summaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
authorLibravatar netblue30 <netblue30@yahoo.com>2017-11-02 13:03:34 -0400
committerLibravatar netblue30 <netblue30@yahoo.com>2017-11-02 13:03:34 -0400
commitac5a936b331ab738ff5dadfb5153b6480f9b0bce (patch)
tree417ef1eb2481f9aab8627099ec48d11aa5493483 /etc
parentfixing filesystem reporting for firetools (diff)
downloadfirejail-ac5a936b331ab738ff5dadfb5153b6480f9b0bce.tar.gz
firejail-ac5a936b331ab738ff5dadfb5153b6480f9b0bce.tar.zst
firejail-ac5a936b331ab738ff5dadfb5153b6480f9b0bce.zip
matching noblacklist in profile files with blacklist in disable-programs.inc
Diffstat (limited to 'etc')
-rw-r--r--etc/atril.profile4
-rw-r--r--etc/bitlbee.profile2
-rw-r--r--etc/brackets.profile4
-rw-r--r--etc/caja.profile6
-rw-r--r--etc/cherrytree.profile4
-rw-r--r--etc/cliqz.profile2
-rw-r--r--etc/digikam.profile1
-rw-r--r--etc/disable-common.inc12
-rw-r--r--etc/disable-programs.inc46
-rw-r--r--etc/dolphin.profile4
-rw-r--r--etc/evolution.profile3
-rw-r--r--etc/firefox.profile2
-rw-r--r--etc/gnome-mplayer.profile1
-rw-r--r--etc/inkscape.profile2
-rw-r--r--etc/krita.profile1
-rw-r--r--etc/kwrite.profile1
-rw-r--r--etc/lximage-qt.profile2
-rw-r--r--etc/midori.profile4
-rw-r--r--etc/openbox.profile2
-rw-r--r--etc/pcmanfm.profile4
-rw-r--r--etc/vlc.profile1
-rw-r--r--etc/vym.profile2
-rw-r--r--etc/waterfox.profile2
-rw-r--r--etc/wireshark.profile2
-rw-r--r--etc/xreader.profile2
25 files changed, 89 insertions, 27 deletions
diff --git a/etc/atril.profile b/etc/atril.profile
index 98142012c..50592ec3a 100644
--- a/etc/atril.profile
+++ b/etc/atril.profile
@@ -6,7 +6,9 @@ include /etc/firejail/atril.local
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.config/atril 8noblacklist ~/.config/atril
9noblacklist ~/.local/share 9
10#noblacklist ~/.local/share
11# it seems to use only ~/.local/share/webkitgtk
10 12
11include /etc/firejail/disable-common.inc 13include /etc/firejail/disable-common.inc
12include /etc/firejail/disable-devel.inc 14include /etc/firejail/disable-devel.inc
diff --git a/etc/bitlbee.profile b/etc/bitlbee.profile
index 1b7b2c258..0f57c9e69 100644
--- a/etc/bitlbee.profile
+++ b/etc/bitlbee.profile
@@ -7,7 +7,7 @@ include /etc/firejail/globals.local
7 7
8noblacklist /sbin 8noblacklist /sbin
9noblacklist /usr/sbin 9noblacklist /usr/sbin
10noblacklist /var/log 10# noblacklist /var/log
11 11
12include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-devel.inc 13include /etc/firejail/disable-devel.inc
diff --git a/etc/brackets.profile b/etc/brackets.profile
index 0a8c592a7..a5a06f9f3 100644
--- a/etc/brackets.profile
+++ b/etc/brackets.profile
@@ -6,8 +6,8 @@ include /etc/firejail/brackets.local
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ${HOME}/.config/Brackets 8noblacklist ${HOME}/.config/Brackets
9noblacklist /opt/brackets/ 9#noblacklist /opt/brackets/
10noblacklist /opt/google/ 10#noblacklist /opt/google/
11 11
12include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-passwdmgr.inc 13include /etc/firejail/disable-passwdmgr.inc
diff --git a/etc/caja.profile b/etc/caja.profile
index 97663fddb..83b6befa3 100644
--- a/etc/caja.profile
+++ b/etc/caja.profile
@@ -8,9 +8,9 @@ include /etc/firejail/globals.local
8# Caja is started by systemd on most systems. Therefore it is not firejailed by default. Since there 8# Caja is started by systemd on most systems. Therefore it is not firejailed by default. Since there
9# is already a caja process running on MATE desktops firejail will have no effect. 9# is already a caja process running on MATE desktops firejail will have no effect.
