aboutsummaryrefslogtreecommitdiffstats
path: root/etc/disable-common.inc
diff options
context:
space:
mode:
authorLibravatar smitsohu <smitsohu@gmail.com>2018-02-06 21:38:10 +0100
committerLibravatar smitsohu <smitsohu@gmail.com>2018-02-06 21:38:10 +0100
commit22d7d86c0f9fa2b64ef8f10cfa458f7eeaafe64a (patch)
treeaea67c89991c399255906357db6aced50e36c74c /etc/disable-common.inc
parentenable private-etc for gwenview (diff)
downloadfirejail-22d7d86c0f9fa2b64ef8f10cfa458f7eeaafe64a.tar.gz
firejail-22d7d86c0f9fa2b64ef8f10cfa458f7eeaafe64a.tar.zst
firejail-22d7d86c0f9fa2b64ef8f10cfa458f7eeaafe64a.zip
further harden KDE
and whitelist some kio settings, because we don't know if slave processes will run inside or outside the sandbox. also prevents weird bugs that depend on sequence in which applications were started.
Diffstat (limited to 'etc/disable-common.inc')
-rw-r--r--etc/disable-common.inc4
1 files changed, 4 insertions, 0 deletions
diff --git a/etc/disable-common.inc b/etc/disable-common.inc
index cd79f43ab..ec700e24e 100644
--- a/etc/disable-common.inc
+++ b/etc/disable-common.inc
@@ -80,11 +80,15 @@ blacklist ${HOME}/.local/share/plasma
80blacklist ${HOME}/.local/share/solid 80blacklist ${HOME}/.local/share/solid
81read-only ${HOME}/.cache/ksycoca5_* 81read-only ${HOME}/.cache/ksycoca5_*
82read-only ${HOME}/.config/kdeglobals 82read-only ${HOME}/.config/kdeglobals
83read-only ${HOME}/.config/kio_httprc
84read-only ${HOME}/.config/kiorc
83read-only ${HOME}/.config/kioslaverc 85read-only ${HOME}/.config/kioslaverc
84read-only ${HOME}/.kde/share/config/kdeglobals 86read-only ${HOME}/.kde/share/config/kdeglobals
87read-only ${HOME}/.kde/share/config/kio_httprc
85read-only ${HOME}/.kde/share/config/kioslaverc 88read-only ${HOME}/.kde/share/config/kioslaverc
86read-only ${HOME}/.kde/share/kde4/services 89read-only ${HOME}/.kde/share/kde4/services
87read-only ${HOME}/.kde4/share/config/kdeglobals 90read-only ${HOME}/.kde4/share/config/kdeglobals
91read-only ${HOME}/.kde4/share/config/kio_httprc
88read-only ${HOME}/.kde4/share/config/kioslaverc 92read-only ${HOME}/.kde4/share/config/kioslaverc
89read-only ${HOME}/.kde4/share/kde4/services 93read-only ${HOME}/.kde4/share/kde4/services
90read-only ${HOME}/.local/share/kservices5 94read-only ${HOME}/.local/share/kservices5