aboutsummaryrefslogtreecommitdiffstats
path: root/etc/profile-m-z
diff options
context:
space:
mode:
authorLibravatar Kelvin M. Klann <kmk3.code@protonmail.com>2024-03-24 06:50:30 +0000
committerLibravatar GitHub <noreply@github.com>2024-03-24 06:50:30 +0000
commiteaee3367d26059cc6d1adcd239cfdbba091ce73e (patch)
tree329ff4e2d3039ff65389f4225dbd8714ab867114 /etc/profile-m-z
parentprofiles: deny access to ~/.config/autostart (#6257) (diff)
parentprofiles: replace x11 socket blacklist with disable-X11.inc (diff)
downloadfirejail-eaee3367d26059cc6d1adcd239cfdbba091ce73e.tar.gz
firejail-eaee3367d26059cc6d1adcd239cfdbba091ce73e.tar.zst
firejail-eaee3367d26059cc6d1adcd239cfdbba091ce73e.zip
Merge pull request #6286 from kmk3/x11-none-improvements
profiles: replace x11 socket blacklist with disable-X11.inc
Diffstat (limited to 'etc/profile-m-z')
-rw-r--r--etc/profile-m-z/makepkg.profile2
-rw-r--r--etc/profile-m-z/mimetype.profile2
-rw-r--r--etc/profile-m-z/mocp.profile2
-rw-r--r--etc/profile-m-z/mutt.profile2
-rw-r--r--etc/profile-m-z/neomutt.profile2
-rw-r--r--etc/profile-m-z/nslookup.profile2
-rw-r--r--etc/profile-m-z/rsync-download_only.profile2
-rw-r--r--etc/profile-m-z/rtv.profile2
-rw-r--r--etc/profile-m-z/server.profile2
-rw-r--r--etc/profile-m-z/signal-cli.profile2
-rw-r--r--etc/profile-m-z/ssh-agent.profile2
-rw-r--r--etc/profile-m-z/ssmtp.profile2
-rw-r--r--etc/profile-m-z/statusof.profile2
-rw-r--r--etc/profile-m-z/termshark.profile3
-rw-r--r--etc/profile-m-z/tin.profile2
-rw-r--r--etc/profile-m-z/tmux.profile2
-rw-r--r--etc/profile-m-z/tracker.profile2
-rw-r--r--etc/profile-m-z/tshark.profile3
-rw-r--r--etc/profile-m-z/tvnamer.profile2
-rw-r--r--etc/profile-m-z/unbound.profile2
-rw-r--r--etc/profile-m-z/w3m.profile2
-rw-r--r--etc/profile-m-z/wget.profile2
-rw-r--r--etc/profile-m-z/whois.profile2
-rw-r--r--etc/profile-m-z/yt-dlp.profile2
24 files changed, 26 insertions, 24 deletions
diff --git a/etc/profile-m-z/makepkg.profile b/etc/profile-m-z/makepkg.profile
index 49e84dedb..3bda47fad 100644
--- a/etc/profile-m-z/makepkg.profile
+++ b/etc/profile-m-z/makepkg.profile
@@ -7,7 +7,6 @@ include makepkg.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10blacklist /tmp/.X11-unix
11blacklist ${RUNUSER}/wayland-* 10blacklist ${RUNUSER}/wayland-*
12 11
13# Note: see this Arch forum discussion https://bbs.archlinux.org/viewtopic.php?pid=1743138 12# Note: see this Arch forum discussion https://bbs.archlinux.org/viewtopic.php?pid=1743138
@@ -33,6 +32,7 @@ noblacklist /var/lib/pacman
33include disable-common.inc 32include disable-common.inc
34include disable-exec.inc 33include disable-exec.inc
35include disable-programs.inc 34include disable-programs.inc
35include disable-X11.inc
36 36
37caps.drop all 37caps.drop all
38ipc-namespace 38ipc-namespace
diff --git a/etc/profile-m-z/mimetype.profile b/etc/profile-m-z/mimetype.profile
index 9902da882..4b62624bb 100644
--- a/etc/profile-m-z/mimetype.profile
+++ b/etc/profile-m-z/mimetype.profile
@@ -7,11 +7,11 @@ include mimetype.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10blacklist /tmp/.X11-unix
11blacklist ${RUNUSER}/wayland-* 10blacklist ${RUNUSER}/wayland-*
12 11
13include disable-exec.inc 12include disable-exec.inc
14include disable-proc.inc 13include disable-proc.inc
14include disable-X11.inc
15 15
16apparmor 16apparmor
17caps.drop all 17caps.drop all
diff --git a/etc/profile-m-z/mocp.profile b/etc/profile-m-z/mocp.profile
index 0a5e4255a..d80e263b6 100644
--- a/etc/profile-m-z/mocp.profile
+++ b/etc/profile-m-z/mocp.profile
@@ -10,7 +10,6 @@ include globals.local