10 10
11noblacklist ~/.config/caja 11# noblacklist ~/.config/caja - disable-programs.inc is disabled, see below
12noblacklist ~/.local/share/Trash 12# noblacklist ~/.local/share/Trash
13noblacklist ~/.local/share/caja-python 13# noblacklist ~/.local/share/caja-python
14 14
15include /etc/firejail/disable-common.inc 15include /etc/firejail/disable-common.inc
16include /etc/firejail/disable-devel.inc 16include /etc/firejail/disable-devel.inc
diff --git a/etc/cherrytree.profile b/etc/cherrytree.profile
index 88be562c8..3db2aeb09 100644
--- a/etc/cherrytree.profile
+++ b/etc/cherrytree.profile
@@ -6,8 +6,8 @@ include /etc/firejail/cherrytree.local
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ${HOME}/.config/cherrytree 8noblacklist ${HOME}/.config/cherrytree
9noblacklist /usr/bin/python2* 9#noblacklist /usr/bin/python2*
10noblacklist /usr/lib/python3* 10#noblacklist /usr/lib/python3*
11 11
12include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-devel.inc 13include /etc/firejail/disable-devel.inc
diff --git a/etc/cliqz.profile b/etc/cliqz.profile
index a7c791a02..d61d46dca 100644
--- a/etc/cliqz.profile
+++ b/etc/cliqz.profile
@@ -16,7 +16,7 @@ noblacklist ~/.kde/share/config/okularrc
16noblacklist ~/.kde4/share/apps/okular 16noblacklist ~/.kde4/share/apps/okular
17noblacklist ~/.kde4/share/config/okularpartrc 17noblacklist ~/.kde4/share/config/okularpartrc
18noblacklist ~/.kde4/share/config/okularrc 18noblacklist ~/.kde4/share/config/okularrc
19noblacklist ~/.local/share/gnome-shell/extensions 19# noblacklist ~/.local/share/gnome-shell/extensions
20noblacklist ~/.local/share/okular 20noblacklist ~/.local/share/okular
21noblacklist ~/.local/share/qpdfview 21noblacklist ~/.local/share/qpdfview
22 22
diff --git a/etc/digikam.profile b/etc/digikam.profile
index ef518470e..5557e5457 100644
--- a/etc/digikam.profile
+++ b/etc/digikam.profile
@@ -5,6 +5,7 @@ include /etc/firejail/digikam.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ${HOME}/.config/digikam
8noblacklist ${HOME}/.config/digikamrc 9noblacklist ${HOME}/.config/digikamrc
9noblacklist ${HOME}/.kde/share/apps/digikam 10noblacklist ${HOME}/.kde/share/apps/digikam
10noblacklist ${HOME}/.kde4/share/apps/digikam 11noblacklist ${HOME}/.kde4/share/apps/digikam
diff --git a/etc/disable-common.inc b/etc/disable-common.inc
index 6c8a68d9e..8d8d839a9 100644
--- a/etc/disable-common.inc
+++ b/etc/disable-common.inc
@@ -155,6 +155,17 @@ blacklist /etc/anacrontab
155blacklist /etc/cron* 155blacklist /etc/cron*
156blacklist /etc/profile.d 156blacklist /etc/profile.d
157blacklist /etc/rc.local 157blacklist /etc/rc.local
158# rc1.d, rc2.d, ...
159blacklist /etc/rc?.d
160blacklist /etc/kernel*
161blacklist /etc/grub*
162blacklist /etc/dkms
163blacklist /etc/apparmor*
164blacklist /etc/selinux
165blacklist /etc/modules*
166blacklist /etc/logrotate*
167blacklist /etc/adduser.conf
168blacklist ${HOME}/.config/openbox
158 169
159# Startup files 170# Startup files
160read-only ${HOME}/.antigen 171read-only ${HOME}/.antigen
@@ -201,6 +212,7 @@ read-only ${HOME}/.nano
201read-only ${HOME}/.reportbugrc 212read-only ${HOME}/.reportbugrc
202read-only ${HOME}/.tmux.conf 213read-only ${HOME}/.tmux.conf
203read-only ${HOME}/.vim 214read-only ${HOME}/.vim
215read-only ${HOME}/.viminfo
204read-only ${HOME}/.vimrc 216read-only ${HOME}/.vimrc
205read-only ${HOME}/.xmonad 217read-only ${HOME}/.xmonad
206read-only ${HOME}/.xscreensaver 218read-only ${HOME}/.xscreensaver
diff --git a/etc/disable-programs.inc b/etc/disable-programs.inc
index 73a2e6515..144fa7741 100644
--- a/etc/disable-programs.inc
+++ b/etc/disable-programs.inc
@@ -24,6 +24,7 @@ blacklist ${HOME}/.ZAP
24blacklist ${HOME}/.aMule 24blacklist ${HOME}/.aMule
25blacklist ${HOME}/.android 25blacklist ${HOME}/.android
26blacklist ${HOME}/.arduino15 26blacklist ${HOME}/.arduino15
27blacklist ${HOME}/.arm
27blacklist ${HOME}/.atom 28blacklist ${HOME}/.atom
28blacklist ${HOME}/.attic 29blacklist ${HOME}/.attic
29blacklist ${HOME}/.audacity-data 30blacklist ${HOME}/.audacity-data
@@ -41,6 +42,7 @@ blacklist ${HOME}/.config/Franz
41blacklist ${HOME}/.config/FreeCAD 42blacklist ${HOME}/.config/FreeCAD
42blacklist ${HOME}/.config/Gitter 43blacklist ${HOME}/.config/Gitter
43blacklist ${HOME}/.config/Google 44blacklist ${HOME}/.config/Google
45blacklist ${HOME}/.config/Google Play Music Desktop Player
