow-lua.inc 14include allow-lua.inc
15 15
@@ -25,11 +25,11 @@ include disable-xdg.inc
25mkdir ${HOME}/.cache/Flavio Tordini 25mkdir ${HOME}/.cache/Flavio Tordini
26mkdir ${HOME}/.config/Flavio Tordini 26mkdir ${HOME}/.config/Flavio Tordini
27mkdir ${HOME}/.local/share/Flavio Tordini 27mkdir ${HOME}/.local/share/Flavio Tordini
28whitelist ${PICTURES} 28allow ${PICTURES}
29whitelist ${HOME}/.cache/Flavio Tordini 29allow ${HOME}/.cache/Flavio Tordini
30whitelist ${HOME}/.config/Flavio Tordini 30allow ${HOME}/.config/Flavio Tordini
31whitelist ${HOME}/.local/share/Flavio Tordini 31allow ${HOME}/.local/share/Flavio Tordini
32whitelist /usr/share/minitube 32allow /usr/share/minitube
33include whitelist-common.inc 33include whitelist-common.inc
34include whitelist-runuser-common.inc 34include whitelist-runuser-common.inc
35include whitelist-usr-share-common.inc 35include whitelist-usr-share-common.inc
diff --git a/etc/profile-m-z/mirage.profile b/etc/profile-m-z/mirage.profile
index 505009283..b2f2cc5b1 100644
--- a/etc/profile-m-z/mirage.profile
+++ b/etc/profile-m-z/mirage.profile
@@ -6,10 +6,10 @@ include mirage.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.cache/mirage 9nodeny ${HOME}/.cache/mirage
10noblacklist ${HOME}/.config/mirage 10nodeny ${HOME}/.config/mirage
11noblacklist ${HOME}/.local/share/mirage 11nodeny ${HOME}/.local/share/mirage
12noblacklist /sbin 12nodeny /sbin
13 13
14# Allow python (blacklisted by disable-interpreters.inc) 14# Allow python (blacklisted by disable-interpreters.inc)
15include allow-python2.inc 15include allow-python2.inc
@@ -27,10 +27,10 @@ include disable-xdg.inc
27mkdir ${HOME}/.cache/mirage 27mkdir ${HOME}/.cache/mirage
28mkdir ${HOME}/.config/mirage 28mkdir ${HOME}/.config/mirage
29mkdir ${HOME}/.local/share/mirage 29mkdir ${HOME}/.local/share/mirage
30whitelist ${HOME}/.cache/mirage 30allow ${HOME}/.cache/mirage
31whitelist ${HOME}/.config/mirage 31allow ${HOME}/.config/mirage
32whitelist ${HOME}/.local/share/mirage 32allow ${HOME}/.local/share/mirage
33whitelist ${DOWNLOADS} 33allow ${DOWNLOADS}
34include whitelist-common.inc 34include whitelist-common.inc
35include whitelist-runuser-common.inc 35include whitelist-runuser-common.inc
36include whitelist-usr-share-common.inc 36include whitelist-usr-share-common.inc
diff --git a/etc/profile-m-z/mirrormagic.profile b/etc/profile-m-z/mirrormagic.profile
index 58dfd56f5..d5ebfd4b0 100644
--- a/etc/profile-m-z/mirrormagic.profile
+++ b/etc/profile-m-z/mirrormagic.profile
@@ -6,7 +6,7 @@ include mirrormagic.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.mirrormagic 9nodeny ${HOME}/.mirrormagic
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -18,8 +18,8 @@ include disable-shell.inc
18include disable-xdg.inc 18include disable-xdg.inc
19 19
20mkdir ${HOME}/.mirrormagic 20mkdir ${HOME}/.mirrormagic
21whitelist ${HOME}/.mirrormagic 21allow ${HOME}/.mirrormagic
22whitelist /usr/share/mirrormagic 22allow /usr/share/mirrormagic
23include whitelist-common.inc 23include whitelist-common.inc
24include whitelist-usr-share-common.inc 24include whitelist-usr-share-common.inc
25include whitelist-var-common.inc 25include whitelist-var-common.inc
diff --git a/etc/profile-m-z/mocp.profile b/etc/profile-m-z/mocp.profile
index e71ba4569..b734bd7c0 100644
--- a/etc/profile-m-z/mocp.profile
+++ b/etc/profile-m-z/mocp.profile
@@ -7,8 +7,8 @@ include mocp.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10noblacklist ${HOME}/.moc 10nodeny ${HOME}/.moc
11noblacklist ${MUSIC} 11nodeny ${MUSIC}
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
diff --git a/etc/profile-m-z/mousepad.profile b/etc/profile-m-z/mousepad.profile
index 98063fa7c..a02b29b61 100644
--- a/etc/profile-m-z/mousepad.profile
+++ b/etc/profile-m-z/mousepad.profile
@@ -6,7 +6,7 @@ include mousepad.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/Mousepad 9nodeny ${HOME}/.config/Mousepad
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
diff --git a/etc/profile-m-z/mp3splt-gtk.profile b/etc/profile-m-z/mp3splt-gtk.profile
index 37ce60e04..f47384753 100644
--- a/etc/profile-m-z/mp3splt-gtk.profile
+++ b/etc/profile-m-z/mp3splt-gtk.profile
@@ -6,7 +6,7 @@ include mp3splt-gtk.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.mp3splt-gtk 9nodeny ${HOME}/.mp3splt-gtk
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
diff --git a/etc/profile-m-z/mp3splt.profile b/etc/profile-m-z/mp3splt.profile
index 070de8451..8a2ab15bd 100644
--- a/etc/profile-m-z/mp3splt.profile
+++ b/etc/profile-m-z/mp3splt.profile
@@ -6,9 +6,9 @@ include mp3splt.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9blacklist ${RUNUSER}/wayland-* 9deny ${RUNUSER}/wayland-*
10 10
11noblacklist ${MUSIC} 11nodeny ${MUSIC}
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
diff --git a/etc/profile-m-z/mpDris2.profile b/etc/profile-m-z/mpDris2.profile
index 55a0b5897..6994b0429 100644
--- a/etc/profile-m-z/mpDris2.profile
+++ b/etc/profile-m-z/mpDris2.profile
@@ -6,13 +6,13 @@ include mpDris2.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/mpDris2 9nodeny ${HOME}/.config/mpDris2
10 10
11# Allow python (blacklisted by disable-interpreters.inc) 11# Allow python (blacklisted by disable-interpreters.inc)
12include allow-python2.inc 12include allow-python2.inc
13include allow-python3.inc 13include allow-python3.inc
14 14
15noblacklist ${MUSIC} 15nodeny ${MUSIC}
16 16
17include disable-common.inc 17include disable-common.inc
18include disable-devel.inc 18include disable-devel.inc
@@ -23,10 +23,10 @@ include disable-programs.inc
23include disable-shell.inc 23include disable-shell.inc
24include disable-xdg.inc 24include disable-xdg.inc
25 25
26whitelist ${MUSIC} 26allow ${MUSIC}
27 27
28mkdir ${HOME}/.config/mpDris2 28mkdir ${HOME}/.config/mpDris2
29whitelist ${HOME}/.config/mpDris2 29allow ${HOME}/.config/mpDris2
30include whitelist-usr-share-common.inc 30include whitelist-usr-share-common.inc
31include whitelist-var-common.inc 31include whitelist-var-common.inc
32 32
diff --git a/etc/profile-m-z/mpd.profile b/etc/profile-m-z/mpd.profile
index b517d4ab2..8b3350ac8 100644
--- a/etc/profile-m-z/mpd.profile
+++ b/etc/profile-m-z/mpd.profile
@@ -6,10 +6,10 @@ include mpd.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/mpd 9nodeny ${HOME}/.config/mpd
10noblacklist ${HOME}/.mpd 10nodeny ${HOME}/.mpd
11noblacklist ${HOME}/.mpdconf 11nodeny ${HOME}/.mpdconf
12noblacklist ${MUSIC} 12nodeny ${MUSIC}
13 13
14include disable-common.inc 14include disable-common.inc
15include disable-devel.inc 15include disable-devel.inc
diff --git a/etc/profile-m-z/mpg123.profile b/etc/profile-m-z/mpg123.profile
index 25187e894..03bd44daa 100644
--- a/etc/profile-m-z/mpg123.profile
+++ b/etc/profile-m-z/mpg123.profile
@@ -7,7 +7,7 @@ include mpg123.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10noblacklist ${MUSIC} 10nodeny ${MUSIC}
11 11
12include disable-common.inc 12include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
diff --git a/etc/profile-m-z/mplayer.profile b/etc/profile-m-z/mplayer.profile
index 5d023b7f1..84754aeb2 100644
--- a/etc/profile-m-z/mplayer.profile
+++ b/etc/profile-m-z/mplayer.profile
@@ -6,7 +6,7 @@ include mplayer.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.mplayer 9nodeny ${HOME}/.mplayer
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -17,7 +17,7 @@ include disable-programs.inc
17 17
18read-only ${DESKTOP} 18read-only ${DESKTOP}
19mkdir ${HOME}/.mplayer 19mkdir ${HOME}/.mplayer
20whitelist ${HOME}/.mplayer 20allow ${HOME}/.mplayer
21include whitelist-common.inc 21include whitelist-common.inc
22include whitelist-player-common.inc 22include whitelist-player-common.inc
23include whitelist-usr-share-common.inc 23include whitelist-usr-share-common.inc
diff --git a/etc/profile-m-z/mpsyt.profile b/etc/profile-m-z/mpsyt.profile
index bfe57a132..d35519103 100644
--- a/etc/profile-m-z/mpsyt.profile
+++ b/etc/profile-m-z/mpsyt.profile
@@ -6,12 +6,12 @@ include mpsyt.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/mps-youtube 9nodeny ${HOME}/.config/mps-youtube
10noblacklist ${HOME}/.config/mpv 10nodeny ${HOME}/.config/mpv
11noblacklist ${HOME}/.config/youtube-dl 11nodeny ${HOME}/.config/youtube-dl
12noblacklist ${HOME}/.mplayer 12nodeny ${HOME}/.mplayer
13noblacklist ${HOME}/.netrc 13nodeny ${HOME}/.netrc
14noblacklist ${HOME}/mps 14nodeny ${HOME}/mps
15 15
16# Allow lua (blacklisted by disable-interpreters.inc) 16# Allow lua (blacklisted by disable-interpreters.inc)
17include allow-lua.inc 17include allow-lua.inc
@@ -20,8 +20,8 @@ include allow-lua.inc
20include allow-python2.inc 20include allow-python2.inc
21include allow-python3.inc 21include allow-python3.inc
22 22
23noblacklist ${MUSIC} 23nodeny ${MUSIC}
24noblacklist ${VIDEOS} 24nodeny ${VIDEOS}
25 25
26include disable-common.inc 26include disable-common.inc
27include disable-devel.inc 27include disable-devel.inc
@@ -37,12 +37,12 @@ mkdir ${HOME}/.config/mpv
37mkdir ${HOME}/.config/youtube-dl 37mkdir ${HOME}/.config/youtube-dl
38mkdir ${HOME}/.mplayer 38mkdir ${HOME}/.mplayer
39mkdir ${HOME}/mps 39mkdir ${HOME}/mps
40whitelist ${HOME}/.config/mps-youtube 40allow ${HOME}/.config/mps-youtube
41whitelist ${HOME}/.config/mpv 41allow ${HOME}/.config/mpv
42whitelist ${HOME}/.config/youtube-dl 42allow ${HOME}/.config/youtube-dl
43whitelist ${HOME}/.mplayer 43allow ${HOME}/.mplayer
44whitelist ${HOME}/.netrc 44allow ${HOME}/.netrc
45whitelist ${HOME}/mps 45allow ${HOME}/mps
46include whitelist-common.inc 46include whitelist-common.inc
47include whitelist-player-common.inc 47include whitelist-player-common.inc
48include whitelist-var-common.inc 48include whitelist-var-common.inc
diff --git a/etc/profile-m-z/mpv.profile b/etc/profile-m-z/mpv.profile
index af5c214f7..4ea2dd348 100644
--- a/etc/profile-m-z/mpv.profile
+++ b/etc/profile-m-z/mpv.profile
@@ -24,9 +24,9 @@ include globals.local
24#include allow-bin-sh.inc 24#include allow-bin-sh.inc
25#private-bin sh 25#private-bin sh
26 26
27noblacklist ${HOME}/.config/mpv 27nodeny ${HOME}/.config/mpv
28noblacklist ${HOME}/.config/youtube-dl 28nodeny ${HOME}/.config/youtube-dl
29noblacklist ${HOME}/.netrc 29nodeny ${HOME}/.netrc
30 30
31# Allow lua (blacklisted by disable-interpreters.inc) 31# Allow lua (blacklisted by disable-interpreters.inc)
32include allow-lua.inc 32include allow-lua.inc
@@ -35,7 +35,7 @@ include allow-lua.inc
35include allow-python2.inc 35include allow-python2.inc
36include allow-python3.inc 36include allow-python3.inc
37 37
38blacklist /usr/libexec 38deny /usr/libexec
39 39
40include disable-common.inc 40include disable-common.inc
41include disable-devel.inc 41include disable-devel.inc
@@ -49,14 +49,14 @@ read-only ${DESKTOP}
49mkdir ${HOME}/.config/mpv 49mkdir ${HOME}/.config/mpv
50mkdir ${HOME}/.config/youtube-dl 50mkdir ${HOME}/.config/youtube-dl
51mkfile ${HOME}/.netrc 51mkfile ${HOME}/.netrc
52whitelist ${HOME}/.config/mpv 52allow ${HOME}/.config/mpv
53whitelist ${HOME}/.config/youtube-dl 53allow ${HOME}/.config/youtube-dl
54whitelist ${HOME}/.netrc 54allow ${HOME}/.netrc
55include whitelist-common.inc 55include whitelist-common.inc
56include whitelist-player-common.inc 56include whitelist-player-common.inc
57whitelist /usr/share/lua 57allow /usr/share/lua
58whitelist /usr/share/lua* 58allow /usr/share/lua*
59whitelist /usr/share/vulkan 59allow /usr/share/vulkan
60include whitelist-usr-share-common.inc 60include whitelist-usr-share-common.inc
61include whitelist-var-common.inc 61include whitelist-var-common.inc
62 62
diff --git a/etc/profile-m-z/mrrescue.profile b/etc/profile-m-z/mrrescue.profile
index e3ceb3bd4..a8c49a690 100644
--- a/etc/profile-m-z/mrrescue.profile
+++ b/etc/profile-m-z/mrrescue.profile
@@ -6,7 +6,7 @@ include mrrescue.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.local/share/love 9nodeny ${HOME}/.local/share/love
10 10
11# Allow /bin/sh (blacklisted by disable-shell.inc) 11# Allow /bin/sh (blacklisted by disable-shell.inc)
12include allow-bin-sh.inc 12include allow-bin-sh.inc
@@ -14,7 +14,7 @@ include allow-bin-sh.inc
14# Allow lua (blacklisted by disable-interpreters.inc) 14# Allow lua (blacklisted by disable-interpreters.inc)
15include allow-lua.inc 15include allow-lua.inc
16 16
17blacklist /usr/libexec 17deny /usr/libexec
18 18
19include disable-common.inc 19include disable-common.inc
20include disable-devel.inc 20include disable-devel.inc
@@ -26,8 +26,8 @@ include disable-shell.inc
26include disable-xdg.inc 26include disable-xdg.inc
27 27
28mkdir ${HOME}/.local/share/love 28mkdir ${HOME}/.local/share/love
29whitelist ${HOME}/.local/share/love 29allow ${HOME}/.local/share/love
30whitelist /usr/share/mrrescue 30allow /usr/share/mrrescue
31include whitelist-common.inc 31include whitelist-common.inc
32include whitelist-runuser-common.inc 32include whitelist-runuser-common.inc
33include whitelist-usr-share-common.inc 33include whitelist-usr-share-common.inc
diff --git a/etc/profile-m-z/ms-excel.profile b/etc/profile-m-z/ms-excel.profile
index db24e8f9b..5fea86ae7 100644
--- a/etc/profile-m-z/ms-excel.profile
+++ b/etc/profile-m-z/ms-excel.profile
@@ -6,7 +6,7 @@ include ms-excel.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.cache/ms-excel-online 9nodeny ${HOME}/.cache/ms-excel-online
10private-bin ms-excel 10private-bin ms-excel
11 11
12# Redirect 12# Redirect
diff --git a/etc/profile-m-z/ms-office.profile b/etc/profile-m-z/ms-office.profile
index 38fc84ecc..4033627f7 100644
--- a/etc/profile-m-z/ms-office.profile
+++ b/etc/profile-m-z/ms-office.profile
@@ -5,8 +5,8 @@ include ms-office.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${HOME}/.cache/ms-office-online 8nodeny ${HOME}/.cache/ms-office-online
9noblacklist ${HOME}/.jak 9nodeny ${HOME}/.jak
10 10
11# Allow python (blacklisted by disable-interpreters.inc) 11# Allow python (blacklisted by disable-interpreters.inc)
12include allow-python2.inc 12include allow-python2.inc
diff --git a/etc/profile-m-z/ms-onenote.profile b/etc/profile-m-z/ms-onenote.profile
index 9ea0637bd..805de5102 100644
--- a/etc/profile-m-z/ms-onenote.profile
+++ b/etc/profile-m-z/ms-onenote.profile
@@ -6,7 +6,7 @@ include ms-onenote.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.cache/ms-onenote-online 9nodeny ${HOME}/.cache/ms-onenote-online
10private-bin ms-onenote 10private-bin ms-onenote
11 11
12# Redirect 12# Redirect
diff --git a/etc/profile-m-z/ms-outlook.profile b/etc/profile-m-z/ms-outlook.profile
index fc3e7c009..bd14fb7d3 100644
--- a/etc/profile-m-z/ms-outlook.profile
+++ b/etc/profile-m-z/ms-outlook.profile
@@ -6,7 +6,7 @@ include ms-outlook.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.cache/ms-outlook-online 9nodeny ${HOME}/.cache/ms-outlook-online
10private-bin ms-outlook 10private-bin ms-outlook
11 11
12# Redirect 12# Redirect
diff --git a/etc/profile-m-z/ms-powerpoint.profile b/etc/profile-m-z/ms-powerpoint.profile
index dadcd5b1e..02a7424e2 100644
--- a/etc/profile-m-z/ms-powerpoint.profile
+++ b/etc/profile-m-z/ms-powerpoint.profile
@@ -6,7 +6,7 @@ include ms-powerpoint.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.cache/ms-powerpoint-online 9nodeny ${HOME}/.cache/ms-powerpoint-online
10private-bin ms-powerpoint 10private-bin ms-powerpoint
11 11
12# Redirect 12# Redirect
diff --git a/etc/profile-m-z/ms-skype.profile b/etc/profile-m-z/ms-skype.profile
index df1618361..01729f9a2 100644
--- a/etc/profile-m-z/ms-skype.profile
+++ b/etc/profile-m-z/ms-skype.profile
@@ -8,7 +8,7 @@ include ms-skype.local
8 8
9ignore novideo 9ignore novideo
10 10
11noblacklist ${HOME}/.cache/ms-skype-online 11nodeny ${HOME}/.cache/ms-skype-online
12 12
13private-bin ms-skype 13private-bin ms-skype
14 14
diff --git a/etc/profile-m-z/ms-word.profile b/etc/profile-m-z/ms-word.profile
index 5a617a893..34cf02128 100644
--- a/etc/profile-m-z/ms-word.profile
+++ b/etc/profile-m-z/ms-word.profile
@@ -6,7 +6,7 @@ include ms-word.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.cache/ms-word-online 9nodeny ${HOME}/.cache/ms-word-online
10private-bin ms-word 10private-bin ms-word
11 11
12# Redirect 12# Redirect
diff --git a/etc/profile-m-z/mtpaint.profile b/etc/profile-m-z/mtpaint.profile
index 85c3ee9f2..ec7cd5d04 100644
--- a/etc/profile-m-z/mtpaint.profile
+++ b/etc/profile-m-z/mtpaint.profile
@@ -6,7 +6,7 @@ include mtpaint.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${PICTURES} 9nodeny ${PICTURES}
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
diff --git a/etc/profile-m-z/multimc5.profile b/etc/profile-m-z/multimc5.profile
index 6df681df1..447e7753f 100644
--- a/etc/profile-m-z/multimc5.profile
+++ b/etc/profile-m-z/multimc5.profile
@@ -5,9 +5,9 @@ include multimc5.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${HOME}/.local/share/multimc 8nodeny ${HOME}/.local/share/multimc
9noblacklist ${HOME}/.local/share/multimc5 9nodeny ${HOME}/.local/share/multimc5
10noblacklist ${HOME}/.multimc5 10nodeny ${HOME}/.multimc5
11 11
12# Allow java (blacklisted by disable-devel.inc) 12# Allow java (blacklisted by disable-devel.inc)
13include allow-java.inc 13include allow-java.inc
@@ -22,9 +22,9 @@ include disable-programs.inc
22mkdir ${HOME}/.local/share/multimc 22mkdir ${HOME}/.local/share/multimc
23mkdir ${HOME}/.local/share/multimc5 23mkdir ${HOME}/.local/share/multimc5
24mkdir ${HOME}/.multimc5 24mkdir ${HOME}/.multimc5
25whitelist ${HOME}/.local/share/multimc 25allow ${HOME}/.local/share/multimc
26whitelist ${HOME}/.local/share/multimc5 26allow ${HOME}/.local/share/multimc5
27whitelist ${HOME}/.multimc5 27allow ${HOME}/.multimc5
28include whitelist-common.inc 28include whitelist-common.inc
29 29
30caps.drop all 30caps.drop all
diff --git a/etc/profile-m-z/mumble.profile b/etc/profile-m-z/mumble.profile
index c7f59c5ee..1d72e07b8 100644
--- a/etc/profile-m-z/mumble.profile
+++ b/etc/profile-m-z/mumble.profile
@@ -6,9 +6,9 @@ include mumble.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/Mumble 9nodeny ${HOME}/.config/Mumble
10noblacklist ${HOME}/.local/share/data/Mumble 10nodeny ${HOME}/.local/share/data/Mumble
11noblacklist ${HOME}/.local/share/Mumble 11nodeny ${HOME}/.local/share/Mumble
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
@@ -21,9 +21,9 @@ include disable-shell.inc
21mkdir ${HOME}/.config/Mumble 21mkdir ${HOME}/.config/Mumble
22mkdir ${HOME}/.local/share/data/Mumble 22mkdir ${HOME}/.local/share/data/Mumble
23mkdir ${HOME}/.local/share/Mumble 23mkdir ${HOME}/.local/share/Mumble
24whitelist ${HOME}/.config/Mumble 24allow ${HOME}/.config/Mumble
25whitelist ${HOME}/.local/share/data/Mumble 25allow ${HOME}/.local/share/data/Mumble
26whitelist ${HOME}/.local/share/Mumble 26allow ${HOME}/.local/share/Mumble
27include whitelist-common.inc 27include whitelist-common.inc
28include whitelist-var-common.inc 28include whitelist-var-common.inc
29 29
diff --git a/etc/profile-m-z/mupdf-gl.profile b/etc/profile-m-z/mupdf-gl.profile
index be94a9083..c208a5e54 100644
--- a/etc/profile-m-z/mupdf-gl.profile
+++ b/etc/profile-m-z/mupdf-gl.profile
@@ -7,7 +7,7 @@ include mupdf-gl.local
7# added by included profile 7# added by included profile
8#include globals.local 8#include globals.local
9 9
10noblacklist ${HOME}/.mupdf.history 10nodeny ${HOME}/.mupdf.history
11 11
12# Redirect 12# Redirect
13include mupdf.profile 13include mupdf.profile
diff --git a/etc/profile-m-z/mupdf.profile b/etc/profile-m-z/mupdf.profile
index 9e4609c48..e602b1429 100644
--- a/etc/profile-m-z/mupdf.profile
+++ b/etc/profile-m-z/mupdf.profile
@@ -6,7 +6,7 @@ include mupdf.local
6# Persistent global definitions 6# Persistent global definitions
7#include globals.local 7#include globals.local
8 8
9noblacklist ${DOCUMENTS} 9nodeny ${DOCUMENTS}
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
diff --git a/etc/profile-m-z/mupen64plus.profile b/etc/profile-m-z/mupen64plus.profile
index 00983a8f3..ecc7e2957 100644
--- a/etc/profile-m-z/mupen64plus.profile
+++ b/etc/profile-m-z/mupen64plus.profile
@@ -6,8 +6,8 @@ include mupen64plus.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/mupen64plus 9nodeny ${HOME}/.config/mupen64plus
10noblacklist ${HOME}/.local/share/mupen64plus 10nodeny ${HOME}/.local/share/mupen64plus
11 11
12include disable-common.inc 12include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
@@ -18,8 +18,8 @@ include disable-programs.inc
18# you'll need to manually whitelist ROM files 18# you'll need to manually whitelist ROM files
19mkdir ${HOME}/.config/mupen64plus 19mkdir ${HOME}/.config/mupen64plus
20mkdir ${HOME}/.local/share/mupen64plus 20mkdir ${HOME}/.local/share/mupen64plus
21whitelist ${HOME}/.config/mupen64plus 21allow ${HOME}/.config/mupen64plus
22whitelist ${HOME}/.local/share/mupen64plus 22allow ${HOME}/.local/share/mupen64plus
23include whitelist-common.inc 23include whitelist-common.inc
24 24
25caps.drop all 25caps.drop all
diff --git a/etc/profile-m-z/musescore.profile b/etc/profile-m-z/musescore.profile
index 679e82ae8..aa141f9c0 100644
--- a/etc/profile-m-z/musescore.profile
+++ b/etc/profile-m-z/musescore.profile
@@ -6,12 +6,12 @@ include musescore.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/MusE 9nodeny ${HOME}/.config/MusE
10noblacklist ${HOME}/.config/MuseScore 10nodeny ${HOME}/.config/MuseScore
11noblacklist ${HOME}/.local/share/data/MusE 11nodeny ${HOME}/.local/share/data/MusE
12noblacklist ${HOME}/.local/share/data/MuseScore 12nodeny ${HOME}/.local/share/data/MuseScore
13noblacklist ${DOCUMENTS} 13nodeny ${DOCUMENTS}
14noblacklist ${MUSIC} 14nodeny ${MUSIC}
15 15
16include disable-common.inc 16include disable-common.inc
17include disable-devel.inc 17include disable-devel.inc
diff --git a/etc/profile-m-z/musictube.profile b/etc/profile-m-z/musictube.profile
index 04500ac6a..5ab1303a2 100644
--- a/etc/profile-m-z/musictube.profile
+++ b/etc/profile-m-z/musictube.profile
@@ -6,9 +6,9 @@ include musictube.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.cache/Flavio Tordini 9nodeny ${HOME}/.cache/Flavio Tordini
10noblacklist ${HOME}/.config/Flavio Tordini 10nodeny ${HOME}/.config/Flavio Tordini
11noblacklist ${HOME}/.local/share/Flavio Tordini 11nodeny ${HOME}/.local/share/Flavio Tordini
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
@@ -22,10 +22,10 @@ include disable-xdg.inc
22mkdir ${HOME}/.cache/Flavio Tordini 22mkdir ${HOME}/.cache/Flavio Tordini
23mkdir ${HOME}/.config/Flavio Tordini 23mkdir ${HOME}/.config/Flavio Tordini
24mkdir ${HOME}/.local/share/Flavio Tordini 24mkdir ${HOME}/.local/share/Flavio Tordini
25whitelist ${HOME}/.cache/Flavio Tordini 25allow ${HOME}/.cache/Flavio Tordini
26whitelist ${HOME}/.config/Flavio Tordini 26allow ${HOME}/.config/Flavio Tordini
27whitelist ${HOME}/.local/share/Flavio Tordini 27allow ${HOME}/.local/share/Flavio Tordini
28whitelist /usr/share/musictube 28allow /usr/share/musictube
29include whitelist-common.inc 29include whitelist-common.inc
30include whitelist-runuser-common.inc 30include whitelist-runuser-common.inc
31include whitelist-usr-share-common.inc 31include whitelist-usr-share-common.inc
diff --git a/etc/profile-m-z/musixmatch.profile b/etc/profile-m-z/musixmatch.profile
index 74b3e9a5f..9390f9dcf 100644
--- a/etc/profile-m-z/musixmatch.profile
+++ b/etc/profile-m-z/musixmatch.profile
@@ -5,7 +5,7 @@ include musixmatch.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${MUSIC} 8nodeny ${MUSIC}
9 9
10include disable-common.inc 10include disable-common.inc
11include disable-devel.inc 11include disable-devel.inc
diff --git a/etc/profile-m-z/mutt.profile b/etc/profile-m-z/mutt.profile
index debf81659..91606bdfa 100644
--- a/etc/profile-m-z/mutt.profile
+++ b/etc/profile-m-z/mutt.profile
@@ -7,36 +7,36 @@ include mutt.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10noblacklist /var/mail 10nodeny /var/mail
11noblacklist /var/spool/mail 11nodeny /var/spool/mail
12noblacklist ${DOCUMENTS} 12nodeny ${DOCUMENTS}
13noblacklist ${HOME}/.Mail 13nodeny ${HOME}/.Mail
14noblacklist ${HOME}/.bogofilter 14nodeny ${HOME}/.bogofilter
15noblacklist ${HOME}/.cache/mutt 15nodeny ${HOME}/.cache/mutt
16noblacklist ${HOME}/.config/mutt 16nodeny ${HOME}/.config/mutt
17noblacklist ${HOME}/.config/nano 17nodeny ${HOME}/.config/nano
18noblacklist ${HOME}/.elinks 18nodeny ${HOME}/.elinks
19noblacklist ${HOME}/.emacs 19nodeny ${HOME}/.emacs
20noblacklist ${HOME}/.emacs.d 20nodeny ${HOME}/.emacs.d
21noblacklist ${HOME}/.gnupg 21nodeny ${HOME}/.gnupg
22noblacklist ${HOME}/.mail 22nodeny ${HOME}/.mail
23noblacklist ${HOME}/.mailcap 23nodeny ${HOME}/.mailcap
24noblacklist ${HOME}/.msmtprc 24nodeny ${HOME}/.msmtprc
25noblacklist ${HOME}/.mutt 25nodeny ${HOME}/.mutt
26noblacklist ${HOME}/.muttrc 26nodeny ${HOME}/.muttrc
27noblacklist ${HOME}/.nanorc 27nodeny ${HOME}/.nanorc
28noblacklist ${HOME}/.signature 28nodeny ${HOME}/.signature
29noblacklist ${HOME}/.vim 29nodeny ${HOME}/.vim
30noblacklist ${HOME}/.viminfo 30nodeny ${HOME}/.viminfo
31noblacklist ${HOME}/.vimrc 31nodeny ${HOME}/.vimrc
32noblacklist ${HOME}/.w3m 32nodeny ${HOME}/.w3m
33noblacklist ${HOME}/Mail 33nodeny ${HOME}/Mail
34noblacklist ${HOME}/mail 34nodeny ${HOME}/mail
35noblacklist ${HOME}/postponed 35nodeny ${HOME}/postponed
36noblacklist ${HOME}/sent 36nodeny ${HOME}/sent
37 37
38blacklist /tmp/.X11-unix 38deny /tmp/.X11-unix
39blacklist ${RUNUSER}/wayland-* 39deny ${RUNUSER}/wayland-*
40 40
41# Add the next lines to your mutt.local for oauth.py,S/MIME support. 41# Add the next lines to your mutt.local for oauth.py,S/MIME support.
42#include allow-perl.inc 42#include allow-perl.inc
@@ -75,37 +75,37 @@ mkfile ${HOME}/.nanorc
75mkfile ${HOME}/.signature 75mkfile ${HOME}/.signature
76mkfile ${HOME}/.viminfo 76mkfile ${HOME}/.viminfo
77mkfile ${HOME}/.vimrc 77mkfile ${HOME}/.vimrc
78whitelist ${DOCUMENTS} 78allow ${DOCUMENTS}
79whitelist ${DOWNLOADS} 79allow ${DOWNLOADS}
80whitelist ${HOME}/.Mail 80allow ${HOME}/.Mail
81whitelist ${HOME}/.bogofilter 81allow ${HOME}/.bogofilter
82whitelist ${HOME}/.cache/mutt 82allow ${HOME}/.cache/mutt
83whitelist ${HOME}/.config/mutt 83allow ${HOME}/.config/mutt
84whitelist ${HOME}/.config/nano 84allow ${HOME}/.config/nano
85whitelist ${HOME}/.elinks 85allow ${HOME}/.elinks
86whitelist ${HOME}/.emacs 86allow ${HOME}/.emacs
87whitelist ${HOME}/.emacs.d 87allow ${HOME}/.emacs.d
88whitelist ${HOME}/.gnupg 88allow ${HOME}/.gnupg
89whitelist ${HOME}/.mail 89allow ${HOME}/.mail
90whitelist ${HOME}/.mailcap 90allow ${HOME}/.mailcap
91whitelist ${HOME}/.msmtprc 91allow ${HOME}/.msmtprc
92whitelist ${HOME}/.mutt 92allow ${HOME}/.mutt
93whitelist ${HOME}/.muttrc 93allow ${HOME}/.muttrc
94whitelist ${HOME}/.nanorc 94allow ${HOME}/.nanorc
95whitelist ${HOME}/.signature 95allow ${HOME}/.signature
96whitelist ${HOME}/.vim 96allow ${HOME}/.vim
97whitelist ${HOME}/.viminfo 97allow ${HOME}/.viminfo
98whitelist ${HOME}/.vimrc 98allow ${HOME}/.vimrc
99whitelist ${HOME}/.w3m 99allow ${HOME}/.w3m
100whitelist ${HOME}/Mail 100allow ${HOME}/Mail
101whitelist ${HOME}/mail 101allow ${HOME}/mail
102whitelist ${HOME}/postponed 102allow ${HOME}/postponed
103whitelist ${HOME}/sent 103allow ${HOME}/sent
104whitelist /usr/share/gnupg 104allow /usr/share/gnupg
105whitelist /usr/share/gnupg2 105allow /usr/share/gnupg2
106whitelist /usr/share/mutt 106allow /usr/share/mutt
107whitelist /var/mail 107allow /var/mail
108whitelist /var/spool/mail 108allow /var/spool/mail
109include whitelist-common.inc 109include whitelist-common.inc
110include whitelist-runuser-common.inc 110include whitelist-runuser-common.inc
111include whitelist-usr-share-common.inc 111include whitelist-usr-share-common.inc
diff --git a/etc/profile-m-z/mypaint.profile b/etc/profile-m-z/mypaint.profile
index d8d487fe7..19af47498 100644
--- a/etc/profile-m-z/mypaint.profile
+++ b/etc/profile-m-z/mypaint.profile
@@ -6,10 +6,10 @@ include mypaint.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.cache/mypaint 9nodeny ${HOME}/.cache/mypaint
10noblacklist ${HOME}/.config/mypaint 10nodeny ${HOME}/.config/mypaint
11noblacklist ${HOME}/.local/share/mypaint 11nodeny ${HOME}/.local/share/mypaint
12noblacklist ${PICTURES} 12nodeny ${PICTURES}
13 13
14# Allow python (blacklisted by disable-interpreters.inc) 14# Allow python (blacklisted by disable-interpreters.inc)
15include allow-python2.inc 15include allow-python2.inc
diff --git a/etc/profile-m-z/nano.profile b/etc/profile-m-z/nano.profile
index 4698c2287..f0553bed5 100644
--- a/etc/profile-m-z/nano.profile
+++ b/etc/profile-m-z/nano.profile
@@ -7,10 +7,10 @@ include nano.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10blacklist ${RUNUSER}/wayland-* 10deny ${RUNUSER}/wayland-*
11 11
12noblacklist ${HOME}/.config/nano 12nodeny ${HOME}/.config/nano
13noblacklist ${HOME}/.nanorc 13nodeny ${HOME}/.nanorc
14 14
15include disable-common.inc 15include disable-common.inc
16include disable-devel.inc 16include disable-devel.inc
@@ -19,7 +19,7 @@ include disable-interpreters.inc
19include disable-passwdmgr.inc 19include disable-passwdmgr.inc
20include disable-programs.inc 20include disable-programs.inc
21 21
22whitelist /usr/share/nano 22allow /usr/share/nano
23include whitelist-usr-share-common.inc 23include whitelist-usr-share-common.inc
24 24
25apparmor 25apparmor
diff --git a/etc/profile-m-z/natron.profile b/etc/profile-m-z/natron.profile
index 5bf152f84..35d152748 100644
--- a/etc/profile-m-z/natron.profile
+++ b/etc/profile-m-z/natron.profile
@@ -5,9 +5,9 @@ include natron.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${HOME}/.Natron 8nodeny ${HOME}/.Natron
9noblacklist ${HOME}/.cache/INRIA/Natron 9nodeny ${HOME}/.cache/INRIA/Natron
10noblacklist ${HOME}/.config/INRIA 10nodeny ${HOME}/.config/INRIA
11 11
12# Allow python (blacklisted by disable-interpreters.inc) 12# Allow python (blacklisted by disable-interpreters.inc)
13include allow-python2.inc 13include allow-python2.inc
diff --git a/etc/profile-m-z/ncdu.profile b/etc/profile-m-z/ncdu.profile
index 063e30366..38646dc90 100644
--- a/etc/profile-m-z/ncdu.profile
+++ b/etc/profile-m-z/ncdu.profile
@@ -6,7 +6,7 @@ include ncdu.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9blacklist ${RUNUSER}/wayland-* 9deny ${RUNUSER}/wayland-*
10 10
11include disable-exec.inc 11include disable-exec.inc
12 12
diff --git a/etc/profile-m-z/neochat.profile b/etc/profile-m-z/neochat.profile
index 9f00448c8..ceb885908 100644
--- a/etc/profile-m-z/neochat.profile
+++ b/etc/profile-m-z/neochat.profile
@@ -6,12 +6,12 @@ include neochat.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.cache/KDE/neochat 9nodeny ${HOME}/.cache/KDE/neochat
10noblacklist ${HOME}/.config/KDE 10nodeny ${HOME}/.config/KDE
11noblacklist ${HOME}/.config/KDE/neochat 11nodeny ${HOME}/.config/KDE/neochat
12noblacklist ${HOME}/.config/neochatrc 12nodeny ${HOME}/.config/neochatrc
13noblacklist ${HOME}/.config/neochat.notifyrc 13nodeny ${HOME}/.config/neochat.notifyrc
14noblacklist ${HOME}/.local/share/KDE/neochat 14nodeny ${HOME}/.local/share/KDE/neochat
15 15
16include disable-common.inc 16include disable-common.inc
17include disable-devel.inc 17include disable-devel.inc
@@ -24,9 +24,9 @@ include disable-xdg.inc
24 24
25mkdir ${HOME}/.cache/KDE/neochat 25mkdir ${HOME}/.cache/KDE/neochat
26mkdir ${HOME}/.local/share/KDE/neochat 26mkdir ${HOME}/.local/share/KDE/neochat
27whitelist ${HOME}/.cache/KDE/neochat 27allow ${HOME}/.cache/KDE/neochat
28whitelist ${HOME}/.local/share/KDE/neochat 28allow ${HOME}/.local/share/KDE/neochat
29whitelist ${DOWNLOADS} 29allow ${DOWNLOADS}
30include whitelist-1793-workaround.inc 30include whitelist-1793-workaround.inc
31include whitelist-common.inc 31include whitelist-common.inc
32include whitelist-runuser-common.inc 32include whitelist-runuser-common.inc
diff --git a/etc/profile-m-z/neomutt.profile b/etc/profile-m-z/neomutt.profile
index fafa129e4..939d6f111 100644
--- a/etc/profile-m-z/neomutt.profile
+++ b/etc/profile-m-z/neomutt.profile
@@ -7,38 +7,38 @@ include neomutt.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10noblacklist ${DOCUMENTS} 10nodeny ${DOCUMENTS}
11noblacklist ${HOME}/.Mail 11nodeny ${HOME}/.Mail
12noblacklist ${HOME}/.bogofilter 12nodeny ${HOME}/.bogofilter
13noblacklist ${HOME}/.config/mutt 13nodeny ${HOME}/.config/mutt
14noblacklist ${HOME}/.config/nano 14nodeny ${HOME}/.config/nano
15noblacklist ${HOME}/.config/neomutt 15nodeny ${HOME}/.config/neomutt
16noblacklist ${HOME}/.elinks 16nodeny ${HOME}/.elinks
17noblacklist ${HOME}/.emacs 17nodeny ${HOME}/.emacs
18noblacklist ${HOME}/.emacs.d 18nodeny ${HOME}/.emacs.d
19noblacklist ${HOME}/.gnupg 19nodeny ${HOME}/.gnupg
20noblacklist ${HOME}/.mail 20nodeny ${HOME}/.mail
21noblacklist ${HOME}/.mailcap 21nodeny ${HOME}/.mailcap
22noblacklist ${HOME}/.msmtprc 22nodeny ${HOME}/.msmtprc
23noblacklist ${HOME}/.mutt 23nodeny ${HOME}/.mutt
24noblacklist ${HOME}/.muttrc 24nodeny ${HOME}/.muttrc
25noblacklist ${HOME}/.nanorc 25nodeny ${HOME}/.nanorc
26noblacklist ${HOME}/.neomutt 26nodeny ${HOME}/.neomutt
27noblacklist ${HOME}/.neomuttrc 27nodeny ${HOME}/.neomuttrc
28noblacklist ${HOME}/.signature 28nodeny ${HOME}/.signature
29noblacklist ${HOME}/.vim 29nodeny ${HOME}/.vim
30noblacklist ${HOME}/.viminfo 30nodeny ${HOME}/.viminfo
31noblacklist ${HOME}/.vimrc 31nodeny ${HOME}/.vimrc
32noblacklist ${HOME}/.w3m 32nodeny ${HOME}/.w3m
33noblacklist ${HOME}/Mail 33nodeny ${HOME}/Mail
34noblacklist ${HOME}/mail 34nodeny ${HOME}/mail
35noblacklist ${HOME}/postponed 35nodeny ${HOME}/postponed
36noblacklist ${HOME}/sent 36nodeny ${HOME}/sent
37noblacklist /var/mail 37nodeny /var/mail
38noblacklist /var/spool/mail 38nodeny /var/spool/mail
39 39
40blacklist /tmp/.X11-unix 40deny /tmp/.X11-unix
41blacklist ${RUNUSER}/wayland-* 41deny ${RUNUSER}/wayland-*
42 42
43include allow-lua.inc 43include allow-lua.inc
44 44
@@ -76,39 +76,39 @@ mkfile ${HOME}/.neomuttrc
76mkfile ${HOME}/.signature 76mkfile ${HOME}/.signature
77mkfile ${HOME}/.viminfo 77mkfile ${HOME}/.viminfo
78mkfile ${HOME}/.vimrc 78mkfile ${HOME}/.vimrc
79whitelist ${DOCUMENTS} 79allow ${DOCUMENTS}
80whitelist ${DOWNLOADS} 80allow ${DOWNLOADS}
81whitelist ${HOME}/.Mail 81allow ${HOME}/.Mail
82whitelist ${HOME}/.bogofilter 82allow ${HOME}/.bogofilter
83whitelist ${HOME}/.config/mutt 83allow ${HOME}/.config/mutt
84whitelist ${HOME}/.config/nano 84allow ${HOME}/.config/nano
85whitelist ${HOME}/.config/neomutt 85allow ${HOME}/.config/neomutt
86whitelist ${HOME}/.elinks 86allow ${HOME}/.elinks
87whitelist ${HOME}/.emacs 87allow ${HOME}/.emacs
88whitelist ${HOME}/.emacs.d 88allow ${HOME}/.emacs.d
89whitelist ${HOME}/.gnupg 89allow ${HOME}/.gnupg
90whitelist ${HOME}/.mail 90allow ${HOME}/.mail
91whitelist ${HOME}/.mailcap 91allow ${HOME}/.mailcap
92whitelist ${HOME}/.msmtprc 92allow ${HOME}/.msmtprc
93whitelist ${HOME}/.mutt 93allow ${HOME}/.mutt
94whitelist ${HOME}/.muttrc 94allow ${HOME}/.muttrc
95whitelist ${HOME}/.nanorc 95allow ${HOME}/.nanorc
96whitelist ${HOME}/.neomutt 96allow ${HOME}/.neomutt
97whitelist ${HOME}/.neomuttrc 97allow ${HOME}/.neomuttrc
98whitelist ${HOME}/.signature 98allow ${HOME}/.signature
99whitelist ${HOME}/.vim 99allow ${HOME}/.vim
100whitelist ${HOME}/.viminfo 100allow ${HOME}/.viminfo
101whitelist ${HOME}/.vimrc 101allow ${HOME}/.vimrc
102whitelist ${HOME}/.w3m 102allow ${HOME}/.w3m
103whitelist ${HOME}/Mail 103allow ${HOME}/Mail
104whitelist ${HOME}/mail 104allow ${HOME}/mail
105whitelist ${HOME}/postponed 105allow ${HOME}/postponed
106whitelist ${HOME}/sent 106allow ${HOME}/sent
107whitelist /usr/share/gnupg 107allow /usr/share/gnupg
108whitelist /usr/share/gnupg2 108allow /usr/share/gnupg2
109whitelist /usr/share/neomutt 109allow /usr/share/neomutt
110whitelist /var/mail 110allow /var/mail
111whitelist /var/spool/mail 111allow /var/spool/mail
112include whitelist-common.inc 112include whitelist-common.inc
113include whitelist-runuser-common.inc 113include whitelist-runuser-common.inc
114include whitelist-usr-share-common.inc 114include whitelist-usr-share-common.inc
diff --git a/etc/profile-m-z/netactview.profile b/etc/profile-m-z/netactview.profile
index 5d45dd7bc..68297c110 100644
--- a/etc/profile-m-z/netactview.profile
+++ b/etc/profile-m-z/netactview.profile
@@ -6,7 +6,7 @@ include netactview.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.netactview 9nodeny ${HOME}/.netactview
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -18,8 +18,8 @@ include disable-shell.inc
18include disable-xdg.inc 18include disable-xdg.inc
19 19
20mkfile ${HOME}/.netactview 20mkfile ${HOME}/.netactview
21whitelist ${HOME}/.netactview 21allow ${HOME}/.netactview
22whitelist /usr/share/netactview 22allow /usr/share/netactview
23include whitelist-common.inc 23include whitelist-common.inc
24include whitelist-usr-share-common.inc 24include whitelist-usr-share-common.inc
25include whitelist-var-common.inc 25include whitelist-var-common.inc
diff --git a/etc/profile-m-z/nethack-vultures.profile b/etc/profile-m-z/nethack-vultures.profile
index c9a537370..d5bf8a52a 100644
--- a/etc/profile-m-z/nethack-vultures.profile
+++ b/etc/profile-m-z/nethack-vultures.profile
@@ -6,7 +6,7 @@ include nethack.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.vultures 9nodeny ${HOME}/.vultures
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -16,8 +16,8 @@ include disable-passwdmgr.inc
16include disable-programs.inc 16include disable-programs.inc
17 17
18mkdir ${HOME}/.vultures 18mkdir ${HOME}/.vultures
19whitelist ${HOME}/.vultures 19allow ${HOME}/.vultures
20whitelist /var/log/vultures 20allow /var/log/vultures
21include whitelist-common.inc 21include whitelist-common.inc
22include whitelist-var-common.inc 22include whitelist-var-common.inc
23 23
diff --git a/etc/profile-m-z/nethack.profile b/etc/profile-m-z/nethack.profile
index b57abe260..23b57bb52 100644
--- a/etc/profile-m-z/nethack.profile
+++ b/etc/profile-m-z/nethack.profile
@@ -6,7 +6,7 @@ include nethack.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist /var/games/nethack 9nodeny /var/games/nethack
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -15,7 +15,7 @@ include disable-interpreters.inc
15include disable-passwdmgr.inc 15include disable-passwdmgr.inc
16include disable-programs.inc 16include disable-programs.inc
17 17
18whitelist /var/games/nethack 18allow /var/games/nethack
19include whitelist-common.inc 19include whitelist-common.inc
20include whitelist-var-common.inc 20include whitelist-var-common.inc
21 21
diff --git a/etc/profile-m-z/netsurf.profile b/etc/profile-m-z/netsurf.profile
index 0ddb7bbbe..b099d6f0c 100644
--- a/etc/profile-m-z/netsurf.profile
+++ b/etc/profile-m-z/netsurf.profile
@@ -6,8 +6,8 @@ include netsurf.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.cache/netsurf 9nodeny ${HOME}/.cache/netsurf
10noblacklist ${HOME}/.config/netsurf 10nodeny ${HOME}/.config/netsurf
11 11
12include disable-common.inc 12include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
@@ -16,9 +16,9 @@ include disable-programs.inc
16 16
17mkdir ${HOME}/.cache/netsurf 17mkdir ${HOME}/.cache/netsurf
18mkdir ${HOME}/.config/netsurf 18mkdir ${HOME}/.config/netsurf
19whitelist ${DOWNLOADS} 19allow ${DOWNLOADS}
20whitelist ${HOME}/.cache/netsurf 20allow ${HOME}/.cache/netsurf
21whitelist ${HOME}/.config/netsurf 21allow ${HOME}/.config/netsurf
22include whitelist-common.inc 22include whitelist-common.inc
23 23
24caps.drop all 24caps.drop all
diff --git a/etc/profile-m-z/neverball.profile b/etc/profile-m-z/neverball.profile
index ecfbb14e4..dad90a66c 100644
--- a/etc/profile-m-z/neverball.profile
+++ b/etc/profile-m-z/neverball.profile
@@ -6,7 +6,7 @@ include neverball.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.neverball 9nodeny ${HOME}/.neverball
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -18,8 +18,8 @@ include disable-shell.inc
18include disable-xdg.inc 18include disable-xdg.inc
19 19
20mkdir ${HOME}/.neverball 20mkdir ${HOME}/.neverball
21whitelist ${HOME}/.neverball 21allow ${HOME}/.neverball
22whitelist /usr/share/neverball 22allow /usr/share/neverball
23include whitelist-common.inc 23include whitelist-common.inc
24include whitelist-runuser-common.inc 24include whitelist-runuser-common.inc
25include whitelist-usr-share-common.inc 25include whitelist-usr-share-common.inc
diff --git a/etc/profile-m-z/newsbeuter.profile b/etc/profile-m-z/newsbeuter.profile
index 6efb19502..c26ba4be0 100644
--- a/etc/profile-m-z/newsbeuter.profile
+++ b/etc/profile-m-z/newsbeuter.profile
@@ -11,15 +11,15 @@ ignore include newsboat.local
11ignore mkdir ${HOME}/.config/newsboat 11ignore mkdir ${HOME}/.config/newsboat
12ignore mkdir ${HOME}/.local/share/newsboat 12ignore mkdir ${HOME}/.local/share/newsboat
13ignore mkdir ${HOME}/.newsboat 13ignore mkdir ${HOME}/.newsboat
14blacklist ${PATH}/newsboat 14deny ${PATH}/newsboat
15 15
16blacklist ${HOME}/.config/newsboat 16deny ${HOME}/.config/newsboat
17blacklist ${HOME}/.local/share/newsboat 17deny ${HOME}/.local/share/newsboat
18blacklist ${HOME}/.newsboat 18deny ${HOME}/.newsboat
19 19
20nowhitelist ${HOME}/.config/newsboat 20noallow ${HOME}/.config/newsboat
21nowhitelist ${HOME}/.local/share/newsboat 21noallow ${HOME}/.local/share/newsboat
22nowhitelist ${HOME}/.newsboat 22noallow ${HOME}/.newsboat
23 23
24mkdir ${HOME}/.config/newsbeuter 24mkdir ${HOME}/.config/newsbeuter
25mkdir ${HOME}/.local/share/newsbeuter 25mkdir ${HOME}/.local/share/newsbeuter
diff --git a/etc/profile-m-z/newsboat.profile b/etc/profile-m-z/newsboat.profile
index 13bc3a615..e34752b55 100644
--- a/etc/profile-m-z/newsboat.profile
+++ b/etc/profile-m-z/newsboat.profile
@@ -6,12 +6,12 @@ include newsboat.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/newsbeuter 9nodeny ${HOME}/.config/newsbeuter
10noblacklist ${HOME}/.config/newsboat 10nodeny ${HOME}/.config/newsboat
11noblacklist ${HOME}/.local/share/newsbeuter 11nodeny ${HOME}/.local/share/newsbeuter
12noblacklist ${HOME}/.local/share/newsboat 12nodeny ${HOME}/.local/share/newsboat
13noblacklist ${HOME}/.newsbeuter 13nodeny ${HOME}/.newsbeuter
14noblacklist ${HOME}/.newsboat 14nodeny ${HOME}/.newsboat
15 15
16include disable-common.inc 16include disable-common.inc
17include disable-devel.inc 17include disable-devel.inc
@@ -24,12 +24,12 @@ include disable-xdg.inc
24mkdir ${HOME}/.config/newsboat 24mkdir ${HOME}/.config/newsboat
25mkdir ${HOME}/.local/share/newsboat 25mkdir ${HOME}/.local/share/newsboat
26mkdir ${HOME}/.newsboat 26mkdir ${HOME}/.newsboat
27whitelist ${HOME}/.config/newsbeuter 27allow ${HOME}/.config/newsbeuter
28whitelist ${HOME}/.config/newsboat 28allow ${HOME}/.config/newsboat
29whitelist ${HOME}/.local/share/newsbeuter 29allow ${HOME}/.local/share/newsbeuter
30whitelist ${HOME}/.local/share/newsboat 30allow ${HOME}/.local/share/newsboat
31whitelist ${HOME}/.newsbeuter 31allow ${HOME}/.newsbeuter
32whitelist ${HOME}/.newsboat 32allow ${HOME}/.newsboat
33include whitelist-common.inc 33include whitelist-common.inc
34include whitelist-runuser-common.inc 34include whitelist-runuser-common.inc
35include whitelist-var-common.inc 35include whitelist-var-common.inc
diff --git a/etc/profile-m-z/newsflash.profile b/etc/profile-m-z/newsflash.profile
index 18d8c6ed4..273628ea2 100644
--- a/etc/profile-m-z/newsflash.profile
+++ b/etc/profile-m-z/newsflash.profile
@@ -6,9 +6,9 @@ include newsflash.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.cache/NewsFlashGTK 9nodeny ${HOME}/.cache/NewsFlashGTK
10noblacklist ${HOME}/.config/news-flash 10nodeny ${HOME}/.config/news-flash
11noblacklist ${HOME}/.local/share/news-flash 11nodeny ${HOME}/.local/share/news-flash
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
@@ -22,9 +22,9 @@ include disable-xdg.inc
22mkdir ${HOME}/.cache/NewsFlashGTK 22mkdir ${HOME}/.cache/NewsFlashGTK
23mkdir ${HOME}/.config/news-flash 23mkdir ${HOME}/.config/news-flash
24mkdir ${HOME}/.local/share/news-flash 24mkdir ${HOME}/.local/share/news-flash
25whitelist ${HOME}/.cache/NewsFlashGTK 25allow ${HOME}/.cache/NewsFlashGTK
26whitelist ${HOME}/.config/news-flash 26allow ${HOME}/.config/news-flash
27whitelist ${HOME}/.local/share/news-flash 27allow ${HOME}/.local/share/news-flash
28include whitelist-common.inc 28include whitelist-common.inc
29include whitelist-runuser-common.inc 29include whitelist-runuser-common.inc
30include whitelist-usr-share-common.inc 30include whitelist-usr-share-common.inc
diff --git a/etc/profile-m-z/nextcloud.profile b/etc/profile-m-z/nextcloud.profile
index 9fd76fbe7..7ba46691d 100644
--- a/etc/profile-m-z/nextcloud.profile
+++ b/etc/profile-m-z/nextcloud.profile
@@ -6,9 +6,9 @@ include nextcloud.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/Nextcloud 9nodeny ${HOME}/Nextcloud
10noblacklist ${HOME}/.config/Nextcloud 10nodeny ${HOME}/.config/Nextcloud
11noblacklist ${HOME}/.local/share/Nextcloud 11nodeny ${HOME}/.local/share/Nextcloud
12# Add the next lines to your nextcloud.local to allow sync in more directories. 12# Add the next lines to your nextcloud.local to allow sync in more directories.
