aboutsummaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
authorLibravatar Fred-Barclay <Fred-Barclay@users.noreply.github.com>2019-02-17 12:09:02 -0600
committerLibravatar Fred-Barclay <Fred-Barclay@users.noreply.github.com>2019-02-17 12:09:02 -0600
commit83ddb3e5b276613ad2be190cebf74401daebef03 (patch)
tree542b76f3d93dec7c18bc986836e738679efa42a1 /etc
parentAdd alternatives to private-etc for profiles in /etc-fixes (diff)
downloadfirejail-83ddb3e5b276613ad2be190cebf74401daebef03.tar.gz
firejail-83ddb3e5b276613ad2be190cebf74401daebef03.tar.zst
firejail-83ddb3e5b276613ad2be190cebf74401daebef03.zip
Add alternatives to private-etc for profiles in etc/
See discussion in #2399
Diffstat (limited to 'etc')
-rw-r--r--etc/QMediathekView.profile2
-rw-r--r--etc/QOwnNotes.profile2
-rw-r--r--etc/Xephyr.profile2
-rw-r--r--etc/Xvfb.profile2
-rw-r--r--etc/abrowser.profile2
-rw-r--r--etc/amarok.profile2
-rw-r--r--etc/ardour5.profile2
-rw-r--r--etc/aria2c.profile2
-rw-r--r--etc/ark.profile2
-rw-r--r--etc/arm.profile2
-rw-r--r--etc/artha.profile2
-rw-r--r--etc/atool.profile2
-rw-r--r--etc/atril.profile2
-rw-r--r--etc/authenticator.profile2
-rw-r--r--etc/basilisk.profile2
-rw-r--r--etc/bibletime.profile2
-rw-r--r--etc/bitcoin-qt.profile2
-rw-r--r--etc/bless.profile2
-rw-r--r--etc/brasero.profile2
-rw-r--r--etc/bsdtar.profile2
-rw-r--r--etc/caja.profile2
-rw-r--r--etc/clawsker.profile2
-rw-r--r--etc/cliqz.profile2
-rw-r--r--etc/cmus.profile2
-rw-r--r--etc/crow.profile2
-rw-r--r--etc/curl.profile2
-rw-r--r--etc/cyberfox.profile2
-rw-r--r--etc/default.profile2
-rw-r--r--etc/devilspie.profile2
-rw-r--r--etc/devilspie2.profile2
-rw-r--r--etc/dig.profile2
-rw-r--r--etc/digikam.profile2
-rw-r--r--etc/dino.profile2
-rw-r--r--etc/discord-common.profile2
-rw-r--r--etc/display.profile2
-rw-r--r--etc/easystroke.profile2
-rw-r--r--etc/electrum.profile2
-rw-r--r--etc/elinks.profile2
-rw-r--r--etc/enchant.profile2
-rw-r--r--etc/engrampa.profile2
-rw-r--r--etc/eog.profile2
-rw-r--r--etc/eom.profile2
-rw-r--r--etc/etr.profile2
-rw-r--r--etc/evince.profile2
-rw-r--r--etc/exiftool.profile2
-rw-r--r--etc/feh.profile2
-rw-r--r--etc/file-roller.profile2
-rw-r--r--etc/file.profile2
-rw-r--r--etc/firefox-common-addons.inc2
-rw-r--r--etc/firefox-common.profile2
-rw-r--r--etc/firefox.profile2
-rw-r--r--etc/flameshot.profile2
-rw-r--r--etc/frozen-bubble.profile2
-rw-r--r--etc/gajim.profile2
-rw-r--r--etc/galculator.profile2
-rw-r--r--etc/gcloud.profile2
-rw-r--r--etc/gedit.profile2
-rw-r--r--etc/geeqie.profile2
-rw-r--r--etc/ghostwriter.profile2
-rw-r--r--etc/github-desktop.profile2
-rw-r--r--etc/gitter.profile2
-rw-r--r--etc/gjs.profile2
-rw-r--r--etc/gnome-books.profile2
-rw-r--r--etc/gnome-chess.profile2
-rw-r--r--etc/gnome-clocks.profile2
-rw-r--r--etc/gnome-logs.profile2
-rw-r--r--etc/gnome-maps.profile2
-rw-r--r--etc/gnome-music.profile2
-rw-r--r--etc/gnome-photos.profile2
-rw-r--r--etc/gnome-pie.profile2
-rw-r--r--etc/gnome-recipes.profile2
-rw-r--r--etc/gnome-weather.profile2
-rw-r--r--etc/goobox.profile2
-rw-r--r--etc/gpicview.profile2
-rw-r--r--etc/gpredict.profile2
-rw-r--r--etc/gradio.profile2
-rw-r--r--etc/gwenview.profile2
-rw-r--r--etc/highlight.profile2
-rw-r--r--etc/icecat.profile2
-rw-r--r--etc/iceweasel.profile2
-rw-r--r--etc/img2txt.profile2
-rw-r--r--etc/kate.profile2
-rw-r--r--etc/keepassx.profile2
-rw-r--r--etc/keepassxc.profile2
-rw-r--r--etc/klavaro.profile2
-rw-r--r--etc/kwin_x11.profile2
-rw-r--r--etc/kwrite.profile2
-rw-r--r--etc/lollypop.profile2
-rw-r--r--etc/lynx.profile2
-rw-r--r--etc/masterpdfeditor.profile2
-rw-r--r--etc/mate-calc.profile2
-rw-r--r--etc/mate-color-select.profile2
-rw-r--r--etc/mate-dictionary.profile2
-rw-r--r--etc/mcabber.profile2
-rw-r--r--etc/mediainfo.profile2
-rw-r--r--etc/min.profile2
-rw-r--r--etc/minetest.profile2
-rw-r--r--etc/ms-office.profile2
-rw-r--r--etc/mupdf.profile2
-rw-r--r--etc/musixmatch.profile4
-rw-r--r--etc/mypaint.profile2
-rw-r--r--etc/nautilus.profile2
-rw-r--r--etc/nitroshare.profile2
-rw-r--r--etc/nyx.profile2
-rw-r--r--etc/ocenaudio.profile2
-rw-r--r--etc/odt2txt.profile2
-rw-r--r--etc/open-invaders.profile2
-rw-r--r--etc/palemoon.profile2
-rw-r--r--etc/parole.profile2
-rw-r--r--etc/pdfchain.profile2
-rw-r--r--etc/pdftotext.profile2
-rw-r--r--etc/ping.profile2
-rw-r--r--etc/pingus.profile2
-rw-r--r--etc/pluma.profile2
-rw-r--r--etc/ppsspp.profile2
-rw-r--r--etc/pybitmessage.profile2
-rw-r--r--etc/pycharm-community.profile2
-rw-r--r--etc/qbittorrent.profile2
-rw-r--r--etc/qtox.profile2
-rw-r--r--etc/quiterss.profile2
-rw-r--r--etc/qupzilla.profile2
-rw-r--r--etc/ricochet.profile2
-rw-r--r--etc/seamonkey.profile2
-rw-r--r--etc/server.profile2
-rw-r--r--etc/simple-scan.profile2
-rw-r--r--etc/simutrans.profile2
-rw-r--r--etc/slack.profile2
-rw-r--r--etc/spotify.profile2
-rw-r--r--etc/standardnotes-desktop.profile2
-rw-r--r--etc/start-tor-browser.profile2
-rw-r--r--etc/steam.profile2
-rw-r--r--etc/strings.profile2
-rw-r--r--etc/supertux2.profile2
-rw-r--r--etc/supertuxkart.profile2
-rw-r--r--etc/surf.profile2
-rw-r--r--etc/tar.profile2
-rw-r--r--etc/terasology.profile2
-rw-r--r--etc/tilp.profile2
-rw-r--r--etc/tor.profile2
-rw-r--r--etc/torbrowser-launcher.profile2
-rw-r--r--etc/totem.profile2
-rw-r--r--etc/tracker.profile2
-rw-r--r--etc/transmission-cli.profile2
-rw-r--r--etc/transmission-show.profile2
-rw-r--r--etc/unknown-horizons.profile2
-rw-r--r--etc/unrar.profile2
-rw-r--r--etc/unzip.profile2
-rw-r--r--etc/uudeview.profile2
-rw-r--r--etc/viewnior.profile2
-rw-r--r--etc/w3m.profile2
-rw-r--r--etc/waterfox.profile2
-rw-r--r--etc/wget.profile2
-rw-r--r--etc/whois.profile2
-rw-r--r--etc/wire-desktop.profile2
-rw-r--r--etc/wireshark.profile2
-rw-r--r--etc/xed.profile2
-rw-r--r--etc/xfburn.profile2
-rw-r--r--etc/xiphos.profile2
-rw-r--r--etc/xmr-stak.profile2
-rw-r--r--etc/xonotic.profile2
-rw-r--r--etc/xplayer.profile2
-rw-r--r--etc/xpra.profile2
-rw-r--r--etc/xreader.profile2
-rw-r--r--etc/xviewer.profile2
-rw-r--r--etc/zathura.profile2
165 files changed, 166 insertions, 166 deletions
diff --git a/etc/QMediathekView.profile b/etc/QMediathekView.profile
index d988fd41a..69dfbecfe 100644
--- a/etc/QMediathekView.profile
+++ b/etc/QMediathekView.profile
@@ -47,7 +47,7 @@ disable-mnt
47private-bin QMediathekView,mplayer,mpv,smplayer,totem,vlc,xplayer 47private-bin QMediathekView,mplayer,mpv,smplayer,totem,vlc,xplayer
48private-cache 48private-cache
49private-dev 49private-dev
50# private-etc none 50# private-etc alternatives
51# private-lib 51# private-lib
52private-tmp 52private-tmp
53 53
diff --git a/etc/QOwnNotes.profile b/etc/QOwnNotes.profile
index 1135b850b..f63a8b9ef 100644
--- a/etc/QOwnNotes.profile
+++ b/etc/QOwnNotes.profile
@@ -49,7 +49,7 @@ tracelog
49disable-mnt 49disable-mnt
50private-bin QOwnNotes,gio 50private-bin QOwnNotes,gio
51private-dev 51private-dev
52private-etc fonts,ld.so.cache,pulse,resolv.conf,hosts,nsswitch.conf,host.conf,ca-certificates,ssl,pki,crypto-policies 52private-etc alternatives,fonts,ld.so.cache,pulse,resolv.conf,hosts,nsswitch.conf,host.conf,ca-certificates,ssl,pki,crypto-policies
53private-tmp 53private-tmp
54 54
55noexec ${HOME} 55noexec ${HOME}
diff --git a/etc/Xephyr.profile b/etc/Xephyr.profile
index a95c8989a..d9b7f8c26 100644
--- a/etc/Xephyr.profile
+++ b/etc/Xephyr.profile
@@ -39,5 +39,5 @@ private
39# private-bin Xephyr,sh,xkbcomp 39# private-bin Xephyr,sh,xkbcomp
40# private-bin Xephyr,sh,xkbcomp,strace,bash,cat,ls 40# private-bin Xephyr,sh,xkbcomp,strace,bash,cat,ls
41private-dev 41private-dev
42# private-etc ld.so.conf,ld.so.cache,resolv.conf,host.conf,nsswitch.conf,gai.conf,hosts,hostname 42# private-etc alternatives,ld.so.conf,ld.so.cache,resolv.conf,host.conf,nsswitch.conf,gai.conf,hosts,hostname
