diff options
author | netblue30 <netblue30@protonmail.com> | 2023-02-05 10:17:26 -0500 |
---|---|---|
committer | netblue30 <netblue30@protonmail.com> | 2023-02-05 10:17:26 -0500 |
commit | 5d0822c52c9a5e631676899e9642911d9143dba8 (patch) | |
tree | dd3f6c7688f208c63aa470f8cf2d399588f067e0 /etc/profile-m-z | |
parent | private-etc: cleanup tool (diff) | |
download | firejail-5d0822c52c9a5e631676899e9642911d9143dba8.tar.gz firejail-5d0822c52c9a5e631676899e9642911d9143dba8.tar.zst firejail-5d0822c52c9a5e631676899e9642911d9143dba8.zip |
private-etc: big profile changes
Diffstat (limited to 'etc/profile-m-z')
169 files changed, 169 insertions, 169 deletions
diff --git a/etc/profile-m-z/PCSX2.profile b/etc/profile-m-z/PCSX2.profile index 902fc9a6a..e75de80ac 100644 --- a/etc/profile-m-z/PCSX2.profile +++ b/etc/profile-m-z/PCSX2.profile | |||
@@ -47,7 +47,7 @@ private-bin PCSX2 | |||
47 | private-cache | 47 | private-cache |
48 | # Add the next line to your PCSX2.local if you do not need controller support. | 48 | # Add the next line to your PCSX2.local if you do not need controller support. |
49 | #private-dev | 49 | #private-dev |
50 | private-etc alsa,alternatives,asound.conf,bumblebee,ca-certificates,crypto-policies,dconf,drirc,fonts,gconf,glvnd,gtk-2.0,gtk-3.0,host.conf,hostname,hosts,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,locale,locale.alias,locale.conf,localtime,machine-id,mime.types,nsswitch.conf,nvidia,pango,pki,protocols,pulse,resolv.conf,rpc,services,ssl,X11,xdg | 50 | private-etc @tls-ca,@x11,bumblebee,gconf,glvnd,host.conf,mime.types,rpc,services |
51 | private-opt none | 51 | private-opt none |
52 | private-tmp | 52 | private-tmp |
53 | 53 | ||
diff --git a/etc/profile-m-z/QMediathekView.profile b/etc/profile-m-z/QMediathekView.profile index 22c4c4631..f8b5cec13 100644 --- a/etc/profile-m-z/QMediathekView.profile +++ b/etc/profile-m-z/QMediathekView.profile | |||
@@ -71,7 +71,7 @@ disable-mnt | |||
71 | private-bin mplayer,mpv,QMediathekView,smplayer,totem,vlc,xplayer | 71 | private-bin mplayer,mpv,QMediathekView,smplayer,totem,vlc,xplayer |
72 | private-cache | 72 | private-cache |
73 | private-dev | 73 | private-dev |
74 | private-etc alternatives,asound.conf,ca-certificates,crypto-policies,fonts,group,hostname,hosts,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,login.defs,nsswitch.conf,passwd,pki,pulse,resolv.conf,ssl | 74 | private-etc @tls-ca |
75 | private-tmp | 75 | private-tmp |
76 | 76 | ||
77 | dbus-user none | 77 | dbus-user none |
diff --git a/etc/profile-m-z/QOwnNotes.profile b/etc/profile-m-z/QOwnNotes.profile index 6140de60f..eed839041 100644 --- a/etc/profile-m-z/QOwnNotes.profile +++ b/etc/profile-m-z/QOwnNotes.profile | |||
@@ -49,7 +49,7 @@ tracelog | |||
49 | disable-mnt | 49 | disable-mnt |
50 | private-bin gio,QOwnNotes | 50 | private-bin gio,QOwnNotes |
51 | private-dev | 51 | private-dev |
52 | private-etc alternatives,ca-certificates,crypto-policies,fonts,host.conf,hosts,ld.so.cache,ld.so.preload,machine-id,nsswitch.conf,pki,pulse,resolv.conf,ssl | 52 | private-etc @tls-ca,host.conf |
53 | private-tmp | 53 | private-tmp |
54 | 54 | ||
55 | restrict-namespaces | 55 | restrict-namespaces |
diff --git a/etc/profile-m-z/Viber.profile b/etc/profile-m-z/Viber.profile index 2ea185ec0..34d500bb1 100644 --- a/etc/profile-m-z/Viber.profile +++ b/etc/profile-m-z/Viber.profile | |||
@@ -32,7 +32,7 @@ seccomp !chroot | |||
32 | 32 | ||
33 | disable-mnt | 33 | disable-mnt |
34 | private-bin awk,bash,dig,sh,Viber | 34 | private-bin awk,bash,dig,sh,Viber |
35 | private-etc alternatives,asound.conf,ca-certificates,crypto-policies,fonts,hosts,ld.so.cache,ld.so.preload,localtime,machine-id,mailcap,nsswitch.conf,pki,proxychains.conf,pulse,resolv.conf,ssl,X11 | 35 | private-etc @tls-ca,@x11,mailcap,proxychains.conf |
36 | private-tmp | 36 | private-tmp |
37 | 37 | ||
38 | # restrict-namespaces | 38 | # restrict-namespaces |
diff --git a/etc/profile-m-z/Xvfb.profile b/etc/profile-m-z/Xvfb.profile index 8bf79f554..ee19fa3b0 100644 --- a/etc/profile-m-z/Xvfb.profile +++ b/etc/profile-m-z/Xvfb.profile | |||
@@ -42,7 +42,7 @@ private | |||
42 | # private-bin sh,xkbcomp,Xvfb | 42 | # private-bin sh,xkbcomp,Xvfb |
43 | # private-bin bash,cat,ls,sh,strace,xkbcomp,Xvfb | 43 | # private-bin bash,cat,ls,sh,strace,xkbcomp,Xvfb |
44 | private-dev | 44 | private-dev |
45 | private-etc alternatives,gai.conf,host.conf,hostname,hosts,ld.so.cache,ld.so.conf,ld.so.preload,nsswitch.conf,resolv.conf | 45 | private-etc gai.conf,host.conf |
46 | private-tmp | 46 | private-tmp |
47 | 47 | ||
48 | restrict-namespaces | 48 | restrict-namespaces |
diff --git a/etc/profile-m-z/magicor.profile b/etc/profile-m-z/magicor.profile index e5d994b57..d9990825a 100644 --- a/etc/profile-m-z/magicor.profile +++ b/etc/profile-m-z/magicor.profile | |||
@@ -44,7 +44,7 @@ disable-mnt | |||
44 | private-bin magicor,python2* | 44 | private-bin magicor,python2* |
45 | private-cache | 45 | private-cache |
46 | private-dev | 46 | private-dev |
47 | private-etc alternatives,ld.so.cache,ld.so.preload,machine-id | 47 | private-etc |
48 | private-tmp | 48 | private-tmp |
49 | 49 | ||
50 | dbus-user none | 50 | dbus-user none |
diff --git a/etc/profile-m-z/man.profile b/etc/profile-m-z/man.profile index 0e3f9e6e2..6cb523727 100644 --- a/etc/profile-m-z/man.profile +++ b/etc/profile-m-z/man.profile | |||
@@ -56,7 +56,7 @@ disable-mnt | |||
56 | #private-bin apropos,bash,cat,catman,col,gpreconv,groff,grotty,gunzip,gzip,less,man,most,nroff,preconv,sed,sh,tbl,tr,troff,whatis,which,xtotroff,zcat,zsoelim | 56 | #private-bin apropos,bash,cat,catman,col,gpreconv,groff,grotty,gunzip,gzip,less,man,most,nroff,preconv,sed,sh,tbl,tr,troff,whatis,which,xtotroff,zcat,zsoelim |
57 | private-cache | 57 | private-cache |
58 | private-dev | 58 | private-dev |
59 | private-etc alternatives,fonts,groff,group,ld.so.cache,ld.so.preload,locale,locale.alias,locale.conf,login.defs,man_db.conf,manpath.config,passwd,selinux,sysless,xdg | 59 | private-etc @x11,groff,man_db.conf,manpath.config,selinux,sysless |
60 | #private-tmp | 60 | #private-tmp |
61 | 61 | ||
62 | dbus-user none | 62 | dbus-user none |
diff --git a/etc/profile-m-z/marker.profile b/etc/profile-m-z/marker.profile index 7066f4229..acaaa113a 100644 --- a/etc/profile-m-z/marker.profile +++ b/etc/profile-m-z/marker.profile | |||
@@ -53,7 +53,7 @@ tracelog | |||
53 | private-bin marker,python3* | 53 | private-bin marker,python3* |
54 | private-cache | 54 | private-cache |
55 | private-dev | 55 | private-dev |
56 | private-etc alternatives,dconfgtk-3.0,fonts,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,locale,locale.alias,locale.conf,localtime,pango,X11 | 56 | private-etc @x11,dconfgtk-3.0 |
57 | private-tmp | 57 | private-tmp |
58 | 58 | ||
59 | dbus-user filter | 59 | dbus-user filter |
diff --git a/etc/profile-m-z/masterpdfeditor.profile b/etc/profile-m-z/masterpdfeditor.profile index 176506ff2..95a16cbb8 100644 --- a/etc/profile-m-z/masterpdfeditor.profile +++ b/etc/profile-m-z/masterpdfeditor.profile | |||
@@ -35,7 +35,7 @@ tracelog | |||
35 | 35 | ||
36 | private-cache | 36 | private-cache |
37 | private-dev | 37 | private-dev |
38 | private-etc alternatives,fonts,ld.so.cache,ld.so.preload | 38 | private-etc |
39 | private-tmp | 39 | private-tmp |
40 | 40 | ||
41 | restrict-namespaces | 41 | restrict-namespaces |
diff --git a/etc/profile-m-z/mate-calc.profile b/etc/profile-m-z/mate-calc.profile index e3a5c6ab6..ee780333d 100644 --- a/etc/profile-m-z/mate-calc.profile +++ b/etc/profile-m-z/mate-calc.profile | |||
@@ -41,7 +41,7 @@ seccomp | |||
41 | 41 | ||
42 | disable-mnt | 42 | disable-mnt |
43 | private-bin mate-calc,mate-calculator | 43 | private-bin mate-calc,mate-calculator |
44 | private-etc alternatives,dconf,fonts,gtk-3.0,ld.so.cache,ld.so.preload | 44 | private-etc @x11 |
45 | private-dev | 45 | private-dev |
46 | private-opt none | 46 | private-opt none |
47 | private-tmp | 47 | private-tmp |
diff --git a/etc/profile-m-z/mate-color-select.profile b/etc/profile-m-z/mate-color-select.profile index 337c2d6e5..37cae5c70 100644 --- a/etc/profile-m-z/mate-color-select.profile +++ b/etc/profile-m-z/mate-color-select.profile | |||
@@ -32,7 +32,7 @@ seccomp | |||
32 | 32 | ||
33 | disable-mnt | 33 | disable-mnt |
34 | private-bin mate-color-select | 34 | private-bin mate-color-select |
35 | private-etc alternatives,fonts,ld.so.cache,ld.so.preload | 35 | private-etc |
36 | private-dev | 36 | private-dev |
37 | private-lib | 37 | private-lib |
38 | private-tmp | 38 | private-tmp |
diff --git a/etc/profile-m-z/mate-dictionary.profile b/etc/profile-m-z/mate-dictionary.profile index e80b220b7..b56317037 100644 --- a/etc/profile-m-z/mate-dictionary.profile +++ b/etc/profile-m-z/mate-dictionary.profile | |||
@@ -36,7 +36,7 @@ seccomp | |||
36 | 36 | ||
37 | disable-mnt | 37 | disable-mnt |
38 | private-bin mate-dictionary | 38 | private-bin mate-dictionary |
39 | private-etc alternatives,ca-certificates,crypto-policies,fonts,ld.so.cache,ld.so.preload,pki,resolv.conf,ssl | 39 | private-etc @tls-ca |
40 | private-opt mate-dictionary | 40 | private-opt mate-dictionary |
41 | private-dev | 41 | private-dev |
42 | private-tmp | 42 | private-tmp |
diff --git a/etc/profile-m-z/mattermost-desktop.profile b/etc/profile-m-z/mattermost-desktop.profile index 3c2bf4fa3..f4eb6d404 100644 --- a/etc/profile-m-z/mattermost-desktop.profile +++ b/etc/profile-m-z/mattermost-desktop.profile | |||
@@ -17,7 +17,7 @@ include disable-shell.inc | |||
17 | mkdir ${HOME}/.config/Mattermost | 17 | mkdir ${HOME}/.config/Mattermost |
18 | whitelist ${HOME}/.config/Mattermost | 18 | whitelist ${HOME}/.config/Mattermost |
19 | 19 | ||
20 | private-etc alternatives,ca-certificates,crypto-policies,fonts,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,machine-id,nsswitch.conf,pki,resolv.conf,ssl | 20 | private-etc @tls-ca |
21 | 21 | ||
22 | # Not tested | 22 | # Not tested |
23 | #dbus-user filter | 23 | #dbus-user filter |
diff --git a/etc/profile-m-z/mcabber.profile b/etc/profile-m-z/mcabber.profile index 1ebe9aaba..d880228de 100644 --- a/etc/profile-m-z/mcabber.profile +++ b/etc/profile-m-z/mcabber.profile | |||
@@ -30,6 +30,6 @@ seccomp | |||
30 | 30 | ||
31 | private-bin mcabber | 31 | private-bin mcabber |
32 | private-dev | 32 | private-dev |
33 | private-etc alternatives,ca-certificates,crypto-policies,ld.so.cache,ld.so.preload,pki,ssl | 33 | private-etc @tls-ca |
34 | 34 | ||
35 | restrict-namespaces | 35 | restrict-namespaces |
diff --git a/etc/profile-m-z/mcomix.profile b/etc/profile-m-z/mcomix.profile index a3ff768b7..a288f1972 100644 --- a/etc/profile-m-z/mcomix.profile +++ b/etc/profile-m-z/mcomix.profile | |||
@@ -57,7 +57,7 @@ private-bin 7z,lha,mcomix,mutool,python*,rar,sh,unrar,unzip | |||
57 | private-cache | 57 | private-cache |
58 | private-dev | 58 | private-dev |
59 | # mcomix <= 1.2 uses gtk-2.0 | 59 | # mcomix <= 1.2 uses gtk-2.0 |
60 | private-etc alternatives,dconf,fonts,gconf,gtk-2.0,gtk-3.0,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,locale,locale.alias,locale.conf,localtime,machine-id,mime.types,pango,passwd,X11,xdg | 60 | private-etc @x11,gconf,mime.types |
61 | private-tmp | 61 | private-tmp |
62 | 62 | ||
63 | dbus-user none | 63 | dbus-user none |
diff --git a/etc/profile-m-z/mdr.profile b/etc/profile-m-z/mdr.profile index e1025a1fb..d3b3c6d48 100644 --- a/etc/profile-m-z/mdr.profile +++ b/etc/profile-m-z/mdr.profile | |||
@@ -44,7 +44,7 @@ disable-mnt | |||
44 | private-bin mdr | 44 | private-bin mdr |
45 | private-cache | 45 | private-cache |
46 | private-dev | 46 | private-dev |
47 | private-etc alternatives,ld.so.cache,ld.so.preload | 47 | private-etc |
48 | private-lib | 48 | private-lib |
49 | private-tmp | 49 | private-tmp |
50 | 50 | ||
diff --git a/etc/profile-m-z/mediainfo.profile b/etc/profile-m-z/mediainfo.profile index 12d692b72..01edd23ab 100644 --- a/etc/profile-m-z/mediainfo.profile +++ b/etc/profile-m-z/mediainfo.profile | |||
@@ -42,7 +42,7 @@ x11 none | |||
42 | private-bin mediainfo | 42 | private-bin mediainfo |
43 | private-cache | 43 | private-cache |
44 | private-dev | 44 | private-dev |
45 | private-etc alternatives,ld.so.cache,ld.so.preload | 45 | private-etc |
46 | private-tmp | 46 | private-tmp |
47 | 47 | ||
48 | dbus-user none | 48 | dbus-user none |
diff --git a/etc/profile-m-z/menulibre.profile b/etc/profile-m-z/menulibre.profile index cd4938ec6..a67ef9101 100644 --- a/etc/profile-m-z/menulibre.profile +++ b/etc/profile-m-z/menulibre.profile | |||
@@ -51,7 +51,7 @@ tracelog | |||
51 | disable-mnt | 51 | disable-mnt |
52 | private-cache | 52 | private-cache |
53 | private-dev | 53 | private-dev |
54 | private-etc alternatives,dconf,fonts,gtk-3.0,ld.so.cache,ld.so.preload,locale.alias,locale.conf,mime.types,nsswitch.conf,passwd,pki,selinux,X11,xdg | 54 | private-etc @tls-ca,@x11,mime.types,selinux |
55 | private-tmp | 55 | private-tmp |
56 | 56 | ||
57 | dbus-user none | 57 | dbus-user none |
diff --git a/etc/profile-m-z/mindless.profile b/etc/profile-m-z/mindless.profile index a26896b19..48ac0ec69 100644 --- a/etc/profile-m-z/mindless.profile +++ b/etc/profile-m-z/mindless.profile | |||
@@ -41,7 +41,7 @@ private | |||
41 | private-bin mindless | 41 | private-bin mindless |
42 | private-cache | 42 | private-cache |
43 | private-dev | 43 | private-dev |
44 | private-etc alternatives,fonts,ld.so.cache,ld.so.preload | 44 | private-etc |
45 | private-tmp | 45 | private-tmp |
46 | 46 | ||
47 | dbus-user none | 47 | dbus-user none |
diff --git a/etc/profile-m-z/minecraft-launcher.profile b/etc/profile-m-z/minecraft-launcher.profile index e6bf86802..86378527b 100644 --- a/etc/profile-m-z/minecraft-launcher.profile +++ b/etc/profile-m-z/minecraft-launcher.profile | |||
@@ -50,7 +50,7 @@ private-cache | |||
50 | private-dev | 50 | private-dev |
51 | # If multiplayer or realms break, add 'private-etc <your-own-java-folder-from-/etc>' | 51 | # If multiplayer or realms break, add 'private-etc <your-own-java-folder-from-/etc>' |
52 | # or 'ignore private-etc' to your minecraft-launcher.local. | 52 | # or 'ignore private-etc' to your minecraft-launcher.local. |
53 | private-etc alternatives,asound.conf,ati,ca-certificates,crypto-policies,drirc,fonts,group,gtk-2.0,gtk-3.0,host.conf,hostname,hosts,java-10-openjdk,java-11-openjdk,java-12-openjdk,java-13-openjdk,java-14-openjdk,java-7-openjdk,java-8-openjdk,java-9-openjdk,java-openjdk,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,localtime,login.defs,machine-id,mime.types,nvidia,passwd,pki,pulse,resolv.conf,selinux,services,ssl,timezone,X11,xdg | 53 | private-etc @tls-ca,@x11,host.conf,java-10-openjdk,java-11-openjdk,java-12-openjdk,java-13-openjdk,java-14-openjdk,java-7-openjdk,java-8-openjdk,java-9-openjdk,java-openjdk,mime.types,selinux,services,timezone |
54 | private-opt minecraft-launcher | 54 | private-opt minecraft-launcher |
55 | private-tmp | 55 | private-tmp |
56 | 56 | ||
diff --git a/etc/profile-m-z/minitube.profile b/etc/profile-m-z/minitube.profile index ce938c867..20e956cff 100644 --- a/etc/profile-m-z/minitube.profile +++ b/etc/profile-m-z/minitube.profile | |||
@@ -53,7 +53,7 @@ disable-mnt | |||
53 | private-bin minitube | 53 | private-bin minitube |
54 | private-cache | 54 | private-cache |
55 | private-dev | 55 | private-dev |