44blacklist ${HOME}/.config/Gpredict 46blacklist ${HOME}/.config/Gpredict
45blacklist ${HOME}/.config/INRIA 47blacklist ${HOME}/.config/INRIA
46blacklist ${HOME}/.config/InSilmaril 48blacklist ${HOME}/.config/InSilmaril
@@ -50,12 +52,15 @@ blacklist ${HOME}/.config/Mousepad
50blacklist ${HOME}/.config/Mumble 52blacklist ${HOME}/.config/Mumble
51blacklist ${HOME}/.config/MusE 53blacklist ${HOME}/.config/MusE
52blacklist ${HOME}/.config/MuseScore 54blacklist ${HOME}/.config/MuseScore
55blacklist ${HOME}/.config/MusicBrainz
53blacklist ${HOME}/.config/Nylas Mail 56blacklist ${HOME}/.config/Nylas Mail
54blacklist ${HOME}/.config/Qlipper 57blacklist ${HOME}/.config/Qlipper
55blacklist ${HOME}/.config/QuiteRss 58blacklist ${HOME}/.config/QuiteRss
56blacklist ${HOME}/.config/QuiteRssrc 59blacklist ${HOME}/.config/QuiteRssrc
60blacklist ${HOME}/.config/Rambox
57blacklist ${HOME}/.config/Riot 61blacklist ${HOME}/.config/Riot
58blacklist ${HOME}/.config/Rocket.Chat 62blacklist ${HOME}/.config/Rocket.Chat
63blacklist ${HOME}/.config/Signal
59blacklist ${HOME}/.config/Slack 64blacklist ${HOME}/.config/Slack
60blacklist ${HOME}/.config/Thunar 65blacklist ${HOME}/.config/Thunar
61blacklist ${HOME}/.config/VirtualBox 66blacklist ${HOME}/.config/VirtualBox
@@ -89,6 +94,7 @@ blacklist ${HOME}/.config/darktable
89blacklist ${HOME}/.config/deadbeef 94blacklist ${HOME}/.config/deadbeef
90blacklist ${HOME}/.config/deluge 95blacklist ${HOME}/.config/deluge
91blacklist ${HOME}/.config/digikam 96blacklist ${HOME}/.config/digikam
97blacklist ${HOME}/.config/digikamrc
92blacklist ${HOME}/.config/dolphinrc 98blacklist ${HOME}/.config/dolphinrc
93blacklist ${HOME}/.config/dragonplayerrc 99blacklist ${HOME}/.config/dragonplayerrc
94blacklist ${HOME}/.config/enchant 100blacklist ${HOME}/.config/enchant
@@ -105,6 +111,7 @@ blacklist ${HOME}/.config/gedit
105blacklist ${HOME}/.config/geeqie 111blacklist ${HOME}/.config/geeqie
106blacklist ${HOME}/.config/ghb 112blacklist ${HOME}/.config/ghb
107blacklist ${HOME}/.config/globaltime 113blacklist ${HOME}/.config/globaltime
114blacklist ${HOME}/.config/gnome-mplayer
108blacklist ${HOME}/.config/google-chrome 115blacklist ${HOME}/.config/google-chrome
109blacklist ${HOME}/.config/google-chrome-beta 116blacklist ${HOME}/.config/google-chrome-beta
110blacklist ${HOME}/.config/google-chrome-unstable 117blacklist ${HOME}/.config/google-chrome-unstable
@@ -112,7 +119,9 @@ blacklist ${HOME}/.config/gpicview
112blacklist ${HOME}/.config/gthumb 119blacklist ${HOME}/.config/gthumb
113blacklist ${HOME}/.config/gwenviewrc 120blacklist ${HOME}/.config/gwenviewrc
114blacklist ${HOME}/.config/hexchat 121blacklist ${HOME}/.config/hexchat
122blacklist ${HOME}/.config/inkscape
115blacklist ${HOME}/.config/inox 123blacklist ${HOME}/.config/inox
124blacklist ${HOME}/.config/iridium
116blacklist ${HOME}/.config/itch 125blacklist ${HOME}/.config/itch
117blacklist ${HOME}/.config/jd-gui.cfg 126blacklist ${HOME}/.config/jd-gui.cfg
118blacklist ${HOME}/.config/k3brc 127blacklist ${HOME}/.config/k3brc
@@ -121,17 +130,21 @@ blacklist ${HOME}/.config/katerc
121blacklist ${HOME}/.config/kateschemarc 130blacklist ${HOME}/.config/kateschemarc
122blacklist ${HOME}/.config/katesyntaxhighlightingrc 131blacklist ${HOME}/.config/katesyntaxhighlightingrc
123blacklist ${HOME}/.config/katevirc 132blacklist ${HOME}/.config/katevirc
133blacklist ${HOME}/.config/kritarc
134blacklist ${HOME}/.config/kwriterc
124blacklist ${HOME}/.config/kdeconnect 135blacklist ${HOME}/.config/kdeconnect
125blacklist ${HOME}/.config/knotesrc 136blacklist ${HOME}/.config/knotesrc
126blacklist ${HOME}/.config/ktorrentrc 137blacklist ${HOME}/.config/ktorrentrc
127blacklist ${HOME}/.config/leafpad 138blacklist ${HOME}/.config/leafpad
128blacklist ${HOME}/.config/libreoffice 139blacklist ${HOME}/.config/libreoffice
140blacklist ${HOME}/.config/liferea
129blacklist ${HOME}/.config/lximage-qt 141blacklist ${HOME}/.config/lximage-qt
130blacklist ${HOME}/.config/mate-calc 142blacklist ${HOME}/.config/mate-calc
131blacklist ${HOME}/.config/mate/eom 143blacklist ${HOME}/.config/mate/eom
132blacklist ${HOME}/.config/mate/mate-dictionary 144blacklist ${HOME}/.config/mate/mate-dictionary
133blacklist ${HOME}/.config/mfusion 145blacklist ${HOME}/.config/mfusion
134blacklist ${HOME}/.config/midori 146blacklist ${HOME}/.config/midori
147blacklist ${HOME}/.config/mono
