aboutsummaryrefslogtreecommitdiffstats
path: root/etc/profile-a-l
diff options
context:
space:
mode:
authorLibravatar glitsj16 <glitsj16@users.noreply.github.com>2023-08-11 03:54:39 +0000
committerLibravatar GitHub <noreply@github.com>2023-08-11 03:54:39 +0000
commita3a41b8fff7763862b07db00b0357f20774687f5 (patch)
tree9a6bebb77b42aeea30539077032f856a595681f2 /etc/profile-a-l
parent0ad.profile: fix libmozjs error on OpenSUSE Tumbleweed (#5944) (diff)
downloadfirejail-a3a41b8fff7763862b07db00b0357f20774687f5.tar.gz
firejail-a3a41b8fff7763862b07db00b0357f20774687f5.tar.zst
firejail-a3a41b8fff7763862b07db00b0357f20774687f5.zip
profiles: improvements to profiles using private (#5946)
Changes: * comment `include whitelist-common.inc` when using `private` * drop `private` on profiles that access files in `${HOME}` * use `#` in comments Relates to #903.
Diffstat (limited to 'etc/profile-a-l')
-rw-r--r--etc/profile-a-l/daisy.profile3
-rw-r--r--etc/profile-a-l/dbus-send.profile5
-rw-r--r--etc/profile-a-l/drill.profile2
-rw-r--r--etc/profile-a-l/gapplication.profile2
-rw-r--r--etc/profile-a-l/gnome-calendar.profile2
-rw-r--r--etc/profile-a-l/gnubik.profile2
-rw-r--r--etc/profile-a-l/gravity-beams-and-evaporating-stars.profile2
-rw-r--r--etc/profile-a-l/ipcalc.profile2
8 files changed, 9 insertions, 11 deletions
diff --git a/etc/profile-a-l/daisy.profile b/etc/profile-a-l/daisy.profile
index 4f1c80f23..40b29a1f5 100644
--- a/etc/profile-a-l/daisy.profile
+++ b/etc/profile-a-l/daisy.profile
@@ -15,7 +15,7 @@ include disable-interpreters.inc
15include disable-proc.inc 15include disable-proc.inc
16include disable-programs.inc 16include disable-programs.inc
17include disable-shell.inc 17include disable-shell.inc
18#include disable-X11.inc - x11 none 18#include disable-X11.inc # x11 none
19include disable-xdg.inc 19include disable-xdg.inc
20 20
21include whitelist-common.inc 21include whitelist-common.inc
@@ -47,7 +47,6 @@ tracelog
47x11 none 47x11 none
48 48
49disable-mnt 49disable-mnt
50private
51private-bin daisy 50private-bin daisy
52private-cache 51private-cache
53private-dev 52private-dev
diff --git a/etc/profile-a-l/dbus-send.profile b/etc/profile-a-l/dbus-send.profile
index 80790bb0c..70bd7370d 100644
--- a/etc/profile-a-l/dbus-send.profile
+++ b/etc/profile-a-l/dbus-send.profile
@@ -19,7 +19,7 @@ include disable-shell.inc
19include disable-write-mnt.inc 19include disable-write-mnt.inc
20include disable-xdg.inc 20include disable-xdg.inc
21 21
22include whitelist-common.inc 22#include whitelist-common.inc # see #903
23include whitelist-runuser-common.inc 23include whitelist-runuser-common.inc
24include whitelist-usr-share-common.inc 24include whitelist-usr-share-common.inc
25include whitelist-var-common.inc 25include whitelist-var-common.inc
@@ -28,8 +28,7 @@ apparmor
28caps.drop all 28caps.drop all
29ipc-namespace 29ipc-namespace
30machine-id 30machine-id
31# Breaks abstract sockets 31#net none # breaks abstract sockets
32#net none
33netfilter 32netfilter
34no3d 33no3d
35nodvd 34nodvd
diff --git a/etc/profile-a-l/drill.profile b/etc/profile-a-l/drill.profile
index bd6fb6dcc..bea114dd6 100644
--- a/etc/profile-a-l/drill.profile
+++ b/etc/profile-a-l/drill.profile
@@ -19,7 +19,7 @@ include disable-exec.inc
19include disable-programs.inc 19include disable-programs.inc
20include disable-xdg.inc 20include disable-xdg.inc
21 21
22include whitelist-common.inc 22#include whitelist-common.inc # see #903
23include whitelist-usr-share-common.inc 23include whitelist-usr-share-common.inc
