aboutsummaryrefslogtreecommitdiffstats
path: root/etc/profile-a-l
diff options
context:
space:
mode:
authorLibravatar glitsj16 <glitsj16@users.noreply.github.com>2022-03-01 23:09:23 +0000
committerLibravatar GitHub <noreply@github.com>2022-03-01 23:09:23 +0000
commit4bb590f0416468be725114b90888a67d70945fe7 (patch)
tree3e0c8a562f79a526b9cd6c8cc6998c9ccc809fd3 /etc/profile-a-l
parentBump github/codeql-action from 1.1.2 to 1.1.3 (diff)
downloadfirejail-4bb590f0416468be725114b90888a67d70945fe7.tar.gz
firejail-4bb590f0416468be725114b90888a67d70945fe7.tar.zst
firejail-4bb590f0416468be725114b90888a67d70945fe7.zip
geary fixes (#4992)
* geary fixes * comment ipc-namespace
Diffstat (limited to 'etc/profile-a-l')
-rw-r--r--etc/profile-a-l/geary.profile18
1 files changed, 13 insertions, 5 deletions
diff --git a/etc/profile-a-l/geary.profile b/etc/profile-a-l/geary.profile
index cececd9e9..221fbff01 100644
--- a/etc/profile-a-l/geary.profile
+++ b/etc/profile-a-l/geary.profile
@@ -13,7 +13,11 @@ noblacklist ${HOME}/.config/evolution
13noblacklist ${HOME}/.config/geary 13noblacklist ${HOME}/.config/geary
14noblacklist ${HOME}/.local/share/evolution 14noblacklist ${HOME}/.local/share/evolution
15noblacklist ${HOME}/.local/share/geary 15noblacklist ${HOME}/.local/share/geary
16noblacklist ${HOME}/.local/share/pki
16noblacklist ${HOME}/.mozilla 17noblacklist ${HOME}/.mozilla
18noblacklist ${HOME}/.pki
19
20include allow-bin-sh.inc
17 21
18include disable-common.inc 22include disable-common.inc
19include disable-devel.inc 23include disable-devel.inc
@@ -38,7 +42,9 @@ whitelist ${HOME}/.config/evolution
38whitelist ${HOME}/.config/geary 42whitelist ${HOME}/.config/geary
39whitelist ${HOME}/.local/share/evolution 43whitelist ${HOME}/.local/share/evolution
40whitelist ${HOME}/.local/share/geary 44whitelist ${HOME}/.local/share/geary
45whitelist ${HOME}/.local/share/pki
41whitelist ${HOME}/.mozilla/firefox/profiles.ini 46whitelist ${HOME}/.mozilla/firefox/profiles.ini
47whitelist ${HOME}/.pki
42whitelist /usr/share/geary 48whitelist /usr/share/geary
43include whitelist-common.inc 49include whitelist-common.inc
44include whitelist-runuser-common.inc 50include whitelist-runuser-common.inc
@@ -47,7 +53,8 @@ include whitelist-var-common.inc
47 53
48apparmor 54apparmor
49caps.drop all 55caps.drop all
50machine-id 56#ipc-namespace - may cause issues with X11
57#machine-id
51netfilter 58netfilter
52no3d 59no3d
53nodvd 60nodvd
@@ -55,7 +62,7 @@ nogroups
55noinput 62noinput
56nonewprivs 63nonewprivs
57noroot 64noroot
58nosound 65#nosound
59notv 66notv
60nou2f 67nou2f
61novideo 68novideo
@@ -66,21 +73,22 @@ shell none
66tracelog 73tracelog
67 74
68# disable-mnt 75# disable-mnt
69# Add 'ignore private-bin' to geary.local for hyperlink support 76#private-bin geary,sh
70private-bin geary
71private-cache 77private-cache
72private-dev 78private-dev
73private-etc alternatives,ca-certificates,crypto-policies,fonts,hostname,hosts,ld.so.cache,ld.so.preload,pki,resolv.conf,ssl,xdg 79private-etc alternatives,ca-certificates,crypto-policies,fonts,group,gtk-3.0,hostname,hosts,ld.so.cache,ld.so.preload,machine-id,mailcap,mime.types,nsswitch.conf,passwd,pki,resolv.conf,ssl,xdg
74private-tmp 80private-tmp
75 81
76dbus-user filter 82dbus-user filter
77dbus-user.own org.gnome.Geary 83dbus-user.own org.gnome.Geary
78dbus-user.talk ca.desrt.dconf 84dbus-user.talk ca.desrt.dconf
85dbus-user.talk org.freedesktop.Notifications
79dbus-user.talk org.freedesktop.secrets 86dbus-user.talk org.freedesktop.secrets
80dbus-user.talk org.gnome.Contacts 87dbus-user.talk org.gnome.Contacts
81dbus-user.talk org.gnome.OnlineAccounts 88dbus-user.talk org.gnome.OnlineAccounts
82dbus-user.talk org.gnome.evolution.dataserver.AddressBook10 89dbus-user.talk org.gnome.evolution.dataserver.AddressBook10
83dbus-user.talk org.gnome.evolution.dataserver.Sources5 90dbus-user.talk org.gnome.evolution.dataserver.Sources5
91?ALLOW_TRAY: dbus-user.talk org.kde.StatusNotifierWatcher
84dbus-system none 92dbus-system none
85 93
86read-only ${HOME}/.mozilla/firefox/profiles.ini 94read-only ${HOME}/.mozilla/firefox/profiles.ini