10noblacklist ${HOME}/.moc 10noblacklist ${HOME}/.moc
11noblacklist ${MUSIC} 11noblacklist ${MUSIC}
12 12
13blacklist /tmp/.X11-unix
14blacklist ${RUNUSER}/wayland-* 13blacklist ${RUNUSER}/wayland-*
15 14
16include disable-common.inc 15include disable-common.inc
@@ -19,6 +18,7 @@ include disable-exec.inc
19include disable-interpreters.inc 18include disable-interpreters.inc
20include disable-proc.inc 19include disable-proc.inc
21include disable-programs.inc 20include disable-programs.inc
21include disable-X11.inc
22include disable-xdg.inc 22include disable-xdg.inc
23 23
24mkdir ${HOME}/.moc 24mkdir ${HOME}/.moc
diff --git a/etc/profile-m-z/mutt.profile b/etc/profile-m-z/mutt.profile
index 097ce6e83..447301d46 100644
--- a/etc/profile-m-z/mutt.profile
+++ b/etc/profile-m-z/mutt.profile
@@ -38,7 +38,6 @@ noblacklist ${HOME}/postponed
38noblacklist ${HOME}/sent 38noblacklist ${HOME}/sent
39noblacklist /etc/msmtprc 39noblacklist /etc/msmtprc
40 40
41blacklist /tmp/.X11-unix
42blacklist ${RUNUSER}/wayland-* 41blacklist ${RUNUSER}/wayland-*
43 42
44# Add the next lines to your mutt.local for oauth.py,S/MIME support. 43# Add the next lines to your mutt.local for oauth.py,S/MIME support.
@@ -51,6 +50,7 @@ include disable-devel.inc
51include disable-exec.inc 50include disable-exec.inc
52include disable-interpreters.inc 51include disable-interpreters.inc
53include disable-programs.inc 52include disable-programs.inc
53include disable-X11.inc
54include disable-xdg.inc 54include disable-xdg.inc
55 55
56mkdir ${HOME}/.Mail 56mkdir ${HOME}/.Mail
diff --git a/etc/profile-m-z/neomutt.profile b/etc/profile-m-z/neomutt.profile
index 51e2e43bf..22720422b 100644
--- a/etc/profile-m-z/neomutt.profile
+++ b/etc/profile-m-z/neomutt.profile
@@ -39,7 +39,6 @@ noblacklist /etc/msmtprc
39noblacklist /var/mail 39noblacklist /var/mail
40noblacklist /var/spool/mail 40noblacklist /var/spool/mail
41 41
42blacklist /tmp/.X11-unix
43blacklist ${RUNUSER}/wayland-* 42blacklist ${RUNUSER}/wayland-*
44 43
45include allow-lua.inc 44include allow-lua.inc
@@ -49,6 +48,7 @@ include disable-devel.inc
49include disable-exec.inc 48include disable-exec.inc
50include disable-interpreters.inc 49include disable-interpreters.inc
51include disable-programs.inc 50include disable-programs.inc
51include disable-X11.inc
52include disable-xdg.inc 52include disable-xdg.inc
53 53
54mkdir ${HOME}/.Mail 54mkdir ${HOME}/.Mail
diff --git a/etc/profile-m-z/nslookup.profile b/etc/profile-m-z/nslookup.profile
index dcd76f2ad..aae506b0b 100644
--- a/etc/profile-m-z/nslookup.profile
+++ b/etc/profile-m-z/nslookup.profile
@@ -7,7 +7,6 @@ include nslookup.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10blacklist /tmp/.X11-unix
11blacklist ${RUNUSER} 10blacklist ${RUNUSER}
12 11
13noblacklist ${PATH}/nslookup 12noblacklist ${PATH}/nslookup
@@ -17,6 +16,7 @@ include disable-devel.inc
17include disable-exec.inc 16include disable-exec.inc
18include disable-interpreters.inc 17include disable-interpreters.inc
19include disable-programs.inc 18include disable-programs.inc
19include disable-X11.inc
20include disable-xdg.inc 20include disable-xdg.inc
21 21
22whitelist ${HOME}/.nslookuprc 22whitelist ${HOME}/.nslookuprc
diff --git a/etc/profile-m-z/rsync-download_only.profile b/etc/profile-m-z/rsync-download_only.profile
index ce90012e3..52ccb4309 100644
--- a/etc/profile-m-z/rsync-download_only.profile
+++ b/etc/profile-m-z/rsync-download_only.profile
@@ -11,7 +11,6 @@ include globals.local
11# not as a daemon (rsync --daemon) nor to create backups. 11# not as a daemon (rsync --daemon) nor to create backups.