43private-tmp 43private-tmp
diff --git a/etc/Xvfb.profile b/etc/Xvfb.profile
index 967946a6c..ed07485d6 100644
--- a/etc/Xvfb.profile
+++ b/etc/Xvfb.profile
@@ -41,5 +41,5 @@ private
41# private-bin Xvfb,sh,xkbcomp 41# private-bin Xvfb,sh,xkbcomp
42# private-bin Xvfb,sh,xkbcomp,strace,bash,cat,ls 42# private-bin Xvfb,sh,xkbcomp,strace,bash,cat,ls
43private-dev 43private-dev
44private-etc ld.so.conf,ld.so.cache,resolv.conf,host.conf,nsswitch.conf,gai.conf,hosts,hostname 44private-etc alternatives,ld.so.conf,ld.so.cache,resolv.conf,host.conf,nsswitch.conf,gai.conf,hosts,hostname
45private-tmp 45private-tmp
diff --git a/etc/abrowser.profile b/etc/abrowser.profile
index 010247c6b..b88d7b5f4 100644
--- a/etc/abrowser.profile
+++ b/etc/abrowser.profile
@@ -14,7 +14,7 @@ whitelist ${HOME}/.cache/mozilla/abrowser
14whitelist ${HOME}/.mozilla 14whitelist ${HOME}/.mozilla
15 15
16# private-etc must first be enabled in firefox-common.profile 16# private-etc must first be enabled in firefox-common.profile
17#private-etc abrowser 17#private-etc abrowser, alternatives
18 18
19 19
20# Redirect 20# Redirect
diff --git a/etc/amarok.profile b/etc/amarok.profile
index 6f2e6b3cc..6cec3befc 100644
--- a/etc/amarok.profile
+++ b/etc/amarok.profile
@@ -31,5 +31,5 @@ shell none
31 31
32# private-bin amarok 32# private-bin amarok
33private-dev 33private-dev
34# private-etc machine-id,pulse,asound.conf,ca-certificates,ssl,pki,crypto-policies 34# private-etc alternatives,machine-id,pulse,asound.conf,ca-certificates,ssl,pki,crypto-policies
35private-tmp 35private-tmp
diff --git a/etc/ardour5.profile b/etc/ardour5.profile
index 3c207b5b3..377ce0a2c 100644
--- a/etc/ardour5.profile
+++ b/etc/ardour5.profile
@@ -36,7 +36,7 @@ shell none
36#private-bin sh,ardour4,ardour5,ardour5-copy-mixer,ardour5-export,ardour5-fix_bbtppq,grep,sed,ldd,nm 36#private-bin sh,ardour4,ardour5,ardour5-copy-mixer,ardour5-export,ardour5-fix_bbtppq,grep,sed,ldd,nm
37private-cache 37private-cache
38private-dev 38private-dev
39#private-etc pulse,X11,alternatives,ardour4,ardour5,fonts,machine-id,asound.conf 39#private-etc alternatives,pulse,X11,alternatives,ardour4,ardour5,fonts,machine-id,asound.conf
40private-tmp 40private-tmp
41 41
42noexec ${HOME} 42noexec ${HOME}
diff --git a/etc/aria2c.profile b/etc/aria2c.profile
index 3015349b7..56ed081e6 100644
--- a/etc/aria2c.profile
+++ b/etc/aria2c.profile
@@ -37,7 +37,7 @@ disable-mnt
37private-bin aria2c,gzip 37private-bin aria2c,gzip
38private-cache 38private-cache
39private-dev 39private-dev
40private-etc ca-certificates,ssl 40private-etc alternatives,ca-certificates,ssl
41private-lib libreadline.so.* 41private-lib libreadline.so.*
42private-tmp 42private-tmp
43 43
diff --git a/etc/ark.profile b/etc/ark.profile
index 37211682c..b60674f95 100644
--- a/etc/ark.profile
+++ b/etc/ark.profile
@@ -34,7 +34,7 @@ seccomp
34shell none 34shell none
35 35
36private-bin ark,unrar,rar,unzip,zip,zipinfo,7z,p7zip,unar,lsar,lrzip,lzop,lz4,bash,sh,tclsh 36private-bin ark,unrar,rar,unzip,zip,zipinfo,7z,p7zip,unar,lsar,lrzip,lzop,lz4,bash,sh,tclsh
37#private-etc smb.conf,samba,mtab,fonts,drirc,kde5rc,passwd,group,xdg 37#private-etc alternatives,smb.conf,samba,mtab,fonts,drirc,kde5rc,passwd,group,xdg
38 38
39private-dev 39private-dev
40private-tmp 40private-tmp
diff --git a/etc/arm.profile b/etc/arm.profile
index 288dd972a..217b61d09 100644
--- a/etc/arm.profile
+++ b/etc/arm.profile
@@ -44,7 +44,7 @@ tracelog
44disable-mnt 44disable-mnt
45private-bin arm,tor,sh,bash,python*,ps,lsof,ldconfig 45private-bin arm,tor,sh,bash,python*,ps,lsof,ldconfig
46private-dev 46private-dev
47private-etc tor,passwd,ca-certificates,ssl,pki,crypto-policies 47private-etc alternatives,tor,passwd,ca-certificates,ssl,pki,crypto-policies
48private-tmp 48private-tmp
49 49
50noexec ${HOME} 50noexec ${HOME}
diff --git a/etc/artha.profile b/etc/artha.profile
index 7b0c6735b..431fc3ed1 100644
--- a/etc/artha.profile
+++ b/etc/artha.profile
@@ -37,7 +37,7 @@ disable-mnt
37private-bin artha,enchant,notify-send 37private-bin artha,enchant,notify-send
38private-cache 38private-cache
39private-dev 39private-dev
40private-etc fonts 40private-etc alternatives,fonts
41private-lib libnotify.so.* 41private-lib libnotify.so.*
42private-tmp 42private-tmp
43 43
diff --git a/etc/atool.profile b/etc/atool.profile
index d5daeabbe..c82108cef 100644
--- a/etc/atool.profile
+++ b/etc/atool.profile
@@ -43,5 +43,5 @@ private-cache
43# private-bin atool 43# private-bin atool
44private-dev 44private-dev
45# without login.defs atool complains and uses UID/GID 1000 by default 45# without login.defs atool complains and uses UID/GID 1000 by default
46private-etc passwd,group,login.defs 46private-etc alternatives,passwd,group,login.defs
47private-tmp 47private-tmp
diff --git a/etc/atril.profile b/etc/atril.profile
index 92fae21d4..aca945ba3 100644
--- a/etc/atril.profile
+++ b/etc/atril.profile
@@ -41,7 +41,7 @@ tracelog
41 41
42private-bin atril, atril-previewer, atril-thumbnailer 42private-bin atril, atril-previewer, atril-thumbnailer
43private-dev 43private-dev
44private-etc fonts,ld.so.cache 44private-etc alternatives,fonts,ld.so.cache
45# atril uses webkit gtk to display epub files 45# atril uses webkit gtk to display epub files
46# waiting for globbing support in private-lib; for now hardcoding it to webkit2gtk-4.0 46# waiting for globbing support in private-lib; for now hardcoding it to webkit2gtk-4.0
47#private-lib webkit2gtk-4.0 - problems on Arch with the new version of WebKit 47#private-lib webkit2gtk-4.0 - problems on Arch with the new version of WebKit
diff --git a/etc/authenticator.profile b/etc/authenticator.profile
index 9656bb3d7..fc86001be 100644
--- a/etc/authenticator.profile
+++ b/etc/authenticator.profile
@@ -40,7 +40,7 @@ disable-mnt
40# private-bin authenticator 40# private-bin authenticator
41private-cache 41private-cache
42private-dev 42private-dev
43private-etc fonts,ld.so.cache 43private-etc alternatives,fonts,ld.so.cache
44# private-lib 44# private-lib
45private-tmp 45private-tmp
46 46
diff --git a/etc/basilisk.profile b/etc/basilisk.profile
index 5f9fc8ef7..21daebaac 100644
--- a/etc/basilisk.profile
+++ b/etc/basilisk.profile
@@ -20,7 +20,7 @@ seccomp
20 20
21#private-bin basilisk 21#private-bin basilisk
22# private-etc must first be enabled in firefox-common.profile 22# private-etc must first be enabled in firefox-common.profile
23#private-etc basilisk 23#private-etc alternatives,basilisk
24#private-opt basilisk 24#private-opt basilisk
25 25
26# Redirect 26# Redirect
diff --git a/etc/bibletime.profile b/etc/bibletime.profile
index 07cb889e4..6e40054f7 100644
--- a/etc/bibletime.profile
+++ b/etc/bibletime.profile
@@ -44,5 +44,5 @@ shell none
44 44
45# private-bin bibletime,qt5ct 45# private-bin bibletime,qt5ct
46private-dev 46private-dev
47private-etc fonts,resolv.conf,sword,sword.conf,passwd,machine-id,ca-certificates,ssl,pki,crypto-policies 47private-etc alternatives,fonts,resolv.conf,sword,sword.conf,passwd,machine-id,ca-certificates,ssl,pki,crypto-policies
48private-tmp 48private-tmp
diff --git a/etc/bitcoin-qt.profile b/etc/bitcoin-qt.profile
index 46ce0775b..def292118 100644
--- a/etc/bitcoin-qt.profile
+++ b/etc/bitcoin-qt.profile
@@ -42,7 +42,7 @@ tracelog
42private-bin bitcoin-qt 42private-bin bitcoin-qt
43private-dev 43private-dev
44# Causes problem with loading of libGL.so 44# Causes problem with loading of libGL.so
45#private-etc fonts,ca-certificates,ssl,pki,crypto-policies 45#private-etc alternatives,fonts,ca-certificates,ssl,pki,crypto-policies
46# Works, but QT complains about OpenSSL a bit. 46# Works, but QT complains about OpenSSL a bit.