135blacklist ${HOME}/.config/mpv 148blacklist ${HOME}/.config/mpv
136blacklist ${HOME}/.config/mupen64plus 149blacklist ${HOME}/.config/mupen64plus
137blacklist ${HOME}/.config/nautilus 150blacklist ${HOME}/.config/nautilus
@@ -157,11 +170,13 @@ blacklist ${HOME}/.config/qupzilla
157blacklist ${HOME}/.config/qutebrowser 170blacklist ${HOME}/.config/qutebrowser
158blacklist ${HOME}/.config/ranger 171blacklist ${HOME}/.config/ranger
159blacklist ${HOME}/.config/redshift.conf 172blacklist ${HOME}/.config/redshift.conf
173blacklist ${HOME}/.config/remmina
160blacklist ${HOME}/.config/ristretto 174blacklist ${HOME}/.config/ristretto
161blacklist ${HOME}/.config/scribus 175blacklist ${HOME}/.config/scribus
162blacklist ${HOME}/.config/skypeforlinux 176blacklist ${HOME}/.config/skypeforlinux
163blacklist ${HOME}/.config/slimjet 177blacklist ${HOME}/.config/slimjet
164blacklist ${HOME}/.config/smplayer 178blacklist ${HOME}/.config/smplayer
179blacklist ${HOME}/.config/smtube
165blacklist ${HOME}/.config/spotify 180blacklist ${HOME}/.config/spotify
166blacklist ${HOME}/.config/stellarium 181blacklist ${HOME}/.config/stellarium
167blacklist ${HOME}/.config/synfig 182blacklist ${HOME}/.config/synfig
@@ -169,8 +184,10 @@ blacklist ${HOME}/.config/telepathy-account-widgets
169blacklist ${HOME}/.config/torbrowser 184blacklist ${HOME}/.config/torbrowser
170blacklist ${HOME}/.config/totem 185blacklist ${HOME}/.config/totem
171blacklist ${HOME}/.config/tox 186blacklist ${HOME}/.config/tox
187blacklist ${HOME}/.config/truecraft
172blacklist ${HOME}/.config/transmission 188blacklist ${HOME}/.config/transmission
173blacklist ${HOME}/.config/uGet 189blacklist ${HOME}/.config/uGet
190blacklist ${HOME}/.config/uzbl
174blacklist ${HOME}/.config/viewnior 191blacklist ${HOME}/.config/viewnior
175blacklist ${HOME}/.config/vivaldi 192blacklist ${HOME}/.config/vivaldi
176blacklist ${HOME}/.config/vlc 193blacklist ${HOME}/.config/vlc
@@ -199,7 +216,7 @@ blacklist ${HOME}/.dia
199blacklist ${HOME}/.dillo 216blacklist ${HOME}/.dillo
200blacklist ${HOME}/.dooble 217blacklist ${HOME}/.dooble
201blacklist ${HOME}/.dosbox 218blacklist ${HOME}/.dosbox
202blacklist ${HOME}/.dropbox-dist 219blacklist ${HOME}/.dropbox*
203blacklist ${HOME}/.electrum* 220blacklist ${HOME}/.electrum*
204blacklist ${HOME}/.elinks 221blacklist ${HOME}/.elinks
205blacklist ${HOME}/.emacs 222blacklist ${HOME}/.emacs
@@ -209,6 +226,7 @@ blacklist ${HOME}/.etr
209blacklist ${HOME}/.filezilla 226blacklist ${HOME}/.filezilla
210blacklist ${HOME}/.flowblade 227blacklist ${HOME}/.flowblade
211blacklist ${HOME}/.fltk 228blacklist ${HOME}/.fltk
229blacklist ${HOME}/.fossamail
212blacklist ${HOME}/.frozen-bubble 230blacklist ${HOME}/.frozen-bubble
213blacklist ${HOME}/.gimp* 231blacklist ${HOME}/.gimp*
214blacklist ${HOME}/.git-credential-cache 232blacklist ${HOME}/.git-credential-cache
@@ -228,6 +246,7 @@ blacklist ${HOME}/.jack-server
228blacklist ${HOME}/.jack-settings 246blacklist ${HOME}/.jack-settings
229blacklist ${HOME}/.java 247blacklist ${HOME}/.java
230blacklist ${HOME}/.jitsi 248blacklist ${HOME}/.jitsi
249blacklist ${HOME}/.kde/share/apps/digikam
231blacklist ${HOME}/.kde/share/apps/gwenview 250blacklist ${HOME}/.kde/share/apps/gwenview
232blacklist ${HOME}/.kde/share/apps/kcookiejar 251blacklist ${HOME}/.kde/share/apps/kcookiejar
233blacklist ${HOME}/.kde/share/apps/kget 252blacklist ${HOME}/.kde/share/apps/kget
@@ -235,7 +254,8 @@ blacklist ${HOME}/.kde/share/apps/khtml
235blacklist ${HOME}/.kde/share/apps/konqsidebartng 254blacklist ${HOME}/.kde/share/apps/konqsidebartng
236blacklist ${HOME}/.kde/share/apps/konqueror 255blacklist ${HOME}/.kde/share/apps/konqueror
237blacklist ${HOME}/.kde/share/apps/kopete 256blacklist ${HOME}/.kde/share/apps/kopete
238blacklist ${HOME}/.kde/share/apps/okular 257blacklist ${HOME}/.kde/share/apps/khtml
258blacklist ${HOME}/.kde/share/apps/ktorrent
239blacklist ${HOME}/.kde/share/config/baloofilerc 259blacklist ${HOME}/.kde/share/config/baloofilerc
240blacklist ${HOME}/.kde/share/config/baloorc 260blacklist ${HOME}/.kde/share/config/baloorc
241blacklist ${HOME}/.kde/share/config/digikam 261blacklist ${HOME}/.kde/share/config/digikam
@@ -251,6 +271,7 @@ blacklist ${HOME}/.kde/share/config/kopeterc
251blacklist ${HOME}/.kde/share/config/ktorrentrc 271blacklist ${HOME}/.kde/share/config/ktorrentrc