56 | private-etc alsa,alternatives,asound.conf,ca-certificates,crypto-policies,drirc,fonts,gtk-2.0,gtk-3.0,host.conf,hostname,hosts,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,mime.types,nsswitch.conf,pki,pulse,resolv.conf,selinux,ssl,X11,xdg | 56 | private-etc @tls-ca,@x11,host.conf,mime.types,selinux |
57 | private-tmp | 57 | private-tmp |
58 | 58 | ||
59 | dbus-user none | 59 | dbus-user none |
diff --git a/etc/profile-m-z/mirage.profile b/etc/profile-m-z/mirage.profile index d36c0fc81..7c5b3aee4 100644 --- a/etc/profile-m-z/mirage.profile +++ b/etc/profile-m-z/mirage.profile | |||
@@ -53,7 +53,7 @@ disable-mnt | |||
53 | private-bin ldconfig,mirage | 53 | private-bin ldconfig,mirage |
54 | private-cache | 54 | private-cache |
55 | private-dev | 55 | private-dev |
56 | private-etc alsa,alternatives,asound.conf,ca-certificates,crypto-policies,fonts,gtk-2.0,gtk-3.0,host.conf,hostname,hosts,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,locale,locale.alias,locale.conf,mime.types,nsswitch.conf,pki,pulse,resolv.conf,selinux,ssl,X11,xdg | 56 | private-etc @tls-ca,@x11,host.conf,mime.types,selinux |
57 | private-tmp | 57 | private-tmp |
58 | 58 | ||
59 | dbus-user none | 59 | dbus-user none |
diff --git a/etc/profile-m-z/mirrormagic.profile b/etc/profile-m-z/mirrormagic.profile index 34721b4a3..4943a80af 100644 --- a/etc/profile-m-z/mirrormagic.profile +++ b/etc/profile-m-z/mirrormagic.profile | |||
@@ -43,7 +43,7 @@ private | |||
43 | private-bin mirrormagic | 43 | private-bin mirrormagic |
44 | private-cache | 44 | private-cache |
45 | private-dev | 45 | private-dev |
46 | private-etc alternatives,ld.so.cache,ld.so.preload,machine-id | 46 | private-etc |
47 | private-tmp | 47 | private-tmp |
48 | 48 | ||
49 | dbus-user none | 49 | dbus-user none |
diff --git a/etc/profile-m-z/mocp.profile b/etc/profile-m-z/mocp.profile index 46320f8ea..2ba03ec97 100644 --- a/etc/profile-m-z/mocp.profile +++ b/etc/profile-m-z/mocp.profile | |||
@@ -41,7 +41,7 @@ tracelog | |||
41 | private-bin mocp | 41 | private-bin mocp |
42 | private-cache | 42 | private-cache |
43 | private-dev | 43 | private-dev |
44 | private-etc alternatives,asound.conf,ca-certificates,crypto-policies,group,ld.so.cache,ld.so.preload,machine-id,pki,pulse,resolv.conf,ssl | 44 | private-etc @tls-ca |
45 | private-tmp | 45 | private-tmp |
46 | 46 | ||
47 | dbus-user none | 47 | dbus-user none |
diff --git a/etc/profile-m-z/mp3splt-gtk.profile b/etc/profile-m-z/mp3splt-gtk.profile index 89cee657d..ed344ba3f 100644 --- a/etc/profile-m-z/mp3splt-gtk.profile +++ b/etc/profile-m-z/mp3splt-gtk.profile | |||
@@ -36,7 +36,7 @@ tracelog | |||
36 | private-bin mp3splt-gtk | 36 | private-bin mp3splt-gtk |
37 | private-cache | 37 | private-cache |
38 | private-dev | 38 | private-dev |
39 | private-etc alsa,alternatives,asound.conf,dconf,fonts,gtk-3.0,ld.so.cache,ld.so.preload,machine-id,openal,pulse | 39 | private-etc @games,@x11 |
40 | private-tmp | 40 | private-tmp |
41 | 41 | ||
42 | dbus-user none | 42 | dbus-user none |
diff --git a/etc/profile-m-z/mp3splt.profile b/etc/profile-m-z/mp3splt.profile index 77ad30d0c..ef4635075 100644 --- a/etc/profile-m-z/mp3splt.profile +++ b/etc/profile-m-z/mp3splt.profile | |||
@@ -43,7 +43,7 @@ disable-mnt | |||
43 | private-bin flacsplt,mp3splt,mp3wrap,oggsplt | 43 | private-bin flacsplt,mp3splt,mp3wrap,oggsplt |
44 | private-cache | 44 | private-cache |
45 | private-dev | 45 | private-dev |
46 | private-etc alternatives,ld.so.cache,ld.so.preload | 46 | private-etc |
47 | private-tmp | 47 | private-tmp |
48 | 48 | ||
49 | dbus-user none | 49 | dbus-user none |
diff --git a/etc/profile-m-z/mpDris2.profile b/etc/profile-m-z/mpDris2.profile index 94b342865..a9631733c 100644 --- a/etc/profile-m-z/mpDris2.profile +++ b/etc/profile-m-z/mpDris2.profile | |||
@@ -48,7 +48,7 @@ seccomp | |||
48 | private-bin mpDris2,notify-send,python* | 48 | private-bin mpDris2,notify-send,python* |
49 | private-cache | 49 | private-cache |
50 | private-dev | 50 | private-dev |
51 | private-etc alternatives,hosts,ld.so.cache,ld.so.preload,nsswitch.conf,resolv.conf | 51 | private-etc |
52 | private-lib libdbus-1.so.*,libdbus-glib-1.so.*,libgirepository-1.0.so.*,libnotify.so.*,libpython*,python2*,python3* | 52 | private-lib libdbus-1.so.*,libdbus-glib-1.so.*,libgirepository-1.0.so.*,libnotify.so.*,libpython*,python2*,python3* |
53 | private-tmp | 53 | private-tmp |
54 | 54 | ||
diff --git a/etc/profile-m-z/mrrescue.profile b/etc/profile-m-z/mrrescue.profile index 4f7ae09b9..fd79e2a80 100644 --- a/etc/profile-m-z/mrrescue.profile +++ b/etc/profile-m-z/mrrescue.profile | |||
@@ -51,7 +51,7 @@ disable-mnt | |||
51 | private-bin love,mrrescue,sh | 51 | private-bin love,mrrescue,sh |
52 | private-cache | 52 | private-cache |
53 | private-dev | 53 | private-dev |
54 | private-etc alternatives,ld.so.cache,ld.so.preload,machine-id | 54 | private-etc |
55 | private-tmp | 55 | private-tmp |
56 | 56 | ||
57 | dbus-user none | 57 | dbus-user none |
diff --git a/etc/profile-m-z/ms-office.profile b/etc/profile-m-z/ms-office.profile index d979e7401..91e990cf6 100644 --- a/etc/profile-m-z/ms-office.profile +++ b/etc/profile-m-z/ms-office.profile | |||
@@ -34,7 +34,7 @@ tracelog | |||
34 | 34 | ||
35 | disable-mnt | 35 | disable-mnt |
36 | private-bin bash,env,fonts,jak,ms-office,python*,sh | 36 | private-bin bash,env,fonts,jak,ms-office,python*,sh |
37 | private-etc alternatives,ca-certificates,crypto-policies,ld.so.cache,ld.so.preload,pki,resolv.conf,ssl | 37 | private-etc @tls-ca |
38 | private-dev | 38 | private-dev |
39 | private-tmp | 39 | private-tmp |
40 | 40 | ||
diff --git a/etc/profile-m-z/mupdf-x11-curl.profile b/etc/profile-m-z/mupdf-x11-curl.profile index 006f64ba8..f8dec6e7d 100644 --- a/etc/profile-m-z/mupdf-x11-curl.profile +++ b/etc/profile-m-z/mupdf-x11-curl.profile | |||
@@ -12,7 +12,7 @@ ignore net none | |||
12 | netfilter | 12 | netfilter |
13 | protocol unix,inet,inet6 | 13 | protocol unix,inet,inet6 |
14 | 14 | ||
15 | private-etc alternatives,ca-certificates,crypto-policies,hosts,ld.so.cache,ld.so.preload,nsswitch.conf,pki,resolv.conf,ssl | 15 | private-etc @tls-ca |
16 | 16 | ||
17 | # Redirect | 17 | # Redirect |
18 | include mupdf.profile | 18 | include mupdf.profile |
diff --git a/etc/profile-m-z/mupdf.profile b/etc/profile-m-z/mupdf.profile index 954016c2c..1e92b07bf 100644 --- a/etc/profile-m-z/mupdf.profile +++ b/etc/profile-m-z/mupdf.profile | |||
@@ -36,7 +36,7 @@ seccomp | |||
36 | tracelog | 36 | tracelog |
37 | 37 | ||
38 | private-dev | 38 | private-dev |
39 | private-etc alternatives,fonts,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload | 39 | private-etc |
40 | private-tmp | 40 | private-tmp |
41 | 41 | ||
42 | dbus-user none | 42 | dbus-user none |
diff --git a/etc/profile-m-z/musictube.profile b/etc/profile-m-z/musictube.profile index 01b8d20b3..0da6a8c3d 100644 --- a/etc/profile-m-z/musictube.profile +++ b/etc/profile-m-z/musictube.profile | |||
@@ -49,7 +49,7 @@ disable-mnt | |||
49 | private-bin musictube | 49 | private-bin musictube |
50 | private-cache | 50 | private-cache |
51 | private-dev | 51 | private-dev |
52 | private-etc alsa,alternatives,asound.conf,ca-certificates,crypto-policies,drirc,fonts,gtk-2.0,gtk-3.0,host.conf,hostname,hosts,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,machine-id,mime.types,nsswitch.conf,pki,pulse,resolv.conf,selinux,ssl,X11,xdg | 52 | private-etc @tls-ca,@x11,host.conf,mime.types,selinux |
53 | private-tmp | 53 | private-tmp |
54 | 54 | ||
55 | dbus-user none | 55 | dbus-user none |
diff --git a/etc/profile-m-z/musixmatch.profile b/etc/profile-m-z/musixmatch.profile index d2032dcf6..7ce7fbd19 100644 --- a/etc/profile-m-z/musixmatch.profile +++ b/etc/profile-m-z/musixmatch.profile | |||
@@ -33,6 +33,6 @@ seccomp !chroot | |||
33 | 33 | ||
34 | disable-mnt | 34 | disable-mnt |
35 | private-dev | 35 | private-dev |
36 | private-etc alternatives,asound.conf,ca-certificates,crypto-policies,ld.so.cache,ld.so.preload,machine-id,pki,pulse,ssl | 36 | private-etc @tls-ca |
37 | 37 | ||
38 | # restrict-namespaces | 38 | # restrict-namespaces |
diff --git a/etc/profile-m-z/mutt.profile b/etc/profile-m-z/mutt.profile index 904b0cd7c..c96dca73a 100644 --- a/etc/profile-m-z/mutt.profile +++ b/etc/profile-m-z/mutt.profile | |||
@@ -124,7 +124,7 @@ tracelog | |||
124 | # disable-mnt | 124 | # disable-mnt |
125 | private-cache | 125 | private-cache |
126 | private-dev | 126 | private-dev |
127 | private-etc alternatives,ca-certificates,crypto-policies,fonts,gai.conf,gcrypt,gnupg,gnutls,hostname,hosts,hosts.conf,ld.so.cache,ld.so.preload,mail,mailname,Mutt,Muttrc,Muttrc.d,nntpserver,nsswitch.conf,passwd,pki,resolv.conf,ssl,terminfo,xdg | 127 | private-etc @tls-ca,@x11,gai.conf,gnupg,gnutls,hosts.conf,mail,mailname,Mutt,Muttrc,Muttrc.d,nntpserver,terminfo |
128 | private-tmp | 128 | private-tmp |
129 | writable-run-user | 129 | writable-run-user |
130 | writable-var | 130 | writable-var |
diff --git a/etc/profile-m-z/mypaint.profile b/etc/profile-m-z/mypaint.profile index 18117965e..774865a38 100644 --- a/etc/profile-m-z/mypaint.profile +++ b/etc/profile-m-z/mypaint.profile | |||
@@ -42,7 +42,7 @@ tracelog | |||
42 | 42 | ||
43 | private-cache | 43 | private-cache |
44 | private-dev | 44 | private-dev |
45 | private-etc alternatives,dconf,fonts,gtk-3.0,ld.so.cache,ld.so.preload | 45 | private-etc @x11 |
46 | private-tmp | 46 | private-tmp |
47 | 47 | ||
48 | dbus-user none | 48 | dbus-user none |
diff --git a/etc/profile-m-z/nano.profile b/etc/profile-m-z/nano.profile index 74403c335..6b4074dfb 100644 --- a/etc/profile-m-z/nano.profile +++ b/etc/profile-m-z/nano.profile | |||
@@ -48,7 +48,7 @@ private-dev | |||
48 | # Add the next lines to your nano.local if you want to edit files in /etc directly. | 48 | # Add the next lines to your nano.local if you want to edit files in /etc directly. |
49 | #ignore private-etc | 49 | #ignore private-etc |
50 | #writable-etc | 50 | #writable-etc |
51 | private-etc alternatives,ld.so.cache,ld.so.preload,nanorc | 51 | private-etc nanorc |
52 | # Add the next line to your nano.local if you want to edit files in /var directly. | 52 | # Add the next line to your nano.local if you want to edit files in /var directly. |
53 | #writable-var | 53 | #writable-var |
54 | 54 | ||
diff --git a/etc/profile-m-z/neochat.profile b/etc/profile-m-z/neochat.profile index fde1d4d2c..244e01cc5 100644 --- a/etc/profile-m-z/neochat.profile +++ b/etc/profile-m-z/neochat.profile | |||
@@ -53,7 +53,7 @@ tracelog | |||
53 | disable-mnt | 53 | disable-mnt |
54 | private-bin neochat | 54 | private-bin neochat |
55 | private-dev | 55 | private-dev |
56 | private-etc alternatives,ca-certificates,crypto-policies,dbus-1,fonts,host.conf,hostname,hosts,kde4rc,kde5rc,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,locale,locale.alias,locale.conf,localtime,machine-id,mime.types,nsswitch.conf,pango,pki,protocols,resolv.conf,rpc,services,ssl,Trolltech.conf,X11,xdg | 56 | private-etc @tls-ca,@x11,dbus-1,host.conf,mime.types,rpc,services,Trolltech.conf |
57 | private-tmp | 57 | private-tmp |
58 | 58 | ||
59 | dbus-user filter | 59 | dbus-user filter |
diff --git a/etc/profile-m-z/neomutt.profile b/etc/profile-m-z/neomutt.profile index f343226ae..4f311b155 100644 --- a/etc/profile-m-z/neomutt.profile +++ b/etc/profile-m-z/neomutt.profile | |||
@@ -116,7 +116,7 @@ tracelog | |||
116 | # disable-mnt | 116 | # disable-mnt |
117 | private-cache | 117 | private-cache |
118 | private-dev | 118 | private-dev |
119 | private-etc alternatives,ca-certificates,crypto-policies,dconf,fonts,gcrypt,gnupg,hostname,hosts,hosts.conf,ld.so.cache,ld.so.preload,mail,mailname,Mutt,Muttrc,Muttrc.d,neomuttrc,neomuttrc.d,nntpserver,nsswitch.conf,passwd,pki,resolv.conf,ssl,xdg | 119 | private-etc @tls-ca,@x11,gnupg,hosts.conf,mail,mailname,Mutt,Muttrc,Muttrc.d,neomuttrc,neomuttrc.d,nntpserver |
120 | private-tmp | 120 | private-tmp |
121 | writable-run-user | 121 | writable-run-user |
122 | writable-var | 122 | writable-var |
diff --git a/etc/profile-m-z/netactview.profile b/etc/profile-m-z/netactview.profile index 1ede42405..b0828cd76 100644 --- a/etc/profile-m-z/netactview.profile +++ b/etc/profile-m-z/netactview.profile | |||
@@ -44,7 +44,7 @@ disable-mnt | |||
44 | private-bin netactview,netactview_polkit | 44 | private-bin netactview,netactview_polkit |
45 | private-cache | 45 | private-cache |
46 | private-dev | 46 | private-dev |
47 | private-etc alternatives,fonts,ld.so.cache,ld.so.preload,resolv.conf | 47 | private-etc |
48 | private-lib | 48 | private-lib |
49 | private-tmp | 49 | private-tmp |
50 | 50 | ||
diff --git a/etc/profile-m-z/neverball.profile b/etc/profile-m-z/neverball.profile index 68b0ce2ea..a7c404201 100644 --- a/etc/profile-m-z/neverball.profile +++ b/etc/profile-m-z/neverball.profile | |||
@@ -43,7 +43,7 @@ disable-mnt | |||
43 | private-bin neverball | 43 | private-bin neverball |
44 | private-cache | 44 | private-cache |
45 | private-dev | 45 | private-dev |
46 | private-etc alternatives,fonts,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,locale,machine-id | 46 | private-etc |
47 | private-tmp | 47 | private-tmp |
48 | 48 | ||
49 | dbus-user none | 49 | dbus-user none |
diff --git a/etc/profile-m-z/newsboat.profile b/etc/profile-m-z/newsboat.profile index b80a0a151..a08fbad36 100644 --- a/etc/profile-m-z/newsboat.profile +++ b/etc/profile-m-z/newsboat.profile | |||
@@ -52,7 +52,7 @@ disable-mnt | |||
52 | private-bin gzip,lynx,newsboat,sh,w3m | 52 | private-bin gzip,lynx,newsboat,sh,w3m |
53 | private-cache | 53 | private-cache |
54 | private-dev | 54 | private-dev |
55 | private-etc alternatives,ca-certificates,crypto-policies,ld.so.cache,ld.so.preload,lynx.cfg,lynx.lss,pki,resolv.conf,ssl,terminfo | 55 | private-etc @tls-ca,lynx.cfg,lynx.lss,terminfo |
56 | private-tmp | 56 | private-tmp |
57 | 57 | ||
58 | dbus-user none | 58 | dbus-user none |
diff --git a/etc/profile-m-z/newsflash.profile b/etc/profile-m-z/newsflash.profile index 59f16bb10..c7c8abc0b 100644 --- a/etc/profile-m-z/newsflash.profile +++ b/etc/profile-m-z/newsflash.profile | |||
@@ -50,7 +50,7 @@ disable-mnt | |||
50 | private-bin com.gitlab.newsflash,newsflash | 50 | private-bin com.gitlab.newsflash,newsflash |
51 | private-cache | 51 | private-cache |
52 | private-dev | 52 | private-dev |
53 | private-etc alternatives,ca-certificates,crypto-policies,dconf,fonts,gtk-3.0,hosts,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,nsswitch.conf,pango,pki,resolv.conf,ssl,X11 | 53 | private-etc @tls-ca,@x11 |
54 | private-tmp | 54 | private-tmp |
55 | 55 | ||
56 | dbus-user none | 56 | dbus-user none |
diff --git a/etc/profile-m-z/nextcloud.profile b/etc/profile-m-z/nextcloud.profile index c26942c81..32a65f0c5 100644 --- a/etc/profile-m-z/nextcloud.profile +++ b/etc/profile-m-z/nextcloud.profile | |||
@@ -61,7 +61,7 @@ tracelog | |||
61 | disable-mnt | 61 | disable-mnt |
62 | private-bin nextcloud,nextcloud-desktop | 62 | private-bin nextcloud,nextcloud-desktop |
63 | private-cache | 63 | private-cache |
64 | private-etc alternatives,ca-certificates,crypto-policies,drirc,fonts,gcrypt,host.conf,hosts,ld.so.cache,ld.so.preload,machine-id,Nextcloud,nsswitch.conf,os-release,passwd,pki,pulse,resolv.conf,selinux,ssl,xdg | 64 | private-etc @tls-ca,@x11,host.conf,Nextcloud,os-release,selinux |
65 | private-dev | 65 | private-dev |
66 | private-tmp | 66 | private-tmp |
67 | 67 | ||