47#private-lib 47#private-lib
48private-tmp 48private-tmp
diff --git a/etc/bless.profile b/etc/bless.profile
index cc03107a5..8315f4563 100644
--- a/etc/bless.profile
+++ b/etc/bless.profile
@@ -35,7 +35,7 @@ shell none
35# private-bin bless,sh,bash,mono 35# private-bin bless,sh,bash,mono
36private-cache 36private-cache
37private-dev 37private-dev
38private-etc fonts,mono 38private-etc alternatives,fonts,mono
39private-tmp 39private-tmp
40 40
41noexec ${HOME} 41noexec ${HOME}
diff --git a/etc/brasero.profile b/etc/brasero.profile
index 8ab9472ac..5021db254 100644
--- a/etc/brasero.profile
+++ b/etc/brasero.profile
@@ -30,7 +30,7 @@ tracelog
30# private-bin brasero 30# private-bin brasero
31private-cache 31private-cache
32# private-dev 32# private-dev
33# private-etc fonts 33# private-etc alternatives,fonts
34# private-tmp 34# private-tmp
35 35
36memory-deny-write-execute 36memory-deny-write-execute
diff --git a/etc/bsdtar.profile b/etc/bsdtar.profile
index f6864386e..9e45b1fd6 100644
--- a/etc/bsdtar.profile
+++ b/etc/bsdtar.profile
@@ -37,4 +37,4 @@ tracelog
37# support compressed archives 37# support compressed archives
38private-bin sh,bash,bsdcat,bsdcpio,bsdtar,gtar,compress,gzip,lzma,xz,bzip2,lbzip2,lzip,lzop,lz4,libarchive 38private-bin sh,bash,bsdcat,bsdcpio,bsdtar,gtar,compress,gzip,lzma,xz,bzip2,lbzip2,lzip,lzop,lz4,libarchive
39private-dev 39private-dev
40private-etc passwd,group,localtime 40private-etc alternatives,passwd,group,localtime
diff --git a/etc/caja.profile b/etc/caja.profile
index f938792cd..49516de8c 100644
--- a/etc/caja.profile
+++ b/etc/caja.profile
@@ -41,5 +41,5 @@ tracelog
41# caja needs to be able to start arbitrary applications so we cannot blacklist their files 41# caja needs to be able to start arbitrary applications so we cannot blacklist their files
42# private-bin caja 42# private-bin caja
43# private-dev 43# private-dev
44# private-etc fonts 44# private-etc alternatives,fonts
45# private-tmp 45# private-tmp
diff --git a/etc/clawsker.profile b/etc/clawsker.profile
index e863a6a45..d50882c75 100644
--- a/etc/clawsker.profile
+++ b/etc/clawsker.profile
@@ -44,7 +44,7 @@ shell none
44private-bin clawsker,perl 44private-bin clawsker,perl
45private-cache 45private-cache
46private-dev 46private-dev
47private-etc fonts 47private-etc alternatives,fonts
48private-lib girepository-1.*,libgirepository-1.*,perl* 48private-lib girepository-1.*,libgirepository-1.*,perl*
49private-tmp 49private-tmp
50 50
diff --git a/etc/cliqz.profile b/etc/cliqz.profile
index d0b8cc0ef..b1e4ea613 100644
--- a/etc/cliqz.profile
+++ b/etc/cliqz.profile
@@ -17,7 +17,7 @@ whitelist ${HOME}/.cliqz
17whitelist ${HOME}/.config/cliqz 17whitelist ${HOME}/.config/cliqz
18 18
19# private-etc must first be enabled in firefox-common.profile 19# private-etc must first be enabled in firefox-common.profile
20#private-etc cliqz 20#private-etc alternatives,cliqz
21 21
22# Redirect 22# Redirect
23include firefox-common.profile 23include firefox-common.profile
diff --git a/etc/cmus.profile b/etc/cmus.profile
index ee6600b76..e602c4e2a 100644
--- a/etc/cmus.profile
+++ b/etc/cmus.profile
@@ -27,4 +27,4 @@ seccomp
27shell none 27shell none
28 28
29private-bin cmus 29private-bin cmus
30private-etc group,machine-id,pulse,asound.conf,ca-certificates,ssl,pki,crypto-policies 30private-etc alternatives,group,machine-id,pulse,asound.conf,ca-certificates,ssl,pki,crypto-policies
diff --git a/etc/crow.profile b/etc/crow.profile
index c016717be..93f71cef8 100644
--- a/etc/crow.profile
+++ b/etc/crow.profile
@@ -37,7 +37,7 @@ shell none
37disable-mnt 37disable-mnt
38private-bin crow 38private-bin crow
39private-dev 39private-dev
40private-etc ca-certificates,ssl,machine-id,dconf,nsswitch.conf,resolv.conf,fonts,asound.conf,pulse,pki,crypto-policies 40private-etc alternatives,ca-certificates,ssl,machine-id,dconf,nsswitch.conf,resolv.conf,fonts,asound.conf,pulse,pki,crypto-policies
41private-opt none 41private-opt none
42private-tmp 42private-tmp
43private-srv none 43private-srv none
diff --git a/etc/curl.profile b/etc/curl.profile
index d20e00740..1783f1337 100644
--- a/etc/curl.profile
+++ b/etc/curl.profile
@@ -33,7 +33,7 @@ shell none
33# private-bin curl 33# private-bin curl
34private-cache 34private-cache
35private-dev 35private-dev
36# private-etc resolv.conf,ca-certificates,ssl,pki,crypto-policies 36# private-etc alternatives,resolv.conf,ca-certificates,ssl,pki,crypto-policies
37private-tmp 37private-tmp
38 38
39noexec ${HOME} 39noexec ${HOME}
diff --git a/etc/cyberfox.profile b/etc/cyberfox.profile
index fcb448b30..147791d26 100644
--- a/etc/cyberfox.profile
+++ b/etc/cyberfox.profile
@@ -15,7 +15,7 @@ whitelist ${HOME}/.cache/8pecxstudios
15 15
16# private-bin cyberfox,which,sh,dbus-launch,dbus-send,env 16# private-bin cyberfox,which,sh,dbus-launch,dbus-send,env
17# private-etc must first be enabled in firefox-common.profile 17# private-etc must first be enabled in firefox-common.profile
18#private-etc cyberfox 18#private-etc alternatives,cyberfox
19 19
20# Redirect 20# Redirect
21include firefox-common.profile 21include firefox-common.profile
diff --git a/etc/default.profile b/etc/default.profile
index 14ea0ae17..917e42287 100644
--- a/etc/default.profile
+++ b/etc/default.profile
@@ -37,7 +37,7 @@ seccomp
37# private-bin program 37# private-bin program
38# private-cache 38# private-cache
39# private-dev 39# private-dev
40# private-etc none 40# private-etc alternatives
41# private-lib 41# private-lib
42# private-tmp 42# private-tmp
43 43
diff --git a/etc/devilspie.profile b/etc/devilspie.profile
index b3558a038..a809bee0c 100644
--- a/etc/devilspie.profile
+++ b/etc/devilspie.profile
@@ -37,7 +37,7 @@ disable-mnt
37private-bin devilspie 37private-bin devilspie
38private-cache 38private-cache
39private-dev 39private-dev
40private-etc none 40private-etc alternatives
41private-lib gconv 41private-lib gconv
42private-tmp 42private-tmp
43 43
diff --git a/etc/devilspie2.profile b/etc/devilspie2.profile
index 4ab2634e8..d8c10413b 100644
--- a/etc/devilspie2.profile
+++ b/etc/devilspie2.profile
@@ -37,7 +37,7 @@ disable-mnt
37private-bin devilspie2 37private-bin devilspie2
38private-cache 38private-cache
39private-dev 39private-dev
40private-etc none 40private-etc alternatives
41private-lib gconv 41private-lib gconv
42private-tmp 42private-tmp
43 43
diff --git a/etc/dig.profile b/etc/dig.profile
index 8a0ba8f09..f5b26c195 100644
--- a/etc/dig.profile
+++ b/etc/dig.profile
@@ -40,7 +40,7 @@ private
40private-bin sh,bash,dig 40private-bin sh,bash,dig
41private-cache 41private-cache
42private-dev 42private-dev
43# private-etc resolv.conf 43# private-etc alternatives,resolv.conf
44private-lib 44private-lib
45private-tmp 45private-tmp
46 46
diff --git a/etc/digikam.profile b/etc/digikam.profile
index ccc0a6544..cc0e98ba3 100644
--- a/etc/digikam.profile
+++ b/etc/digikam.profile
@@ -37,7 +37,7 @@ shell none
37 37
38# private-bin program 38# private-bin program
39# private-dev - prevents libdc1394 loading; this lib is used to connect to a camera device 39# private-dev - prevents libdc1394 loading; this lib is used to connect to a camera device
40# private-etc ca-certificates,ssl,pki,crypto-policies 40# private-etc alternatives,ca-certificates,ssl,pki,crypto-policies
41private-tmp 41private-tmp
42 42
43noexec ${HOME} 43noexec ${HOME}
diff --git a/etc/dino.profile b/etc/dino.profile
index 9844ce81a..76f63fdc8 100644
--- a/etc/dino.profile
+++ b/etc/dino.profile
@@ -36,7 +36,7 @@ shell none
36disable-mnt 36disable-mnt
37private-bin dino 37private-bin dino
38private-dev 38private-dev
39# private-etc fonts,ca-certificates,ssl,pki,crypto-policies # breaks server connection 39# private-etc alternatives,fonts,ca-certificates,ssl,pki,crypto-policies # breaks server connection
40private-tmp 40private-tmp
41 41
42noexec ${HOME} 42noexec ${HOME}
diff --git a/etc/discord-common.profile b/etc/discord-common.profile
index 9c6a40e8a..c520454e8 100644
--- a/etc/discord-common.profile
+++ b/etc/discord-common.profile
@@ -27,7 +27,7 @@ seccomp
27 27
28private-bin sh,xdg-mime,tr,sed,echo,head,cut,xdg-open,grep,egrep,bash,zsh 28private-bin sh,xdg-mime,tr,sed,echo,head,cut,xdg-open,grep,egrep,bash,zsh
29private-dev 29private-dev
30private-etc fonts,machine-id,localtime,ld.so.cache,ca-certificates,ssl,pki,crypto-policies,resolv.conf 30private-etc alternatives,fonts,machine-id,localtime,ld.so.cache,ca-certificates,ssl,pki,crypto-policies,resolv.conf
31private-tmp 31private-tmp
32 32
33noexec ${HOME} 33noexec ${HOME}
diff --git a/etc/display.profile b/etc/display.profile
index 3182aebbe..7e4263d2e 100644
--- a/etc/display.profile
+++ b/etc/display.profile
@@ -39,5 +39,5 @@ shell none
39 39
40private-bin display,python* 40private-bin display,python*
41private-dev 41private-dev
42# private-etc none - on Debian-based systems display is a symlink in /etc/alternatives 42# private-etc alternatives - on Debian-based systems display is a symlink in /etc/alternatives
43private-tmp 43private-tmp
diff --git a/etc/easystroke.profile b/etc/easystroke.profile
index 31cc48e9f..44156f97e 100644
--- a/etc/easystroke.profile
+++ b/etc/easystroke.profile
@@ -36,7 +36,7 @@ disable-mnt
36private-bin easystroke,bash,sh 36private-bin easystroke,bash,sh
37private-cache 37private-cache
38private-dev 38private-dev
39private-etc fonts 39private-etc alternatives,fonts
40private-lib gdk-pixbuf-2.*,gio,gvfs/libgvfscommon.so,libgconf-2.so.*,librsvg-2.so.* 40private-lib gdk-pixbuf-2.*,gio,gvfs/libgvfscommon.so,libgconf-2.so.*,librsvg-2.so.*
41private-tmp 41private-tmp
42 42
diff --git a/etc/electrum.profile b/etc/electrum.profile
index d24a31299..a290683de 100644
--- a/etc/electrum.profile
+++ b/etc/electrum.profile
@@ -47,7 +47,7 @@ disable-mnt
47private-bin electrum,python* 47private-bin electrum,python*