24include whitelist-var-common.inc 24include whitelist-var-common.inc
25 25
diff --git a/etc/profile-a-l/gapplication.profile b/etc/profile-a-l/gapplication.profile
index baf8f614e..2d0511cf6 100644
--- a/etc/profile-a-l/gapplication.profile
+++ b/etc/profile-a-l/gapplication.profile
@@ -17,7 +17,7 @@ include disable-programs.inc
17include disable-shell.inc 17include disable-shell.inc
18include disable-xdg.inc 18include disable-xdg.inc
19 19
20include whitelist-common.inc 20#include whitelist-common.inc # see #903
21include whitelist-runuser-common.inc 21include whitelist-runuser-common.inc
22include whitelist-usr-share-common.inc 22include whitelist-usr-share-common.inc
23include whitelist-var-common.inc 23include whitelist-var-common.inc
diff --git a/etc/profile-a-l/gnome-calendar.profile b/etc/profile-a-l/gnome-calendar.profile
index ddfe57879..e6fe27774 100644
--- a/etc/profile-a-l/gnome-calendar.profile
+++ b/etc/profile-a-l/gnome-calendar.profile
@@ -15,7 +15,7 @@ include disable-shell.inc
15include disable-xdg.inc 15include disable-xdg.inc
16 16
17whitelist /usr/share/libgweather 17whitelist /usr/share/libgweather
18include whitelist-common.inc 18#include whitelist-common.inc # see #903
19include whitelist-runuser-common.inc 19include whitelist-runuser-common.inc
20include whitelist-usr-share-common.inc 20include whitelist-usr-share-common.inc
21include whitelist-var-common.inc 21include whitelist-var-common.inc
diff --git a/etc/profile-a-l/gnubik.profile b/etc/profile-a-l/gnubik.profile
index 025cb74b6..0c4ca35ac 100644
--- a/etc/profile-a-l/gnubik.profile
+++ b/etc/profile-a-l/gnubik.profile
@@ -15,7 +15,7 @@ include disable-shell.inc
15include disable-xdg.inc 15include disable-xdg.inc
16 16
17whitelist /usr/share/gnubik 17whitelist /usr/share/gnubik
18include whitelist-common.inc 18#include whitelist-common.inc # see #903
19include whitelist-runuser-common.inc 19include whitelist-runuser-common.inc
20include whitelist-usr-share-common.inc 20include whitelist-usr-share-common.inc
21include whitelist-var-common.inc 21include whitelist-var-common.inc
diff --git a/etc/profile-a-l/gravity-beams-and-evaporating-stars.profile b/etc/profile-a-l/gravity-beams-and-evaporating-stars.profile
index 19af7c0b9..5ccce8447 100644
--- a/etc/profile-a-l/gravity-beams-and-evaporating-stars.profile
+++ b/etc/profile-a-l/gravity-beams-and-evaporating-stars.profile
@@ -15,7 +15,7 @@ include disable-shell.inc
15include disable-xdg.inc 15include disable-xdg.inc
16 16
17whitelist /usr/share/gravity-beams-and-evaporating-stars 17whitelist /usr/share/gravity-beams-and-evaporating-stars
18include whitelist-common.inc 18#include whitelist-common.inc # see #903
19include whitelist-usr-share-common.inc 19include whitelist-usr-share-common.inc
20include whitelist-var-common.inc 20include whitelist-var-common.inc
21 21
diff --git a/etc/profile-a-l/ipcalc.profile b/etc/profile-a-l/ipcalc.profile
index 7eabbca84..e73ca44a8 100644
--- a/etc/profile-a-l/ipcalc.profile
+++ b/etc/profile-a-l/ipcalc.profile
@@ -18,7 +18,7 @@ include disable-programs.inc
18include disable-write-mnt.inc 18include disable-write-mnt.inc
19include disable-xdg.inc 19include disable-xdg.inc
20 20
21# include whitelist-common.inc 21#include whitelist-common.inc # see #903
22include whitelist-runuser-common.inc 22include whitelist-runuser-common.inc
23include whitelist-usr-share-common.inc 23include whitelist-usr-share-common.inc
24include whitelist-var-common.inc 24include whitelist-var-common.inc