summaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
authorLibravatar SYN-cook <syncookongit@gmail.com>2017-03-31 05:06:50 +0200
committerLibravatar Fred Barclay <Fred-Barclay@users.noreply.github.com>2017-03-31 03:06:50 +0000
commit81c50814dd5a9a2e8aa5100bb7305649fa5b698f (patch)
tree483250f6b9df8d6ea46804e4d0f857c3f46cd611 /etc
parenttypo (diff)
downloadfirejail-81c50814dd5a9a2e8aa5100bb7305649fa5b698f.tar.gz
firejail-81c50814dd5a9a2e8aa5100bb7305649fa5b698f.tar.zst
firejail-81c50814dd5a9a2e8aa5100bb7305649fa5b698f.zip
restrict more KDE files (#1181)
* update noblacklist * blacklist local plasma overrides, plasmoids * add more KDE configuration (kdeglobals, plasmoids) * kdeglobals now in disable-common.inc
Diffstat (limited to 'etc')
-rw-r--r--etc/disable-common.inc13
-rw-r--r--etc/gwenview.profile2
-rw-r--r--etc/okular.profile2
3 files changed, 13 insertions, 4 deletions
diff --git a/etc/disable-common.inc b/etc/disable-common.inc
index 45541906a..0ada3314f 100644
--- a/etc/disable-common.inc
+++ b/etc/disable-common.inc
@@ -45,24 +45,33 @@ blacklist ${HOME}/.fluxbox/startup
45# blacklist ${HOME}/.xpra - this will kill --x11=xpra cmdline option for all programs 45# blacklist ${HOME}/.xpra - this will kill --x11=xpra cmdline option for all programs
46 46
47# KDE config 47# KDE config
48blacklist ${HOME}/.kde4/share/apps/solid
49blacklist ${HOME}/.kde4/share/apps/konsole 48blacklist ${HOME}/.kde4/share/apps/konsole
49blacklist ${HOME}/.kde4/share/apps/plasma
50blacklist ${HOME}/.kde4/share/apps/solid
50blacklist ${HOME}/.kde4/share/config/*.notifyrc 51blacklist ${HOME}/.kde4/share/config/*.notifyrc
52read-only ${HOME}/.kde4/share/config/kdeglobals
51blacklist ${HOME}/.kde4/share/config/khotkeysrc 53blacklist ${HOME}/.kde4/share/config/khotkeysrc
52blacklist ${HOME}/.kde4/share/config/krunnerrc 54blacklist ${HOME}/.kde4/share/config/krunnerrc
55blacklist ${HOME}/.kde4/share/config/plasma-desktop-appletsrc
53blacklist ${HOME}/.kde4/share/kde4/services 56blacklist ${HOME}/.kde4/share/kde4/services
54blacklist ${HOME}/.kde/share/apps/solid
55blacklist ${HOME}/.kde/share/apps/konsole 57blacklist ${HOME}/.kde/share/apps/konsole
58blacklist ${HOME}/.kde/share/apps/plasma
59blacklist ${HOME}/.kde/share/apps/solid
56blacklist ${HOME}/.kde/share/config/*.notifyrc 60blacklist ${HOME}/.kde/share/config/*.notifyrc
61read-only ${HOME}/.kde/share/config/kdeglobals
57blacklist ${HOME}/.kde/share/config/khotkeysrc 62blacklist ${HOME}/.kde/share/config/khotkeysrc
58blacklist ${HOME}/.kde/share/config/krunnerrc 63blacklist ${HOME}/.kde/share/config/krunnerrc
64blacklist ${HOME}/.kde/share/config/plasma-desktop-appletsrc
59blacklist ${HOME}/.kde/share/kde4/services 65blacklist ${HOME}/.kde/share/kde4/services
60blacklist ${HOME}/.config/*.notifyrc 66blacklist ${HOME}/.config/*.notifyrc
67read-only ${HOME}/.config/kdeglobals
61blacklist ${HOME}/.config/khotkeysrc 68blacklist ${HOME}/.config/khotkeysrc
62blacklist ${HOME}/.config/krunnerrc 69blacklist ${HOME}/.config/krunnerrc
70blacklist ${HOME}/.config/plasma-org.kde.plasma.desktop-appletsrc
63blacklist ${HOME}/.local/share/kglobalaccel 71blacklist ${HOME}/.local/share/kglobalaccel
64blacklist ${HOME}/.local/share/konsole 72blacklist ${HOME}/.local/share/konsole
65blacklist ${HOME}/.local/share/kservices5 73blacklist ${HOME}/.local/share/kservices5
74blacklist ${HOME}/.local/share/plasma
66blacklist ${HOME}/.local/share/solid 75blacklist ${HOME}/.local/share/solid
67 76
68# VirtualBox 77# VirtualBox
diff --git a/etc/gwenview.profile b/etc/gwenview.profile
index b8067866c..35e39a3ce 100644
--- a/etc/gwenview.profile
+++ b/etc/gwenview.profile
@@ -3,6 +3,8 @@
3include /etc/firejail/gwenview.local 3include /etc/firejail/gwenview.local
4 4
5# KDE gwenview profile 5# KDE gwenview profile
6noblacklist ~/.kde4/share/apps/gwenview
7noblacklist ~/.kde4/share/config/gwenviewrc
6noblacklist ~/.kde/share/apps/gwenview 8noblacklist ~/.kde/share/apps/gwenview
7noblacklist ~/.kde/share/config/gwenviewrc 9noblacklist ~/.kde/share/config/gwenviewrc
8noblacklist ~/.config/gwenviewrc 10noblacklist ~/.config/gwenviewrc
diff --git a/etc/okular.profile b/etc/okular.profile
index 07819068e..b4ee3ad32 100644
--- a/etc/okular.profile
+++ b/etc/okular.profile
@@ -6,11 +6,9 @@ include /etc/firejail/okular.local
6noblacklist ~/.kde4/share/apps/okular 6noblacklist ~/.kde4/share/apps/okular
7noblacklist ~/.kde4/share/config/okularrc 7noblacklist ~/.kde4/share/config/okularrc
8noblacklist ~/.kde4/share/config/okularpartrc 8noblacklist ~/.kde4/share/config/okularpartrc
9read-only ~/.kde4/share/config/kdeglobals
10noblacklist ~/.kde/share/apps/okular 9noblacklist ~/.kde/share/apps/okular
11noblacklist ~/.kde/share/config/okularrc 10noblacklist ~/.kde/share/config/okularrc
12noblacklist ~/.kde/share/config/okularpartrc 11noblacklist ~/.kde/share/config/okularpartrc
13read-only ~/.kde/share/config/kdeglobals
14include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
15include /etc/firejail/disable-programs.inc 13include /etc/firejail/disable-programs.inc
16include /etc/firejail/disable-devel.inc 14include /etc/firejail/disable-devel.inc