48private-cache 48private-cache
49private-dev 49private-dev
50private-etc fonts,dconf,ca-certificates,ssl,pki,crypto-policies,machine-id 50private-etc alternatives,fonts,dconf,ca-certificates,ssl,pki,crypto-policies,machine-id
51private-tmp 51private-tmp
52 52
53noexec ${HOME} 53noexec ${HOME}
diff --git a/etc/elinks.profile b/etc/elinks.profile
index 6643c5fda..842a0db04 100644
--- a/etc/elinks.profile
+++ b/etc/elinks.profile
@@ -36,5 +36,5 @@ tracelog
36# private-bin elinks 36# private-bin elinks
37private-cache 37private-cache
38private-dev 38private-dev
39# private-etc ca-certificates,ssl,pki,crypto-policies 39# private-etc alternatives,ca-certificates,ssl,pki,crypto-policies
40private-tmp 40private-tmp
diff --git a/etc/enchant.profile b/etc/enchant.profile
index e29e542ab..1d3d33d68 100644
--- a/etc/enchant.profile
+++ b/etc/enchant.profile
@@ -35,7 +35,7 @@ tracelog
35# private-bin enchant, enchant-* 35# private-bin enchant, enchant-*
36private-cache 36private-cache
37private-dev 37private-dev
38private-etc none 38private-etc alternatives
39private-tmp 39private-tmp
40 40
41# memory-deny-write-execute 41# memory-deny-write-execute
diff --git a/etc/engrampa.profile b/etc/engrampa.profile
index b9f2632c4..670808de2 100644
--- a/etc/engrampa.profile
+++ b/etc/engrampa.profile
@@ -34,7 +34,7 @@ tracelog
34 34
35# private-bin engrampa 35# private-bin engrampa
36private-dev 36private-dev
37# private-etc fonts 37# private-etc alternatives,fonts
38# private-tmp 38# private-tmp
39 39
40memory-deny-write-execute 40memory-deny-write-execute
diff --git a/etc/eog.profile b/etc/eog.profile
index 75d343d4e..d448b7c6c 100644
--- a/etc/eog.profile
+++ b/etc/eog.profile
@@ -39,7 +39,7 @@ shell none
39private-bin eog 39private-bin eog
40private-cache 40private-cache
41private-dev 41private-dev
42private-etc fonts 42private-etc alternatives,fonts
43private-lib gdk-pixbuf-2.*,gio,girepository-1.*,gvfs,libgconf-2.so.* 43private-lib gdk-pixbuf-2.*,gio,girepository-1.*,gvfs,libgconf-2.so.*
44private-tmp 44private-tmp
45 45
diff --git a/etc/eom.profile b/etc/eom.profile
index 7d84cd3b4..c34331da6 100644
--- a/etc/eom.profile
+++ b/etc/eom.profile
@@ -39,7 +39,7 @@ tracelog
39 39
40private-bin eom 40private-bin eom
41private-dev 41private-dev
42private-etc fonts 42private-etc alternatives,fonts
43private-lib 43private-lib
44private-tmp 44private-tmp
45 45
diff --git a/etc/etr.profile b/etc/etr.profile
index 6c3db897b..cf13a42de 100644
--- a/etc/etr.profile
+++ b/etc/etr.profile
@@ -31,5 +31,5 @@ shell none
31 31
32# private-bin etr 32# private-bin etr
33private-dev 33private-dev
34# private-etc none 34# private-etc alternatives
35private-tmp 35private-tmp
diff --git a/etc/evince.profile b/etc/evince.profile
index b9ff3c121..e9b530ece 100644
--- a/etc/evince.profile
+++ b/etc/evince.profile
@@ -39,7 +39,7 @@ tracelog
39 39
40private-bin evince,evince-previewer,evince-thumbnailer 40private-bin evince,evince-previewer,evince-thumbnailer
41private-dev 41private-dev
42private-etc fonts,machine-id 42private-etc alternatives,fonts,machine-id
43 43
44private-lib evince,gdk-pixbuf-2.*,gio,gvfs/libgvfscommon.so,libdjvulibre.so.*,libgconf-2.so.*,libpoppler-glib.so.*,librsvg-2.so.*,gconv 44private-lib evince,gdk-pixbuf-2.*,gio,gvfs/libgvfscommon.so,libdjvulibre.so.*,libgconf-2.so.*,libpoppler-glib.so.*,librsvg-2.so.*,gconv
45 45
diff --git a/etc/exiftool.profile b/etc/exiftool.profile
index 3eac35bac..37e01f8d3 100644
--- a/etc/exiftool.profile
+++ b/etc/exiftool.profile
@@ -39,5 +39,5 @@ tracelog
39# private-bin exiftool,perl 39# private-bin exiftool,perl
40private-cache 40private-cache
41private-dev 41private-dev
42private-etc none 42private-etc alternatives
43private-tmp 43private-tmp
diff --git a/etc/feh.profile b/etc/feh.profile
index ddf0fa154..eb6f311bb 100644
--- a/etc/feh.profile
+++ b/etc/feh.profile
@@ -31,5 +31,5 @@ shell none
31private-bin feh,jpegexiforient,jpegtran 31private-bin feh,jpegexiforient,jpegtran
32private-cache 32private-cache
33private-dev 33private-dev
34private-etc feh 34private-etc alternatives,feh
35private-tmp 35private-tmp
diff --git a/etc/file-roller.profile b/etc/file-roller.profile
index d79b4de4b..e4863bfc0 100644
--- a/etc/file-roller.profile
+++ b/etc/file-roller.profile
@@ -34,7 +34,7 @@ tracelog
34 34
35# private-bin file-roller 35# private-bin file-roller
36private-dev 36private-dev
37# private-etc fonts 37# private-etc alternatives,fonts
38# private-tmp 38# private-tmp
39 39
40#memory-deny-write-execute - breaks on Arch 40#memory-deny-write-execute - breaks on Arch
diff --git a/etc/file.profile b/etc/file.profile
index f2f9f25f9..0769f8887 100644
--- a/etc/file.profile
+++ b/etc/file.profile
@@ -34,7 +34,7 @@ x11 none
34#private-bin file 34#private-bin file
35private-cache 35private-cache
36private-dev 36private-dev
37private-etc magic.mgc,magic,localtime 37private-etc alternatives,magic.mgc,magic,localtime
38private-lib libarchive.so.*,libfakeroot,libmagic.so.* 38private-lib libarchive.so.*,libfakeroot,libmagic.so.*
39 39
40memory-deny-write-execute 40memory-deny-write-execute
diff --git a/etc/firefox-common-addons.inc b/etc/firefox-common-addons.inc
index 7a0c3e99f..1932b2f1c 100644
--- a/etc/firefox-common-addons.inc
+++ b/etc/firefox-common-addons.inc
@@ -61,4 +61,4 @@ noblacklist /usr/lib/python3*
61 61
62# Flash plugin 62# Flash plugin
63# private-etc must first be enabled in firefox-common.profile and in profiles including it. 63# private-etc must first be enabled in firefox-common.profile and in profiles including it.
64#private-etc adobe 64#private-etc alternatives,adobe
diff --git a/etc/firefox-common.profile b/etc/firefox-common.profile
index 7c65be7cb..69920aa5f 100644
--- a/etc/firefox-common.profile
+++ b/etc/firefox-common.profile
@@ -51,7 +51,7 @@ shell none
51disable-mnt 51disable-mnt
52private-dev 52private-dev
53# private-etc below works fine on most distributions. There are some problems on CentOS. 53# private-etc below works fine on most distributions. There are some problems on CentOS.
54#private-etc ca-certificates,ssl,machine-id,dconf,selinux,passwd,group,hostname,hosts,localtime,nsswitch.conf,resolv.conf,xdg,gtk-2.0,gtk-3.0,X11,pango,fonts,mime.types,mailcap,asound.conf,pulse,pki,crypto-policies,ld.so.cache 54#private-etc alternatives,ca-certificates,ssl,machine-id,dconf,selinux,passwd,group,hostname,hosts,localtime,nsswitch.conf,resolv.conf,xdg,gtk-2.0,gtk-3.0,X11,pango,fonts,mime.types,mailcap,asound.conf,pulse,pki,crypto-policies,ld.so.cache
55private-tmp 55private-tmp
56 56
57# breaks DRM binaries 57# breaks DRM binaries
diff --git a/etc/firefox.profile b/etc/firefox.profile
index 830bbc6a7..2861a91b4 100644
--- a/etc/firefox.profile
+++ b/etc/firefox.profile
@@ -17,7 +17,7 @@ whitelist ${HOME}/.mozilla
17# firefox requires a shell to launch on Arch. 17# firefox requires a shell to launch on Arch.
18#private-bin firefox,which,sh,dbus-launch,dbus-send,env,bash 18#private-bin firefox,which,sh,dbus-launch,dbus-send,env,bash
19# private-etc must first be enabled in firefox-common.profile 19# private-etc must first be enabled in firefox-common.profile
20#private-etc firefox 20#private-etc alternatives,firefox
21 21
22# Redirect 22# Redirect
23include firefox-common.profile 23include firefox-common.profile
diff --git a/etc/flameshot.profile b/etc/flameshot.profile
index d665d1851..1c5f90f42 100644
--- a/etc/flameshot.profile
+++ b/etc/flameshot.profile
@@ -35,7 +35,7 @@ shell none
35disable-mnt 35disable-mnt
36private-bin flameshot 36private-bin flameshot
37private-cache 37private-cache
38private-etc fonts,ld.so.conf,resolv.conf,ca-certificates,ssl,pki,crypto-policies 38private-etc alternatives,fonts,ld.so.conf,resolv.conf,ca-certificates,ssl,pki,crypto-policies
39private-dev 39private-dev
40private-tmp 40private-tmp
41 41
diff --git a/etc/frozen-bubble.profile b/etc/frozen-bubble.profile
index 3697252e7..ed3b4490f 100644
--- a/etc/frozen-bubble.profile
+++ b/etc/frozen-bubble.profile
@@ -35,5 +35,5 @@ shell none
35disable-mnt 35disable-mnt
36# private-bin frozen-bubble 36# private-bin frozen-bubble
37private-dev 37private-dev
38# private-etc none 38# private-etc alternatives
39private-tmp 39private-tmp
diff --git a/etc/gajim.profile b/etc/gajim.profile
index a957b07b0..efe85f3aa 100644
--- a/etc/gajim.profile
+++ b/etc/gajim.profile
@@ -47,7 +47,7 @@ tracelog
47disable-mnt 47disable-mnt
48private-bin python,python3,sh,gpg,gpg2,gajim,bash,zsh,paplay,gajim-history-manager 48private-bin python,python3,sh,gpg,gpg2,gajim,bash,zsh,paplay,gajim-history-manager
49private-dev 49private-dev
50private-etc alsa,asound.conf,ca-certificates,crypto-policies,fonts,group,hostname,hosts,ld.so.cache,ld.so.conf,localtime,machine-id,passwd,pki,pulse,resolv.conf,ssl 50private-etc alsa,alternatives,asound.conf,ca-certificates,crypto-policies,fonts,group,hostname,hosts,ld.so.cache,ld.so.conf,localtime,machine-id,passwd,pki,pulse,resolv.conf,ssl
51private-tmp 51private-tmp
52 52
53noexec ${HOME} 53noexec ${HOME}
diff --git a/etc/galculator.profile b/etc/galculator.profile
index 323c880a8..509d9bd05 100644
--- a/etc/galculator.profile
+++ b/etc/galculator.profile
@@ -38,6 +38,6 @@ tracelog
38 38
39private-bin galculator 39private-bin galculator
40private-dev 40private-dev
41private-etc fonts 41private-etc alternatives,fonts
42private-lib 42private-lib
43private-tmp 43private-tmp
diff --git a/etc/gcloud.profile b/etc/gcloud.profile
index 5aa73b38f..d9df8fd37 100644
--- a/etc/gcloud.profile
+++ b/etc/gcloud.profile
@@ -32,7 +32,7 @@ tracelog
32 32
33disable-mnt 33disable-mnt
34private-dev 34private-dev
35private-etc ca-certificates,ssl,hosts,localtime,nsswitch.conf,resolv.conf,pki,crypto-policies,ld.so.cache 35private-etc alternatives,ca-certificates,ssl,hosts,localtime,nsswitch.conf,resolv.conf,pki,crypto-policies,ld.so.cache