diff --git a/etc/profile-m-z/nheko.profile b/etc/profile-m-z/nheko.profile index 4e4c7bfe7..a0565c77d 100644 --- a/etc/profile-m-z/nheko.profile +++ b/etc/profile-m-z/nheko.profile | |||
@@ -47,7 +47,7 @@ disable-mnt | |||
47 | private-bin nheko | 47 | private-bin nheko |
48 | private-cache | 48 | private-cache |
49 | private-dev | 49 | private-dev |
50 | private-etc alsa,alternatives,asound.conf,ca-certificates,crypto-policies,fonts,gtk-2.0,gtk-3.0,host.conf,hostname,hosts,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,locale,locale.alias,locale.conf,mime.types,nsswitch.conf,pki,pulse,resolv.conf,selinux,ssl,X11,xdg | 50 | private-etc @tls-ca,@x11,host.conf,mime.types,selinux |
51 | private-tmp | 51 | private-tmp |
52 | 52 | ||
53 | dbus-user filter | 53 | dbus-user filter |
diff --git a/etc/profile-m-z/nitroshare.profile b/etc/profile-m-z/nitroshare.profile index cefe9fa79..7a97ca825 100644 --- a/etc/profile-m-z/nitroshare.profile +++ b/etc/profile-m-z/nitroshare.profile | |||
@@ -41,7 +41,7 @@ disable-mnt | |||
41 | private-bin awk,grep,nitroshare,nitroshare-cli,nitroshare-nmh,nitroshare-send,nitroshare-ui | 41 | private-bin awk,grep,nitroshare,nitroshare-cli,nitroshare-nmh,nitroshare-send,nitroshare-ui |
42 | private-cache | 42 | private-cache |
43 | private-dev | 43 | private-dev |
44 | private-etc alternatives,ca-certificates,dconf,fonts,hostname,hosts,ld.so.cache,ld.so.preload,machine-id,nsswitch.conf,ssl | 44 | private-etc @tls-ca,@x11 |
45 | # private-lib libnitroshare.so.*,libqhttpengine.so.*,libqmdnsengine.so.*,nitroshare | 45 | # private-lib libnitroshare.so.*,libqhttpengine.so.*,libqmdnsengine.so.*,nitroshare |
46 | private-tmp | 46 | private-tmp |
47 | 47 | ||
diff --git a/etc/profile-m-z/nodejs-common.profile b/etc/profile-m-z/nodejs-common.profile index f185a04ee..f3b0c8a49 100644 --- a/etc/profile-m-z/nodejs-common.profile +++ b/etc/profile-m-z/nodejs-common.profile | |||
@@ -92,7 +92,7 @@ seccomp.block-secondary | |||
92 | 92 | ||
93 | disable-mnt | 93 | disable-mnt |
94 | private-dev | 94 | private-dev |
95 | private-etc alternatives,ca-certificates,crypto-policies,group,host.conf,hostname,hosts,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,locale,locale.alias,locale.conf,localtime,login.defs,mime.types,nsswitch.conf,passwd,pki,protocols,resolv.conf,rpc,services,ssl,xdg | 95 | private-etc @tls-ca,@x11,host.conf,mime.types,rpc,services |
96 | #private-tmp | 96 | #private-tmp |
97 | 97 | ||
98 | dbus-user none | 98 | dbus-user none |
diff --git a/etc/profile-m-z/nomacs.profile b/etc/profile-m-z/nomacs.profile index ac8336331..87373a02b 100644 --- a/etc/profile-m-z/nomacs.profile +++ b/etc/profile-m-z/nomacs.profile | |||
@@ -40,7 +40,7 @@ tracelog | |||
40 | #private-bin nomacs | 40 | #private-bin nomacs |
41 | private-cache | 41 | private-cache |
42 | private-dev | 42 | private-dev |
43 | private-etc alternatives,ca-certificates,crypto-policies,dconf,drirc,fonts,gtk-3.0,hosts,ld.so.cache,ld.so.preload,login.defs,machine-id,pki,resolv.conf,ssl | 43 | private-etc @tls-ca,@x11 |
44 | private-tmp | 44 | private-tmp |
45 | 45 | ||
46 | restrict-namespaces | 46 | restrict-namespaces |
diff --git a/etc/profile-m-z/notify-send.profile b/etc/profile-m-z/notify-send.profile index 11d6bd795..f0f2cca2e 100644 --- a/etc/profile-m-z/notify-send.profile +++ b/etc/profile-m-z/notify-send.profile | |||
@@ -48,7 +48,7 @@ private | |||
48 | private-bin notify-send | 48 | private-bin notify-send |
49 | private-cache | 49 | private-cache |
50 | private-dev | 50 | private-dev |
51 | private-etc alternatives,ld.so.cache,ld.so.preload | 51 | private-etc |
52 | private-tmp | 52 | private-tmp |
53 | 53 | ||
54 | dbus-user filter | 54 | dbus-user filter |
diff --git a/etc/profile-m-z/nslookup.profile b/etc/profile-m-z/nslookup.profile index 5866cda47..dcd76f2ad 100644 --- a/etc/profile-m-z/nslookup.profile +++ b/etc/profile-m-z/nslookup.profile | |||
@@ -45,7 +45,7 @@ tracelog | |||
45 | 45 | ||
46 | disable-mnt | 46 | disable-mnt |
47 | private-bin bash,nslookup,sh | 47 | private-bin bash,nslookup,sh |
48 | private-etc alternatives,ld.so.cache,ld.so.preload,login.defs,passwd,resolv.conf | 48 | private-etc |
49 | private-dev | 49 | private-dev |
50 | private-tmp | 50 | private-tmp |
51 | 51 | ||
diff --git a/etc/profile-m-z/nuclear.profile b/etc/profile-m-z/nuclear.profile index 9f4a6ec46..452cda5e5 100644 --- a/etc/profile-m-z/nuclear.profile +++ b/etc/profile-m-z/nuclear.profile | |||
@@ -18,7 +18,7 @@ whitelist ${HOME}/.config/nuclear | |||
18 | no3d | 18 | no3d |
19 | 19 | ||
20 | # private-bin nuclear | 20 | # private-bin nuclear |
21 | private-etc alsa,alternatives,asound.conf,ca-certificates,crypto-policies,fonts,gtk-2.0,gtk-3.0,host.conf,hostname,hosts,ld.so.cache,ld.so.preload,mime.types,nsswitch.conf,pki,pulse,resolv.conf,selinux,ssl,X11,xdg | 21 | private-etc @tls-ca,@x11,host.conf,mime.types,selinux |
22 | private-opt nuclear | 22 | private-opt nuclear |
23 | 23 | ||
24 | # Redirect | 24 | # Redirect |
diff --git a/etc/profile-m-z/nyx.profile b/etc/profile-m-z/nyx.profile index 4f767f046..4355fd0c7 100644 --- a/etc/profile-m-z/nyx.profile +++ b/etc/profile-m-z/nyx.profile | |||
@@ -44,7 +44,7 @@ disable-mnt | |||
44 | private-bin nyx,python* | 44 | private-bin nyx,python* |
45 | private-cache | 45 | private-cache |
46 | private-dev | 46 | private-dev |
47 | private-etc alternatives,fonts,ld.so.cache,ld.so.preload,passwd,tor | 47 | private-etc tor |
48 | private-opt none | 48 | private-opt none |
49 | private-srv none | 49 | private-srv none |
50 | private-tmp | 50 | private-tmp |
diff --git a/etc/profile-m-z/ocenaudio.profile b/etc/profile-m-z/ocenaudio.profile index 87c665cba..830483bd4 100644 --- a/etc/profile-m-z/ocenaudio.profile +++ b/etc/profile-m-z/ocenaudio.profile | |||
@@ -53,7 +53,7 @@ tracelog | |||
53 | private-bin ocenaudio,ocenvst | 53 | private-bin ocenaudio,ocenvst |
54 | private-cache | 54 | private-cache |
55 | private-dev | 55 | private-dev |
56 | private-etc alternatives,asound.conf,ca-certificates,crypto-policies,dconf,fonts,group,gtk-2.0,gtk-3.0,hostname,hosts,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,mime.types,nsswitch.conf,pki,pulse,resolv.conf,ssl,X11,xdg | 56 | private-etc @tls-ca,@x11,mime.types |
57 | private-opt ocenaudio | 57 | private-opt ocenaudio |
58 | private-tmp | 58 | private-tmp |
59 | 59 | ||
diff --git a/etc/profile-m-z/odt2txt.profile b/etc/profile-m-z/odt2txt.profile index 25da2139f..73b72efc2 100644 --- a/etc/profile-m-z/odt2txt.profile +++ b/etc/profile-m-z/odt2txt.profile | |||
@@ -37,7 +37,7 @@ x11 none | |||
37 | private-bin odt2txt | 37 | private-bin odt2txt |
38 | private-cache | 38 | private-cache |
39 | private-dev | 39 | private-dev |
40 | private-etc alternatives,ld.so.cache,ld.so.preload | 40 | private-etc |
41 | private-tmp | 41 | private-tmp |
42 | 42 | ||
43 | dbus-user none | 43 | dbus-user none |
diff --git a/etc/profile-m-z/okular.profile b/etc/profile-m-z/okular.profile index 568b6566e..8e0758c37 100644 --- a/etc/profile-m-z/okular.profile +++ b/etc/profile-m-z/okular.profile | |||
@@ -61,7 +61,7 @@ tracelog | |||
61 | 61 | ||
62 | private-bin kbuildsycoca4,kdeinit4,lpr,okular,unar,unrar | 62 | private-bin kbuildsycoca4,kdeinit4,lpr,okular,unar,unrar |
63 | private-dev | 63 | private-dev |
64 | private-etc alternatives,cups,fonts,kde4rc,kde5rc,ld.so.cache,ld.so.preload,machine-id,passwd,xdg | 64 | private-etc @x11,cups |
65 | # private-tmp - on KDE we need access to the real /tmp for data exchange with email clients | 65 | # private-tmp - on KDE we need access to the real /tmp for data exchange with email clients |
66 | 66 | ||
67 | # dbus-user none | 67 | # dbus-user none |
diff --git a/etc/profile-m-z/onboard.profile b/etc/profile-m-z/onboard.profile index 913b499d3..a142598b7 100644 --- a/etc/profile-m-z/onboard.profile +++ b/etc/profile-m-z/onboard.profile | |||
@@ -49,7 +49,7 @@ disable-mnt | |||
49 | private-cache | 49 | private-cache |
50 | private-bin onboard,python*,tput | 50 | private-bin onboard,python*,tput |
51 | private-dev | 51 | private-dev |
52 | private-etc alternatives,dbus-1,dconf,fonts,gtk-2.0,gtk-3.0,ld.so.cache,ld.so.preload,locale,locale.alias,locale.conf,mime.types,selinux,X11,xdg | 52 | private-etc @x11,dbus-1,mime.types,selinux |
53 | private-tmp | 53 | private-tmp |
54 | 54 | ||
55 | dbus-system none | 55 | dbus-system none |
diff --git a/etc/profile-m-z/openarena.profile b/etc/profile-m-z/openarena.profile index 053f54b48..1600db144 100644 --- a/etc/profile-m-z/openarena.profile +++ b/etc/profile-m-z/openarena.profile | |||
@@ -42,7 +42,7 @@ disable-mnt | |||
42 | private-bin bash,cut,glxinfo,grep,head,openarena,openarena_ded,quake3,zenity | 42 | private-bin bash,cut,glxinfo,grep,head,openarena,openarena_ded,quake3,zenity |
43 | private-cache | 43 | private-cache |
44 | private-dev | 44 | private-dev |
45 | private-etc alternatives,drirc,ld.so.cache,ld.so.preload,machine-id,openal,passwd,selinux,udev,xdg | 45 | private-etc @games,@x11,selinux,udev |
46 | private-tmp | 46 | private-tmp |
47 | 47 | ||
48 | dbus-user none | 48 | dbus-user none |
diff --git a/etc/profile-m-z/openmw.profile b/etc/profile-m-z/openmw.profile index be97552ab..507d6d634 100644 --- a/etc/profile-m-z/openmw.profile +++ b/etc/profile-m-z/openmw.profile | |||
@@ -52,7 +52,7 @@ tracelog | |||
52 | private-bin bsatool,esmtool,niftest,openmw,openmw-cs,openmw-essimporter,openmw-iniimporter,openmw-launcher,openmw-wizard | 52 | private-bin bsatool,esmtool,niftest,openmw,openmw-cs,openmw-essimporter,openmw-iniimporter,openmw-launcher,openmw-wizard |
53 | private-cache | 53 | private-cache |
54 | private-dev | 54 | private-dev |
55 | private-etc alsa,alternatives,asound.conf,bumblebee,drirc,fonts,glvnd,group,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,locale,locale.alias,locale.conf,localtime,machine-id,mime.types,nvidia,openmw,pango,passwd,pulse,Trolltech.conf,X11,xdg | 55 | private-etc @x11,bumblebee,glvnd,mime.types,openmw,Trolltech.conf |
56 | private-opt none | 56 | private-opt none |
57 | private-tmp | 57 | private-tmp |
58 | 58 | ||
diff --git a/etc/profile-m-z/otter-browser.profile b/etc/profile-m-z/otter-browser.profile index 028c6fe90..420ceece3 100644 --- a/etc/profile-m-z/otter-browser.profile +++ b/etc/profile-m-z/otter-browser.profile | |||
@@ -52,7 +52,7 @@ disable-mnt | |||
52 | private-bin bash,otter-browser,sh,which | 52 | private-bin bash,otter-browser,sh,which |
53 | private-cache | 53 | private-cache |
54 | ?BROWSER_DISABLE_U2F: private-dev | 54 | ?BROWSER_DISABLE_U2F: private-dev |
55 | private-etc alternatives,asound.conf,ca-certificates,crypto-policies,dconf,fonts,group,gtk-2.0,gtk-3.0,hostname,hosts,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,localtime,machine-id,mailcap,mime.types,nsswitch.conf,pango,passwd,pki,pulse,resolv.conf,selinux,ssl,X11,xdg | 55 | private-etc @tls-ca,@x11,mailcap,mime.types,selinux |
56 | private-tmp | 56 | private-tmp |
57 | 57 | ||
58 | dbus-system none | 58 | dbus-system none |
diff --git a/etc/profile-m-z/pandoc.profile b/etc/profile-m-z/pandoc.profile index 2610ae67a..0a906718a 100644 --- a/etc/profile-m-z/pandoc.profile +++ b/etc/profile-m-z/pandoc.profile | |||
@@ -49,7 +49,7 @@ x11 none | |||
49 | disable-mnt | 49 | disable-mnt |
50 | private-cache | 50 | private-cache |
51 | private-dev | 51 | private-dev |
52 | private-etc alternatives,ld.so.cache,ld.so.preload,texlive,texmf | 52 | private-etc texlive,texmf |
53 | private-tmp | 53 | private-tmp |
54 | 54 | ||
55 | dbus-user none | 55 | dbus-user none |
diff --git a/etc/profile-m-z/parole.profile b/etc/profile-m-z/parole.profile index fb629669a..662896530 100644 --- a/etc/profile-m-z/parole.profile +++ b/etc/profile-m-z/parole.profile | |||
@@ -26,6 +26,6 @@ seccomp | |||
26 | 26 | ||
27 | private-bin dbus-launch,parole | 27 | private-bin dbus-launch,parole |
28 | private-cache | 28 | private-cache |
29 | private-etc alternatives,asound.conf,ca-certificates,crypto-policies,fonts,group,ld.so.cache,ld.so.preload,machine-id,passwd,pki,pulse,ssl | 29 | private-etc @tls-ca |
30 | 30 | ||
31 | restrict-namespaces | 31 | restrict-namespaces |
diff --git a/etc/profile-m-z/pavucontrol.profile b/etc/profile-m-z/pavucontrol.profile index 1780f982c..196ce424d 100644 --- a/etc/profile-m-z/pavucontrol.profile +++ b/etc/profile-m-z/pavucontrol.profile | |||
@@ -44,7 +44,7 @@ disable-mnt | |||
44 | private-bin pavucontrol | 44 | private-bin pavucontrol |
45 | private-cache | 45 | private-cache |
46 | private-dev | 46 | private-dev |
47 | private-etc alternatives,asound.conf,avahi,fonts,ld.so.cache,ld.so.preload,machine-id,pulse,resolv.conf | 47 | private-etc avahi |
48 | private-lib | 48 | private-lib |
49 | private-tmp | 49 | private-tmp |
50 | 50 | ||
diff --git a/etc/profile-m-z/pcsxr.profile b/etc/profile-m-z/pcsxr.profile index 784d82736..5b3cf0fef 100644 --- a/etc/profile-m-z/pcsxr.profile +++ b/etc/profile-m-z/pcsxr.profile | |||
@@ -47,7 +47,7 @@ private-bin pcsxr | |||
47 | private-cache | 47 | private-cache |
48 | # Add the next line to your pcsxr.local if you do not need controller support. | 48 | # Add the next line to your pcsxr.local if you do not need controller support. |
49 | #private-dev | 49 | #private-dev |
50 | private-etc alsa,alternatives,asound.conf,bumblebee,ca-certificates,crypto-policies,dconf,drirc,fonts,gconf,glvnd,gtk-2.0,gtk-3.0,host.conf,hostname,hosts,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,locale,locale.alias,locale.conf,localtime,machine-id,mime.types,nsswitch.conf,nvidia,pango,pki,protocols,pulse,resolv.conf,rpc,services,ssl,X11,xdg | 50 | private-etc @tls-ca,@x11,bumblebee,gconf,glvnd,host.conf,mime.types,rpc,services |
51 | private-opt none | 51 | private-opt none |
52 | private-tmp | 52 | private-tmp |
53 | 53 | ||
diff --git a/etc/profile-m-z/pdfchain.profile b/etc/profile-m-z/pdfchain.profile index 2e38dde3b..0ab006084 100644 --- a/etc/profile-m-z/pdfchain.profile +++ b/etc/profile-m-z/pdfchain.profile | |||
@@ -33,7 +33,7 @@ seccomp | |||
33 | 33 | ||
34 | private-bin pdfchain,pdftk,sh | 34 | private-bin pdfchain,pdftk,sh |
35 | private-dev | 35 | private-dev |
36 | private-etc alternatives,dconf,fonts,gtk-3.0,ld.so.cache,ld.so.preload,xdg | 36 | private-etc @x11 |
37 | private-tmp | 37 | private-tmp |
38 | 38 | ||
39 | dbus-user none | 39 | dbus-user none |
diff --git a/etc/profile-m-z/pdftotext.profile b/etc/profile-m-z/pdftotext.profile index 7ece10835..cb7e0809f 100644 --- a/etc/profile-m-z/pdftotext.profile +++ b/etc/profile-m-z/pdftotext.profile | |||
@@ -48,7 +48,7 @@ x11 none | |||
48 | private-bin pdftotext | 48 | private-bin pdftotext |
49 | private-cache | 49 | private-cache |
50 | private-dev | 50 | private-dev |
51 | private-etc alternatives,ld.so.cache,ld.so.preload | 51 | private-etc |
52 | private-tmp | 52 | private-tmp |
53 | 53 | ||
54 | dbus-user none | 54 | dbus-user none |
diff --git a/etc/profile-m-z/peek.profile b/etc/profile-m-z/peek.profile index 24a1bc979..96744e019 100644 --- a/etc/profile-m-z/peek.profile +++ b/etc/profile-m-z/peek.profile | |||
@@ -47,7 +47,7 @@ tracelog | |||
47 | disable-mnt | 47 | disable-mnt |
48 | private-bin bash,convert,ffmpeg,firejail,fish,peek,sh,which,zsh | 48 | private-bin bash,convert,ffmpeg,firejail,fish,peek,sh,which,zsh |
49 | private-dev | 49 | private-dev |
