aboutsummaryrefslogtreecommitdiffstats
path: root/etc/profile-a-l/dia.profile
diff options
context:
space:
mode:
authorLibravatar rusty-snake <41237666+rusty-snake@users.noreply.github.com>2020-11-16 11:41:35 +0100
committerLibravatar rusty-snake <41237666+rusty-snake@users.noreply.github.com>2020-11-16 11:41:35 +0100
commit096d0de5f8bb253d0c1035796464bc5982f06f81 (patch)
treed9634d1c26afca63ada52f66dd55eb09a46647dd /etc/profile-a-l/dia.profile
parentAdd XAUTHORITY file of sddm from openSUSE Tumblew… (diff)
downloadfirejail-096d0de5f8bb253d0c1035796464bc5982f06f81.tar.gz
firejail-096d0de5f8bb253d0c1035796464bc5982f06f81.tar.zst
firejail-096d0de5f8bb253d0c1035796464bc5982f06f81.zip
from my overrides
- add seccomp.block-secondary to a lot profiles - add wruc to firefox-common and ignore it in TB and firefox-common-addons - harden dia, gnome-keyring, libreoffice, megaglest, pngquant, ghostwriter, rhythmbox, sqlitebrowser
Diffstat (limited to 'etc/profile-a-l/dia.profile')
-rw-r--r--etc/profile-a-l/dia.profile13
1 files changed, 11 insertions, 2 deletions
diff --git a/etc/profile-a-l/dia.profile b/etc/profile-a-l/dia.profile
index 52bf1c7f8..e409eb044 100644
--- a/etc/profile-a-l/dia.profile
+++ b/etc/profile-a-l/dia.profile
@@ -9,16 +9,24 @@ include globals.local
9noblacklist ${HOME}/.dia 9noblacklist ${HOME}/.dia
10noblacklist ${DOCUMENTS} 10noblacklist ${DOCUMENTS}
11 11
12include allow-python2.inc
13include allow-python3.inc
14
12include disable-common.inc 15include disable-common.inc
13include disable-devel.inc 16include disable-devel.inc
14include disable-exec.inc 17include disable-exec.inc
15include allow-python2.inc
16include allow-python3.inc
17include disable-interpreters.inc 18include disable-interpreters.inc
18include disable-passwdmgr.inc 19include disable-passwdmgr.inc
19include disable-programs.inc 20include disable-programs.inc
20include disable-xdg.inc 21include disable-xdg.inc
21 22
23#mkdir ${HOME}/.dia
24#whitelist ${HOME}/.dia
25#whitelist ${DOCUMENTS}
26#include whitelist-common.inc
27whitelist /usr/share/dia
28include whitelist-runuser-common.inc
29include whitelist-usr-share-common.inc
22include whitelist-var-common.inc 30include whitelist-var-common.inc
23 31
24apparmor 32apparmor
@@ -36,6 +44,7 @@ novideo
36protocol unix 44protocol unix
37seccomp 45seccomp
38shell none 46shell none
47tracelog
39 48
40disable-mnt 49disable-mnt
41#private-bin dia 50#private-bin dia