36private-tmp 36private-tmp
37 37
38noexec /tmp 38noexec /tmp
diff --git a/etc/gedit.profile b/etc/gedit.profile
index af0a3da56..a583c534f 100644
--- a/etc/gedit.profile
+++ b/etc/gedit.profile
@@ -40,7 +40,7 @@ tracelog
40 40
41# private-bin gedit 41# private-bin gedit
42private-dev 42private-dev
43# private-etc fonts 43# private-etc alternatives,fonts
44private-lib /usr/bin/gedit,libtinfo.so.*,libreadline.so.*,gedit,libgspell-1.so.*,gconv,aspell 44private-lib /usr/bin/gedit,libtinfo.so.*,libreadline.so.*,gedit,libgspell-1.so.*,gconv,aspell
45private-tmp 45private-tmp
46 46
diff --git a/etc/geeqie.profile b/etc/geeqie.profile
index a7d82b5fb..adfc3ef1c 100644
--- a/etc/geeqie.profile
+++ b/etc/geeqie.profile
@@ -31,4 +31,4 @@ shell none
31 31
32# private-bin geeqie 32# private-bin geeqie
33private-dev 33private-dev
34# private-etc X11 34# private-etc alternatives,X11
diff --git a/etc/ghostwriter.profile b/etc/ghostwriter.profile
index bdca281ed..11686e0e9 100644
--- a/etc/ghostwriter.profile
+++ b/etc/ghostwriter.profile
@@ -52,7 +52,7 @@ tracelog
52#private-bin ghostwriter,pandoc 52#private-bin ghostwriter,pandoc
53private-cache 53private-cache
54private-dev 54private-dev
55private-etc cups,crypto-policies,localtime,drirc,fonts,gtk-3.0,dconf,machine-id 55private-etc alternatives,cups,crypto-policies,localtime,drirc,fonts,gtk-3.0,dconf,machine-id
56# Breaks Translation 56# Breaks Translation
57#private-lib 57#private-lib
58private-tmp 58private-tmp
diff --git a/etc/github-desktop.profile b/etc/github-desktop.profile
index 9ac212fe8..934ac7c40 100644
--- a/etc/github-desktop.profile
+++ b/etc/github-desktop.profile
@@ -39,7 +39,7 @@ disable-mnt
39private-cache 39private-cache
40?HAS_APPIMAGE: ignore private-dev 40?HAS_APPIMAGE: ignore private-dev
41private-dev 41private-dev
42# private-etc none 42# private-etc alternatives
43# private-lib 43# private-lib
44private-tmp 44private-tmp
45 45
diff --git a/etc/gitter.profile b/etc/gitter.profile
index d8439fa79..d84f01f20 100644
--- a/etc/gitter.profile
+++ b/etc/gitter.profile
@@ -35,7 +35,7 @@ shell none
35 35
36disable-mnt 36disable-mnt
37private-bin bash,env,gitter 37private-bin bash,env,gitter
38private-etc fonts,pulse,resolv.conf,ca-certificates,ssl,pki,crypto-policies 38private-etc alternatives,fonts,pulse,resolv.conf,ca-certificates,ssl,pki,crypto-policies
39private-opt Gitter 39private-opt Gitter
40private-dev 40private-dev
41private-tmp 41private-tmp
diff --git a/etc/gjs.profile b/etc/gjs.profile
index 9c7aa5700..f119e5b34 100644
--- a/etc/gjs.profile
+++ b/etc/gjs.profile
@@ -34,5 +34,5 @@ tracelog
34 34
35# private-bin gjs,gnome-books,gnome-documents,gnome-photos,gnome-maps,gnome-weather 35# private-bin gjs,gnome-books,gnome-documents,gnome-photos,gnome-maps,gnome-weather
36private-dev 36private-dev
37# private-etc fonts,ca-certificates,ssl,pki,crypto-policies 37# private-etc alternatives,fonts,ca-certificates,ssl,pki,crypto-policies
38private-tmp 38private-tmp
diff --git a/etc/gnome-books.profile b/etc/gnome-books.profile
index c748cf7e3..b880980bc 100644
--- a/etc/gnome-books.profile
+++ b/etc/gnome-books.profile
@@ -37,7 +37,7 @@ tracelog
37 37
38# private-bin gjs gnome-books 38# private-bin gjs gnome-books
39private-dev 39private-dev
40# private-etc fonts 40# private-etc alternatives,fonts
41private-tmp 41private-tmp
42 42
43noexec ${HOME} 43noexec ${HOME}
diff --git a/etc/gnome-chess.profile b/etc/gnome-chess.profile
index fbd8c22c0..42aa3ea2c 100644
--- a/etc/gnome-chess.profile
+++ b/etc/gnome-chess.profile
@@ -35,7 +35,7 @@ tracelog
35disable-mnt 35disable-mnt
36private-bin fairymax,gnome-chess,hoichess 36private-bin fairymax,gnome-chess,hoichess
37private-dev 37private-dev
38private-etc fonts,gnome-chess 38private-etc alternatives,fonts,gnome-chess
39private-tmp 39private-tmp
40 40
41noexec ${HOME} 41noexec ${HOME}
diff --git a/etc/gnome-clocks.profile b/etc/gnome-clocks.profile
index 54356a1b7..83ece0fce 100644
--- a/etc/gnome-clocks.profile
+++ b/etc/gnome-clocks.profile
@@ -34,7 +34,7 @@ tracelog
34disable-mnt 34disable-mnt
35# private-bin gnome-clocks 35# private-bin gnome-clocks
36private-dev 36private-dev
37# private-etc fonts,ca-certificates,ssl,pki,crypto-policies 37# private-etc alternatives,fonts,ca-certificates,ssl,pki,crypto-policies
38private-tmp 38private-tmp
39 39
40noexec ${HOME} 40noexec ${HOME}
diff --git a/etc/gnome-logs.profile b/etc/gnome-logs.profile
index f89684219..c429c7697 100644
--- a/etc/gnome-logs.profile
+++ b/etc/gnome-logs.profile
@@ -37,7 +37,7 @@ shell none
37disable-mnt 37disable-mnt
38private-bin gnome-logs 38private-bin gnome-logs
39private-dev 39private-dev
40private-etc fonts,localtime,machine-id 40private-etc alternatives,fonts,localtime,machine-id
41private-lib gdk-pixbuf-2.*,gio,gvfs/libgvfscommon.so,libgconf-2.so.*,librsvg-2.so.* 41private-lib gdk-pixbuf-2.*,gio,gvfs/libgvfscommon.so,libgconf-2.so.*,librsvg-2.so.*
42private-tmp 42private-tmp
43writable-var-log 43writable-var-log
diff --git a/etc/gnome-maps.profile b/etc/gnome-maps.profile
index 2d2f5aa6d..b963c17dd 100644
--- a/etc/gnome-maps.profile
+++ b/etc/gnome-maps.profile
@@ -38,7 +38,7 @@ tracelog
38disable-mnt 38disable-mnt
39# private-bin gjs gnome-maps 39# private-bin gjs gnome-maps
40private-dev 40private-dev
41# private-etc fonts,ca-certificates,ssl,pki,crypto-policies 41# private-etc alternatives,fonts,ca-certificates,ssl,pki,crypto-policies
42private-tmp 42private-tmp
43 43
44noexec ${HOME} 44noexec ${HOME}
diff --git a/etc/gnome-music.profile b/etc/gnome-music.profile
index 54e055358..c4dedcf1c 100644
--- a/etc/gnome-music.profile
+++ b/etc/gnome-music.profile
@@ -40,7 +40,7 @@ tracelog
40 40
41private-bin gnome-music,python*,env,gio-launch-desktop,yelp 41private-bin gnome-music,python*,env,gio-launch-desktop,yelp
42private-dev 42private-dev
43private-etc fonts,machine-id,pulse,asound.conf 43private-etc alternatives,fonts,machine-id,pulse,asound.conf
44private-tmp 44private-tmp
45 45
46noexec ${HOME} 46noexec ${HOME}
diff --git a/etc/gnome-photos.profile b/etc/gnome-photos.profile
index 2e3356607..c48ca50a5 100644
--- a/etc/gnome-photos.profile
+++ b/etc/gnome-photos.profile
@@ -34,7 +34,7 @@ tracelog
34 34
35# private-bin gjs gnome-photos 35# private-bin gjs gnome-photos
36private-dev 36private-dev
37# private-etc fonts 37# private-etc alternatives,fonts
38private-tmp 38private-tmp
39 39
40noexec ${HOME} 40noexec ${HOME}
diff --git a/etc/gnome-pie.profile b/etc/gnome-pie.profile
index cef741eb3..01c65a5a4 100644
--- a/etc/gnome-pie.profile
+++ b/etc/gnome-pie.profile
@@ -34,7 +34,7 @@ shell none
34disable-mnt 34disable-mnt
35private-cache 35private-cache
36private-dev 36private-dev
37private-etc fonts 37private-etc alternatives,fonts
38private-lib gdk-pixbuf-2.*,gio,gvfs/libgvfscommon.so,libgconf-2.so.*,librsvg-2.so.* 38private-lib gdk-pixbuf-2.*,gio,gvfs/libgvfscommon.so,libgconf-2.so.*,librsvg-2.so.*
39private-tmp 39private-tmp
40 40
diff --git a/etc/gnome-recipes.profile b/etc/gnome-recipes.profile
index 761c604ff..e516566d7 100644
--- a/etc/gnome-recipes.profile
+++ b/etc/gnome-recipes.profile
@@ -38,7 +38,7 @@ shell none
38disable-mnt 38disable-mnt
39private-bin gnome-recipes,tar 39private-bin gnome-recipes,tar
40private-dev 40private-dev
41private-etc ca-certificates,fonts,ssl,crypto-policies,pki 41private-etc alternatives,ca-certificates,fonts,ssl,crypto-policies,pki
42# private-lib works for me with Gnome Shell 3.26.2, Mutter WM (Arch Linux) 42# private-lib works for me with Gnome Shell 3.26.2, Mutter WM (Arch Linux)
43# not widely tested though, leaving it to devs discretion to enable it later 43# not widely tested though, leaving it to devs discretion to enable it later
44#private-lib gdk-pixbuf-2.0,gio,gvfs/libgvfscommon.so,libgconf-2.so.4,libgnutls.so.30,libjpeg.so.8,libp11-kit.so.0,libproxy.so.1,librsvg-2.so.2 44#private-lib gdk-pixbuf-2.0,gio,gvfs/libgvfscommon.so,libgconf-2.so.4,libgnutls.so.30,libjpeg.so.8,libp11-kit.so.0,libproxy.so.1,librsvg-2.so.2
diff --git a/etc/gnome-weather.profile b/etc/gnome-weather.profile
index 6b5f5480d..baa5d39fd 100644
--- a/etc/gnome-weather.profile
+++ b/etc/gnome-weather.profile
@@ -38,7 +38,7 @@ tracelog
38disable-mnt 38disable-mnt
39# private-bin gjs gnome-weather 39# private-bin gjs gnome-weather
40private-dev 40private-dev
41# private-etc fonts,ca-certificates,ssl,pki,crypto-policies 41# private-etc alternatives,fonts,ca-certificates,ssl,pki,crypto-policies
42private-tmp 42private-tmp
43 43
44noexec ${HOME} 44noexec ${HOME}
diff --git a/etc/goobox.profile b/etc/goobox.profile
index 3cc159eb2..be332665e 100644
--- a/etc/goobox.profile
+++ b/etc/goobox.profile
@@ -31,5 +31,5 @@ tracelog
31 31
32# private-bin goobox 32# private-bin goobox
33private-dev 33private-dev
34# private-etc fonts,machine-id,pulse,asound.conf,ca-certificates,ssl,pki,crypto-policies 34# private-etc alternatives,fonts,machine-id,pulse,asound.conf,ca-certificates,ssl,pki,crypto-policies
35# private-tmp 35# private-tmp
diff --git a/etc/gpicview.profile b/etc/gpicview.profile
index d3e1123f3..af9680b49 100644
--- a/etc/gpicview.profile
+++ b/etc/gpicview.profile
@@ -34,6 +34,6 @@ tracelog
34 34
35private-bin gpicview 35private-bin gpicview
36private-dev 36private-dev
37private-etc fonts 37private-etc alternatives,fonts
38private-lib 38private-lib
39private-tmp 39private-tmp
diff --git a/etc/gpredict.profile b/etc/gpredict.profile
index 76a10f697..38897f184 100644
--- a/etc/gpredict.profile
+++ b/etc/gpredict.profile
@@ -33,7 +33,7 @@ tracelog
33 33
34private-bin gpredict 34private-bin gpredict
35private-dev 35private-dev
36private-etc fonts,resolv.conf,ca-certificates,ssl,pki,crypto-policies 36private-etc alternatives,fonts,resolv.conf,ca-certificates,ssl,pki,crypto-policies
37private-tmp 37private-tmp
38 38