252blacklist ${HOME}/.kde/share/config/okularpartrc 272blacklist ${HOME}/.kde/share/config/okularpartrc
253blacklist ${HOME}/.kde/share/config/okularrc 273blacklist ${HOME}/.kde/share/config/okularrc
274blacklist ${HOME}/.kde4/share/apps/digikam
254blacklist ${HOME}/.kde4/share/apps/gwenview 275blacklist ${HOME}/.kde4/share/apps/gwenview
255blacklist ${HOME}/.kde4/share/apps/kcookiejar 276blacklist ${HOME}/.kde4/share/apps/kcookiejar
256blacklist ${HOME}/.kde4/share/apps/kget 277blacklist ${HOME}/.kde4/share/apps/kget
@@ -258,6 +279,7 @@ blacklist ${HOME}/.kde4/share/apps/khtml
258blacklist ${HOME}/.kde4/share/apps/konqueror 279blacklist ${HOME}/.kde4/share/apps/konqueror
259blacklist ${HOME}/.kde4/share/apps/konqsidebartng 280blacklist ${HOME}/.kde4/share/apps/konqsidebartng
260blacklist ${HOME}/.kde4/share/apps/kopete 281blacklist ${HOME}/.kde4/share/apps/kopete
282blacklist ${HOME}/.kde4/share/apps/ktorrent
261blacklist ${HOME}/.kde4/share/apps/okular 283blacklist ${HOME}/.kde4/share/apps/okular
262blacklist ${HOME}/.kde4/share/config/baloorc 284blacklist ${HOME}/.kde4/share/config/baloorc
263blacklist ${HOME}/.kde4/share/config/baloofilerc 285blacklist ${HOME}/.kde4/share/config/baloofilerc
@@ -311,16 +333,22 @@ blacklist ${HOME}/.local/share/feral-interactive
311blacklist ${HOME}/.local/share/gajim 333blacklist ${HOME}/.local/share/gajim
312blacklist ${HOME}/.local/share/geary 334blacklist ${HOME}/.local/share/geary
313blacklist ${HOME}/.local/share/geeqie 335blacklist ${HOME}/.local/share/geeqie
336blacklist ${HOME}/.local/share/gitg
314blacklist ${HOME}/.local/share/gnome-2048 337blacklist ${HOME}/.local/share/gnome-2048
315blacklist ${HOME}/.local/share/gnome-chess 338blacklist ${HOME}/.local/share/gnome-chess
316blacklist ${HOME}/.local/share/gnome-music 339blacklist ${HOME}/.local/share/gnome-music
317blacklist ${HOME}/.local/share/gnome-photos 340blacklist ${HOME}/.local/share/gnome-photos
341blacklist ${HOME}/.local/share/gnome-ring
342blacklist ${HOME}/.local/share/gnome-twitch
318blacklist ${HOME}/.local/share/gwenview 343blacklist ${HOME}/.local/share/gwenview
319blacklist ${HOME}/.local/share/kate 344blacklist ${HOME}/.local/share/kate
320blacklist ${HOME}/.local/share/ktorrentrc 345blacklist ${HOME}/.local/share/ktorrentrc
346blacklist ${HOME}/.local/share/ktorrent
321blacklist ${HOME}/.local/share/kwrite 347blacklist ${HOME}/.local/share/kwrite
348blacklist ${HOME}/.local/share/liferea
322blacklist ${HOME}/.local/share/lollypop 349blacklist ${HOME}/.local/share/lollypop
323blacklist ${HOME}/.local/share/meld 350blacklist ${HOME}/.local/share/meld
351blacklist ${HOME}/.local/share/midori
324blacklist ${HOME}/.local/share/multimc 352blacklist ${HOME}/.local/share/multimc
325blacklist ${HOME}/.local/share/multimc5 353blacklist ${HOME}/.local/share/multimc5
326blacklist ${HOME}/.local/share/mupen64plus 354blacklist ${HOME}/.local/share/mupen64plus
@@ -335,6 +363,7 @@ blacklist ${HOME}/.local/share/org.kde.gwenview
335blacklist ${HOME}/.local/share/pix 363blacklist ${HOME}/.local/share/pix
336blacklist ${HOME}/.local/share/psi+ 364blacklist ${HOME}/.local/share/psi+
337blacklist ${HOME}/.local/share/qpdfview 365blacklist ${HOME}/.local/share/qpdfview
366blacklist ${HOME}/.local/share/remmina
338blacklist ${HOME}/.local/share/scribus 367blacklist ${HOME}/.local/share/scribus
339blacklist ${HOME}/.local/share/spotify 368blacklist ${HOME}/.local/share/spotify
340blacklist ${HOME}/.local/share/steam 369blacklist ${HOME}/.local/share/steam
@@ -343,6 +372,7 @@ blacklist ${HOME}/.local/share/telepathy
343blacklist ${HOME}/.local/share/terasology 372blacklist ${HOME}/.local/share/terasology
344blacklist ${HOME}/.local/share/torbrowser 373blacklist ${HOME}/.local/share/torbrowser
345blacklist ${HOME}/.local/share/totem 374blacklist ${HOME}/.local/share/totem
375blacklist ${HOME}/.local/share/vlc
346blacklist ${HOME}/.local/share/vpltd 376blacklist ${HOME}/.local/share/vpltd
347blacklist ${HOME}/.local/share/vulkan 377blacklist ${HOME}/.local/share/vulkan
348blacklist ${HOME}/.local/share/wesnoth 378blacklist ${HOME}/.local/share/wesnoth
@@ -395,21 +425,24 @@ blacklist ${HOME}/.tooling
395blacklist ${HOME}/.tor-browser-en 425blacklist ${HOME}/.tor-browser-en
396blacklist ${HOME}/.ts3client 426blacklist ${HOME}/.ts3client
397blacklist ${HOME}/.tuxguitar* 427blacklist ${HOME}/.tuxguitar*
398blacklist ${HOME}/.unknow-horizons 428blacklist ${HOME}/.unknown-horizons