13#noblacklist ${DOCUMENTS} 13#noblacklist ${DOCUMENTS}
14#noblacklist ${MUSIC} 14#noblacklist ${MUSIC}
@@ -27,9 +27,9 @@ include disable-xdg.inc
27mkdir ${HOME}/Nextcloud 27mkdir ${HOME}/Nextcloud
28mkdir ${HOME}/.config/Nextcloud 28mkdir ${HOME}/.config/Nextcloud
29mkdir ${HOME}/.local/share/Nextcloud 29mkdir ${HOME}/.local/share/Nextcloud
30whitelist ${HOME}/Nextcloud 30allow ${HOME}/Nextcloud
31whitelist ${HOME}/.config/Nextcloud 31allow ${HOME}/.config/Nextcloud
32whitelist ${HOME}/.local/share/Nextcloud 32allow ${HOME}/.local/share/Nextcloud
33# Add the next lines to your nextcloud.local to allow sync in more directories. 33# Add the next lines to your nextcloud.local to allow sync in more directories.
34#whitelist ${DOCUMENTS} 34#whitelist ${DOCUMENTS}
35#whitelist ${MUSIC} 35#whitelist ${MUSIC}
diff --git a/etc/profile-m-z/nheko.profile b/etc/profile-m-z/nheko.profile
index f8062891c..0149e0737 100644
--- a/etc/profile-m-z/nheko.profile
+++ b/etc/profile-m-z/nheko.profile
@@ -6,9 +6,9 @@ include nheko.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.cache/nheko 9nodeny ${HOME}/.cache/nheko
10noblacklist ${HOME}/.config/nheko 10nodeny ${HOME}/.config/nheko
11noblacklist ${HOME}/.local/share/nheko 11nodeny ${HOME}/.local/share/nheko
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
@@ -22,10 +22,10 @@ include disable-xdg.inc
22mkdir ${HOME}/.cache/nheko 22mkdir ${HOME}/.cache/nheko
23mkdir ${HOME}/.config/nheko 23mkdir ${HOME}/.config/nheko
24mkdir ${HOME}/.local/share/nheko 24mkdir ${HOME}/.local/share/nheko
25whitelist ${HOME}/.cache/nheko 25allow ${HOME}/.cache/nheko
26whitelist ${HOME}/.config/nheko 26allow ${HOME}/.config/nheko
27whitelist ${HOME}/.local/share/nheko 27allow ${HOME}/.local/share/nheko
28whitelist ${DOWNLOADS} 28allow ${DOWNLOADS}
29include whitelist-common.inc 29include whitelist-common.inc
30include whitelist-runuser-common.inc 30include whitelist-runuser-common.inc
31include whitelist-usr-share-common.inc 31include whitelist-usr-share-common.inc
diff --git a/etc/profile-m-z/nicotine.profile b/etc/profile-m-z/nicotine.profile
index 1c7dbc009..b31a7babf 100644
--- a/etc/profile-m-z/nicotine.profile
+++ b/etc/profile-m-z/nicotine.profile
@@ -6,7 +6,7 @@ include nicotine.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.nicotine 9nodeny ${HOME}/.nicotine
10 10
11# Allow python (blacklisted by disable-interpreters.inc) 11# Allow python (blacklisted by disable-interpreters.inc)
12include allow-python2.inc 12include allow-python2.inc
@@ -21,9 +21,9 @@ include disable-shell.inc
21include disable-xdg.inc 21include disable-xdg.inc
22 22
23mkdir ${HOME}/.nicotine 23mkdir ${HOME}/.nicotine
24whitelist ${DOWNLOADS} 24allow ${DOWNLOADS}
25whitelist ${HOME}/.nicotine 25allow ${HOME}/.nicotine
26whitelist /usr/share/GeoIP 26allow /usr/share/GeoIP
27include whitelist-common.inc 27include whitelist-common.inc
28include whitelist-runuser-common.inc 28include whitelist-runuser-common.inc
29include whitelist-usr-share-common.inc 29include whitelist-usr-share-common.inc
diff --git a/etc/profile-m-z/nitroshare.profile b/etc/profile-m-z/nitroshare.profile
index 8dba84f02..70fffd5d4 100644
--- a/etc/profile-m-z/nitroshare.profile
+++ b/etc/profile-m-z/nitroshare.profile
@@ -6,8 +6,8 @@ include nitroshare.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/Nathan Osman 9nodeny ${HOME}/.config/Nathan Osman
10noblacklist ${HOME}/.config/NitroShare 10nodeny ${HOME}/.config/NitroShare
11 11
12# Allow python (blacklisted by disable-interpreters.inc) 12# Allow python (blacklisted by disable-interpreters.inc)
13include allow-python2.inc 13include allow-python2.inc
diff --git a/etc/profile-m-z/nodejs-common.profile b/etc/profile-m-z/nodejs-common.profile
index fa69f9214..7981ba6ae 100644
--- a/etc/profile-m-z/nodejs-common.profile
+++ b/etc/profile-m-z/nodejs-common.profile
@@ -7,22 +7,22 @@ include nodejs-common.local
7# added by caller profile 7# added by caller profile
8#include globals.local 8#include globals.local
9 9
10blacklist /tmp/.X11-unix 10deny /tmp/.X11-unix
11blacklist ${RUNUSER} 11deny ${RUNUSER}
12 12
13ignore read-only ${HOME}/.npm-packages 13ignore read-only ${HOME}/.npm-packages
14ignore read-only ${HOME}/.npmrc 14ignore read-only ${HOME}/.npmrc
15ignore read-only ${HOME}/.nvm 15ignore read-only ${HOME}/.nvm
16ignore read-only ${HOME}/.yarnrc 16ignore read-only ${HOME}/.yarnrc
17 17
18noblacklist ${HOME}/.node-gyp 18nodeny ${HOME}/.node-gyp
19noblacklist ${HOME}/.npm 19nodeny ${HOME}/.npm
20noblacklist ${HOME}/.npmrc 20nodeny ${HOME}/.npmrc
21noblacklist ${HOME}/.nvm 21nodeny ${HOME}/.nvm
22noblacklist ${HOME}/.yarn 22nodeny ${HOME}/.yarn
23noblacklist ${HOME}/.yarn-config 23nodeny ${HOME}/.yarn-config
24noblacklist ${HOME}/.yarncache 24nodeny ${HOME}/.yarncache
25noblacklist ${HOME}/.yarnrc 25nodeny ${HOME}/.yarnrc
26 26
27ignore noexec ${HOME} 27ignore noexec ${HOME}
28 28
@@ -58,9 +58,9 @@ include disable-xdg.inc
58#whitelist ${HOME}/Projects 58#whitelist ${HOME}/Projects
59#include whitelist-common.inc 59#include whitelist-common.inc
60 60
61whitelist /usr/share/doc/node 61allow /usr/share/doc/node
62whitelist /usr/share/nvm 62allow /usr/share/nvm
63whitelist /usr/share/systemtap/tapset/node.stp 63allow /usr/share/systemtap/tapset/node.stp
64include whitelist-runuser-common.inc 64include whitelist-runuser-common.inc
65include whitelist-usr-share-common.inc 65include whitelist-usr-share-common.inc
66include whitelist-var-common.inc 66include whitelist-var-common.inc
diff --git a/etc/profile-m-z/nomacs.profile b/etc/profile-m-z/nomacs.profile
index a36dee874..80fbd0fcb 100644
--- a/etc/profile-m-z/nomacs.profile
+++ b/etc/profile-m-z/nomacs.profile
@@ -6,10 +6,10 @@ include nomacs.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/nomacs 9nodeny ${HOME}/.config/nomacs
10noblacklist ${HOME}/.local/share/nomacs 10nodeny ${HOME}/.local/share/nomacs
11noblacklist ${HOME}/.local/share/data/nomacs 11nodeny ${HOME}/.local/share/data/nomacs
12noblacklist ${PICTURES} 12nodeny ${PICTURES}
13 13
14include disable-common.inc 14include disable-common.inc
15include disable-devel.inc 15include disable-devel.inc
diff --git a/etc/profile-m-z/notify-send.profile b/etc/profile-m-z/notify-send.profile
index 650118c98..a3bcc040c 100644
--- a/etc/profile-m-z/notify-send.profile
+++ b/etc/profile-m-z/notify-send.profile
@@ -7,7 +7,7 @@ include notify-send.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10blacklist ${RUNUSER}/wayland-* 10deny ${RUNUSER}/wayland-*
11 11
12include disable-common.inc 12include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
diff --git a/etc/profile-m-z/nslookup.profile b/etc/profile-m-z/nslookup.profile
index c7a131a2c..b3002ad0e 100644
--- a/etc/profile-m-z/nslookup.profile
+++ b/etc/profile-m-z/nslookup.profile
@@ -7,10 +7,10 @@ include nslookup.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10blacklist /tmp/.X11-unix 10deny /tmp/.X11-unix
11blacklist ${RUNUSER} 11deny ${RUNUSER}
12 12
13noblacklist ${PATH}/nslookup 13nodeny ${PATH}/nslookup
14 14
15include disable-common.inc 15include disable-common.inc
16include disable-devel.inc 16include disable-devel.inc
@@ -20,7 +20,7 @@ include disable-passwdmgr.inc
20include disable-programs.inc 20include disable-programs.inc
21include disable-xdg.inc 21include disable-xdg.inc
22 22
23whitelist ${HOME}/.nslookuprc 23allow ${HOME}/.nslookuprc
24include whitelist-common.inc 24include whitelist-common.inc
25include whitelist-usr-share-common.inc 25include whitelist-usr-share-common.inc
26include whitelist-var-common.inc 26include whitelist-var-common.inc
diff --git a/etc/profile-m-z/nuclear.profile b/etc/profile-m-z/nuclear.profile
index 886403b9e..67f54f9fc 100644
--- a/etc/profile-m-z/nuclear.profile
+++ b/etc/profile-m-z/nuclear.profile
@@ -8,12 +8,12 @@ include globals.local
8 8
9ignore dbus-user 9ignore dbus-user
10 10
11noblacklist ${HOME}/.config/nuclear 11nodeny ${HOME}/.config/nuclear
12 12
13include disable-shell.inc 13include disable-shell.inc
14 14
15mkdir ${HOME}/.config/nuclear 15mkdir ${HOME}/.config/nuclear
16whitelist ${HOME}/.config/nuclear 16allow ${HOME}/.config/nuclear
17 17
18no3d 18no3d
19 19
diff --git a/etc/profile-m-z/nylas.profile b/etc/profile-m-z/nylas.profile
index fe0c2116b..ee7710b9c 100644
--- a/etc/profile-m-z/nylas.profile
+++ b/etc/profile-m-z/nylas.profile
@@ -5,8 +5,8 @@ include nylas.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${HOME}/.config/Nylas Mail 8nodeny ${HOME}/.config/Nylas Mail
9noblacklist ${HOME}/.nylas-mail 9nodeny ${HOME}/.nylas-mail
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -16,9 +16,9 @@ include disable-programs.inc
16 16
17mkdir ${HOME}/.config/Nylas Mail 17mkdir ${HOME}/.config/Nylas Mail
18mkdir ${HOME}/.nylas-mail 18mkdir ${HOME}/.nylas-mail
19whitelist ${DOWNLOADS} 19allow ${DOWNLOADS}
20whitelist ${HOME}/.config/Nylas Mail 20allow ${HOME}/.config/Nylas Mail
21whitelist ${HOME}/.nylas-mail 21allow ${HOME}/.nylas-mail
22include whitelist-common.inc 22include whitelist-common.inc
23 23
24caps.drop all 24caps.drop all
diff --git a/etc/profile-m-z/nyx.profile b/etc/profile-m-z/nyx.profile
index d040d42af..1d606f70c 100644
--- a/etc/profile-m-z/nyx.profile
+++ b/etc/profile-m-z/nyx.profile
@@ -10,7 +10,7 @@ include globals.local
10include allow-python2.inc 10include allow-python2.inc
11include allow-python3.inc 11include allow-python3.inc
12 12
13noblacklist ${HOME}/.nyx 13nodeny ${HOME}/.nyx
14 14
15include disable-common.inc 15include disable-common.inc
16include disable-devel.inc 16include disable-devel.inc
@@ -22,7 +22,7 @@ include disable-shell.inc
22include disable-xdg.inc 22include disable-xdg.inc
23 23
24mkdir ${HOME}/.nyx 24mkdir ${HOME}/.nyx
25whitelist ${HOME}/.nyx 25allow ${HOME}/.nyx
26include whitelist-common.inc 26include whitelist-common.inc
27include whitelist-var-common.inc 27include whitelist-var-common.inc
28 28
diff --git a/etc/profile-m-z/obs.profile b/etc/profile-m-z/obs.profile
index 9345cee4f..f70bdc55a 100644
--- a/etc/profile-m-z/obs.profile
+++ b/etc/profile-m-z/obs.profile
@@ -5,10 +5,10 @@ include obs.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${HOME}/.config/obs-studio 8nodeny ${HOME}/.config/obs-studio
9noblacklist ${MUSIC} 9nodeny ${MUSIC}
10noblacklist ${PICTURES} 10nodeny ${PICTURES}
11noblacklist ${VIDEOS} 11nodeny ${VIDEOS}
12 12
13# Allow python (blacklisted by disable-interpreters.inc) 13# Allow python (blacklisted by disable-interpreters.inc)
14include allow-python2.inc 14include allow-python2.inc
diff --git a/etc/profile-m-z/ocenaudio.profile b/etc/profile-m-z/ocenaudio.profile
index 7be68a201..792c2ffc6 100644
--- a/etc/profile-m-z/ocenaudio.profile
+++ b/etc/profile-m-z/ocenaudio.profile
@@ -6,9 +6,9 @@ include ocenaudio.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.local/share/ocenaudio 9nodeny ${HOME}/.local/share/ocenaudio
10noblacklist ${DOCUMENTS} 10nodeny ${DOCUMENTS}
11noblacklist ${MUSIC} 11nodeny ${MUSIC}
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
diff --git a/etc/profile-m-z/odt2txt.profile b/etc/profile-m-z/odt2txt.profile
index 6163d2e22..61b71ec10 100644
--- a/etc/profile-m-z/odt2txt.profile
+++ b/etc/profile-m-z/odt2txt.profile
@@ -6,9 +6,9 @@ include odt2txt.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9blacklist ${RUNUSER}/wayland-* 9deny ${RUNUSER}/wayland-*
10 10
11noblacklist ${DOCUMENTS} 11nodeny ${DOCUMENTS}
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
diff --git a/etc/profile-m-z/okular.profile b/etc/profile-m-z/okular.profile
index ab8ccf623..feeed86cb 100644
--- a/etc/profile-m-z/okular.profile
+++ b/etc/profile-m-z/okular.profile
@@ -6,18 +6,18 @@ include okular.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.cache/okular 9nodeny ${HOME}/.cache/okular
10noblacklist ${HOME}/.config/okularpartrc 10nodeny ${HOME}/.config/okularpartrc
11noblacklist ${HOME}/.config/okularrc 11nodeny ${HOME}/.config/okularrc
12noblacklist ${HOME}/.kde/share/apps/okular 12nodeny ${HOME}/.kde/share/apps/okular
13noblacklist ${HOME}/.kde/share/config/okularpartrc 13nodeny ${HOME}/.kde/share/config/okularpartrc
14noblacklist ${HOME}/.kde/share/config/okularrc 14nodeny ${HOME}/.kde/share/config/okularrc
15noblacklist ${HOME}/.kde4/share/apps/okular 15nodeny ${HOME}/.kde4/share/apps/okular
16noblacklist ${HOME}/.kde4/share/config/okularpartrc 16nodeny ${HOME}/.kde4/share/config/okularpartrc
17noblacklist ${HOME}/.kde4/share/config/okularrc 17nodeny ${HOME}/.kde4/share/config/okularrc
18noblacklist ${HOME}/.local/share/kxmlgui5/okular 18nodeny ${HOME}/.local/share/kxmlgui5/okular
19noblacklist ${HOME}/.local/share/okular 19nodeny ${HOME}/.local/share/okular
20noblacklist ${DOCUMENTS} 20nodeny ${DOCUMENTS}
21 21
22include disable-common.inc 22include disable-common.inc
23include disable-devel.inc 23include disable-devel.inc
@@ -28,15 +28,15 @@ include disable-programs.inc
28include disable-shell.inc 28include disable-shell.inc
29include disable-xdg.inc 29include disable-xdg.inc
30 30
31whitelist /usr/share/config.kcfg/gssettings.kcfg 31allow /usr/share/config.kcfg/gssettings.kcfg
32whitelist /usr/share/config.kcfg/pdfsettings.kcfg 32allow /usr/share/config.kcfg/pdfsettings.kcfg
33whitelist /usr/share/config.kcfg/okular.kcfg 33allow /usr/share/config.kcfg/okular.kcfg
34whitelist /usr/share/config.kcfg/okular_core.kcfg 34allow /usr/share/config.kcfg/okular_core.kcfg
35whitelist /usr/share/ghostscript 35allow /usr/share/ghostscript
36whitelist /usr/share/kconf_update/okular.upd 36allow /usr/share/kconf_update/okular.upd
37whitelist /usr/share/kxmlgui5/okular 37allow /usr/share/kxmlgui5/okular
38whitelist /usr/share/okular 38allow /usr/share/okular
39whitelist /usr/share/poppler 39allow /usr/share/poppler
40include whitelist-runuser-common.inc 40include whitelist-runuser-common.inc
41include whitelist-usr-share-common.inc 41include whitelist-usr-share-common.inc
42include whitelist-var-common.inc 42include whitelist-var-common.inc
diff --git a/etc/profile-m-z/onboard.profile b/etc/profile-m-z/onboard.profile
index 5b367b639..748d17995 100644
--- a/etc/profile-m-z/onboard.profile
+++ b/etc/profile-m-z/onboard.profile
@@ -6,7 +6,7 @@ include onboard.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/onboard 9nodeny ${HOME}/.config/onboard
10 10
11# Allow python (blacklisted by disable-interpreters.inc) 11# Allow python (blacklisted by disable-interpreters.inc)
12include allow-python2.inc 12include allow-python2.inc
@@ -22,8 +22,8 @@ include disable-shell.inc
22include disable-xdg.inc 22include disable-xdg.inc
23 23
24mkdir ${HOME}/.config/onboard 24mkdir ${HOME}/.config/onboard
25whitelist ${HOME}/.config/onboard 25allow ${HOME}/.config/onboard
26whitelist /usr/share/onboard 26allow /usr/share/onboard
27include whitelist-common.inc 27include whitelist-common.inc
28include whitelist-usr-share-common.inc 28include whitelist-usr-share-common.inc
29include whitelist-runuser-common.inc 29include whitelist-runuser-common.inc
diff --git a/etc/profile-m-z/onionshare-gui.profile b/etc/profile-m-z/onionshare-gui.profile
index 960df9034..188818a7f 100644
--- a/etc/profile-m-z/onionshare-gui.profile
+++ b/etc/profile-m-z/onionshare-gui.profile
@@ -5,7 +5,7 @@ include onionshare-gui.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${HOME}/.config/onionshare 8nodeny ${HOME}/.config/onionshare
9 9
10# Allow python (blacklisted by disable-interpreters.inc) 10# Allow python (blacklisted by disable-interpreters.inc)
11include allow-python3.inc 11include allow-python3.inc
diff --git a/etc/profile-m-z/open-invaders.profile b/etc/profile-m-z/open-invaders.profile
index 7a840d4a9..6e2b31def 100644
--- a/etc/profile-m-z/open-invaders.profile
+++ b/etc/profile-m-z/open-invaders.profile
@@ -6,7 +6,7 @@ include open-invaders.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.openinvaders 9nodeny ${HOME}/.openinvaders
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -17,7 +17,7 @@ include disable-programs.inc
17include disable-shell.inc 17include disable-shell.inc
18 18
19mkdir ${HOME}/.openinvaders 19mkdir ${HOME}/.openinvaders
20whitelist ${HOME}/.openinvaders 20allow ${HOME}/.openinvaders
21include whitelist-common.inc 21include whitelist-common.inc
22include whitelist-var-common.inc 22include whitelist-var-common.inc
23 23
diff --git a/etc/profile-m-z/openarena.profile b/etc/profile-m-z/openarena.profile
index 36ce0316f..dfc78e5a9 100644
--- a/etc/profile-m-z/openarena.profile
+++ b/etc/profile-m-z/openarena.profile
@@ -6,7 +6,7 @@ include openarena.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.openarena 9nodeny ${HOME}/.openarena
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -17,8 +17,8 @@ include disable-programs.inc
17include disable-xdg.inc 17include disable-xdg.inc
18 18
19mkdir ${HOME}/.openarena 19mkdir ${HOME}/.openarena
20whitelist ${HOME}/.openarena 20allow ${HOME}/.openarena
21whitelist /usr/share/openarena 21allow /usr/share/openarena
22include whitelist-common.inc 22include whitelist-common.inc
23include whitelist-runuser-common.inc 23include whitelist-runuser-common.inc
24include whitelist-usr-share-common.inc 24include whitelist-usr-share-common.inc
diff --git a/etc/profile-m-z/openbox.profile b/etc/profile-m-z/openbox.profile
index b49fd9932..5a6b378f0 100644
--- a/etc/profile-m-z/openbox.profile
+++ b/etc/profile-m-z/openbox.profile
@@ -7,7 +7,7 @@ include openbox.local
7include globals.local 7include globals.local
8 8
9# all applications started in openbox will run in this profile 9# all applications started in openbox will run in this profile
10noblacklist ${HOME}/.config/openbox 10nodeny ${HOME}/.config/openbox
11include disable-common.inc 11include disable-common.inc
12 12
13caps.drop all 13caps.drop all
diff --git a/etc/profile-m-z/opencity.profile b/etc/profile-m-z/opencity.profile
index a3d371e15..268e7cee3 100644
--- a/etc/profile-m-z/opencity.profile
+++ b/etc/profile-m-z/opencity.profile
@@ -6,7 +6,7 @@ include opencity.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.opencity 9nodeny ${HOME}/.opencity
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -18,7 +18,7 @@ include disable-shell.inc
18include disable-xdg.inc 18include disable-xdg.inc
19 19
20mkdir ${HOME}/.opencity 20mkdir ${HOME}/.opencity
21whitelist ${HOME}/.opencity 21allow ${HOME}/.opencity
22include whitelist-common.inc 22include whitelist-common.inc
23include whitelist-var-common.inc 23include whitelist-var-common.inc
24 24
diff --git a/etc/profile-m-z/openclonk.profile b/etc/profile-m-z/openclonk.profile
index 32b40df42..588191cb3 100644
--- a/etc/profile-m-z/openclonk.profile
+++ b/etc/profile-m-z/openclonk.profile
@@ -6,7 +6,7 @@ include openclonk.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.clonk 9nodeny ${HOME}/.clonk
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -18,7 +18,7 @@ include disable-shell.inc
18include disable-xdg.inc 18include disable-xdg.inc
19 19
20mkdir ${HOME}/.clonk 20mkdir ${HOME}/.clonk
21whitelist ${HOME}/.clonk 21allow ${HOME}/.clonk
22include whitelist-common.inc 22include whitelist-common.inc
23include whitelist-var-common.inc 23include whitelist-var-common.inc
24 24
diff --git a/etc/profile-m-z/openmw.profile b/etc/profile-m-z/openmw.profile
index d1fe67aed..95d507c98 100644
--- a/etc/profile-m-z/openmw.profile
+++ b/etc/profile-m-z/openmw.profile
@@ -6,8 +6,8 @@ include openmw.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/openmw 9nodeny ${HOME}/.config/openmw
10noblacklist ${HOME}/.local/share/openmw 10nodeny ${HOME}/.local/share/openmw
11 11
12include disable-common.inc 12include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
@@ -21,11 +21,11 @@ include disable-xdg.inc
21 21
22mkdir ${HOME}/.config/openmw 22mkdir ${HOME}/.config/openmw
23mkdir ${HOME}/.local/share/openmw 23mkdir ${HOME}/.local/share/openmw
24whitelist ${HOME}/.config/openmw 24allow ${HOME}/.config/openmw
25# Copy Morrowind data files into ${HOME}/.local/share/openmw or load them from /mnt. 25# Copy Morrowind data files into ${HOME}/.local/share/openmw or load them from /mnt.
26# Alternatively you can whitelist custom paths in your openmw.local. 26# Alternatively you can whitelist custom paths in your openmw.local.
27whitelist ${HOME}/.local/share/openmw 27allow ${HOME}/.local/share/openmw
28whitelist /usr/share/openmw 28allow /usr/share/openmw
29include whitelist-common.inc 29include whitelist-common.inc
30include whitelist-runuser-common.inc 30include whitelist-runuser-common.inc
31include whitelist-usr-share-common.inc 31include whitelist-usr-share-common.inc
diff --git a/etc/profile-m-z/openshot.profile b/etc/profile-m-z/openshot.profile
index 6118630c4..ebb536b3e 100644
--- a/etc/profile-m-z/openshot.profile
+++ b/etc/profile-m-z/openshot.profile
@@ -6,8 +6,8 @@ include openshot.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.openshot 9nodeny ${HOME}/.openshot
10noblacklist ${HOME}/.openshot_qt 10nodeny ${HOME}/.openshot_qt
11 11
12# Allow python (blacklisted by disable-interpreters.inc) 12# Allow python (blacklisted by disable-interpreters.inc)
13include allow-python3.inc 13include allow-python3.inc
@@ -19,8 +19,8 @@ include disable-interpreters.inc
19include disable-passwdmgr.inc 19include disable-passwdmgr.inc
20include disable-programs.inc 20include disable-programs.inc
21 21
22whitelist /usr/share/blender 22allow /usr/share/blender
23whitelist /usr/share/inkscape 23allow /usr/share/inkscape
24include whitelist-runuser-common.inc 24include whitelist-runuser-common.inc
25include whitelist-usr-share-common.inc 25include whitelist-usr-share-common.inc
26include whitelist-var-common.inc 26include whitelist-var-common.inc
diff --git a/etc/profile-m-z/openttd.profile b/etc/profile-m-z/openttd.profile
index 546958bb7..79c1f8ffa 100644
--- a/etc/profile-m-z/openttd.profile
+++ b/etc/profile-m-z/openttd.profile
@@ -6,7 +6,7 @@ include openttd.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.openttd 9nodeny ${HOME}/.openttd
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -18,7 +18,7 @@ include disable-shell.inc
18include disable-xdg.inc 18include disable-xdg.inc
19 19
20mkdir ${HOME}/.openttd 20mkdir ${HOME}/.openttd
21whitelist ${HOME}/.openttd 21allow ${HOME}/.openttd
22include whitelist-common.inc 22include whitelist-common.inc
23include whitelist-var-common.inc 23include whitelist-var-common.inc
24 24
diff --git a/etc/profile-m-z/opera-beta.profile b/etc/profile-m-z/opera-beta.profile
index 551f1aba4..548afc0b4 100644
--- a/etc/profile-m-z/opera-beta.profile
+++ b/etc/profile-m-z/opera-beta.profile
@@ -10,13 +10,13 @@ ignore whitelist /usr/share/chromium
10ignore include whitelist-runuser-common.inc 10ignore include whitelist-runuser-common.inc
11ignore include whitelist-usr-share-common.inc 11ignore include whitelist-usr-share-common.inc
12 12
13noblacklist ${HOME}/.cache/opera 13nodeny ${HOME}/.cache/opera
14noblacklist ${HOME}/.config/opera-beta 14nodeny ${HOME}/.config/opera-beta
15 15
16mkdir ${HOME}/.cache/opera 16mkdir ${HOME}/.cache/opera
17mkdir ${HOME}/.config/opera-beta 17mkdir ${HOME}/.config/opera-beta
18whitelist ${HOME}/.cache/opera 18allow ${HOME}/.cache/opera
19whitelist ${HOME}/.config/opera-beta 19allow ${HOME}/.config/opera-beta
20 20
21# Redirect 21# Redirect
22include chromium-common.profile 22include chromium-common.profile
diff --git a/etc/profile-m-z/opera.profile b/etc/profile-m-z/opera.profile
index 2c7c5fc35..5a3fe064e 100644
--- a/etc/profile-m-z/opera.profile
+++ b/etc/profile-m-z/opera.profile
@@ -11,16 +11,16 @@ ignore whitelist /usr/share/chromium
11ignore include whitelist-runuser-common.inc 11ignore include whitelist-runuser-common.inc
12ignore include whitelist-usr-share-common.inc 12ignore include whitelist-usr-share-common.inc
13 13
14noblacklist ${HOME}/.cache/opera 14nodeny ${HOME}/.cache/opera
15noblacklist ${HOME}/.config/opera 15nodeny ${HOME}/.config/opera
16noblacklist ${HOME}/.opera 16nodeny ${HOME}/.opera
17 17
18mkdir ${HOME}/.cache/opera 18mkdir ${HOME}/.cache/opera
19mkdir ${HOME}/.config/opera 19mkdir ${HOME}/.config/opera
20mkdir ${HOME}/.opera 20mkdir ${HOME}/.opera
21whitelist ${HOME}/.cache/opera 21allow ${HOME}/.cache/opera
22whitelist ${HOME}/.config/opera 22allow ${HOME}/.config/opera
23whitelist ${HOME}/.opera 23allow ${HOME}/.opera
24 24
25# Redirect 25# Redirect
26include chromium-common.profile 26include chromium-common.profile
diff --git a/etc/profile-m-z/orage.profile b/etc/profile-m-z/orage.profile
index 4e4d8bea5..a49cbdb91 100644
--- a/etc/profile-m-z/orage.profile
+++ b/etc/profile-m-z/orage.profile
@@ -6,8 +6,8 @@ include orage.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/orage 9nodeny ${HOME}/.config/orage
10noblacklist ${HOME}/.local/share/orage 10nodeny ${HOME}/.local/share/orage
11 11
12include disable-common.inc 12include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
diff --git a/etc/profile-m-z/ostrichriders.profile b/etc/profile-m-z/ostrichriders.profile
index 310b90919..ed881816e 100644
--- a/etc/profile-m-z/ostrichriders.profile
+++ b/etc/profile-m-z/ostrichriders.profile
@@ -6,7 +6,7 @@ include ostrichriders.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.ostrichriders 9nodeny ${HOME}/.ostrichriders
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -18,8 +18,8 @@ include disable-shell.inc
18include disable-xdg.inc 18include disable-xdg.inc
19 19
20mkdir ${HOME}/.ostrichriders 20mkdir ${HOME}/.ostrichriders
21whitelist ${HOME}/.ostrichriders 21allow ${HOME}/.ostrichriders
22whitelist /usr/share/ostrichriders 22allow /usr/share/ostrichriders
23include whitelist-common.inc 23include whitelist-common.inc
24include whitelist-usr-share-common.inc 24include whitelist-usr-share-common.inc
25include whitelist-var-common.inc 25include whitelist-var-common.inc
diff --git a/etc/profile-m-z/otter-browser.profile b/etc/profile-m-z/otter-browser.profile
index 20a4e25ed..bc9e730a1 100644
--- a/etc/profile-m-z/otter-browser.profile
+++ b/etc/profile-m-z/otter-browser.profile
@@ -8,10 +8,10 @@ include globals.local
8 8
9?BROWSER_ALLOW_DRM: ignore noexec ${HOME} 9?BROWSER_ALLOW_DRM: ignore noexec ${HOME}
10 10
11noblacklist ${HOME}/.cache/Otter 11nodeny ${HOME}/.cache/Otter
12noblacklist ${HOME}/.config/otter 12nodeny ${HOME}/.config/otter
13noblacklist ${HOME}/.pki 13nodeny ${HOME}/.pki
14noblacklist ${HOME}/.local/share/pki 14nodeny ${HOME}/.local/share/pki
15 15
16include disable-common.inc 16include disable-common.inc
17include disable-devel.inc 17include disable-devel.inc
@@ -25,12 +25,12 @@ mkdir ${HOME}/.cache/Otter
25mkdir ${HOME}/.config/otter 25mkdir ${HOME}/.config/otter
26mkdir ${HOME}/.pki 26mkdir ${HOME}/.pki
27mkdir ${HOME}/.local/share/pki 27mkdir ${HOME}/.local/share/pki
28whitelist ${DOWNLOADS} 28allow ${DOWNLOADS}
29whitelist ${HOME}/.cache/Otter 29allow ${HOME}/.cache/Otter
30whitelist ${HOME}/.config/otter 30allow ${HOME}/.config/otter
31whitelist ${HOME}/.pki 31allow ${HOME}/.pki
32whitelist ${HOME}/.local/share/pki 32allow ${HOME}/.local/share/pki
33whitelist /usr/share/otter-browser 33allow /usr/share/otter-browser
34include whitelist-common.inc 34include whitelist-common.inc
35include whitelist-runuser-common.inc 35include whitelist-runuser-common.inc
36include whitelist-usr-share-common.inc 36include whitelist-usr-share-common.inc
diff --git a/etc/profile-m-z/palemoon.profile b/etc/profile-m-z/palemoon.profile
index acb2ce176..503c141d8 100644
--- a/etc/profile-m-z/palemoon.profile
+++ b/etc/profile-m-z/palemoon.profile
@@ -5,13 +5,13 @@ include palemoon.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${HOME}/.cache/moonchild productions/pale moon 8nodeny ${HOME}/.cache/moonchild productions/pale moon
9noblacklist ${HOME}/.moonchild productions/pale moon 9nodeny ${HOME}/.moonchild productions/pale moon
10 10
11mkdir ${HOME}/.cache/moonchild productions/pale moon 11mkdir ${HOME}/.cache/moonchild productions/pale moon
12mkdir ${HOME}/.moonchild productions 12mkdir ${HOME}/.moonchild productions
13whitelist ${HOME}/.cache/moonchild productions/pale moon 13allow ${HOME}/.cache/moonchild productions/pale moon
14whitelist ${HOME}/.moonchild productions 14allow ${HOME}/.moonchild productions
15 15
16# Palemoon can use the full firejail seccomp filter (unlike firefox >= 60) 16# Palemoon can use the full firejail seccomp filter (unlike firefox >= 60)
17seccomp 17seccomp
diff --git a/etc/profile-m-z/pandoc.profile b/etc/profile-m-z/pandoc.profile
index 513b4119e..a59f53298 100644
--- a/etc/profile-m-z/pandoc.profile
+++ b/etc/profile-m-z/pandoc.profile
@@ -7,9 +7,9 @@ include pandoc.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10blacklist ${RUNUSER} 10deny ${RUNUSER}
11 11
12noblacklist ${DOCUMENTS} 12nodeny ${DOCUMENTS}
13 13
14include disable-common.inc 14include disable-common.inc
15include disable-devel.inc 15include disable-devel.inc
diff --git a/etc/profile-m-z/parole.profile b/etc/profile-m-z/parole.profile
index 0a4422a73..a277d1cbc 100644
--- a/etc/profile-m-z/parole.profile
+++ b/etc/profile-m-z/parole.profile
@@ -6,8 +6,8 @@ include parole.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${MUSIC} 9nodeny ${MUSIC}
10noblacklist ${VIDEOS} 10nodeny ${VIDEOS}
11 11
12include disable-common.inc 12include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
diff --git a/etc/profile-m-z/patch.profile b/etc/profile-m-z/patch.profile
index 0de968185..156c3956d 100644
--- a/etc/profile-m-z/patch.profile
+++ b/etc/profile-m-z/patch.profile
@@ -7,9 +7,9 @@ include patch.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10blacklist ${RUNUSER} 10deny ${RUNUSER}
11 11
12noblacklist ${DOCUMENTS} 12nodeny ${DOCUMENTS}
13 13
14include disable-common.inc 14include disable-common.inc
15include disable-devel.inc 15include disable-devel.inc
diff --git a/etc/profile-m-z/pavucontrol-qt.profile b/etc/profile-m-z/pavucontrol-qt.profile
index f96ba14d2..dcd69cdd0 100644
--- a/etc/profile-m-z/pavucontrol-qt.profile
+++ b/etc/profile-m-z/pavucontrol-qt.profile
@@ -7,10 +7,10 @@ include pavucontrol-qt.local
7# added by included profile 7# added by included profile
8#include globals.local 8#include globals.local
9 9
10noblacklist ${HOME}/.config/pavucontrol-qt 10nodeny ${HOME}/.config/pavucontrol-qt
11 11
12mkdir ${HOME}/.config/pavucontrol-qt 12mkdir ${HOME}/.config/pavucontrol-qt
13whitelist ${HOME}/.config/pavucontrol-qt 13allow ${HOME}/.config/pavucontrol-qt
14 14
15private-bin pavucontrol-qt 15private-bin pavucontrol-qt
16ignore private-lib 16ignore private-lib
diff --git a/etc/profile-m-z/pavucontrol.profile b/etc/profile-m-z/pavucontrol.profile
index b46fb3026..f44730c33 100644
--- a/etc/profile-m-z/pavucontrol.profile
+++ b/etc/profile-m-z/pavucontrol.profile
@@ -6,7 +6,7 @@ include pavucontrol.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/pavucontrol.ini 9nodeny ${HOME}/.config/pavucontrol.ini
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -19,8 +19,8 @@ include disable-xdg.inc
19# whitelisting in ${HOME} is broken, see #3112 19# whitelisting in ${HOME} is broken, see #3112
20#mkfile ${HOME}/.config/pavucontrol.ini 20#mkfile ${HOME}/.config/pavucontrol.ini
21#whitelist ${HOME}/.config/pavucontrol.ini 21#whitelist ${HOME}/.config/pavucontrol.ini
22whitelist /usr/share/pavucontrol 22allow /usr/share/pavucontrol
23whitelist /usr/share/pavucontrol-qt 23allow /usr/share/pavucontrol-qt
24#include whitelist-common.inc 24#include whitelist-common.inc
25include whitelist-usr-share-common.inc 25include whitelist-usr-share-common.inc
26include whitelist-var-common.inc 26include whitelist-var-common.inc
diff --git a/etc/profile-m-z/pcsxr.profile b/etc/profile-m-z/pcsxr.profile
index a6dab2a9a..3f920ced8 100644
--- a/etc/profile-m-z/pcsxr.profile
+++ b/etc/profile-m-z/pcsxr.profile
@@ -8,7 +8,7 @@ include globals.local
8 8
9# Note: you must whitelist your games folder in your pcsxr.local 9# Note: you must whitelist your games folder in your pcsxr.local
10 10
11noblacklist ${HOME}/.pcsxr 11nodeny ${HOME}/.pcsxr
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
@@ -21,7 +21,7 @@ include disable-write-mnt.inc
21include disable-xdg.inc 21include disable-xdg.inc
22 22
23mkdir ${HOME}/.pcsxr 23mkdir ${HOME}/.pcsxr
24whitelist ${HOME}/.pcsxr 24allow ${HOME}/.pcsxr
25include whitelist-common.inc 25include whitelist-common.inc
26include whitelist-runuser-common.inc 26include whitelist-runuser-common.inc
27include whitelist-usr-share-common.inc 27include whitelist-usr-share-common.inc
diff --git a/etc/profile-m-z/pdfchain.profile b/etc/profile-m-z/pdfchain.profile
index d72417914..13a011072 100644
--- a/etc/profile-m-z/pdfchain.profile
+++ b/etc/profile-m-z/pdfchain.profile
@@ -5,7 +5,7 @@ include pdfchain.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${DOCUMENTS} 8nodeny ${DOCUMENTS}
9 9
10include disable-common.inc 10include disable-common.inc
11include disable-devel.inc 11include disable-devel.inc
diff --git a/etc/profile-m-z/pdfmod.profile b/etc/profile-m-z/pdfmod.profile
index a19826555..e49ce8073 100644
--- a/etc/profile-m-z/pdfmod.profile
+++ b/etc/profile-m-z/pdfmod.profile
@@ -6,9 +6,9 @@ include pdfmod.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.cache/pdfmod 9nodeny ${HOME}/.cache/pdfmod
10noblacklist ${HOME}/.config/pdfmod 10nodeny ${HOME}/.config/pdfmod
11noblacklist ${DOCUMENTS} 11nodeny ${DOCUMENTS}
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
diff --git a/etc/profile-m-z/pdfsam.profile b/etc/profile-m-z/pdfsam.profile
index e2808d4d2..67c14bbc3 100644
--- a/etc/profile-m-z/pdfsam.profile
+++ b/etc/profile-m-z/pdfsam.profile
@@ -6,7 +6,7 @@ include pdfsam.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${DOCUMENTS} 9nodeny ${DOCUMENTS}
10 10
11# Allow java (blacklisted by disable-devel.inc) 11# Allow java (blacklisted by disable-devel.inc)
12include allow-java.inc 12include allow-java.inc
diff --git a/etc/profile-m-z/pdftotext.profile b/etc/profile-m-z/pdftotext.profile
index d3902a51c..1c7ebfad5 100644
--- a/etc/profile-m-z/pdftotext.profile
+++ b/etc/profile-m-z/pdftotext.profile
@@ -6,9 +6,9 @@ include pdftotext.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9blacklist ${RUNUSER} 9deny ${RUNUSER}
10 10
11noblacklist ${DOCUMENTS} 11nodeny ${DOCUMENTS}
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
@@ -19,9 +19,9 @@ include disable-programs.inc
19include disable-shell.inc 19include disable-shell.inc
20include disable-xdg.inc 20include disable-xdg.inc
21 21
22whitelist ${DOCUMENTS} 22allow ${DOCUMENTS}
23whitelist ${DOWNLOADS} 23allow ${DOWNLOADS}
24whitelist /usr/share/poppler 24allow /usr/share/poppler
25include whitelist-usr-share-common.inc 25include whitelist-usr-share-common.inc
26include whitelist-var-common.inc 26include whitelist-var-common.inc
27 27
diff --git a/etc/profile-m-z/peek.profile b/etc/profile-m-z/peek.profile
index c33953687..e809625ad 100644
--- a/etc/profile-m-z/peek.profile
+++ b/etc/profile-m-z/peek.profile
@@ -5,9 +5,9 @@ include peek.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${HOME}/.cache/peek 8nodeny ${HOME}/.cache/peek
9noblacklist ${PICTURES} 9nodeny ${PICTURES}
10noblacklist ${VIDEOS} 10nodeny ${VIDEOS}
11 11
12include disable-common.inc 12include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
diff --git a/etc/profile-m-z/penguin-command.profile b/etc/profile-m-z/penguin-command.profile
index f5ad0321d..5ebd7b462 100644
--- a/etc/profile-m-z/penguin-command.profile
+++ b/etc/profile-m-z/penguin-command.profile
@@ -6,7 +6,7 @@ include penguin-command.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.penguin-command 9nodeny ${HOME}/.penguin-command
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -16,7 +16,7 @@ include disable-passwdmgr.inc
16include disable-programs.inc 16include disable-programs.inc
17include disable-shell.inc 17include disable-shell.inc
18 18
19whitelist ${HOME}/.penguin-command 19allow ${HOME}/.penguin-command
20include whitelist-common.inc 20include whitelist-common.inc
21include whitelist-var-common.inc 21include whitelist-var-common.inc
22 22
diff --git a/etc/profile-m-z/photoflare.profile b/etc/profile-m-z/photoflare.profile
index 40068ff78..8dd506850 100644
--- a/etc/profile-m-z/photoflare.profile
+++ b/etc/profile-m-z/photoflare.profile
@@ -6,7 +6,7 @@ include photoflare.local
6# Persistent global definitions 6# Persistent global definitions
7include photoflare.local 7include photoflare.local
8 8
9noblacklist ${PICTURES} 9nodeny ${PICTURES}
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
diff --git a/etc/profile-m-z/picard.profile b/etc/profile-m-z/picard.profile
index a5ea47088..ac178ee6c 100644
--- a/etc/profile-m-z/picard.profile
+++ b/etc/profile-m-z/picard.profile
@@ -6,9 +6,9 @@ include picard.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.cache/MusicBrainz 9nodeny ${HOME}/.cache/MusicBrainz
10noblacklist ${HOME}/.config/MusicBrainz 10nodeny ${HOME}/.config/MusicBrainz
11noblacklist ${MUSIC} 11nodeny ${MUSIC}
12 12
13# Allow python (blacklisted by disable-interpreters.inc) 13# Allow python (blacklisted by disable-interpreters.inc)
14include allow-python2.inc 14include allow-python2.inc
diff --git a/etc/profile-m-z/pidgin.profile b/etc/profile-m-z/pidgin.profile
index 26872e9a1..a65abeb2e 100644
--- a/etc/profile-m-z/pidgin.profile
+++ b/etc/profile-m-z/pidgin.profile
@@ -9,7 +9,7 @@ include globals.local
9ignore noexec ${RUNUSER} 9ignore noexec ${RUNUSER}
10ignore noexec /dev/shm 10ignore noexec /dev/shm
11 11
12noblacklist ${HOME}/.purple 12nodeny ${HOME}/.purple
13 13
14include disable-common.inc 14include disable-common.inc
15include disable-devel.inc 15include disable-devel.inc
@@ -20,9 +20,9 @@ include disable-programs.inc
20include disable-xdg.inc 20include disable-xdg.inc
21 21
22mkdir ${HOME}/.purple 22mkdir ${HOME}/.purple
23whitelist ${HOME}/.purple 23allow ${HOME}/.purple
24whitelist ${DOWNLOADS} 24allow ${DOWNLOADS}
25whitelist ${PICTURES} 25allow ${PICTURES}
26include whitelist-common.inc 26include whitelist-common.inc
27include whitelist-usr-share-common.inc 27include whitelist-usr-share-common.inc
28include whitelist-var-common.inc 28include whitelist-var-common.inc
diff --git a/etc/profile-m-z/pinball.profile b/etc/profile-m-z/pinball.profile
index 2e17be2ce..41e4fb6c0 100644
--- a/etc/profile-m-z/pinball.profile
+++ b/etc/profile-m-z/pinball.profile
@@ -6,7 +6,7 @@ include pinball.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/emilia 9nodeny ${HOME}/.config/emilia
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -18,11 +18,11 @@ include disable-shell.inc
18include disable-xdg.inc 18include disable-xdg.inc
19 19
20mkdir ${HOME}/.config/emilia 20mkdir ${HOME}/.config/emilia
21whitelist ${HOME}/.config/emilia 21allow ${HOME}/.config/emilia
22 22
23whitelist /usr/share/pinball 23allow /usr/share/pinball
24# on debian games are stored under /usr/share/games 24# on debian games are stored under /usr/share/games
25whitelist /usr/share/games/pinball 25allow /usr/share/games/pinball
26include whitelist-common.inc 26include whitelist-common.inc
27include whitelist-runuser-common.inc 27include whitelist-runuser-common.inc
28include whitelist-usr-share-common.inc 28include whitelist-usr-share-common.inc
diff --git a/etc/profile-m-z/ping.profile b/etc/profile-m-z/ping.profile
index e914007c0..65e77abfa 100644
--- a/etc/profile-m-z/ping.profile
+++ b/etc/profile-m-z/ping.profile