39noexec ${HOME} 39noexec ${HOME}
diff --git a/etc/gradio.profile b/etc/gradio.profile
index e7f415090..eec7376b4 100644
--- a/etc/gradio.profile
+++ b/etc/gradio.profile
@@ -34,7 +34,7 @@ protocol unix,inet,inet6
34seccomp 34seccomp
35shell none 35shell none
36 36
37private-etc asound.conf,ca-certificates,fonts,host.conf,hostname,hosts,pulse,resolv.conf,ssl,pki,crypto-policies,gtk-3.0,xdg,machine-id 37private-etc alternatives,asound.conf,ca-certificates,fonts,host.conf,hostname,hosts,pulse,resolv.conf,ssl,pki,crypto-policies,gtk-3.0,xdg,machine-id
38private-tmp 38private-tmp
39 39
40noexec ${HOME} 40noexec ${HOME}
diff --git a/etc/gwenview.profile b/etc/gwenview.profile
index e90578333..790e4920d 100644
--- a/etc/gwenview.profile
+++ b/etc/gwenview.profile
@@ -44,7 +44,7 @@ shell none
44 44
45private-bin gwenview,gimp*,kbuildsycoca4,kdeinit4 45private-bin gwenview,gimp*,kbuildsycoca4,kdeinit4
46private-dev 46private-dev
47private-etc fonts,gimp,gtk-2.0,kde4rc,kde5rc,ld.so.cache,machine-id,pulse,xdg 47private-etc alternatives,fonts,gimp,gtk-2.0,kde4rc,kde5rc,ld.so.cache,machine-id,pulse,xdg
48 48
49# memory-deny-write-execute 49# memory-deny-write-execute
50noexec ${HOME} 50noexec ${HOME}
diff --git a/etc/highlight.profile b/etc/highlight.profile
index ae2cce0b4..243643aea 100644
--- a/etc/highlight.profile
+++ b/etc/highlight.profile
@@ -34,5 +34,5 @@ tracelog
34private-bin highlight 34private-bin highlight
35private-cache 35private-cache
36private-dev 36private-dev
37# private-etc none 37# private-etc alternatives
38private-tmp 38private-tmp
diff --git a/etc/icecat.profile b/etc/icecat.profile
index 660343a29..0dae814c0 100644
--- a/etc/icecat.profile
+++ b/etc/icecat.profile
@@ -14,7 +14,7 @@ whitelist ${HOME}/.cache/mozilla/icecat
14whitelist ${HOME}/.mozilla 14whitelist ${HOME}/.mozilla
15 15
16# private-etc must first be enabled in firefox-common.profile 16# private-etc must first be enabled in firefox-common.profile
17#private-etc icecat 17#private-etc alternatives,icecat
18 18
19# Redirect 19# Redirect
20include firefox-common.profile 20include firefox-common.profile
diff --git a/etc/iceweasel.profile b/etc/iceweasel.profile
index 24a2f4cc3..4184b23a7 100644
--- a/etc/iceweasel.profile
+++ b/etc/iceweasel.profile
@@ -6,7 +6,7 @@ include iceweasel.local
6include globals.local 6include globals.local
7 7
8# private-etc must first be enabled in firefox-common.profile 8# private-etc must first be enabled in firefox-common.profile
9#private-etc iceweasel 9#private-etc alternatives,iceweasel
10 10
11# Redirect 11# Redirect
12include firefox.profile 12include firefox.profile
diff --git a/etc/img2txt.profile b/etc/img2txt.profile
index 6f860a3d4..2011759e3 100644
--- a/etc/img2txt.profile
+++ b/etc/img2txt.profile
@@ -34,5 +34,5 @@ tracelog
34# private-bin img2txt 34# private-bin img2txt
35private-cache 35private-cache
36private-dev 36private-dev
37# private-etc none 37# private-etc alternatives
38private-tmp 38private-tmp
diff --git a/etc/kate.profile b/etc/kate.profile
index cce36eacc..4a78d718f 100644
--- a/etc/kate.profile
+++ b/etc/kate.profile
@@ -42,7 +42,7 @@ tracelog
42 42
43# private-bin kate,kbuildsycoca4,kdeinit4 43# private-bin kate,kbuildsycoca4,kdeinit4
44private-dev 44private-dev
45# private-etc fonts,kde4rc,kde5rc,ld.so.cache,machine-id,xdg 45# private-etc alternatives,fonts,kde4rc,kde5rc,ld.so.cache,machine-id,xdg
46private-tmp 46private-tmp
47 47
48# noexec ${HOME} 48# noexec ${HOME}
diff --git a/etc/keepassx.profile b/etc/keepassx.profile
index fc9386618..357eb435d 100644
--- a/etc/keepassx.profile
+++ b/etc/keepassx.profile
@@ -41,7 +41,7 @@ tracelog
41 41
42private-bin keepassx,keepassx2 42private-bin keepassx,keepassx2
43private-dev 43private-dev
44private-etc fonts,machine-id 44private-etc alternatives,fonts,machine-id
45private-tmp 45private-tmp
46 46
47memory-deny-write-execute 47memory-deny-write-execute
diff --git a/etc/keepassxc.profile b/etc/keepassxc.profile
index 448f5455f..d565373f4 100644
--- a/etc/keepassxc.profile
+++ b/etc/keepassxc.profile
@@ -42,7 +42,7 @@ shell none
42 42
43private-bin keepassxc 43private-bin keepassxc
44private-dev 44private-dev
45private-etc fonts,ld.so.cache,machine-id 45private-etc alternatives,fonts,ld.so.cache,machine-id
46private-tmp 46private-tmp
47 47
48# 2.2.4 crashes on database open 48# 2.2.4 crashes on database open
diff --git a/etc/klavaro.profile b/etc/klavaro.profile
index 890cde3db..04b4a5ae5 100644
--- a/etc/klavaro.profile
+++ b/etc/klavaro.profile
@@ -45,7 +45,7 @@ disable-mnt
45private-bin klavaro,tclsh,tclsh*,bash 45private-bin klavaro,tclsh,tclsh*,bash
46private-cache 46private-cache
47private-dev 47private-dev
48private-etc fonts 48private-etc alternatives,fonts
49private-tmp 49private-tmp
50private-opt none 50private-opt none
51private-srv none 51private-srv none
diff --git a/etc/kwin_x11.profile b/etc/kwin_x11.profile
index 653283150..834f6f2dd 100644
--- a/etc/kwin_x11.profile
+++ b/etc/kwin_x11.profile
@@ -37,7 +37,7 @@ tracelog
37disable-mnt 37disable-mnt
38private-bin kwin_x11 38private-bin kwin_x11
39private-dev 39private-dev
40private-etc drirc,fonts,kde5rc,ld.so.cache,machine-id,xdg 40private-etc alternatives,drirc,fonts,kde5rc,ld.so.cache,machine-id,xdg
41private-tmp 41private-tmp
42 42
43noexec ${HOME} 43noexec ${HOME}
diff --git a/etc/kwrite.profile b/etc/kwrite.profile
index 9922cb0b5..bc4fba97d 100644
--- a/etc/kwrite.profile
+++ b/etc/kwrite.profile
@@ -44,7 +44,7 @@ tracelog
44 44
45private-bin kwrite,kbuildsycoca4,kdeinit4 45private-bin kwrite,kbuildsycoca4,kdeinit4
46private-dev 46private-dev
47private-etc fonts,kde4rc,kde5rc,ld.so.cache,machine-id,pulse,xdg 47private-etc alternatives,fonts,kde4rc,kde5rc,ld.so.cache,machine-id,pulse,xdg
48private-tmp 48private-tmp
49 49
50noexec ${HOME} 50noexec ${HOME}
diff --git a/etc/lollypop.profile b/etc/lollypop.profile
index 6e53fc62b..047424e5e 100644
--- a/etc/lollypop.profile
+++ b/etc/lollypop.profile
@@ -38,7 +38,7 @@ seccomp
38shell none 38shell none
39 39
40private-dev 40private-dev
41private-etc asound.conf,ca-certificates,fonts,host.conf,hostname,hosts,pulse,resolv.conf,ssl,pki,crypto-policies,gtk-3.0,xdg,machine-id 41private-etc alternatives,asound.conf,ca-certificates,fonts,host.conf,hostname,hosts,pulse,resolv.conf,ssl,pki,crypto-policies,gtk-3.0,xdg,machine-id
42private-tmp 42private-tmp
43 43
44noexec ${HOME} 44noexec ${HOME}
diff --git a/etc/lynx.profile b/etc/lynx.profile
index e8d44823b..2f043c9b9 100644
--- a/etc/lynx.profile
+++ b/etc/lynx.profile
@@ -34,5 +34,5 @@ tracelog
34# private-bin lynx 34# private-bin lynx
35private-cache 35private-cache
36private-dev 36private-dev
37# private-etc ca-certificates,ssl,pki,crypto-policies 37# private-etc alternatives,ca-certificates,ssl,pki,crypto-policies
38private-tmp 38private-tmp
diff --git a/etc/masterpdfeditor.profile b/etc/masterpdfeditor.profile
index e35ddd2a7..56433df41 100644
--- a/etc/masterpdfeditor.profile
+++ b/etc/masterpdfeditor.profile
@@ -41,7 +41,7 @@ tracelog
41private-bin masterpdfeditor* 41private-bin masterpdfeditor*
42private-cache 42private-cache
43private-dev 43private-dev
44private-etc fonts 44private-etc alternatives,fonts
45# private-lib 45# private-lib
46private-tmp 46private-tmp
47 47
diff --git a/etc/mate-calc.profile b/etc/mate-calc.profile
index e3220076d..1d3c21e3f 100644
--- a/etc/mate-calc.profile
+++ b/etc/mate-calc.profile
@@ -39,7 +39,7 @@ shell none
39 39
40disable-mnt 40disable-mnt
41private-bin mate-calc,mate-calculator 41private-bin mate-calc,mate-calculator
42private-etc fonts 42private-etc alternatives,fonts
43private-dev 43private-dev
44private-opt none 44private-opt none
45private-tmp 45private-tmp
diff --git a/etc/mate-color-select.profile b/etc/mate-color-select.profile
index 1ba744d5a..a344f70e1 100644
--- a/etc/mate-color-select.profile
+++ b/etc/mate-color-select.profile
@@ -34,7 +34,7 @@ shell none
34 34
35disable-mnt 35disable-mnt
36private-bin mate-color-select 36private-bin mate-color-select
37private-etc fonts 37private-etc alternatives,fonts
38private-dev 38private-dev
39private-lib 39private-lib
40private-tmp 40private-tmp
diff --git a/etc/mate-dictionary.profile b/etc/mate-dictionary.profile
index ba179dfdd..196f5b2c3 100644
--- a/etc/mate-dictionary.profile
+++ b/etc/mate-dictionary.profile
@@ -36,7 +36,7 @@ shell none
36 36
37disable-mnt 37disable-mnt
38private-bin mate-dictionary 38private-bin mate-dictionary
39private-etc fonts,resolv.conf,ca-certificates,ssl,pki,crypto-policies 39private-etc alternatives,fonts,resolv.conf,ca-certificates,ssl,pki,crypto-policies
40private-opt mate-dictionary 40private-opt mate-dictionary
41private-dev 41private-dev
42private-tmp 42private-tmp
diff --git a/etc/mcabber.profile b/etc/mcabber.profile
index ea4cb0250..c65a25edc 100644
--- a/etc/mcabber.profile
+++ b/etc/mcabber.profile
@@ -30,4 +30,4 @@ shell none
30 30
31private-bin mcabber 31private-bin mcabber
32private-dev 32private-dev
33private-etc ca-certificates,ssl,pki,crypto-policies 33private-etc alternatives,ca-certificates,ssl,pki,crypto-policies
diff --git a/etc/mediainfo.profile b/etc/mediainfo.profile
index 115444e0f..32a269fd3 100644
--- a/etc/mediainfo.profile
+++ b/etc/mediainfo.profile
@@ -34,5 +34,5 @@ tracelog
34private-bin mediainfo 34private-bin mediainfo
35private-cache 35private-cache
36private-dev 36private-dev
37private-etc none 37private-etc alternatives
38private-tmp 38private-tmp
diff --git a/etc/min.profile b/etc/min.profile
index 80baedff7..6101ac2e6 100644
--- a/etc/min.profile
+++ b/etc/min.profile
@@ -46,7 +46,7 @@ disable-mnt
46private-cache 46private-cache
47private-dev 47private-dev
48# private-etc below works fine on most distributions. There are some problems on CentOS. 48# private-etc below works fine on most distributions. There are some problems on CentOS.