50 | private-etc alternatives,dconf,firejail,fonts,gtk-3.0,ld.so.cache,ld.so.preload,login.defs,pango,passwd,X11 | 50 | private-etc @x11,firejail |
51 | private-tmp | 51 | private-tmp |
52 | 52 | ||
53 | dbus-user filter | 53 | dbus-user filter |
diff --git a/etc/profile-m-z/photoflare.profile b/etc/profile-m-z/photoflare.profile index dcb52c846..5261093d2 100644 --- a/etc/profile-m-z/photoflare.profile +++ b/etc/profile-m-z/photoflare.profile | |||
@@ -42,7 +42,7 @@ disable-mnt | |||
42 | private-bin photoflare | 42 | private-bin photoflare |
43 | private-cache | 43 | private-cache |
44 | private-dev | 44 | private-dev |
45 | private-etc alternatives,fonts,ld.so.cache,ld.so.preload,locale,locale.alias,locale.conf,mime.types,X11 | 45 | private-etc @x11,mime.types |
46 | private-tmp | 46 | private-tmp |
47 | 47 | ||
48 | dbus-user none | 48 | dbus-user none |
diff --git a/etc/profile-m-z/pinball.profile b/etc/profile-m-z/pinball.profile index 3664e1469..08aa67bf7 100644 --- a/etc/profile-m-z/pinball.profile +++ b/etc/profile-m-z/pinball.profile | |||
@@ -47,7 +47,7 @@ disable-mnt | |||
47 | private-bin pinball | 47 | private-bin pinball |
48 | private-cache | 48 | private-cache |
49 | private-dev | 49 | private-dev |
50 | private-etc alsa,alternatives,asound.conf,fonts,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,locale,machine-id,pulse | 50 | private-etc |
51 | private-tmp | 51 | private-tmp |
52 | 52 | ||
53 | dbus-user none | 53 | dbus-user none |
diff --git a/etc/profile-m-z/ping.profile b/etc/profile-m-z/ping.profile index ddb8ff867..dbb333afb 100644 --- a/etc/profile-m-z/ping.profile +++ b/etc/profile-m-z/ping.profile | |||
@@ -56,7 +56,7 @@ private | |||
56 | #private-bin ping - has mammoth problems with execvp: "No such file or directory" | 56 | #private-bin ping - has mammoth problems with execvp: "No such file or directory" |
57 | private-cache | 57 | private-cache |
58 | private-dev | 58 | private-dev |
59 | private-etc alternatives,ca-certificates,crypto-policies,hosts,ld.so.cache,ld.so.preload,login.defs,passwd,pki,resolv.conf,ssl | 59 | private-etc @tls-ca |
60 | private-lib | 60 | private-lib |
61 | private-tmp | 61 | private-tmp |
62 | 62 | ||
diff --git a/etc/profile-m-z/pingus.profile b/etc/profile-m-z/pingus.profile index a86b6da04..3ff033e0b 100644 --- a/etc/profile-m-z/pingus.profile +++ b/etc/profile-m-z/pingus.profile | |||
@@ -50,7 +50,7 @@ disable-mnt | |||
50 | private-bin pingus,pingus.bin,sh | 50 | private-bin pingus,pingus.bin,sh |
51 | private-cache | 51 | private-cache |
52 | private-dev | 52 | private-dev |
53 | private-etc alternatives,ld.so.cache,ld.so.preload,machine-id | 53 | private-etc |
54 | private-tmp | 54 | private-tmp |
55 | 55 | ||
56 | dbus-user none | 56 | dbus-user none |
diff --git a/etc/profile-m-z/pkglog.profile b/etc/profile-m-z/pkglog.profile index 88173edca..799c8f607 100644 --- a/etc/profile-m-z/pkglog.profile +++ b/etc/profile-m-z/pkglog.profile | |||
@@ -43,7 +43,7 @@ private | |||
43 | private-bin pkglog,python* | 43 | private-bin pkglog,python* |
44 | private-cache | 44 | private-cache |
45 | private-dev | 45 | private-dev |
46 | private-etc alternatives,ld.so.cache,ld.so.preload | 46 | private-etc |
47 | private-opt none | 47 | private-opt none |
48 | private-tmp | 48 | private-tmp |
49 | writable-var-log | 49 | writable-var-log |
diff --git a/etc/profile-m-z/plv.profile b/etc/profile-m-z/plv.profile index 62927f9f7..34e18cbd7 100644 --- a/etc/profile-m-z/plv.profile +++ b/etc/profile-m-z/plv.profile | |||
@@ -45,7 +45,7 @@ disable-mnt | |||
45 | private-bin plv | 45 | private-bin plv |
46 | private-cache | 46 | private-cache |
47 | private-dev | 47 | private-dev |
48 | private-etc alternatives,fonts,ld.so.cache,ld.so.preload | 48 | private-etc |
49 | private-opt none | 49 | private-opt none |
50 | private-tmp | 50 | private-tmp |
51 | writable-var-log | 51 | writable-var-log |
diff --git a/etc/profile-m-z/pngquant.profile b/etc/profile-m-z/pngquant.profile index 8e2c39b83..34199a08d 100644 --- a/etc/profile-m-z/pngquant.profile +++ b/etc/profile-m-z/pngquant.profile | |||
@@ -46,7 +46,7 @@ x11 none | |||
46 | private-bin pngquant | 46 | private-bin pngquant |
47 | private-cache | 47 | private-cache |
48 | private-dev | 48 | private-dev |
49 | private-etc alternatives,ld.so.cache,ld.so.preload | 49 | private-etc |
50 | private-tmp | 50 | private-tmp |
51 | 51 | ||
52 | dbus-user none | 52 | dbus-user none |
diff --git a/etc/profile-m-z/ppsspp.profile b/etc/profile-m-z/ppsspp.profile index 58528c372..da16ae912 100644 --- a/etc/profile-m-z/ppsspp.profile +++ b/etc/profile-m-z/ppsspp.profile | |||
@@ -42,7 +42,7 @@ seccomp | |||
42 | private-bin ppsspp,PPSSPP,PPSSPPQt,PPSSPPSDL | 42 | private-bin ppsspp,PPSSPP,PPSSPPQt,PPSSPPSDL |
43 | # Add the next line to your ppsspp.local if you do not need controller support. | 43 | # Add the next line to your ppsspp.local if you do not need controller support. |
44 | #private-dev | 44 | #private-dev |
45 | private-etc alternatives,asound.conf,ca-certificates,crypto-policies,drirc,fonts,group,host.conf,hostname,hosts,ld.so.cache,ld.so.preload,localtime,machine-id,nsswitch.conf,passwd,pki,pulse,resolv.conf,ssl | 45 | private-etc @tls-ca,@x11,host.conf |
46 | private-opt ppsspp | 46 | private-opt ppsspp |
47 | private-tmp | 47 | private-tmp |
48 | 48 | ||
diff --git a/etc/profile-m-z/pragha.profile b/etc/profile-m-z/pragha.profile index 73b377712..6d766b212 100644 --- a/etc/profile-m-z/pragha.profile +++ b/etc/profile-m-z/pragha.profile | |||
@@ -32,7 +32,7 @@ protocol unix,inet,inet6 | |||
32 | seccomp | 32 | seccomp |
33 | 33 | ||
34 | private-dev | 34 | private-dev |
35 | private-etc alternatives,asound.conf,ca-certificates,crypto-policies,fonts,gtk-3.0,host.conf,hostname,hosts,ld.so.cache,ld.so.preload,machine-id,pki,pulse,resolv.conf,ssl,xdg | 35 | private-etc @tls-ca,@x11,host.conf |
36 | private-tmp | 36 | private-tmp |
37 | 37 | ||
38 | restrict-namespaces | 38 | restrict-namespaces |
diff --git a/etc/profile-m-z/profanity.profile b/etc/profile-m-z/profanity.profile index 279536bb9..c866c3d16 100644 --- a/etc/profile-m-z/profanity.profile +++ b/etc/profile-m-z/profanity.profile | |||
@@ -43,7 +43,7 @@ seccomp | |||
43 | private-bin profanity | 43 | private-bin profanity |
44 | private-cache | 44 | private-cache |
45 | private-dev | 45 | private-dev |
46 | private-etc alternatives,ca-certificates,crypto-policies,ld.so.cache,ld.so.preload,localtime,mime.types,nsswitch.conf,pki,resolv.conf,ssl | 46 | private-etc @tls-ca,mime.types |
47 | private-tmp | 47 | private-tmp |
48 | 48 | ||
49 | dbus-user filter | 49 | dbus-user filter |
diff --git a/etc/profile-m-z/psi.profile b/etc/profile-m-z/psi.profile index be06c5d89..9d9d6e6c5 100644 --- a/etc/profile-m-z/psi.profile +++ b/etc/profile-m-z/psi.profile | |||
@@ -70,7 +70,7 @@ disable-mnt | |||
70 | private-bin getopt,psi | 70 | private-bin getopt,psi |
71 | private-cache | 71 | private-cache |
72 | private-dev | 72 | private-dev |
73 | private-etc alsa,alternatives,asound.conf,ca-certificates,crypto-policies,drirc,fonts,gcrypt,group,hostname,hosts,ld.so.cache,ld.so.conf,ld.so.preload,machine-id,passwd,pki,pulse,resolv.conf,selinux,ssl,xdg | 73 | private-etc @tls-ca,@x11,selinux |
74 | private-tmp | 74 | private-tmp |
75 | 75 | ||
76 | dbus-user none | 76 | dbus-user none |
diff --git a/etc/profile-m-z/pybitmessage.profile b/etc/profile-m-z/pybitmessage.profile index ba71ab29d..e057ee565 100644 --- a/etc/profile-m-z/pybitmessage.profile +++ b/etc/profile-m-z/pybitmessage.profile | |||
@@ -40,7 +40,7 @@ seccomp | |||
40 | disable-mnt | 40 | disable-mnt |
41 | private-bin bash,env,ldconfig,pybitmessage,python*,sh,stat | 41 | private-bin bash,env,ldconfig,pybitmessage,python*,sh,stat |
42 | private-dev | 42 | private-dev |
43 | private-etc alternatives,ca-certificates,crypto-policies,fonts,gtk-2.0,hosts,ld.so.cache,ld.so.preload,localtime,pki,pki,PyBitmessage,PyBitmessage.conf,resolv.conf,selinux,sni-qt.conf,ssl,system-fips,Trolltech.conf,xdg | 43 | private-etc @tls-ca,@x11,PyBitmessage,PyBitmessage.conf,selinux,sni-qt.conf,system-fips,Trolltech.conf |
44 | private-tmp | 44 | private-tmp |
45 | 45 | ||
46 | restrict-namespaces | 46 | restrict-namespaces |
diff --git a/etc/profile-m-z/qcomicbook.profile b/etc/profile-m-z/qcomicbook.profile index 71374a8c8..cb807c69e 100644 --- a/etc/profile-m-z/qcomicbook.profile +++ b/etc/profile-m-z/qcomicbook.profile | |||
@@ -52,7 +52,7 @@ tracelog | |||
52 | private-bin 7z,7zr,qcomicbook,rar,sh,tar,unace,unrar,unzip | 52 | private-bin 7z,7zr,qcomicbook,rar,sh,tar,unace,unrar,unzip |
53 | private-cache | 53 | private-cache |
54 | private-dev | 54 | private-dev |
55 | private-etc alternatives,fonts,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,locale,locale.alias,locale.conf,localtime,machine-id,mime.types,pango,passwd,Trolltech.conf,X11,xdg | 55 | private-etc @x11,mime.types,Trolltech.conf |
56 | private-tmp | 56 | private-tmp |
57 | 57 | ||
58 | dbus-user none | 58 | dbus-user none |
diff --git a/etc/profile-m-z/qgis.profile b/etc/profile-m-z/qgis.profile index d4b71f972..9635c2e06 100644 --- a/etc/profile-m-z/qgis.profile +++ b/etc/profile-m-z/qgis.profile | |||
@@ -51,7 +51,7 @@ tracelog | |||
51 | disable-mnt | 51 | disable-mnt |
52 | private-cache | 52 | private-cache |
53 | private-dev | 53 | private-dev |
54 | private-etc alternatives,ca-certificates,crypto-policies,fonts,ld.so.cache,ld.so.preload,machine-id,pki,QGIS,QGIS.conf,resolv.conf,ssl,Trolltech.conf | 54 | private-etc @tls-ca,QGIS,QGIS.conf,Trolltech.conf |
55 | private-tmp | 55 | private-tmp |
56 | 56 | ||
57 | dbus-user none | 57 | dbus-user none |
diff --git a/etc/profile-m-z/qnapi.profile b/etc/profile-m-z/qnapi.profile index cafdb98e9..1cfbaee6a 100644 --- a/etc/profile-m-z/qnapi.profile +++ b/etc/profile-m-z/qnapi.profile | |||
@@ -46,7 +46,7 @@ tracelog | |||
46 | private-bin 7z,qnapi | 46 | private-bin 7z,qnapi |
47 | private-cache | 47 | private-cache |
48 | private-dev | 48 | private-dev |
49 | private-etc alternatives,fonts,ld.so.cache,ld.so.preload,resolv.conf | 49 | private-etc |
50 | private-opt none | 50 | private-opt none |
51 | private-tmp | 51 | private-tmp |
52 | 52 | ||
diff --git a/etc/profile-m-z/qrencode.profile b/etc/profile-m-z/qrencode.profile index 09b70756b..42c098487 100644 --- a/etc/profile-m-z/qrencode.profile +++ b/etc/profile-m-z/qrencode.profile | |||
@@ -46,7 +46,7 @@ disable-mnt | |||
46 | private-bin qrencode | 46 | private-bin qrencode |
47 | private-cache | 47 | private-cache |
48 | private-dev | 48 | private-dev |
49 | private-etc alternatives,ld.so.cache,ld.so.preload | 49 | private-etc |
50 | private-lib libpcre* | 50 | private-lib libpcre* |
51 | private-tmp | 51 | private-tmp |
52 | 52 | ||
diff --git a/etc/profile-m-z/qtox.profile b/etc/profile-m-z/qtox.profile index f95720d71..ab0f9425a 100644 --- a/etc/profile-m-z/qtox.profile +++ b/etc/profile-m-z/qtox.profile | |||
@@ -42,7 +42,7 @@ disable-mnt | |||
42 | private-bin qtox | 42 | private-bin qtox |
43 | private-cache | 43 | private-cache |
44 | private-dev | 44 | private-dev |
45 | private-etc alternatives,ca-certificates,crypto-policies,fonts,ld.so.cache,ld.so.preload,localtime,machine-id,pki,pulse,resolv.conf,ssl | 45 | private-etc @tls-ca |
46 | private-tmp | 46 | private-tmp |
47 | 47 | ||
48 | dbus-user none | 48 | dbus-user none |
diff --git a/etc/profile-m-z/quaternion.profile b/etc/profile-m-z/quaternion.profile index ad45a26d5..ddd4800d8 100644 --- a/etc/profile-m-z/quaternion.profile +++ b/etc/profile-m-z/quaternion.profile | |||
@@ -46,7 +46,7 @@ disable-mnt | |||
46 | private-bin quaternion | 46 | private-bin quaternion |
47 | private-cache | 47 | private-cache |
48 | private-dev | 48 | private-dev |
49 | private-etc alsa,alternatives,asound.conf,ca-certificates,crypto-policies,fonts,gtk-2.0,gtk-3.0,host.conf,hostname,hosts,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,locale,locale.alias,locale.conf,mime.types,nsswitch.conf,pki,pulse,resolv.conf,selinux,ssl,X11,xdg | 49 | private-etc @tls-ca,@x11,host.conf,mime.types,selinux |
50 | private-tmp | 50 | private-tmp |
51 | 51 | ||
52 | dbus-user none | 52 | dbus-user none |
diff --git a/etc/profile-m-z/quodlibet.profile b/etc/profile-m-z/quodlibet.profile index ea49684e3..56bfaa917 100644 --- a/etc/profile-m-z/quodlibet.profile +++ b/etc/profile-m-z/quodlibet.profile | |||
@@ -59,7 +59,7 @@ tracelog | |||
59 | private-bin exfalso,operon,python*,quodlibet,sh | 59 | private-bin exfalso,operon,python*,quodlibet,sh |
60 | private-cache | 60 | private-cache |
61 | private-dev | 61 | private-dev |
62 | private-etc alsa,alternatives,asound.conf,ca-certificates,crypto-policies,dconf,fonts,gtk-3.0,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,passwd,pki,pulse,resolv.conf,ssl | 62 | private-etc @tls-ca,@x11 |
63 | private-tmp | 63 | private-tmp |
64 | 64 | ||
65 | dbus-system none | 65 | dbus-system none |
diff --git a/etc/profile-m-z/qutebrowser.profile b/etc/profile-m-z/qutebrowser.profile index ea0e2afa7..e83484ae5 100644 --- a/etc/profile-m-z/qutebrowser.profile +++ b/etc/profile-m-z/qutebrowser.profile | |||
@@ -56,7 +56,7 @@ seccomp !chroot,!name_to_handle_at | |||
56 | disable-mnt | 56 | disable-mnt |
57 | private-cache | 57 | private-cache |
58 | private-dev | 58 | private-dev |
59 | private-etc alternatives,ca-certificates,crypto-policies,fonts,ld.so.cache,ld.so.preload,localtime,machine-id,passwd,pki,pulse,resolv.conf,ssl | 59 | private-etc @tls-ca |
60 | private-tmp | 60 | private-tmp |
61 | 61 | ||
62 | dbus-user filter | 62 | dbus-user filter |
diff --git a/etc/profile-m-z/raincat.profile b/etc/profile-m-z/raincat.profile index e320d82f7..72c5f3979 100644 --- a/etc/profile-m-z/raincat.profile +++ b/etc/profile-m-z/raincat.profile | |||
@@ -39,7 +39,7 @@ private | |||
39 | private-bin raincat | 39 | private-bin raincat |
40 | private-cache | 40 | private-cache |
41 | private-dev | 41 | private-dev |
42 | private-etc alternatives,drirc,ld.so.cache,ld.so.preload,machine-id,passwd,pulse,timidity,timidity.cfg | 42 | private-etc @games,@x11 |
43 | #private-lib | 43 | #private-lib |
44 | private-tmp | 44 | private-tmp |
45 | 45 | ||
diff --git a/etc/profile-m-z/rednotebook.profile b/etc/profile-m-z/rednotebook.profile index 1295ce00d..e0dea194a 100644 --- a/etc/profile-m-z/rednotebook.profile +++ b/etc/profile-m-z/rednotebook.profile | |||
@@ -58,7 +58,7 @@ disable-mnt | |||
58 | private-bin python3*,rednotebook | 58 | private-bin python3*,rednotebook |
59 | private-cache | 59 | private-cache |
60 | private-dev | 60 | private-dev |
61 | private-etc alternatives,fonts,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,pango,X11 | 61 | private-etc @x11 |
62 | private-tmp | 62 | private-tmp |
63 | 63 | ||
64 | dbus-user none | 64 | dbus-user none |
diff --git a/etc/profile-m-z/regextester.profile b/etc/profile-m-z/regextester.profile index 571381f57..2e962b1ea 100644 --- a/etc/profile-m-z/regextester.profile +++ b/etc/profile-m-z/regextester.profile | |||
@@ -42,7 +42,7 @@ disable-mnt | |||
42 | private-bin regextester | 42 | private-bin regextester |
43 | private-cache | 43 | private-cache |
44 | private-dev | 44 | private-dev |
45 | private-etc alternatives,fonts,ld.so.cache,ld.so.preload | 45 | private-etc |
46 | private-lib libgranite.so.* | 46 | private-lib libgranite.so.* |
47 | private-tmp | 47 | private-tmp |
48 | 48 | ||