@@ -7,8 +7,8 @@ include ping.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10blacklist /tmp/.X11-unix 10deny /tmp/.X11-unix
11blacklist ${RUNUSER} 11deny ${RUNUSER}
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
diff --git a/etc/profile-m-z/pingus.profile b/etc/profile-m-z/pingus.profile
index f1fdfcbad..aa2cfe203 100644
--- a/etc/profile-m-z/pingus.profile
+++ b/etc/profile-m-z/pingus.profile
@@ -6,12 +6,12 @@ include pingus.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.pingus 9nodeny ${HOME}/.pingus
10 10
11# Allow /bin/sh (blacklisted by disable-shell.inc) 11# Allow /bin/sh (blacklisted by disable-shell.inc)
12include allow-bin-sh.inc 12include allow-bin-sh.inc
13 13
14blacklist /usr/libexec 14deny /usr/libexec
15 15
16include disable-common.inc 16include disable-common.inc
17include disable-devel.inc 17include disable-devel.inc
@@ -23,8 +23,8 @@ include disable-shell.inc
23include disable-xdg.inc 23include disable-xdg.inc
24 24
25mkdir ${HOME}/.pingus 25mkdir ${HOME}/.pingus
26whitelist ${HOME}/.pingus 26allow ${HOME}/.pingus
27whitelist /usr/share/pingus 27allow /usr/share/pingus
28include whitelist-common.inc 28include whitelist-common.inc
29include whitelist-runuser-common.inc 29include whitelist-runuser-common.inc
30include whitelist-usr-share-common.inc 30include whitelist-usr-share-common.inc
diff --git a/etc/profile-m-z/pinta.profile b/etc/profile-m-z/pinta.profile
index 19406c399..d0d4f1fce 100644
--- a/etc/profile-m-z/pinta.profile
+++ b/etc/profile-m-z/pinta.profile
@@ -6,9 +6,9 @@ include pinta.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/Pinta 9nodeny ${HOME}/.config/Pinta
10noblacklist ${DOCUMENTS} 10nodeny ${DOCUMENTS}
11noblacklist ${PICTURES} 11nodeny ${PICTURES}
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
diff --git a/etc/profile-m-z/pioneer.profile b/etc/profile-m-z/pioneer.profile
index 721b3944a..6cfea28b6 100644
--- a/etc/profile-m-z/pioneer.profile
+++ b/etc/profile-m-z/pioneer.profile
@@ -6,7 +6,7 @@ include pioneer.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.pioneer 9nodeny ${HOME}/.pioneer
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -18,7 +18,7 @@ include disable-shell.inc
18include disable-xdg.inc 18include disable-xdg.inc
19 19
20mkdir ${HOME}/.pioneer 20mkdir ${HOME}/.pioneer
21whitelist ${HOME}/.pioneer 21allow ${HOME}/.pioneer
22include whitelist-common.inc 22include whitelist-common.inc
23include whitelist-var-common.inc 23include whitelist-var-common.inc
24 24
diff --git a/etc/profile-m-z/pipe-viewer.profile b/etc/profile-m-z/pipe-viewer.profile
index 3de064311..acd7eeaf2 100644
--- a/etc/profile-m-z/pipe-viewer.profile
+++ b/etc/profile-m-z/pipe-viewer.profile
@@ -7,13 +7,13 @@ include pipe-viewer.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10noblacklist ${HOME}/.cache/pipe-viewer 10nodeny ${HOME}/.cache/pipe-viewer
11noblacklist ${HOME}/.config/pipe-viewer 11nodeny ${HOME}/.config/pipe-viewer
12 12
13mkdir ${HOME}/.config/pipe-viewer 13mkdir ${HOME}/.config/pipe-viewer
14mkdir ${HOME}/.cache/pipe-viewer 14mkdir ${HOME}/.cache/pipe-viewer
15whitelist ${HOME}/.cache/pipe-viewer 15allow ${HOME}/.cache/pipe-viewer
16whitelist ${HOME}/.config/pipe-viewer 16allow ${HOME}/.config/pipe-viewer
17 17
18private-bin gtk-pipe-viewer,pipe-viewer 18private-bin gtk-pipe-viewer,pipe-viewer
19 19
diff --git a/etc/profile-m-z/pitivi.profile b/etc/profile-m-z/pitivi.profile
index a2dd809c4..abce4c911 100644
--- a/etc/profile-m-z/pitivi.profile
+++ b/etc/profile-m-z/pitivi.profile
@@ -6,7 +6,7 @@ include pitivi.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/pitivi 9nodeny ${HOME}/.config/pitivi
10 10
11# Allow python (blacklisted by disable-interpreters.inc) 11# Allow python (blacklisted by disable-interpreters.inc)
12include allow-python2.inc 12include allow-python2.inc
diff --git a/etc/profile-m-z/pix.profile b/etc/profile-m-z/pix.profile
index 81d3e9370..63451d352 100644
--- a/etc/profile-m-z/pix.profile
+++ b/etc/profile-m-z/pix.profile
@@ -5,10 +5,10 @@ include pix.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${HOME}/.config/pix 8nodeny ${HOME}/.config/pix
9noblacklist ${HOME}/.local/share/pix 9nodeny ${HOME}/.local/share/pix
10noblacklist ${HOME}/.Steam 10nodeny ${HOME}/.Steam
11noblacklist ${HOME}/.steam 11nodeny ${HOME}/.steam
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
diff --git a/etc/profile-m-z/pkglog.profile b/etc/profile-m-z/pkglog.profile
index 4eb41b3bd..13d7db7f7 100644
--- a/etc/profile-m-z/pkglog.profile
+++ b/etc/profile-m-z/pkglog.profile
@@ -17,9 +17,9 @@ include disable-passwdmgr.inc
17include disable-programs.inc 17include disable-programs.inc
18include disable-xdg.inc 18include disable-xdg.inc
19 19
20whitelist /var/log/apt/history.log 20allow /var/log/apt/history.log
21whitelist /var/log/dnf.rpm.log 21allow /var/log/dnf.rpm.log
22whitelist /var/log/pacman.log 22allow /var/log/pacman.log
23 23
24apparmor 24apparmor
25caps.drop all 25caps.drop all
diff --git a/etc/profile-m-z/playonlinux.profile b/etc/profile-m-z/playonlinux.profile
index 8e98905b5..9c23841e2 100644
--- a/etc/profile-m-z/playonlinux.profile
+++ b/etc/profile-m-z/playonlinux.profile
@@ -7,10 +7,10 @@ include playonlinux.local
7# added by included profile 7# added by included profile
8#include globals.local 8#include globals.local
9 9
10noblacklist ${HOME}/.PlayOnLinux 10nodeny ${HOME}/.PlayOnLinux
11 11
12# nc is needed to run playonlinux 12# nc is needed to run playonlinux
13noblacklist ${PATH}/nc 13nodeny ${PATH}/nc
14 14
15# Allow perl (blacklisted by disable-interpreters.inc) 15# Allow perl (blacklisted by disable-interpreters.inc)
16include allow-perl.inc 16include allow-perl.inc
diff --git a/etc/profile-m-z/pluma.profile b/etc/profile-m-z/pluma.profile
index 10e12e5b1..ab7e0c64b 100644
--- a/etc/profile-m-z/pluma.profile
+++ b/etc/profile-m-z/pluma.profile
@@ -6,8 +6,8 @@ include pluma.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/enchant 9nodeny ${HOME}/.config/enchant
10noblacklist ${HOME}/.config/pluma 10nodeny ${HOME}/.config/pluma
11 11
12# Allows files commonly used by IDEs 12# Allows files commonly used by IDEs
13include allow-common-devel.inc 13include allow-common-devel.inc
diff --git a/etc/profile-m-z/plv.profile b/etc/profile-m-z/plv.profile
index 5201fd853..02cb83ef6 100644
--- a/etc/profile-m-z/plv.profile
+++ b/etc/profile-m-z/plv.profile
@@ -6,7 +6,7 @@ include plv.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/PacmanLogViewer 9nodeny ${HOME}/.config/PacmanLogViewer
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -17,8 +17,8 @@ include disable-programs.inc
17include disable-xdg.inc 17include disable-xdg.inc
18 18
19mkdir ${HOME}/.config/PacmanLogViewer 19mkdir ${HOME}/.config/PacmanLogViewer
20whitelist ${HOME}/.config/PacmanLogViewer 20allow ${HOME}/.config/PacmanLogViewer
21whitelist /var/log/pacman.log 21allow /var/log/pacman.log
22include whitelist-common.inc 22include whitelist-common.inc
23include whitelist-usr-share-common.inc 23include whitelist-usr-share-common.inc
24include whitelist-runuser-common.inc 24include whitelist-runuser-common.inc
diff --git a/etc/profile-m-z/pngquant.profile b/etc/profile-m-z/pngquant.profile
index 8a181d5a8..2c4dda43e 100644
--- a/etc/profile-m-z/pngquant.profile
+++ b/etc/profile-m-z/pngquant.profile
@@ -7,9 +7,9 @@ include pngquant.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10noblacklist ${PICTURES} 10nodeny ${PICTURES}
11 11
12blacklist ${RUNUSER}/wayland-* 12deny ${RUNUSER}/wayland-*
13 13
14include disable-common.inc 14include disable-common.inc
15include disable-devel.inc 15include disable-devel.inc
diff --git a/etc/profile-m-z/polari.profile b/etc/profile-m-z/polari.profile
index a3d4f9851..115ac36ab 100644
--- a/etc/profile-m-z/polari.profile
+++ b/etc/profile-m-z/polari.profile
@@ -21,12 +21,12 @@ mkdir ${HOME}/.local/share/Empathy
21mkdir ${HOME}/.local/share/TpLogger 21mkdir ${HOME}/.local/share/TpLogger
22mkdir ${HOME}/.local/share/telepathy 22mkdir ${HOME}/.local/share/telepathy
23mkdir ${HOME}/.purple 23mkdir ${HOME}/.purple
24whitelist ${HOME}/.cache/telepathy 24allow ${HOME}/.cache/telepathy
25whitelist ${HOME}/.config/telepathy-account-widgets 25allow ${HOME}/.config/telepathy-account-widgets
26whitelist ${HOME}/.local/share/Empathy 26allow ${HOME}/.local/share/Empathy
27whitelist ${HOME}/.local/share/TpLogger 27allow ${HOME}/.local/share/TpLogger
28whitelist ${HOME}/.local/share/telepathy 28allow ${HOME}/.local/share/telepathy
29whitelist ${HOME}/.purple 29allow ${HOME}/.purple
30include whitelist-common.inc 30include whitelist-common.inc
31include whitelist-runuser-common.inc 31include whitelist-runuser-common.inc
32 32
diff --git a/etc/profile-m-z/ppsspp.profile b/etc/profile-m-z/ppsspp.profile
index 1f73c1d89..10c59ea32 100644
--- a/etc/profile-m-z/ppsspp.profile
+++ b/etc/profile-m-z/ppsspp.profile
@@ -8,7 +8,7 @@ include globals.local
8 8
9# Note: you must whitelist your games folder in your ppsspp.local. 9# Note: you must whitelist your games folder in your ppsspp.local.
10 10
11noblacklist ${HOME}/.config/ppsspp 11nodeny ${HOME}/.config/ppsspp
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
@@ -20,8 +20,8 @@ include disable-write-mnt.inc
20include disable-xdg.inc 20include disable-xdg.inc
21 21
22mkdir ${HOME}/.config/ppsspp 22mkdir ${HOME}/.config/ppsspp
23whitelist ${HOME}/.config/ppsspp 23allow ${HOME}/.config/ppsspp
24whitelist /usr/share/ppsspp 24allow /usr/share/ppsspp
25include whitelist-common.inc 25include whitelist-common.inc
26include whitelist-runuser-common.inc 26include whitelist-runuser-common.inc
27include whitelist-usr-share-common.inc 27include whitelist-usr-share-common.inc
diff --git a/etc/profile-m-z/pragha.profile b/etc/profile-m-z/pragha.profile
index f138d785e..9b03bf632 100644
--- a/etc/profile-m-z/pragha.profile
+++ b/etc/profile-m-z/pragha.profile
@@ -6,8 +6,8 @@ include pragha.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/pragha 9nodeny ${HOME}/.config/pragha
10noblacklist ${MUSIC} 10nodeny ${MUSIC}
11 11
12include disable-common.inc 12include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
diff --git a/etc/profile-m-z/profanity.profile b/etc/profile-m-z/profanity.profile
index 743458725..137b4cb20 100644
--- a/etc/profile-m-z/profanity.profile
+++ b/etc/profile-m-z/profanity.profile
@@ -7,8 +7,8 @@ include profanity.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10noblacklist ${HOME}/.config/profanity 10nodeny ${HOME}/.config/profanity
11noblacklist ${HOME}/.local/share/profanity 11nodeny ${HOME}/.local/share/profanity
12 12
13# Allow Python 13# Allow Python
14include allow-python2.inc 14include allow-python2.inc
diff --git a/etc/profile-m-z/psi-plus.profile b/etc/profile-m-z/psi-plus.profile
index 5ac58b0ac..b0e28baf7 100644
--- a/etc/profile-m-z/psi-plus.profile
+++ b/etc/profile-m-z/psi-plus.profile
@@ -6,8 +6,8 @@ include psi-plus.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/psi+ 9nodeny ${HOME}/.config/psi+
10noblacklist ${HOME}/.local/share/psi+ 10nodeny ${HOME}/.local/share/psi+
11 11
12include disable-common.inc 12include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
@@ -19,10 +19,10 @@ include disable-programs.inc
19mkdir ${HOME}/.cache/psi+ 19mkdir ${HOME}/.cache/psi+
20mkdir ${HOME}/.config/psi+ 20mkdir ${HOME}/.config/psi+
21mkdir ${HOME}/.local/share/psi+ 21mkdir ${HOME}/.local/share/psi+
22whitelist ${DOWNLOADS} 22allow ${DOWNLOADS}
23whitelist ${HOME}/.cache/psi+ 23allow ${HOME}/.cache/psi+
24whitelist ${HOME}/.config/psi+ 24allow ${HOME}/.config/psi+
25whitelist ${HOME}/.local/share/psi+ 25allow ${HOME}/.local/share/psi+
26include whitelist-common.inc 26include whitelist-common.inc
27 27
28caps.drop all 28caps.drop all
diff --git a/etc/profile-m-z/psi.profile b/etc/profile-m-z/psi.profile
index 7e0ef99fc..2588c3b75 100644
--- a/etc/profile-m-z/psi.profile
+++ b/etc/profile-m-z/psi.profile
@@ -8,11 +8,11 @@ include globals.local
8 8
9# Add the next line to your psi.local to enable GPG support. 9# Add the next line to your psi.local to enable GPG support.
10#noblacklist ${HOME}/.gnupg 10#noblacklist ${HOME}/.gnupg
11noblacklist ${HOME}/.cache/psi 11nodeny ${HOME}/.cache/psi
12noblacklist ${HOME}/.cache/Psi 12nodeny ${HOME}/.cache/Psi
13noblacklist ${HOME}/.config/psi 13nodeny ${HOME}/.config/psi
14noblacklist ${HOME}/.local/share/psi 14nodeny ${HOME}/.local/share/psi
15noblacklist ${HOME}/.local/share/Psi 15nodeny ${HOME}/.local/share/Psi
16 16
17include disable-common.inc 17include disable-common.inc
18include disable-devel.inc 18include disable-devel.inc
@@ -32,16 +32,16 @@ mkdir ${HOME}/.local/share/psi
32mkdir ${HOME}/.local/share/Psi 32mkdir ${HOME}/.local/share/Psi
33# Add the next line to your psi.local to enable GPG support. 33# Add the next line to your psi.local to enable GPG support.
34#whitelist ${HOME}/.gnupg 34#whitelist ${HOME}/.gnupg
35whitelist ${HOME}/.cache/psi 35allow ${HOME}/.cache/psi
36whitelist ${HOME}/.cache/Psi 36allow ${HOME}/.cache/Psi
37whitelist ${HOME}/.config/psi 37allow ${HOME}/.config/psi
38whitelist ${HOME}/.local/share/psi 38allow ${HOME}/.local/share/psi
39whitelist ${HOME}/.local/share/Psi 39allow ${HOME}/.local/share/Psi
40whitelist ${DOWNLOADS} 40allow ${DOWNLOADS}
41# Add the next lines to your psi.local to enable GPG support. 41# Add the next lines to your psi.local to enable GPG support.
42#whitelist /usr/share/gnupg 42#whitelist /usr/share/gnupg
43#whitelist /usr/share/gnupg2 43#whitelist /usr/share/gnupg2
44whitelist /usr/share/psi 44allow /usr/share/psi
45# Add the next lines to your psi.local to enable GPG support. 45# Add the next lines to your psi.local to enable GPG support.
46#whitelist ${RUNUSER}/gnupg 46#whitelist ${RUNUSER}/gnupg
47#whitelist ${RUNUSER}/keyring 47#whitelist ${RUNUSER}/keyring
diff --git a/etc/profile-m-z/pybitmessage.profile b/etc/profile-m-z/pybitmessage.profile
index 60ae37930..1f0e83ab6 100644
--- a/etc/profile-m-z/pybitmessage.profile
+++ b/etc/profile-m-z/pybitmessage.profile
@@ -5,9 +5,9 @@ include pybitmessage.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist /sbin 8nodeny /sbin
9noblacklist /usr/local/sbin 9nodeny /usr/local/sbin
10noblacklist /usr/sbin 10nodeny /usr/sbin
11 11
12# Allow python (blacklisted by disable-interpreters.inc) 12# Allow python (blacklisted by disable-interpreters.inc)
13include allow-python2.inc 13include allow-python2.inc
diff --git a/etc/profile-m-z/pycharm-community.profile b/etc/profile-m-z/pycharm-community.profile
index 00d7239ae..b6c08290e 100644
--- a/etc/profile-m-z/pycharm-community.profile
+++ b/etc/profile-m-z/pycharm-community.profile
@@ -5,7 +5,7 @@ include pycharm-community.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${HOME}/.PyCharmCE* 8nodeny ${HOME}/.PyCharmCE*
9 9
10# Allow java (blacklisted by disable-devel.inc) 10# Allow java (blacklisted by disable-devel.inc)
11include allow-java.inc 11include allow-java.inc
diff --git a/etc/profile-m-z/pycharm-professional.profile b/etc/profile-m-z/pycharm-professional.profile
index b754a18c9..fa0932cc0 100644
--- a/etc/profile-m-z/pycharm-professional.profile
+++ b/etc/profile-m-z/pycharm-professional.profile
@@ -6,7 +6,7 @@ include pyucharm-professional.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.PyCharm* 9nodeny ${HOME}/.PyCharm*
10 10
11# Redirect 11# Redirect
12include pycharm-community.profile 12include pycharm-community.profile
diff --git a/etc/profile-m-z/qbittorrent.profile b/etc/profile-m-z/qbittorrent.profile
index 506b738cc..fb8e622b0 100644
--- a/etc/profile-m-z/qbittorrent.profile
+++ b/etc/profile-m-z/qbittorrent.profile
@@ -6,10 +6,10 @@ include qbittorrent.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.cache/qBittorrent 9nodeny ${HOME}/.cache/qBittorrent
10noblacklist ${HOME}/.config/qBittorrent 10nodeny ${HOME}/.config/qBittorrent
11noblacklist ${HOME}/.config/qBittorrentrc 11nodeny ${HOME}/.config/qBittorrentrc
12noblacklist ${HOME}/.local/share/data/qBittorrent 12nodeny ${HOME}/.local/share/data/qBittorrent
13 13
14# Allow python (blacklisted by disable-interpreters.inc) 14# Allow python (blacklisted by disable-interpreters.inc)
15include allow-python2.inc 15include allow-python2.inc
@@ -27,11 +27,11 @@ mkdir ${HOME}/.cache/qBittorrent
27mkdir ${HOME}/.config/qBittorrent 27mkdir ${HOME}/.config/qBittorrent
28mkfile ${HOME}/.config/qBittorrentrc 28mkfile ${HOME}/.config/qBittorrentrc
29mkdir ${HOME}/.local/share/data/qBittorrent 29mkdir ${HOME}/.local/share/data/qBittorrent
30whitelist ${DOWNLOADS} 30allow ${DOWNLOADS}
31whitelist ${HOME}/.cache/qBittorrent 31allow ${HOME}/.cache/qBittorrent
32whitelist ${HOME}/.config/qBittorrent 32allow ${HOME}/.config/qBittorrent
33whitelist ${HOME}/.config/qBittorrentrc 33allow ${HOME}/.config/qBittorrentrc
34whitelist ${HOME}/.local/share/data/qBittorrent 34allow ${HOME}/.local/share/data/qBittorrent
35include whitelist-common.inc 35include whitelist-common.inc
36include whitelist-var-common.inc 36include whitelist-var-common.inc
37 37
diff --git a/etc/profile-m-z/qcomicbook.profile b/etc/profile-m-z/qcomicbook.profile
index 0e52d7fc4..7bcc4b065 100644
--- a/etc/profile-m-z/qcomicbook.profile
+++ b/etc/profile-m-z/qcomicbook.profile
@@ -6,10 +6,10 @@ include qcomicbook.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.cache/PawelStolowski 9nodeny ${HOME}/.cache/PawelStolowski
10noblacklist ${HOME}/.config/PawelStolowski 10nodeny ${HOME}/.config/PawelStolowski
11noblacklist ${HOME}/.local/share/PawelStolowski 11nodeny ${HOME}/.local/share/PawelStolowski
12noblacklist ${DOCUMENTS} 12nodeny ${DOCUMENTS}
13 13
14# Allow /bin/sh (blacklisted by disable-shell.inc) 14# Allow /bin/sh (blacklisted by disable-shell.inc)
15include allow-bin-sh.inc 15include allow-bin-sh.inc
@@ -27,7 +27,7 @@ include disable-xdg.inc
27mkdir ${HOME}/.cache/PawelStolowski 27mkdir ${HOME}/.cache/PawelStolowski
28mkdir ${HOME}/.config/PawelStolowski 28mkdir ${HOME}/.config/PawelStolowski
29mkdir ${HOME}/.local/share/PawelStolowski 29mkdir ${HOME}/.local/share/PawelStolowski
30whitelist /usr/share/qcomicbook 30allow /usr/share/qcomicbook
31include whitelist-runuser-common.inc 31include whitelist-runuser-common.inc
32include whitelist-usr-share-common.inc 32include whitelist-usr-share-common.inc
33include whitelist-var-common.inc 33include whitelist-var-common.inc
diff --git a/etc/profile-m-z/qemu-launcher.profile b/etc/profile-m-z/qemu-launcher.profile
index ac60384fd..d527a2b82 100644
--- a/etc/profile-m-z/qemu-launcher.profile
+++ b/etc/profile-m-z/qemu-launcher.profile
@@ -5,7 +5,7 @@ include qemu-launcher.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${HOME}/.qemu-launcher 8nodeny ${HOME}/.qemu-launcher
9 9
10include disable-common.inc 10include disable-common.inc
11include disable-passwdmgr.inc 11include disable-passwdmgr.inc
diff --git a/etc/profile-m-z/qgis.profile b/etc/profile-m-z/qgis.profile
index 2e97daea2..e99140c22 100644
--- a/etc/profile-m-z/qgis.profile
+++ b/etc/profile-m-z/qgis.profile
@@ -6,10 +6,10 @@ include qgis.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/QGIS 9nodeny ${HOME}/.config/QGIS
10noblacklist ${HOME}/.local/share/QGIS 10nodeny ${HOME}/.local/share/QGIS
11noblacklist ${HOME}/.qgis2 11nodeny ${HOME}/.qgis2
12noblacklist ${DOCUMENTS} 12nodeny ${DOCUMENTS}
13 13
14# Allow python (blacklisted by disable-interpreters.inc) 14# Allow python (blacklisted by disable-interpreters.inc)
15include allow-python3.inc 15include allow-python3.inc
@@ -25,10 +25,10 @@ include disable-xdg.inc
25mkdir ${HOME}/.local/share/QGIS 25mkdir ${HOME}/.local/share/QGIS
26mkdir ${HOME}/.qgis2 26mkdir ${HOME}/.qgis2
27mkdir ${HOME}/.config/QGIS 27mkdir ${HOME}/.config/QGIS
28whitelist ${HOME}/.local/share/QGIS 28allow ${HOME}/.local/share/QGIS
29whitelist ${HOME}/.qgis2 29allow ${HOME}/.qgis2
30whitelist ${HOME}/.config/QGIS 30allow ${HOME}/.config/QGIS
31whitelist ${DOCUMENTS} 31allow ${DOCUMENTS}
32include whitelist-common.inc 32include whitelist-common.inc
33include whitelist-var-common.inc 33include whitelist-var-common.inc
34 34
diff --git a/etc/profile-m-z/qlipper.profile b/etc/profile-m-z/qlipper.profile
index 6e94d5845..75dc58ae4 100644
--- a/etc/profile-m-z/qlipper.profile
+++ b/etc/profile-m-z/qlipper.profile
@@ -6,7 +6,7 @@ include qlipper.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/Qlipper 9nodeny ${HOME}/.config/Qlipper
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
diff --git a/etc/profile-m-z/qmmp.profile b/etc/profile-m-z/qmmp.profile
index c3d982c17..d37fce997 100644
--- a/etc/profile-m-z/qmmp.profile
+++ b/etc/profile-m-z/qmmp.profile
@@ -6,8 +6,8 @@ include qmmp.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.qmmp 9nodeny ${HOME}/.qmmp
10noblacklist ${MUSIC} 10nodeny ${MUSIC}
11 11
12include disable-common.inc 12include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
diff --git a/etc/profile-m-z/qnapi.profile b/etc/profile-m-z/qnapi.profile
index ca11df5be..f12340052 100644
--- a/etc/profile-m-z/qnapi.profile
+++ b/etc/profile-m-z/qnapi.profile
@@ -6,7 +6,7 @@ include qnapi.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/qnapi.ini 9nodeny ${HOME}/.config/qnapi.ini
10 10
11ignore noexec /tmp 11ignore noexec /tmp
12 12
@@ -20,8 +20,8 @@ include disable-shell.inc
20include disable-xdg.inc 20include disable-xdg.inc
21 21
22mkfile ${HOME}/.config/qnapi.ini 22mkfile ${HOME}/.config/qnapi.ini
23whitelist ${HOME}/.config/qnapi.ini 23allow ${HOME}/.config/qnapi.ini
24whitelist ${DOWNLOADS} 24allow ${DOWNLOADS}
25include whitelist-common.inc 25include whitelist-common.inc
26include whitelist-usr-share-common.inc 26include whitelist-usr-share-common.inc
27include whitelist-runuser-common.inc 27include whitelist-runuser-common.inc
diff --git a/etc/profile-m-z/qpdfview.profile b/etc/profile-m-z/qpdfview.profile
index be690ffa4..62fae324c 100644
--- a/etc/profile-m-z/qpdfview.profile
+++ b/etc/profile-m-z/qpdfview.profile
@@ -6,9 +6,9 @@ include qpdfview.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/qpdfview 9nodeny ${HOME}/.config/qpdfview
10noblacklist ${HOME}/.local/share/qpdfview 10nodeny ${HOME}/.local/share/qpdfview
11noblacklist ${DOCUMENTS} 11nodeny ${DOCUMENTS}
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
diff --git a/etc/profile-m-z/qrencode.profile b/etc/profile-m-z/qrencode.profile
index 6cbf8519f..5f0aec804 100644
--- a/etc/profile-m-z/qrencode.profile
+++ b/etc/profile-m-z/qrencode.profile
@@ -7,7 +7,7 @@ include qrencode.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10blacklist ${RUNUSER} 10deny ${RUNUSER}
11 11
12include disable-common.inc 12include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
diff --git a/etc/profile-m-z/qtox.profile b/etc/profile-m-z/qtox.profile
index 8ffe24d11..1ad46814e 100644
--- a/etc/profile-m-z/qtox.profile
+++ b/etc/profile-m-z/qtox.profile
@@ -6,8 +6,8 @@ include qtox.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.cache/Tox 9nodeny ${HOME}/.cache/Tox
10noblacklist ${HOME}/.config/tox 10nodeny ${HOME}/.config/tox
11 11
12include disable-common.inc 12include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
@@ -19,8 +19,8 @@ include disable-shell.inc
19include disable-xdg.inc 19include disable-xdg.inc
20 20
21mkdir ${HOME}/.config/tox 21mkdir ${HOME}/.config/tox
22whitelist ${DOWNLOADS} 22allow ${DOWNLOADS}
23whitelist ${HOME}/.config/tox 23allow ${HOME}/.config/tox
24include whitelist-common.inc 24include whitelist-common.inc
25include whitelist-var-common.inc 25include whitelist-var-common.inc
26 26
diff --git a/etc/profile-m-z/quadrapassel.profile b/etc/profile-m-z/quadrapassel.profile
index 91e0d9d0d..aee24925c 100644
--- a/etc/profile-m-z/quadrapassel.profile
+++ b/etc/profile-m-z/quadrapassel.profile
@@ -6,11 +6,11 @@ include quadrapassel.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.local/share/quadrapassel 9nodeny ${HOME}/.local/share/quadrapassel
10 10
11mkdir ${HOME}/.local/share/quadrapassel 11mkdir ${HOME}/.local/share/quadrapassel
12whitelist ${HOME}/.local/share/quadrapassel 12allow ${HOME}/.local/share/quadrapassel
13whitelist /usr/share/quadrapassel 13allow /usr/share/quadrapassel
14 14
15private-bin quadrapassel 15private-bin quadrapassel
16 16
diff --git a/etc/profile-m-z/quaternion.profile b/etc/profile-m-z/quaternion.profile
index 1d146aa39..a319e1e12 100644
--- a/etc/profile-m-z/quaternion.profile
+++ b/etc/profile-m-z/quaternion.profile
@@ -6,8 +6,8 @@ include quaternion.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.cache/Quotient/quaternion 9nodeny ${HOME}/.cache/Quotient/quaternion
10noblacklist ${HOME}/.config/Quotient 10nodeny ${HOME}/.config/Quotient
11 11
12include disable-common.inc 12include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
@@ -20,10 +20,10 @@ include disable-xdg.inc
20 20
21mkdir ${HOME}/.cache/Quotient/quaternion 21mkdir ${HOME}/.cache/Quotient/quaternion
22mkdir ${HOME}/.config/Quotient 22mkdir ${HOME}/.config/Quotient
23whitelist ${HOME}/.cache/Quotient/quaternion 23allow ${HOME}/.cache/Quotient/quaternion
24whitelist ${HOME}/.config/Quotient 24allow ${HOME}/.config/Quotient
25whitelist ${DOWNLOADS} 25allow ${DOWNLOADS}
26whitelist /usr/share/Quotient/quaternion 26allow /usr/share/Quotient/quaternion
27include whitelist-common.inc 27include whitelist-common.inc
28include whitelist-runuser-common.inc 28include whitelist-runuser-common.inc
29include whitelist-usr-share-common.inc 29include whitelist-usr-share-common.inc
diff --git a/etc/profile-m-z/quiterss.profile b/etc/profile-m-z/quiterss.profile
index 9490089b2..2693f2ed5 100644
--- a/etc/profile-m-z/quiterss.profile
+++ b/etc/profile-m-z/quiterss.profile
@@ -6,10 +6,10 @@ include quiterss.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.cache/QuiteRss 9nodeny ${HOME}/.cache/QuiteRss
10noblacklist ${HOME}/.config/QuiteRss 10nodeny ${HOME}/.config/QuiteRss
11noblacklist ${HOME}/.config/QuiteRssrc 11nodeny ${HOME}/.config/QuiteRssrc
12noblacklist ${HOME}/.local/share/QuiteRss 12nodeny ${HOME}/.local/share/QuiteRss
13 13
14include disable-common.inc 14include disable-common.inc
15include disable-devel.inc 15include disable-devel.inc
@@ -25,12 +25,12 @@ mkdir ${HOME}/.local/share/data
25mkdir ${HOME}/.local/share/data/QuiteRss 25mkdir ${HOME}/.local/share/data/QuiteRss
26mkdir ${HOME}/.local/share/QuiteRss 26mkdir ${HOME}/.local/share/QuiteRss
27mkfile ${HOME}/quiterssfeeds.opml 27mkfile ${HOME}/quiterssfeeds.opml
28whitelist ${HOME}/.cache/QuiteRss 28allow ${HOME}/.cache/QuiteRss
29whitelist ${HOME}/.config/QuiteRss 29allow ${HOME}/.config/QuiteRss
30whitelist ${HOME}/.config/QuiteRssrc 30allow ${HOME}/.config/QuiteRssrc
31whitelist ${HOME}/.local/share/data/QuiteRss 31allow ${HOME}/.local/share/data/QuiteRss
32whitelist ${HOME}/.local/share/QuiteRss 32allow ${HOME}/.local/share/QuiteRss
33whitelist ${HOME}/quiterssfeeds.opml 33allow ${HOME}/quiterssfeeds.opml
34include whitelist-common.inc 34include whitelist-common.inc
35 35
36caps.drop all 36caps.drop all
diff --git a/etc/profile-m-z/quodlibet.profile b/etc/profile-m-z/quodlibet.profile
index 92b02b2bf..52c120c08 100644
--- a/etc/profile-m-z/quodlibet.profile
+++ b/etc/profile-m-z/quodlibet.profile
@@ -6,10 +6,10 @@ include quodlibet.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.cache/quodlibet 9nodeny ${HOME}/.cache/quodlibet
10noblacklist ${HOME}/.config/quodlibet 10nodeny ${HOME}/.config/quodlibet
11noblacklist ${HOME}/.quodlibet 11nodeny ${HOME}/.quodlibet
12noblacklist ${MUSIC} 12nodeny ${MUSIC}
13 13
14include allow-bin-sh.inc 14include allow-bin-sh.inc
15 15
@@ -30,11 +30,11 @@ mkdir ${HOME}/.cache/quodlibet
30mkdir ${HOME}/.config/quodlibet 30mkdir ${HOME}/.config/quodlibet
31mkdir ${HOME}/.quodlibet 31mkdir ${HOME}/.quodlibet
32 32
33whitelist ${HOME}/.cache/quodlibet 33allow ${HOME}/.cache/quodlibet
34whitelist ${HOME}/.config/quodlibet 34allow ${HOME}/.config/quodlibet
35whitelist ${HOME}/.quodlibet 35allow ${HOME}/.quodlibet
36whitelist ${DOWNLOADS} 36allow ${DOWNLOADS}
37whitelist ${MUSIC} 37allow ${MUSIC}
38include whitelist-common.inc 38include whitelist-common.inc
39include whitelist-runuser-common.inc 39include whitelist-runuser-common.inc
40include whitelist-usr-share-common.inc 40include whitelist-usr-share-common.inc
diff --git a/etc/profile-m-z/qupzilla.profile b/etc/profile-m-z/qupzilla.profile
index 7aa71c848..9bc91808b 100644
--- a/etc/profile-m-z/qupzilla.profile
+++ b/etc/profile-m-z/qupzilla.profile
@@ -6,8 +6,8 @@ include qupzilla.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.cache/qupzilla 9nodeny ${HOME}/.cache/qupzilla
10noblacklist ${HOME}/.config/qupzilla 10nodeny ${HOME}/.config/qupzilla
11 11
12include disable-common.inc 12include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
@@ -18,8 +18,8 @@ include disable-programs.inc
18 18
19mkdir ${HOME}/.cache/qupzilla 19mkdir ${HOME}/.cache/qupzilla
20mkdir ${HOME}/.config/qupzilla 20mkdir ${HOME}/.config/qupzilla
21whitelist ${HOME}/.cache/qupzilla 21allow ${HOME}/.cache/qupzilla
22whitelist ${HOME}/.config/qupzilla 22allow ${HOME}/.config/qupzilla
23 23
24# Redirect 24# Redirect
25include falkon.profile 25include falkon.profile
diff --git a/etc/profile-m-z/qutebrowser.profile b/etc/profile-m-z/qutebrowser.profile
index fc910b589..a342e2acd 100644
--- a/etc/profile-m-z/qutebrowser.profile
+++ b/etc/profile-m-z/qutebrowser.profile
@@ -6,9 +6,9 @@ include qutebrowser.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.cache/qutebrowser 9nodeny ${HOME}/.cache/qutebrowser
10noblacklist ${HOME}/.config/qutebrowser 10nodeny ${HOME}/.config/qutebrowser
11noblacklist ${HOME}/.local/share/qutebrowser 11nodeny ${HOME}/.local/share/qutebrowser
12 12
13# Allow python (blacklisted by disable-interpreters.inc) 13# Allow python (blacklisted by disable-interpreters.inc)
14include allow-python2.inc 14include allow-python2.inc
@@ -22,10 +22,10 @@ include disable-programs.inc
22mkdir ${HOME}/.cache/qutebrowser 22mkdir ${HOME}/.cache/qutebrowser
23mkdir ${HOME}/.config/qutebrowser 23mkdir ${HOME}/.config/qutebrowser
24mkdir ${HOME}/.local/share/qutebrowser 24mkdir ${HOME}/.local/share/qutebrowser
25whitelist ${DOWNLOADS} 25allow ${DOWNLOADS}
26whitelist ${HOME}/.cache/qutebrowser 26allow ${HOME}/.cache/qutebrowser
27whitelist ${HOME}/.config/qutebrowser 27allow ${HOME}/.config/qutebrowser
28whitelist ${HOME}/.local/share/qutebrowser 28allow ${HOME}/.local/share/qutebrowser
29include whitelist-common.inc 29include whitelist-common.inc
30 30
31caps.drop all 31caps.drop all
diff --git a/etc/profile-m-z/rambox.profile b/etc/profile-m-z/rambox.profile
index ffa2022ee..b1059cee8 100644
--- a/etc/profile-m-z/rambox.profile
+++ b/etc/profile-m-z/rambox.profile
@@ -6,9 +6,9 @@ include rambox.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/Rambox 9nodeny ${HOME}/.config/Rambox
10noblacklist ${HOME}/.pki 10nodeny ${HOME}/.pki
11noblacklist ${HOME}/.local/share/pki 11nodeny ${HOME}/.local/share/pki
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
@@ -18,10 +18,10 @@ include disable-programs.inc
18mkdir ${HOME}/.config/Rambox 18mkdir ${HOME}/.config/Rambox
19mkdir ${HOME}/.pki 19mkdir ${HOME}/.pki
20mkdir ${HOME}/.local/share/pki 20mkdir ${HOME}/.local/share/pki
21whitelist ${DOWNLOADS} 21allow ${DOWNLOADS}
22whitelist ${HOME}/.config/Rambox 22allow ${HOME}/.config/Rambox
23whitelist ${HOME}/.pki 23allow ${HOME}/.pki
24whitelist ${HOME}/.local/share/pki 24allow ${HOME}/.local/share/pki
25include whitelist-common.inc 25include whitelist-common.inc
26 26
27caps.drop all 27caps.drop all
diff --git a/etc/profile-m-z/redeclipse.profile b/etc/profile-m-z/redeclipse.profile
index 9bc196a16..3b56f651f 100644
--- a/etc/profile-m-z/redeclipse.profile
+++ b/etc/profile-m-z/redeclipse.profile
@@ -6,7 +6,7 @@ include redeclipse.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.redeclipse 9nodeny ${HOME}/.redeclipse
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -17,8 +17,8 @@ include disable-programs.inc
17include disable-xdg.inc 17include disable-xdg.inc
18 18
19mkdir ${HOME}/.redeclipse 19mkdir ${HOME}/.redeclipse
20whitelist ${HOME}/.redeclipse 20allow ${HOME}/.redeclipse
21whitelist /usr/share/redeclipse 21allow /usr/share/redeclipse
22include whitelist-common.inc 22include whitelist-common.inc
23include whitelist-runuser-common.inc 23include whitelist-runuser-common.inc
24include whitelist-usr-share-common.inc 24include whitelist-usr-share-common.inc
diff --git a/etc/profile-m-z/redshift.profile b/etc/profile-m-z/redshift.profile
index f87c5f67c..3035e1d74 100644
--- a/etc/profile-m-z/redshift.profile
+++ b/etc/profile-m-z/redshift.profile
@@ -7,8 +7,8 @@ include redshift.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10noblacklist ${HOME}/.config/redshift 10nodeny ${HOME}/.config/redshift
11noblacklist ${HOME}/.config/redshift.conf 11nodeny ${HOME}/.config/redshift.conf
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
@@ -19,8 +19,8 @@ include disable-programs.inc
19include disable-xdg.inc 19include disable-xdg.inc
20 20
21mkdir ${HOME}/.config/redshift 21mkdir ${HOME}/.config/redshift
22whitelist ${HOME}/.config/redshift 22allow ${HOME}/.config/redshift
23whitelist ${HOME}/.config/redshift.conf 23allow ${HOME}/.config/redshift.conf
24include whitelist-var-common.inc 24include whitelist-var-common.inc
25 25
26apparmor 26apparmor
diff --git a/etc/profile-m-z/regextester.profile b/etc/profile-m-z/regextester.profile
index f5131c5d0..82feafab9 100644
--- a/etc/profile-m-z/regextester.profile
+++ b/etc/profile-m-z/regextester.profile
@@ -15,7 +15,7 @@ include disable-programs.inc
15include disable-shell.inc 15include disable-shell.inc
16include disable-xdg.inc 16include disable-xdg.inc
17 17
18whitelist /usr/share/com.github.artemanufrij.regextester 18allow /usr/share/com.github.artemanufrij.regextester
19include whitelist-common.inc 19include whitelist-common.inc
20include whitelist-usr-share-common.inc 20include whitelist-usr-share-common.inc
21include whitelist-var-common.inc 21include whitelist-var-common.inc
diff --git a/etc/profile-m-z/remmina.profile b/etc/profile-m-z/remmina.profile
index aca22f187..3f385f602 100644
--- a/etc/profile-m-z/remmina.profile
+++ b/etc/profile-m-z/remmina.profile
@@ -6,9 +6,9 @@ include remmina.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.remmina 9nodeny ${HOME}/.remmina
10noblacklist ${HOME}/.config/remmina 10nodeny ${HOME}/.config/remmina
11noblacklist ${HOME}/.local/share/remmina 11nodeny ${HOME}/.local/share/remmina
12 12
13# Allow ssh (blacklisted by disable-common.inc) 13# Allow ssh (blacklisted by disable-common.inc)
14include allow-ssh.inc 14include allow-ssh.inc
diff --git a/etc/profile-m-z/rhythmbox.profile b/etc/profile-m-z/rhythmbox.profile
index 970e8ffba..c532d3dc1 100644
--- a/etc/profile-m-z/rhythmbox.profile
+++ b/etc/profile-m-z/rhythmbox.profile
@@ -6,9 +6,9 @@ include rhythmbox.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${MUSIC} 9nodeny ${MUSIC}
10noblacklist ${HOME}/.cache/rhythmbox 10nodeny ${HOME}/.cache/rhythmbox
11noblacklist ${HOME}/.local/share/rhythmbox 11nodeny ${HOME}/.local/share/rhythmbox
12 12
13# Allow python (blacklisted by disable-interpreters.inc) 13# Allow python (blacklisted by disable-interpreters.inc)
14include allow-python2.inc 14include allow-python2.inc
@@ -26,10 +26,10 @@ include disable-programs.inc
26include disable-shell.inc 26include disable-shell.inc
27include disable-xdg.inc 27include disable-xdg.inc
28 28
29whitelist /usr/share/rhythmbox 29allow /usr/share/rhythmbox
30whitelist /usr/share/lua 30allow /usr/share/lua
31whitelist /usr/share/libquvi-scripts 31allow /usr/share/libquvi-scripts
32whitelist /usr/share/tracker 32allow /usr/share/tracker
33include whitelist-runuser-common.inc 33include whitelist-runuser-common.inc
34include whitelist-usr-share-common.inc 34include whitelist-usr-share-common.inc
35include whitelist-var-common.inc 35include whitelist-var-common.inc
diff --git a/etc/profile-m-z/ricochet.profile b/etc/profile-m-z/ricochet.profile
index b664a2be3..c3ee57ef3 100644
--- a/etc/profile-m-z/ricochet.profile
+++ b/etc/profile-m-z/ricochet.profile
@@ -5,7 +5,7 @@ include ricochet.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${HOME}/.local/share/Ricochet 8nodeny ${HOME}/.local/share/Ricochet
9 9
10include disable-common.inc 10include disable-common.inc
11include disable-devel.inc 11include disable-devel.inc
@@ -16,8 +16,8 @@ include disable-programs.inc
16include disable-shell.inc 16include disable-shell.inc
17 17
18mkdir ${HOME}/.local/share/Ricochet 18mkdir ${HOME}/.local/share/Ricochet
19whitelist ${DOWNLOADS} 19allow ${DOWNLOADS}
20whitelist ${HOME}/.local/share/Ricochet 20allow ${HOME}/.local/share/Ricochet
21include whitelist-common.inc 21include whitelist-common.inc
22 22
23caps.drop all 23caps.drop all
diff --git a/etc/profile-m-z/riot-web.profile b/etc/profile-m-z/riot-web.profile
index 687c943b0..782396a50 100644
--- a/etc/profile-m-z/riot-web.profile
+++ b/etc/profile-m-z/riot-web.profile
@@ -8,11 +8,11 @@ include globals.local
8 8
9ignore noexec /tmp 9ignore noexec /tmp
10 10
11noblacklist ${HOME}/.config/Riot 11nodeny ${HOME}/.config/Riot
12 12
13mkdir ${HOME}/.config/Riot 13mkdir ${HOME}/.config/Riot
14whitelist ${HOME}/.config/Riot 14allow ${HOME}/.config/Riot
15whitelist /usr/share/webapps/element 15allow /usr/share/webapps/element
16 16
17# Redirect 17# Redirect
18include electron.profile 18include electron.profile
diff --git a/etc/profile-m-z/ripperx.profile b/etc/profile-m-z/ripperx.profile
index be815e714..c97ac8090 100644
--- a/etc/profile-m-z/ripperx.profile
+++ b/etc/profile-m-z/ripperx.profile
@@ -6,8 +6,8 @@ include ripperx.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.ripperXrc 9nodeny ${HOME}/.ripperXrc
10noblacklist ${MUSIC} 10nodeny ${MUSIC}
11 11
12include disable-common.inc 12include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
diff --git a/etc/profile-m-z/ristretto.profile b/etc/profile-m-z/ristretto.profile
index 5572cab5a..109d2f8f1 100644
--- a/etc/profile-m-z/ristretto.profile
+++ b/etc/profile-m-z/ristretto.profile
@@ -6,9 +6,9 @@ include ristretto.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/ristretto 9nodeny ${HOME}/.config/ristretto
10noblacklist ${HOME}/.Steam 10nodeny ${HOME}/.Steam
11noblacklist ${HOME}/.steam 11nodeny ${HOME}/.steam
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
diff --git a/etc/profile-m-z/rocketchat.profile b/etc/profile-m-z/rocketchat.profile
index 8d3607c75..1a76c4211 100644
--- a/etc/profile-m-z/rocketchat.profile
+++ b/etc/profile-m-z/rocketchat.profile
@@ -21,10 +21,10 @@ ignore private-cache
21ignore private-dev 21ignore private-dev
22ignore private-tmp 22ignore private-tmp
23 23
24noblacklist ${HOME}/.config/Rocket.Chat 24nodeny ${HOME}/.config/Rocket.Chat
25 25
26mkdir ${HOME}/.config/Rocket.Chat 26mkdir ${HOME}/.config/Rocket.Chat
27whitelist ${HOME}/.config/Rocket.Chat 27allow ${HOME}/.config/Rocket.Chat
28 28
29# Redirect 29# Redirect
30include electron.profile 30include electron.profile
diff --git a/etc/profile-m-z/rsync-download_only.profile b/etc/profile-m-z/rsync-download_only.profile
index 690b44bb1..4807b7d36 100644
--- a/etc/profile-m-z/rsync-download_only.profile
+++ b/etc/profile-m-z/rsync-download_only.profile
@@ -11,8 +11,8 @@ include globals.local
11# not as a daemon (rsync --daemon) nor to create backups. 11# not as a daemon (rsync --daemon) nor to create backups.