49private-etc ca-certificates,ssl,machine-id,dconf,selinux,passwd,group,hostname,hosts,localtime,nsswitch.conf,resolv.conf,xdg,gtk-2.0,gtk-3.0,X11,pango,fonts,mime.types,mailcap,asound.conf,pulse,pki,crypto-policies,ld.so.cache 49private-etc alternatives,ca-certificates,ssl,machine-id,dconf,selinux,passwd,group,hostname,hosts,localtime,nsswitch.conf,resolv.conf,xdg,gtk-2.0,gtk-3.0,X11,pango,fonts,mime.types,mailcap,asound.conf,pulse,pki,crypto-policies,ld.so.cache
50private-tmp 50private-tmp
51 51
52# memory-deny-write-execute 52# memory-deny-write-execute
diff --git a/etc/minetest.profile b/etc/minetest.profile
index 17b39f7c6..aa50847ea 100644
--- a/etc/minetest.profile
+++ b/etc/minetest.profile
@@ -38,7 +38,7 @@ disable-mnt
38private-bin minetest 38private-bin minetest
39private-dev 39private-dev
40# private-etc needs to be updated, see #1702 40# private-etc needs to be updated, see #1702
41#private-etc asound.conf,ca-certificates,drirc,fonts,group,host.conf,hostname,hosts,ld.so.cache,ld.so.preload,localtime,nsswitch.conf,passwd,pulse,resolv.conf,ssl,pki,crypto-policies,machine-id 41#private-etc alternatives,asound.conf,ca-certificates,drirc,fonts,group,host.conf,hostname,hosts,ld.so.cache,ld.so.preload,localtime,nsswitch.conf,passwd,pulse,resolv.conf,ssl,pki,crypto-policies,machine-id
42private-tmp 42private-tmp
43 43
44noexec ${HOME} 44noexec ${HOME}
diff --git a/etc/ms-office.profile b/etc/ms-office.profile
index 6c8cb213f..6334ecd41 100644
--- a/etc/ms-office.profile
+++ b/etc/ms-office.profile
@@ -37,7 +37,7 @@ tracelog
37 37
38disable-mnt 38disable-mnt
39private-bin bash,fonts,env,jak,ms-office,python*,sh 39private-bin bash,fonts,env,jak,ms-office,python*,sh
40private-etc resolv.conf,ca-certificates,ssl,pki,crypto-policies 40private-etc alternatives,resolv.conf,ca-certificates,ssl,pki,crypto-policies
41private-dev 41private-dev
42private-tmp 42private-tmp
43 43
diff --git a/etc/mupdf.profile b/etc/mupdf.profile
index 011e85c0e..59ad36305 100644
--- a/etc/mupdf.profile
+++ b/etc/mupdf.profile
@@ -37,7 +37,7 @@ tracelog
37 37
38# private-bin mupdf,sh,tempfile,rm 38# private-bin mupdf,sh,tempfile,rm
39private-dev 39private-dev
40private-etc fonts 40private-etc alternatives,fonts
41private-tmp 41private-tmp
42 42
43# mupdf will never write anything 43# mupdf will never write anything
diff --git a/etc/musixmatch.profile b/etc/musixmatch.profile
index d5fde525e..54d9fb16e 100644
--- a/etc/musixmatch.profile
+++ b/etc/musixmatch.profile
@@ -21,7 +21,7 @@ nodvd
21nogroups 21nogroups
22nonewprivs 22nonewprivs
23noroot 23noroot
24nogroups 24nogroups
25nosound 25nosound
26notv 26notv
27nou2f 27nou2f
@@ -31,7 +31,7 @@ seccomp
31 31
32disable-mnt 32disable-mnt
33private-dev 33private-dev
34private-etc machine-id,pulse,asound.conf,ca-certificates,ssl,pki,crypto-policies 34private-etc alternatives,machine-id,pulse,asound.conf,ca-certificates,ssl,pki,crypto-policies
35 35
36noexec ${HOME} 36noexec ${HOME}
37noexec /tmp 37noexec /tmp
diff --git a/etc/mypaint.profile b/etc/mypaint.profile
index acec61816..21fd841cf 100644
--- a/etc/mypaint.profile
+++ b/etc/mypaint.profile
@@ -41,7 +41,7 @@ tracelog
41 41
42private-cache 42private-cache
43private-dev 43private-dev
44private-etc fonts,gtk-3.0,dconf 44private-etc alternatives,fonts,gtk-3.0,dconf
45private-tmp 45private-tmp
46 46
47noexec ${HOME} 47noexec ${HOME}
diff --git a/etc/nautilus.profile b/etc/nautilus.profile
index 13fe9a9e1..b5e65e3ee 100644
--- a/etc/nautilus.profile
+++ b/etc/nautilus.profile
@@ -42,5 +42,5 @@ tracelog
42# nautilus needs to be able to start arbitrary applications so we cannot blacklist their files 42# nautilus needs to be able to start arbitrary applications so we cannot blacklist their files
43# private-bin nautilus 43# private-bin nautilus
44# private-dev 44# private-dev
45# private-etc fonts 45# private-etc alternatives,fonts
46# private-tmp 46# private-tmp
diff --git a/etc/nitroshare.profile b/etc/nitroshare.profile
index 67c651429..bf8fff7cd 100644
--- a/etc/nitroshare.profile
+++ b/etc/nitroshare.profile
@@ -41,7 +41,7 @@ disable-mnt
41private-bin awk,grep,nitroshare,nitroshare-cli,nitroshare-nmh,nitroshare-send,nitroshare-ui 41private-bin awk,grep,nitroshare,nitroshare-cli,nitroshare-nmh,nitroshare-send,nitroshare-ui
42private-cache 42private-cache
43private-dev 43private-dev
44private-etc ca-certificates,dconf,fonts,hostname,hosts,ld.so.cache,machine-id,nsswitch.conf,ssl 44private-etc alternatives,ca-certificates,dconf,fonts,hostname,hosts,ld.so.cache,machine-id,nsswitch.conf,ssl
45# private-lib libnitroshare.so.*,libqhttpengine.so.*,libqmdnsengine.so.*,nitroshare 45# private-lib libnitroshare.so.*,libqhttpengine.so.*,libqmdnsengine.so.*,nitroshare
46private-tmp 46private-tmp
47 47
diff --git a/etc/nyx.profile b/etc/nyx.profile
index 8d41032dd..2a078ef0f 100644
--- a/etc/nyx.profile
+++ b/etc/nyx.profile
@@ -42,7 +42,7 @@ disable-mnt
42private-bin nyx,python* 42private-bin nyx,python*
43private-cache 43private-cache
44private-dev 44private-dev
45private-etc passwd,tor,fonts 45private-etc alternatives,passwd,tor,fonts
46private-opt none 46private-opt none
47private-srv none 47private-srv none
48private-tmp 48private-tmp
diff --git a/etc/ocenaudio.profile b/etc/ocenaudio.profile
index 10f3f68a6..4a4fa828d 100644
--- a/etc/ocenaudio.profile
+++ b/etc/ocenaudio.profile
@@ -43,7 +43,7 @@ tracelog
43private-bin ocenaudio 43private-bin ocenaudio
44private-cache 44private-cache
45private-dev 45private-dev
46private-etc asound.conf,fonts,ld.so.cache,pulse 46private-etc alternatives,asound.conf,fonts,ld.so.cache,pulse
47# private-lib 47# private-lib
48private-tmp 48private-tmp
49 49
diff --git a/etc/odt2txt.profile b/etc/odt2txt.profile
index 3a1369b83..3e1739bf9 100644
--- a/etc/odt2txt.profile
+++ b/etc/odt2txt.profile
@@ -37,6 +37,6 @@ tracelog
37private-bin odt2txt 37private-bin odt2txt
38private-cache 38private-cache
39private-dev 39private-dev
40private-etc none 40private-etc alternatives
41private-tmp 41private-tmp
42read-only ${HOME} 42read-only ${HOME}
diff --git a/etc/open-invaders.profile b/etc/open-invaders.profile
index 108398104..bff42fb19 100644
--- a/etc/open-invaders.profile
+++ b/etc/open-invaders.profile
@@ -33,5 +33,5 @@ shell none
33 33
34# private-bin open-invaders 34# private-bin open-invaders
35private-dev 35private-dev
36# private-etc none 36# private-etc alternatives
37private-tmp 37private-tmp
diff --git a/etc/palemoon.profile b/etc/palemoon.profile
index 11464e6cf..e867006e5 100644
--- a/etc/palemoon.profile
+++ b/etc/palemoon.profile
@@ -19,7 +19,7 @@ seccomp
19 19
20#private-bin palemoon 20#private-bin palemoon
21# private-etc must first be enabled in firefox-common.profile 21# private-etc must first be enabled in firefox-common.profile
22#private-etc palemoon 22#private-etc alternatives,palemoon
23#private-opt palemoon 23#private-opt palemoon
24 24
25# Redirect 25# Redirect
diff --git a/etc/parole.profile b/etc/parole.profile
index 9ad59d2e6..69ed5a2ca 100644
--- a/etc/parole.profile
+++ b/etc/parole.profile
@@ -27,4 +27,4 @@ shell none
27 27
28private-bin parole,dbus-launch 28private-bin parole,dbus-launch
29private-cache 29private-cache
30private-etc passwd,group,fonts,machine-id,pulse,asound.conf,ca-certificates,ssl,pki,crypto-policies 30private-etc alternatives,passwd,group,fonts,machine-id,pulse,asound.conf,ca-certificates,ssl,pki,crypto-policies
diff --git a/etc/pdfchain.profile b/etc/pdfchain.profile
index f0db20b74..d9f721578 100644
--- a/etc/pdfchain.profile
+++ b/etc/pdfchain.profile
@@ -34,7 +34,7 @@ shell none
34 34
35private-bin pdfchain,pdftk,sh 35private-bin pdfchain,pdftk,sh
36private-dev 36private-dev
37private-etc dconf,fonts,gtk-3.0,xdg 37private-etc alternatives,dconf,fonts,gtk-3.0,xdg
38private-tmp 38private-tmp
39 39
40memory-deny-write-execute 40memory-deny-write-execute
diff --git a/etc/pdftotext.profile b/etc/pdftotext.profile
index 6b2b0fba5..85e28372e 100644
--- a/etc/pdftotext.profile
+++ b/etc/pdftotext.profile
@@ -38,5 +38,5 @@ tracelog
38 38
39private-bin pdftotext 39private-bin pdftotext
40private-dev 40private-dev
41private-etc none 41private-etc alternatives
42private-tmp 42private-tmp
diff --git a/etc/ping.profile b/etc/ping.profile
index bdd29c1a1..373b8a918 100644
--- a/etc/ping.profile
+++ b/etc/ping.profile
@@ -41,7 +41,7 @@ private
41#private-bin has mammoth problems with execvp: "No such file or directory" 41#private-bin has mammoth problems with execvp: "No such file or directory"
42private-dev 42private-dev
43# /etc/hosts is required in private-etc; however, just adding it to the list doesn't solve the problem! 43# /etc/hosts is required in private-etc; however, just adding it to the list doesn't solve the problem!