diff --git a/etc/profile-m-z/rsync-download_only.profile b/etc/profile-m-z/rsync-download_only.profile index 91b18678f..c908319ca 100644 --- a/etc/profile-m-z/rsync-download_only.profile +++ b/etc/profile-m-z/rsync-download_only.profile | |||
@@ -48,7 +48,7 @@ disable-mnt | |||
48 | private-bin rsync | 48 | private-bin rsync |
49 | private-cache | 49 | private-cache |
50 | private-dev | 50 | private-dev |
51 | private-etc alternatives,ca-certificates,crypto-policies,host.conf,hostname,hosts,ld.so.cache,ld.so.preload,nsswitch.conf,pki,protocols,resolv.conf,rpc,services,ssl | 51 | private-etc @tls-ca,host.conf,rpc,services |
52 | private-tmp | 52 | private-tmp |
53 | 53 | ||
54 | dbus-user none | 54 | dbus-user none |
diff --git a/etc/profile-m-z/rtv.profile b/etc/profile-m-z/rtv.profile index 565925e7a..0d57e6916 100644 --- a/etc/profile-m-z/rtv.profile +++ b/etc/profile-m-z/rtv.profile | |||
@@ -58,7 +58,7 @@ disable-mnt | |||
58 | private-bin less,python*,rtv,sh,xdg-settings | 58 | private-bin less,python*,rtv,sh,xdg-settings |
59 | private-cache | 59 | private-cache |
60 | private-dev | 60 | private-dev |
61 | private-etc alternatives,ca-certificates,crypto-policies,host.conf,hostname,hosts,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,locale,locale.alias,locale.conf,localtime,mailcap,mime.types,nsswitch.conf,pki,protocols,resolv.conf,rpc,services,ssl,terminfo,xdg | 61 | private-etc @tls-ca,@x11,host.conf,mailcap,mime.types,rpc,services,terminfo |
62 | 62 | ||
63 | dbus-user none | 63 | dbus-user none |
64 | dbus-system none | 64 | dbus-system none |
diff --git a/etc/profile-m-z/scorchwentbonkers.profile b/etc/profile-m-z/scorchwentbonkers.profile index 6dfb50c5a..fb4325264 100644 --- a/etc/profile-m-z/scorchwentbonkers.profile +++ b/etc/profile-m-z/scorchwentbonkers.profile | |||
@@ -42,7 +42,7 @@ disable-mnt | |||
42 | private-bin scorchwentbonkers | 42 | private-bin scorchwentbonkers |
43 | private-cache | 43 | private-cache |
44 | private-dev | 44 | private-dev |
45 | private-etc alsa,alternatives,asound.conf,ld.so.cache,ld.so.preload,machine-id,pulse | 45 | private-etc |
46 | private-tmp | 46 | private-tmp |
47 | 47 | ||
48 | dbus-user none | 48 | dbus-user none |
diff --git a/etc/profile-m-z/seafile-applet.profile b/etc/profile-m-z/seafile-applet.profile index 184a06958..bbf46fe19 100644 --- a/etc/profile-m-z/seafile-applet.profile +++ b/etc/profile-m-z/seafile-applet.profile | |||
@@ -53,7 +53,7 @@ disable-mnt | |||
53 | private-bin seaf-cli,seaf-daemon,seafile-applet | 53 | private-bin seaf-cli,seaf-daemon,seafile-applet |
54 | private-cache | 54 | private-cache |
55 | private-dev | 55 | private-dev |
56 | private-etc alternatives,ca-certificates,crypto-policies,host.conf,hostname,hosts,ld.so.cache,ld.so.preload,nsswitch.conf,pki,protocols,resolv.conf,rpc,services,ssl | 56 | private-etc @tls-ca,host.conf,rpc,services |
57 | #private-opt none | 57 | #private-opt none |
58 | private-tmp | 58 | private-tmp |
59 | 59 | ||
diff --git a/etc/profile-m-z/seahorse-adventures.profile b/etc/profile-m-z/seahorse-adventures.profile index 7ff252ec7..5985e0da3 100644 --- a/etc/profile-m-z/seahorse-adventures.profile +++ b/etc/profile-m-z/seahorse-adventures.profile | |||
@@ -47,7 +47,7 @@ private | |||
47 | private-bin bash,dash,python*,seahorse-adventures,sh | 47 | private-bin bash,dash,python*,seahorse-adventures,sh |
48 | private-cache | 48 | private-cache |
49 | private-dev | 49 | private-dev |
50 | private-etc alternatives,ld.so.cache,ld.so.preload,machine-id | 50 | private-etc |
51 | private-tmp | 51 | private-tmp |
52 | 52 | ||
53 | dbus-user none | 53 | dbus-user none |
diff --git a/etc/profile-m-z/seahorse.profile b/etc/profile-m-z/seahorse.profile index e6f51bff9..190082461 100644 --- a/etc/profile-m-z/seahorse.profile +++ b/etc/profile-m-z/seahorse.profile | |||
@@ -57,7 +57,7 @@ tracelog | |||
57 | disable-mnt | 57 | disable-mnt |
58 | private-cache | 58 | private-cache |
59 | private-dev | 59 | private-dev |
60 | private-etc alternatives,ca-certificates,crypto-policies,dconf,fonts,gconf,gtk-2.0,gtk-3.0,host.conf,hostname,hosts,ld.so.cache,ld.so.preload,login.defs,nsswitch.conf,pango,passwd,pkcs11,pki,protocols,resolv.conf,rpc,services,ssh,ssl,xdg | 60 | private-etc @tls-ca,@x11,gconf,host.conf,pkcs11,rpc,services,ssh |
61 | private-tmp | 61 | private-tmp |
62 | writable-run-user | 62 | writable-run-user |
63 | 63 | ||
diff --git a/etc/profile-m-z/shortwave.profile b/etc/profile-m-z/shortwave.profile index cd2a9f13e..87621de69 100644 --- a/etc/profile-m-z/shortwave.profile +++ b/etc/profile-m-z/shortwave.profile | |||
@@ -45,7 +45,7 @@ disable-mnt | |||
45 | private-bin shortwave | 45 | private-bin shortwave |
46 | private-cache | 46 | private-cache |
47 | private-dev | 47 | private-dev |
48 | private-etc alsa,alternatives,asound.conf,ca-certificates,crypto-policies,dconf,fonts,gconf,group,gtk-2.0,gtk-3.0,host.conf,hostname,hosts,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,locale,locale.alias,locale.conf,localtime,machine-id,mime.types,nsswitch.conf,pango,passwd,pki,pulse,resolv.conf,ssl,X11,xdg | 48 | private-etc @tls-ca,@x11,gconf,host.conf,mime.types |
49 | private-tmp | 49 | private-tmp |
50 | 50 | ||
51 | restrict-namespaces | 51 | restrict-namespaces |
diff --git a/etc/profile-m-z/shotwell.profile b/etc/profile-m-z/shotwell.profile index d33a97ffc..387d45cdc 100644 --- a/etc/profile-m-z/shotwell.profile +++ b/etc/profile-m-z/shotwell.profile | |||
@@ -48,7 +48,7 @@ tracelog | |||
48 | private-bin shotwell | 48 | private-bin shotwell |
49 | private-cache | 49 | private-cache |
50 | private-dev | 50 | private-dev |
51 | private-etc alternatives,fonts,ld.so.cache,ld.so.preload,machine-id | 51 | private-etc |
52 | private-opt none | 52 | private-opt none |
53 | private-tmp | 53 | private-tmp |
54 | 54 | ||
diff --git a/etc/profile-m-z/signal-desktop.profile b/etc/profile-m-z/signal-desktop.profile index 2c4bdecd8..4a57bf38c 100644 --- a/etc/profile-m-z/signal-desktop.profile +++ b/etc/profile-m-z/signal-desktop.profile | |||
@@ -19,7 +19,7 @@ read-only ${HOME}/.mozilla/firefox/profiles.ini | |||
19 | mkdir ${HOME}/.config/Signal | 19 | mkdir ${HOME}/.config/Signal |
20 | whitelist ${HOME}/.config/Signal | 20 | whitelist ${HOME}/.config/Signal |
21 | 21 | ||
22 | private-etc alternatives,ca-certificates,crypto-policies,fonts,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,localtime,machine-id,nsswitch.conf,pki,resolv.conf,ssl | 22 | private-etc @tls-ca |
23 | 23 | ||
24 | dbus-user filter | 24 | dbus-user filter |
25 | 25 | ||
diff --git a/etc/profile-m-z/slack.profile b/etc/profile-m-z/slack.profile index a511ebb1c..a94176bf7 100644 --- a/etc/profile-m-z/slack.profile +++ b/etc/profile-m-z/slack.profile | |||
@@ -26,7 +26,7 @@ mkdir ${HOME}/.config/Slack | |||
26 | whitelist ${HOME}/.config/Slack | 26 | whitelist ${HOME}/.config/Slack |
27 | 27 | ||
28 | private-bin electron,electron[0-9],electron[0-9][0-9],locale,sh,slack | 28 | private-bin electron,electron[0-9],electron[0-9][0-9],locale,sh,slack |
29 | private-etc alternatives,asound.conf,ca-certificates,crypto-policies,debian_version,fedora-release,fonts,group,ld.so.cache,ld.so.conf,ld.so.preload,localtime,machine-id,os-release,passwd,pki,pulse,redhat-release,resolv.conf,ssl,system-release,system-release-cpe | 29 | private-etc @tls-ca,debian_version,fedora-release,os-release,redhat-release,system-release,system-release-cpe |
30 | 30 | ||
31 | # Redirect | 31 | # Redirect |
32 | include electron.profile | 32 | include electron.profile |
diff --git a/etc/profile-m-z/smuxi-frontend-gnome.profile b/etc/profile-m-z/smuxi-frontend-gnome.profile index ffed9d44c..566d72733 100644 --- a/etc/profile-m-z/smuxi-frontend-gnome.profile +++ b/etc/profile-m-z/smuxi-frontend-gnome.profile | |||
@@ -47,7 +47,7 @@ disable-mnt | |||
47 | private-bin bash,mono,mono-sgen,sh,smuxi-frontend-gnome | 47 | private-bin bash,mono,mono-sgen,sh,smuxi-frontend-gnome |
48 | private-cache | 48 | private-cache |
49 | private-dev | 49 | private-dev |
50 | private-etc alsa,alternatives,asound.conf,ca-certificates,crypto-policies,fonts,hostname,hosts,ld.so.cache,ld.so.conf,ld.so.preload,machine-id,mono,passwd,pki,pulse,resolv.conf,selinux,ssl,xdg | 50 | private-etc @tls-ca,@x11,mono,selinux |
51 | private-tmp | 51 | private-tmp |
52 | 52 | ||
53 | dbus-user none | 53 | dbus-user none |
diff --git a/etc/profile-m-z/softmaker-common.profile b/etc/profile-m-z/softmaker-common.profile index b4658b7af..f130176c1 100644 --- a/etc/profile-m-z/softmaker-common.profile +++ b/etc/profile-m-z/softmaker-common.profile | |||
@@ -42,7 +42,7 @@ tracelog | |||
42 | private-bin freeoffice-planmaker,freeoffice-presentations,freeoffice-textmaker,planmaker18,planmaker18free,presentations18,presentations18free,sh,textmaker18,textmaker18free | 42 | private-bin freeoffice-planmaker,freeoffice-presentations,freeoffice-textmaker,planmaker18,planmaker18free,presentations18,presentations18free,sh,textmaker18,textmaker18free |
43 | private-cache | 43 | private-cache |
44 | private-dev | 44 | private-dev |
45 | private-etc alternatives,ca-certificates,crypto-policies,fonts,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,machine-id,nsswitch.conf,pki,SoftMaker,ssl | 45 | private-etc @tls-ca,SoftMaker |
46 | private-tmp | 46 | private-tmp |
47 | 47 | ||
48 | dbus-user none | 48 | dbus-user none |
diff --git a/etc/profile-m-z/spectacle.profile b/etc/profile-m-z/spectacle.profile index 5a1314315..cf64076e3 100644 --- a/etc/profile-m-z/spectacle.profile +++ b/etc/profile-m-z/spectacle.profile | |||
@@ -55,7 +55,7 @@ disable-mnt | |||
55 | private-bin spectacle | 55 | private-bin spectacle |
56 | private-cache | 56 | private-cache |
57 | private-dev | 57 | private-dev |
58 | private-etc alternatives,fonts,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload | 58 | private-etc |
59 | private-tmp | 59 | private-tmp |
60 | 60 | ||
61 | dbus-user filter | 61 | dbus-user filter |
diff --git a/etc/profile-m-z/spectral.profile b/etc/profile-m-z/spectral.profile index 4bc23fc04..492a5bbeb 100644 --- a/etc/profile-m-z/spectral.profile +++ b/etc/profile-m-z/spectral.profile | |||
@@ -45,7 +45,7 @@ disable-mnt | |||
45 | private-cache | 45 | private-cache |
46 | private-bin spectral | 46 | private-bin spectral |
47 | private-dev | 47 | private-dev |
48 | private-etc alsa,alternatives,asound.conf,ca-certificates,crypto-policies,fonts,gtk-2.0,gtk-3.0,host.conf,hostname,hosts,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,locale,locale.alias,locale.conf,mime.types,nsswitch.conf,pki,pulse,resolv.conf,selinux,ssl,X11,xdg | 48 | private-etc @tls-ca,@x11,host.conf,mime.types,selinux |
49 | private-tmp | 49 | private-tmp |
50 | 50 | ||
51 | dbus-user filter | 51 | dbus-user filter |
diff --git a/etc/profile-m-z/spotify.profile b/etc/profile-m-z/spotify.profile index 721e39cd4..f07b10319 100644 --- a/etc/profile-m-z/spotify.profile +++ b/etc/profile-m-z/spotify.profile | |||
@@ -45,7 +45,7 @@ disable-mnt | |||
45 | private-bin bash,cat,dirname,find,grep,head,rm,sh,spotify,tclsh,touch,zenity | 45 | private-bin bash,cat,dirname,find,grep,head,rm,sh,spotify,tclsh,touch,zenity |
46 | private-dev | 46 | private-dev |
47 | # If you want to see album covers or want to use the radio, add 'ignore private-etc' to your spotify.local. | 47 | # If you want to see album covers or want to use the radio, add 'ignore private-etc' to your spotify.local. |
48 | private-etc alternatives,ca-certificates,crypto-policies,fonts,group,host.conf,hosts,ld.so.cache,ld.so.preload,machine-id,nsswitch.conf,pki,pulse,resolv.conf,spotify-adblock,ssl | 48 | private-etc @tls-ca,host.conf,spotify-adblock |
49 | private-opt spotify | 49 | private-opt spotify |
50 | private-srv none | 50 | private-srv none |
51 | private-tmp | 51 | private-tmp |
diff --git a/etc/profile-m-z/sqlitebrowser.profile b/etc/profile-m-z/sqlitebrowser.profile index 00df625c0..4e28958e4 100644 --- a/etc/profile-m-z/sqlitebrowser.profile +++ b/etc/profile-m-z/sqlitebrowser.profile | |||
@@ -41,7 +41,7 @@ seccomp.block-secondary | |||
41 | private-bin sqlitebrowser | 41 | private-bin sqlitebrowser |
42 | private-cache | 42 | private-cache |
43 | private-dev | 43 | private-dev |
44 | private-etc alternatives,ca-certificates,crypto-policies,fonts,group,ld.so.cache,ld.so.preload,machine-id,passwd,pki,resolv.conf,ssl | 44 | private-etc @tls-ca |
45 | private-tmp | 45 | private-tmp |
46 | 46 | ||
47 | # breaks proxy creation | 47 | # breaks proxy creation |
diff --git a/etc/profile-m-z/standardnotes-desktop.profile b/etc/profile-m-z/standardnotes-desktop.profile index 868c724d2..95dc35741 100644 --- a/etc/profile-m-z/standardnotes-desktop.profile +++ b/etc/profile-m-z/standardnotes-desktop.profile | |||
@@ -38,7 +38,7 @@ seccomp !chroot | |||
38 | disable-mnt | 38 | disable-mnt |
39 | private-dev | 39 | private-dev |
40 | private-tmp | 40 | private-tmp |
41 | private-etc alternatives,ca-certificates,crypto-policies,fonts,host.conf,hostname,hosts,ld.so.cache,ld.so.preload,pki,resolv.conf,ssl,xdg | 41 | private-etc @tls-ca,@x11,host.conf |
42 | 42 | ||
43 | dbus-user none | 43 | dbus-user none |
44 | dbus-system none | 44 | dbus-system none |
diff --git a/etc/profile-m-z/steam.profile b/etc/profile-m-z/steam.profile index f807afdc7..39b4c97fa 100644 --- a/etc/profile-m-z/steam.profile +++ b/etc/profile-m-z/steam.profile | |||
@@ -175,7 +175,7 @@ seccomp.32 !process_vm_readv | |||
175 | private-dev | 175 | private-dev |
176 | # private-etc breaks a small selection of games on some systems. Add 'ignore private-etc' | 176 | # private-etc breaks a small selection of games on some systems. Add 'ignore private-etc' |
177 | # to your steam.local to support those. | 177 | # to your steam.local to support those. |
178 | private-etc alsa,alternatives,asound.conf,bumblebee,ca-certificates,crypto-policies,dbus-1,drirc,fonts,group,gtk-2.0,gtk-3.0,host.conf,hostname,hosts,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,localtime,lsb-release,machine-id,mime.types,nvidia,os-release,passwd,pki,pulse,resolv.conf,services,ssl,vulkan | 178 | private-etc @tls-ca,@x11,bumblebee,dbus-1,host.conf,lsb-release,mime.types,os-release,services,vulkan |
179 | private-tmp | 179 | private-tmp |
180 | 180 | ||
181 | #dbus-user none | 181 | #dbus-user none |
diff --git a/etc/profile-m-z/strawberry.profile b/etc/profile-m-z/strawberry.profile index e9d2ca430..b6b2c63d3 100644 --- a/etc/profile-m-z/strawberry.profile +++ b/etc/profile-m-z/strawberry.profile | |||
@@ -42,7 +42,7 @@ disable-mnt | |||
42 | private-bin strawberry,strawberry-tagreader | 42 | private-bin strawberry,strawberry-tagreader |
43 | private-cache | 43 | private-cache |
44 | private-dev | 44 | private-dev |
45 | private-etc alternatives,ca-certificates,crypto-policies,fonts,host.conf,hostname,hosts,ld.so.cache,ld.so.preload,nsswitch.conf,pki,resolv.conf,ssl | 45 | private-etc @tls-ca,host.conf |
46 | private-tmp | 46 | private-tmp |
47 | 47 | ||
48 | dbus-system none | 48 | dbus-system none |
diff --git a/etc/profile-m-z/subdownloader.profile b/etc/profile-m-z/subdownloader.profile index 896d4bc3e..6de288c46 100644 --- a/etc/profile-m-z/subdownloader.profile +++ b/etc/profile-m-z/subdownloader.profile | |||
@@ -43,7 +43,7 @@ tracelog | |||
43 | 43 | ||
44 | private-cache | 44 | private-cache |
45 | private-dev | 45 | private-dev |