12# Usage: firejail --profile=rsync-download_only rsync 12# Usage: firejail --profile=rsync-download_only rsync
13 13
14blacklist /tmp/.X11-unix 14deny /tmp/.X11-unix
15blacklist ${RUNUSER} 15deny ${RUNUSER}
16 16
17include disable-common.inc 17include disable-common.inc
18include disable-devel.inc 18include disable-devel.inc
diff --git a/etc/profile-m-z/rtv-addons.profile b/etc/profile-m-z/rtv-addons.profile
index cc6db5043..6b7d6b155 100644
--- a/etc/profile-m-z/rtv-addons.profile
+++ b/etc/profile-m-z/rtv-addons.profile
@@ -11,16 +11,16 @@ ignore nosound
11ignore private-bin 11ignore private-bin
12ignore dbus-user none 12ignore dbus-user none
13 13
14noblacklist ${HOME}/.config/mpv 14nodeny ${HOME}/.config/mpv
15noblacklist ${HOME}/.mailcap 15nodeny ${HOME}/.mailcap
16noblacklist ${HOME}/.netrc 16nodeny ${HOME}/.netrc
17noblacklist ${HOME}/.w3m 17nodeny ${HOME}/.w3m
18 18
19whitelist ${HOME}/.cache/youtube-dl/youtube-sigfuncs 19allow ${HOME}/.cache/youtube-dl/youtube-sigfuncs
20whitelist ${HOME}/.config/mpv 20allow ${HOME}/.config/mpv
21whitelist ${HOME}/.mailcap 21allow ${HOME}/.mailcap
22whitelist ${HOME}/.netrc 22allow ${HOME}/.netrc
23whitelist ${HOME}/.w3m 23allow ${HOME}/.w3m
24 24
25#private-bin w3m,mpv,youtube-dl 25#private-bin w3m,mpv,youtube-dl
26 26
diff --git a/etc/profile-m-z/rtv.profile b/etc/profile-m-z/rtv.profile
index 2f1fe0155..074050792 100644
--- a/etc/profile-m-z/rtv.profile
+++ b/etc/profile-m-z/rtv.profile
@@ -6,11 +6,11 @@ include rtv.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9blacklist /tmp/.X11-unix 9deny /tmp/.X11-unix
10blacklist ${RUNUSER}/wayland-* 10deny ${RUNUSER}/wayland-*
11 11
12noblacklist ${HOME}/.config/rtv 12nodeny ${HOME}/.config/rtv
13noblacklist ${HOME}/.local/share/rtv 13nodeny ${HOME}/.local/share/rtv
14 14
15# Allow /bin/sh (blacklisted by disable-shell.inc) 15# Allow /bin/sh (blacklisted by disable-shell.inc)
16include allow-bin-sh.inc 16include allow-bin-sh.inc
@@ -33,8 +33,8 @@ include disable-xdg.inc
33 33
34mkdir ${HOME}/.config/rtv 34mkdir ${HOME}/.config/rtv
35mkdir ${HOME}/.local/share/rtv 35mkdir ${HOME}/.local/share/rtv
36whitelist ${HOME}/.config/rtv 36allow ${HOME}/.config/rtv
37whitelist ${HOME}/.local/share/rtv 37allow ${HOME}/.local/share/rtv
38include whitelist-var-common.inc 38include whitelist-var-common.inc
39 39
40apparmor 40apparmor
diff --git a/etc/profile-m-z/sayonara.profile b/etc/profile-m-z/sayonara.profile
index de79913cc..963f5da02 100644
--- a/etc/profile-m-z/sayonara.profile
+++ b/etc/profile-m-z/sayonara.profile
@@ -5,8 +5,8 @@ include sayonara.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${HOME}/.Sayonara 8nodeny ${HOME}/.Sayonara
9noblacklist ${MUSIC} 9nodeny ${MUSIC}
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
diff --git a/etc/profile-m-z/scallion.profile b/etc/profile-m-z/scallion.profile
index eb8468c3b..26550b5e0 100644
--- a/etc/profile-m-z/scallion.profile
+++ b/etc/profile-m-z/scallion.profile
@@ -6,10 +6,10 @@ include scallion.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${PATH}/llvm* 9nodeny ${PATH}/llvm*
10noblacklist ${PATH}/openssl 10nodeny ${PATH}/openssl
11noblacklist ${PATH}/openssl-1.0 11nodeny ${PATH}/openssl-1.0
12noblacklist ${DOCUMENTS} 12nodeny ${DOCUMENTS}
13 13
14include disable-common.inc 14include disable-common.inc
15include disable-exec.inc 15include disable-exec.inc
diff --git a/etc/profile-m-z/scorched3d.profile b/etc/profile-m-z/scorched3d.profile
index b1989e474..921efb49e 100644
--- a/etc/profile-m-z/scorched3d.profile
+++ b/etc/profile-m-z/scorched3d.profile
@@ -6,7 +6,7 @@ include scorched3d.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.scorched3d 9nodeny ${HOME}/.scorched3d
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -17,9 +17,9 @@ include disable-programs.inc
17include disable-xdg.inc 17include disable-xdg.inc
18 18
19mkdir ${HOME}/.scorched3d 19mkdir ${HOME}/.scorched3d
20whitelist ${HOME}/.scorched3d 20allow ${HOME}/.scorched3d
21whitelist /usr/share/scorched3d 21allow /usr/share/scorched3d
22whitelist /usr/share/games/scorched3d 22allow /usr/share/games/scorched3d
23include whitelist-common.inc 23include whitelist-common.inc
24include whitelist-runuser-common.inc 24include whitelist-runuser-common.inc
25include whitelist-usr-share-common.inc 25include whitelist-usr-share-common.inc
diff --git a/etc/profile-m-z/scorchwentbonkers.profile b/etc/profile-m-z/scorchwentbonkers.profile
index 2cb1df6b5..54a6c3a01 100644
--- a/etc/profile-m-z/scorchwentbonkers.profile
+++ b/etc/profile-m-z/scorchwentbonkers.profile
@@ -6,7 +6,7 @@ include scorchwentbonkers.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.swb.ini 9nodeny ${HOME}/.swb.ini
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -18,8 +18,8 @@ include disable-shell.inc
18include disable-xdg.inc 18include disable-xdg.inc
19 19
20mkdir ${HOME}/.swb.ini 20mkdir ${HOME}/.swb.ini
21whitelist ${HOME}/.swb.ini 21allow ${HOME}/.swb.ini
22whitelist /usr/share/scorchwentbonkers 22allow /usr/share/scorchwentbonkers
23include whitelist-common.inc 23include whitelist-common.inc
24include whitelist-usr-share-common.inc 24include whitelist-usr-share-common.inc
25include whitelist-var-common.inc 25include whitelist-var-common.inc
diff --git a/etc/profile-m-z/scribus.profile b/etc/profile-m-z/scribus.profile
index 1fdeaa145..6519f8e87 100644
--- a/etc/profile-m-z/scribus.profile
+++ b/etc/profile-m-z/scribus.profile
@@ -7,24 +7,24 @@ include scribus.local
7include globals.local 7include globals.local
8 8
9# Support for PDF readers comes with Scribus 1.5 and higher 9# Support for PDF readers comes with Scribus 1.5 and higher
10noblacklist ${HOME}/.cache/okular 10nodeny ${HOME}/.cache/okular
11noblacklist ${HOME}/.config/GIMP 11nodeny ${HOME}/.config/GIMP
12noblacklist ${HOME}/.config/okularpartrc 12nodeny ${HOME}/.config/okularpartrc
13noblacklist ${HOME}/.config/okularrc 13nodeny ${HOME}/.config/okularrc
14noblacklist ${HOME}/.config/scribus 14nodeny ${HOME}/.config/scribus
15noblacklist ${HOME}/.config/scribusrc 15nodeny ${HOME}/.config/scribusrc
16noblacklist ${HOME}/.gimp* 16nodeny ${HOME}/.gimp*
17noblacklist ${HOME}/.kde/share/apps/okular 17nodeny ${HOME}/.kde/share/apps/okular
18noblacklist ${HOME}/.kde/share/config/okularpartrc 18nodeny ${HOME}/.kde/share/config/okularpartrc
19noblacklist ${HOME}/.kde/share/config/okularrc 19nodeny ${HOME}/.kde/share/config/okularrc
20noblacklist ${HOME}/.kde4/share/apps/okular 20nodeny ${HOME}/.kde4/share/apps/okular
21noblacklist ${HOME}/.kde4/share/config/okularpartrc 21nodeny ${HOME}/.kde4/share/config/okularpartrc
22noblacklist ${HOME}/.kde4/share/config/okularrc 22nodeny ${HOME}/.kde4/share/config/okularrc
23noblacklist ${HOME}/.local/share/okular 23nodeny ${HOME}/.local/share/okular
24noblacklist ${HOME}/.local/share/scribus 24nodeny ${HOME}/.local/share/scribus
25noblacklist ${HOME}/.scribus 25nodeny ${HOME}/.scribus
26noblacklist ${DOCUMENTS} 26nodeny ${DOCUMENTS}
27noblacklist ${PICTURES} 27nodeny ${PICTURES}
28 28
29# Allow python (blacklisted by disable-interpreters.inc) 29# Allow python (blacklisted by disable-interpreters.inc)
30include allow-python2.inc 30include allow-python2.inc
diff --git a/etc/profile-m-z/seahorse-adventures.profile b/etc/profile-m-z/seahorse-adventures.profile
index 7799ab7ed..95cedac3f 100644
--- a/etc/profile-m-z/seahorse-adventures.profile
+++ b/etc/profile-m-z/seahorse-adventures.profile
@@ -22,8 +22,8 @@ include disable-programs.inc
22include disable-shell.inc 22include disable-shell.inc
23include disable-xdg.inc 23include disable-xdg.inc
24 24
25whitelist /usr/share/seahorse-adventures 25allow /usr/share/seahorse-adventures
26whitelist /usr/share/games/seahorse-adventures 26allow /usr/share/games/seahorse-adventures
27include whitelist-common.inc 27include whitelist-common.inc
28include whitelist-usr-share-common.inc 28include whitelist-usr-share-common.inc
29include whitelist-var-common.inc 29include whitelist-var-common.inc
diff --git a/etc/profile-m-z/seahorse.profile b/etc/profile-m-z/seahorse.profile
index d3d8e453f..66605173b 100644
--- a/etc/profile-m-z/seahorse.profile
+++ b/etc/profile-m-z/seahorse.profile
@@ -6,9 +6,9 @@ include seahorse.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9blacklist /tmp/.X11-unix 9deny /tmp/.X11-unix
10 10
11noblacklist ${HOME}/.gnupg 11nodeny ${HOME}/.gnupg
12 12
13# Allow ssh (blacklisted by disable-common.inc) 13# Allow ssh (blacklisted by disable-common.inc)
14include allow-ssh.inc 14include allow-ssh.inc
@@ -27,13 +27,13 @@ include disable-xdg.inc
27#mkdir ${HOME}/.ssh 27#mkdir ${HOME}/.ssh
28#whitelist ${HOME}/.gnupg 28#whitelist ${HOME}/.gnupg
29#whitelist ${HOME}/.ssh 29#whitelist ${HOME}/.ssh
30whitelist /tmp/ssh-* 30allow /tmp/ssh-*
31whitelist /usr/share/gnupg 31allow /usr/share/gnupg
32whitelist /usr/share/gnupg2 32allow /usr/share/gnupg2
33whitelist /usr/share/seahorse 33allow /usr/share/seahorse
34whitelist /usr/share/seahorse-nautilus 34allow /usr/share/seahorse-nautilus
35whitelist ${RUNUSER}/gnupg 35allow ${RUNUSER}/gnupg
36whitelist ${RUNUSER}/keyring 36allow ${RUNUSER}/keyring
37#include whitelist-common.inc 37#include whitelist-common.inc
38include whitelist-runuser-common.inc 38include whitelist-runuser-common.inc
39include whitelist-usr-share-common.inc 39include whitelist-usr-share-common.inc
diff --git a/etc/profile-m-z/seamonkey.profile b/etc/profile-m-z/seamonkey.profile
index 807effbeb..c9867719a 100644
--- a/etc/profile-m-z/seamonkey.profile
+++ b/etc/profile-m-z/seamonkey.profile
@@ -6,10 +6,10 @@ include seamonkey.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.cache/mozilla 9nodeny ${HOME}/.cache/mozilla
10noblacklist ${HOME}/.mozilla 10nodeny ${HOME}/.mozilla
11noblacklist ${HOME}/.pki 11nodeny ${HOME}/.pki
12noblacklist ${HOME}/.local/share/pki 12nodeny ${HOME}/.local/share/pki
13 13
14include disable-common.inc 14include disable-common.inc
15include disable-devel.inc 15include disable-devel.inc
@@ -20,25 +20,25 @@ mkdir ${HOME}/.cache/mozilla
20mkdir ${HOME}/.mozilla 20mkdir ${HOME}/.mozilla
21mkdir ${HOME}/.pki 21mkdir ${HOME}/.pki
22mkdir ${HOME}/.local/share/pki 22mkdir ${HOME}/.local/share/pki
23whitelist ${DOWNLOADS} 23allow ${DOWNLOADS}
24whitelist ${HOME}/.cache/gnome-mplayer/plugin 24allow ${HOME}/.cache/gnome-mplayer/plugin
25whitelist ${HOME}/.cache/mozilla 25allow ${HOME}/.cache/mozilla
26whitelist ${HOME}/.config/gnome-mplayer 26allow ${HOME}/.config/gnome-mplayer
27whitelist ${HOME}/.config/pipelight-silverlight5.1 27allow ${HOME}/.config/pipelight-silverlight5.1
28whitelist ${HOME}/.config/pipelight-widevine 28allow ${HOME}/.config/pipelight-widevine
29whitelist ${HOME}/.keysnail.js 29allow ${HOME}/.keysnail.js
30whitelist ${HOME}/.lastpass 30allow ${HOME}/.lastpass
31whitelist ${HOME}/.mozilla 31allow ${HOME}/.mozilla
32whitelist ${HOME}/.pentadactyl 32allow ${HOME}/.pentadactyl
33whitelist ${HOME}/.pentadactylrc 33allow ${HOME}/.pentadactylrc
34whitelist ${HOME}/.pki 34allow ${HOME}/.pki
35whitelist ${HOME}/.local/share/pki 35allow ${HOME}/.local/share/pki
36whitelist ${HOME}/.vimperator 36allow ${HOME}/.vimperator
37whitelist ${HOME}/.vimperatorrc 37allow ${HOME}/.vimperatorrc
38whitelist ${HOME}/.wine-pipelight 38allow ${HOME}/.wine-pipelight
39whitelist ${HOME}/.wine-pipelight64 39allow ${HOME}/.wine-pipelight64
40whitelist ${HOME}/.zotero 40allow ${HOME}/.zotero
41whitelist ${HOME}/dwhelper 41allow ${HOME}/dwhelper
42include whitelist-common.inc 42include whitelist-common.inc
43 43
44caps.drop all 44caps.drop all
diff --git a/etc/profile-m-z/server.profile b/etc/profile-m-z/server.profile
index 7d56684db..23f464637 100644
--- a/etc/profile-m-z/server.profile
+++ b/etc/profile-m-z/server.profile
@@ -32,12 +32,12 @@ include globals.local
32# it allows /sbin and /usr/sbin directories - this is where servers are installed 32# it allows /sbin and /usr/sbin directories - this is where servers are installed
33# depending on your usage, you can enable some of the commands below: 33# depending on your usage, you can enable some of the commands below:
34 34
35noblacklist /sbin 35nodeny /sbin
36noblacklist /usr/sbin 36nodeny /usr/sbin
37# noblacklist /var/opt 37# noblacklist /var/opt
38 38
39blacklist /tmp/.X11-unix 39deny /tmp/.X11-unix
40blacklist ${RUNUSER}/wayland-* 40deny ${RUNUSER}/wayland-*
41 41
42include disable-common.inc 42include disable-common.inc
43# include disable-devel.inc 43# include disable-devel.inc
diff --git a/etc/profile-m-z/shellcheck.profile b/etc/profile-m-z/shellcheck.profile
index b7f398f45..0cb9de45a 100644
--- a/etc/profile-m-z/shellcheck.profile
+++ b/etc/profile-m-z/shellcheck.profile
@@ -7,9 +7,9 @@ include shellcheck.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10blacklist ${RUNUSER} 10deny ${RUNUSER}
11 11
12noblacklist ${DOCUMENTS} 12nodeny ${DOCUMENTS}
13 13
14include disable-common.inc 14include disable-common.inc
15include disable-devel.inc 15include disable-devel.inc
@@ -19,7 +19,7 @@ include disable-passwdmgr.inc
19include disable-programs.inc 19include disable-programs.inc
20include disable-xdg.inc 20include disable-xdg.inc
21 21
22whitelist /usr/share/shellcheck 22allow /usr/share/shellcheck
23include whitelist-usr-share-common.inc 23include whitelist-usr-share-common.inc
24include whitelist-var-common.inc 24include whitelist-var-common.inc
25 25
diff --git a/etc/profile-m-z/shortwave.profile b/etc/profile-m-z/shortwave.profile
index d629240ec..a8e5f6b18 100644
--- a/etc/profile-m-z/shortwave.profile
+++ b/etc/profile-m-z/shortwave.profile
@@ -6,8 +6,8 @@ include shortwave.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.cache/Shortwave 9nodeny ${HOME}/.cache/Shortwave
10noblacklist ${HOME}/.local/share/Shortwave 10nodeny ${HOME}/.local/share/Shortwave
11 11
12include disable-common.inc 12include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
@@ -19,9 +19,9 @@ include disable-xdg.inc
19 19
20mkdir ${HOME}/.cache/Shortwave 20mkdir ${HOME}/.cache/Shortwave
21mkdir ${HOME}/.local/share/Shortwave 21mkdir ${HOME}/.local/share/Shortwave
22whitelist ${HOME}/.cache/Shortwave 22allow ${HOME}/.cache/Shortwave
23whitelist ${HOME}/.local/share/Shortwave 23allow ${HOME}/.local/share/Shortwave
24whitelist /usr/share/shortwave 24allow /usr/share/shortwave
25include whitelist-common.inc 25include whitelist-common.inc
26include whitelist-runuser-common.inc 26include whitelist-runuser-common.inc
27include whitelist-usr-share-common.inc 27include whitelist-usr-share-common.inc
diff --git a/etc/profile-m-z/shotcut.profile b/etc/profile-m-z/shotcut.profile
index 63af4d367..1f3c39c46 100644
--- a/etc/profile-m-z/shotcut.profile
+++ b/etc/profile-m-z/shotcut.profile
@@ -8,7 +8,7 @@ include globals.local
8 8
9ignore noexec ${HOME} 9ignore noexec ${HOME}
10 10
11noblacklist ${HOME}/.config/Meltytech 11nodeny ${HOME}/.config/Meltytech
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
diff --git a/etc/profile-m-z/shotwell.profile b/etc/profile-m-z/shotwell.profile
index ddc8a7743..b653930c3 100644
--- a/etc/profile-m-z/shotwell.profile
+++ b/etc/profile-m-z/shotwell.profile
@@ -6,10 +6,10 @@ include shotwell.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.cache/shotwell 9nodeny ${HOME}/.cache/shotwell
10noblacklist ${HOME}/.local/share/shotwell 10nodeny ${HOME}/.local/share/shotwell
11 11
12noblacklist ${PICTURES} 12nodeny ${PICTURES}
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
15include disable-exec.inc 15include disable-exec.inc
@@ -21,9 +21,9 @@ include disable-xdg.inc
21 21
22mkdir ${HOME}/.cache/shotwell 22mkdir ${HOME}/.cache/shotwell
23mkdir ${HOME}/.local/share/shotwell 23mkdir ${HOME}/.local/share/shotwell
24whitelist ${HOME}/.cache/shotwell 24allow ${HOME}/.cache/shotwell
25whitelist ${HOME}/.local/share/shotwell 25allow ${HOME}/.local/share/shotwell
26whitelist ${PICTURES} 26allow ${PICTURES}
27include whitelist-common.inc 27include whitelist-common.inc
28include whitelist-runuser-common.inc 28include whitelist-runuser-common.inc
29include whitelist-usr-share-common.inc 29include whitelist-usr-share-common.inc
diff --git a/etc/profile-m-z/signal-cli.profile b/etc/profile-m-z/signal-cli.profile
index 478377344..8a46899f1 100644
--- a/etc/profile-m-z/signal-cli.profile
+++ b/etc/profile-m-z/signal-cli.profile
@@ -6,10 +6,10 @@ include signal-cli.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9blacklist /tmp/.X11-unix 9deny /tmp/.X11-unix
10blacklist ${RUNUSER}/wayland-* 10deny ${RUNUSER}/wayland-*
11 11
12noblacklist ${HOME}/.local/share/signal-cli 12nodeny ${HOME}/.local/share/signal-cli
13 13
14include allow-java.inc 14include allow-java.inc
15 15
@@ -22,7 +22,7 @@ include disable-programs.inc
22include disable-xdg.inc 22include disable-xdg.inc
23 23
24mkdir ${HOME}/.local/share/signal-cli 24mkdir ${HOME}/.local/share/signal-cli
25whitelist ${HOME}/.local/share/signal-cli 25allow ${HOME}/.local/share/signal-cli
26include whitelist-common.inc 26include whitelist-common.inc
27include whitelist-var-common.inc 27include whitelist-var-common.inc
28 28
diff --git a/etc/profile-m-z/signal-desktop.profile b/etc/profile-m-z/signal-desktop.profile
index 77a7f5b38..a12080748 100644
--- a/etc/profile-m-z/signal-desktop.profile
+++ b/etc/profile-m-z/signal-desktop.profile
@@ -9,15 +9,15 @@ ignore novideo
9 9
10ignore noexec /tmp 10ignore noexec /tmp
11 11
12noblacklist ${HOME}/.config/Signal 12nodeny ${HOME}/.config/Signal
13 13
14# These lines are needed to allow Firefox to open links 14# These lines are needed to allow Firefox to open links
15noblacklist ${HOME}/.mozilla 15nodeny ${HOME}/.mozilla
16whitelist ${HOME}/.mozilla/firefox/profiles.ini 16allow ${HOME}/.mozilla/firefox/profiles.ini
17read-only ${HOME}/.mozilla/firefox/profiles.ini 17read-only ${HOME}/.mozilla/firefox/profiles.ini
18 18
19mkdir ${HOME}/.config/Signal 19mkdir ${HOME}/.config/Signal
20whitelist ${HOME}/.config/Signal 20allow ${HOME}/.config/Signal
21 21
22private-etc alternatives,ca-certificates,crypto-policies,fonts,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,localtime,machine-id,nsswitch.conf,pki,resolv.conf,ssl 22private-etc alternatives,ca-certificates,crypto-policies,fonts,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,localtime,machine-id,nsswitch.conf,pki,resolv.conf,ssl
23 23
diff --git a/etc/profile-m-z/simple-scan.profile b/etc/profile-m-z/simple-scan.profile
index 17920677b..589a44ffc 100644
--- a/etc/profile-m-z/simple-scan.profile
+++ b/etc/profile-m-z/simple-scan.profile
@@ -6,8 +6,8 @@ include simple-scan.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.cache/simple-scan 9nodeny ${HOME}/.cache/simple-scan
10noblacklist ${DOCUMENTS} 10nodeny ${DOCUMENTS}
11 11
12include disable-common.inc 12include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
@@ -16,8 +16,8 @@ include disable-passwdmgr.inc
16include disable-programs.inc 16include disable-programs.inc
17include disable-xdg.inc 17include disable-xdg.inc
18 18
19whitelist /usr/share/hplip 19allow /usr/share/hplip
20whitelist /usr/share/simple-scan 20allow /usr/share/simple-scan
21include whitelist-usr-share-common.inc 21include whitelist-usr-share-common.inc
22include whitelist-var-common.inc 22include whitelist-var-common.inc
23 23
diff --git a/etc/profile-m-z/simplescreenrecorder.profile b/etc/profile-m-z/simplescreenrecorder.profile
index d664f8bf5..83f833508 100644
--- a/etc/profile-m-z/simplescreenrecorder.profile
+++ b/etc/profile-m-z/simplescreenrecorder.profile
@@ -6,8 +6,8 @@ include simplescreenrecorder.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${VIDEOS} 9nodeny ${VIDEOS}
10noblacklist ${HOME}/.ssr 10nodeny ${HOME}/.ssr
11 11
12include disable-common.inc 12include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
@@ -17,7 +17,7 @@ include disable-passwdmgr.inc
17include disable-programs.inc 17include disable-programs.inc
18include disable-xdg.inc 18include disable-xdg.inc
19 19
20whitelist /usr/share/simplescreenrecorder 20allow /usr/share/simplescreenrecorder
21include whitelist-usr-share-common.inc 21include whitelist-usr-share-common.inc
22include whitelist-var-common.inc 22include whitelist-var-common.inc
23 23
diff --git a/etc/profile-m-z/simutrans.profile b/etc/profile-m-z/simutrans.profile
index afaa0f6d8..1d7f41579 100644
--- a/etc/profile-m-z/simutrans.profile
+++ b/etc/profile-m-z/simutrans.profile
@@ -6,7 +6,7 @@ include simutrans.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.simutrans 9nodeny ${HOME}/.simutrans
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -16,7 +16,7 @@ include disable-passwdmgr.inc
16include disable-programs.inc 16include disable-programs.inc
17 17
18mkdir ${HOME}/.simutrans 18mkdir ${HOME}/.simutrans
19whitelist ${HOME}/.simutrans 19allow ${HOME}/.simutrans
20include whitelist-common.inc 20include whitelist-common.inc
21include whitelist-var-common.inc 21include whitelist-var-common.inc
22 22
diff --git a/etc/profile-m-z/skanlite.profile b/etc/profile-m-z/skanlite.profile
index 093a61398..98ed624f9 100644
--- a/etc/profile-m-z/skanlite.profile
+++ b/etc/profile-m-z/skanlite.profile
@@ -6,7 +6,7 @@ include skanlite.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${DOCUMENTS} 9nodeny ${DOCUMENTS}
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
diff --git a/etc/profile-m-z/skypeforlinux.profile b/etc/profile-m-z/skypeforlinux.profile
index ed04eda8e..e7f70eebe 100644
--- a/etc/profile-m-z/skypeforlinux.profile
+++ b/etc/profile-m-z/skypeforlinux.profile
@@ -21,7 +21,7 @@ ignore dbus-system none
21ignore apparmor 21ignore apparmor
22ignore noexec /tmp 22ignore noexec /tmp
23 23
24noblacklist ${HOME}/.config/skypeforlinux 24nodeny ${HOME}/.config/skypeforlinux
25 25
26# private-dev - needs /dev/disk 26# private-dev - needs /dev/disk
27 27
diff --git a/etc/profile-m-z/slack.profile b/etc/profile-m-z/slack.profile
index 51f6c8b00..b8299add3 100644
--- a/etc/profile-m-z/slack.profile
+++ b/etc/profile-m-z/slack.profile
@@ -16,14 +16,14 @@ ignore private-tmp
16ignore dbus-user none 16ignore dbus-user none
17ignore dbus-system none 17ignore dbus-system none
18 18
19noblacklist ${HOME}/.config/Slack 19nodeny ${HOME}/.config/Slack
20 20
21include allow-bin-sh.inc 21include allow-bin-sh.inc
22 22
23include disable-shell.inc 23include disable-shell.inc
24 24
25mkdir ${HOME}/.config/Slack 25mkdir ${HOME}/.config/Slack
26whitelist ${HOME}/.config/Slack 26allow ${HOME}/.config/Slack
27 27
28private-bin electron,electron[0-9],electron[0-9][0-9],locale,sh,slack 28private-bin electron,electron[0-9],electron[0-9][0-9],locale,sh,slack
29private-etc alternatives,asound.conf,ca-certificates,crypto-policies,debian_version,fedora-release,fonts,group,ld.so.cache,ld.so.conf,localtime,machine-id,os-release,passwd,pki,pulse,redhat-release,resolv.conf,ssl,system-release,system-release-cpe 29private-etc alternatives,asound.conf,ca-certificates,crypto-policies,debian_version,fedora-release,fonts,group,ld.so.cache,ld.so.conf,localtime,machine-id,os-release,passwd,pki,pulse,redhat-release,resolv.conf,ssl,system-release,system-release-cpe
diff --git a/etc/profile-m-z/slashem.profile b/etc/profile-m-z/slashem.profile
index c5a31c237..36a0044dc 100644
--- a/etc/profile-m-z/slashem.profile
+++ b/etc/profile-m-z/slashem.profile
@@ -6,7 +6,7 @@ include slashem.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist /var/games/slashem 9nodeny /var/games/slashem
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -15,7 +15,7 @@ include disable-interpreters.inc
15include disable-passwdmgr.inc 15include disable-passwdmgr.inc
16include disable-programs.inc 16include disable-programs.inc
17 17
18whitelist /var/games/slashem 18allow /var/games/slashem
19include whitelist-common.inc 19include whitelist-common.inc
20include whitelist-var-common.inc 20include whitelist-var-common.inc
21 21
diff --git a/etc/profile-m-z/smplayer.profile b/etc/profile-m-z/smplayer.profile
index 01547e5c1..4e4334dc0 100644
--- a/etc/profile-m-z/smplayer.profile
+++ b/etc/profile-m-z/smplayer.profile
@@ -6,9 +6,9 @@ include smplayer.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/smplayer 9nodeny ${HOME}/.config/smplayer
10noblacklist ${HOME}/.config/youtube-dl 10nodeny ${HOME}/.config/youtube-dl
11noblacklist ${HOME}/.mplayer 11nodeny ${HOME}/.mplayer
12 12
13# Allow lua (blacklisted by disable-interpreters.inc) 13# Allow lua (blacklisted by disable-interpreters.inc)
14include allow-lua.inc 14include allow-lua.inc
@@ -17,8 +17,8 @@ include allow-lua.inc
17include allow-python2.inc 17include allow-python2.inc
18include allow-python3.inc 18include allow-python3.inc
19 19
20noblacklist ${MUSIC} 20nodeny ${MUSIC}
21noblacklist ${VIDEOS} 21nodeny ${VIDEOS}
22 22
23include disable-common.inc 23include disable-common.inc
24include disable-devel.inc 24include disable-devel.inc
@@ -29,9 +29,9 @@ include disable-programs.inc
29include disable-shell.inc 29include disable-shell.inc
30include disable-xdg.inc 30include disable-xdg.inc
31 31
32whitelist /usr/share/lua* 32allow /usr/share/lua*
33whitelist /usr/share/smplayer 33allow /usr/share/smplayer
34whitelist /usr/share/vulkan 34allow /usr/share/vulkan
35include whitelist-usr-share-common.inc 35include whitelist-usr-share-common.inc
36include whitelist-var-common.inc 36include whitelist-var-common.inc
37 37
diff --git a/etc/profile-m-z/smtube.profile b/etc/profile-m-z/smtube.profile
index 196950eaf..99d02ffdf 100644
--- a/etc/profile-m-z/smtube.profile
+++ b/etc/profile-m-z/smtube.profile
@@ -6,14 +6,14 @@ include smtube.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/smplayer 9nodeny ${HOME}/.config/smplayer
10noblacklist ${HOME}/.config/smtube 10nodeny ${HOME}/.config/smtube
11noblacklist ${HOME}/.config/mpv 11nodeny ${HOME}/.config/mpv
12noblacklist ${HOME}/.mplayer 12nodeny ${HOME}/.mplayer
13noblacklist ${HOME}/.config/vlc 13nodeny ${HOME}/.config/vlc
14noblacklist ${HOME}/.local/share/vlc 14nodeny ${HOME}/.local/share/vlc
15noblacklist ${MUSIC} 15nodeny ${MUSIC}
16noblacklist ${VIDEOS} 16nodeny ${VIDEOS}
17 17
18include disable-common.inc 18include disable-common.inc
19include disable-devel.inc 19include disable-devel.inc
@@ -23,8 +23,8 @@ include disable-passwdmgr.inc
23include disable-programs.inc 23include disable-programs.inc
24include disable-xdg.inc 24include disable-xdg.inc
25 25
26whitelist /usr/share/smplayer 26allow /usr/share/smplayer
27whitelist /usr/share/smtube 27allow /usr/share/smtube
28include whitelist-usr-share-common.inc 28include whitelist-usr-share-common.inc
29include whitelist-var-common.inc 29include whitelist-var-common.inc
30 30
diff --git a/etc/profile-m-z/smuxi-frontend-gnome.profile b/etc/profile-m-z/smuxi-frontend-gnome.profile
index c3a9bb858..3a79890cc 100644
--- a/etc/profile-m-z/smuxi-frontend-gnome.profile
+++ b/etc/profile-m-z/smuxi-frontend-gnome.profile
@@ -6,9 +6,9 @@ include smuxi-frontend-gnome.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.cache/smuxi 9nodeny ${HOME}/.cache/smuxi
10noblacklist ${HOME}/.config/smuxi 10nodeny ${HOME}/.config/smuxi
11noblacklist ${HOME}/.local/share/smuxi 11nodeny ${HOME}/.local/share/smuxi
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
@@ -21,10 +21,10 @@ include disable-xdg.inc
21mkdir ${HOME}/.cache/smuxi 21mkdir ${HOME}/.cache/smuxi
22mkdir ${HOME}/.config/smuxi 22mkdir ${HOME}/.config/smuxi
23mkdir ${HOME}/.local/share/smuxi 23mkdir ${HOME}/.local/share/smuxi
24whitelist ${HOME}/.cache/smuxi 24allow ${HOME}/.cache/smuxi
25whitelist ${HOME}/.config/smuxi 25allow ${HOME}/.config/smuxi
26whitelist ${HOME}/.local/share/smuxi 26allow ${HOME}/.local/share/smuxi
27whitelist ${DOWNLOADS} 27allow ${DOWNLOADS}
28include whitelist-common.inc 28include whitelist-common.inc
29include whitelist-runuser-common.inc 29include whitelist-runuser-common.inc
30include whitelist-usr-share-common.inc 30include whitelist-usr-share-common.inc
diff --git a/etc/profile-m-z/snox.profile b/etc/profile-m-z/snox.profile
index 83493652c..1d315404e 100644
--- a/etc/profile-m-z/snox.profile
+++ b/etc/profile-m-z/snox.profile
@@ -10,15 +10,15 @@ ignore whitelist /usr/share/chromium
10ignore include whitelist-runuser-common.inc 10ignore include whitelist-runuser-common.inc
11ignore include whitelist-usr-share-common.inc 11ignore include whitelist-usr-share-common.inc
12 12
13noblacklist ${HOME}/.cache/snox 13nodeny ${HOME}/.cache/snox
14noblacklist ${HOME}/.config/snox 14nodeny ${HOME}/.config/snox
15 15
16#mkdir ${HOME}/.cache/dnox 16#mkdir ${HOME}/.cache/dnox
17#mkdir ${HOME}/.config/dnox 17#mkdir ${HOME}/.config/dnox
18mkdir ${HOME}/.cache/snox 18mkdir ${HOME}/.cache/snox
19mkdir ${HOME}/.config/snox 19mkdir ${HOME}/.config/snox
20whitelist ${HOME}/.cache/snox 20allow ${HOME}/.cache/snox
21whitelist ${HOME}/.config/snox 21allow ${HOME}/.config/snox
22 22
23# Redirect 23# Redirect
24include chromium-common.profile 24include chromium-common.profile
diff --git a/etc/profile-m-z/softmaker-common.profile b/etc/profile-m-z/softmaker-common.profile
index 83315231f..bd4991e81 100644
--- a/etc/profile-m-z/softmaker-common.profile
+++ b/etc/profile-m-z/softmaker-common.profile
@@ -10,7 +10,7 @@ include softmaker-common.local
10# with an absolute Exec line. These files are NOT handelt by firecfg, 10# with an absolute Exec line. These files are NOT handelt by firecfg,
11# therefore you must manualy copy them in you home and remove '/usr/bin/'. 11# therefore you must manualy copy them in you home and remove '/usr/bin/'.