12# Usage: firejail --profile=rsync-download_only rsync 12# Usage: firejail --profile=rsync-download_only rsync
13 13
14blacklist /tmp/.X11-unix
15blacklist ${RUNUSER} 14blacklist ${RUNUSER}
16 15
17include disable-common.inc 16include disable-common.inc
@@ -20,6 +19,7 @@ include disable-exec.inc
20include disable-interpreters.inc 19include disable-interpreters.inc
21include disable-programs.inc 20include disable-programs.inc
22include disable-shell.inc 21include disable-shell.inc
22include disable-X11.inc
23include disable-xdg.inc 23include disable-xdg.inc
24 24
25# Add the next line to your rsync-download_only.local to enable extra hardening. 25# Add the next line to your rsync-download_only.local to enable extra hardening.
diff --git a/etc/profile-m-z/rtv.profile b/etc/profile-m-z/rtv.profile
index 0d57e6916..e719b0d0d 100644
--- a/etc/profile-m-z/rtv.profile
+++ b/etc/profile-m-z/rtv.profile
@@ -6,7 +6,6 @@ include rtv.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9blacklist /tmp/.X11-unix
10blacklist ${RUNUSER}/wayland-* 9blacklist ${RUNUSER}/wayland-*
11 10
12noblacklist ${HOME}/.config/rtv 11noblacklist ${HOME}/.config/rtv
@@ -28,6 +27,7 @@ include disable-devel.inc
28include disable-exec.inc 27include disable-exec.inc
29include disable-interpreters.inc 28include disable-interpreters.inc
30include disable-programs.inc 29include disable-programs.inc
30include disable-X11.inc
31include disable-xdg.inc 31include disable-xdg.inc
32 32
33mkdir ${HOME}/.config/rtv 33mkdir ${HOME}/.config/rtv
diff --git a/etc/profile-m-z/server.profile b/etc/profile-m-z/server.profile
index 74587c992..a77cf7e0b 100644
--- a/etc/profile-m-z/server.profile
+++ b/etc/profile-m-z/server.profile
@@ -36,7 +36,6 @@ noblacklist /usr/sbin
36noblacklist /etc/init.d 36noblacklist /etc/init.d
37#noblacklist /var/opt 37#noblacklist /var/opt
38 38
39blacklist /tmp/.X11-unix
40blacklist ${RUNUSER}/wayland-* 39blacklist ${RUNUSER}/wayland-*
41 40
42include disable-common.inc 41include disable-common.inc
@@ -45,6 +44,7 @@ include disable-common.inc
45#include disable-interpreters.inc 44#include disable-interpreters.inc
46include disable-programs.inc 45include disable-programs.inc
47include disable-write-mnt.inc 46include disable-write-mnt.inc
47include disable-X11.inc
48include disable-xdg.inc 48include disable-xdg.inc
49 49
50#include whitelist-runuser-common.inc 50#include whitelist-runuser-common.inc
diff --git a/etc/profile-m-z/signal-cli.profile b/etc/profile-m-z/signal-cli.profile
index d881db714..979d71b33 100644
--- a/etc/profile-m-z/signal-cli.profile
+++ b/etc/profile-m-z/signal-cli.profile
@@ -6,7 +6,6 @@ include signal-cli.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9blacklist /tmp/.X11-unix
10blacklist ${RUNUSER}/wayland-* 9blacklist ${RUNUSER}/wayland-*
11 10
12noblacklist ${HOME}/.local/share/signal-cli 11noblacklist ${HOME}/.local/share/signal-cli
@@ -18,6 +17,7 @@ include disable-devel.inc
18include disable-exec.inc 17include disable-exec.inc
19include disable-interpreters.inc 18include disable-interpreters.inc
20include disable-programs.inc 19include disable-programs.inc
20include disable-X11.inc
21include disable-xdg.inc 21include disable-xdg.inc
22 22
23mkdir ${HOME}/.local/share/signal-cli 23mkdir ${HOME}/.local/share/signal-cli
diff --git a/etc/profile-m-z/ssh-agent.profile b/etc/profile-m-z/ssh-agent.profile
index 76755def4..6630244be 100644
--- a/etc/profile-m-z/ssh-agent.profile
+++ b/etc/profile-m-z/ssh-agent.profile
@@ -9,11 +9,11 @@ include globals.local