399blacklist ${HOME}/.viking 429blacklist ${HOME}/.viking
400blacklist ${HOME}/.viking-maps 430blacklist ${HOME}/.viking-maps
401blacklist ${HOME}/.vst 431blacklist ${HOME}/.vst
402blacklist ${HOME}/.w3m 432blacklist ${HOME}/.w3m
403blacklist ${HOME}/.warzone2100-3.* 433blacklist ${HOME}/.warzone2100-3.*
434blacklist ${HOME}/.waterfox
404blacklist ${HOME}/.weechat 435blacklist ${HOME}/.weechat
405blacklist ${HOME}/.wgetrc 436blacklist ${HOME}/.wgetrc
406blacklist ${HOME}/.wine 437blacklist ${HOME}/.wine
438blacklist ${HOME}/.wireshark
407blacklist ${HOME}/.wine64 439blacklist ${HOME}/.wine64
408blacklist ${HOME}/.xiphos 440blacklist ${HOME}/.xiphos
409blacklist ${HOME}/.xmms 441blacklist ${HOME}/.xmms
410blacklist ${HOME}/.xonotic 442blacklist ${HOME}/.xonotic
411blacklist ${HOME}/.xpdfrc 443blacklist ${HOME}/.xpdfrc
412blacklist ${HOME}/.zoom 444blacklist ${HOME}/.zoom
445blacklist ${HOME}/Arduino
413blacklist ${HOME}/wallet.dat 446blacklist ${HOME}/wallet.dat
414blacklist /tmp/ssh-* 447blacklist /tmp/ssh-*
415 448
@@ -418,6 +451,7 @@ blacklist ${HOME}/.cache/0ad
418blacklist ${HOME}/.cache/8pecxstudios 451blacklist ${HOME}/.cache/8pecxstudios
419blacklist ${HOME}/.cache/Franz 452blacklist ${HOME}/.cache/Franz
420blacklist ${HOME}/.cache/INRIA 453blacklist ${HOME}/.cache/INRIA
454blacklist ${HOME}/.cache/MusicBrainz
421blacklist ${HOME}/.cache/QuiteRss 455blacklist ${HOME}/.cache/QuiteRss
422blacklist ${HOME}/.cache/attic 456blacklist ${HOME}/.cache/attic
423blacklist ${HOME}/.cache/borg 457blacklist ${HOME}/.cache/borg
@@ -429,16 +463,21 @@ blacklist ${HOME}/.cache/cliqz
429blacklist ${HOME}/.cache/darktable 463blacklist ${HOME}/.cache/darktable
430blacklist ${HOME}/.cache/epiphany 464blacklist ${HOME}/.cache/epiphany
431blacklist ${HOME}/.cache/evolution 465blacklist ${HOME}/.cache/evolution
466blacklist ${HOME}/.cache/fossamail
432blacklist ${HOME}/.cache/gajim 467blacklist ${HOME}/.cache/gajim
433blacklist ${HOME}/.cache/geeqie 468blacklist ${HOME}/.cache/geeqie
434blacklist ${HOME}/.cache/google-chrome 469blacklist ${HOME}/.cache/google-chrome
435blacklist ${HOME}/.cache/google-chrome-beta 470blacklist ${HOME}/.cache/google-chrome-beta
436blacklist ${HOME}/.cache/google-chrome-unstable 471blacklist ${HOME}/.cache/google-chrome-unstable
472blacklist ${HOME}/.cache/gnome-twitch
437blacklist ${HOME}/.cache/icedove 473blacklist ${HOME}/.cache/icedove
438blacklist ${HOME}/.cache/INRIA/Natron 474blacklist ${HOME}/.cache/INRIA/Natron
439blacklist ${HOME}/.cache/inox 475blacklist ${HOME}/.cache/inox
476blacklist ${HOME}/.cache/iridium
440blacklist ${HOME}/.cache/libgweather 477blacklist ${HOME}/.cache/libgweather
478blacklist ${HOME}/.cache/liferea
441blacklist ${HOME}/.cache/midori 479blacklist ${HOME}/.cache/midori
480noblacklist ${HOME}/.cache/moonchild productions/pale moon
442blacklist ${HOME}/.cache/mozilla 481blacklist ${HOME}/.cache/mozilla
443blacklist ${HOME}/.cache/mutt 482blacklist ${HOME}/.cache/mutt
444blacklist ${HOME}/.cache/netsurf 483blacklist ${HOME}/.cache/netsurf
@@ -458,6 +497,7 @@ blacklist ${HOME}/.cache/thunderbird
458blacklist ${HOME}/.cache/torbrowser 497blacklist ${HOME}/.cache/torbrowser
459blacklist ${HOME}/.cache/transmission 498blacklist ${HOME}/.cache/transmission
460blacklist ${HOME}/.cache/vivaldi 499blacklist ${HOME}/.cache/vivaldi
500blacklist ${HOME}/.cache/waterfox
461blacklist ${HOME}/.cache/wesnoth 501blacklist ${HOME}/.cache/wesnoth
462blacklist ${HOME}/.cache/xmms2 502blacklist ${HOME}/.cache/xmms2
463blacklist ${HOME}/.cache/xreader 503blacklist ${HOME}/.cache/xreader
diff --git a/etc/dolphin.profile b/etc/dolphin.profile
index 7566e927b..fe72ee654 100644
--- a/etc/dolphin.profile
+++ b/etc/dolphin.profile
@@ -8,8 +8,8 @@ include /etc/firejail/globals.local
8# warning: firejail is currently not effectively constraining dolphin since used services are started by kdeinit5 8# warning: firejail is currently not effectively constraining dolphin since used services are started by kdeinit5
9 9
10noblacklist ${HOME}/.local/share/Trash 10noblacklist ${HOME}/.local/share/Trash
11noblacklist ~/.config/dolphinrc 11# noblacklist ~/.config/dolphinrc - diable-programs.inc is disabled, see below
12noblacklist ~/.local/share/dolphin 12# noblacklist ~/.local/share/dolphin
13 13
14include /etc/firejail/disable-common.inc 14include /etc/firejail/disable-common.inc