12 12
13noblacklist ${HOME}/SoftMaker 13nodeny ${HOME}/SoftMaker
14 14
15include disable-common.inc 15include disable-common.inc
16include disable-devel.inc 16include disable-devel.inc
@@ -19,8 +19,8 @@ include disable-interpreters.inc
19include disable-passwdmgr.inc 19include disable-passwdmgr.inc
20include disable-programs.inc 20include disable-programs.inc
21 21
22whitelist /usr/share/office2018 22allow /usr/share/office2018
23whitelist /usr/share/freeoffice2018 23allow /usr/share/freeoffice2018
24include whitelist-usr-share-common.inc 24include whitelist-usr-share-common.inc
25include whitelist-var-common.inc 25include whitelist-var-common.inc
26 26
diff --git a/etc/profile-m-z/sound-juicer.profile b/etc/profile-m-z/sound-juicer.profile
index ef00fdfff..16ee39e09 100644
--- a/etc/profile-m-z/sound-juicer.profile
+++ b/etc/profile-m-z/sound-juicer.profile
@@ -6,8 +6,8 @@ include sound-juicer.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/sound-juicer 9nodeny ${HOME}/.config/sound-juicer
10noblacklist ${MUSIC} 10nodeny ${MUSIC}
11 11
12include disable-common.inc 12include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
diff --git a/etc/profile-m-z/soundconverter.profile b/etc/profile-m-z/soundconverter.profile
index 4dbf34100..46da7a453 100644
--- a/etc/profile-m-z/soundconverter.profile
+++ b/etc/profile-m-z/soundconverter.profile
@@ -10,7 +10,7 @@ include globals.local
10include allow-python2.inc 10include allow-python2.inc
11include allow-python3.inc 11include allow-python3.inc
12 12
13noblacklist ${MUSIC} 13nodeny ${MUSIC}
14 14
15include disable-common.inc 15include disable-common.inc
16include disable-devel.inc 16include disable-devel.inc
@@ -20,9 +20,9 @@ include disable-passwdmgr.inc
20include disable-programs.inc 20include disable-programs.inc
21include disable-xdg.inc 21include disable-xdg.inc
22 22
23whitelist ${DOWNLOADS} 23allow ${DOWNLOADS}
24whitelist ${MUSIC} 24allow ${MUSIC}
25whitelist /usr/share/soundconverter 25allow /usr/share/soundconverter
26include whitelist-common.inc 26include whitelist-common.inc
27include whitelist-usr-share-common.inc 27include whitelist-usr-share-common.inc
28include whitelist-var-common.inc 28include whitelist-var-common.inc
diff --git a/etc/profile-m-z/spectacle.profile b/etc/profile-m-z/spectacle.profile
index 4468f21e7..08adb5861 100644
--- a/etc/profile-m-z/spectacle.profile
+++ b/etc/profile-m-z/spectacle.profile
@@ -12,8 +12,8 @@ include globals.local
12#private-etc ca-certificates,crypto-policies,pki,resolv.conf,ssl 12#private-etc ca-certificates,crypto-policies,pki,resolv.conf,ssl
13#protocol unix,inet,inet6 13#protocol unix,inet,inet6
14 14
15noblacklist ${HOME}/.config/spectaclerc 15nodeny ${HOME}/.config/spectaclerc
16noblacklist ${PICTURES} 16nodeny ${PICTURES}
17 17
18include disable-common.inc 18include disable-common.inc
19include disable-devel.inc 19include disable-devel.inc
@@ -24,10 +24,10 @@ include disable-programs.inc
24include disable-xdg.inc 24include disable-xdg.inc
25 25
26mkfile ${HOME}/.config/spectaclerc 26mkfile ${HOME}/.config/spectaclerc
27whitelist ${HOME}/.config/spectaclerc 27allow ${HOME}/.config/spectaclerc
28whitelist ${PICTURES} 28allow ${PICTURES}
29whitelist /usr/share/kconf_update/spectacle_newConfig.upd 29allow /usr/share/kconf_update/spectacle_newConfig.upd
30whitelist /usr/share/kconf_update/spectacle_shortcuts.upd 30allow /usr/share/kconf_update/spectacle_shortcuts.upd
31include whitelist-common.inc 31include whitelist-common.inc
32include whitelist-runuser-common.inc 32include whitelist-runuser-common.inc
33include whitelist-usr-share-common.inc 33include whitelist-usr-share-common.inc
diff --git a/etc/profile-m-z/spectral.profile b/etc/profile-m-z/spectral.profile
index 283674517..4c1b2d3e1 100644
--- a/etc/profile-m-z/spectral.profile
+++ b/etc/profile-m-z/spectral.profile
@@ -6,8 +6,8 @@ include spectral.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.cache/ENCOM/Spectral 9nodeny ${HOME}/.cache/ENCOM/Spectral
10noblacklist ${HOME}/.config/ENCOM 10nodeny ${HOME}/.config/ENCOM
11 11
12include disable-common.inc 12include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
@@ -20,9 +20,9 @@ include disable-xdg.inc
20 20
21mkdir ${HOME}/.cache/ENCOM/Spectral 21mkdir ${HOME}/.cache/ENCOM/Spectral
22mkdir ${HOME}/.config/ENCOM 22mkdir ${HOME}/.config/ENCOM
23whitelist ${HOME}/.cache/ENCOM/Spectral 23allow ${HOME}/.cache/ENCOM/Spectral
24whitelist ${HOME}/.config/ENCOM 24allow ${HOME}/.config/ENCOM
25whitelist ${DOWNLOADS} 25allow ${DOWNLOADS}
26include whitelist-common.inc 26include whitelist-common.inc
27include whitelist-runuser-common.inc 27include whitelist-runuser-common.inc
28include whitelist-usr-share-common.inc 28include whitelist-usr-share-common.inc
diff --git a/etc/profile-m-z/spectre-meltdown-checker.profile b/etc/profile-m-z/spectre-meltdown-checker.profile
index 984461f90..3a3fd838d 100644
--- a/etc/profile-m-z/spectre-meltdown-checker.profile
+++ b/etc/profile-m-z/spectre-meltdown-checker.profile
@@ -6,10 +6,10 @@ include spectre-meltdown-checker.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9blacklist ${RUNUSER}/wayland-* 9deny ${RUNUSER}/wayland-*
10 10
11noblacklist ${PATH}/mount 11nodeny ${PATH}/mount
12noblacklist ${PATH}/umount 12nodeny ${PATH}/umount
13 13
14# Allow perl (blacklisted by disable-interpreters.inc) 14# Allow perl (blacklisted by disable-interpreters.inc)
15include allow-perl.inc 15include allow-perl.inc
diff --git a/etc/profile-m-z/spotify.profile b/etc/profile-m-z/spotify.profile
index 01bc2bc05..e1c830268 100644
--- a/etc/profile-m-z/spotify.profile
+++ b/etc/profile-m-z/spotify.profile
@@ -5,11 +5,11 @@ include spotify.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${HOME}/.cache/spotify 8nodeny ${HOME}/.cache/spotify
9noblacklist ${HOME}/.config/spotify 9nodeny ${HOME}/.config/spotify
10noblacklist ${HOME}/.local/share/spotify 10nodeny ${HOME}/.local/share/spotify
11 11
12blacklist ${HOME}/.bashrc 12deny ${HOME}/.bashrc
13 13
14include disable-common.inc 14include disable-common.inc
15include disable-devel.inc 15include disable-devel.inc
@@ -21,9 +21,9 @@ include disable-programs.inc
21mkdir ${HOME}/.cache/spotify 21mkdir ${HOME}/.cache/spotify
22mkdir ${HOME}/.config/spotify 22mkdir ${HOME}/.config/spotify
23mkdir ${HOME}/.local/share/spotify 23mkdir ${HOME}/.local/share/spotify
24whitelist ${HOME}/.cache/spotify 24allow ${HOME}/.cache/spotify
25whitelist ${HOME}/.config/spotify 25allow ${HOME}/.config/spotify
26whitelist ${HOME}/.local/share/spotify 26allow ${HOME}/.local/share/spotify
27include whitelist-common.inc 27include whitelist-common.inc
28include whitelist-var-common.inc 28include whitelist-var-common.inc
29 29
diff --git a/etc/profile-m-z/sqlitebrowser.profile b/etc/profile-m-z/sqlitebrowser.profile
index 4dd2c7262..aa577b63a 100644
--- a/etc/profile-m-z/sqlitebrowser.profile
+++ b/etc/profile-m-z/sqlitebrowser.profile
@@ -6,8 +6,8 @@ include sqlitebrowser.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/sqlitebrowser 9nodeny ${HOME}/.config/sqlitebrowser
10noblacklist ${DOCUMENTS} 10nodeny ${DOCUMENTS}
11 11
12include disable-common.inc 12include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
diff --git a/etc/profile-m-z/ssh-agent.profile b/etc/profile-m-z/ssh-agent.profile
index 5802299a3..e456ebe07 100644
--- a/etc/profile-m-z/ssh-agent.profile
+++ b/etc/profile-m-z/ssh-agent.profile
@@ -9,8 +9,8 @@ include globals.local
9# Allow ssh (blacklisted by disable-common.inc) 9# Allow ssh (blacklisted by disable-common.inc)
10include allow-ssh.inc 10include allow-ssh.inc
11 11
12blacklist /tmp/.X11-unix 12deny /tmp/.X11-unix
13blacklist ${RUNUSER}/wayland-* 13deny ${RUNUSER}/wayland-*
14 14
15include disable-common.inc 15include disable-common.inc
16include disable-passwdmgr.inc 16include disable-passwdmgr.inc
diff --git a/etc/profile-m-z/ssh.profile b/etc/profile-m-z/ssh.profile
index a58642192..8a0d86150 100644
--- a/etc/profile-m-z/ssh.profile
+++ b/etc/profile-m-z/ssh.profile
@@ -8,8 +8,8 @@ include ssh.local
8include globals.local 8include globals.local
9 9
10# nc can be used as ProxyCommand, e.g. when using tor 10# nc can be used as ProxyCommand, e.g. when using tor
11noblacklist ${PATH}/nc 11nodeny ${PATH}/nc
12noblacklist ${PATH}/ncat 12nodeny ${PATH}/ncat
13 13
14# Allow ssh (blacklisted by disable-common.inc) 14# Allow ssh (blacklisted by disable-common.inc)
15include allow-ssh.inc 15include allow-ssh.inc
@@ -19,8 +19,8 @@ include disable-exec.inc
19include disable-passwdmgr.inc 19include disable-passwdmgr.inc
20include disable-programs.inc 20include disable-programs.inc
21 21
22whitelist ${RUNUSER}/gnupg/S.gpg-agent.ssh 22allow ${RUNUSER}/gnupg/S.gpg-agent.ssh
23whitelist ${RUNUSER}/keyring/ssh 23allow ${RUNUSER}/keyring/ssh
24include whitelist-usr-share-common.inc 24include whitelist-usr-share-common.inc
25include whitelist-runuser-common.inc 25include whitelist-runuser-common.inc
26 26
diff --git a/etc/profile-m-z/standardnotes-desktop.profile b/etc/profile-m-z/standardnotes-desktop.profile
index 48a532876..75de118ab 100644
--- a/etc/profile-m-z/standardnotes-desktop.profile
+++ b/etc/profile-m-z/standardnotes-desktop.profile
@@ -5,8 +5,8 @@ include standardnotes-desktop.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${HOME}/Standard Notes Backups 8nodeny ${HOME}/Standard Notes Backups
9noblacklist ${HOME}/.config/Standard Notes 9nodeny ${HOME}/.config/Standard Notes
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -17,8 +17,8 @@ include disable-programs.inc
17 17
18mkdir ${HOME}/Standard Notes Backups 18mkdir ${HOME}/Standard Notes Backups
19mkdir ${HOME}/.config/Standard Notes 19mkdir ${HOME}/.config/Standard Notes
20whitelist ${HOME}/Standard Notes Backups 20allow ${HOME}/Standard Notes Backups
21whitelist ${HOME}/.config/Standard Notes 21allow ${HOME}/.config/Standard Notes
22include whitelist-var-common.inc 22include whitelist-var-common.inc
23 23
24apparmor 24apparmor
diff --git a/etc/profile-m-z/start-tor-browser.desktop.profile b/etc/profile-m-z/start-tor-browser.desktop.profile
index 2f73c9fee..8f75365e8 100644
--- a/etc/profile-m-z/start-tor-browser.desktop.profile
+++ b/etc/profile-m-z/start-tor-browser.desktop.profile
@@ -6,71 +6,71 @@ include start-tor-browser.desktop.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.tor-browser* 9nodeny ${HOME}/.tor-browser*
10 10
11whitelist ${HOME}/.tor-browser-ar 11allow ${HOME}/.tor-browser-ar
12whitelist ${HOME}/.tor-browser-ca 12allow ${HOME}/.tor-browser-ca
13whitelist ${HOME}/.tor-browser-cs 13allow ${HOME}/.tor-browser-cs
14whitelist ${HOME}/.tor-browser-da 14allow ${HOME}/.tor-browser-da
15whitelist ${HOME}/.tor-browser-de 15allow ${HOME}/.tor-browser-de
16whitelist ${HOME}/.tor-browser-el 16allow ${HOME}/.tor-browser-el
17whitelist ${HOME}/.tor-browser-en 17allow ${HOME}/.tor-browser-en
18whitelist ${HOME}/.tor-browser-en-us 18allow ${HOME}/.tor-browser-en-us
19whitelist ${HOME}/.tor-browser-es 19allow ${HOME}/.tor-browser-es
20whitelist ${HOME}/.tor-browser-es-es 20allow ${HOME}/.tor-browser-es-es
21whitelist ${HOME}/.tor-browser-fa 21allow ${HOME}/.tor-browser-fa
22whitelist ${HOME}/.tor-browser-fr 22allow ${HOME}/.tor-browser-fr
23whitelist ${HOME}/.tor-browser-ga-ie 23allow ${HOME}/.tor-browser-ga-ie
24whitelist ${HOME}/.tor-browser-he 24allow ${HOME}/.tor-browser-he
25whitelist ${HOME}/.tor-browser-hu 25allow ${HOME}/.tor-browser-hu
26whitelist ${HOME}/.tor-browser-id 26allow ${HOME}/.tor-browser-id
27whitelist ${HOME}/.tor-browser-is 27allow ${HOME}/.tor-browser-is
28whitelist ${HOME}/.tor-browser-it 28allow ${HOME}/.tor-browser-it
29whitelist ${HOME}/.tor-browser-ja 29allow ${HOME}/.tor-browser-ja
30whitelist ${HOME}/.tor-browser-ka 30allow ${HOME}/.tor-browser-ka
31whitelist ${HOME}/.tor-browser-ko 31allow ${HOME}/.tor-browser-ko
32whitelist ${HOME}/.tor-browser-nb 32allow ${HOME}/.tor-browser-nb
33whitelist ${HOME}/.tor-browser-nl 33allow ${HOME}/.tor-browser-nl
34whitelist ${HOME}/.tor-browser-pl 34allow ${HOME}/.tor-browser-pl
35whitelist ${HOME}/.tor-browser-pt-br 35allow ${HOME}/.tor-browser-pt-br
36whitelist ${HOME}/.tor-browser-ru 36allow ${HOME}/.tor-browser-ru
37whitelist ${HOME}/.tor-browser-sv-se 37allow ${HOME}/.tor-browser-sv-se
38whitelist ${HOME}/.tor-browser-tr 38allow ${HOME}/.tor-browser-tr
39whitelist ${HOME}/.tor-browser-vi 39allow ${HOME}/.tor-browser-vi
40whitelist ${HOME}/.tor-browser-zh-cn 40allow ${HOME}/.tor-browser-zh-cn
41whitelist ${HOME}/.tor-browser-zh-tw 41allow ${HOME}/.tor-browser-zh-tw
42 42
43whitelist ${HOME}/.tor-browser_ar 43allow ${HOME}/.tor-browser_ar
44whitelist ${HOME}/.tor-browser_ca 44allow ${HOME}/.tor-browser_ca
45whitelist ${HOME}/.tor-browser_cs 45allow ${HOME}/.tor-browser_cs
46whitelist ${HOME}/.tor-browser_da 46allow ${HOME}/.tor-browser_da
47whitelist ${HOME}/.tor-browser_de 47allow ${HOME}/.tor-browser_de
48whitelist ${HOME}/.tor-browser_el 48allow ${HOME}/.tor-browser_el
49whitelist ${HOME}/.tor-browser_en 49allow ${HOME}/.tor-browser_en
50whitelist ${HOME}/.tor-browser_en_US 50allow ${HOME}/.tor-browser_en_US
51whitelist ${HOME}/.tor-browser_es 51allow ${HOME}/.tor-browser_es
52whitelist ${HOME}/.tor-browser_es-ES 52allow ${HOME}/.tor-browser_es-ES
53whitelist ${HOME}/.tor-browser_fa 53allow ${HOME}/.tor-browser_fa
54whitelist ${HOME}/.tor-browser_fr 54allow ${HOME}/.tor-browser_fr
55whitelist ${HOME}/.tor-browser_ga-IE 55allow ${HOME}/.tor-browser_ga-IE
56whitelist ${HOME}/.tor-browser_he 56allow ${HOME}/.tor-browser_he
57whitelist ${HOME}/.tor-browser_hu 57allow ${HOME}/.tor-browser_hu
58whitelist ${HOME}/.tor-browser_id 58allow ${HOME}/.tor-browser_id
59whitelist ${HOME}/.tor-browser_is 59allow ${HOME}/.tor-browser_is
60whitelist ${HOME}/.tor-browser_it 60allow ${HOME}/.tor-browser_it
61whitelist ${HOME}/.tor-browser_ja 61allow ${HOME}/.tor-browser_ja
62whitelist ${HOME}/.tor-browser_ka 62allow ${HOME}/.tor-browser_ka
63whitelist ${HOME}/.tor-browser_ko 63allow ${HOME}/.tor-browser_ko
64whitelist ${HOME}/.tor-browser_nb 64allow ${HOME}/.tor-browser_nb
65whitelist ${HOME}/.tor-browser_nl 65allow ${HOME}/.tor-browser_nl
66whitelist ${HOME}/.tor-browser_pl 66allow ${HOME}/.tor-browser_pl
67whitelist ${HOME}/.tor-browser_pt-BR 67allow ${HOME}/.tor-browser_pt-BR
68whitelist ${HOME}/.tor-browser_ru 68allow ${HOME}/.tor-browser_ru
69whitelist ${HOME}/.tor-browser_sv-SE 69allow ${HOME}/.tor-browser_sv-SE
70whitelist ${HOME}/.tor-browser_tr 70allow ${HOME}/.tor-browser_tr
71whitelist ${HOME}/.tor-browser_vi 71allow ${HOME}/.tor-browser_vi
72whitelist ${HOME}/.tor-browser_zh-CN 72allow ${HOME}/.tor-browser_zh-CN
73whitelist ${HOME}/.tor-browser_zh-TW 73allow ${HOME}/.tor-browser_zh-TW
74 74
75# Redirect 75# Redirect
76include torbrowser-launcher.profile 76include torbrowser-launcher.profile
diff --git a/etc/profile-m-z/steam.profile b/etc/profile-m-z/steam.profile
index 06d08f3a2..09e29373d 100644
--- a/etc/profile-m-z/steam.profile
+++ b/etc/profile-m-z/steam.profile
@@ -6,40 +6,40 @@ include steam.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/Epic 9nodeny ${HOME}/.config/Epic
10noblacklist ${HOME}/.config/Loop_Hero 10nodeny ${HOME}/.config/Loop_Hero
11noblacklist ${HOME}/.config/ModTheSpire 11nodeny ${HOME}/.config/ModTheSpire
12noblacklist ${HOME}/.config/RogueLegacy 12nodeny ${HOME}/.config/RogueLegacy
13noblacklist ${HOME}/.config/RogueLegacyStorageContainer 13nodeny ${HOME}/.config/RogueLegacyStorageContainer
14noblacklist ${HOME}/.killingfloor 14nodeny ${HOME}/.killingfloor
15noblacklist ${HOME}/.klei 15nodeny ${HOME}/.klei
16noblacklist ${HOME}/.local/share/3909/PapersPlease 16nodeny ${HOME}/.local/share/3909/PapersPlease
17noblacklist ${HOME}/.local/share/aspyr-media 17nodeny ${HOME}/.local/share/aspyr-media
18noblacklist ${HOME}/.local/share/bohemiainteractive 18nodeny ${HOME}/.local/share/bohemiainteractive
19noblacklist ${HOME}/.local/share/cdprojektred 19nodeny ${HOME}/.local/share/cdprojektred
20noblacklist ${HOME}/.local/share/Dredmor 20nodeny ${HOME}/.local/share/Dredmor
21noblacklist ${HOME}/.local/share/FasterThanLight 21nodeny ${HOME}/.local/share/FasterThanLight
22noblacklist ${HOME}/.local/share/feral-interactive 22nodeny ${HOME}/.local/share/feral-interactive
23noblacklist ${HOME}/.local/share/IntoTheBreach 23nodeny ${HOME}/.local/share/IntoTheBreach
24noblacklist ${HOME}/.local/share/Paradox Interactive 24nodeny ${HOME}/.local/share/Paradox Interactive
25noblacklist ${HOME}/.local/share/PillarsOfEternity 25nodeny ${HOME}/.local/share/PillarsOfEternity
26noblacklist ${HOME}/.local/share/RogueLegacy 26nodeny ${HOME}/.local/share/RogueLegacy
27noblacklist ${HOME}/.local/share/RogueLegacyStorageContainer 27nodeny ${HOME}/.local/share/RogueLegacyStorageContainer
28noblacklist ${HOME}/.local/share/Steam 28nodeny ${HOME}/.local/share/Steam
29noblacklist ${HOME}/.local/share/SteamWorldDig 29nodeny ${HOME}/.local/share/SteamWorldDig
30noblacklist ${HOME}/.local/share/SteamWorld Dig 2 30nodeny ${HOME}/.local/share/SteamWorld Dig 2
31noblacklist ${HOME}/.local/share/SuperHexagon 31nodeny ${HOME}/.local/share/SuperHexagon
32noblacklist ${HOME}/.local/share/Terraria 32nodeny ${HOME}/.local/share/Terraria
33noblacklist ${HOME}/.local/share/vpltd 33nodeny ${HOME}/.local/share/vpltd
34noblacklist ${HOME}/.local/share/vulkan 34nodeny ${HOME}/.local/share/vulkan
35noblacklist ${HOME}/.mbwarband 35nodeny ${HOME}/.mbwarband
36noblacklist ${HOME}/.paradoxinteractive 36nodeny ${HOME}/.paradoxinteractive
37noblacklist ${HOME}/.steam 37nodeny ${HOME}/.steam
38noblacklist ${HOME}/.steampath 38nodeny ${HOME}/.steampath
39noblacklist ${HOME}/.steampid 39nodeny ${HOME}/.steampid
40# needed for STEAM_RUNTIME_PREFER_HOST_LIBRARIES=1 to work 40# needed for STEAM_RUNTIME_PREFER_HOST_LIBRARIES=1 to work
41noblacklist /sbin 41nodeny /sbin
42noblacklist /usr/sbin 42nodeny /usr/sbin
43 43
44# Allow java (blacklisted by disable-devel.inc) 44# Allow java (blacklisted by disable-devel.inc)
45include allow-java.inc 45include allow-java.inc
@@ -84,38 +84,38 @@ mkdir ${HOME}/.paradoxinteractive
84mkdir ${HOME}/.steam 84mkdir ${HOME}/.steam
85mkfile ${HOME}/.steampath 85mkfile ${HOME}/.steampath
86mkfile ${HOME}/.steampid 86mkfile ${HOME}/.steampid
87whitelist ${HOME}/.config/Epic 87allow ${HOME}/.config/Epic
88whitelist ${HOME}/.config/Loop_Hero 88allow ${HOME}/.config/Loop_Hero
89whitelist ${HOME}/.config/ModTheSpire 89allow ${HOME}/.config/ModTheSpire
90whitelist ${HOME}/.config/RogueLegacy 90allow ${HOME}/.config/RogueLegacy
91whitelist ${HOME}/.config/RogueLegacyStorageContainer 91allow ${HOME}/.config/RogueLegacyStorageContainer
92whitelist ${HOME}/.config/unity3d 92allow ${HOME}/.config/unity3d
93whitelist ${HOME}/.killingfloor 93allow ${HOME}/.killingfloor
94whitelist ${HOME}/.klei 94allow ${HOME}/.klei
95whitelist ${HOME}/.local/share/3909/PapersPlease 95allow ${HOME}/.local/share/3909/PapersPlease
96whitelist ${HOME}/.local/share/aspyr-media 96allow ${HOME}/.local/share/aspyr-media
97whitelist ${HOME}/.local/share/bohemiainteractive 97allow ${HOME}/.local/share/bohemiainteractive
98whitelist ${HOME}/.local/share/cdprojektred 98allow ${HOME}/.local/share/cdprojektred
99whitelist ${HOME}/.local/share/Dredmor 99allow ${HOME}/.local/share/Dredmor
100whitelist ${HOME}/.local/share/FasterThanLight 100allow ${HOME}/.local/share/FasterThanLight
101whitelist ${HOME}/.local/share/feral-interactive 101allow ${HOME}/.local/share/feral-interactive
102whitelist ${HOME}/.local/share/IntoTheBreach 102allow ${HOME}/.local/share/IntoTheBreach
103whitelist ${HOME}/.local/share/Paradox Interactive 103allow ${HOME}/.local/share/Paradox Interactive
104whitelist ${HOME}/.local/share/PillarsOfEternity 104allow ${HOME}/.local/share/PillarsOfEternity
105whitelist ${HOME}/.local/share/RogueLegacy 105allow ${HOME}/.local/share/RogueLegacy
106whitelist ${HOME}/.local/share/RogueLegacyStorageContainer 106allow ${HOME}/.local/share/RogueLegacyStorageContainer
107whitelist ${HOME}/.local/share/Steam 107allow ${HOME}/.local/share/Steam
108whitelist ${HOME}/.local/share/SteamWorldDig 108allow ${HOME}/.local/share/SteamWorldDig
109whitelist ${HOME}/.local/share/SteamWorld Dig 2 109allow ${HOME}/.local/share/SteamWorld Dig 2
110whitelist ${HOME}/.local/share/SuperHexagon 110allow ${HOME}/.local/share/SuperHexagon
111whitelist ${HOME}/.local/share/Terraria 111allow ${HOME}/.local/share/Terraria
112whitelist ${HOME}/.local/share/vpltd 112allow ${HOME}/.local/share/vpltd
113whitelist ${HOME}/.local/share/vulkan 113allow ${HOME}/.local/share/vulkan
114whitelist ${HOME}/.mbwarband 114allow ${HOME}/.mbwarband
115whitelist ${HOME}/.paradoxinteractive 115allow ${HOME}/.paradoxinteractive
116whitelist ${HOME}/.steam 116allow ${HOME}/.steam
117whitelist ${HOME}/.steampath 117allow ${HOME}/.steampath
118whitelist ${HOME}/.steampid 118allow ${HOME}/.steampid
119include whitelist-common.inc 119include whitelist-common.inc
120include whitelist-var-common.inc 120include whitelist-var-common.inc
121 121
diff --git a/etc/profile-m-z/stellarium.profile b/etc/profile-m-z/stellarium.profile
index a752ab53c..003d3a079 100644
--- a/etc/profile-m-z/stellarium.profile
+++ b/etc/profile-m-z/stellarium.profile
@@ -6,8 +6,8 @@ include stellarium.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/stellarium 9nodeny ${HOME}/.config/stellarium
10noblacklist ${HOME}/.stellarium 10nodeny ${HOME}/.stellarium
11 11
12include disable-common.inc 12include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
@@ -19,8 +19,8 @@ include disable-shell.inc
19 19
20mkdir ${HOME}/.config/stellarium 20mkdir ${HOME}/.config/stellarium
21mkdir ${HOME}/.stellarium 21mkdir ${HOME}/.stellarium
22whitelist ${HOME}/.config/stellarium 22allow ${HOME}/.config/stellarium
23whitelist ${HOME}/.stellarium 23allow ${HOME}/.stellarium
24include whitelist-common.inc 24include whitelist-common.inc
25include whitelist-var-common.inc 25include whitelist-var-common.inc
26 26
diff --git a/etc/profile-m-z/straw-viewer.profile b/etc/profile-m-z/straw-viewer.profile
index d73927f2a..dd643bc20 100644
--- a/etc/profile-m-z/straw-viewer.profile
+++ b/etc/profile-m-z/straw-viewer.profile
@@ -7,13 +7,13 @@ include straw-viewer.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10noblacklist ${HOME}/.cache/straw-viewer 10nodeny ${HOME}/.cache/straw-viewer
11noblacklist ${HOME}/.config/straw-viewer 11nodeny ${HOME}/.config/straw-viewer
12 12
13mkdir ${HOME}/.config/straw-viewer 13mkdir ${HOME}/.config/straw-viewer
14mkdir ${HOME}/.cache/straw-viewer 14mkdir ${HOME}/.cache/straw-viewer
15whitelist ${HOME}/.cache/straw-viewer 15allow ${HOME}/.cache/straw-viewer
16whitelist ${HOME}/.config/straw-viewer 16allow ${HOME}/.config/straw-viewer
17 17
18private-bin gtk-straw-viewer,straw-viewer 18private-bin gtk-straw-viewer,straw-viewer
19 19
diff --git a/etc/profile-m-z/strawberry.profile b/etc/profile-m-z/strawberry.profile
index b87906f55..aed0b7910 100644
--- a/etc/profile-m-z/strawberry.profile
+++ b/etc/profile-m-z/strawberry.profile
@@ -6,10 +6,10 @@ include strawberry.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.cache/strawberry 9nodeny ${HOME}/.cache/strawberry
10noblacklist ${HOME}/.config/strawberry 10nodeny ${HOME}/.config/strawberry
11noblacklist ${HOME}/.local/share/strawberry 11nodeny ${HOME}/.local/share/strawberry
12noblacklist ${MUSIC} 12nodeny ${MUSIC}
13 13
14include disable-common.inc 14include disable-common.inc
15include disable-devel.inc 15include disable-devel.inc
diff --git a/etc/profile-m-z/strings.profile b/etc/profile-m-z/strings.profile
index 1ebcded7f..5c820ef81 100644
--- a/etc/profile-m-z/strings.profile
+++ b/etc/profile-m-z/strings.profile
@@ -7,7 +7,7 @@ include strings.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10blacklist ${RUNUSER} 10deny ${RUNUSER}
11 11
12#include disable-common.inc 12#include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
diff --git a/etc/profile-m-z/subdownloader.profile b/etc/profile-m-z/subdownloader.profile
index bbe92fd38..0d07b5ea7 100644
--- a/etc/profile-m-z/subdownloader.profile
+++ b/etc/profile-m-z/subdownloader.profile
@@ -6,8 +6,8 @@ include subdownloader.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/SubDownloader 9nodeny ${HOME}/.config/SubDownloader
10noblacklist ${VIDEOS} 10nodeny ${VIDEOS}
11 11
12# Allow python (blacklisted by disable-interpreters.inc) 12# Allow python (blacklisted by disable-interpreters.inc)
13include allow-python2.inc 13include allow-python2.inc
diff --git a/etc/profile-m-z/supertux2.profile b/etc/profile-m-z/supertux2.profile
index cfd7a63ea..8cc547805 100644
--- a/etc/profile-m-z/supertux2.profile
+++ b/etc/profile-m-z/supertux2.profile
@@ -6,7 +6,7 @@ include supertux2.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.local/share/supertux2 9nodeny ${HOME}/.local/share/supertux2
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -18,9 +18,9 @@ include disable-shell.inc
18include disable-xdg.inc 18include disable-xdg.inc
19 19
20mkdir ${HOME}/.local/share/supertux2 20mkdir ${HOME}/.local/share/supertux2
21whitelist ${HOME}/.local/share/supertux2 21allow ${HOME}/.local/share/supertux2
22whitelist /usr/share/supertux2 22allow /usr/share/supertux2
23whitelist /usr/share/games/supertux2 # Debian version 23allow /usr/share/games/supertux2 # Debian version
24include whitelist-common.inc 24include whitelist-common.inc
25include whitelist-runuser-common.inc 25include whitelist-runuser-common.inc
26include whitelist-usr-share-common.inc 26include whitelist-usr-share-common.inc
diff --git a/etc/profile-m-z/supertuxkart.profile b/etc/profile-m-z/supertuxkart.profile
index 4eb8f921c..44dc1524f 100644
--- a/etc/profile-m-z/supertuxkart.profile
+++ b/etc/profile-m-z/supertuxkart.profile
@@ -6,11 +6,11 @@ include supertuxkart.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/supertuxkart 9nodeny ${HOME}/.config/supertuxkart
10noblacklist ${HOME}/.cache/supertuxkart 10nodeny ${HOME}/.cache/supertuxkart
11noblacklist ${HOME}/.local/share/supertuxkart 11nodeny ${HOME}/.local/share/supertuxkart
12 12
13blacklist /usr/libexec 13deny /usr/libexec
14 14
15include disable-common.inc 15include disable-common.inc
16include disable-devel.inc 16include disable-devel.inc
@@ -24,11 +24,11 @@ include disable-xdg.inc
24mkdir ${HOME}/.config/supertuxkart 24mkdir ${HOME}/.config/supertuxkart
25mkdir ${HOME}/.cache/supertuxkart 25mkdir ${HOME}/.cache/supertuxkart
26mkdir ${HOME}/.local/share/supertuxkart 26mkdir ${HOME}/.local/share/supertuxkart
27whitelist ${HOME}/.config/supertuxkart 27allow ${HOME}/.config/supertuxkart
28whitelist ${HOME}/.cache/supertuxkart 28allow ${HOME}/.cache/supertuxkart
29whitelist ${HOME}/.local/share/supertuxkart 29allow ${HOME}/.local/share/supertuxkart
30whitelist /usr/share/supertuxkart 30allow /usr/share/supertuxkart
31whitelist /usr/share/games/supertuxkart # Debian version 31allow /usr/share/games/supertuxkart # Debian version
32include whitelist-common.inc 32include whitelist-common.inc
33include whitelist-runuser-common.inc 33include whitelist-runuser-common.inc
34include whitelist-usr-share-common.inc 34include whitelist-usr-share-common.inc
diff --git a/etc/profile-m-z/surf.profile b/etc/profile-m-z/surf.profile
index 8db7d2433..fd1e7f9e9 100644
--- a/etc/profile-m-z/surf.profile
+++ b/etc/profile-m-z/surf.profile
@@ -6,7 +6,7 @@ include surf.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.surf 9nodeny ${HOME}/.surf
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -15,8 +15,8 @@ include disable-passwdmgr.inc
15include disable-programs.inc 15include disable-programs.inc
16 16
17mkdir ${HOME}/.surf 17mkdir ${HOME}/.surf
18whitelist ${HOME}/.surf 18allow ${HOME}/.surf
19whitelist ${DOWNLOADS} 19allow ${DOWNLOADS}
20include whitelist-common.inc 20include whitelist-common.inc
21 21
22caps.drop all 22caps.drop all
diff --git a/etc/profile-m-z/swell-foop.profile b/etc/profile-m-z/swell-foop.profile
index 9efae815d..55cd0965a 100644
--- a/etc/profile-m-z/swell-foop.profile
+++ b/etc/profile-m-z/swell-foop.profile
@@ -6,12 +6,12 @@ include swell-foop.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.local/share/swell-foop 9nodeny ${HOME}/.local/share/swell-foop
10 10
11mkdir ${HOME}/.local/share/swell-foop 11mkdir ${HOME}/.local/share/swell-foop
12whitelist ${HOME}/.local/share/swell-foop 12allow ${HOME}/.local/share/swell-foop
13 13
14whitelist /usr/share/swell-foop 14allow /usr/share/swell-foop
15 15
16private-bin swell-foop 16private-bin swell-foop
17 17
diff --git a/etc/profile-m-z/sylpheed.profile b/etc/profile-m-z/sylpheed.profile
index 328812b04..447cdc99e 100644
--- a/etc/profile-m-z/sylpheed.profile
+++ b/etc/profile-m-z/sylpheed.profile
@@ -6,12 +6,12 @@ include sylpheed.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.sylpheed-2.0 9nodeny ${HOME}/.sylpheed-2.0
10 10
11mkdir ${HOME}/.sylpheed-2.0 11mkdir ${HOME}/.sylpheed-2.0
12whitelist ${HOME}/.sylpheed-2.0 12allow ${HOME}/.sylpheed-2.0
13 13
14whitelist /usr/share/sylpheed 14allow /usr/share/sylpheed
15 15
16# private-bin curl,gpg,gpg2,gpg-agent,gpgsm,pinentry,pinentry-gtk-2,sylpheed 16# private-bin curl,gpg,gpg2,gpg-agent,gpgsm,pinentry,pinentry-gtk-2,sylpheed
17 17
diff --git a/etc/profile-m-z/synfigstudio.profile b/etc/profile-m-z/synfigstudio.profile
index c60186c42..7cbbafd54 100644
--- a/etc/profile-m-z/synfigstudio.profile
+++ b/etc/profile-m-z/synfigstudio.profile
@@ -6,8 +6,8 @@ include synfigstudio.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/synfig 9nodeny ${HOME}/.config/synfig
10noblacklist ${HOME}/.synfig 10nodeny ${HOME}/.synfig
11 11
12include disable-common.inc 12include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
diff --git a/etc/profile-m-z/sysprof.profile b/etc/profile-m-z/sysprof.profile
index b52b25b96..f20f88791 100644
--- a/etc/profile-m-z/sysprof.profile
+++ b/etc/profile-m-z/sysprof.profile
@@ -6,7 +6,7 @@ include sysprof.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${DOCUMENTS} 9nodeny ${DOCUMENTS}
10include disable-common.inc 10include disable-common.inc
11include disable-devel.inc 11include disable-devel.inc
12include disable-exec.inc 12include disable-exec.inc
@@ -24,15 +24,15 @@ include disable-xdg.inc
24#nowhitelist /usr/share/yelp-tools 24#nowhitelist /usr/share/yelp-tools
25#nowhitelist /usr/share/yelp-xsl 25#nowhitelist /usr/share/yelp-xsl
26 26
27noblacklist ${HOME}/.config/yelp 27nodeny ${HOME}/.config/yelp
28mkdir ${HOME}/.config/yelp 28mkdir ${HOME}/.config/yelp
29whitelist ${HOME}/.config/yelp 29allow ${HOME}/.config/yelp
30whitelist /usr/share/help/C/sysprof 30allow /usr/share/help/C/sysprof
31whitelist /usr/share/yelp 31allow /usr/share/yelp
32whitelist /usr/share/yelp-tools 32allow /usr/share/yelp-tools
33whitelist /usr/share/yelp-xsl 33allow /usr/share/yelp-xsl
34 34
35whitelist ${DOCUMENTS} 35allow ${DOCUMENTS}
36include whitelist-common.inc 36include whitelist-common.inc
37include whitelist-runuser-common.inc 37include whitelist-runuser-common.inc
38include whitelist-usr-share-common.inc 38include whitelist-usr-share-common.inc
diff --git a/etc/profile-m-z/tar.profile b/etc/profile-m-z/tar.profile
index 0d3a900e9..74c8a0849 100644
--- a/etc/profile-m-z/tar.profile
+++ b/etc/profile-m-z/tar.profile
@@ -12,7 +12,7 @@ ignore include disable-shell.inc
12 12
13# Arch Linux (based distributions) need access to /var/lib/pacman. As we drop 13# Arch Linux (based distributions) need access to /var/lib/pacman. As we drop
14# all capabilities this is automatically read-only. 14# all capabilities this is automatically read-only.
15noblacklist /var/lib/pacman 15nodeny /var/lib/pacman
16 16
17private-etc alternatives,group,localtime,login.defs,passwd 17private-etc alternatives,group,localtime,login.defs,passwd
18#private-lib libfakeroot,liblzma.so.*,libreadline.so.* 18#private-lib libfakeroot,liblzma.so.*,libreadline.so.*
diff --git a/etc/profile-m-z/tb-starter-wrapper.profile b/etc/profile-m-z/tb-starter-wrapper.profile
index ffe9605b6..691c33191 100644
--- a/etc/profile-m-z/tb-starter-wrapper.profile
+++ b/etc/profile-m-z/tb-starter-wrapper.profile
@@ -8,10 +8,10 @@ include tb-starter-wrapper.local
8# added by included profile 8# added by included profile
9#include globals.local 9#include globals.local
10 10
11noblacklist ${HOME}/.tb 11nodeny ${HOME}/.tb
12 12
13mkdir ${HOME}/.tb 13mkdir ${HOME}/.tb
14whitelist ${HOME}/.tb 14allow ${HOME}/.tb
15 15
16private-bin tb-starter-wrapper 16private-bin tb-starter-wrapper
17 17
diff --git a/etc/profile-m-z/tcpdump.profile b/etc/profile-m-z/tcpdump.profile
index e2ba5893c..b4c4873b3 100644
--- a/etc/profile-m-z/tcpdump.profile
+++ b/etc/profile-m-z/tcpdump.profile
@@ -6,9 +6,9 @@ include tcpdump.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist /sbin 9nodeny /sbin
10noblacklist /usr/sbin 10nodeny /usr/sbin
11noblacklist ${PATH}/tcpdump 11nodeny ${PATH}/tcpdump
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
diff --git a/etc/profile-m-z/teams-for-linux.profile b/etc/profile-m-z/teams-for-linux.profile
index eee083332..24cbb42da 100644
--- a/etc/profile-m-z/teams-for-linux.profile
+++ b/etc/profile-m-z/teams-for-linux.profile
@@ -14,10 +14,10 @@ ignore include whitelist-usr-share-common.inc
14ignore dbus-user none 14ignore dbus-user none
15ignore dbus-system none 15ignore dbus-system none
16 16
17noblacklist ${HOME}/.config/teams-for-linux 17nodeny ${HOME}/.config/teams-for-linux
18 18
19mkdir ${HOME}/.config/teams-for-linux 19mkdir ${HOME}/.config/teams-for-linux
20whitelist ${HOME}/.config/teams-for-linux 20allow ${HOME}/.config/teams-for-linux
21 21
22private-bin bash,cut,echo,egrep,grep,head,sed,sh,teams-for-linux,tr,xdg-mime,xdg-open,zsh 22private-bin bash,cut,echo,egrep,grep,head,sed,sh,teams-for-linux,tr,xdg-mime,xdg-open,zsh
23private-etc ca-certificates,crypto-policies,fonts,ld.so.cache,localtime,machine-id,pki,resolv.conf,ssl 23private-etc ca-certificates,crypto-policies,fonts,ld.so.cache,localtime,machine-id,pki,resolv.conf,ssl
diff --git a/etc/profile-m-z/teams.profile b/etc/profile-m-z/teams.profile
index c8d98cbaa..8639edbc8 100644
--- a/etc/profile-m-z/teams.profile
+++ b/etc/profile-m-z/teams.profile
@@ -18,13 +18,13 @@ ignore apparmor
18ignore dbus-user none 18ignore dbus-user none
19ignore dbus-system none 19ignore dbus-system none
20 20
21noblacklist ${HOME}/.config/teams 21nodeny ${HOME}/.config/teams
22noblacklist ${HOME}/.config/Microsoft 22nodeny ${HOME}/.config/Microsoft
23 23
24mkdir ${HOME}/.config/teams 24mkdir ${HOME}/.config/teams
25mkdir ${HOME}/.config/Microsoft 25mkdir ${HOME}/.config/Microsoft
26whitelist ${HOME}/.config/teams 26allow ${HOME}/.config/teams
27whitelist ${HOME}/.config/Microsoft 27allow ${HOME}/.config/Microsoft
28 28
29# Redirect 29# Redirect
30include electron.profile 30include electron.profile
diff --git a/etc/profile-m-z/teamspeak3.profile b/etc/profile-m-z/teamspeak3.profile
index 02a2c8ae4..781a5f4eb 100644
--- a/etc/profile-m-z/teamspeak3.profile
+++ b/etc/profile-m-z/teamspeak3.profile
@@ -6,8 +6,8 @@ include teamspeak3.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.ts3client 9nodeny ${HOME}/.ts3client
10noblacklist ${PATH}/openssl 10nodeny ${PATH}/openssl
11 11
12include disable-common.inc 12include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
@@ -17,8 +17,8 @@ include disable-passwdmgr.inc
17include disable-programs.inc 17include disable-programs.inc
18 18
19mkdir ${HOME}/.ts3client 19mkdir ${HOME}/.ts3client
20whitelist ${DOWNLOADS} 20allow ${DOWNLOADS}
21whitelist ${HOME}/.ts3client 21allow ${HOME}/.ts3client
22include whitelist-common.inc 22include whitelist-common.inc
23 23
24caps.drop all 24caps.drop all
diff --git a/etc/profile-m-z/teeworlds.profile b/etc/profile-m-z/teeworlds.profile
index be01aee12..c9c444ffc 100644
--- a/etc/profile-m-z/teeworlds.profile
+++ b/etc/profile-m-z/teeworlds.profile
@@ -6,7 +6,7 @@ include teeworlds.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.teeworlds 9nodeny ${HOME}/.teeworlds
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -18,7 +18,7 @@ include disable-shell.inc
18include disable-xdg.inc 18include disable-xdg.inc
19 19
20mkdir ${HOME}/.teeworlds 20mkdir ${HOME}/.teeworlds
21whitelist ${HOME}/.teeworlds 21allow ${HOME}/.teeworlds
22include whitelist-common.inc 22include whitelist-common.inc
23include whitelist-var-common.inc 23include whitelist-var-common.inc
24 24
diff --git a/etc/profile-m-z/telegram.profile b/etc/profile-m-z/telegram.profile
index e7580938d..92689a461 100644
--- a/etc/profile-m-z/telegram.profile
+++ b/etc/profile-m-z/telegram.profile
@@ -5,8 +5,8 @@ include telegram.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${HOME}/.TelegramDesktop 8nodeny ${HOME}/.TelegramDesktop
9noblacklist ${HOME}/.local/share/TelegramDesktop 9nodeny ${HOME}/.local/share/TelegramDesktop
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -19,9 +19,9 @@ include disable-xdg.inc
19 19
20mkdir ${HOME}/.TelegramDesktop 20mkdir ${HOME}/.TelegramDesktop
21mkdir ${HOME}/.local/share/TelegramDesktop 21mkdir ${HOME}/.local/share/TelegramDesktop
22whitelist ${HOME}/.TelegramDesktop 22allow ${HOME}/.TelegramDesktop
23whitelist ${HOME}/.local/share/TelegramDesktop 23allow ${HOME}/.local/share/TelegramDesktop
24whitelist ${DOWNLOADS} 24allow ${DOWNLOADS}
25include whitelist-common.inc 25include whitelist-common.inc
26include whitelist-runuser-common.inc 26include whitelist-runuser-common.inc
27include whitelist-usr-share-common.inc 27include whitelist-usr-share-common.inc
diff --git a/etc/profile-m-z/terasology.profile b/etc/profile-m-z/terasology.profile
index ce2ca1d17..b2f98fbac 100644
--- a/etc/profile-m-z/terasology.profile
+++ b/etc/profile-m-z/terasology.profile
@@ -7,7 +7,7 @@ include globals.local
7 7
8ignore noexec /tmp 8ignore noexec /tmp
9 9
10noblacklist ${HOME}/.local/share/terasology 10nodeny ${HOME}/.local/share/terasology
11 11
12# Allow java (blacklisted by disable-devel.inc) 12# Allow java (blacklisted by disable-devel.inc)
13include allow-java.inc 13include allow-java.inc
@@ -21,8 +21,8 @@ include disable-programs.inc
21 21
22mkdir ${HOME}/.java 22mkdir ${HOME}/.java
23mkdir ${HOME}/.local/share/terasology 23mkdir ${HOME}/.local/share/terasology
24whitelist ${HOME}/.java 24allow ${HOME}/.java
25whitelist ${HOME}/.local/share/terasology 25allow ${HOME}/.local/share/terasology
26include whitelist-common.inc 26include whitelist-common.inc
27 27
28caps.drop all 28caps.drop all
diff --git a/etc/profile-m-z/thunderbird.profile b/etc/profile-m-z/thunderbird.profile
index b478fbe1e..a539cadf8 100644
--- a/etc/profile-m-z/thunderbird.profile
+++ b/etc/profile-m-z/thunderbird.profile
@@ -22,14 +22,14 @@ writable-run-user
22#writable-var 22#writable-var
23 23
24# These lines are needed to allow Firefox to load your profile when clicking a link in an email 24# These lines are needed to allow Firefox to load your profile when clicking a link in an email
25noblacklist ${HOME}/.mozilla 25nodeny ${HOME}/.mozilla
26whitelist ${HOME}/.mozilla/firefox/profiles.ini 26allow ${HOME}/.mozilla/firefox/profiles.ini
27read-only ${HOME}/.mozilla/firefox/profiles.ini 27read-only ${HOME}/.mozilla/firefox/profiles.ini
28 28
29noblacklist ${HOME}/.cache/thunderbird 29nodeny ${HOME}/.cache/thunderbird
30noblacklist ${HOME}/.gnupg 30nodeny ${HOME}/.gnupg
31# noblacklist ${HOME}/.icedove 31# noblacklist ${HOME}/.icedove
32noblacklist ${HOME}/.thunderbird 32nodeny ${HOME}/.thunderbird
33 33
34include disable-passwdmgr.inc 34include disable-passwdmgr.inc
35include disable-xdg.inc 35include disable-xdg.inc
@@ -42,15 +42,15 @@ mkdir ${HOME}/.cache/thunderbird
42mkdir ${HOME}/.gnupg 42mkdir ${HOME}/.gnupg
43# mkdir ${HOME}/.icedove 43# mkdir ${HOME}/.icedove
44mkdir ${HOME}/.thunderbird 44mkdir ${HOME}/.thunderbird
45whitelist ${HOME}/.cache/thunderbird 45allow ${HOME}/.cache/thunderbird
46whitelist ${HOME}/.gnupg 46allow ${HOME}/.gnupg
47# whitelist ${HOME}/.icedove 47# whitelist ${HOME}/.icedove