46 | private-etc alternatives,fonts,ld.so.cache,ld.so.preload | 46 | private-etc |
47 | private-tmp | 47 | private-tmp |
48 | 48 | ||
49 | dbus-user none | 49 | dbus-user none |
diff --git a/etc/profile-m-z/supertux2.profile b/etc/profile-m-z/supertux2.profile index 1f532d76c..2ad107f1a 100644 --- a/etc/profile-m-z/supertux2.profile +++ b/etc/profile-m-z/supertux2.profile | |||
@@ -43,7 +43,7 @@ tracelog | |||
43 | disable-mnt | 43 | disable-mnt |
44 | # private-bin supertux2 | 44 | # private-bin supertux2 |
45 | private-cache | 45 | private-cache |
46 | private-etc alternatives,ld.so.cache,ld.so.preload,machine-id | 46 | private-etc |
47 | private-dev | 47 | private-dev |
48 | private-tmp | 48 | private-tmp |
49 | 49 | ||
diff --git a/etc/profile-m-z/supertuxkart.profile b/etc/profile-m-z/supertuxkart.profile index b4eb70fcb..0a436b22f 100644 --- a/etc/profile-m-z/supertuxkart.profile +++ b/etc/profile-m-z/supertuxkart.profile | |||
@@ -53,7 +53,7 @@ private-bin supertuxkart | |||
53 | private-cache | 53 | private-cache |
54 | # Add the next line to your supertuxkart.local if you do not need controller support. | 54 | # Add the next line to your supertuxkart.local if you do not need controller support. |
55 | #private-dev | 55 | #private-dev |
56 | private-etc alternatives,ca-certificates,crypto-policies,drirc,hosts,ld.so.cache,ld.so.preload,machine-id,openal,pki,resolv.conf,ssl | 56 | private-etc @games,@tls-ca,@x11 |
57 | private-tmp | 57 | private-tmp |
58 | private-opt none | 58 | private-opt none |
59 | private-srv none | 59 | private-srv none |
diff --git a/etc/profile-m-z/surf.profile b/etc/profile-m-z/surf.profile index 3508e11b0..9be7aaf3c 100644 --- a/etc/profile-m-z/surf.profile +++ b/etc/profile-m-z/surf.profile | |||
@@ -33,7 +33,7 @@ tracelog | |||
33 | disable-mnt | 33 | disable-mnt |
34 | private-bin bash,curl,dmenu,ls,printf,sed,sh,sleep,st,stterm,surf,xargs,xprop | 34 | private-bin bash,curl,dmenu,ls,printf,sed,sh,sleep,st,stterm,surf,xargs,xprop |
35 | private-dev | 35 | private-dev |
36 | private-etc alternatives,ca-certificates,crypto-policies,fonts,group,hosts,ld.so.cache,ld.so.preload,machine-id,passwd,pki,resolv.conf,ssl | 36 | private-etc @tls-ca |
37 | private-tmp | 37 | private-tmp |
38 | 38 | ||
39 | restrict-namespaces | 39 | restrict-namespaces |
diff --git a/etc/profile-m-z/sysprof.profile b/etc/profile-m-z/sysprof.profile index cef029401..726baf336 100644 --- a/etc/profile-m-z/sysprof.profile +++ b/etc/profile-m-z/sysprof.profile | |||
@@ -62,7 +62,7 @@ disable-mnt | |||
62 | #private-bin sysprof - breaks help menu | 62 | #private-bin sysprof - breaks help menu |
63 | private-cache | 63 | private-cache |
64 | private-dev | 64 | private-dev |
65 | private-etc alternatives,fonts,ld.so.cache,ld.so.preload,machine-id,ssl | 65 | private-etc @tls-ca |
66 | # private-lib - breaks help menu | 66 | # private-lib - breaks help menu |
67 | #private-lib gdk-pixbuf-2.*,gio,gtk3,gvfs/libgvfscommon.so,libgconf-2.so.*,librsvg-2.so.*,libsysprof-2.so,libsysprof-ui-2.so | 67 | #private-lib gdk-pixbuf-2.*,gio,gtk3,gvfs/libgvfscommon.so,libgconf-2.so.*,librsvg-2.so.*,libsysprof-2.so,libsysprof-ui-2.so |
68 | private-tmp | 68 | private-tmp |
diff --git a/etc/profile-m-z/tar.profile b/etc/profile-m-z/tar.profile index a9d0a60d1..da3b4f782 100644 --- a/etc/profile-m-z/tar.profile +++ b/etc/profile-m-z/tar.profile | |||
@@ -17,7 +17,7 @@ ignore include disable-shell.inc | |||
17 | # all capabilities this is automatically read-only. | 17 | # all capabilities this is automatically read-only. |
18 | noblacklist /var/lib/pacman | 18 | noblacklist /var/lib/pacman |
19 | 19 | ||
20 | private-etc alternatives,group,ld.so.cache,ld.so.preload,localtime,login.defs,passwd | 20 | private-etc |
21 | #private-lib libfakeroot,liblzma.so.*,libreadline.so.* | 21 | #private-lib libfakeroot,liblzma.so.*,libreadline.so.* |
22 | # Debian based distributions need this for 'dpkg --unpack' (incl. synaptic) | 22 | # Debian based distributions need this for 'dpkg --unpack' (incl. synaptic) |
23 | writable-var | 23 | writable-var |
diff --git a/etc/profile-m-z/teams-for-linux.profile b/etc/profile-m-z/teams-for-linux.profile index 5711c1b36..fd55daa4a 100644 --- a/etc/profile-m-z/teams-for-linux.profile +++ b/etc/profile-m-z/teams-for-linux.profile | |||
@@ -22,7 +22,7 @@ mkdir ${HOME}/.config/teams-for-linux | |||
22 | whitelist ${HOME}/.config/teams-for-linux | 22 | whitelist ${HOME}/.config/teams-for-linux |
23 | 23 | ||
24 | private-bin bash,cut,echo,egrep,electron,electron[0-9],electron[0-9][0-9],grep,head,sed,sh,teams-for-linux,tr,xdg-mime,xdg-open,zsh | 24 | private-bin bash,cut,echo,egrep,electron,electron[0-9],electron[0-9][0-9],grep,head,sed,sh,teams-for-linux,tr,xdg-mime,xdg-open,zsh |
25 | private-etc alternatives,ca-certificates,crypto-policies,fonts,ld.so.cache,ld.so.preload,localtime,machine-id,pki,resolv.conf,ssl | 25 | private-etc @tls-ca |
26 | 26 | ||
27 | # Redirect | 27 | # Redirect |
28 | include electron.profile | 28 | include electron.profile |
diff --git a/etc/profile-m-z/telegram.profile b/etc/profile-m-z/telegram.profile index 886d303c8..ba915c2d4 100644 --- a/etc/profile-m-z/telegram.profile +++ b/etc/profile-m-z/telegram.profile | |||
@@ -46,7 +46,7 @@ disable-mnt | |||
46 | private-bin bash,sh,telegram,Telegram,telegram-desktop,xdg-open | 46 | private-bin bash,sh,telegram,Telegram,telegram-desktop,xdg-open |
47 | private-cache | 47 | private-cache |
48 | private-dev | 48 | private-dev |
49 | private-etc alsa,alternatives,ca-certificates,crypto-policies,fonts,group,ld.so.cache,ld.so.preload,localtime,machine-id,os-release,passwd,pki,pulse,resolv.conf,ssl,xdg | 49 | private-etc @tls-ca,@x11,os-release |
50 | private-tmp | 50 | private-tmp |
51 | 51 | ||
52 | dbus-user filter | 52 | dbus-user filter |
diff --git a/etc/profile-m-z/terasology.profile b/etc/profile-m-z/terasology.profile index 9249e33c8..27e0cc7d1 100644 --- a/etc/profile-m-z/terasology.profile +++ b/etc/profile-m-z/terasology.profile | |||
@@ -40,7 +40,7 @@ seccomp | |||
40 | 40 | ||
41 | disable-mnt | 41 | disable-mnt |
42 | private-dev | 42 | private-dev |
43 | private-etc alternatives,asound.conf,ca-certificates,crypto-policies,dbus-1,drirc,fonts,group,gtk-2.0,gtk-3.0,host.conf,hostname,hosts,java-7-openjdk,java-8-openjdk,ld.so.cache,ld.so.preload,localtime,lsb-release,machine-id,mime.types,passwd,pki,pulse,resolv.conf,ssl | 43 | private-etc @tls-ca,@x11,dbus-1,host.conf,java-7-openjdk,java-8-openjdk,lsb-release,mime.types |
44 | private-tmp | 44 | private-tmp |
45 | 45 | ||
46 | dbus-user none | 46 | dbus-user none |
diff --git a/etc/profile-m-z/tesseract.profile b/etc/profile-m-z/tesseract.profile index 11a21c471..54568b7d3 100644 --- a/etc/profile-m-z/tesseract.profile +++ b/etc/profile-m-z/tesseract.profile | |||
@@ -54,7 +54,7 @@ x11 none | |||
54 | private-bin ambiguous_words,classifier_tester,cntraining,combine_lang_model,combine_tessdata,dawg2wordlist,lstmeval,lstmtraining,merge_unicharsets,mftraining,set_unicharset_properties,shapeclustering,tesseract,text2image,unicharset_extractor,wordlist2dawg | 54 | private-bin ambiguous_words,classifier_tester,cntraining,combine_lang_model,combine_tessdata,dawg2wordlist,lstmeval,lstmtraining,merge_unicharsets,mftraining,set_unicharset_properties,shapeclustering,tesseract,text2image,unicharset_extractor,wordlist2dawg |
55 | private-cache | 55 | private-cache |
56 | private-dev | 56 | private-dev |
57 | private-etc alternatives,fonts,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload | 57 | private-etc |
58 | #private-lib libtesseract.so.* | 58 | #private-lib libtesseract.so.* |
59 | private-tmp | 59 | private-tmp |
60 | 60 | ||
diff --git a/etc/profile-m-z/tilp.profile b/etc/profile-m-z/tilp.profile index f49738f2b..ed8cd7369 100644 --- a/etc/profile-m-z/tilp.profile +++ b/etc/profile-m-z/tilp.profile | |||
@@ -29,7 +29,7 @@ tracelog | |||
29 | disable-mnt | 29 | disable-mnt |
30 | private-bin tilp | 30 | private-bin tilp |
31 | private-cache | 31 | private-cache |
32 | private-etc alternatives,fonts,ld.so.cache,ld.so.preload | 32 | private-etc |
33 | private-tmp | 33 | private-tmp |
34 | 34 | ||
35 | restrict-namespaces | 35 | restrict-namespaces |
diff --git a/etc/profile-m-z/tin.profile b/etc/profile-m-z/tin.profile index 3cbf90660..a03a6caa0 100644 --- a/etc/profile-m-z/tin.profile +++ b/etc/profile-m-z/tin.profile | |||
@@ -57,7 +57,7 @@ disable-mnt | |||
57 | private-bin rtin,tin | 57 | private-bin rtin,tin |
58 | private-cache | 58 | private-cache |
59 | private-dev | 59 | private-dev |
60 | private-etc alternatives,ld.so.cache,ld.so.preload,passwd,resolv.conf,terminfo,tin | 60 | private-etc terminfo,tin |
61 | private-lib terminfo | 61 | private-lib terminfo |
62 | private-tmp | 62 | private-tmp |
63 | 63 | ||
diff --git a/etc/profile-m-z/tor.profile b/etc/profile-m-z/tor.profile index 275b170ff..b58aec926 100644 --- a/etc/profile-m-z/tor.profile +++ b/etc/profile-m-z/tor.profile | |||
@@ -45,7 +45,7 @@ private | |||
45 | private-bin bash,tor | 45 | private-bin bash,tor |
46 | private-cache | 46 | private-cache |
47 | private-dev | 47 | private-dev |
48 | private-etc alternatives,ca-certificates,crypto-policies,ld.so.cache,ld.so.preload,passwd,pki,ssl,tor | 48 | private-etc @tls-ca,tor |
49 | private-tmp | 49 | private-tmp |
50 | writable-var | 50 | writable-var |
51 | 51 | ||
diff --git a/etc/profile-m-z/torbrowser-launcher.profile b/etc/profile-m-z/torbrowser-launcher.profile index fab792826..41ac6f7a7 100644 --- a/etc/profile-m-z/torbrowser-launcher.profile +++ b/etc/profile-m-z/torbrowser-launcher.profile | |||
@@ -58,7 +58,7 @@ seccomp !chroot | |||
58 | disable-mnt | 58 | disable-mnt |
59 | private-bin bash,cat,cp,cut,dirname,env,expr,file,gpg,grep,gxmessage,id,kdialog,ln,mkdir,mv,python*,rm,sed,sh,tail,tar,tclsh,test,tor-browser,tor-browser-en,torbrowser-launcher,update-desktop-database,xmessage,xz,zenity | 59 | private-bin bash,cat,cp,cut,dirname,env,expr,file,gpg,grep,gxmessage,id,kdialog,ln,mkdir,mv,python*,rm,sed,sh,tail,tar,tclsh,test,tor-browser,tor-browser-en,torbrowser-launcher,update-desktop-database,xmessage,xz,zenity |
60 | private-dev | 60 | private-dev |
61 | private-etc alsa,alternatives,asound.conf,ca-certificates,crypto-policies,fonts,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,machine-id,pki,pulse,resolv.conf,ssl | 61 | private-etc @tls-ca |
62 | private-tmp | 62 | private-tmp |
63 | 63 | ||
64 | dbus-user none | 64 | dbus-user none |
diff --git a/etc/profile-m-z/transgui.profile b/etc/profile-m-z/transgui.profile index 6069be500..645c55c3b 100644 --- a/etc/profile-m-z/transgui.profile +++ b/etc/profile-m-z/transgui.profile | |||
@@ -44,7 +44,7 @@ tracelog | |||
44 | private-bin geoiplookup,geoiplookup6,transgui | 44 | private-bin geoiplookup,geoiplookup6,transgui |
45 | private-cache | 45 | private-cache |
46 | private-dev | 46 | private-dev |
47 | private-etc alternatives,fonts,ld.so.cache,ld.so.preload,resolv.conf | 47 | private-etc |
48 | private-lib libgdk_pixbuf-2.0.so.*,libGeoIP.so*,libgthread-2.0.so.*,libgtk-x11-2.0.so.*,libX11.so.* | 48 | private-lib libgdk_pixbuf-2.0.so.*,libGeoIP.so*,libgthread-2.0.so.*,libgtk-x11-2.0.so.*,libX11.so.* |
49 | private-tmp | 49 | private-tmp |
50 | 50 | ||
diff --git a/etc/profile-m-z/transmission-cli.profile b/etc/profile-m-z/transmission-cli.profile index 8a1711e97..edb4db8aa 100644 --- a/etc/profile-m-z/transmission-cli.profile +++ b/etc/profile-m-z/transmission-cli.profile | |||
@@ -8,7 +8,7 @@ include transmission-cli.local | |||
8 | include globals.local | 8 | include globals.local |
9 | 9 | ||
10 | private-bin transmission-cli | 10 | private-bin transmission-cli |
11 | private-etc alternatives,ca-certificates,crypto-policies,ld.so.cache,ld.so.preload,nsswitch.conf,pki,resolv.conf,ssl | 11 | private-etc @tls-ca |
12 | 12 | ||
13 | # Redirect | 13 | # Redirect |
14 | include transmission-common.profile | 14 | include transmission-common.profile |
diff --git a/etc/profile-m-z/transmission-daemon.profile b/etc/profile-m-z/transmission-daemon.profile index 5d28f2f10..4fc5a3aa7 100644 --- a/etc/profile-m-z/transmission-daemon.profile +++ b/etc/profile-m-z/transmission-daemon.profile | |||
@@ -17,7 +17,7 @@ caps.keep ipc_lock,net_bind_service,setgid,setuid,sys_chroot | |||
17 | protocol packet | 17 | protocol packet |
18 | 18 | ||
19 | private-bin transmission-daemon | 19 | private-bin transmission-daemon |
20 | private-etc alternatives,ca-certificates,crypto-policies,ld.so.cache,ld.so.preload,nsswitch.conf,pki,resolv.conf,ssl | 20 | private-etc @tls-ca |
21 | 21 | ||
22 | read-write /var/lib/transmission | 22 | read-write /var/lib/transmission |
23 | writable-var-log | 23 | writable-var-log |
diff --git a/etc/profile-m-z/transmission-remote-gtk.profile b/etc/profile-m-z/transmission-remote-gtk.profile index f93c4229c..a8dd96001 100644 --- a/etc/profile-m-z/transmission-remote-gtk.profile +++ b/etc/profile-m-z/transmission-remote-gtk.profile | |||
@@ -12,7 +12,7 @@ noblacklist ${HOME}/.config/transmission-remote-gtk | |||
12 | mkdir ${HOME}/.config/transmission-remote-gtk | 12 | mkdir ${HOME}/.config/transmission-remote-gtk |
13 | whitelist ${HOME}/.config/transmission-remote-gtk | 13 | whitelist ${HOME}/.config/transmission-remote-gtk |
14 | 14 | ||
15 | private-etc alternatives,fonts,hostname,hosts,ld.so.cache,ld.so.preload,resolv.conf | 15 | private-etc |
16 | 16 | ||
17 | ignore memory-deny-write-execute | 17 | ignore memory-deny-write-execute |
18 | 18 | ||
diff --git a/etc/profile-m-z/transmission-remote.profile b/etc/profile-m-z/transmission-remote.profile index 565433d99..a431164f6 100644 --- a/etc/profile-m-z/transmission-remote.profile +++ b/etc/profile-m-z/transmission-remote.profile | |||
@@ -8,7 +8,7 @@ include transmission-remote.local | |||
8 | include globals.local | 8 | include globals.local |
9 | 9 | ||
10 | private-bin transmission-remote | 10 | private-bin transmission-remote |
11 | private-etc alternatives,hosts,ld.so.cache,ld.so.preload,nsswitch.conf | 11 | private-etc |
12 | 12 | ||
13 | # Redirect | 13 | # Redirect |
14 | include transmission-common.profile | 14 | include transmission-common.profile |
diff --git a/etc/profile-m-z/transmission-show.profile b/etc/profile-m-z/transmission-show.profile index 0a5826ec4..dc667ae05 100644 --- a/etc/profile-m-z/transmission-show.profile +++ b/etc/profile-m-z/transmission-show.profile | |||
@@ -8,7 +8,7 @@ include transmission-show.local | |||
8 | include globals.local | 8 | include globals.local |
9 | 9 | ||
10 | private-bin transmission-show | 10 | private-bin transmission-show |
11 | private-etc alternatives,hosts,ld.so.cache,ld.so.preload,nsswitch.conf | 11 | private-etc |
12 | 12 | ||
13 | # Redirect | 13 | # Redirect |
14 | include transmission-common.profile | 14 | include transmission-common.profile |
diff --git a/etc/profile-m-z/trojita.profile b/etc/profile-m-z/trojita.profile index 63e964355..8acc6f763 100644 --- a/etc/profile-m-z/trojita.profile +++ b/etc/profile-m-z/trojita.profile | |||
@@ -53,7 +53,7 @@ tracelog | |||
53 | private-bin trojita | 53 | private-bin trojita |
54 | private-cache | 54 | private-cache |
55 | private-dev | 55 | private-dev |
56 | private-etc alternatives,ca-certificates,crypto-policies,fonts,hostname,hosts,ld.so.cache,ld.so.preload,pki,resolv.conf,selinux,ssl,xdg | 56 | private-etc @tls-ca,@x11,selinux |