15include /etc/firejail/disable-devel.inc 15include /etc/firejail/disable-devel.inc
diff --git a/etc/evolution.profile b/etc/evolution.profile
index 9f29b229b..e74c68f63 100644
--- a/etc/evolution.profile
+++ b/etc/evolution.profile
@@ -7,13 +7,12 @@ include /etc/firejail/globals.local
7 7
8noblacklist /var/mail 8noblacklist /var/mail
9noblacklist /var/spool/mail 9noblacklist /var/spool/mail
10noblacklist ~/.bogofilter 10# noblacklist ~/.bogofilter
11noblacklist ~/.cache/evolution 11noblacklist ~/.cache/evolution
12noblacklist ~/.config/evolution 12noblacklist ~/.config/evolution
13noblacklist ~/.gnupg 13noblacklist ~/.gnupg
14noblacklist ~/.local/share/evolution 14noblacklist ~/.local/share/evolution
15noblacklist ~/.pki 15noblacklist ~/.pki
16noblacklist ~/.pki/nssdb
17 16
18include /etc/firejail/disable-common.inc 17include /etc/firejail/disable-common.inc
19include /etc/firejail/disable-devel.inc 18include /etc/firejail/disable-devel.inc
diff --git a/etc/firefox.profile b/etc/firefox.profile
index 1f4106936..2423b149c 100644
--- a/etc/firefox.profile
+++ b/etc/firefox.profile
@@ -19,7 +19,7 @@ noblacklist ~/.kde4/share/apps/okular
19noblacklist ~/.kde4/share/config/kgetrc 19noblacklist ~/.kde4/share/config/kgetrc
20noblacklist ~/.kde4/share/config/okularpartrc 20noblacklist ~/.kde4/share/config/okularpartrc
21noblacklist ~/.kde4/share/config/okularrc 21noblacklist ~/.kde4/share/config/okularrc
22noblacklist ~/.local/share/gnome-shell/extensions 22# noblacklist ~/.local/share/gnome-shell/extensions
23noblacklist ~/.local/share/okular 23noblacklist ~/.local/share/okular
24noblacklist ~/.local/share/qpdfview 24noblacklist ~/.local/share/qpdfview
25noblacklist ~/.mozilla 25noblacklist ~/.mozilla
diff --git a/etc/gnome-mplayer.profile b/etc/gnome-mplayer.profile
index d63cc4500..166994374 100644
--- a/etc/gnome-mplayer.profile
+++ b/etc/gnome-mplayer.profile
@@ -5,6 +5,7 @@ include /etc/firejail/gnome-mplayer.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.config/gnome-mplayer
8 9
9include /etc/firejail/disable-common.inc 10include /etc/firejail/disable-common.inc
10include /etc/firejail/disable-devel.inc 11include /etc/firejail/disable-devel.inc
diff --git a/etc/inkscape.profile b/etc/inkscape.profile
index b190e4326..d2929412b 100644
--- a/etc/inkscape.profile
+++ b/etc/inkscape.profile
@@ -6,6 +6,8 @@ include /etc/firejail/inkscape.local
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ${HOME}/.inkscape 8noblacklist ${HOME}/.inkscape
9noblacklist ${HOME}/.config/inkscape
10
9 11
10include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-devel.inc 13include /etc/firejail/disable-devel.inc
diff --git a/etc/krita.profile b/etc/krita.profile
index 52329eaab..0d2b62c5d 100644
--- a/etc/krita.profile
+++ b/etc/krita.profile
@@ -6,6 +6,7 @@ include /etc/firejail/krita.local
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8# blacklist /run/user/*/bus 8# blacklist /run/user/*/bus
9noblacklist ${HOME}/.config/kritarc
9 10
10include /etc/firejail/disable-common.inc 11include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-devel.inc 12include /etc/firejail/disable-devel.inc
diff --git a/etc/kwrite.profile b/etc/kwrite.profile
index af1fa179b..5d6eba094 100644
--- a/etc/kwrite.profile
+++ b/etc/kwrite.profile
@@ -12,6 +12,7 @@ noblacklist ~/.config/katerc
12noblacklist ~/.config/kateschemarc 12noblacklist ~/.config/kateschemarc
13noblacklist ~/.config/katesyntaxhighlightingrc 13noblacklist ~/.config/katesyntaxhighlightingrc
14noblacklist ~/.config/katevirc 14noblacklist ~/.config/katevirc
15noblacklist ~/.config/kwriterc
15noblacklist ~/.local/share/kwrite 16noblacklist ~/.local/share/kwrite
16 17
17include /etc/firejail/disable-common.inc 18include /etc/firejail/disable-common.inc
diff --git a/etc/lximage-qt.profile b/etc/lximage-qt.profile
index 734f16e92..1a3b26c10 100644
--- a/etc/lximage-qt.profile
+++ b/etc/lximage-qt.profile
@@ -5,7 +5,7 @@ include /etc/firejail/lximage-qt.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist .config/lximage-qt 8noblacklist ~/.config/lximage-qt
9 9
10include /etc/firejail/disable-common.inc 10include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-devel.inc 11include /etc/firejail/disable-devel.inc
diff --git a/etc/midori.profile b/etc/midori.profile
index 8ddb37776..e8373b042 100644
--- a/etc/midori.profile