48whitelist ${HOME}/.thunderbird 48allow ${HOME}/.thunderbird
49 49
50whitelist /usr/share/gnupg 50allow /usr/share/gnupg
51whitelist /usr/share/mozilla 51allow /usr/share/mozilla
52whitelist /usr/share/thunderbird 52allow /usr/share/thunderbird
53whitelist /usr/share/webext 53allow /usr/share/webext
54include whitelist-usr-share-common.inc 54include whitelist-usr-share-common.inc
55 55
56# machine-id breaks audio in browsers; enable or put it in your thunderbird.local when sound is not required 56# machine-id breaks audio in browsers; enable or put it in your thunderbird.local when sound is not required
diff --git a/etc/profile-m-z/tilp.profile b/etc/profile-m-z/tilp.profile
index dd4a372c4..b0fa54f08 100644
--- a/etc/profile-m-z/tilp.profile
+++ b/etc/profile-m-z/tilp.profile
@@ -5,7 +5,7 @@ include tilp.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${HOME}/.tilp 8nodeny ${HOME}/.tilp
9 9
10include disable-common.inc 10include disable-common.inc
11include disable-devel.inc 11include disable-devel.inc
diff --git a/etc/profile-m-z/tin.profile b/etc/profile-m-z/tin.profile
index e0ed3090a..3ee696b8b 100644
--- a/etc/profile-m-z/tin.profile
+++ b/etc/profile-m-z/tin.profile
@@ -6,12 +6,12 @@ include tin.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.newsrc 9nodeny ${HOME}/.newsrc
10noblacklist ${HOME}/.tin 10nodeny ${HOME}/.tin
11 11
12blacklist /tmp/.X11-unix 12deny /tmp/.X11-unix
13blacklist ${RUNUSER} 13deny ${RUNUSER}
14blacklist /usr/libexec 14deny /usr/libexec
15 15
16include disable-common.inc 16include disable-common.inc
17include disable-devel.inc 17include disable-devel.inc
diff --git a/etc/profile-m-z/tmux.profile b/etc/profile-m-z/tmux.profile
index 0139d7515..d2e90e356 100644
--- a/etc/profile-m-z/tmux.profile
+++ b/etc/profile-m-z/tmux.profile
@@ -7,10 +7,10 @@ include tmux.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10blacklist /tmp/.X11-unix 10deny /tmp/.X11-unix
11blacklist ${RUNUSER} 11deny ${RUNUSER}
12 12
13noblacklist /tmp/tmux-* 13nodeny /tmp/tmux-*
14 14
15# include disable-common.inc 15# include disable-common.inc
16# include disable-devel.inc 16# include disable-devel.inc
diff --git a/etc/profile-m-z/tor-browser-ar.profile b/etc/profile-m-z/tor-browser-ar.profile
index 59f1bc3b1..49158b93e 100644
--- a/etc/profile-m-z/tor-browser-ar.profile
+++ b/etc/profile-m-z/tor-browser-ar.profile
@@ -6,10 +6,10 @@ include tor-browser-ar.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.tor-browser-ar 9nodeny ${HOME}/.tor-browser-ar
10 10
11mkdir ${HOME}/.tor-browser-ar 11mkdir ${HOME}/.tor-browser-ar
12whitelist ${HOME}/.tor-browser-ar 12allow ${HOME}/.tor-browser-ar
13 13
14# Redirect 14# Redirect
15include torbrowser-launcher.profile 15include torbrowser-launcher.profile
diff --git a/etc/profile-m-z/tor-browser-ca.profile b/etc/profile-m-z/tor-browser-ca.profile
index 68577e352..612f8bd7c 100644
--- a/etc/profile-m-z/tor-browser-ca.profile
+++ b/etc/profile-m-z/tor-browser-ca.profile
@@ -6,10 +6,10 @@ include tor-browser-ca.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.tor-browser-ca 9nodeny ${HOME}/.tor-browser-ca
10 10
11mkdir ${HOME}/.tor-browser-ca 11mkdir ${HOME}/.tor-browser-ca
12whitelist ${HOME}/.tor-browser-ca 12allow ${HOME}/.tor-browser-ca
13 13
14# Redirect 14# Redirect
15include torbrowser-launcher.profile 15include torbrowser-launcher.profile
diff --git a/etc/profile-m-z/tor-browser-cs.profile b/etc/profile-m-z/tor-browser-cs.profile
index 33e51fcd0..a400fde05 100644
--- a/etc/profile-m-z/tor-browser-cs.profile
+++ b/etc/profile-m-z/tor-browser-cs.profile
@@ -6,10 +6,10 @@ include tor-browser-cs.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.tor-browser-cs 9nodeny ${HOME}/.tor-browser-cs
10 10
11mkdir ${HOME}/.tor-browser-cs 11mkdir ${HOME}/.tor-browser-cs
12whitelist ${HOME}/.tor-browser-cs 12allow ${HOME}/.tor-browser-cs
13 13
14# Redirect 14# Redirect
15include torbrowser-launcher.profile 15include torbrowser-launcher.profile
diff --git a/etc/profile-m-z/tor-browser-da.profile b/etc/profile-m-z/tor-browser-da.profile
index 440bb7fc3..9010025e3 100644
--- a/etc/profile-m-z/tor-browser-da.profile
+++ b/etc/profile-m-z/tor-browser-da.profile
@@ -6,10 +6,10 @@ include tor-browser-da.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.tor-browser-da 9nodeny ${HOME}/.tor-browser-da
10 10
11mkdir ${HOME}/.tor-browser-da 11mkdir ${HOME}/.tor-browser-da
12whitelist ${HOME}/.tor-browser-da 12allow ${HOME}/.tor-browser-da
13 13
14# Redirect 14# Redirect
15include torbrowser-launcher.profile 15include torbrowser-launcher.profile
diff --git a/etc/profile-m-z/tor-browser-de.profile b/etc/profile-m-z/tor-browser-de.profile
index b2b98cf82..cd556c32b 100644
--- a/etc/profile-m-z/tor-browser-de.profile
+++ b/etc/profile-m-z/tor-browser-de.profile
@@ -6,10 +6,10 @@ include tor-browser-de.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.tor-browser-de 9nodeny ${HOME}/.tor-browser-de
10 10
11mkdir ${HOME}/.tor-browser-de 11mkdir ${HOME}/.tor-browser-de
12whitelist ${HOME}/.tor-browser-de 12allow ${HOME}/.tor-browser-de
13 13
14# Redirect 14# Redirect
15include torbrowser-launcher.profile 15include torbrowser-launcher.profile
diff --git a/etc/profile-m-z/tor-browser-el.profile b/etc/profile-m-z/tor-browser-el.profile
index 626757dd5..ee2b0fea7 100644
--- a/etc/profile-m-z/tor-browser-el.profile
+++ b/etc/profile-m-z/tor-browser-el.profile
@@ -6,10 +6,10 @@ include tor-browser-el.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.tor-browser-el 9nodeny ${HOME}/.tor-browser-el
10 10
11mkdir ${HOME}/.tor-browser-el 11mkdir ${HOME}/.tor-browser-el
12whitelist ${HOME}/.tor-browser-el 12allow ${HOME}/.tor-browser-el
13 13
14# Redirect 14# Redirect
15include torbrowser-launcher.profile 15include torbrowser-launcher.profile
diff --git a/etc/profile-m-z/tor-browser-en-us.profile b/etc/profile-m-z/tor-browser-en-us.profile
index 15e690748..2be71a5aa 100644
--- a/etc/profile-m-z/tor-browser-en-us.profile
+++ b/etc/profile-m-z/tor-browser-en-us.profile
@@ -6,10 +6,10 @@ include tor-browser-en-us.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.tor-browser-en-us 9nodeny ${HOME}/.tor-browser-en-us
10 10
11mkdir ${HOME}/.tor-browser-en-us 11mkdir ${HOME}/.tor-browser-en-us
12whitelist ${HOME}/.tor-browser-en-us 12allow ${HOME}/.tor-browser-en-us
13 13
14# Redirect 14# Redirect
15include torbrowser-launcher.profile 15include torbrowser-launcher.profile
diff --git a/etc/profile-m-z/tor-browser-en.profile b/etc/profile-m-z/tor-browser-en.profile
index ef8c1eb8b..633c2f4f9 100644
--- a/etc/profile-m-z/tor-browser-en.profile
+++ b/etc/profile-m-z/tor-browser-en.profile
@@ -6,10 +6,10 @@ include tor-browser-en.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.tor-browser-en 9nodeny ${HOME}/.tor-browser-en
10 10
11mkdir ${HOME}/.tor-browser-en 11mkdir ${HOME}/.tor-browser-en
12whitelist ${HOME}/.tor-browser-en 12allow ${HOME}/.tor-browser-en
13 13
14# Redirect 14# Redirect
15include torbrowser-launcher.profile 15include torbrowser-launcher.profile
diff --git a/etc/profile-m-z/tor-browser-es-es.profile b/etc/profile-m-z/tor-browser-es-es.profile
index ad734662e..f7c2302a7 100644
--- a/etc/profile-m-z/tor-browser-es-es.profile
+++ b/etc/profile-m-z/tor-browser-es-es.profile
@@ -6,10 +6,10 @@ include tor-browser-es-es.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.tor-browser-es-es 9nodeny ${HOME}/.tor-browser-es-es
10 10
11mkdir ${HOME}/.tor-browser-es-es 11mkdir ${HOME}/.tor-browser-es-es
12whitelist ${HOME}/.tor-browser-es-es 12allow ${HOME}/.tor-browser-es-es
13 13
14# Redirect 14# Redirect
15include torbrowser-launcher.profile 15include torbrowser-launcher.profile
diff --git a/etc/profile-m-z/tor-browser-es.profile b/etc/profile-m-z/tor-browser-es.profile
index 97d8d8577..d88dcdec1 100644
--- a/etc/profile-m-z/tor-browser-es.profile
+++ b/etc/profile-m-z/tor-browser-es.profile
@@ -6,10 +6,10 @@ include tor-browser-es.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.tor-browser-es 9nodeny ${HOME}/.tor-browser-es
10 10
11mkdir ${HOME}/.tor-browser-es 11mkdir ${HOME}/.tor-browser-es
12whitelist ${HOME}/.tor-browser-es 12allow ${HOME}/.tor-browser-es
13 13
14# Redirect 14# Redirect
15include torbrowser-launcher.profile 15include torbrowser-launcher.profile
diff --git a/etc/profile-m-z/tor-browser-fa.profile b/etc/profile-m-z/tor-browser-fa.profile
index 095be69e4..3f7074fdb 100644
--- a/etc/profile-m-z/tor-browser-fa.profile
+++ b/etc/profile-m-z/tor-browser-fa.profile
@@ -6,10 +6,10 @@ include tor-browser-fa.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.tor-browser-fa 9nodeny ${HOME}/.tor-browser-fa
10 10
11mkdir ${HOME}/.tor-browser-fa 11mkdir ${HOME}/.tor-browser-fa
12whitelist ${HOME}/.tor-browser-fa 12allow ${HOME}/.tor-browser-fa
13 13
14# Redirect 14# Redirect
15include torbrowser-launcher.profile 15include torbrowser-launcher.profile
diff --git a/etc/profile-m-z/tor-browser-fr.profile b/etc/profile-m-z/tor-browser-fr.profile
index 37f61fc3a..ef14f44a2 100644
--- a/etc/profile-m-z/tor-browser-fr.profile
+++ b/etc/profile-m-z/tor-browser-fr.profile
@@ -6,10 +6,10 @@ include tor-browser-fr.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.tor-browser-fr 9nodeny ${HOME}/.tor-browser-fr
10 10
11mkdir ${HOME}/.tor-browser-fr 11mkdir ${HOME}/.tor-browser-fr
12whitelist ${HOME}/.tor-browser-fr 12allow ${HOME}/.tor-browser-fr
13 13
14# Redirect 14# Redirect
15include torbrowser-launcher.profile 15include torbrowser-launcher.profile
diff --git a/etc/profile-m-z/tor-browser-ga-ie.profile b/etc/profile-m-z/tor-browser-ga-ie.profile
index ab7141fc4..06baaf34f 100644
--- a/etc/profile-m-z/tor-browser-ga-ie.profile
+++ b/etc/profile-m-z/tor-browser-ga-ie.profile
@@ -6,10 +6,10 @@ include tor-browser-ga-ie.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.tor-browser-ga-ie 9nodeny ${HOME}/.tor-browser-ga-ie
10 10
11mkdir ${HOME}/.tor-browser-ga-ie 11mkdir ${HOME}/.tor-browser-ga-ie
12whitelist ${HOME}/.tor-browser-ga-ie 12allow ${HOME}/.tor-browser-ga-ie
13 13
14# Redirect 14# Redirect
15include torbrowser-launcher.profile 15include torbrowser-launcher.profile
diff --git a/etc/profile-m-z/tor-browser-he.profile b/etc/profile-m-z/tor-browser-he.profile
index ae56f3b7f..57588ffc7 100644
--- a/etc/profile-m-z/tor-browser-he.profile
+++ b/etc/profile-m-z/tor-browser-he.profile
@@ -6,10 +6,10 @@ include tor-browser-he.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.tor-browser-he 9nodeny ${HOME}/.tor-browser-he
10 10
11mkdir ${HOME}/.tor-browser-he 11mkdir ${HOME}/.tor-browser-he
12whitelist ${HOME}/.tor-browser-he 12allow ${HOME}/.tor-browser-he
13 13
14# Redirect 14# Redirect
15include torbrowser-launcher.profile 15include torbrowser-launcher.profile
diff --git a/etc/profile-m-z/tor-browser-hu.profile b/etc/profile-m-z/tor-browser-hu.profile
index 65cd18ac8..a10b66a24 100644
--- a/etc/profile-m-z/tor-browser-hu.profile
+++ b/etc/profile-m-z/tor-browser-hu.profile
@@ -6,10 +6,10 @@ include tor-browser-hu.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.tor-browser-hu 9nodeny ${HOME}/.tor-browser-hu
10 10
11mkdir ${HOME}/.tor-browser-hu 11mkdir ${HOME}/.tor-browser-hu
12whitelist ${HOME}/.tor-browser-hu 12allow ${HOME}/.tor-browser-hu
13 13
14# Redirect 14# Redirect
15include torbrowser-launcher.profile 15include torbrowser-launcher.profile
diff --git a/etc/profile-m-z/tor-browser-id.profile b/etc/profile-m-z/tor-browser-id.profile
index 57fe09f47..fcdb822cd 100644
--- a/etc/profile-m-z/tor-browser-id.profile
+++ b/etc/profile-m-z/tor-browser-id.profile
@@ -6,10 +6,10 @@ include tor-browser-id.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.tor-browser-id 9nodeny ${HOME}/.tor-browser-id
10 10
11mkdir ${HOME}/.tor-browser-id 11mkdir ${HOME}/.tor-browser-id
12whitelist ${HOME}/.tor-browser-id 12allow ${HOME}/.tor-browser-id
13 13
14# Redirect 14# Redirect
15include torbrowser-launcher.profile 15include torbrowser-launcher.profile
diff --git a/etc/profile-m-z/tor-browser-is.profile b/etc/profile-m-z/tor-browser-is.profile
index 54f1df42d..45b47c108 100644
--- a/etc/profile-m-z/tor-browser-is.profile
+++ b/etc/profile-m-z/tor-browser-is.profile
@@ -6,10 +6,10 @@ include tor-browser-is.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.tor-browser-is 9nodeny ${HOME}/.tor-browser-is
10 10
11mkdir ${HOME}/.tor-browser-is 11mkdir ${HOME}/.tor-browser-is
12whitelist ${HOME}/.tor-browser-is 12allow ${HOME}/.tor-browser-is
13 13
14# Redirect 14# Redirect
15include torbrowser-launcher.profile 15include torbrowser-launcher.profile
diff --git a/etc/profile-m-z/tor-browser-it.profile b/etc/profile-m-z/tor-browser-it.profile
index a7d46e875..b5a2f7c13 100644
--- a/etc/profile-m-z/tor-browser-it.profile
+++ b/etc/profile-m-z/tor-browser-it.profile
@@ -6,10 +6,10 @@ include tor-browser-it.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.tor-browser-it 9nodeny ${HOME}/.tor-browser-it
10 10
11mkdir ${HOME}/.tor-browser-it 11mkdir ${HOME}/.tor-browser-it
12whitelist ${HOME}/.tor-browser-it 12allow ${HOME}/.tor-browser-it
13 13
14# Redirect 14# Redirect
15include torbrowser-launcher.profile 15include torbrowser-launcher.profile
diff --git a/etc/profile-m-z/tor-browser-ja.profile b/etc/profile-m-z/tor-browser-ja.profile
index b89016141..e1f023bd4 100644
--- a/etc/profile-m-z/tor-browser-ja.profile
+++ b/etc/profile-m-z/tor-browser-ja.profile
@@ -6,10 +6,10 @@ include tor-browser-ja.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.tor-browser-ja 9nodeny ${HOME}/.tor-browser-ja
10 10
11mkdir ${HOME}/.tor-browser-ja 11mkdir ${HOME}/.tor-browser-ja
12whitelist ${HOME}/.tor-browser-ja 12allow ${HOME}/.tor-browser-ja
13 13
14# Redirect 14# Redirect
15include torbrowser-launcher.profile 15include torbrowser-launcher.profile
diff --git a/etc/profile-m-z/tor-browser-ka.profile b/etc/profile-m-z/tor-browser-ka.profile
index b57cf10de..17930b58e 100644
--- a/etc/profile-m-z/tor-browser-ka.profile
+++ b/etc/profile-m-z/tor-browser-ka.profile
@@ -6,10 +6,10 @@ include tor-browser-ka.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.tor-browser-ka 9nodeny ${HOME}/.tor-browser-ka
10 10
11mkdir ${HOME}/.tor-browser-ka 11mkdir ${HOME}/.tor-browser-ka
12whitelist ${HOME}/.tor-browser-ka 12allow ${HOME}/.tor-browser-ka
13 13
14# Redirect 14# Redirect
15include torbrowser-launcher.profile 15include torbrowser-launcher.profile
diff --git a/etc/profile-m-z/tor-browser-ko.profile b/etc/profile-m-z/tor-browser-ko.profile
index a9bedb6fd..b33d1edb4 100644
--- a/etc/profile-m-z/tor-browser-ko.profile
+++ b/etc/profile-m-z/tor-browser-ko.profile
@@ -6,10 +6,10 @@ include tor-browser-ko.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.tor-browser-ko 9nodeny ${HOME}/.tor-browser-ko
10 10
11mkdir ${HOME}/.tor-browser-ko 11mkdir ${HOME}/.tor-browser-ko
12whitelist ${HOME}/.tor-browser-ko 12allow ${HOME}/.tor-browser-ko
13 13
14# Redirect 14# Redirect
15include torbrowser-launcher.profile 15include torbrowser-launcher.profile
diff --git a/etc/profile-m-z/tor-browser-nb.profile b/etc/profile-m-z/tor-browser-nb.profile
index fbe9f92bd..b462eb9ac 100644
--- a/etc/profile-m-z/tor-browser-nb.profile
+++ b/etc/profile-m-z/tor-browser-nb.profile
@@ -6,10 +6,10 @@ include tor-browser-nb.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.tor-browser-nb 9nodeny ${HOME}/.tor-browser-nb
10 10
11mkdir ${HOME}/.tor-browser-nb 11mkdir ${HOME}/.tor-browser-nb
12whitelist ${HOME}/.tor-browser-nb 12allow ${HOME}/.tor-browser-nb
13 13
14# Redirect 14# Redirect
15include torbrowser-launcher.profile 15include torbrowser-launcher.profile
diff --git a/etc/profile-m-z/tor-browser-nl.profile b/etc/profile-m-z/tor-browser-nl.profile
index 678ac1713..0225eb6fd 100644
--- a/etc/profile-m-z/tor-browser-nl.profile
+++ b/etc/profile-m-z/tor-browser-nl.profile
@@ -6,10 +6,10 @@ include tor-browser-nl.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.tor-browser-nl 9nodeny ${HOME}/.tor-browser-nl
10 10
11mkdir ${HOME}/.tor-browser-nl 11mkdir ${HOME}/.tor-browser-nl
12whitelist ${HOME}/.tor-browser-nl 12allow ${HOME}/.tor-browser-nl
13 13
14# Redirect 14# Redirect
15include torbrowser-launcher.profile 15include torbrowser-launcher.profile
diff --git a/etc/profile-m-z/tor-browser-pl.profile b/etc/profile-m-z/tor-browser-pl.profile
index 25d473b1a..75604b458 100644
--- a/etc/profile-m-z/tor-browser-pl.profile
+++ b/etc/profile-m-z/tor-browser-pl.profile
@@ -6,10 +6,10 @@ include tor-browser-pl.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.tor-browser-pl 9nodeny ${HOME}/.tor-browser-pl
10 10
11mkdir ${HOME}/.tor-browser-pl 11mkdir ${HOME}/.tor-browser-pl
12whitelist ${HOME}/.tor-browser-pl 12allow ${HOME}/.tor-browser-pl
13 13
14# Redirect 14# Redirect
15include torbrowser-launcher.profile 15include torbrowser-launcher.profile
diff --git a/etc/profile-m-z/tor-browser-pt-br.profile b/etc/profile-m-z/tor-browser-pt-br.profile
index 55adbd5ea..4d50d8034 100644
--- a/etc/profile-m-z/tor-browser-pt-br.profile
+++ b/etc/profile-m-z/tor-browser-pt-br.profile
@@ -6,10 +6,10 @@ include tor-browser-pt-br.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.tor-browser-pt-br 9nodeny ${HOME}/.tor-browser-pt-br
10 10
11mkdir ${HOME}/.tor-browser-pt-br 11mkdir ${HOME}/.tor-browser-pt-br
12whitelist ${HOME}/.tor-browser-pt-br 12allow ${HOME}/.tor-browser-pt-br
13 13
14# Redirect 14# Redirect
15include torbrowser-launcher.profile 15include torbrowser-launcher.profile
diff --git a/etc/profile-m-z/tor-browser-ru.profile b/etc/profile-m-z/tor-browser-ru.profile
index aea13be9d..4bca3c46f 100644
--- a/etc/profile-m-z/tor-browser-ru.profile
+++ b/etc/profile-m-z/tor-browser-ru.profile
@@ -6,10 +6,10 @@ include tor-browser-ru.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.tor-browser-ru 9nodeny ${HOME}/.tor-browser-ru
10 10
11mkdir ${HOME}/.tor-browser-ru 11mkdir ${HOME}/.tor-browser-ru
12whitelist ${HOME}/.tor-browser-ru 12allow ${HOME}/.tor-browser-ru
13 13
14# Redirect 14# Redirect
15include torbrowser-launcher.profile 15include torbrowser-launcher.profile
diff --git a/etc/profile-m-z/tor-browser-sv-se.profile b/etc/profile-m-z/tor-browser-sv-se.profile
index b7882bd04..1b319dc43 100644
--- a/etc/profile-m-z/tor-browser-sv-se.profile
+++ b/etc/profile-m-z/tor-browser-sv-se.profile
@@ -6,10 +6,10 @@ include tor-browser-sv-se.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.tor-browser-sv-se 9nodeny ${HOME}/.tor-browser-sv-se
10 10
11mkdir ${HOME}/.tor-browser-sv-se 11mkdir ${HOME}/.tor-browser-sv-se
12whitelist ${HOME}/.tor-browser-sv-se 12allow ${HOME}/.tor-browser-sv-se
13 13
14# Redirect 14# Redirect
15include torbrowser-launcher.profile 15include torbrowser-launcher.profile
diff --git a/etc/profile-m-z/tor-browser-tr.profile b/etc/profile-m-z/tor-browser-tr.profile
index c52e8c4c4..0775a0c08 100644
--- a/etc/profile-m-z/tor-browser-tr.profile
+++ b/etc/profile-m-z/tor-browser-tr.profile
@@ -6,10 +6,10 @@ include tor-browser-tr.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.tor-browser-tr 9nodeny ${HOME}/.tor-browser-tr
10 10
11mkdir ${HOME}/.tor-browser-tr 11mkdir ${HOME}/.tor-browser-tr
12whitelist ${HOME}/.tor-browser-tr 12allow ${HOME}/.tor-browser-tr
13 13
14# Redirect 14# Redirect
15include torbrowser-launcher.profile 15include torbrowser-launcher.profile
diff --git a/etc/profile-m-z/tor-browser-vi.profile b/etc/profile-m-z/tor-browser-vi.profile
index d5bf76655..c4d5a7a76 100644
--- a/etc/profile-m-z/tor-browser-vi.profile
+++ b/etc/profile-m-z/tor-browser-vi.profile
@@ -6,10 +6,10 @@ include tor-browser-vi.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.tor-browser-vi 9nodeny ${HOME}/.tor-browser-vi
10 10
11mkdir ${HOME}/.tor-browser-vi 11mkdir ${HOME}/.tor-browser-vi
12whitelist ${HOME}/.tor-browser-vi 12allow ${HOME}/.tor-browser-vi
13 13
14# Redirect 14# Redirect
15include torbrowser-launcher.profile 15include torbrowser-launcher.profile
diff --git a/etc/profile-m-z/tor-browser-zh-cn.profile b/etc/profile-m-z/tor-browser-zh-cn.profile
index 6c8925a4a..4cd287e5d 100644
--- a/etc/profile-m-z/tor-browser-zh-cn.profile
+++ b/etc/profile-m-z/tor-browser-zh-cn.profile
@@ -6,10 +6,10 @@ include tor-browser-zh-cn.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.tor-browser-zh-cn 9nodeny ${HOME}/.tor-browser-zh-cn
10 10
11mkdir ${HOME}/.tor-browser-zh-cn 11mkdir ${HOME}/.tor-browser-zh-cn
12whitelist ${HOME}/.tor-browser-zh-cn 12allow ${HOME}/.tor-browser-zh-cn
13 13
14# Redirect 14# Redirect
15include torbrowser-launcher.profile 15include torbrowser-launcher.profile
diff --git a/etc/profile-m-z/tor-browser-zh-tw.profile b/etc/profile-m-z/tor-browser-zh-tw.profile
index 141a6701e..c75baf522 100644
--- a/etc/profile-m-z/tor-browser-zh-tw.profile
+++ b/etc/profile-m-z/tor-browser-zh-tw.profile
@@ -6,10 +6,10 @@ include tor-browser-zh-tw.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.tor-browser-zh-tw 9nodeny ${HOME}/.tor-browser-zh-tw
10 10
11mkdir ${HOME}/.tor-browser-zh-tw 11mkdir ${HOME}/.tor-browser-zh-tw
12whitelist ${HOME}/.tor-browser-zh-tw 12allow ${HOME}/.tor-browser-zh-tw
13 13
14# Redirect 14# Redirect
15include torbrowser-launcher.profile 15include torbrowser-launcher.profile
diff --git a/etc/profile-m-z/tor-browser.profile b/etc/profile-m-z/tor-browser.profile
index 76a0e1fa5..8a2dbda53 100644
--- a/etc/profile-m-z/tor-browser.profile
+++ b/etc/profile-m-z/tor-browser.profile
@@ -6,10 +6,10 @@ include tor-browser.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.tor-browser 9nodeny ${HOME}/.tor-browser
10 10
11mkdir ${HOME}/.tor-browser 11mkdir ${HOME}/.tor-browser
12whitelist ${HOME}/.tor-browser 12allow ${HOME}/.tor-browser
13 13
14# Redirect 14# Redirect
15include torbrowser-launcher.profile 15include torbrowser-launcher.profile
diff --git a/etc/profile-m-z/tor-browser_ar.profile b/etc/profile-m-z/tor-browser_ar.profile
index d811b7549..90b5a0960 100644
--- a/etc/profile-m-z/tor-browser_ar.profile
+++ b/etc/profile-m-z/tor-browser_ar.profile
@@ -6,10 +6,10 @@ include tor-browser_ar.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.tor-browser_ar 9nodeny ${HOME}/.tor-browser_ar
10 10
11mkdir ${HOME}/.tor-browser_ar 11mkdir ${HOME}/.tor-browser_ar
12whitelist ${HOME}/.tor-browser_ar 12allow ${HOME}/.tor-browser_ar
13 13
14# Redirect 14# Redirect
15include torbrowser-launcher.profile 15include torbrowser-launcher.profile
diff --git a/etc/profile-m-z/tor-browser_ca.profile b/etc/profile-m-z/tor-browser_ca.profile
index 8bf1f7cd4..a04207ccd 100644
--- a/etc/profile-m-z/tor-browser_ca.profile
+++ b/etc/profile-m-z/tor-browser_ca.profile
@@ -6,10 +6,10 @@ include tor-browser_ca.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.tor-browser_ca 9nodeny ${HOME}/.tor-browser_ca
10 10
11mkdir ${HOME}/.tor-browser_ca 11mkdir ${HOME}/.tor-browser_ca
12whitelist ${HOME}/.tor-browser_ca 12allow ${HOME}/.tor-browser_ca
13 13
14# Redirect 14# Redirect
15include torbrowser-launcher.profile 15include torbrowser-launcher.profile
diff --git a/etc/profile-m-z/tor-browser_cs.profile b/etc/profile-m-z/tor-browser_cs.profile
index b41107bf1..b99ad14a8 100644
--- a/etc/profile-m-z/tor-browser_cs.profile
+++ b/etc/profile-m-z/tor-browser_cs.profile
@@ -6,10 +6,10 @@ include tor-browser_cs.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.tor-browser_cs 9nodeny ${HOME}/.tor-browser_cs
10 10
11mkdir ${HOME}/.tor-browser_cs 11mkdir ${HOME}/.tor-browser_cs
12whitelist ${HOME}/.tor-browser_cs 12allow ${HOME}/.tor-browser_cs
13 13
14# Redirect 14# Redirect
15include torbrowser-launcher.profile 15include torbrowser-launcher.profile
diff --git a/etc/profile-m-z/tor-browser_da.profile b/etc/profile-m-z/tor-browser_da.profile
index cbec4ee2e..545e53b7e 100644
--- a/etc/profile-m-z/tor-browser_da.profile
+++ b/etc/profile-m-z/tor-browser_da.profile
@@ -6,10 +6,10 @@ include tor-browser_da.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.tor-browser_da 9nodeny ${HOME}/.tor-browser_da
10 10
11mkdir ${HOME}/.tor-browser_da 11mkdir ${HOME}/.tor-browser_da
12whitelist ${HOME}/.tor-browser_da 12allow ${HOME}/.tor-browser_da
13 13
14# Redirect 14# Redirect
15include torbrowser-launcher.profile 15include torbrowser-launcher.profile
diff --git a/etc/profile-m-z/tor-browser_de.profile b/etc/profile-m-z/tor-browser_de.profile
index ea26765d3..545f82f72 100644
--- a/etc/profile-m-z/tor-browser_de.profile
+++ b/etc/profile-m-z/tor-browser_de.profile
@@ -6,10 +6,10 @@ include tor-browser_de.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.tor-browser_de 9nodeny ${HOME}/.tor-browser_de
10 10
11mkdir ${HOME}/.tor-browser_de 11mkdir ${HOME}/.tor-browser_de
12whitelist ${HOME}/.tor-browser_de 12allow ${HOME}/.tor-browser_de
13 13
14# Redirect 14# Redirect
15include torbrowser-launcher.profile 15include torbrowser-launcher.profile
diff --git a/etc/profile-m-z/tor-browser_el.profile b/etc/profile-m-z/tor-browser_el.profile
index ff57a8722..3120b1701 100644
--- a/etc/profile-m-z/tor-browser_el.profile
+++ b/etc/profile-m-z/tor-browser_el.profile
@@ -6,10 +6,10 @@ include tor-browser_el.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.tor-browser_el 9nodeny ${HOME}/.tor-browser_el
10 10
11mkdir ${HOME}/.tor-browser_el 11mkdir ${HOME}/.tor-browser_el
12whitelist ${HOME}/.tor-browser_el 12allow ${HOME}/.tor-browser_el
13 13
14# Redirect 14# Redirect
15include torbrowser-launcher.profile 15include torbrowser-launcher.profile
diff --git a/etc/profile-m-z/tor-browser_en-US.profile b/etc/profile-m-z/tor-browser_en-US.profile
index 18c92b638..6719ac057 100644
--- a/etc/profile-m-z/tor-browser_en-US.profile
+++ b/etc/profile-m-z/tor-browser_en-US.profile
@@ -6,10 +6,10 @@ include tor-browser_en-US.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.tor-browser_en-US 9nodeny ${HOME}/.tor-browser_en-US
10 10
11mkdir ${HOME}/.tor-browser_en-US 11mkdir ${HOME}/.tor-browser_en-US
12whitelist ${HOME}/.tor-browser_en-US 12allow ${HOME}/.tor-browser_en-US
13 13
14# Redirect 14# Redirect
15include torbrowser-launcher.profile 15include torbrowser-launcher.profile
diff --git a/etc/profile-m-z/tor-browser_en.profile b/etc/profile-m-z/tor-browser_en.profile
index ebba83cc4..4cbd37109 100644
--- a/etc/profile-m-z/tor-browser_en.profile
+++ b/etc/profile-m-z/tor-browser_en.profile
@@ -6,10 +6,10 @@ include tor-browser_en.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.tor-browser_en 9nodeny ${HOME}/.tor-browser_en
10 10
11mkdir ${HOME}/.tor-browser_en 11mkdir ${HOME}/.tor-browser_en
12whitelist ${HOME}/.tor-browser_en 12allow ${HOME}/.tor-browser_en
13 13
14# Redirect 14# Redirect
15include torbrowser-launcher.profile 15include torbrowser-launcher.profile
diff --git a/etc/profile-m-z/tor-browser_es-ES.profile b/etc/profile-m-z/tor-browser_es-ES.profile
index aecab38d5..6c8a5987c 100644
--- a/etc/profile-m-z/tor-browser_es-ES.profile
+++ b/etc/profile-m-z/tor-browser_es-ES.profile
@@ -6,10 +6,10 @@ include tor-browser_es-ES.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.tor-browser_es-ES 9nodeny ${HOME}/.tor-browser_es-ES
10 10
11mkdir ${HOME}/.tor-browser_es-ES 11mkdir ${HOME}/.tor-browser_es-ES
12whitelist ${HOME}/.tor-browser_es-ES 12allow ${HOME}/.tor-browser_es-ES
13 13
14# Redirect 14# Redirect
15include torbrowser-launcher.profile 15include torbrowser-launcher.profile
diff --git a/etc/profile-m-z/tor-browser_es.profile b/etc/profile-m-z/tor-browser_es.profile
index e19e9b5e6..7d358b7ca 100644
--- a/etc/profile-m-z/tor-browser_es.profile
+++ b/etc/profile-m-z/tor-browser_es.profile
@@ -6,10 +6,10 @@ include tor-browser_es.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.tor-browser_es 9nodeny ${HOME}/.tor-browser_es
10 10
11mkdir ${HOME}/.tor-browser_es 11mkdir ${HOME}/.tor-browser_es
12whitelist ${HOME}/.tor-browser_es 12allow ${HOME}/.tor-browser_es
13 13
14# Redirect 14# Redirect
15include torbrowser-launcher.profile 15include torbrowser-launcher.profile
diff --git a/etc/profile-m-z/tor-browser_fa.profile b/etc/profile-m-z/tor-browser_fa.profile
index 68414c277..fc4285c5d 100644
--- a/etc/profile-m-z/tor-browser_fa.profile
+++ b/etc/profile-m-z/tor-browser_fa.profile
@@ -6,10 +6,10 @@ include tor-browser_fa.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.tor-browser_fa 9nodeny ${HOME}/.tor-browser_fa
10 10
11mkdir ${HOME}/.tor-browser_fa 11mkdir ${HOME}/.tor-browser_fa
12whitelist ${HOME}/.tor-browser_fa 12allow ${HOME}/.tor-browser_fa
13 13
14# Redirect 14# Redirect
15include torbrowser-launcher.profile 15include torbrowser-launcher.profile
diff --git a/etc/profile-m-z/tor-browser_fr.profile b/etc/profile-m-z/tor-browser_fr.profile
index 0a8bb30b7..2d0c0ff1f 100644
--- a/etc/profile-m-z/tor-browser_fr.profile
+++ b/etc/profile-m-z/tor-browser_fr.profile
@@ -6,10 +6,10 @@ include tor-browser_fr.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.tor-browser_fr 9nodeny ${HOME}/.tor-browser_fr
10 10
11mkdir ${HOME}/.tor-browser_fr 11mkdir ${HOME}/.tor-browser_fr
12whitelist ${HOME}/.tor-browser_fr 12allow ${HOME}/.tor-browser_fr
13 13
14# Redirect 14# Redirect
15include torbrowser-launcher.profile 15include torbrowser-launcher.profile
diff --git a/etc/profile-m-z/tor-browser_ga-IE.profile b/etc/profile-m-z/tor-browser_ga-IE.profile
index 12354b900..2880e1e2a 100644
--- a/etc/profile-m-z/tor-browser_ga-IE.profile
+++ b/etc/profile-m-z/tor-browser_ga-IE.profile
@@ -6,10 +6,10 @@ include tor-browser_ga-IE.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.tor-browser_ga-IE 9nodeny ${HOME}/.tor-browser_ga-IE
10 10
11mkdir ${HOME}/.tor-browser_ga-IE 11mkdir ${HOME}/.tor-browser_ga-IE
12whitelist ${HOME}/.tor-browser_ga-IE 12allow ${HOME}/.tor-browser_ga-IE
13 13
14# Redirect 14# Redirect
15include torbrowser-launcher.profile 15include torbrowser-launcher.profile
diff --git a/etc/profile-m-z/tor-browser_he.profile b/etc/profile-m-z/tor-browser_he.profile
index 19cbb0809..ac6993019 100644
--- a/etc/profile-m-z/tor-browser_he.profile
+++ b/etc/profile-m-z/tor-browser_he.profile
@@ -6,10 +6,10 @@ include tor-browser_he.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.tor-browser_he 9nodeny ${HOME}/.tor-browser_he
10 10
11mkdir ${HOME}/.tor-browser_he 11mkdir ${HOME}/.tor-browser_he
12whitelist ${HOME}/.tor-browser_he 12allow ${HOME}/.tor-browser_he
13 13
14# Redirect 14# Redirect
15include torbrowser-launcher.profile 15include torbrowser-launcher.profile
diff --git a/etc/profile-m-z/tor-browser_hu.profile b/etc/profile-m-z/tor-browser_hu.profile
index 62b55e170..6877a6be4 100644
--- a/etc/profile-m-z/tor-browser_hu.profile
+++ b/etc/profile-m-z/tor-browser_hu.profile
@@ -6,10 +6,10 @@ include tor-browser_hu.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.tor-browser_hu 9nodeny ${HOME}/.tor-browser_hu
10 10
11mkdir ${HOME}/.tor-browser_hu 11mkdir ${HOME}/.tor-browser_hu
12whitelist ${HOME}/.tor-browser_hu 12allow ${HOME}/.tor-browser_hu
13 13
14# Redirect 14# Redirect
15include torbrowser-launcher.profile 15include torbrowser-launcher.profile
diff --git a/etc/profile-m-z/tor-browser_id.profile b/etc/profile-m-z/tor-browser_id.profile
index 2970a7747..5f5601f74 100644
--- a/etc/profile-m-z/tor-browser_id.profile
+++ b/etc/profile-m-z/tor-browser_id.profile
@@ -6,10 +6,10 @@ include tor-browser_id.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.tor-browser_id 9nodeny ${HOME}/.tor-browser_id
10 10
11mkdir ${HOME}/.tor-browser_id 11mkdir ${HOME}/.tor-browser_id
12whitelist ${HOME}/.tor-browser_id 12allow ${HOME}/.tor-browser_id
13 13
14# Redirect 14# Redirect
15include torbrowser-launcher.profile 15include torbrowser-launcher.profile
diff --git a/etc/profile-m-z/tor-browser_is.profile b/etc/profile-m-z/tor-browser_is.profile
index f922c7644..f0814d16e 100644
--- a/etc/profile-m-z/tor-browser_is.profile
+++ b/etc/profile-m-z/tor-browser_is.profile
@@ -6,10 +6,10 @@ include tor-browser_is.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.tor-browser_is 9nodeny ${HOME}/.tor-browser_is
10 10
11mkdir ${HOME}/.tor-browser_is 11mkdir ${HOME}/.tor-browser_is
12whitelist ${HOME}/.tor-browser_is 12allow ${HOME}/.tor-browser_is
13 13
14# Redirect 14# Redirect
15include torbrowser-launcher.profile 15include torbrowser-launcher.profile
diff --git a/etc/profile-m-z/tor-browser_it.profile b/etc/profile-m-z/tor-browser_it.profile
index 406901759..fa01f6bca 100644
--- a/etc/profile-m-z/tor-browser_it.profile
+++ b/etc/profile-m-z/tor-browser_it.profile
@@ -6,10 +6,10 @@ include tor-browser_it.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.tor-browser_it 9nodeny ${HOME}/.tor-browser_it
10 10
11mkdir ${HOME}/.tor-browser_it 11mkdir ${HOME}/.tor-browser_it
12whitelist ${HOME}/.tor-browser_it 12allow ${HOME}/.tor-browser_it
13 13
14# Redirect 14# Redirect
15include torbrowser-launcher.profile 15include torbrowser-launcher.profile
diff --git a/etc/profile-m-z/tor-browser_ja.profile b/etc/profile-m-z/tor-browser_ja.profile
index 8f9d8d751..dde107dd3 100644
--- a/etc/profile-m-z/tor-browser_ja.profile
+++ b/etc/profile-m-z/tor-browser_ja.profile
@@ -6,10 +6,10 @@ include tor-browser_ja.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.tor-browser_ja 9nodeny ${HOME}/.tor-browser_ja
10 10
11mkdir ${HOME}/.tor-browser_ja 11mkdir ${HOME}/.tor-browser_ja
12whitelist ${HOME}/.tor-browser_ja 12allow ${HOME}/.tor-browser_ja
13 13
14# Redirect 14# Redirect
15include torbrowser-launcher.profile 15include torbrowser-launcher.profile
diff --git a/etc/profile-m-z/tor-browser_ka.profile b/etc/profile-m-z/tor-browser_ka.profile
index 4de4135e1..7de4dff65 100644
--- a/etc/profile-m-z/tor-browser_ka.profile
+++ b/etc/profile-m-z/tor-browser_ka.profile
@@ -6,10 +6,10 @@ include tor-browser_ka.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.tor-browser_ka 9nodeny ${HOME}/.tor-browser_ka
10 10
11mkdir ${HOME}/.tor-browser_ka 11mkdir ${HOME}/.tor-browser_ka
12whitelist ${HOME}/.tor-browser_ka 12allow ${HOME}/.tor-browser_ka
13 13
14# Redirect 14# Redirect
15include torbrowser-launcher.profile 15include torbrowser-launcher.profile
diff --git a/etc/profile-m-z/tor-browser_ko.profile b/etc/profile-m-z/tor-browser_ko.profile
index 125c733ce..7e3ceb4d9 100644
--- a/etc/profile-m-z/tor-browser_ko.profile
+++ b/etc/profile-m-z/tor-browser_ko.profile
@@ -6,10 +6,10 @@ include tor-browser_ko.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.tor-browser_ko 9nodeny ${HOME}/.tor-browser_ko
10 10
11mkdir ${HOME}/.tor-browser_ko 11mkdir ${HOME}/.tor-browser_ko
12whitelist ${HOME}/.tor-browser_ko 12allow ${HOME}/.tor-browser_ko
13 13
14# Redirect 14# Redirect
15include torbrowser-launcher.profile 15include torbrowser-launcher.profile
diff --git a/etc/profile-m-z/tor-browser_nb.profile b/etc/profile-m-z/tor-browser_nb.profile
index dc6ac876b..c11001960 100644
--- a/etc/profile-m-z/tor-browser_nb.profile
+++ b/etc/profile-m-z/tor-browser_nb.profile
@@ -6,10 +6,10 @@ include tor-browser_nb.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.tor-browser_nb 9nodeny ${HOME}/.tor-browser_nb
10 10
11mkdir ${HOME}/.tor-browser_nb 11mkdir ${HOME}/.tor-browser_nb
12whitelist ${HOME}/.tor-browser_nb 12allow ${HOME}/.tor-browser_nb
13 13
14# Redirect 14# Redirect
15include torbrowser-launcher.profile 15include torbrowser-launcher.profile
diff --git a/etc/profile-m-z/tor-browser_nl.profile b/etc/profile-m-z/tor-browser_nl.profile
index 2a3a5b519..2d1044f9d 100644
--- a/etc/profile-m-z/tor-browser_nl.profile
+++ b/etc/profile-m-z/tor-browser_nl.profile
@@ -6,10 +6,10 @@ include tor-browser_nl.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.tor-browser_nl 9nodeny ${HOME}/.tor-browser_nl
10 10
11mkdir ${HOME}/.tor-browser_nl 11mkdir ${HOME}/.tor-browser_nl
12whitelist ${HOME}/.tor-browser_nl 12allow ${HOME}/.tor-browser_nl
13 13
14# Redirect 14# Redirect
15include torbrowser-launcher.profile 15include torbrowser-launcher.profile
diff --git a/etc/profile-m-z/tor-browser_pl.profile b/etc/profile-m-z/tor-browser_pl.profile
index b7dec32db..2818320a0 100644
--- a/etc/profile-m-z/tor-browser_pl.profile
+++ b/etc/profile-m-z/tor-browser_pl.profile
@@ -6,10 +6,10 @@ include tor-browser_pl.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.tor-browser_pl 9nodeny ${HOME}/.tor-browser_pl
10 10
11mkdir ${HOME}/.tor-browser_pl 11mkdir ${HOME}/.tor-browser_pl
12whitelist ${HOME}/.tor-browser_pl 12allow ${HOME}/.tor-browser_pl
13 13
14# Redirect 14# Redirect
15include torbrowser-launcher.profile 15include torbrowser-launcher.profile
diff --git a/etc/profile-m-z/tor-browser_pt-BR.profile b/etc/profile-m-z/tor-browser_pt-BR.profile
index 7a7d4726c..8c33e2545 100644
--- a/etc/profile-m-z/tor-browser_pt-BR.profile
+++ b/etc/profile-m-z/tor-browser_pt-BR.profile
@@ -6,10 +6,10 @@ include tor-browser_pt-BR.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.tor-browser_pt-BR 9nodeny ${HOME}/.tor-browser_pt-BR
10 10
11mkdir ${HOME}/.tor-browser_pt-BR 11mkdir ${HOME}/.tor-browser_pt-BR
12whitelist ${HOME}/.tor-browser_pt-BR 12allow ${HOME}/.tor-browser_pt-BR
13 13
14# Redirect 14# Redirect
15include torbrowser-launcher.profile 15include torbrowser-launcher.profile
diff --git a/etc/profile-m-z/tor-browser_ru.profile b/etc/profile-m-z/tor-browser_ru.profile
index 7d2e6bc97..2553bb031 100644
--- a/etc/profile-m-z/tor-browser_ru.profile
+++ b/etc/profile-m-z/tor-browser_ru.profile
@@ -6,10 +6,10 @@ include tor-browser_ru.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.tor-browser_ru 9nodeny ${HOME}/.tor-browser_ru
10 10
11mkdir ${HOME}/.tor-browser_ru 11mkdir ${HOME}/.tor-browser_ru
12whitelist ${HOME}/.tor-browser_ru 12allow ${HOME}/.tor-browser_ru
13 13
14# Redirect 14# Redirect
15include torbrowser-launcher.profile 15include torbrowser-launcher.profile
diff --git a/etc/profile-m-z/tor-browser_sv-SE.profile b/etc/profile-m-z/tor-browser_sv-SE.profile
index 585925e81..3152cb658 100644
--- a/etc/profile-m-z/tor-browser_sv-SE.profile
+++ b/etc/profile-m-z/tor-browser_sv-SE.profile
@@ -6,10 +6,10 @@ include tor-browser_sv-SE.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.tor-browser_sv-SE 9nodeny ${HOME}/.tor-browser_sv-SE
10 10
11mkdir ${HOME}/.tor-browser_sv-SE 11mkdir ${HOME}/.tor-browser_sv-SE
12whitelist ${HOME}/.tor-browser_sv-SE 12allow ${HOME}/.tor-browser_sv-SE
13 13
14# Redirect 14# Redirect
15include torbrowser-launcher.profile 15include torbrowser-launcher.profile
diff --git a/etc/profile-m-z/tor-browser_tr.profile b/etc/profile-m-z/tor-browser_tr.profile
index 4b0cc3821..9808d4725 100644
--- a/etc/profile-m-z/tor-browser_tr.profile
+++ b/etc/profile-m-z/tor-browser_tr.profile
@@ -6,10 +6,10 @@ include tor-browser_tr.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.tor-browser_tr 9nodeny ${HOME}/.tor-browser_tr
10 10
11mkdir ${HOME}/.tor-browser_tr 11mkdir ${HOME}/.tor-browser_tr
12whitelist ${HOME}/.tor-browser_tr 12allow ${HOME}/.tor-browser_tr
13 13
14# Redirect 14# Redirect
15include torbrowser-launcher.profile 15include torbrowser-launcher.profile
diff --git a/etc/profile-m-z/tor-browser_vi.profile b/etc/profile-m-z/tor-browser_vi.profile
index 4dcfbf56d..364fca40b 100644
--- a/etc/profile-m-z/tor-browser_vi.profile
+++ b/etc/profile-m-z/tor-browser_vi.profile
@@ -6,10 +6,10 @@ include tor-browser_vi.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.tor-browser_vi 9nodeny ${HOME}/.tor-browser_vi
10 10
11mkdir ${HOME}/.tor-browser_vi 11mkdir ${HOME}/.tor-browser_vi
12whitelist ${HOME}/.tor-browser_vi 12allow ${HOME}/.tor-browser_vi
13 13
14# Redirect 14# Redirect
15include torbrowser-launcher.profile 15include torbrowser-launcher.profile
diff --git a/etc/profile-m-z/tor-browser_zh-CN.profile b/etc/profile-m-z/tor-browser_zh-CN.profile
index 1e03b8d6b..193e8a399 100644
--- a/etc/profile-m-z/tor-browser_zh-CN.profile
+++ b/etc/profile-m-z/tor-browser_zh-CN.profile
@@ -6,10 +6,10 @@ include tor-browser_zh-CN.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.tor-browser_zh-CN 9nodeny ${HOME}/.tor-browser_zh-CN
10 10
11mkdir ${HOME}/.tor-browser_zh-CN 11mkdir ${HOME}/.tor-browser_zh-CN