9# Allow ssh (blacklisted by disable-common.inc) 9# Allow ssh (blacklisted by disable-common.inc)
10include allow-ssh.inc 10include allow-ssh.inc
11 11
12blacklist /tmp/.X11-unix
13blacklist ${RUNUSER}/wayland-* 12blacklist ${RUNUSER}/wayland-*
14 13
15include disable-common.inc 14include disable-common.inc
16include disable-programs.inc 15include disable-programs.inc
16include disable-X11.inc
17 17
18include whitelist-usr-share-common.inc 18include whitelist-usr-share-common.inc
19 19
diff --git a/etc/profile-m-z/ssmtp.profile b/etc/profile-m-z/ssmtp.profile
index b87f514f9..356a732e7 100644
--- a/etc/profile-m-z/ssmtp.profile
+++ b/etc/profile-m-z/ssmtp.profile
@@ -24,8 +24,8 @@ include disable-interpreters.inc
24include disable-proc.inc 24include disable-proc.inc
25include disable-programs.inc 25include disable-programs.inc
26include disable-shell.inc 26include disable-shell.inc
27include disable-xdg.inc
28include disable-X11.inc 27include disable-X11.inc
28include disable-xdg.inc
29 29
30mkfile ${HOME}/dead.letter 30mkfile ${HOME}/dead.letter
31whitelist ${HOME}/dead.letter 31whitelist ${HOME}/dead.letter
diff --git a/etc/profile-m-z/statusof.profile b/etc/profile-m-z/statusof.profile
index 7463b90f5..25c8df680 100644
--- a/etc/profile-m-z/statusof.profile
+++ b/etc/profile-m-z/statusof.profile
@@ -7,7 +7,6 @@ include statusof.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10blacklist /tmp/.X11-unix
11blacklist /usr/libexec 10blacklist /usr/libexec
12blacklist ${RUNUSER} 11blacklist ${RUNUSER}
13 12
@@ -21,6 +20,7 @@ include disable-interpreters.inc
21include disable-proc.inc 20include disable-proc.inc
22include disable-programs.inc 21include disable-programs.inc
23include disable-shell.inc 22include disable-shell.inc
23include disable-X11.inc
24include disable-xdg.inc 24include disable-xdg.inc
25 25
26include whitelist-common.inc 26include whitelist-common.inc
diff --git a/etc/profile-m-z/termshark.profile b/etc/profile-m-z/termshark.profile
index 630d5dda6..bdee14e64 100644
--- a/etc/profile-m-z/termshark.profile
+++ b/etc/profile-m-z/termshark.profile
@@ -8,8 +8,9 @@ include termshark.local
8# added by included profile 8# added by included profile
9#include globals.local 9#include globals.local
10 10
11blacklist /tmp/.X11-unix
12blacklist ${RUNUSER} 11blacklist ${RUNUSER}
13 12
13include disable-X11.inc
14
14# Redirect 15# Redirect
15include wireshark.profile 16include wireshark.profile
diff --git a/etc/profile-m-z/tin.profile b/etc/profile-m-z/tin.profile
index 35ff14e88..7c1d534e9 100644
--- a/etc/profile-m-z/tin.profile
+++ b/etc/profile-m-z/tin.profile
@@ -9,7 +9,6 @@ include globals.local
9noblacklist ${HOME}/.newsrc 9noblacklist ${HOME}/.newsrc
10noblacklist ${HOME}/.tin 10noblacklist ${HOME}/.tin
11 11
12blacklist /tmp/.X11-unix
13blacklist ${RUNUSER} 12blacklist ${RUNUSER}
14blacklist /usr/libexec 13blacklist /usr/libexec
15 14
@@ -19,6 +18,7 @@ include disable-exec.inc
19include disable-interpreters.inc 18include disable-interpreters.inc
20include disable-programs.inc 19include disable-programs.inc
21include disable-shell.inc 20include disable-shell.inc
21include disable-X11.inc
22include disable-xdg.inc 22include disable-xdg.inc
23 23
24mkdir ${HOME}/.tin 24mkdir ${HOME}/.tin
diff --git a/etc/profile-m-z/tmux.profile b/etc/profile-m-z/tmux.profile
index ddd2aa85f..55d84a618 100644
--- a/etc/profile-m-z/tmux.profile
+++ b/etc/profile-m-z/tmux.profile
@@ -7,7 +7,6 @@ include tmux.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10blacklist /tmp/.X11-unix