57 | private-tmp | 57 | private-tmp |
58 | 58 | ||
59 | dbus-user filter | 59 | dbus-user filter |
diff --git a/etc/profile-m-z/tutanota-desktop.profile b/etc/profile-m-z/tutanota-desktop.profile index d2cb0cc8a..56eacf338 100644 --- a/etc/profile-m-z/tutanota-desktop.profile +++ b/etc/profile-m-z/tutanota-desktop.profile | |||
@@ -24,7 +24,7 @@ whitelist ${HOME}/.mozilla/firefox/profiles.ini | |||
24 | read-only ${HOME}/.mozilla/firefox/profiles.ini | 24 | read-only ${HOME}/.mozilla/firefox/profiles.ini |
25 | 25 | ||
26 | ?HAS_APPIMAGE: ignore private-dev | 26 | ?HAS_APPIMAGE: ignore private-dev |
27 | private-etc alternatives,ca-certificates,crypto-policies,fonts,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,machine-id,nsswitch.conf,pki,resolv.conf,ssl | 27 | private-etc @tls-ca |
28 | private-opt tutanota-desktop | 28 | private-opt tutanota-desktop |
29 | 29 | ||
30 | # Redirect | 30 | # Redirect |
diff --git a/etc/profile-m-z/twitch.profile b/etc/profile-m-z/twitch.profile index 987a2b719..1e759a760 100644 --- a/etc/profile-m-z/twitch.profile +++ b/etc/profile-m-z/twitch.profile | |||
@@ -18,7 +18,7 @@ mkdir ${HOME}/.config/Twitch | |||
18 | whitelist ${HOME}/.config/Twitch | 18 | whitelist ${HOME}/.config/Twitch |
19 | 19 | ||
20 | private-bin electron,electron[0-9],electron[0-9][0-9],twitch | 20 | private-bin electron,electron[0-9],electron[0-9][0-9],twitch |
21 | private-etc alsa,alternatives,asound.conf,ati,bumblebee,ca-certificates,crypto-policies,drirc,fonts,gtk-2.0,gtk-3.0,host.conf,hostname,hosts,ld.so.cache,ld.so.preload,mime.types,nsswitch.conf,nvidia,pki,pulse,resolv.conf,selinux,ssl,X11,xdg | 21 | private-etc @tls-ca,@x11,bumblebee,host.conf,mime.types,selinux |
22 | private-opt Twitch | 22 | private-opt Twitch |
23 | 23 | ||
24 | # Redirect | 24 | # Redirect |
diff --git a/etc/profile-m-z/udiskie.profile b/etc/profile-m-z/udiskie.profile index 7e3c7ac5a..c182326bb 100644 --- a/etc/profile-m-z/udiskie.profile +++ b/etc/profile-m-z/udiskie.profile | |||
@@ -40,7 +40,7 @@ private-bin awk,cut,dbus-send,egrep,file,grep,head,python*,readlink,sed,sh,udisk | |||
40 | # private-bin thunar | 40 | # private-bin thunar |
41 | private-cache | 41 | private-cache |
42 | private-dev | 42 | private-dev |
43 | private-etc alternatives,fonts,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,locale,locale.alias,locale.conf,localtime,mime.types,xdg | 43 | private-etc @x11,mime.types |
44 | private-tmp | 44 | private-tmp |
45 | 45 | ||
46 | restrict-namespaces | 46 | restrict-namespaces |
diff --git a/etc/profile-m-z/unf.profile b/etc/profile-m-z/unf.profile index 6ec6ea609..aac99aed5 100644 --- a/etc/profile-m-z/unf.profile +++ b/etc/profile-m-z/unf.profile | |||
@@ -48,7 +48,7 @@ private-bin unf | |||
48 | private-cache | 48 | private-cache |
49 | ?HAS_APPIMAGE: ignore private-dev | 49 | ?HAS_APPIMAGE: ignore private-dev |
50 | private-dev | 50 | private-dev |
51 | private-etc alternatives,ld.so.cache,ld.so.preload | 51 | private-etc |
52 | private-lib gcc/*/*/libgcc_s.so.* | 52 | private-lib gcc/*/*/libgcc_s.so.* |
53 | private-tmp | 53 | private-tmp |
54 | 54 | ||
diff --git a/etc/profile-m-z/unrar.profile b/etc/profile-m-z/unrar.profile index 443d1f415..43d5dae5e 100644 --- a/etc/profile-m-z/unrar.profile +++ b/etc/profile-m-z/unrar.profile | |||
@@ -8,7 +8,7 @@ include unrar.local | |||
8 | include globals.local | 8 | include globals.local |
9 | 9 | ||
10 | private-bin unrar | 10 | private-bin unrar |
11 | private-etc alternatives,group,ld.so.cache,ld.so.preload,localtime,passwd | 11 | private-etc |
12 | private-tmp | 12 | private-tmp |
13 | 13 | ||
14 | # Redirect | 14 | # Redirect |
diff --git a/etc/profile-m-z/unzip.profile b/etc/profile-m-z/unzip.profile index 97df693ba..9fefe6ad3 100644 --- a/etc/profile-m-z/unzip.profile +++ b/etc/profile-m-z/unzip.profile | |||
@@ -10,7 +10,7 @@ include globals.local | |||
10 | # GNOME Shell integration (chrome-gnome-shell) | 10 | # GNOME Shell integration (chrome-gnome-shell) |
11 | noblacklist ${HOME}/.local/share/gnome-shell | 11 | noblacklist ${HOME}/.local/share/gnome-shell |
12 | 12 | ||
13 | private-etc alternatives,group,ld.so.cache,ld.so.preload,localtime,passwd | 13 | private-etc |
14 | 14 | ||
15 | # Redirect | 15 | # Redirect |
16 | include archiver-common.profile | 16 | include archiver-common.profile |
diff --git a/etc/profile-m-z/utox.profile b/etc/profile-m-z/utox.profile index f85e52273..046b75a87 100644 --- a/etc/profile-m-z/utox.profile +++ b/etc/profile-m-z/utox.profile | |||
@@ -42,7 +42,7 @@ disable-mnt | |||
42 | private-bin utox | 42 | private-bin utox |
43 | private-cache | 43 | private-cache |
44 | private-dev | 44 | private-dev |
45 | private-etc alternatives,ca-certificates,crypto-policies,fonts,ld.so.cache,ld.so.preload,localtime,machine-id,openal,pki,pulse,resolv.conf,ssl | 45 | private-etc @games,@tls-ca |
46 | private-tmp | 46 | private-tmp |
47 | 47 | ||
48 | memory-deny-write-execute | 48 | memory-deny-write-execute |
diff --git a/etc/profile-m-z/uudeview.profile b/etc/profile-m-z/uudeview.profile index 29d88832c..a6d2a65e9 100644 --- a/etc/profile-m-z/uudeview.profile +++ b/etc/profile-m-z/uudeview.profile | |||
@@ -40,7 +40,7 @@ x11 none | |||
40 | private-bin uudeview | 40 | private-bin uudeview |
41 | private-cache | 41 | private-cache |
42 | private-dev | 42 | private-dev |
43 | private-etc alternatives,ld.so.cache,ld.so.preload | 43 | private-etc |
44 | 44 | ||
45 | dbus-user none | 45 | dbus-user none |
46 | dbus-system none | 46 | dbus-system none |
diff --git a/etc/profile-m-z/viewnior.profile b/etc/profile-m-z/viewnior.profile index cdf615a02..aa8199442 100644 --- a/etc/profile-m-z/viewnior.profile +++ b/etc/profile-m-z/viewnior.profile | |||
@@ -43,7 +43,7 @@ tracelog | |||
43 | private-bin viewnior | 43 | private-bin viewnior |
44 | private-cache | 44 | private-cache |
45 | private-dev | 45 | private-dev |
46 | private-etc alternatives,fonts,ld.so.cache,ld.so.preload,machine-id | 46 | private-etc |
47 | private-tmp | 47 | private-tmp |
48 | 48 | ||
49 | dbus-user none | 49 | dbus-user none |
diff --git a/etc/profile-m-z/virtualbox.profile b/etc/profile-m-z/virtualbox.profile index b9a5c08e8..37e962867 100644 --- a/etc/profile-m-z/virtualbox.profile +++ b/etc/profile-m-z/virtualbox.profile | |||
@@ -44,7 +44,7 @@ tracelog | |||
44 | #disable-mnt | 44 | #disable-mnt |
45 | #private-bin awk,basename,bash,env,gawk,grep,ps,readlink,sh,virtualbox,VirtualBox,VBox*,vbox*,whoami | 45 | #private-bin awk,basename,bash,env,gawk,grep,ps,readlink,sh,virtualbox,VirtualBox,VBox*,vbox*,whoami |
46 | private-cache | 46 | private-cache |
47 | private-etc alsa,alternatives,asound.conf,ca-certificates,conf.d,crypto-policies,dconf,fonts,hostname,hosts,ld.so.cache,ld.so.preload,localtime,machine-id,pki,pulse,resolv.conf,ssl | 47 | private-etc @tls-ca,@x11,conf.d |
48 | private-tmp | 48 | private-tmp |
49 | 49 | ||
50 | dbus-user none | 50 | dbus-user none |
diff --git a/etc/profile-m-z/vmware-view.profile b/etc/profile-m-z/vmware-view.profile index ba4136413..c2fd14811 100644 --- a/etc/profile-m-z/vmware-view.profile +++ b/etc/profile-m-z/vmware-view.profile | |||
@@ -48,7 +48,7 @@ tracelog | |||
48 | disable-mnt | 48 | disable-mnt |
49 | private-cache | 49 | private-cache |
50 | private-dev | 50 | private-dev |
51 | private-etc alsa,alternatives,asound.conf,bumblebee,ca-certificates,crypto-policies,dconf,drirc,fonts,gai.conf,gconf,glvnd,group,gtk-2.0,gtk-3.0,host.conf,hostname,hosts,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,locale,locale.alias,locale.conf,localtime,login.defs,machine-id,magic,magic.mgc,mime.types,nsswitch.conf,nvidia,pango,passwd,pki,protocols,proxychains.conf,pulse,resolv.conf,rpc,services,ssl,terminfo,vmware,vmware-tools,vmware-vix,X11,xdg | 51 | private-etc @tls-ca,@x11,bumblebee,gai.conf,gconf,glvnd,host.conf,magic,magic.mgc,mime.types,proxychains.conf,rpc,services,terminfo,vmware,vmware-tools,vmware-vix |
52 | # Logs are kept in /tmp. Add 'ignore private-tmp' to your vmware-view.local if you need them without joining the sandbox. | 52 | # Logs are kept in /tmp. Add 'ignore private-tmp' to your vmware-view.local if you need them without joining the sandbox. |
53 | private-tmp | 53 | private-tmp |
54 | 54 | ||
diff --git a/etc/profile-m-z/vmware.profile b/etc/profile-m-z/vmware.profile index 74c951fe6..7619ef47b 100644 --- a/etc/profile-m-z/vmware.profile +++ b/etc/profile-m-z/vmware.profile | |||
@@ -38,6 +38,6 @@ tracelog | |||
38 | #disable-mnt | 38 | #disable-mnt |
39 | # Add the next line to your vmware.local to enable private-bin. | 39 | # Add the next line to your vmware.local to enable private-bin. |
40 | #private-bin env,bash,sh,ovftool,vmafossexec,vmaf_*,vmnet-*,vmplayer,vmrest,vmrun,vmss2core,vmstat,vmware,vmware-* | 40 | #private-bin env,bash,sh,ovftool,vmafossexec,vmaf_*,vmnet-*,vmplayer,vmrest,vmrun,vmss2core,vmstat,vmware,vmware-* |
41 | private-etc alsa,alternatives,asound.conf,ca-certificates,conf.d,crypto-policies,dconf,fonts,gtk-2.0,gtk-3.0,hostname,hosts,ld.so.cache,ld.so.preload,localtime,machine-id,mtab,passwd,pki,pulse,resolv.conf,ssl,vmware,vmware-installer,vmware-vix | 41 | private-etc @tls-ca,@x11,conf.d,mtab,vmware,vmware-installer,vmware-vix |
42 | dbus-user none | 42 | dbus-user none |
43 | dbus-system none | 43 | dbus-system none |
diff --git a/etc/profile-m-z/w3m.profile b/etc/profile-m-z/w3m.profile index 1e111f83e..edc08ca44 100644 --- a/etc/profile-m-z/w3m.profile +++ b/etc/profile-m-z/w3m.profile | |||
@@ -61,7 +61,7 @@ disable-mnt | |||
61 | private-bin perl,sh,w3m | 61 | private-bin perl,sh,w3m |
62 | private-cache | 62 | private-cache |
63 | private-dev | 63 | private-dev |
64 | private-etc alternatives,ca-certificates,crypto-policies,ld.so.cache,ld.so.preload,mailcap,nsswitch.conf,pki,resolv.conf,ssl | 64 | private-etc @tls-ca,mailcap |
65 | private-tmp | 65 | private-tmp |
66 | 66 | ||
67 | dbus-user none | 67 | dbus-user none |
diff --git a/etc/profile-m-z/warmux.profile b/etc/profile-m-z/warmux.profile index 37a8f78bb..5765613d4 100644 --- a/etc/profile-m-z/warmux.profile +++ b/etc/profile-m-z/warmux.profile | |||
@@ -48,7 +48,7 @@ disable-mnt | |||
48 | private-bin warmux | 48 | private-bin warmux |
49 | private-cache | 49 | private-cache |
50 | private-dev | 50 | private-dev |
51 | private-etc alternatives,ca-certificates,crypto-policies,host.conf,hostname,hosts,ld.so.cache,ld.so.preload,machine-id,nsswitch.conf,pki,protocols,resolv.conf,rpc,services,ssl | 51 | private-etc @tls-ca,host.conf,rpc,services |
52 | private-tmp | 52 | private-tmp |
53 | 53 | ||
54 | dbus-user none | 54 | dbus-user none |
diff --git a/etc/profile-m-z/whalebird.profile b/etc/profile-m-z/whalebird.profile index 8a9614fb0..62d667d57 100644 --- a/etc/profile-m-z/whalebird.profile +++ b/etc/profile-m-z/whalebird.profile | |||
@@ -22,7 +22,7 @@ whitelist ${HOME}/.config/Whalebird | |||
22 | no3d | 22 | no3d |
23 | 23 | ||
24 | private-bin electron,electron[0-9],electron[0-9][0-9],whalebird | 24 | private-bin electron,electron[0-9],electron[0-9][0-9],whalebird |
25 | private-etc alternatives,ca-certificates,crypto-policies,fonts,ld.so.cache,ld.so.preload,machine-id,nsswitch.conf,pki,resolv.conf,ssl | 25 | private-etc @tls-ca |
26 | 26 | ||
27 | # Redirect | 27 | # Redirect |
28 | include electron.profile | 28 | include electron.profile |
diff --git a/etc/profile-m-z/whois.profile b/etc/profile-m-z/whois.profile index d8c72ac8b..8958564ef 100644 --- a/etc/profile-m-z/whois.profile +++ b/etc/profile-m-z/whois.profile | |||
@@ -46,7 +46,7 @@ private | |||
46 | private-bin bash,sh,whois | 46 | private-bin bash,sh,whois |
47 | private-cache | 47 | private-cache |
48 | private-dev | 48 | private-dev |
49 | private-etc alternatives,hosts,jwhois.conf,ld.so.cache,ld.so.preload,resolv.conf,services,whois.conf | 49 | private-etc jwhois.conf,services,whois.conf |
50 | private-lib gconv | 50 | private-lib gconv |
51 | private-tmp | 51 | private-tmp |
52 | 52 | ||
diff --git a/etc/profile-m-z/wire-desktop.profile b/etc/profile-m-z/wire-desktop.profile index d8742cd71..fc4fa2435 100644 --- a/etc/profile-m-z/wire-desktop.profile +++ b/etc/profile-m-z/wire-desktop.profile | |||
@@ -26,7 +26,7 @@ mkdir ${HOME}/.config/Wire | |||
26 | whitelist ${HOME}/.config/Wire | 26 | whitelist ${HOME}/.config/Wire |
27 | 27 | ||
28 | private-bin bash,electron,electron[0-9],electron[0-9][0-9],env,sh,wire-desktop | 28 | private-bin bash,electron,electron[0-9],electron[0-9][0-9],env,sh,wire-desktop |
29 | private-etc alternatives,ca-certificates,crypto-policies,fonts,ld.so.cache,ld.so.preload,machine-id,pki,resolv.conf,ssl | 29 | private-etc @tls-ca |
30 | 30 | ||
31 | # Redirect | 31 | # Redirect |
32 | include electron.profile | 32 | include electron.profile |
diff --git a/etc/profile-m-z/wordwarvi.profile b/etc/profile-m-z/wordwarvi.profile index ccc2e8dd0..310e8b470 100644 --- a/etc/profile-m-z/wordwarvi.profile +++ b/etc/profile-m-z/wordwarvi.profile | |||
@@ -44,7 +44,7 @@ private | |||
44 | private-bin wordwarvi | 44 | private-bin wordwarvi |
45 | private-cache | 45 | private-cache |
46 | private-dev | 46 | private-dev |
47 | private-etc alsa,alternatives,asound.conf,ld.so.cache,ld.so.preload,machine-id,pulse | 47 | private-etc |
48 | private-tmp | 48 | private-tmp |
49 | 49 | ||
50 | dbus-user none | 50 | dbus-user none |
diff --git a/etc/profile-m-z/xbill.profile b/etc/profile-m-z/xbill.profile index 1b44b63e0..e85bb9f18 100644 --- a/etc/profile-m-z/xbill.profile +++ b/etc/profile-m-z/xbill.profile | |||
@@ -43,7 +43,7 @@ private | |||
43 | private-bin xbill | 43 | private-bin xbill |
44 | private-cache | 44 | private-cache |
45 | private-dev | 45 | private-dev |
46 | private-etc alternatives,ld.so.cache,ld.so.preload | 46 | private-etc |
47 | private-tmp | 47 | private-tmp |
48 | 48 | ||
49 | dbus-user none | 49 | dbus-user none |
diff --git a/etc/profile-m-z/xfce4-mixer.profile b/etc/profile-m-z/xfce4-mixer.profile index 95eb2046e..9c4fa8293 100644 --- a/etc/profile-m-z/xfce4-mixer.profile +++ b/etc/profile-m-z/xfce4-mixer.profile | |||
@@ -45,7 +45,7 @@ disable-mnt | |||
45 | private-bin xfce4-mixer,xfconf-query | 45 | private-bin xfce4-mixer,xfconf-query |
46 | private-cache | 46 | private-cache |
47 | private-dev | 47 | private-dev |
48 | private-etc alternatives,asound.conf,fonts,ld.so.cache,ld.so.preload,machine-id,pulse | 48 | private-etc |
49 | private-tmp | 49 | private-tmp |
50 | 50 | ||
51 | dbus-user filter | 51 | dbus-user filter |
diff --git a/etc/profile-m-z/xfce4-screenshooter.profile b/etc/profile-m-z/xfce4-screenshooter.profile index 575acc9b2..4d841b35c 100644 --- a/etc/profile-m-z/xfce4-screenshooter.profile +++ b/etc/profile-m-z/xfce4-screenshooter.profile | |||
@@ -41,7 +41,7 @@ tracelog | |||
41 | disable-mnt | 41 | disable-mnt |
42 | private-bin xfce4-screenshooter,xfconf-query | 42 | private-bin xfce4-screenshooter,xfconf-query |
43 | private-dev | 43 | private-dev |
44 | private-etc alternatives,ca-certificates,crypto-policies,dconf,fonts,gtk-3.0,ld.so.cache,ld.so.preload,pki,resolv.conf,ssl | 44 | private-etc @tls-ca,@x11 |
45 | private-tmp | 45 | private-tmp |
46 | 46 | ||
47 | dbus-user none | 47 | dbus-user none |
diff --git a/etc/profile-m-z/xiphos.profile b/etc/profile-m-z/xiphos.profile index 371db722c..dd0bbf744 100644 --- a/etc/profile-m-z/xiphos.profile +++ b/etc/profile-m-z/xiphos.profile | |||