12whitelist ${HOME}/.tor-browser_zh-CN 12allow ${HOME}/.tor-browser_zh-CN
13 13
14# Redirect 14# Redirect
15include torbrowser-launcher.profile 15include torbrowser-launcher.profile
diff --git a/etc/profile-m-z/tor-browser_zh-TW.profile b/etc/profile-m-z/tor-browser_zh-TW.profile
index a2dcf5cf1..047be9b8e 100644
--- a/etc/profile-m-z/tor-browser_zh-TW.profile
+++ b/etc/profile-m-z/tor-browser_zh-TW.profile
@@ -6,10 +6,10 @@ include tor-browser_zh-TW.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.tor-browser_zh-TW 9nodeny ${HOME}/.tor-browser_zh-TW
10 10
11mkdir ${HOME}/.tor-browser_zh-TW 11mkdir ${HOME}/.tor-browser_zh-TW
12whitelist ${HOME}/.tor-browser_zh-TW 12allow ${HOME}/.tor-browser_zh-TW
13 13
14# Redirect 14# Redirect
15include torbrowser-launcher.profile 15include torbrowser-launcher.profile
diff --git a/etc/profile-m-z/torbrowser-launcher.profile b/etc/profile-m-z/torbrowser-launcher.profile
index 7659ed1e9..65a37db5f 100644
--- a/etc/profile-m-z/torbrowser-launcher.profile
+++ b/etc/profile-m-z/torbrowser-launcher.profile
@@ -8,15 +8,15 @@ include globals.local
8 8
9ignore noexec ${HOME} 9ignore noexec ${HOME}
10 10
11noblacklist ${HOME}/.config/torbrowser 11nodeny ${HOME}/.config/torbrowser
12noblacklist ${HOME}/.local/share/torbrowser 12nodeny ${HOME}/.local/share/torbrowser
13 13
14# Allow python (blacklisted by disable-interpreters.inc) 14# Allow python (blacklisted by disable-interpreters.inc)
15include allow-python2.inc 15include allow-python2.inc
16include allow-python3.inc 16include allow-python3.inc
17 17
18blacklist /opt 18deny /opt
19blacklist /srv 19deny /srv
20 20
21include disable-common.inc 21include disable-common.inc
22include disable-devel.inc 22include disable-devel.inc
@@ -28,10 +28,10 @@ include disable-xdg.inc
28 28
29mkdir ${HOME}/.config/torbrowser 29mkdir ${HOME}/.config/torbrowser
30mkdir ${HOME}/.local/share/torbrowser 30mkdir ${HOME}/.local/share/torbrowser
31whitelist ${DOWNLOADS} 31allow ${DOWNLOADS}
32whitelist ${HOME}/.config/torbrowser 32allow ${HOME}/.config/torbrowser
33whitelist ${HOME}/.local/share/torbrowser 33allow ${HOME}/.local/share/torbrowser
34whitelist /usr/share/torbrowser-launcher 34allow /usr/share/torbrowser-launcher
35include whitelist-common.inc 35include whitelist-common.inc
36include whitelist-var-common.inc 36include whitelist-var-common.inc
37include whitelist-runuser-common.inc 37include whitelist-runuser-common.inc
diff --git a/etc/profile-m-z/torcs.profile b/etc/profile-m-z/torcs.profile
index 0f98a8f64..c5d89c3e3 100644
--- a/etc/profile-m-z/torcs.profile
+++ b/etc/profile-m-z/torcs.profile
@@ -6,7 +6,7 @@ include torcs.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.torcs 9nodeny ${HOME}/.torcs
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -17,9 +17,9 @@ include disable-programs.inc
17include disable-xdg.inc 17include disable-xdg.inc
18 18
19mkdir ${HOME}/.torcs 19mkdir ${HOME}/.torcs
20whitelist ${HOME}/.torcs 20allow ${HOME}/.torcs
21whitelist /usr/share/games/torcs 21allow /usr/share/games/torcs
22whitelist /var/games/torcs 22allow /var/games/torcs
23include whitelist-common.inc 23include whitelist-common.inc
24include whitelist-usr-share-common.inc 24include whitelist-usr-share-common.inc
25include whitelist-var-common.inc 25include whitelist-var-common.inc
diff --git a/etc/profile-m-z/totem.profile b/etc/profile-m-z/totem.profile
index 70d9e0aee..77d3c55f8 100644
--- a/etc/profile-m-z/totem.profile
+++ b/etc/profile-m-z/totem.profile
@@ -13,8 +13,8 @@ include allow-lua.inc
13# Allow python (blacklisted by disable-interpreters.inc) 13# Allow python (blacklisted by disable-interpreters.inc)
14include allow-python3.inc 14include allow-python3.inc
15 15
16noblacklist ${HOME}/.config/totem 16nodeny ${HOME}/.config/totem
17noblacklist ${HOME}/.local/share/totem 17nodeny ${HOME}/.local/share/totem
18 18
19include disable-common.inc 19include disable-common.inc
20include disable-devel.inc 20include disable-devel.inc
@@ -27,9 +27,9 @@ include disable-shell.inc
27read-only ${DESKTOP} 27read-only ${DESKTOP}
28mkdir ${HOME}/.config/totem 28mkdir ${HOME}/.config/totem
29mkdir ${HOME}/.local/share/totem 29mkdir ${HOME}/.local/share/totem
30whitelist ${HOME}/.config/totem 30allow ${HOME}/.config/totem
31whitelist ${HOME}/.local/share/totem 31allow ${HOME}/.local/share/totem
32whitelist /usr/share/totem 32allow /usr/share/totem
33include whitelist-common.inc 33include whitelist-common.inc
34include whitelist-player-common.inc 34include whitelist-player-common.inc
35include whitelist-runuser-common.inc 35include whitelist-runuser-common.inc
diff --git a/etc/profile-m-z/tracker.profile b/etc/profile-m-z/tracker.profile
index 87c5de076..26f4abd0b 100644
--- a/etc/profile-m-z/tracker.profile
+++ b/etc/profile-m-z/tracker.profile
@@ -8,8 +8,8 @@ include globals.local
8 8
9# Tracker is started by systemd on most systems. Therefore it is not firejailed by default 9# Tracker is started by systemd on most systems. Therefore it is not firejailed by default
10 10
11blacklist /tmp/.X11-unix 11deny /tmp/.X11-unix
12blacklist ${RUNUSER}/wayland-* 12deny ${RUNUSER}/wayland-*
13 13
14include disable-common.inc 14include disable-common.inc
15include disable-devel.inc 15include disable-devel.inc
diff --git a/etc/profile-m-z/transgui.profile b/etc/profile-m-z/transgui.profile
index ea118a9f0..d5920e2a2 100644
--- a/etc/profile-m-z/transgui.profile
+++ b/etc/profile-m-z/transgui.profile
@@ -6,7 +6,7 @@ include transgui.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/transgui 9nodeny ${HOME}/.config/transgui
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -18,8 +18,8 @@ include disable-shell.inc
18include disable-xdg.inc 18include disable-xdg.inc
19 19
20mkdir ${HOME}/.config/transgui 20mkdir ${HOME}/.config/transgui
21whitelist ${HOME}/.config/transgui 21allow ${HOME}/.config/transgui
22whitelist ${DOWNLOADS} 22allow ${DOWNLOADS}
23include whitelist-common.inc 23include whitelist-common.inc
24include whitelist-usr-share-common.inc 24include whitelist-usr-share-common.inc
25include whitelist-var-common.inc 25include whitelist-var-common.inc
diff --git a/etc/profile-m-z/transmission-common.profile b/etc/profile-m-z/transmission-common.profile
index 82671b709..5c2cf9d9a 100644
--- a/etc/profile-m-z/transmission-common.profile
+++ b/etc/profile-m-z/transmission-common.profile
@@ -7,8 +7,8 @@ include transmission-common.local
7# added by caller profile 7# added by caller profile
8#include globals.local 8#include globals.local
9 9
10noblacklist ${HOME}/.cache/transmission 10nodeny ${HOME}/.cache/transmission
11noblacklist ${HOME}/.config/transmission 11nodeny ${HOME}/.config/transmission
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
@@ -19,9 +19,9 @@ include disable-programs.inc
19 19
20mkdir ${HOME}/.cache/transmission 20mkdir ${HOME}/.cache/transmission
21mkdir ${HOME}/.config/transmission 21mkdir ${HOME}/.config/transmission
22whitelist ${DOWNLOADS} 22allow ${DOWNLOADS}
23whitelist ${HOME}/.cache/transmission 23allow ${HOME}/.cache/transmission
24whitelist ${HOME}/.config/transmission 24allow ${HOME}/.config/transmission
25include whitelist-common.inc 25include whitelist-common.inc
26include whitelist-usr-share-common.inc 26include whitelist-usr-share-common.inc
27include whitelist-var-common.inc 27include whitelist-var-common.inc
diff --git a/etc/profile-m-z/transmission-daemon.profile b/etc/profile-m-z/transmission-daemon.profile
index 348d3cb80..9f0c464fc 100644
--- a/etc/profile-m-z/transmission-daemon.profile
+++ b/etc/profile-m-z/transmission-daemon.profile
@@ -10,8 +10,8 @@ include globals.local
10ignore caps.drop all 10ignore caps.drop all
11 11
12mkdir ${HOME}/.config/transmission-daemon 12mkdir ${HOME}/.config/transmission-daemon
13whitelist ${HOME}/.config/transmission-daemon 13allow ${HOME}/.config/transmission-daemon
14whitelist /var/lib/transmission 14allow /var/lib/transmission
15 15
16caps.keep ipc_lock,net_bind_service,setgid,setuid,sys_chroot 16caps.keep ipc_lock,net_bind_service,setgid,setuid,sys_chroot
17protocol packet 17protocol packet
diff --git a/etc/profile-m-z/transmission-remote-gtk.profile b/etc/profile-m-z/transmission-remote-gtk.profile
index a6400e2c0..7c8eddcbc 100644
--- a/etc/profile-m-z/transmission-remote-gtk.profile
+++ b/etc/profile-m-z/transmission-remote-gtk.profile
@@ -7,10 +7,10 @@ include transmission-remote-gtk.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10noblacklist ${HOME}/.config/transmission-remote-gtk 10nodeny ${HOME}/.config/transmission-remote-gtk
11 11
12mkdir ${HOME}/.config/transmission-remote-gtk 12mkdir ${HOME}/.config/transmission-remote-gtk
13whitelist ${HOME}/.config/transmission-remote-gtk 13allow ${HOME}/.config/transmission-remote-gtk
14 14
15private-etc fonts,hostname,hosts,resolv.conf 15private-etc fonts,hostname,hosts,resolv.conf
16# Problems with private-lib (see issue #2889) 16# Problems with private-lib (see issue #2889)
diff --git a/etc/profile-m-z/tremulous.profile b/etc/profile-m-z/tremulous.profile
index aba563fac..c2797ddaa 100644
--- a/etc/profile-m-z/tremulous.profile
+++ b/etc/profile-m-z/tremulous.profile
@@ -6,7 +6,7 @@ include tremulous.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.tremulous 9nodeny ${HOME}/.tremulous
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -18,8 +18,8 @@ include disable-shell.inc
18include disable-xdg.inc 18include disable-xdg.inc
19 19
20mkdir ${HOME}/.tremulous 20mkdir ${HOME}/.tremulous
21whitelist ${HOME}/.tremulous 21allow ${HOME}/.tremulous
22whitelist /usr/share/tremulous 22allow /usr/share/tremulous
23include whitelist-common.inc 23include whitelist-common.inc
24include whitelist-runuser-common.inc 24include whitelist-runuser-common.inc
25include whitelist-usr-share-common.inc 25include whitelist-usr-share-common.inc
diff --git a/etc/profile-m-z/trojita.profile b/etc/profile-m-z/trojita.profile
index 2d95081f6..95f39b35d 100644
--- a/etc/profile-m-z/trojita.profile
+++ b/etc/profile-m-z/trojita.profile
@@ -6,10 +6,10 @@ include trojita.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.abook 9nodeny ${HOME}/.abook
10noblacklist ${HOME}/.mozilla 10nodeny ${HOME}/.mozilla
11noblacklist ${HOME}/.cache/flaska.net/trojita 11nodeny ${HOME}/.cache/flaska.net/trojita
12noblacklist ${HOME}/.config/flaska.net 12nodeny ${HOME}/.config/flaska.net
13 13
14include disable-common.inc 14include disable-common.inc
15include disable-devel.inc 15include disable-devel.inc
@@ -23,10 +23,10 @@ include disable-xdg.inc
23mkdir ${HOME}/.abook 23mkdir ${HOME}/.abook
24mkdir ${HOME}/.cache/flaska.net/trojita 24mkdir ${HOME}/.cache/flaska.net/trojita
25mkdir ${HOME}/.config/flaska.net 25mkdir ${HOME}/.config/flaska.net
26whitelist ${HOME}/.abook 26allow ${HOME}/.abook
27whitelist ${HOME}/.mozilla/firefox/profiles.ini 27allow ${HOME}/.mozilla/firefox/profiles.ini
28whitelist ${HOME}/.cache/flaska.net/trojita 28allow ${HOME}/.cache/flaska.net/trojita
29whitelist ${HOME}/.config/flaska.net 29allow ${HOME}/.config/flaska.net
30include whitelist-common.inc 30include whitelist-common.inc
31include whitelist-runuser-common.inc 31include whitelist-runuser-common.inc
32include whitelist-usr-share-common.inc 32include whitelist-usr-share-common.inc
diff --git a/etc/profile-m-z/truecraft.profile b/etc/profile-m-z/truecraft.profile
index 749626475..76f289a27 100644
--- a/etc/profile-m-z/truecraft.profile
+++ b/etc/profile-m-z/truecraft.profile
@@ -5,8 +5,8 @@ include truecraft.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${HOME}/.config/mono 8nodeny ${HOME}/.config/mono
9noblacklist ${HOME}/.config/truecraft 9nodeny ${HOME}/.config/truecraft
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -17,8 +17,8 @@ include disable-programs.inc
17 17
18mkdir ${HOME}/.config/mono 18mkdir ${HOME}/.config/mono
19mkdir ${HOME}/.config/truecraft 19mkdir ${HOME}/.config/truecraft
20whitelist ${HOME}/.config/mono 20allow ${HOME}/.config/mono
21whitelist ${HOME}/.config/truecraft 21allow ${HOME}/.config/truecraft
22include whitelist-common.inc 22include whitelist-common.inc
23 23
24caps.drop all 24caps.drop all
diff --git a/etc/profile-m-z/ts3client_runscript.sh.profile b/etc/profile-m-z/ts3client_runscript.sh.profile
index 8d4675454..cd6ae96df 100644
--- a/etc/profile-m-z/ts3client_runscript.sh.profile
+++ b/etc/profile-m-z/ts3client_runscript.sh.profile
@@ -9,11 +9,11 @@ include ts3client_runscript.sh.local
9 9
10ignore noexec ${HOME} 10ignore noexec ${HOME}
11 11
12noblacklist ${HOME}/TeamSpeak3-Client-linux_x86 12nodeny ${HOME}/TeamSpeak3-Client-linux_x86
13noblacklist ${HOME}/TeamSpeak3-Client-linux_amd64 13nodeny ${HOME}/TeamSpeak3-Client-linux_amd64
14 14
15whitelist ${HOME}/TeamSpeak3-Client-linux_x86 15allow ${HOME}/TeamSpeak3-Client-linux_x86
16whitelist ${HOME}/TeamSpeak3-Client-linux_amd64 16allow ${HOME}/TeamSpeak3-Client-linux_amd64
17 17
18# Redirect 18# Redirect
19include teamspeak3.profile 19include teamspeak3.profile
diff --git a/etc/profile-m-z/tutanota-desktop.profile b/etc/profile-m-z/tutanota-desktop.profile
index d2cb0cc8a..e59a86ce6 100644
--- a/etc/profile-m-z/tutanota-desktop.profile
+++ b/etc/profile-m-z/tutanota-desktop.profile
@@ -6,8 +6,8 @@ include tutanota-desktop.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/tuta_integration 9nodeny ${HOME}/.config/tuta_integration
10noblacklist ${HOME}/.config/tutanota-desktop 10nodeny ${HOME}/.config/tutanota-desktop
11 11
12ignore noexec /tmp 12ignore noexec /tmp
13 13
@@ -15,12 +15,12 @@ include disable-shell.inc
15 15
16mkdir ${HOME}/.config/tuta_integration 16mkdir ${HOME}/.config/tuta_integration
17mkdir ${HOME}/.config/tutanota-desktop 17mkdir ${HOME}/.config/tutanota-desktop
18whitelist ${HOME}/.config/tuta_integration 18allow ${HOME}/.config/tuta_integration
19whitelist ${HOME}/.config/tutanota-desktop 19allow ${HOME}/.config/tutanota-desktop
20 20
21# These lines are needed to allow Firefox to open links 21# These lines are needed to allow Firefox to open links
22noblacklist ${HOME}/.mozilla 22nodeny ${HOME}/.mozilla
23whitelist ${HOME}/.mozilla/firefox/profiles.ini 23allow ${HOME}/.mozilla/firefox/profiles.ini
24read-only ${HOME}/.mozilla/firefox/profiles.ini 24read-only ${HOME}/.mozilla/firefox/profiles.ini
25 25
26?HAS_APPIMAGE: ignore private-dev 26?HAS_APPIMAGE: ignore private-dev
diff --git a/etc/profile-m-z/tuxguitar.profile b/etc/profile-m-z/tuxguitar.profile
index 3cd496412..5bb97e161 100644
--- a/etc/profile-m-z/tuxguitar.profile
+++ b/etc/profile-m-z/tuxguitar.profile
@@ -9,9 +9,9 @@ include globals.local
9# tuxguitar fails to launch 9# tuxguitar fails to launch
10ignore noexec ${HOME} 10ignore noexec ${HOME}
11 11
12noblacklist ${HOME}/.tuxguitar* 12nodeny ${HOME}/.tuxguitar*
13noblacklist ${DOCUMENTS} 13nodeny ${DOCUMENTS}
14noblacklist ${MUSIC} 14nodeny ${MUSIC}
15 15
16# Allow java (blacklisted by disable-devel.inc) 16# Allow java (blacklisted by disable-devel.inc)
17include allow-java.inc 17include allow-java.inc
diff --git a/etc/profile-m-z/tvbrowser.profile b/etc/profile-m-z/tvbrowser.profile
index dae7d86da..8febcd337 100644
--- a/etc/profile-m-z/tvbrowser.profile
+++ b/etc/profile-m-z/tvbrowser.profile
@@ -6,8 +6,8 @@ include tvbrowser.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/tvbrowser 9nodeny ${HOME}/.config/tvbrowser
10noblacklist ${HOME}/.tvbrowser 10nodeny ${HOME}/.tvbrowser
11 11
12# Allow java (blacklisted by disable-devel.inc) 12# Allow java (blacklisted by disable-devel.inc)
13include allow-java.inc 13include allow-java.inc
@@ -22,9 +22,9 @@ include disable-xdg.inc
22 22
23mkdir ${HOME}/.config/tvbrowser 23mkdir ${HOME}/.config/tvbrowser
24mkdir ${HOME}/.tvbrowser 24mkdir ${HOME}/.tvbrowser
25whitelist ${HOME}/.config/tvbrowser 25allow ${HOME}/.config/tvbrowser
26whitelist ${HOME}/.tvbrowser 26allow ${HOME}/.tvbrowser
27whitelist /usr/share/tvbrowser 27allow /usr/share/tvbrowser
28include whitelist-common.inc 28include whitelist-common.inc
29include whitelist-usr-share-common.inc 29include whitelist-usr-share-common.inc
30include whitelist-var-common.inc 30include whitelist-var-common.inc
diff --git a/etc/profile-m-z/twitch.profile b/etc/profile-m-z/twitch.profile
index 2f573c872..abcc885e6 100644
--- a/etc/profile-m-z/twitch.profile
+++ b/etc/profile-m-z/twitch.profile
@@ -10,12 +10,12 @@ include globals.local
10ignore nou2f 10ignore nou2f
11ignore novideo 11ignore novideo
12 12
13noblacklist ${HOME}/.config/Twitch 13nodeny ${HOME}/.config/Twitch
14 14
15include disable-shell.inc 15include disable-shell.inc
16 16
17mkdir ${HOME}/.config/Twitch 17mkdir ${HOME}/.config/Twitch
18whitelist ${HOME}/.config/Twitch 18allow ${HOME}/.config/Twitch
19 19
20private-bin twitch 20private-bin twitch
21private-etc alsa,alternatives,asound.conf,ati,bumblebee,ca-certificates,crypto-policies,drirc,fonts,gtk-2.0,gtk-3.0,host.conf,hostname,hosts,mime.types,nsswitch.conf,nvidia,pki,pulse,resolv.conf,selinux,ssl,X11,xdg 21private-etc alsa,alternatives,asound.conf,ati,bumblebee,ca-certificates,crypto-policies,drirc,fonts,gtk-2.0,gtk-3.0,host.conf,hostname,hosts,mime.types,nsswitch.conf,nvidia,pki,pulse,resolv.conf,selinux,ssl,X11,xdg
diff --git a/etc/profile-m-z/uefitool.profile b/etc/profile-m-z/uefitool.profile
index 3e4fdbb03..8c705c95f 100644
--- a/etc/profile-m-z/uefitool.profile
+++ b/etc/profile-m-z/uefitool.profile
@@ -5,7 +5,7 @@ include uefitool.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${DOCUMENTS} 8nodeny ${DOCUMENTS}
9 9
10include disable-common.inc 10include disable-common.inc
11include disable-devel.inc 11include disable-devel.inc
diff --git a/etc/profile-m-z/uget-gtk.profile b/etc/profile-m-z/uget-gtk.profile
index 4420099ff..eed2db541 100644
--- a/etc/profile-m-z/uget-gtk.profile
+++ b/etc/profile-m-z/uget-gtk.profile
@@ -5,7 +5,7 @@ include uget-gtk.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${HOME}/.config/uGet 8nodeny ${HOME}/.config/uGet
9 9
10include disable-common.inc 10include disable-common.inc
11include disable-devel.inc 11include disable-devel.inc
@@ -14,8 +14,8 @@ include disable-programs.inc
14include disable-shell.inc 14include disable-shell.inc
15 15
16mkdir ${HOME}/.config/uGet 16mkdir ${HOME}/.config/uGet
17whitelist ${DOWNLOADS} 17allow ${DOWNLOADS}
18whitelist ${HOME}/.config/uGet 18allow ${HOME}/.config/uGet
19include whitelist-common.inc 19include whitelist-common.inc
20include whitelist-usr-share-common.inc 20include whitelist-usr-share-common.inc
21include whitelist-var-common.inc 21include whitelist-var-common.inc
diff --git a/etc/profile-m-z/unbound.profile b/etc/profile-m-z/unbound.profile
index 0c077babf..7e7b3fbec 100644
--- a/etc/profile-m-z/unbound.profile
+++ b/etc/profile-m-z/unbound.profile
@@ -6,11 +6,11 @@ include unbound.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist /sbin 9nodeny /sbin
10noblacklist /usr/sbin 10nodeny /usr/sbin
11 11
12blacklist /tmp/.X11-unix 12deny /tmp/.X11-unix
13blacklist ${RUNUSER}/wayland-* 13deny ${RUNUSER}/wayland-*
14 14
15include disable-common.inc 15include disable-common.inc
16include disable-devel.inc 16include disable-devel.inc
@@ -22,8 +22,8 @@ include disable-xdg.inc
22 22
23include whitelist-usr-share-common.inc 23include whitelist-usr-share-common.inc
24 24
25whitelist /var/lib/unbound 25allow /var/lib/unbound
26whitelist /var/run 26allow /var/run
27 27
28caps.keep net_admin,net_bind_service,setgid,setuid,sys_chroot,sys_resource 28caps.keep net_admin,net_bind_service,setgid,setuid,sys_chroot,sys_resource
29ipc-namespace 29ipc-namespace
diff --git a/etc/profile-m-z/unf.profile b/etc/profile-m-z/unf.profile
index 6db7ba362..846271971 100644
--- a/etc/profile-m-z/unf.profile
+++ b/etc/profile-m-z/unf.profile
@@ -7,7 +7,7 @@ include unf.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10blacklist ${RUNUSER}/wayland-* 10deny ${RUNUSER}/wayland-*
11 11
12include disable-common.inc 12include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
@@ -18,7 +18,7 @@ include disable-programs.inc
18include disable-shell.inc 18include disable-shell.inc
19include disable-xdg.inc 19include disable-xdg.inc
20 20
21whitelist ${DOWNLOADS} 21allow ${DOWNLOADS}
22include whitelist-common.inc 22include whitelist-common.inc
23include whitelist-usr-share-common.inc 23include whitelist-usr-share-common.inc
24include whitelist-var-common.inc 24include whitelist-var-common.inc
diff --git a/etc/profile-m-z/unknown-horizons.profile b/etc/profile-m-z/unknown-horizons.profile
index 956492f52..3e1c6264d 100644
--- a/etc/profile-m-z/unknown-horizons.profile
+++ b/etc/profile-m-z/unknown-horizons.profile
@@ -6,7 +6,7 @@ include unknown-horizons.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.unknown-horizons 9nodeny ${HOME}/.unknown-horizons
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-exec.inc 12include disable-exec.inc
@@ -14,10 +14,10 @@ include disable-passwdmgr.inc
14include disable-programs.inc 14include disable-programs.inc
15 15
16mkdir ${HOME}/.unknown-horizons 16mkdir ${HOME}/.unknown-horizons
17whitelist ${HOME}/.unknown-horizons 17allow ${HOME}/.unknown-horizons
18include whitelist-common.inc 18include whitelist-common.inc
19include whitelist-runuser-common.inc 19include whitelist-runuser-common.inc
20whitelist /usr/share/unknown-horizons 20allow /usr/share/unknown-horizons
21include whitelist-usr-share-common.inc 21include whitelist-usr-share-common.inc
22include whitelist-var-common.inc 22include whitelist-var-common.inc
23 23
diff --git a/etc/profile-m-z/unzip.profile b/etc/profile-m-z/unzip.profile
index 0231e3dba..99d2415ca 100644
--- a/etc/profile-m-z/unzip.profile
+++ b/etc/profile-m-z/unzip.profile
@@ -8,7 +8,7 @@ include unzip.local
8include globals.local 8include globals.local
9 9
10# GNOME Shell integration (chrome-gnome-shell) 10# GNOME Shell integration (chrome-gnome-shell)
11noblacklist ${HOME}/.local/share/gnome-shell 11nodeny ${HOME}/.local/share/gnome-shell
12 12
13private-etc alternatives,group,localtime,passwd 13private-etc alternatives,group,localtime,passwd
14 14
diff --git a/etc/profile-m-z/utox.profile b/etc/profile-m-z/utox.profile
index dd881f091..3b0f7c646 100644
--- a/etc/profile-m-z/utox.profile
+++ b/etc/profile-m-z/utox.profile
@@ -6,8 +6,8 @@ include utox.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.cache/Tox 9nodeny ${HOME}/.cache/Tox
10noblacklist ${HOME}/.config/tox 10nodeny ${HOME}/.config/tox
11 11
12include disable-common.inc 12include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
@@ -19,8 +19,8 @@ include disable-shell.inc
19include disable-xdg.inc 19include disable-xdg.inc
20 20
21mkdir ${HOME}/.config/tox 21mkdir ${HOME}/.config/tox
22whitelist ${DOWNLOADS} 22allow ${DOWNLOADS}
23whitelist ${HOME}/.config/tox 23allow ${HOME}/.config/tox
24include whitelist-common.inc 24include whitelist-common.inc
25include whitelist-var-common.inc 25include whitelist-var-common.inc
26 26
diff --git a/etc/profile-m-z/uudeview.profile b/etc/profile-m-z/uudeview.profile
index 2adc044e5..3bda71666 100644
--- a/etc/profile-m-z/uudeview.profile
+++ b/etc/profile-m-z/uudeview.profile
@@ -7,7 +7,7 @@ include uudeview.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10blacklist ${RUNUSER}/wayland-* 10deny ${RUNUSER}/wayland-*
11 11
12include disable-common.inc 12include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
diff --git a/etc/profile-m-z/uzbl-browser.profile b/etc/profile-m-z/uzbl-browser.profile
index 41487a8f2..6899f4bf7 100644
--- a/etc/profile-m-z/uzbl-browser.profile
+++ b/etc/profile-m-z/uzbl-browser.profile
@@ -5,9 +5,9 @@ include uzbl-browser.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${HOME}/.config/uzbl 8nodeny ${HOME}/.config/uzbl
9noblacklist ${HOME}/.gnupg 9nodeny ${HOME}/.gnupg
10noblacklist ${HOME}/.local/share/uzbl 10nodeny ${HOME}/.local/share/uzbl
11 11
12# Allow python (blacklisted by disable-interpreters.inc) 12# Allow python (blacklisted by disable-interpreters.inc)
13include allow-python2.inc 13include allow-python2.inc
@@ -22,11 +22,11 @@ mkdir ${HOME}/.config/uzbl
22mkdir ${HOME}/.gnupg 22mkdir ${HOME}/.gnupg
23mkdir ${HOME}/.local/share/uzbl 23mkdir ${HOME}/.local/share/uzbl
24mkdir ${HOME}/.password-store 24mkdir ${HOME}/.password-store
25whitelist ${DOWNLOADS} 25allow ${DOWNLOADS}
26whitelist ${HOME}/.config/uzbl 26allow ${HOME}/.config/uzbl
27whitelist ${HOME}/.gnupg 27allow ${HOME}/.gnupg
28whitelist ${HOME}/.local/share/uzbl 28allow ${HOME}/.local/share/uzbl
29whitelist ${HOME}/.password-store 29allow ${HOME}/.password-store
30include whitelist-common.inc 30include whitelist-common.inc
31 31
32caps.drop all 32caps.drop all
diff --git a/etc/profile-m-z/viewnior.profile b/etc/profile-m-z/viewnior.profile
index a9ba344dd..e0bf02706 100644
--- a/etc/profile-m-z/viewnior.profile
+++ b/etc/profile-m-z/viewnior.profile
@@ -6,11 +6,11 @@ include viewnior.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.Steam 9nodeny ${HOME}/.Steam
10noblacklist ${HOME}/.config/viewnior 10nodeny ${HOME}/.config/viewnior
11noblacklist ${HOME}/.steam 11nodeny ${HOME}/.steam
12 12
13blacklist ${HOME}/.bashrc 13deny ${HOME}/.bashrc
14 14
15include disable-common.inc 15include disable-common.inc
16include disable-devel.inc 16include disable-devel.inc
diff --git a/etc/profile-m-z/viking.profile b/etc/profile-m-z/viking.profile
index 8f8ef5939..b16f691d6 100644
--- a/etc/profile-m-z/viking.profile
+++ b/etc/profile-m-z/viking.profile
@@ -6,9 +6,9 @@ include viking.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.viking 9nodeny ${HOME}/.viking
10noblacklist ${HOME}/.viking-maps 10nodeny ${HOME}/.viking-maps
11noblacklist ${DOCUMENTS} 11nodeny ${DOCUMENTS}
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
diff --git a/etc/profile-m-z/vim.profile b/etc/profile-m-z/vim.profile
index c3cfe5980..b535225dd 100644
--- a/etc/profile-m-z/vim.profile
+++ b/etc/profile-m-z/vim.profile
@@ -6,9 +6,9 @@ include vim.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.vim 9nodeny ${HOME}/.vim
10noblacklist ${HOME}/.viminfo 10nodeny ${HOME}/.viminfo
11noblacklist ${HOME}/.vimrc 11nodeny ${HOME}/.vimrc
12 12
13# Allows files commonly used by IDEs 13# Allows files commonly used by IDEs
14include allow-common-devel.inc 14include allow-common-devel.inc
diff --git a/etc/profile-m-z/virtualbox.profile b/etc/profile-m-z/virtualbox.profile
index c22fb0ff9..f28828338 100644
--- a/etc/profile-m-z/virtualbox.profile
+++ b/etc/profile-m-z/virtualbox.profile
@@ -6,12 +6,12 @@ include virtualbox.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.VirtualBox 9nodeny ${HOME}/.VirtualBox
10noblacklist ${HOME}/.config/VirtualBox 10nodeny ${HOME}/.config/VirtualBox
11noblacklist ${HOME}/VirtualBox VMs 11nodeny ${HOME}/VirtualBox VMs
12# noblacklist /usr/bin/virtualbox 12# noblacklist /usr/bin/virtualbox
13noblacklist /usr/lib/virtualbox 13nodeny /usr/lib/virtualbox
14noblacklist /usr/lib64/virtualbox 14nodeny /usr/lib64/virtualbox
15 15
16include disable-common.inc 16include disable-common.inc
17include disable-devel.inc 17include disable-devel.inc
@@ -23,10 +23,10 @@ include disable-xdg.inc
23 23
24mkdir ${HOME}/.config/VirtualBox 24mkdir ${HOME}/.config/VirtualBox
25mkdir ${HOME}/VirtualBox VMs 25mkdir ${HOME}/VirtualBox VMs
26whitelist ${HOME}/.config/VirtualBox 26allow ${HOME}/.config/VirtualBox
27whitelist ${HOME}/VirtualBox VMs 27allow ${HOME}/VirtualBox VMs
28whitelist ${DOWNLOADS} 28allow ${DOWNLOADS}
29whitelist /usr/share/virtualbox 29allow /usr/share/virtualbox
30include whitelist-common.inc 30include whitelist-common.inc
31include whitelist-runuser-common.inc 31include whitelist-runuser-common.inc
32include whitelist-usr-share-common.inc 32include whitelist-usr-share-common.inc
diff --git a/etc/profile-m-z/vivaldi.profile b/etc/profile-m-z/vivaldi.profile
index fdeb0307f..3858405db 100644
--- a/etc/profile-m-z/vivaldi.profile
+++ b/etc/profile-m-z/vivaldi.profile
@@ -8,26 +8,26 @@ include globals.local
8# Allow HTML5 Proprietary Media & DRM/EME (Widevine) 8# Allow HTML5 Proprietary Media & DRM/EME (Widevine)
9ignore apparmor 9ignore apparmor
10ignore noexec /var 10ignore noexec /var
11noblacklist /var/opt 11nodeny /var/opt
12whitelist /var/opt/vivaldi 12allow /var/opt/vivaldi
13writable-var 13writable-var
14 14
15noblacklist ${HOME}/.cache/vivaldi 15nodeny ${HOME}/.cache/vivaldi
16noblacklist ${HOME}/.cache/vivaldi-snapshot 16nodeny ${HOME}/.cache/vivaldi-snapshot
17noblacklist ${HOME}/.config/vivaldi 17nodeny ${HOME}/.config/vivaldi
18noblacklist ${HOME}/.config/vivaldi-snapshot 18nodeny ${HOME}/.config/vivaldi-snapshot
19noblacklist ${HOME}/.local/lib/vivaldi 19nodeny ${HOME}/.local/lib/vivaldi
20 20
21mkdir ${HOME}/.cache/vivaldi 21mkdir ${HOME}/.cache/vivaldi
22mkdir ${HOME}/.cache/vivaldi-snapshot 22mkdir ${HOME}/.cache/vivaldi-snapshot
23mkdir ${HOME}/.config/vivaldi 23mkdir ${HOME}/.config/vivaldi
24mkdir ${HOME}/.config/vivaldi-snapshot 24mkdir ${HOME}/.config/vivaldi-snapshot
25mkdir ${HOME}/.local/lib/vivaldi 25mkdir ${HOME}/.local/lib/vivaldi
26whitelist ${HOME}/.cache/vivaldi 26allow ${HOME}/.cache/vivaldi
27whitelist ${HOME}/.cache/vivaldi-snapshot 27allow ${HOME}/.cache/vivaldi-snapshot
28whitelist ${HOME}/.config/vivaldi 28allow ${HOME}/.config/vivaldi
29whitelist ${HOME}/.config/vivaldi-snapshot 29allow ${HOME}/.config/vivaldi-snapshot
30whitelist ${HOME}/.local/lib/vivaldi 30allow ${HOME}/.local/lib/vivaldi
31 31
32#private-bin bash,cat,dirname,readlink,rm,vivaldi,vivaldi-stable,vivaldi-snapshot 32#private-bin bash,cat,dirname,readlink,rm,vivaldi,vivaldi-stable,vivaldi-snapshot
33 33
diff --git a/etc/profile-m-z/vlc.profile b/etc/profile-m-z/vlc.profile
index cd7dccd8a..ede2d4525 100644
--- a/etc/profile-m-z/vlc.profile
+++ b/etc/profile-m-z/vlc.profile
@@ -6,10 +6,10 @@ include vlc.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.cache/vlc 9nodeny ${HOME}/.cache/vlc
10noblacklist ${HOME}/.config/vlc 10nodeny ${HOME}/.config/vlc
11noblacklist ${HOME}/.config/aacs 11nodeny ${HOME}/.config/aacs
12noblacklist ${HOME}/.local/share/vlc 12nodeny ${HOME}/.local/share/vlc
13 13
14include disable-common.inc 14include disable-common.inc
15include disable-devel.inc 15include disable-devel.inc
@@ -22,10 +22,10 @@ read-only ${DESKTOP}
22mkdir ${HOME}/.cache/vlc 22mkdir ${HOME}/.cache/vlc
23mkdir ${HOME}/.config/vlc 23mkdir ${HOME}/.config/vlc
24mkdir ${HOME}/.local/share/vlc 24mkdir ${HOME}/.local/share/vlc
25whitelist ${HOME}/.cache/vlc 25allow ${HOME}/.cache/vlc
26whitelist ${HOME}/.config/vlc 26allow ${HOME}/.config/vlc
27whitelist ${HOME}/.config/aacs 27allow ${HOME}/.config/aacs
28whitelist ${HOME}/.local/share/vlc 28allow ${HOME}/.local/share/vlc
29include whitelist-common.inc 29include whitelist-common.inc
30include whitelist-player-common.inc 30include whitelist-player-common.inc
31include whitelist-var-common.inc 31include whitelist-var-common.inc
diff --git a/etc/profile-m-z/vmware-view.profile b/etc/profile-m-z/vmware-view.profile
index f07c31b68..f23e90e84 100644
--- a/etc/profile-m-z/vmware-view.profile
+++ b/etc/profile-m-z/vmware-view.profile
@@ -6,10 +6,10 @@ include vmware-view.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.vmware 9nodeny ${HOME}/.vmware
10 10
11noblacklist /sbin 11nodeny /sbin
12noblacklist /usr/sbin 12nodeny /usr/sbin
13 13
14include allow-bin-sh.inc 14include allow-bin-sh.inc
15 15
@@ -23,7 +23,7 @@ include disable-shell.inc
23include disable-xdg.inc 23include disable-xdg.inc
24 24
25mkdir ${HOME}/.vmware 25mkdir ${HOME}/.vmware
26whitelist ${HOME}/.vmware 26allow ${HOME}/.vmware
27include whitelist-common.inc 27include whitelist-common.inc
28include whitelist-runuser-common.inc 28include whitelist-runuser-common.inc
29include whitelist-usr-share-common.inc 29include whitelist-usr-share-common.inc
diff --git a/etc/profile-m-z/vmware.profile b/etc/profile-m-z/vmware.profile
index 5241e27b3..3a535588f 100644
--- a/etc/profile-m-z/vmware.profile
+++ b/etc/profile-m-z/vmware.profile
@@ -6,8 +6,8 @@ include vmware.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.cache/vmware 9nodeny ${HOME}/.cache/vmware
10noblacklist ${HOME}/.vmware 10nodeny ${HOME}/.vmware
11 11
12include disable-common.inc 12include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
@@ -19,8 +19,8 @@ include disable-xdg.inc
19 19
20mkdir ${HOME}/.cache/vmware 20mkdir ${HOME}/.cache/vmware
21mkdir ${HOME}/.vmware 21mkdir ${HOME}/.vmware
22whitelist ${HOME}/.cache/vmware 22allow ${HOME}/.cache/vmware
23whitelist ${HOME}/.vmware 23allow ${HOME}/.vmware
24# Add the next lines to your vmware.local if you need to use "shared VM". 24# Add the next lines to your vmware.local if you need to use "shared VM".
25#whitelist /var/lib/vmware 25#whitelist /var/lib/vmware
26#writable-var 26#writable-var
diff --git a/etc/profile-m-z/vscodium.profile b/etc/profile-m-z/vscodium.profile
index a4a4fb7d8..7996113f5 100644
--- a/etc/profile-m-z/vscodium.profile
+++ b/etc/profile-m-z/vscodium.profile
@@ -6,7 +6,7 @@ include vscodium.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist ${HOME}/.VSCodium 9nodeny ${HOME}/.VSCodium
10 10
11# Redirect 11# Redirect
12include code.profile 12include code.profile
diff --git a/etc/profile-m-z/vulturesclaw.profile b/etc/profile-m-z/vulturesclaw.profile
index fa6ddf1fb..a6c38c1f1 100644
--- a/etc/profile-m-z/vulturesclaw.profile
+++ b/etc/profile-m-z/vulturesclaw.profile
@@ -6,8 +6,8 @@ include vulturesclaw.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist /var/games/vulturesclaw 9nodeny /var/games/vulturesclaw
10whitelist /var/games/vulturesclaw 10allow /var/games/vulturesclaw
11 11
12# Redirect 12# Redirect
13include nethack-vultures.profile 13include nethack-vultures.profile
diff --git a/etc/profile-m-z/vultureseye.profile b/etc/profile-m-z/vultureseye.profile
index 49d3fa94f..763c50bf6 100644
--- a/etc/profile-m-z/vultureseye.profile
+++ b/etc/profile-m-z/vultureseye.profile
@@ -6,8 +6,8 @@ include vultureseye.local
6# added by included profile 6# added by included profile
7#include globals.local 7#include globals.local
8 8
9noblacklist /var/games/vultureseye 9nodeny /var/games/vultureseye
10whitelist /var/games/vultureseye 10allow /var/games/vultureseye
11 11
12# Redirect 12# Redirect
13include nethack-vultures.profile 13include nethack-vultures.profile
diff --git a/etc/profile-m-z/vym.profile b/etc/profile-m-z/vym.profile
index 5421c4e4b..1f2462c32 100644
--- a/etc/profile-m-z/vym.profile
+++ b/etc/profile-m-z/vym.profile
@@ -6,7 +6,7 @@ include vym.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/InSilmaril 9nodeny ${HOME}/.config/InSilmaril
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
diff --git a/etc/profile-m-z/w3m.profile b/etc/profile-m-z/w3m.profile
index 69b2c6c59..6b38bbf13 100644
--- a/etc/profile-m-z/w3m.profile
+++ b/etc/profile-m-z/w3m.profile
@@ -12,10 +12,10 @@ include globals.local
12#ignore private-dev 12#ignore private-dev
13#ignore private-etc 13#ignore private-etc
14 14
15noblacklist ${HOME}/.w3m 15nodeny ${HOME}/.w3m
16 16
17blacklist /tmp/.X11-unix 17deny /tmp/.X11-unix
18blacklist ${RUNUSER}/wayland-* 18deny ${RUNUSER}/wayland-*
19 19
20# Allow /bin/sh (blacklisted by disable-shell.inc) 20# Allow /bin/sh (blacklisted by disable-shell.inc)
21include allow-bin-sh.inc 21include allow-bin-sh.inc
@@ -33,9 +33,9 @@ include disable-shell.inc
33include disable-xdg.inc 33include disable-xdg.inc
34 34
35mkdir ${HOME}/.w3m 35mkdir ${HOME}/.w3m
36whitelist /usr/share/w3m 36allow /usr/share/w3m
37whitelist ${DOWNLOADS} 37allow ${DOWNLOADS}
38whitelist ${HOME}/.w3m 38allow ${HOME}/.w3m
39include whitelist-runuser-common.inc 39include whitelist-runuser-common.inc
40include whitelist-usr-share-common.inc 40include whitelist-usr-share-common.inc
41include whitelist-var-common.inc 41include whitelist-var-common.inc
diff --git a/etc/profile-m-z/warmux.profile b/etc/profile-m-z/warmux.profile
index 1227a202c..6658ac5db 100644
--- a/etc/profile-m-z/warmux.profile
+++ b/etc/profile-m-z/warmux.profile
@@ -6,9 +6,9 @@ include warmux.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/wormux 9nodeny ${HOME}/.config/wormux
10noblacklist ${HOME}/.local/share/wormux 10nodeny ${HOME}/.local/share/wormux
11noblacklist ${HOME}/.wormux 11nodeny ${HOME}/.wormux
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
@@ -22,10 +22,10 @@ include disable-xdg.inc
22mkdir ${HOME}/.config/wormux 22mkdir ${HOME}/.config/wormux
23mkdir ${HOME}/.local/share/wormux 23mkdir ${HOME}/.local/share/wormux
24mkdir ${HOME}/.wormux 24mkdir ${HOME}/.wormux
25whitelist ${HOME}/.config/wormux 25allow ${HOME}/.config/wormux
26whitelist ${HOME}/.local/share/wormux 26allow ${HOME}/.local/share/wormux
27whitelist ${HOME}/.wormux 27allow ${HOME}/.wormux
28whitelist /usr/share/warmux 28allow /usr/share/warmux
29include whitelist-common.inc 29include whitelist-common.inc
30include whitelist-usr-share-common.inc 30include whitelist-usr-share-common.inc
31include whitelist-var-common.inc 31include whitelist-var-common.inc
diff --git a/etc/profile-m-z/warsow.profile b/etc/profile-m-z/warsow.profile
index e0cd3daad..fac4d0555 100644
--- a/etc/profile-m-z/warsow.profile
+++ b/etc/profile-m-z/warsow.profile
@@ -8,8 +8,8 @@ include globals.local
8 8
9ignore noexec ${HOME} 9ignore noexec ${HOME}
10 10
11noblacklist ${HOME}/.cache/warsow-2.1 11nodeny ${HOME}/.cache/warsow-2.1
12noblacklist ${HOME}/.local/share/warsow-2.1 12nodeny ${HOME}/.local/share/warsow-2.1
13 13
14include disable-common.inc 14include disable-common.inc
15include disable-devel.inc 15include disable-devel.inc
@@ -22,9 +22,9 @@ include disable-xdg.inc
22 22
23mkdir ${HOME}/.cache/warsow-2.1 23mkdir ${HOME}/.cache/warsow-2.1
24mkdir ${HOME}/.local/share/warsow-2.1 24mkdir ${HOME}/.local/share/warsow-2.1
25whitelist ${HOME}/.cache/warsow-2.1 25allow ${HOME}/.cache/warsow-2.1
26whitelist ${HOME}/.local/share/warsow-2.1 26allow ${HOME}/.local/share/warsow-2.1
27whitelist /usr/share/warsow 27allow /usr/share/warsow
28include whitelist-common.inc 28include whitelist-common.inc
29include whitelist-runuser-common.inc 29include whitelist-runuser-common.inc
30include whitelist-usr-share-common.inc 30include whitelist-usr-share-common.inc
diff --git a/etc/profile-m-z/warzone2100.profile b/etc/profile-m-z/warzone2100.profile
index 420e8927e..081ae349b 100644
--- a/etc/profile-m-z/warzone2100.profile
+++ b/etc/profile-m-z/warzone2100.profile
@@ -6,7 +6,7 @@ include warzone2100.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.warzone2100-3.* 9nodeny ${HOME}/.warzone2100-3.*
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -18,9 +18,9 @@ include disable-shell.inc
18 18
19mkdir ${HOME}/.warzone2100-3.1 19mkdir ${HOME}/.warzone2100-3.1
20mkdir ${HOME}/.warzone2100-3.2 20mkdir ${HOME}/.warzone2100-3.2
21whitelist ${HOME}/.warzone2100-3.1 21allow ${HOME}/.warzone2100-3.1
22whitelist ${HOME}/.warzone2100-3.2 22allow ${HOME}/.warzone2100-3.2
23whitelist /usr/share/games 23allow /usr/share/games
24include whitelist-common.inc 24include whitelist-common.inc
25include whitelist-runuser-common.inc 25include whitelist-runuser-common.inc
26include whitelist-usr-share-common.inc 26include whitelist-usr-share-common.inc
diff --git a/etc/profile-m-z/waterfox.profile b/etc/profile-m-z/waterfox.profile
index 18f1ca79a..4081b29b9 100644
--- a/etc/profile-m-z/waterfox.profile
+++ b/etc/profile-m-z/waterfox.profile
@@ -5,13 +5,13 @@ include waterfox.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${HOME}/.cache/waterfox 8nodeny ${HOME}/.cache/waterfox
9noblacklist ${HOME}/.waterfox 9nodeny ${HOME}/.waterfox
10 10
11mkdir ${HOME}/.cache/waterfox 11mkdir ${HOME}/.cache/waterfox
12mkdir ${HOME}/.waterfox 12mkdir ${HOME}/.waterfox
13whitelist ${HOME}/.cache/waterfox 13allow ${HOME}/.cache/waterfox
14whitelist ${HOME}/.waterfox 14allow ${HOME}/.waterfox
15 15
16# Add the next lines to your watefox.local if you want to use the migration wizard. 16# Add the next lines to your watefox.local if you want to use the migration wizard.