11blacklist ${RUNUSER} 10blacklist ${RUNUSER}
12 11
13noblacklist /tmp/tmux-* 12noblacklist /tmp/tmux-*
@@ -16,6 +15,7 @@ noblacklist /tmp/tmux-*
16#include disable-devel.inc 15#include disable-devel.inc
17#include disable-exec.inc 16#include disable-exec.inc
18#include disable-programs.inc 17#include disable-programs.inc
18include disable-X11.inc
19 19
20caps.drop all 20caps.drop all
21ipc-namespace 21ipc-namespace
diff --git a/etc/profile-m-z/tracker.profile b/etc/profile-m-z/tracker.profile
index c46b00fc9..8a3464496 100644
--- a/etc/profile-m-z/tracker.profile
+++ b/etc/profile-m-z/tracker.profile
@@ -8,7 +8,6 @@ include globals.local
8 8
9# Tracker is started by systemd on most systems. Therefore it is not firejailed by default 9# Tracker is started by systemd on most systems. Therefore it is not firejailed by default
10 10
11blacklist /tmp/.X11-unix
12blacklist ${RUNUSER}/wayland-* 11blacklist ${RUNUSER}/wayland-*
13 12
14include disable-common.inc 13include disable-common.inc
@@ -16,6 +15,7 @@ include disable-devel.inc
16include disable-interpreters.inc 15include disable-interpreters.inc
17include disable-programs.inc 16include disable-programs.inc
18include disable-shell.inc 17include disable-shell.inc
18include disable-X11.inc
19 19
20include whitelist-runuser-common.inc 20include whitelist-runuser-common.inc
21 21
diff --git a/etc/profile-m-z/tshark.profile b/etc/profile-m-z/tshark.profile
index f2273e6a7..fab45a334 100644
--- a/etc/profile-m-z/tshark.profile
+++ b/etc/profile-m-z/tshark.profile
@@ -7,8 +7,9 @@ include tshark.local
7# added by included profile 7# added by included profile
8#include globals.local 8#include globals.local
9 9
10blacklist /tmp/.X11-unix
11blacklist ${RUNUSER} 10blacklist ${RUNUSER}
12 11
12include disable-X11.inc
13
13# Redirect 14# Redirect
14include wireshark.profile 15include wireshark.profile
diff --git a/etc/profile-m-z/tvnamer.profile b/etc/profile-m-z/tvnamer.profile
index ccfd07e40..24439672a 100644
--- a/etc/profile-m-z/tvnamer.profile
+++ b/etc/profile-m-z/tvnamer.profile
@@ -6,7 +6,6 @@ include tvnamer.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9blacklist /tmp/.X11-unix
10blacklist /usr/libexec 9blacklist /usr/libexec
11blacklist ${RUNUSER} 10blacklist ${RUNUSER}
12 11
@@ -24,6 +23,7 @@ include disable-interpreters.inc
24include disable-programs.inc 23include disable-programs.inc
25include disable-proc.inc 24include disable-proc.inc
26include disable-shell.inc 25include disable-shell.inc
26include disable-X11.inc
27include disable-xdg.inc 27include disable-xdg.inc
28 28
29mkdir ${HOME}/.config/tvnamer 29mkdir ${HOME}/.config/tvnamer
diff --git a/etc/profile-m-z/unbound.profile b/etc/profile-m-z/unbound.profile
index 63d84688c..dfce92e2d 100644
--- a/etc/profile-m-z/unbound.profile
+++ b/etc/profile-m-z/unbound.profile
@@ -9,7 +9,6 @@ include globals.local
9noblacklist /sbin 9noblacklist /sbin
10noblacklist /usr/sbin 10noblacklist /usr/sbin
11 11
12blacklist /tmp/.X11-unix
13blacklist ${RUNUSER} 12blacklist ${RUNUSER}
14 13
15include disable-common.inc 14include disable-common.inc
@@ -17,6 +16,7 @@ include disable-devel.inc
17include disable-exec.inc 16include disable-exec.inc
18include disable-interpreters.inc 17include disable-interpreters.inc
19include disable-programs.inc 18include disable-programs.inc
19include disable-X11.inc
20include disable-xdg.inc 20include disable-xdg.inc
21 21
22whitelist /usr/share/dns 22whitelist /usr/share/dns