@@ -46,7 +46,7 @@ disable-mnt | |||
46 | private-bin xiphos | 46 | private-bin xiphos |
47 | private-cache | 47 | private-cache |
48 | private-dev | 48 | private-dev |
49 | private-etc alternatives,ca-certificates,crypto-policies,fonts,ld.so.cache,ld.so.preload,pki,resolv.conf,ssli,sword,sword.conf | 49 | private-etc @tls-ca,ssli,sword,sword.conf |
50 | private-tmp | 50 | private-tmp |
51 | 51 | ||
52 | restrict-namespaces | 52 | restrict-namespaces |
diff --git a/etc/profile-m-z/xlinks.profile b/etc/profile-m-z/xlinks.profile index 404baf607..b597dc7a2 100644 --- a/etc/profile-m-z/xlinks.profile +++ b/etc/profile-m-z/xlinks.profile | |||
@@ -14,7 +14,7 @@ include whitelist-common.inc | |||
14 | # if you want to use user-configured programs add 'private-bin PROGRAM1,PROGRAM2' | 14 | # if you want to use user-configured programs add 'private-bin PROGRAM1,PROGRAM2' |
15 | # to your xlinks.local or append 'PROGRAM1,PROGRAM2' to this private-bin line | 15 | # to your xlinks.local or append 'PROGRAM1,PROGRAM2' to this private-bin line |
16 | private-bin xlinks | 16 | private-bin xlinks |
17 | private-etc alternatives,fonts,ld.so.cache,ld.so.preload | 17 | private-etc |
18 | 18 | ||
19 | # Redirect | 19 | # Redirect |
20 | include links.profile | 20 | include links.profile |
diff --git a/etc/profile-m-z/xlinks2.profile b/etc/profile-m-z/xlinks2.profile index d7edd3543..83356fb7b 100644 --- a/etc/profile-m-z/xlinks2.profile +++ b/etc/profile-m-z/xlinks2.profile | |||
@@ -14,7 +14,7 @@ include whitelist-common.inc | |||
14 | # if you want to use user-configured programs add 'private-bin PROGRAM1,PROGRAM2' | 14 | # if you want to use user-configured programs add 'private-bin PROGRAM1,PROGRAM2' |
15 | # to your xlinks.local or append 'PROGRAM1,PROGRAM2' to this private-bin line | 15 | # to your xlinks.local or append 'PROGRAM1,PROGRAM2' to this private-bin line |
16 | private-bin xlinks2 | 16 | private-bin xlinks2 |
17 | private-etc alternatives,fonts,ld.so.cache,ld.so.preload | 17 | private-etc |
18 | 18 | ||
19 | # Redirect | 19 | # Redirect |
20 | include links2.profile | 20 | include links2.profile |
diff --git a/etc/profile-m-z/xmr-stak.profile b/etc/profile-m-z/xmr-stak.profile index ad1ba8ca3..b8bf0ae96 100644 --- a/etc/profile-m-z/xmr-stak.profile +++ b/etc/profile-m-z/xmr-stak.profile | |||
@@ -37,7 +37,7 @@ disable-mnt | |||
37 | private ${HOME}/.xmr-stak | 37 | private ${HOME}/.xmr-stak |
38 | private-bin xmr-stak | 38 | private-bin xmr-stak |
39 | private-dev | 39 | private-dev |
40 | private-etc alternatives,ca-certificates,crypto-policies,ld.so.cache,ld.so.preload,nsswitch.conf,pki,resolv.conf,ssl | 40 | private-etc @tls-ca |
41 | #private-lib libxmrstak_opencl_backend,libxmrstak_cuda_backend | 41 | #private-lib libxmrstak_opencl_backend,libxmrstak_cuda_backend |
42 | private-opt cuda | 42 | private-opt cuda |
43 | private-tmp | 43 | private-tmp |
diff --git a/etc/profile-m-z/xonotic.profile b/etc/profile-m-z/xonotic.profile index 9128c330b..87e75986d 100644 --- a/etc/profile-m-z/xonotic.profile +++ b/etc/profile-m-z/xonotic.profile | |||
@@ -45,7 +45,7 @@ disable-mnt | |||
45 | private-cache | 45 | private-cache |
46 | private-bin blind-id,darkplaces-glx,darkplaces-sdl,dirname,ldd,netstat,ps,readlink,sh,uname,xonotic* | 46 | private-bin blind-id,darkplaces-glx,darkplaces-sdl,dirname,ldd,netstat,ps,readlink,sh,uname,xonotic* |
47 | private-dev | 47 | private-dev |
48 | private-etc alternatives,asound.conf,ca-certificates,crypto-policies,drirc,fonts,group,host.conf,hostname,hosts,ld.so.cache,ld.so.preload,localtime,machine-id,nsswitch.conf,passwd,pki,pulse,resolv.conf,ssl | 48 | private-etc @tls-ca,@x11,host.conf |
49 | private-tmp | 49 | private-tmp |
50 | 50 | ||
51 | dbus-user none | 51 | dbus-user none |
diff --git a/etc/profile-m-z/xournal.profile b/etc/profile-m-z/xournal.profile index a17464a2a..e2e97f028 100644 --- a/etc/profile-m-z/xournal.profile +++ b/etc/profile-m-z/xournal.profile | |||
@@ -42,7 +42,7 @@ tracelog | |||
42 | private-bin xournal | 42 | private-bin xournal |
43 | private-cache | 43 | private-cache |
44 | private-dev | 44 | private-dev |
45 | private-etc alternatives,fonts,group,ld.so.cache,ld.so.preload,machine-id,passwd | 45 | private-etc |
46 | # TODO should use private-lib | 46 | # TODO should use private-lib |
47 | private-tmp | 47 | private-tmp |
48 | 48 | ||
diff --git a/etc/profile-m-z/xournalpp.profile b/etc/profile-m-z/xournalpp.profile index a23ad68df..e1c9c03e8 100644 --- a/etc/profile-m-z/xournalpp.profile +++ b/etc/profile-m-z/xournalpp.profile | |||
@@ -28,7 +28,7 @@ include whitelist-runuser-common.inc | |||
28 | #include whitelist-common.inc | 28 | #include whitelist-common.inc |
29 | 29 | ||
30 | private-bin kpsewhich,pdflatex,xournalpp | 30 | private-bin kpsewhich,pdflatex,xournalpp |
31 | private-etc alternatives,latexmk.conf,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,texlive | 31 | private-etc latexmk.conf,texlive |
32 | 32 | ||
33 | # Redirect | 33 | # Redirect |
34 | include xournal.profile | 34 | include xournal.profile |
diff --git a/etc/profile-m-z/xreader.profile b/etc/profile-m-z/xreader.profile index ff5dc619b..6edbf9357 100644 --- a/etc/profile-m-z/xreader.profile +++ b/etc/profile-m-z/xreader.profile | |||
@@ -38,7 +38,7 @@ tracelog | |||
38 | 38 | ||
39 | private-bin xreader,xreader-previewer,xreader-thumbnailer | 39 | private-bin xreader,xreader-previewer,xreader-thumbnailer |
40 | private-dev | 40 | private-dev |
41 | private-etc alternatives,fonts,ld.so.cache,ld.so.preload | 41 | private-etc |
42 | private-tmp | 42 | private-tmp |
43 | 43 | ||
44 | memory-deny-write-execute | 44 | memory-deny-write-execute |
diff --git a/etc/profile-m-z/yelp.profile b/etc/profile-m-z/yelp.profile index 6ea7fdfbd..f5dd0c309 100644 --- a/etc/profile-m-z/yelp.profile +++ b/etc/profile-m-z/yelp.profile | |||
@@ -55,7 +55,7 @@ disable-mnt | |||
55 | private-bin groff,man,tbl,troff,yelp | 55 | private-bin groff,man,tbl,troff,yelp |
56 | private-cache | 56 | private-cache |
57 | private-dev | 57 | private-dev |
58 | private-etc alsa,alternatives,asound.conf,crypto-policies,cups,dconf,drirc,fonts,gcrypt,groff,gtk-3.0,ld.so.cache,ld.so.preload,machine-id,man_db.conf,openal,os-release,pulse,sgml,xml | 58 | private-etc @games,@tls-ca,@x11,cups,groff,man_db.conf,os-release,sgml,xml |
59 | private-tmp | 59 | private-tmp |
60 | 60 | ||
61 | dbus-user filter | 61 | dbus-user filter |
diff --git a/etc/profile-m-z/youtube-dl-gui.profile b/etc/profile-m-z/youtube-dl-gui.profile index c846893ef..b706bec4e 100644 --- a/etc/profile-m-z/youtube-dl-gui.profile +++ b/etc/profile-m-z/youtube-dl-gui.profile | |||
@@ -48,7 +48,7 @@ disable-mnt | |||
48 | private-bin atomicparsley,ffmpeg,ffprobe,python*,youtube-dl-gui | 48 | private-bin atomicparsley,ffmpeg,ffprobe,python*,youtube-dl-gui |
49 | private-cache | 49 | private-cache |
50 | private-dev | 50 | private-dev |
51 | private-etc alternatives,ca-certificates,crypto-policies,dconf,fonts,gtk-2.0,gtk-3.0,hostname,hosts,ld.so.cache,ld.so.preload,locale,locale.conf,passwd,pki,resolv.conf,ssl | 51 | private-etc @tls-ca,@x11 |
52 | private-tmp | 52 | private-tmp |
53 | 53 | ||
54 | dbus-user none | 54 | dbus-user none |
diff --git a/etc/profile-m-z/youtube-dl.profile b/etc/profile-m-z/youtube-dl.profile index 4f2cc9523..8376b4989 100644 --- a/etc/profile-m-z/youtube-dl.profile +++ b/etc/profile-m-z/youtube-dl.profile | |||
@@ -57,7 +57,7 @@ tracelog | |||
57 | private-bin env,ffmpeg,python*,youtube-dl | 57 | private-bin env,ffmpeg,python*,youtube-dl |
58 | private-cache | 58 | private-cache |
59 | private-dev | 59 | private-dev |
60 | private-etc alternatives,ca-certificates,crypto-policies,hostname,hosts,ld.so.cache,ld.so.preload,mime.types,pki,resolv.conf,ssl,youtube-dl.conf | 60 | private-etc @tls-ca,mime.types,youtube-dl.conf |
61 | private-tmp | 61 | private-tmp |
62 | 62 | ||
63 | dbus-user none | 63 | dbus-user none |
diff --git a/etc/profile-m-z/youtube-viewers-common.profile b/etc/profile-m-z/youtube-viewers-common.profile index f66e2938b..9ef90eb92 100644 --- a/etc/profile-m-z/youtube-viewers-common.profile +++ b/etc/profile-m-z/youtube-viewers-common.profile | |||
@@ -59,7 +59,7 @@ disable-mnt | |||
59 | private-bin bash,ffmpeg,ffprobe,firefox,mpv,perl,python*,sh,smplayer,stty,wget,wget2,which,xterm,youtube-dl,yt-dlp | 59 | private-bin bash,ffmpeg,ffprobe,firefox,mpv,perl,python*,sh,smplayer,stty,wget,wget2,which,xterm,youtube-dl,yt-dlp |
60 | private-cache | 60 | private-cache |
61 | private-dev | 61 | private-dev |
62 | private-etc alsa,alternatives,asound.conf,ca-certificates,crypto-policies,fonts,gtk-2.0,gtk-3.0,host.conf,hostname,hosts,ld.so.cache,ld.so.preload,machine-id,mime.types,nsswitch.conf,passwd,pki,pulse,resolv.conf,ssl,X11,xdg | 62 | private-etc @tls-ca,@x11,host.conf,mime.types |
63 | private-tmp | 63 | private-tmp |
64 | 64 | ||
65 | dbus-user filter | 65 | dbus-user filter |
diff --git a/etc/profile-m-z/youtube.profile b/etc/profile-m-z/youtube.profile index 5c4d697da..5049b740e 100644 --- a/etc/profile-m-z/youtube.profile +++ b/etc/profile-m-z/youtube.profile | |||
@@ -17,7 +17,7 @@ mkdir ${HOME}/.config/Youtube | |||
17 | whitelist ${HOME}/.config/Youtube | 17 | whitelist ${HOME}/.config/Youtube |
18 | 18 | ||
19 | private-bin electron,electron[0-9],electron[0-9][0-9],youtube | 19 | private-bin electron,electron[0-9],electron[0-9][0-9],youtube |
20 | private-etc alsa,alternatives,asound.conf,ati,bumblebee,ca-certificates,crypto-policies,drirc,fonts,gtk-2.0,gtk-3.0,host.conf,hostname,hosts,ld.so.cache,ld.so.preload,mime.types,nsswitch.conf,nvidia,pki,pulse,resolv.conf,selinux,ssl,X11,xdg | 20 | private-etc @tls-ca,@x11,bumblebee,host.conf,mime.types,selinux |
21 | private-opt Youtube | 21 | private-opt Youtube |
22 | 22 | ||
23 | # Redirect | 23 | # Redirect |
diff --git a/etc/profile-m-z/youtubemusic-nativefier.profile b/etc/profile-m-z/youtubemusic-nativefier.profile index 2b5ffeaaf..570399557 100644 --- a/etc/profile-m-z/youtubemusic-nativefier.profile +++ b/etc/profile-m-z/youtubemusic-nativefier.profile | |||
@@ -14,7 +14,7 @@ mkdir ${HOME}/.config/youtubemusic-nativefier-040164 | |||
14 | whitelist ${HOME}/.config/youtubemusic-nativefier-040164 | 14 | whitelist ${HOME}/.config/youtubemusic-nativefier-040164 |
15 | 15 | ||
16 | private-bin electron,electron[0-9],electron[0-9][0-9],youtubemusic-nativefier | 16 | private-bin electron,electron[0-9],electron[0-9][0-9],youtubemusic-nativefier |
17 | private-etc alsa,alternatives,asound.conf,ati,bumblebee,ca-certificates,crypto-policies,drirc,fonts,gtk-2.0,gtk-3.0,host.conf,hostname,hosts,ld.so.cache,ld.so.preload,mime.types,nsswitch.conf,nvidia,pki,pulse,resolv.conf,selinux,ssl,X11,xdg | 17 | private-etc @tls-ca,@x11,bumblebee,host.conf,mime.types,selinux |
18 | private-opt youtubemusic-nativefier | 18 | private-opt youtubemusic-nativefier |
19 | 19 | ||
20 | # Redirect | 20 | # Redirect |
diff --git a/etc/profile-m-z/yt-dlp.profile b/etc/profile-m-z/yt-dlp.profile index 6e835b03f..49d4b3b56 100644 --- a/etc/profile-m-z/yt-dlp.profile +++ b/etc/profile-m-z/yt-dlp.profile | |||
@@ -15,7 +15,7 @@ noblacklist ${HOME}/yt-dlp.conf | |||
15 | noblacklist ${HOME}/yt-dlp.conf.txt | 15 | noblacklist ${HOME}/yt-dlp.conf.txt |
16 | 16 | ||
17 | private-bin ffprobe,yt-dlp | 17 | private-bin ffprobe,yt-dlp |
18 | private-etc alternatives,ld.so.cache,ld.so.preload,yt-dlp.conf | 18 | private-etc yt-dlp.conf |
19 | 19 | ||
20 | # Redirect | 20 | # Redirect |
21 | include youtube-dl.profile | 21 | include youtube-dl.profile |
diff --git a/etc/profile-m-z/ytmdesktop.profile b/etc/profile-m-z/ytmdesktop.profile index aa466871c..f74887185 100644 --- a/etc/profile-m-z/ytmdesktop.profile +++ b/etc/profile-m-z/ytmdesktop.profile | |||
@@ -14,7 +14,7 @@ mkdir ${HOME}/.config/youtube-music-desktop-app | |||
14 | whitelist ${HOME}/.config/youtube-music-desktop-app | 14 | whitelist ${HOME}/.config/youtube-music-desktop-app |
15 | 15 | ||
16 | # private-bin env,ytmdesktop | 16 | # private-bin env,ytmdesktop |
17 | private-etc alsa,alternatives,asound.conf,ati,bumblebee,ca-certificates,crypto-policies,drirc,fonts,gtk-2.0,gtk-3.0,host.conf,hostname,hosts,ld.so.cache,ld.so.preload,mime.types,nsswitch.conf,nvidia,pki,pulse,resolv.conf,selinux,ssl,X11,xdg | 17 | private-etc @tls-ca,@x11,bumblebee,host.conf,mime.types,selinux |
18 | # private-opt | 18 | # private-opt |
19 | 19 | ||
20 | # Redirect | 20 | # Redirect |
diff --git a/etc/profile-m-z/zathura.profile b/etc/profile-m-z/zathura.profile index 1daf89c84..35c3f1300 100644 --- a/etc/profile-m-z/zathura.profile +++ b/etc/profile-m-z/zathura.profile | |||
@@ -48,7 +48,7 @@ tracelog | |||
48 | private-bin zathura | 48 | private-bin zathura |
49 | private-cache | 49 | private-cache |
50 | private-dev | 50 | private-dev |
51 | private-etc alternatives,fonts,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,machine-id | 51 | private-etc |
52 | # private-lib has problems on Debian 10 | 52 | # private-lib has problems on Debian 10 |
53 | #private-lib gcc/*/*/libgcc_s.so.*,gcc/*/*/libstdc++.so.*,libarchive.so.*,libdjvulibre.so.*,libgirara-gtk*,libpoppler-glib.so.*,libspectre.so.*,zathura | 53 | #private-lib gcc/*/*/libgcc_s.so.*,gcc/*/*/libstdc++.so.*,libarchive.so.*,libdjvulibre.so.*,libgirara-gtk*,libpoppler-glib.so.*,libspectre.so.*,zathura |
54 | private-tmp | 54 | private-tmp |
diff --git a/etc/profile-m-z/zeal.profile b/etc/profile-m-z/zeal.profile index 453f40e73..7505fb575 100644 --- a/etc/profile-m-z/zeal.profile +++ b/etc/profile-m-z/zeal.profile | |||
@@ -60,7 +60,7 @@ disable-mnt | |||
60 | private-bin zeal | 60 | private-bin zeal |
61 | private-cache | 61 | private-cache |
62 | private-dev | 62 | private-dev |
63 | private-etc alternatives,ca-certificates,crypto-policies,fonts,host.conf,hostname,hosts,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,locale,locale.alias,locale.conf,localtime,mime.types,nsswitch.conf,pango,pki,protocols,resolv.conf,rpc,services,ssl,Trolltech.conf,X11,xdg | 63 | private-etc @tls-ca,@x11,host.conf,mime.types,rpc,services,Trolltech.conf |
64 | private-tmp | 64 | private-tmp |
65 | 65 | ||
66 | dbus-user filter | 66 | dbus-user filter |
diff --git a/etc/profile-m-z/zim.profile b/etc/profile-m-z/zim.profile index a9e5aa5c3..69ec3a706 100644 --- a/etc/profile-m-z/zim.profile +++ b/etc/profile-m-z/zim.profile | |||
@@ -63,7 +63,7 @@ disable-mnt | |||
63 | private-bin python*,zim | 63 | private-bin python*,zim |
64 | private-cache | 64 | private-cache |
65 | private-dev | 65 | private-dev |
66 | private-etc alternatives,dconf,fonts,gconf,gtk-2.0,gtk-3.0,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,pango,X11 | 66 | private-etc @x11,gconf |
67 | private-tmp | 67 | private-tmp |
68 | 68 | ||
69 | dbus-user none | 69 | dbus-user none |
diff --git a/etc/profile-m-z/zulip.profile b/etc/profile-m-z/zulip.profile index b69de3be1..1622b3886 100644 --- a/etc/profile-m-z/zulip.profile +++ b/etc/profile-m-z/zulip.profile | |||
@@ -43,7 +43,7 @@ disable-mnt | |||
43 | private-bin locale,zulip | 43 | private-bin locale,zulip |
44 | private-cache | 44 | private-cache |
45 | private-dev | 45 | private-dev |
46 | private-etc alternatives,asound.conf,fonts,ld.so.cache,ld.so.preload,machine-id | 46 | private-etc |
47 | private-tmp | 47 | private-tmp |
48 | 48 | ||
49 | restrict-namespaces | 49 | restrict-namespaces |