+++ b/etc/midori.profile
@@ -7,8 +7,8 @@ include /etc/firejail/globals.local
7 7
8noblacklist ~/.config/midori 8noblacklist ~/.config/midori
9noblacklist ~/.local/share/midori 9noblacklist ~/.local/share/midori
10noblacklist ~/.local/share/webkit 10# noblacklist ~/.local/share/webkit
11noblacklist ~/.local/share/webkitgtk 11# noblacklist ~/.local/share/webkitgtk
12noblacklist ~/.pki 12noblacklist ~/.pki
13 13
14include /etc/firejail/disable-common.inc 14include /etc/firejail/disable-common.inc
diff --git a/etc/openbox.profile b/etc/openbox.profile
index 99c579c37..5bab7ce7d 100644
--- a/etc/openbox.profile
+++ b/etc/openbox.profile
@@ -6,7 +6,7 @@ include /etc/firejail/openbox.local
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8# all applications started in OpenBox will run in this profile 8# all applications started in OpenBox will run in this profile
9 9noblacklist ${HOME}/.config/openbox
10include /etc/firejail/disable-common.inc 10include /etc/firejail/disable-common.inc
11 11
12caps.drop all 12caps.drop all
diff --git a/etc/pcmanfm.profile b/etc/pcmanfm.profile
index 7d2121710..03e7e450f 100644
--- a/etc/pcmanfm.profile
+++ b/etc/pcmanfm.profile
@@ -8,8 +8,8 @@ include /etc/firejail/globals.local
8# blacklist /run/user/*/bus 8# blacklist /run/user/*/bus
9 9
10noblacklist ${HOME}/.local/share/Trash 10noblacklist ${HOME}/.local/share/Trash
11noblacklist ~/.config/libfm 11# noblacklist ~/.config/libfm - disable-programs.inc is disabled, see below
12noblacklist ~/.config/pcmanfm 12# noblacklist ~/.config/pcmanfm
13 13
14include /etc/firejail/disable-common.inc 14include /etc/firejail/disable-common.inc
15include /etc/firejail/disable-devel.inc 15include /etc/firejail/disable-devel.inc
diff --git a/etc/vlc.profile b/etc/vlc.profile
index c3a4d58d0..e906d738c 100644
--- a/etc/vlc.profile
+++ b/etc/vlc.profile
@@ -6,6 +6,7 @@ include /etc/firejail/vlc.local
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ${HOME}/.config/vlc 8noblacklist ${HOME}/.config/vlc
9noblacklist ${HOME}/.local/share/vlc
9 10
10include /etc/firejail/disable-common.inc 11include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-devel.inc 12include /etc/firejail/disable-devel.inc
diff --git a/etc/vym.profile b/etc/vym.profile
index 4f60b2ada..b38d87fde 100644
--- a/etc/vym.profile
+++ b/etc/vym.profile
@@ -5,7 +5,7 @@ include /etc/firejail/vym.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ./.config/InSilmaril 8noblacklist ~/.config/InSilmaril
9 9
10include /etc/firejail/disable-common.inc 10include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-devel.inc 11include /etc/firejail/disable-devel.inc
diff --git a/etc/waterfox.profile b/etc/waterfox.profile
index 9626c17aa..53543e97e 100644
--- a/etc/waterfox.profile
+++ b/etc/waterfox.profile
@@ -16,7 +16,7 @@ noblacklist ~/.kde/share/config/okularrc
16noblacklist ~/.kde4/share/apps/okular 16noblacklist ~/.kde4/share/apps/okular
17noblacklist ~/.kde4/share/config/okularpartrc 17noblacklist ~/.kde4/share/config/okularpartrc
18noblacklist ~/.kde4/share/config/okularrc 18noblacklist ~/.kde4/share/config/okularrc
19noblacklist ~/.local/share/gnome-shell/extensions 19# noblacklist ~/.local/share/gnome-shell/extensions
20noblacklist ~/.local/share/okular 20noblacklist ~/.local/share/okular
21noblacklist ~/.local/share/qpdfview 21noblacklist ~/.local/share/qpdfview
22noblacklist ~/.mozilla 22noblacklist ~/.mozilla
diff --git a/etc/wireshark.profile b/etc/wireshark.profile
index e283b6149..ba717cfe5 100644
--- a/etc/wireshark.profile
+++ b/etc/wireshark.profile
@@ -6,6 +6,8 @@ include /etc/firejail/wireshark.local
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ${HOME}/.config/wireshark 8noblacklist ${HOME}/.config/wireshark
9noblacklist ${HOME}/.wireshark
10
9 11
10include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-devel.inc 13include /etc/firejail/disable-devel.inc
diff --git a/etc/xreader.profile b/etc/xreader.profile
index 9583b6ee1..76fae9fed 100644
--- a/etc/xreader.profile
+++ b/etc/xreader.profile
@@ -7,7 +7,7 @@ include /etc/firejail/globals.local
7 7
8noblacklist ~/.cache/xreader 8noblacklist ~/.cache/xreader
9noblacklist ~/.config/xreader 9noblacklist ~/.config/xreader
10noblacklist ~/.local/share 10# noblacklist ~/.local/share
11 11
12include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-devel.inc 13include /etc/firejail/disable-devel.inc