diff --git a/etc/profile-m-z/w3m.profile b/etc/profile-m-z/w3m.profile
index edc08ca44..4e2f1bb3e 100644
--- a/etc/profile-m-z/w3m.profile
+++ b/etc/profile-m-z/w3m.profile
@@ -14,7 +14,6 @@ include globals.local
14 14
15noblacklist ${HOME}/.w3m 15noblacklist ${HOME}/.w3m
16 16
17blacklist /tmp/.X11-unix
18blacklist ${RUNUSER}/wayland-* 17blacklist ${RUNUSER}/wayland-*
19 18
20# Allow /bin/sh (blacklisted by disable-shell.inc) 19# Allow /bin/sh (blacklisted by disable-shell.inc)
@@ -29,6 +28,7 @@ include disable-exec.inc
29include disable-interpreters.inc 28include disable-interpreters.inc
30include disable-programs.inc 29include disable-programs.inc
31include disable-shell.inc 30include disable-shell.inc
31include disable-X11.inc
32include disable-xdg.inc 32include disable-xdg.inc
33 33
34mkdir ${HOME}/.w3m 34mkdir ${HOME}/.w3m
diff --git a/etc/profile-m-z/wget.profile b/etc/profile-m-z/wget.profile
index 5e1823593..90a1d3d7a 100644
--- a/etc/profile-m-z/wget.profile
+++ b/etc/profile-m-z/wget.profile
@@ -15,7 +15,6 @@ noblacklist ${HOME}/.wgetrc
15#ignore read-only ${HOME}/.nvm 15#ignore read-only ${HOME}/.nvm
16#noblacklist ${HOME}/.nvm 16#noblacklist ${HOME}/.nvm
17 17
18blacklist /tmp/.X11-unix
19blacklist ${RUNUSER} 18blacklist ${RUNUSER}
20 19
21include disable-common.inc 20include disable-common.inc
@@ -24,6 +23,7 @@ include disable-exec.inc
24include disable-interpreters.inc 23include disable-interpreters.inc
25include disable-programs.inc 24include disable-programs.inc
26include disable-shell.inc 25include disable-shell.inc
26include disable-X11.inc
27# Depending on workflow you can add the next line to your wget.local. 27# Depending on workflow you can add the next line to your wget.local.
28#include disable-xdg.inc 28#include disable-xdg.inc
29 29
diff --git a/etc/profile-m-z/whois.profile b/etc/profile-m-z/whois.profile
index 8265e1ff8..e7f66cf76 100644
--- a/etc/profile-m-z/whois.profile
+++ b/etc/profile-m-z/whois.profile
@@ -7,7 +7,6 @@ include whois.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10blacklist /tmp/.X11-unix
11blacklist ${RUNUSER} 10blacklist ${RUNUSER}
12 11
13include disable-common.inc 12include disable-common.inc
@@ -15,6 +14,7 @@ include disable-devel.inc
15include disable-exec.inc 14include disable-exec.inc
16include disable-interpreters.inc 15include disable-interpreters.inc
17include disable-programs.inc 16include disable-programs.inc
17include disable-X11.inc
18include disable-xdg.inc 18include disable-xdg.inc
19 19
20include whitelist-usr-share-common.inc 20include whitelist-usr-share-common.inc
diff --git a/etc/profile-m-z/yt-dlp.profile b/etc/profile-m-z/yt-dlp.profile
index 97f9e620a..6dd9d03a3 100644
--- a/etc/profile-m-z/yt-dlp.profile
+++ b/etc/profile-m-z/yt-dlp.profile
@@ -29,7 +29,6 @@ noblacklist ${VIDEOS}
29# Allow python (blacklisted by disable-interpreters.inc) 29# Allow python (blacklisted by disable-interpreters.inc)
30include allow-python3.inc 30include allow-python3.inc
31 31
32blacklist /tmp/.X11-unix
33blacklist ${RUNUSER} 32blacklist ${RUNUSER}
34 33
35include disable-common.inc 34include disable-common.inc
@@ -38,6 +37,7 @@ include disable-exec.inc
38include disable-interpreters.inc 37include disable-interpreters.inc
39include disable-programs.inc 38include disable-programs.inc
40include disable-shell.inc 39include disable-shell.inc
40include disable-X11.inc
41include disable-xdg.inc 41include disable-xdg.inc
42 42
43include whitelist-usr-share-common.inc 43include whitelist-usr-share-common.inc