aboutsummaryrefslogtreecommitdiffstats
path: root/etc/inc/disable-common.inc
diff options
context:
space:
mode:
authorLibravatar rusty-snake <41237666+rusty-snake@users.noreply.github.com>2020-05-27 12:07:09 +0200
committerLibravatar rusty-snake <41237666+rusty-snake@users.noreply.github.com>2020-05-27 12:07:09 +0200
commit28c099bdc32710fc40e16aa53549a53222eef931 (patch)
tree86b4216a4b34d6099381d871c8a70b1e1b6808e5 /etc/inc/disable-common.inc
parentUpdate dino-im.profile (#3433) (diff)
downloadfirejail-28c099bdc32710fc40e16aa53549a53222eef931.tar.gz
firejail-28c099bdc32710fc40e16aa53549a53222eef931.tar.zst
firejail-28c099bdc32710fc40e16aa53549a53222eef931.zip
${RUNUSER} blacklisting + typo
Diffstat (limited to 'etc/inc/disable-common.inc')
-rw-r--r--etc/inc/disable-common.inc20
1 files changed, 20 insertions, 0 deletions
diff --git a/etc/inc/disable-common.inc b/etc/inc/disable-common.inc
index 8f1350a60..ce3b24584 100644
--- a/etc/inc/disable-common.inc
+++ b/etc/inc/disable-common.inc
@@ -144,12 +144,16 @@ blacklist ${RUNUSER}/kdesud_*
144blacklist ${HOME}/.local/share/gnome-shell 144blacklist ${HOME}/.local/share/gnome-shell
145# no direct modification of dconf database 145# no direct modification of dconf database
146read-only ${HOME}/.config/dconf 146read-only ${HOME}/.config/dconf
147blacklist ${RUNUSER}/gnome-session-leader-fifo
148blacklist ${RUNUSER}/gnome-shell
149blacklist ${RUNUSER}/gsconnect
147 150
148# systemd 151# systemd
149blacklist ${HOME}/.config/systemd 152blacklist ${HOME}/.config/systemd
150blacklist ${HOME}/.local/share/systemd 153blacklist ${HOME}/.local/share/systemd
151blacklist /var/lib/systemd 154blacklist /var/lib/systemd
152blacklist ${PATH}/systemd-run 155blacklist ${PATH}/systemd-run
156blacklist ${RUNUSER}/systemd
153# creates problems on Arch where /etc/resolv.conf is a symlink to /var/run/systemd/resolve/resolv.conf 157# creates problems on Arch where /etc/resolv.conf is a symlink to /var/run/systemd/resolve/resolv.conf
154#blacklist /var/run/systemd 158#blacklist /var/run/systemd
155 159
@@ -175,6 +179,13 @@ blacklist /var/cache/libvirt
175blacklist /var/lib/libvirt 179blacklist /var/lib/libvirt
176blacklist /var/log/libvirt 180blacklist /var/log/libvirt
177 181
182# OCI-Containers / Podman
183blacklist ${RUNUSER}/containers
184blacklist ${RUNUSER}/crun
185blacklist ${RUNUSER}/libpod
186blacklist ${RUNUSER}/runc
187blacklist ${RUNUSER}/toolbox
188
178# VeraCrypt 189# VeraCrypt
179blacklist ${HOME}/.VeraCrypt 190blacklist ${HOME}/.VeraCrypt
180blacklist ${PATH}/veracrypt 191blacklist ${PATH}/veracrypt
@@ -478,6 +489,9 @@ blacklist /var/lib/flatpak
478# most of the time bwrap is SUID binary 489# most of the time bwrap is SUID binary
479blacklist ${PATH}/bwrap 490blacklist ${PATH}/bwrap
480 491
492# snap
493blacklist ${RUNUSER}/snapd-session-agent.socket
494
481# mail directories used by mutt 495# mail directories used by mutt
482blacklist ${HOME}/.Mail 496blacklist ${HOME}/.Mail
483blacklist ${HOME}/.mail 497blacklist ${HOME}/.mail
@@ -502,3 +516,9 @@ blacklist ${PATH}/dns2tcp
502blacklist ${PATH}/iodine 516blacklist ${PATH}/iodine
503blacklist ${PATH}/knsupdate 517blacklist ${PATH}/knsupdate
504blacklist ${PATH}/resolvectl 518blacklist ${PATH}/resolvectl
519
520# rest of ${RUNUSER}
521blacklist ${RUNUSER}/*.lock
522blacklist ${RUNUSER}/inaccessible
523blacklist ${RUNUSER}/update-notifier.pid
524blacklist ${RUNUSER}/pk-debconf-socket