aboutsummaryrefslogtreecommitdiffstats
path: root/etc/disable-common.inc
diff options
context:
space:
mode:
authorLibravatar SYN-cook <syncookongit@gmail.com>2017-03-31 16:24:38 +0200
committerLibravatar Fred Barclay <Fred-Barclay@users.noreply.github.com>2017-03-31 14:24:38 +0000
commitba85fa81088a0b468f3fb98d96b535f8d07989c8 (patch)
treebef5910fdcbc1b393079b61cc11782f50f3a3017 /etc/disable-common.inc
parentrestrict more KDE files (#1181) (diff)
downloadfirejail-ba85fa81088a0b468f3fb98d96b535f8d07989c8.tar.gz
firejail-ba85fa81088a0b468f3fb98d96b535f8d07989c8.tar.zst
firejail-ba85fa81088a0b468f3fb98d96b535f8d07989c8.zip
tidy up (#1182)
* minor reorganization * tidy up * tidy up * tidy up * tidy up * tidy up * tidy up
Diffstat (limited to 'etc/disable-common.inc')
-rw-r--r--etc/disable-common.inc11
1 files changed, 7 insertions, 4 deletions
diff --git a/etc/disable-common.inc b/etc/disable-common.inc
index 0ada3314f..451203865 100644
--- a/etc/disable-common.inc
+++ b/etc/disable-common.inc
@@ -6,11 +6,8 @@ include /etc/firejail/disable-common.local
6blacklist-nolog ${HOME}/.history 6blacklist-nolog ${HOME}/.history
7blacklist-nolog ${HOME}/.*_history 7blacklist-nolog ${HOME}/.*_history
8blacklist-nolog ${HOME}/.bash_history 8blacklist-nolog ${HOME}/.bash_history
9blacklist ${HOME}/.local/share/systemd
10blacklist ${HOME}/.config/systemd
11blacklist-nolog ${HOME}/.adobe 9blacklist-nolog ${HOME}/.adobe
12blacklist-nolog ${HOME}/.macromedia 10blacklist-nolog ${HOME}/.macromedia
13read-only ${HOME}/.local/share/applications
14 11
15# X11 session autostart 12# X11 session autostart
16blacklist ${HOME}/.xinitrc 13blacklist ${HOME}/.xinitrc
@@ -74,6 +71,10 @@ blacklist ${HOME}/.local/share/kservices5
74blacklist ${HOME}/.local/share/plasma 71blacklist ${HOME}/.local/share/plasma
75blacklist ${HOME}/.local/share/solid 72blacklist ${HOME}/.local/share/solid
76 73
74# systemd
75blacklist ${HOME}/.local/share/systemd
76blacklist ${HOME}/.config/systemd
77
77# VirtualBox 78# VirtualBox
78blacklist ${HOME}/.VirtualBox 79blacklist ${HOME}/.VirtualBox
79blacklist ${HOME}/VirtualBox VMs 80blacklist ${HOME}/VirtualBox VMs
@@ -177,9 +178,11 @@ read-only ${HOME}/.luarocks
177read-only ${HOME}/.npm-packages 178read-only ${HOME}/.npm-packages
178 179
179# Make the contents of ~/.local read-only, 180# Make the contents of ~/.local read-only,
180# except the commonly-used ~/.local/share 181# except the commonly-used ~/.local/share,
182# but including ~/.local/share/applications
181read-only ${HOME}/.local 183read-only ${HOME}/.local
182read-write ${HOME}/.local/share 184read-write ${HOME}/.local/share
185read-only ${HOME}/.local/share/applications
183 186
184# top secret 187# top secret
185blacklist ${HOME}/.ecryptfs 188blacklist ${HOME}/.ecryptfs