17#noblacklist ${HOME}/.mozilla 17#noblacklist ${HOME}/.mozilla
diff --git a/etc/profile-m-z/webstorm.profile b/etc/profile-m-z/webstorm.profile
index 69e96d0cd..1f42dae2c 100644
--- a/etc/profile-m-z/webstorm.profile
+++ b/etc/profile-m-z/webstorm.profile
@@ -5,12 +5,12 @@ include webstorm.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${HOME}/.WebStorm* 8nodeny ${HOME}/.WebStorm*
9noblacklist ${HOME}/.android 9nodeny ${HOME}/.android
10noblacklist ${HOME}/.local/share/JetBrains 10nodeny ${HOME}/.local/share/JetBrains
11noblacklist ${HOME}/.tooling 11nodeny ${HOME}/.tooling
12# Allow KDE file manager to open with log directories (blacklisted by disable-programs.inc) 12# Allow KDE file manager to open with log directories (blacklisted by disable-programs.inc)
13noblacklist ${HOME}/.config/dolphinrc 13nodeny ${HOME}/.config/dolphinrc
14 14
15# Allows files commonly used by IDEs 15# Allows files commonly used by IDEs
16include allow-common-devel.inc 16include allow-common-devel.inc
@@ -18,8 +18,8 @@ include allow-common-devel.inc
18# Allow ssh (blacklisted by disable-common.inc) 18# Allow ssh (blacklisted by disable-common.inc)
19include allow-ssh.inc 19include allow-ssh.inc
20 20
21noblacklist ${PATH}/node 21nodeny ${PATH}/node
22noblacklist ${HOME}/.nvm 22nodeny ${HOME}/.nvm
23 23
24include disable-common.inc 24include disable-common.inc
25include disable-devel.inc 25include disable-devel.inc
diff --git a/etc/profile-m-z/webui-aria2.profile b/etc/profile-m-z/webui-aria2.profile
index d5a998f35..d1bbcfb67 100644
--- a/etc/profile-m-z/webui-aria2.profile
+++ b/etc/profile-m-z/webui-aria2.profile
@@ -6,7 +6,7 @@ include webui-aria2.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${PATH}/node 9nodeny ${PATH}/node
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
diff --git a/etc/profile-m-z/weechat.profile b/etc/profile-m-z/weechat.profile
index 76935212f..99941a590 100644
--- a/etc/profile-m-z/weechat.profile
+++ b/etc/profile-m-z/weechat.profile
@@ -6,12 +6,12 @@ include weechat.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.weechat 9nodeny ${HOME}/.weechat
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-programs.inc 12include disable-programs.inc
13 13
14whitelist /usr/share/weechat 14allow /usr/share/weechat
15include whitelist-usr-share-common.inc 15include whitelist-usr-share-common.inc
16include whitelist-var-common.inc 16include whitelist-var-common.inc
17 17
diff --git a/etc/profile-m-z/wesnoth.profile b/etc/profile-m-z/wesnoth.profile
index 199b3c6f0..47b923e6a 100644
--- a/etc/profile-m-z/wesnoth.profile
+++ b/etc/profile-m-z/wesnoth.profile
@@ -6,9 +6,9 @@ include wesnoth.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.cache/wesnoth 9nodeny ${HOME}/.cache/wesnoth
10noblacklist ${HOME}/.config/wesnoth 10nodeny ${HOME}/.config/wesnoth
11noblacklist ${HOME}/.local/share/wesnoth 11nodeny ${HOME}/.local/share/wesnoth
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
@@ -19,9 +19,9 @@ include disable-programs.inc
19mkdir ${HOME}/.cache/wesnoth 19mkdir ${HOME}/.cache/wesnoth
20mkdir ${HOME}/.config/wesnoth 20mkdir ${HOME}/.config/wesnoth
21mkdir ${HOME}/.local/share/wesnoth 21mkdir ${HOME}/.local/share/wesnoth
22whitelist ${HOME}/.cache/wesnoth 22allow ${HOME}/.cache/wesnoth
23whitelist ${HOME}/.config/wesnoth 23allow ${HOME}/.config/wesnoth
24whitelist ${HOME}/.local/share/wesnoth 24allow ${HOME}/.local/share/wesnoth
25include whitelist-common.inc 25include whitelist-common.inc
26 26
27caps.drop all 27caps.drop all
diff --git a/etc/profile-m-z/wget.profile b/etc/profile-m-z/wget.profile
index 53c4711bd..3c4a4eb63 100644
--- a/etc/profile-m-z/wget.profile
+++ b/etc/profile-m-z/wget.profile
@@ -7,12 +7,12 @@ include wget.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10noblacklist ${HOME}/.netrc 10nodeny ${HOME}/.netrc
11noblacklist ${HOME}/.wget-hsts 11nodeny ${HOME}/.wget-hsts
12noblacklist ${HOME}/.wgetrc 12nodeny ${HOME}/.wgetrc
13 13
14blacklist /tmp/.X11-unix 14deny /tmp/.X11-unix
15blacklist ${RUNUSER} 15deny ${RUNUSER}
16 16
17include disable-common.inc 17include disable-common.inc
18include disable-devel.inc 18include disable-devel.inc
diff --git a/etc/profile-m-z/whalebird.profile b/etc/profile-m-z/whalebird.profile
index 22a84274d..fdbd406c2 100644
--- a/etc/profile-m-z/whalebird.profile
+++ b/etc/profile-m-z/whalebird.profile
@@ -13,10 +13,10 @@ ignore include whitelist-usr-share-common.inc
13ignore dbus-user none 13ignore dbus-user none
14ignore dbus-system none 14ignore dbus-system none
15 15
16noblacklist ${HOME}/.config/Whalebird 16nodeny ${HOME}/.config/Whalebird
17 17
18mkdir ${HOME}/.config/Whalebird 18mkdir ${HOME}/.config/Whalebird
19whitelist ${HOME}/.config/Whalebird 19allow ${HOME}/.config/Whalebird
20 20
21no3d 21no3d
22 22
diff --git a/etc/profile-m-z/whois.profile b/etc/profile-m-z/whois.profile
index 93871a5a4..35d7fe9cb 100644
--- a/etc/profile-m-z/whois.profile
+++ b/etc/profile-m-z/whois.profile
@@ -7,8 +7,8 @@ include whois.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10blacklist /tmp/.X11-unix 10deny /tmp/.X11-unix
11blacklist ${RUNUSER} 11deny ${RUNUSER}
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
diff --git a/etc/profile-m-z/widelands.profile b/etc/profile-m-z/widelands.profile
index 0dc26b11d..8f5adb0fc 100644
--- a/etc/profile-m-z/widelands.profile
+++ b/etc/profile-m-z/widelands.profile
@@ -6,7 +6,7 @@ include widelands.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.widelands 9nodeny ${HOME}/.widelands
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -18,7 +18,7 @@ include disable-shell.inc
18include disable-xdg.inc 18include disable-xdg.inc
19 19
20mkdir ${HOME}/.widelands 20mkdir ${HOME}/.widelands
21whitelist ${HOME}/.widelands 21allow ${HOME}/.widelands
22include whitelist-common.inc 22include whitelist-common.inc
23include whitelist-var-common.inc 23include whitelist-var-common.inc
24 24
diff --git a/etc/profile-m-z/wine.profile b/etc/profile-m-z/wine.profile
index 0ea24aafd..6bc68c829 100644
--- a/etc/profile-m-z/wine.profile
+++ b/etc/profile-m-z/wine.profile
@@ -6,13 +6,13 @@ include wine.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.cache/winetricks 9nodeny ${HOME}/.cache/winetricks
10noblacklist ${HOME}/.Steam 10nodeny ${HOME}/.Steam
11noblacklist ${HOME}/.local/share/Steam 11nodeny ${HOME}/.local/share/Steam
12noblacklist ${HOME}/.local/share/steam 12nodeny ${HOME}/.local/share/steam
13noblacklist ${HOME}/.steam 13nodeny ${HOME}/.steam
14noblacklist ${HOME}/.wine 14nodeny ${HOME}/.wine
15noblacklist /tmp/.wine-* 15nodeny /tmp/.wine-*
16 16
17include disable-common.inc 17include disable-common.inc
18include disable-devel.inc 18include disable-devel.inc
diff --git a/etc/profile-m-z/wire-desktop.profile b/etc/profile-m-z/wire-desktop.profile
index 151cd2adb..5f40bbd48 100644
--- a/etc/profile-m-z/wire-desktop.profile
+++ b/etc/profile-m-z/wire-desktop.profile
@@ -20,10 +20,10 @@ ignore private-cache
20ignore dbus-user none 20ignore dbus-user none
21ignore dbus-system none 21ignore dbus-system none
22 22
23noblacklist ${HOME}/.config/Wire 23nodeny ${HOME}/.config/Wire
24 24
25mkdir ${HOME}/.config/Wire 25mkdir ${HOME}/.config/Wire
26whitelist ${HOME}/.config/Wire 26allow ${HOME}/.config/Wire
27 27
28private-bin bash,electron,electron[0-9],electron[0-9][0-9],env,sh,wire-desktop 28private-bin bash,electron,electron[0-9],electron[0-9][0-9],env,sh,wire-desktop
29private-etc alternatives,ca-certificates,crypto-policies,fonts,machine-id,pki,resolv.conf,ssl 29private-etc alternatives,ca-certificates,crypto-policies,fonts,machine-id,pki,resolv.conf,ssl
diff --git a/etc/profile-m-z/wireshark.profile b/etc/profile-m-z/wireshark.profile
index 1824026a8..f3f347283 100644
--- a/etc/profile-m-z/wireshark.profile
+++ b/etc/profile-m-z/wireshark.profile
@@ -6,9 +6,9 @@ include wireshark.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/wireshark 9nodeny ${HOME}/.config/wireshark
10noblacklist ${HOME}/.wireshark 10nodeny ${HOME}/.wireshark
11noblacklist ${DOCUMENTS} 11nodeny ${DOCUMENTS}
12 12
13# Allow lua (blacklisted by disable-interpreters.inc) 13# Allow lua (blacklisted by disable-interpreters.inc)
14include allow-lua.inc 14include allow-lua.inc
@@ -21,7 +21,7 @@ include disable-passwdmgr.inc
21include disable-programs.inc 21include disable-programs.inc
22include disable-xdg.inc 22include disable-xdg.inc
23 23
24whitelist /usr/share/wireshark 24allow /usr/share/wireshark
25include whitelist-usr-share-common.inc 25include whitelist-usr-share-common.inc
26include whitelist-var-common.inc 26include whitelist-var-common.inc
27 27
diff --git a/etc/profile-m-z/wordwarvi.profile b/etc/profile-m-z/wordwarvi.profile
index 9c724a5d2..1f1541a20 100644
--- a/etc/profile-m-z/wordwarvi.profile
+++ b/etc/profile-m-z/wordwarvi.profile
@@ -6,7 +6,7 @@ include wordwarvi.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.wordwarvi 9nodeny ${HOME}/.wordwarvi
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -18,8 +18,8 @@ include disable-shell.inc
18include disable-xdg.inc 18include disable-xdg.inc
19 19
20mkdir ${HOME}/.wordwarvi 20mkdir ${HOME}/.wordwarvi
21whitelist ${HOME}/.wordwarvi 21allow ${HOME}/.wordwarvi
22whitelist /usr/share/wordwarvi 22allow /usr/share/wordwarvi
23include whitelist-common.inc 23include whitelist-common.inc
24include whitelist-usr-share-common.inc 24include whitelist-usr-share-common.inc
25include whitelist-var-common.inc 25include whitelist-var-common.inc
diff --git a/etc/profile-m-z/wps.profile b/etc/profile-m-z/wps.profile
index a44b6490e..6d16dfb04 100644
--- a/etc/profile-m-z/wps.profile
+++ b/etc/profile-m-z/wps.profile
@@ -6,9 +6,9 @@ include wps.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.kingsoft 9nodeny ${HOME}/.kingsoft
10noblacklist ${HOME}/.config/Kingsoft 10nodeny ${HOME}/.config/Kingsoft
11noblacklist ${HOME}/.local/share/Kingsoft 11nodeny ${HOME}/.local/share/Kingsoft
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
diff --git a/etc/profile-m-z/x2goclient.profile b/etc/profile-m-z/x2goclient.profile
index 557f07cd9..311746cd9 100644
--- a/etc/profile-m-z/x2goclient.profile
+++ b/etc/profile-m-z/x2goclient.profile
@@ -6,8 +6,8 @@ include x2goclient.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.x2go 9nodeny ${HOME}/.x2go
10noblacklist ${HOME}/.x2goclient 10nodeny ${HOME}/.x2goclient
11 11
12# Allow ssh (blacklisted by disable-common.inc) 12# Allow ssh (blacklisted by disable-common.inc)
13include allow-ssh.inc 13include allow-ssh.inc
diff --git a/etc/profile-m-z/xbill.profile b/etc/profile-m-z/xbill.profile
index 384f76acc..e545aa3a0 100644
--- a/etc/profile-m-z/xbill.profile
+++ b/etc/profile-m-z/xbill.profile
@@ -15,8 +15,8 @@ include disable-programs.inc
15include disable-shell.inc 15include disable-shell.inc
16include disable-xdg.inc 16include disable-xdg.inc
17 17
18whitelist /usr/share/xbill 18allow /usr/share/xbill
19whitelist /var/games/xbill/scores 19allow /var/games/xbill/scores
20include whitelist-common.inc 20include whitelist-common.inc
21include whitelist-usr-share-common.inc 21include whitelist-usr-share-common.inc
22include whitelist-var-common.inc 22include whitelist-var-common.inc
diff --git a/etc/profile-m-z/xchat.profile b/etc/profile-m-z/xchat.profile
index a94444aab..7d0adbcc2 100644
--- a/etc/profile-m-z/xchat.profile
+++ b/etc/profile-m-z/xchat.profile
@@ -6,7 +6,7 @@ include xchat.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/xchat 9nodeny ${HOME}/.config/xchat
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
diff --git a/etc/profile-m-z/xed.profile b/etc/profile-m-z/xed.profile
index 4a3022e83..5db709bd1 100644
--- a/etc/profile-m-z/xed.profile
+++ b/etc/profile-m-z/xed.profile
@@ -5,10 +5,10 @@ include xed.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${HOME}/.config/xed 8nodeny ${HOME}/.config/xed
9noblacklist ${HOME}/.python-history 9nodeny ${HOME}/.python-history
10noblacklist ${HOME}/.python_history 10nodeny ${HOME}/.python_history
11noblacklist ${HOME}/.pythonhist 11nodeny ${HOME}/.pythonhist
12 12
13# Allow python (blacklisted by disable-interpreters.inc) 13# Allow python (blacklisted by disable-interpreters.inc)
14include allow-python2.inc 14include allow-python2.inc
diff --git a/etc/profile-m-z/xfburn.profile b/etc/profile-m-z/xfburn.profile
index cd9561e74..297ff6164 100644
--- a/etc/profile-m-z/xfburn.profile
+++ b/etc/profile-m-z/xfburn.profile
@@ -6,7 +6,7 @@ include xfburn.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/xfburn 9nodeny ${HOME}/.config/xfburn
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
diff --git a/etc/profile-m-z/xfce4-dict.profile b/etc/profile-m-z/xfce4-dict.profile
index ecd321c7e..8ecd84116 100644
--- a/etc/profile-m-z/xfce4-dict.profile
+++ b/etc/profile-m-z/xfce4-dict.profile
@@ -6,7 +6,7 @@ include xfce4-dict.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/xfce4-dict 9nodeny ${HOME}/.config/xfce4-dict
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
diff --git a/etc/profile-m-z/xfce4-mixer.profile b/etc/profile-m-z/xfce4-mixer.profile
index bb38dbebd..8a6f9e921 100644
--- a/etc/profile-m-z/xfce4-mixer.profile
+++ b/etc/profile-m-z/xfce4-mixer.profile
@@ -6,7 +6,7 @@ include xfce4-mixer.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/xfce4/xfconf/xfce-perchannel-xml/xfce4-mixer.xml 9nodeny ${HOME}/.config/xfce4/xfconf/xfce-perchannel-xml/xfce4-mixer.xml
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -18,10 +18,10 @@ include disable-shell.inc
18include disable-xdg.inc 18include disable-xdg.inc
19 19
20mkfile ${HOME}/.config/xfce4/xfconf/xfce-perchannel-xml/xfce4-mixer.xml 20mkfile ${HOME}/.config/xfce4/xfconf/xfce-perchannel-xml/xfce4-mixer.xml
21whitelist ${HOME}/.config/xfce4/xfconf/xfce-perchannel-xml/xfce4-mixer.xml 21allow ${HOME}/.config/xfce4/xfconf/xfce-perchannel-xml/xfce4-mixer.xml
22whitelist /usr/share/gstreamer-* 22allow /usr/share/gstreamer-*
23whitelist /usr/share/xfce4 23allow /usr/share/xfce4
24whitelist /usr/share/xfce4-mixer 24allow /usr/share/xfce4-mixer
25include whitelist-common.inc 25include whitelist-common.inc
26include whitelist-usr-share-common.inc 26include whitelist-usr-share-common.inc
27include whitelist-var-common.inc 27include whitelist-var-common.inc
diff --git a/etc/profile-m-z/xfce4-notes.profile b/etc/profile-m-z/xfce4-notes.profile
index ebfb4333c..fe88f9b27 100644
--- a/etc/profile-m-z/xfce4-notes.profile
+++ b/etc/profile-m-z/xfce4-notes.profile
@@ -6,9 +6,9 @@ include xfce4-notes.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/xfce4/xfce4-notes.gtkrc 9nodeny ${HOME}/.config/xfce4/xfce4-notes.gtkrc
10noblacklist ${HOME}/.config/xfce4/xfce4-notes.rc 10nodeny ${HOME}/.config/xfce4/xfce4-notes.rc
11noblacklist ${HOME}/.local/share/notes 11nodeny ${HOME}/.local/share/notes
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
diff --git a/etc/profile-m-z/xfce4-screenshooter.profile b/etc/profile-m-z/xfce4-screenshooter.profile
index b1e5bafbf..baf222354 100644
--- a/etc/profile-m-z/xfce4-screenshooter.profile
+++ b/etc/profile-m-z/xfce4-screenshooter.profile
@@ -6,7 +6,7 @@ include xfce4-screenshooter.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${PICTURES} 9nodeny ${PICTURES}
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -17,7 +17,7 @@ include disable-programs.inc
17include disable-shell.inc 17include disable-shell.inc
18include disable-xdg.inc 18include disable-xdg.inc
19 19
20whitelist /usr/share/xfce4 20allow /usr/share/xfce4
21include whitelist-runuser-common.inc 21include whitelist-runuser-common.inc
22include whitelist-usr-share-common.inc 22include whitelist-usr-share-common.inc
23include whitelist-var-common.inc 23include whitelist-var-common.inc
diff --git a/etc/profile-m-z/xiphos.profile b/etc/profile-m-z/xiphos.profile
index 81d98db7a..5c11cbd66 100644
--- a/etc/profile-m-z/xiphos.profile
+++ b/etc/profile-m-z/xiphos.profile
@@ -6,10 +6,10 @@ include xiphos.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.sword 9nodeny ${HOME}/.sword
10noblacklist ${HOME}/.xiphos 10nodeny ${HOME}/.xiphos
11 11
12blacklist ${HOME}/.bashrc 12deny ${HOME}/.bashrc
13 13
14include disable-common.inc 14include disable-common.inc
15include disable-devel.inc 15include disable-devel.inc
@@ -21,8 +21,8 @@ include disable-shell.inc
21 21
22mkdir ${HOME}/.sword 22mkdir ${HOME}/.sword
23mkdir ${HOME}/.xiphos 23mkdir ${HOME}/.xiphos
24whitelist ${HOME}/.sword 24allow ${HOME}/.sword
25whitelist ${HOME}/.xiphos 25allow ${HOME}/.xiphos
26include whitelist-common.inc 26include whitelist-common.inc
27include whitelist-var-common.inc 27include whitelist-var-common.inc
28 28
diff --git a/etc/profile-m-z/xlinks.profile b/etc/profile-m-z/xlinks.profile
index d5e25cfe7..da4801101 100644
--- a/etc/profile-m-z/xlinks.profile
+++ b/etc/profile-m-z/xlinks.profile
@@ -7,7 +7,7 @@ include xlinks.local
7# added by included profile 7# added by included profile
8#include globals.local 8#include globals.local
9 9
10noblacklist /tmp/.X11-unix 10nodeny /tmp/.X11-unix
11 11
12include whitelist-common.inc 12include whitelist-common.inc
13 13
diff --git a/etc/profile-m-z/xlinks2 b/etc/profile-m-z/xlinks2
index 1ae6a60ca..a7612cb2a 100644
--- a/etc/profile-m-z/xlinks2
+++ b/etc/profile-m-z/xlinks2
@@ -7,7 +7,7 @@ include xlinks2.local
7# added by included profile 7# added by included profile
8#include globals.local 8#include globals.local
9 9
10noblacklist /tmp/.X11-unix 10nodeny /tmp/.X11-unix
11 11
12include whitelist-common.inc 12include whitelist-common.inc
13 13
diff --git a/etc/profile-m-z/xmms.profile b/etc/profile-m-z/xmms.profile
index 25261d925..1ed35f29a 100644
--- a/etc/profile-m-z/xmms.profile
+++ b/etc/profile-m-z/xmms.profile
@@ -5,8 +5,8 @@ include xmms.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${HOME}/.xmms 8nodeny ${HOME}/.xmms
9noblacklist ${MUSIC} 9nodeny ${MUSIC}
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
diff --git a/etc/profile-m-z/xmr-stak.profile b/etc/profile-m-z/xmr-stak.profile
index e7020f36b..c97c12f56 100644
--- a/etc/profile-m-z/xmr-stak.profile
+++ b/etc/profile-m-z/xmr-stak.profile
@@ -5,7 +5,7 @@ include xmr-stak.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${HOME}/.xmr-stak 8nodeny ${HOME}/.xmr-stak
9 9
10include disable-common.inc 10include disable-common.inc
11include disable-devel.inc 11include disable-devel.inc
diff --git a/etc/profile-m-z/xonotic.profile b/etc/profile-m-z/xonotic.profile
index 53c9a0a08..94a09198c 100644
--- a/etc/profile-m-z/xonotic.profile
+++ b/etc/profile-m-z/xonotic.profile
@@ -6,7 +6,7 @@ include xonotic.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.xonotic 9nodeny ${HOME}/.xonotic
10 10
11include allow-bin-sh.inc 11include allow-bin-sh.inc
12include allow-opengl-game.inc 12include allow-opengl-game.inc
@@ -21,8 +21,8 @@ include disable-shell.inc
21include disable-xdg.inc 21include disable-xdg.inc
22 22
23mkdir ${HOME}/.xonotic 23mkdir ${HOME}/.xonotic
24whitelist ${HOME}/.xonotic 24allow ${HOME}/.xonotic
25whitelist /usr/share/xonotic 25allow /usr/share/xonotic
26include whitelist-common.inc 26include whitelist-common.inc
27include whitelist-runuser-common.inc 27include whitelist-runuser-common.inc
28include whitelist-usr-share-common.inc 28include whitelist-usr-share-common.inc
diff --git a/etc/profile-m-z/xournal.profile b/etc/profile-m-z/xournal.profile
index c4f092d50..34a188a4e 100644
--- a/etc/profile-m-z/xournal.profile
+++ b/etc/profile-m-z/xournal.profile
@@ -6,7 +6,7 @@ include xournal.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${DOCUMENTS} 9nodeny ${DOCUMENTS}
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -17,8 +17,8 @@ include disable-programs.inc
17include disable-shell.inc 17include disable-shell.inc
18include disable-xdg.inc 18include disable-xdg.inc
19 19
20whitelist /usr/share/xournal 20allow /usr/share/xournal
21whitelist /usr/share/poppler 21allow /usr/share/poppler
22include whitelist-usr-share-common.inc 22include whitelist-usr-share-common.inc
23include whitelist-var-common.inc 23include whitelist-var-common.inc
24 24
diff --git a/etc/profile-m-z/xournalpp.profile b/etc/profile-m-z/xournalpp.profile
index 988b878b9..f82d2a5d3 100644
--- a/etc/profile-m-z/xournalpp.profile
+++ b/etc/profile-m-z/xournalpp.profile
@@ -7,13 +7,13 @@ include xournalpp.local
7# added by included profile 7# added by included profile
8#include globals.local 8#include globals.local
9 9
10noblacklist ${HOME}/.xournalpp 10nodeny ${HOME}/.xournalpp
11 11
12include allow-lua.inc 12include allow-lua.inc
13 13
14whitelist /usr/share/texlive 14allow /usr/share/texlive
15whitelist /usr/share/xournalpp 15allow /usr/share/xournalpp
16whitelist /var/lib/texmf 16allow /var/lib/texmf
17include whitelist-runuser-common.inc 17include whitelist-runuser-common.inc
18 18
19#mkdir ${HOME}/.xournalpp 19#mkdir ${HOME}/.xournalpp
diff --git a/etc/profile-m-z/xpdf.profile b/etc/profile-m-z/xpdf.profile
index 1447ec9a7..9da63b52a 100644
--- a/etc/profile-m-z/xpdf.profile
+++ b/etc/profile-m-z/xpdf.profile
@@ -6,8 +6,8 @@ include xpdf.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.xpdfrc 9nodeny ${HOME}/.xpdfrc
10noblacklist ${DOCUMENTS} 10nodeny ${DOCUMENTS}
11 11
12include disable-common.inc 12include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
diff --git a/etc/profile-m-z/xplayer.profile b/etc/profile-m-z/xplayer.profile
index c3bb3292c..4af4586e3 100644
--- a/etc/profile-m-z/xplayer.profile
+++ b/etc/profile-m-z/xplayer.profile
@@ -5,8 +5,8 @@ include xplayer.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${HOME}/.config/xplayer 8nodeny ${HOME}/.config/xplayer
9noblacklist ${HOME}/.local/share/xplayer 9nodeny ${HOME}/.local/share/xplayer
10 10
11# Allow python (blacklisted by disable-interpreters.inc) 11# Allow python (blacklisted by disable-interpreters.inc)
12include allow-python2.inc 12include allow-python2.inc
@@ -22,8 +22,8 @@ include disable-programs.inc
22read-only ${DESKTOP} 22read-only ${DESKTOP}
23mkdir ${HOME}/.config/xplayer 23mkdir ${HOME}/.config/xplayer
24mkdir ${HOME}/.local/share/xplayer 24mkdir ${HOME}/.local/share/xplayer
25whitelist ${HOME}/.config/xplayer 25allow ${HOME}/.config/xplayer
26whitelist ${HOME}/.local/share/xplayer 26allow ${HOME}/.local/share/xplayer
27include whitelist-common.inc 27include whitelist-common.inc
28include whitelist-player-common.inc 28include whitelist-player-common.inc
29include whitelist-var-common.inc 29include whitelist-var-common.inc
diff --git a/etc/profile-m-z/xpra.profile b/etc/profile-m-z/xpra.profile
index 6e409e1aa..28fbc94dd 100644
--- a/etc/profile-m-z/xpra.profile
+++ b/etc/profile-m-z/xpra.profile
@@ -25,7 +25,7 @@ include disable-interpreters.inc
25include disable-passwdmgr.inc 25include disable-passwdmgr.inc
26include disable-programs.inc 26include disable-programs.inc
27 27
28whitelist /var/lib/xkb 28allow /var/lib/xkb
29# whitelisting home directory, or including whitelist-common.inc 29# whitelisting home directory, or including whitelist-common.inc
30# will crash xpra on some platforms 30# will crash xpra on some platforms
31 31
diff --git a/etc/profile-m-z/xreader.profile b/etc/profile-m-z/xreader.profile
index 3ab35edfc..440f26af2 100644
--- a/etc/profile-m-z/xreader.profile
+++ b/etc/profile-m-z/xreader.profile
@@ -6,9 +6,9 @@ include xreader.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.cache/xreader 9nodeny ${HOME}/.cache/xreader
10noblacklist ${HOME}/.config/xreader 10nodeny ${HOME}/.config/xreader
11noblacklist ${DOCUMENTS} 11nodeny ${DOCUMENTS}
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
diff --git a/etc/profile-m-z/xviewer.profile b/etc/profile-m-z/xviewer.profile
index 4d454f81c..671e0cf5b 100644
--- a/etc/profile-m-z/xviewer.profile
+++ b/etc/profile-m-z/xviewer.profile
@@ -5,10 +5,10 @@ include xviewer.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8noblacklist ${HOME}/.Steam 8nodeny ${HOME}/.Steam
9noblacklist ${HOME}/.config/xviewer 9nodeny ${HOME}/.config/xviewer
10noblacklist ${HOME}/.local/share/Trash 10nodeny ${HOME}/.local/share/Trash
11noblacklist ${HOME}/.steam 11nodeny ${HOME}/.steam
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
diff --git a/etc/profile-m-z/yandex-browser.profile b/etc/profile-m-z/yandex-browser.profile
index 81cd021f7..27d0eb411 100644
--- a/etc/profile-m-z/yandex-browser.profile
+++ b/etc/profile-m-z/yandex-browser.profile
@@ -10,19 +10,19 @@ ignore whitelist /usr/share/chromium
10ignore include whitelist-runuser-common.inc 10ignore include whitelist-runuser-common.inc
11ignore include whitelist-usr-share-common.inc 11ignore include whitelist-usr-share-common.inc
12 12
13noblacklist ${HOME}/.cache/yandex-browser 13nodeny ${HOME}/.cache/yandex-browser
14noblacklist ${HOME}/.cache/yandex-browser-beta 14nodeny ${HOME}/.cache/yandex-browser-beta
15noblacklist ${HOME}/.config/yandex-browser 15nodeny ${HOME}/.config/yandex-browser
16noblacklist ${HOME}/.config/yandex-browser-beta 16nodeny ${HOME}/.config/yandex-browser-beta
17 17
18mkdir ${HOME}/.cache/yandex-browser 18mkdir ${HOME}/.cache/yandex-browser
19mkdir ${HOME}/.cache/yandex-browser-beta 19mkdir ${HOME}/.cache/yandex-browser-beta
20mkdir ${HOME}/.config/yandex-browser 20mkdir ${HOME}/.config/yandex-browser
21mkdir ${HOME}/.config/yandex-browser-beta 21mkdir ${HOME}/.config/yandex-browser-beta
22whitelist ${HOME}/.cache/yandex-browser 22allow ${HOME}/.cache/yandex-browser
23whitelist ${HOME}/.cache/yandex-browser-beta 23allow ${HOME}/.cache/yandex-browser-beta
24whitelist ${HOME}/.config/yandex-browser 24allow ${HOME}/.config/yandex-browser
25whitelist ${HOME}/.config/yandex-browser-beta 25allow ${HOME}/.config/yandex-browser-beta
26 26
27# Redirect 27# Redirect
28include chromium-common.profile 28include chromium-common.profile
diff --git a/etc/profile-m-z/yelp.profile b/etc/profile-m-z/yelp.profile
index dee154409..b288993f2 100644
--- a/etc/profile-m-z/yelp.profile
+++ b/etc/profile-m-z/yelp.profile
@@ -6,7 +6,7 @@ include yelp.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/yelp 9nodeny ${HOME}/.config/yelp
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc 12include disable-devel.inc
@@ -18,15 +18,15 @@ include disable-shell.inc
18include disable-xdg.inc 18include disable-xdg.inc
19 19
20mkdir ${HOME}/.config/yelp 20mkdir ${HOME}/.config/yelp
21whitelist ${HOME}/.config/yelp 21allow ${HOME}/.config/yelp
22whitelist /usr/libexec/webkit2gtk-4.0 22allow /usr/libexec/webkit2gtk-4.0
23whitelist /usr/share/doc 23allow /usr/share/doc
24whitelist /usr/share/groff 24allow /usr/share/groff
25whitelist /usr/share/help 25allow /usr/share/help
26whitelist /usr/share/man 26allow /usr/share/man
27whitelist /usr/share/yelp 27allow /usr/share/yelp
28whitelist /usr/share/yelp-tools 28allow /usr/share/yelp-tools
29whitelist /usr/share/yelp-xsl 29allow /usr/share/yelp-xsl
30include whitelist-common.inc 30include whitelist-common.inc
31include whitelist-runuser-common.inc 31include whitelist-runuser-common.inc
32include whitelist-usr-share-common.inc 32include whitelist-usr-share-common.inc
diff --git a/etc/profile-m-z/youtube-dl-gui.profile b/etc/profile-m-z/youtube-dl-gui.profile
index b52271a2c..26ea3acaa 100644
--- a/etc/profile-m-z/youtube-dl-gui.profile
+++ b/etc/profile-m-z/youtube-dl-gui.profile
@@ -8,7 +8,7 @@ include globals.local
8include allow-python2.inc 8include allow-python2.inc
9include allow-python3.inc 9include allow-python3.inc
10 10
11noblacklist ${HOME}/.config/youtube-dlg 11nodeny ${HOME}/.config/youtube-dlg
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
@@ -20,8 +20,8 @@ include disable-shell.inc
20include disable-xdg.inc 20include disable-xdg.inc
21 21
22mkdir ${HOME}/.config/youtube-dlg 22mkdir ${HOME}/.config/youtube-dlg
23whitelist ${HOME}/.config/youtube-dlg 23allow ${HOME}/.config/youtube-dlg
24whitelist ${DOWNLOADS} 24allow ${DOWNLOADS}
25include whitelist-common.inc 25include whitelist-common.inc
26include whitelist-runuser-common.inc 26include whitelist-runuser-common.inc
27include whitelist-usr-share-common.inc 27include whitelist-usr-share-common.inc
diff --git a/etc/profile-m-z/youtube-dl.profile b/etc/profile-m-z/youtube-dl.profile
index 24c4d6db3..37f87d0b5 100644
--- a/etc/profile-m-z/youtube-dl.profile
+++ b/etc/profile-m-z/youtube-dl.profile
@@ -10,18 +10,18 @@ include globals.local
10# breaks when installed under ${HOME} via `pip install --user` (see #2833) 10# breaks when installed under ${HOME} via `pip install --user` (see #2833)
11ignore noexec ${HOME} 11ignore noexec ${HOME}
12 12
13noblacklist ${HOME}/.cache/youtube-dl 13nodeny ${HOME}/.cache/youtube-dl
14noblacklist ${HOME}/.config/youtube-dl 14nodeny ${HOME}/.config/youtube-dl
15noblacklist ${HOME}/.netrc 15nodeny ${HOME}/.netrc
16noblacklist ${MUSIC} 16nodeny ${MUSIC}
17noblacklist ${VIDEOS} 17nodeny ${VIDEOS}
18 18
19# Allow python (blacklisted by disable-interpreters.inc) 19# Allow python (blacklisted by disable-interpreters.inc)
20include allow-python2.inc 20include allow-python2.inc
21include allow-python3.inc 21include allow-python3.inc
22 22
23blacklist /tmp/.X11-unix 23deny /tmp/.X11-unix
24blacklist ${RUNUSER} 24deny ${RUNUSER}
25 25
26include disable-common.inc 26include disable-common.inc
27include disable-devel.inc 27include disable-devel.inc
diff --git a/etc/profile-m-z/youtube-viewer.profile b/etc/profile-m-z/youtube-viewer.profile
index b54dd37ad..84b8bbc6a 100644
--- a/etc/profile-m-z/youtube-viewer.profile
+++ b/etc/profile-m-z/youtube-viewer.profile
@@ -7,13 +7,13 @@ include youtube-viewer.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10noblacklist ${HOME}/.cache/youtube-viewer 10nodeny ${HOME}/.cache/youtube-viewer
11noblacklist ${HOME}/.config/youtube-viewer 11nodeny ${HOME}/.config/youtube-viewer
12 12
13mkdir ${HOME}/.cache/youtube-viewer 13mkdir ${HOME}/.cache/youtube-viewer
14mkdir ${HOME}/.config/youtube-viewer 14mkdir ${HOME}/.config/youtube-viewer
15whitelist ${HOME}/.cache/youtube-viewer 15allow ${HOME}/.cache/youtube-viewer
16whitelist ${HOME}/.config/youtube-viewer 16allow ${HOME}/.config/youtube-viewer
17 17
18private-bin gtk-youtube-viewer,gtk2-youtube-viewer,gtk3-youtube-viewer,youtube-viewer 18private-bin gtk-youtube-viewer,gtk2-youtube-viewer,gtk3-youtube-viewer,youtube-viewer
19 19
diff --git a/etc/profile-m-z/youtube-viewers-common.profile b/etc/profile-m-z/youtube-viewers-common.profile
index 25a073d4a..f531f815e 100644
--- a/etc/profile-m-z/youtube-viewers-common.profile
+++ b/etc/profile-m-z/youtube-viewers-common.profile
@@ -7,7 +7,7 @@ include youtube-viewers-common.local
7# added by caller profile 7# added by caller profile
8#include globals.local 8#include globals.local
9 9
10noblacklist ${HOME}/.cache/youtube-dl 10nodeny ${HOME}/.cache/youtube-dl
11 11
12# Allow lua (blacklisted by disable-interpreters.inc) 12# Allow lua (blacklisted by disable-interpreters.inc)
13include allow-lua.inc 13include allow-lua.inc
@@ -27,8 +27,8 @@ include disable-passwdmgr.inc
27include disable-programs.inc 27include disable-programs.inc
28include disable-xdg.inc 28include disable-xdg.inc
29 29
30whitelist ${DOWNLOADS} 30allow ${DOWNLOADS}
31whitelist ${HOME}/.cache/youtube-dl/youtube-sigfuncs 31allow ${HOME}/.cache/youtube-dl/youtube-sigfuncs
32include whitelist-common.inc 32include whitelist-common.inc
33include whitelist-runuser-common.inc 33include whitelist-runuser-common.inc
34include whitelist-usr-share-common.inc 34include whitelist-usr-share-common.inc
diff --git a/etc/profile-m-z/youtube.profile b/etc/profile-m-z/youtube.profile
index ad7ceaee4..b015fb013 100644
--- a/etc/profile-m-z/youtube.profile
+++ b/etc/profile-m-z/youtube.profile
@@ -9,12 +9,12 @@ include globals.local
9# Disabled until someone reported positive feedback 9# Disabled until someone reported positive feedback
10ignore nou2f 10ignore nou2f
11 11
12noblacklist ${HOME}/.config/Youtube 12nodeny ${HOME}/.config/Youtube
13 13
14include disable-shell.inc 14include disable-shell.inc
15 15
16mkdir ${HOME}/.config/Youtube 16mkdir ${HOME}/.config/Youtube
17whitelist ${HOME}/.config/Youtube 17allow ${HOME}/.config/Youtube
18 18
19private-bin youtube 19private-bin youtube
20private-etc alsa,alternatives,asound.conf,ati,bumblebee,ca-certificates,crypto-policies,drirc,fonts,gtk-2.0,gtk-3.0,host.conf,hostname,hosts,mime.types,nsswitch.conf,nvidia,pki,pulse,resolv.conf,selinux,ssl,X11,xdg 20private-etc alsa,alternatives,asound.conf,ati,bumblebee,ca-certificates,crypto-policies,drirc,fonts,gtk-2.0,gtk-3.0,host.conf,hostname,hosts,mime.types,nsswitch.conf,nvidia,pki,pulse,resolv.conf,selinux,ssl,X11,xdg
diff --git a/etc/profile-m-z/youtubemusic-nativefier.profile b/etc/profile-m-z/youtubemusic-nativefier.profile
index 74b0e38b9..d594a3d0f 100644
--- a/etc/profile-m-z/youtubemusic-nativefier.profile
+++ b/etc/profile-m-z/youtubemusic-nativefier.profile
@@ -6,12 +6,12 @@ include youtube.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/youtubemusic-nativefier-040164 9nodeny ${HOME}/.config/youtubemusic-nativefier-040164
10 10
11include disable-shell.inc 11include disable-shell.inc
12 12
13mkdir ${HOME}/.config/youtubemusic-nativefier-040164 13mkdir ${HOME}/.config/youtubemusic-nativefier-040164
14whitelist ${HOME}/.config/youtubemusic-nativefier-040164 14allow ${HOME}/.config/youtubemusic-nativefier-040164
15 15
16private-bin youtubemusic-nativefier 16private-bin youtubemusic-nativefier
17private-etc alsa,alternatives,asound.conf,ati,bumblebee,ca-certificates,crypto-policies,drirc,fonts,gtk-2.0,gtk-3.0,host.conf,hostname,hosts,mime.types,nsswitch.conf,nvidia,pki,pulse,resolv.conf,selinux,ssl,X11,xdg 17private-etc alsa,alternatives,asound.conf,ati,bumblebee,ca-certificates,crypto-policies,drirc,fonts,gtk-2.0,gtk-3.0,host.conf,hostname,hosts,mime.types,nsswitch.conf,nvidia,pki,pulse,resolv.conf,selinux,ssl,X11,xdg
diff --git a/etc/profile-m-z/ytmdesktop.profile b/etc/profile-m-z/ytmdesktop.profile
index ab46fccc2..9987c953e 100644
--- a/etc/profile-m-z/ytmdesktop.profile
+++ b/etc/profile-m-z/ytmdesktop.profile
@@ -8,10 +8,10 @@ include globals.local
8 8
9ignore dbus-user none 9ignore dbus-user none
10 10
11noblacklist ${HOME}/.config/youtube-music-desktop-app 11nodeny ${HOME}/.config/youtube-music-desktop-app
12 12
13mkdir ${HOME}/.config/youtube-music-desktop-app 13mkdir ${HOME}/.config/youtube-music-desktop-app
14whitelist ${HOME}/.config/youtube-music-desktop-app 14allow ${HOME}/.config/youtube-music-desktop-app
15 15
16# private-bin env,ytmdesktop 16# private-bin env,ytmdesktop
17private-etc alsa,alternatives,asound.conf,ati,bumblebee,ca-certificates,crypto-policies,drirc,fonts,gtk-2.0,gtk-3.0,host.conf,hostname,hosts,mime.types,nsswitch.conf,nvidia,pki,pulse,resolv.conf,selinux,ssl,X11,xdg 17private-etc alsa,alternatives,asound.conf,ati,bumblebee,ca-certificates,crypto-policies,drirc,fonts,gtk-2.0,gtk-3.0,host.conf,hostname,hosts,mime.types,nsswitch.conf,nvidia,pki,pulse,resolv.conf,selinux,ssl,X11,xdg
diff --git a/etc/profile-m-z/zaproxy.profile b/etc/profile-m-z/zaproxy.profile
index 5a168feb6..2f18a8c45 100644
--- a/etc/profile-m-z/zaproxy.profile
+++ b/etc/profile-m-z/zaproxy.profile
@@ -6,7 +6,7 @@ include zaproxy.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.ZAP 9nodeny ${HOME}/.ZAP
10 10
11# Allow java (blacklisted by disable-devel.inc) 11# Allow java (blacklisted by disable-devel.inc)
12include allow-java.inc 12include allow-java.inc
@@ -20,8 +20,8 @@ include disable-programs.inc
20 20
21mkdir ${HOME}/.java 21mkdir ${HOME}/.java
22mkdir ${HOME}/.ZAP 22mkdir ${HOME}/.ZAP
23whitelist ${HOME}/.java 23allow ${HOME}/.java
24whitelist ${HOME}/.ZAP 24allow ${HOME}/.ZAP
25include whitelist-common.inc 25include whitelist-common.inc
26include whitelist-var-common.inc 26include whitelist-var-common.inc
27 27
diff --git a/etc/profile-m-z/zart.profile b/etc/profile-m-z/zart.profile
index 10f83aa30..32ff4f8ed 100644
--- a/etc/profile-m-z/zart.profile
+++ b/etc/profile-m-z/zart.profile
@@ -6,8 +6,8 @@ include zart.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${DOCUMENTS} 9nodeny ${DOCUMENTS}
10noblacklist ${PICTURES} 10nodeny ${PICTURES}
11 11
12include disable-common.inc 12include disable-common.inc
13include disable-devel.inc 13include disable-devel.inc
diff --git a/etc/profile-m-z/zathura.profile b/etc/profile-m-z/zathura.profile
index d0e68c980..4bc841f63 100644
--- a/etc/profile-m-z/zathura.profile
+++ b/etc/profile-m-z/zathura.profile
@@ -6,9 +6,9 @@ include zathura.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/zathura 9nodeny ${HOME}/.config/zathura
10noblacklist ${HOME}/.local/share/zathura 10nodeny ${HOME}/.local/share/zathura
11noblacklist ${DOCUMENTS} 11nodeny ${DOCUMENTS}
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
@@ -22,8 +22,8 @@ include disable-xdg.inc
22 22
23mkdir ${HOME}/.config/zathura 23mkdir ${HOME}/.config/zathura
24mkdir ${HOME}/.local/share/zathura 24mkdir ${HOME}/.local/share/zathura
25whitelist /usr/share/doc 25allow /usr/share/doc
26whitelist /usr/share/zathura 26allow /usr/share/zathura
27include whitelist-runuser-common.inc 27include whitelist-runuser-common.inc
28include whitelist-usr-share-common.inc 28include whitelist-usr-share-common.inc
29include whitelist-var-common.inc 29include whitelist-var-common.inc
diff --git a/etc/profile-m-z/zcat.profile b/etc/profile-m-z/zcat.profile
index 5de13ab90..904ea9f05 100644
--- a/etc/profile-m-z/zcat.profile
+++ b/etc/profile-m-z/zcat.profile
@@ -9,7 +9,7 @@ include zcat.local
9 9
10# Allow running kernel config check 10# Allow running kernel config check
11ignore include disable-shell.inc 11ignore include disable-shell.inc
12noblacklist /proc/config.gz 12nodeny /proc/config.gz
13 13
14# Redirect 14# Redirect
15include gzip.profile 15include gzip.profile
diff --git a/etc/profile-m-z/zeal.profile b/etc/profile-m-z/zeal.profile
index 2c6f6910f..458df2a46 100644
--- a/etc/profile-m-z/zeal.profile
+++ b/etc/profile-m-z/zeal.profile
@@ -6,9 +6,9 @@ include zeal.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/Zeal 9nodeny ${HOME}/.config/Zeal
10noblacklist ${HOME}/.cache/Zeal 10nodeny ${HOME}/.cache/Zeal
11noblacklist ${HOME}/.local/share/Zeal 11nodeny ${HOME}/.local/share/Zeal
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
@@ -23,9 +23,9 @@ mkdir ${HOME}/.cache/Zeal
23mkdir ${HOME}/.config/qt5ct 23mkdir ${HOME}/.config/qt5ct
24mkdir ${HOME}/.config/Zeal 24mkdir ${HOME}/.config/Zeal
25mkdir ${HOME}/.local/share/Zeal 25mkdir ${HOME}/.local/share/Zeal
26whitelist ${HOME}/.cache/Zeal 26allow ${HOME}/.cache/Zeal
27whitelist ${HOME}/.config/Zeal 27allow ${HOME}/.config/Zeal
28whitelist ${HOME}/.local/share/Zeal 28allow ${HOME}/.local/share/Zeal
29include whitelist-common.inc 29include whitelist-common.inc
30include whitelist-var-common.inc 30include whitelist-var-common.inc
31 31
diff --git a/etc/profile-m-z/zgrep.profile b/etc/profile-m-z/zgrep.profile
index f63dc871f..e2dfbd105 100644
--- a/etc/profile-m-z/zgrep.profile
+++ b/etc/profile-m-z/zgrep.profile
@@ -9,7 +9,7 @@ include zgrep.local
9 9
10# Allow running kernel config check 10# Allow running kernel config check
11ignore include disable-shell.inc 11ignore include disable-shell.inc
12noblacklist /proc/config.gz 12nodeny /proc/config.gz
13 13
14# Redirect 14# Redirect
15include gzip.profile 15include gzip.profile
diff --git a/etc/profile-m-z/zoom.profile b/etc/profile-m-z/zoom.profile
index ac615d861..6b0417b56 100644
--- a/etc/profile-m-z/zoom.profile
+++ b/etc/profile-m-z/zoom.profile
@@ -16,17 +16,17 @@ ignore dbus-system none
16# If you use such a system, add 'ignore nogroups' to your zoom.local. 16# If you use such a system, add 'ignore nogroups' to your zoom.local.
17#ignore nogroups 17#ignore nogroups
18 18
19noblacklist ${HOME}/.config/zoomus.conf 19nodeny ${HOME}/.config/zoomus.conf
20noblacklist ${HOME}/.zoom 20nodeny ${HOME}/.zoom
21 21
22nowhitelist ${DOWNLOADS} 22noallow ${DOWNLOADS}
23 23
24mkdir ${HOME}/.cache/zoom 24mkdir ${HOME}/.cache/zoom
25mkfile ${HOME}/.config/zoomus.conf 25mkfile ${HOME}/.config/zoomus.conf
26mkdir ${HOME}/.zoom 26mkdir ${HOME}/.zoom
27whitelist ${HOME}/.cache/zoom 27allow ${HOME}/.cache/zoom
28whitelist ${HOME}/.config/zoomus.conf 28allow ${HOME}/.config/zoomus.conf
29whitelist ${HOME}/.zoom 29allow ${HOME}/.zoom
30 30
31# Disable for now, see https://github.com/netblue30/firejail/issues/3726 31# Disable for now, see https://github.com/netblue30/firejail/issues/3726
32#private-etc alternatives,ca-certificates,crypto-policies,fonts,group,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,machine-id,nsswitch.conf,pki,resolv.conf,ssl 32#private-etc alternatives,ca-certificates,crypto-policies,fonts,group,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,machine-id,nsswitch.conf,pki,resolv.conf,ssl
diff --git a/etc/profile-m-z/zulip.profile b/etc/profile-m-z/zulip.profile
index 093da5212..cdbbdccf1 100644
--- a/etc/profile-m-z/zulip.profile
+++ b/etc/profile-m-z/zulip.profile
@@ -8,7 +8,7 @@ include globals.local
8 8
9ignore noexec /tmp 9ignore noexec /tmp
10 10
11noblacklist ${HOME}/.config/Zulip 11nodeny ${HOME}/.config/Zulip
12 12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
@@ -20,8 +20,8 @@ include disable-shell.inc
20include disable-xdg.inc 20include disable-xdg.inc
21 21
22mkdir ${HOME}/.config/Zulip 22mkdir ${HOME}/.config/Zulip
23whitelist ${HOME}/.config/Zulip 23allow ${HOME}/.config/Zulip
24whitelist ${DOWNLOADS} 24allow ${DOWNLOADS}
25include whitelist-common.inc 25include whitelist-common.inc
26include whitelist-var-common.inc 26include whitelist-var-common.inc
27 27
diff --git a/src/firejail/profile.c b/src/firejail/profile.c
index 29bb5fbac..b7c7185a6 100644
--- a/src/firejail/profile.c
+++ b/src/firejail/profile.c
@@ -1751,6 +1751,13 @@ void profile_read(const char *fname) {
1751 free(ptr); 1751 free(ptr);
1752 ptr = tmp; 1752 ptr = tmp;
1753 } 1753 }
1754 else if (strncmp(ptr, "deny-nolog ", 11) == 0) {
1755 char *tmp;
1756 if (asprintf(&tmp, "blacklist-nolog %s", ptr + 11) == -1)
1757 errExit("asprintf");
1758 free(ptr);
1759 ptr = tmp;
1760 }
1754 // translate noallow/nodeny to nowhitelist/noblacklist 1761 // translate noallow/nodeny to nowhitelist/noblacklist
1755 else if (strncmp(ptr, "noallow ", 8) == 0) { 1762 else if (strncmp(ptr, "noallow ", 8) == 0) {
1756 char *tmp; 1763 char *tmp;
diff --git a/src/tools/profcleaner.c b/src/tools/profcleaner.c
new file mode 100644
index 000000000..93bb3f73d
--- /dev/null
+++ b/src/tools/profcleaner.c
@@ -0,0 +1,75 @@
1/*
2 * Copyright (C) 2014-2021 Firejail Authors
3 *
4 * This file is part of firejail project
5 *
6 * This program is free software; you can redistribute it and/or modify
7 * it under the terms of the GNU General Public License as published by
8 * the Free Software Foundation; either version 2 of the License, or
9 * (at your option) any later version.
10 *
11 * This program is distributed in the hope that it will be useful,
12 * but WITHOUT ANY WARRANTY; without even the implied warranty of
13 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
14 * GNU General Public License for more details.
15 *
16 * You should have received a copy of the GNU General Public License along
17 * with this program; if not, write to the Free Software Foundation, Inc.,
18 * 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
19*/
20
21//*************************************************************
22// Small utility program to convert profiles from blacklist/whitelist to deny/allow
23// Compile:
24// gcc -o profcleaner profcleaner.c
25// Usage:
26// profcleaner *.profile
27//*************************************************************
28
29#include <stdio.h>
30#include <stdlib.h>
31#include <string.h>
32#include <unistd.h>
33#define MAXBUF 4096
34
35int main(int argc, char **argv) {
36 printf("Usage: profcleaner files\n");
37 int i;
38
39 for (i = 1; i < argc; i++) {
40 FILE *fp = fopen(argv[i], "r");
41 if (!fp) {
42 fprintf(stderr, "Error: cannot open %s\n", argv[i]);
43 return 1;
44 }
45
46 FILE *fpout = fopen("profcleaner-tmp", "w");
47 if (!fpout) {
48 fprintf(stderr, "Error: cannot open output file\n");
49 return 1;
50 }
51
52 char buf[MAXBUF];
53 while (fgets(buf, MAXBUF, fp)) {
54 if (strncmp(buf, "blacklist-nolog", 15) == 0)
55 fprintf(fpout, "deny-nolog %s", buf + 15);
56 else if (strncmp(buf, "blacklist", 9) == 0)
57 fprintf(fpout, "deny %s", buf + 9);
58 else if (strncmp(buf, "noblacklist", 11) == 0)
59 fprintf(fpout, "nodeny %s", buf + 11);
60 else if (strncmp(buf, "whitelist", 9) == 0)
61 fprintf(fpout, "allow %s", buf + 9);
62 else if (strncmp(buf, "nowhitelist", 11) == 0)
63 fprintf(fpout, "noallow %s", buf + 11);
64 else
65 fprintf(fpout, "%s", buf);
66 }
67
68 fclose(fp);
69 fclose(fpout);
70 unlink(argv[i]);
71 rename("profcleaner-tmp", argv[i]);
72 }
73
74 return 0;
75} \ No newline at end of file