44#private-etc resolv.conf,hosts,ca-certificates,ssl,pki,crypto-policies 44#private-etc alternatives,resolv.conf,hosts,ca-certificates,ssl,pki,crypto-policies
45private-tmp 45private-tmp
46 46
47# memory-deny-write-execute is built using seccomp; nonewprivs will kill it 47# memory-deny-write-execute is built using seccomp; nonewprivs will kill it
diff --git a/etc/pingus.profile b/etc/pingus.profile
index f071e664f..6b664248f 100644
--- a/etc/pingus.profile
+++ b/etc/pingus.profile
@@ -33,5 +33,5 @@ shell none
33 33
34# private-bin pingus 34# private-bin pingus
35private-dev 35private-dev
36# private-etc none 36# private-etc alternatives
37private-tmp 37private-tmp
diff --git a/etc/pluma.profile b/etc/pluma.profile
index 35b141c1a..79e4b89b3 100644
--- a/etc/pluma.profile
+++ b/etc/pluma.profile
@@ -37,7 +37,7 @@ tracelog
37 37
38private-bin pluma 38private-bin pluma
39private-dev 39private-dev
40# private-etc fonts 40# private-etc alternatives,fonts
41private-lib pluma 41private-lib pluma
42private-tmp 42private-tmp
43 43
diff --git a/etc/ppsspp.profile b/etc/ppsspp.profile
index fc37e6fd2..0c8bfa770 100644
--- a/etc/ppsspp.profile
+++ b/etc/ppsspp.profile
@@ -37,7 +37,7 @@ shell none
37 37
38# private-dev is disabled to allow controller support 38# private-dev is disabled to allow controller support
39#private-dev 39#private-dev
40private-etc asound.conf,ca-certificates,drirc,fonts,group,host.conf,hostname,hosts,ld.so.cache,ld.so.preload,localtime,nsswitch.conf,passwd,pulse,resolv.conf,ssl,pki,crypto-policies,machine-id 40private-etc alternatives,asound.conf,ca-certificates,drirc,fonts,group,host.conf,hostname,hosts,ld.so.cache,ld.so.preload,localtime,nsswitch.conf,passwd,pulse,resolv.conf,ssl,pki,crypto-policies,machine-id
41private-opt ppsspp 41private-opt ppsspp
42private-tmp 42private-tmp
43 43
diff --git a/etc/pybitmessage.profile b/etc/pybitmessage.profile
index c98f34e77..92cae0f97 100644
--- a/etc/pybitmessage.profile
+++ b/etc/pybitmessage.profile
@@ -42,7 +42,7 @@ shell none
42disable-mnt 42disable-mnt
43private-bin pybitmessage,python*,sh,ldconfig,env,bash,stat 43private-bin pybitmessage,python*,sh,ldconfig,env,bash,stat
44private-dev 44private-dev
45private-etc PyBitmessage,PyBitmessage.conf,Trolltech.conf,fonts,gtk-2.0,hosts,ld.so.cache,ld.so.preload,localtime,pki,resolv.conf,selinux,sni-qt.conf,system-fips,xdg,ca-certificates,ssl,pki,crypto-policies 45private-etc alternatives,PyBitmessage,PyBitmessage.conf,Trolltech.conf,fonts,gtk-2.0,hosts,ld.so.cache,ld.so.preload,localtime,pki,resolv.conf,selinux,sni-qt.conf,system-fips,xdg,ca-certificates,ssl,pki,crypto-policies
46private-tmp 46private-tmp
47 47
48noexec ${HOME} 48noexec ${HOME}
diff --git a/etc/pycharm-community.profile b/etc/pycharm-community.profile
index bb948a971..bfe8b614e 100644
--- a/etc/pycharm-community.profile
+++ b/etc/pycharm-community.profile
@@ -32,7 +32,7 @@ novideo
32shell none 32shell none
33tracelog 33tracelog
34 34
35# private-etc fonts,passwd - minimal required to run but will probably break 35# private-etc alternatives,fonts,passwd - minimal required to run but will probably break
36# program! 36# program!
37private-cache 37private-cache
38private-dev 38private-dev
diff --git a/etc/qbittorrent.profile b/etc/qbittorrent.profile
index b6b94c703..0420d38e9 100644
--- a/etc/qbittorrent.profile
+++ b/etc/qbittorrent.profile
@@ -53,7 +53,7 @@ shell none
53 53
54private-bin qbittorrent,python* 54private-bin qbittorrent,python*
55private-dev 55private-dev
56# private-etc X11,fonts,xdg,resolv.conf,ca-certificates,ssl,pki,crypto-policies 56# private-etc alternatives,X11,fonts,xdg,resolv.conf,ca-certificates,ssl,pki,crypto-policies
57# private-lib - problems on Arch 57# private-lib - problems on Arch
58private-tmp 58private-tmp
59 59
diff --git a/etc/qtox.profile b/etc/qtox.profile
index b6cb9772a..3dc4c6a30 100644
--- a/etc/qtox.profile
+++ b/etc/qtox.profile
@@ -36,7 +36,7 @@ tracelog
36 36
37disable-mnt 37disable-mnt
38private-bin qtox 38private-bin qtox
39private-etc fonts,resolv.conf,ld.so.cache,localtime,ca-certificates,ssl,pki,crypto-policies,machine-id,pulse 39private-etc alternatives,fonts,resolv.conf,ld.so.cache,localtime,ca-certificates,ssl,pki,crypto-policies,machine-id,pulse
40private-dev 40private-dev
41private-tmp 41private-tmp
42 42
diff --git a/etc/quiterss.profile b/etc/quiterss.profile
index ce0816114..e6c441e27 100644
--- a/etc/quiterss.profile
+++ b/etc/quiterss.profile
@@ -47,7 +47,7 @@ tracelog
47disable-mnt 47disable-mnt
48private-bin quiterss 48private-bin quiterss
49private-dev 49private-dev
50# private-etc X11,ssl,pki,ca-certificates,crypto-policies 50# private-etc alternatives,X11,ssl,pki,ca-certificates,crypto-policies
51 51
52noexec ${HOME} 52noexec ${HOME}
53noexec /tmp 53noexec /tmp
diff --git a/etc/qupzilla.profile b/etc/qupzilla.profile
index efee6ce84..eef0c8fa6 100644
--- a/etc/qupzilla.profile
+++ b/etc/qupzilla.profile
@@ -34,7 +34,7 @@ seccomp.drop @clock,@cpu-emulation,@debug,@module,@obsolete,@raw-io,@reboot,@res
34# tracelog 34# tracelog
35 35
36private-dev 36private-dev
37# private-etc passwd,group,hostname,hosts,localtime,nsswitch.conf,resolv.conf,gtk-2.0,pango,fonts,adobe,mime.types,mailcap,asound.conf,pulse,machine-id,ca-certificates,ssl,pki,crypto-policies 37# private-etc alternatives,passwd,group,hostname,hosts,localtime,nsswitch.conf,resolv.conf,gtk-2.0,pango,fonts,adobe,mime.types,mailcap,asound.conf,pulse,machine-id,ca-certificates,ssl,pki,crypto-policies
38# private-tmp - interferes with the opening of downloaded files 38# private-tmp - interferes with the opening of downloaded files
39 39
40noexec ${HOME} 40noexec ${HOME}
diff --git a/etc/ricochet.profile b/etc/ricochet.profile
index cbdc28cf6..a67d6b7ca 100644
--- a/etc/ricochet.profile
+++ b/etc/ricochet.profile
@@ -36,7 +36,7 @@ shell none
36disable-mnt 36disable-mnt
37private-bin ricochet,tor 37private-bin ricochet,tor
38private-dev 38private-dev
39#private-etc fonts,tor,X11,alternatives,ca-certificates,ssl,pki,crypto-policies 39#private-etc alternatives,fonts,tor,X11,alternatives,ca-certificates,ssl,pki,crypto-policies
40 40
41noexec ${HOME} 41noexec ${HOME}
42noexec /tmp 42noexec /tmp
diff --git a/etc/seamonkey.profile b/etc/seamonkey.profile
index 8cb291ba6..d92c62a52 100644
--- a/etc/seamonkey.profile
+++ b/etc/seamonkey.profile
@@ -50,4 +50,4 @@ seccomp
50tracelog 50tracelog
51 51
52disable-mnt 52disable-mnt
53# private-etc passwd,group,hostname,hosts,localtime,nsswitch.conf,resolv.conf,gtk-2.0,pango,fonts,iceweasel,firefox,adobe,mime.types,mailcap,asound.conf,pulse,machine-id,ca-certificates,ssl,pki,crypto-policies 53# private-etc alternatives,passwd,group,hostname,hosts,localtime,nsswitch.conf,resolv.conf,gtk-2.0,pango,fonts,iceweasel,firefox,adobe,mime.types,mailcap,asound.conf,pulse,machine-id,ca-certificates,ssl,pki,crypto-policies
diff --git a/etc/server.profile b/etc/server.profile
index 3526e88ab..8da4853e7 100644
--- a/etc/server.profile
+++ b/etc/server.profile
@@ -43,7 +43,7 @@ private
43# private-bin program 43# private-bin program
44# private-cache 44# private-cache
45private-dev 45private-dev
46# private-etc none 46# private-etc alternatives
47# private-lib 47# private-lib
48private-tmp 48private-tmp
49 49
diff --git a/etc/simple-scan.profile b/etc/simple-scan.profile
index 85cb00ef1..4ad841880 100644
--- a/etc/simple-scan.profile
+++ b/etc/simple-scan.profile
@@ -33,5 +33,5 @@ tracelog
33 33
34# private-bin simple-scan 34# private-bin simple-scan
35# private-dev 35# private-dev
36# private-etc fonts,ca-certificates,ssl,pki,crypto-policies 36# private-etc alternatives,fonts,ca-certificates,ssl,pki,crypto-policies
37# private-tmp 37# private-tmp
diff --git a/etc/simutrans.profile b/etc/simutrans.profile
index a4e4d892c..c07b1c145 100644
--- a/etc/simutrans.profile
+++ b/etc/simutrans.profile
@@ -33,5 +33,5 @@ shell none
33 33
34# private-bin simutrans 34# private-bin simutrans
35private-dev 35private-dev
36# private-etc none 36# private-etc alternatives
37private-tmp 37private-tmp
diff --git a/etc/slack.profile b/etc/slack.profile
index 995d49687..841998b0e 100644
--- a/etc/slack.profile
+++ b/etc/slack.profile
@@ -37,5 +37,5 @@ shell none
37disable-mnt 37disable-mnt
38private-bin slack,locale 38private-bin slack,locale
39private-dev 39private-dev
40private-etc asound.conf,ca-certificates,fonts,group,passwd,pulse,resolv.conf,ssl,ld.so.conf,ld.so.cache,localtime,pki,crypto-policies,machine-id 40private-etc alternatives,asound.conf,ca-certificates,fonts,group,passwd,pulse,resolv.conf,ssl,ld.so.conf,ld.so.cache,localtime,pki,crypto-policies,machine-id
41private-tmp 41private-tmp
diff --git a/etc/spotify.profile b/etc/spotify.profile
index 14f9f5228..60d15735d 100644
--- a/etc/spotify.profile
+++ b/etc/spotify.profile
@@ -46,7 +46,7 @@ tracelog
46disable-mnt 46disable-mnt
47private-bin spotify,bash,sh,zenity 47private-bin spotify,bash,sh,zenity
48private-dev 48private-dev
49private-etc fonts,group,ld.so.cache,machine-id,pulse,resolv.conf,hosts,nsswitch.conf,host.conf,ca-certificates,ssl,pki,crypto-policies 49private-etc alternatives,fonts,group,ld.so.cache,machine-id,pulse,resolv.conf,hosts,nsswitch.conf,host.conf,ca-certificates,ssl,pki,crypto-policies
50private-opt spotify 50private-opt spotify
51private-tmp 51private-tmp
52 52
diff --git a/etc/standardnotes-desktop.profile b/etc/standardnotes-desktop.profile
index 4486c8869..0a4d38dbe 100644
--- a/etc/standardnotes-desktop.profile
+++ b/etc/standardnotes-desktop.profile
@@ -38,7 +38,7 @@ seccomp
38disable-mnt 38disable-mnt
39private-dev 39private-dev
40private-tmp 40private-tmp
41private-etc ca-certificates,fonts,host.conf,hostname,hosts,resolv.conf,ssl,pki,crypto-policies,xdg 41private-etc alternatives,ca-certificates,fonts,host.conf,hostname,hosts,resolv.conf,ssl,pki,crypto-policies,xdg
42 42
43noexec ${HOME} 43noexec ${HOME}
44noexec /tmp 44noexec /tmp
diff --git a/etc/start-tor-browser.profile b/etc/start-tor-browser.profile
index d3b0b27e3..b0cb52a0f 100644
--- a/etc/start-tor-browser.profile
+++ b/etc/start-tor-browser.profile
@@ -34,7 +34,7 @@ shell none
34disable-mnt 34disable-mnt
35private-bin bash,sh,grep,tail,env,gpg,id,readlink,dirname,test,mkdir,ln,sed,cp,rm,getconf 35private-bin bash,sh,grep,tail,env,gpg,id,readlink,dirname,test,mkdir,ln,sed,cp,rm,getconf
36private-dev 36private-dev
37private-etc fonts,hostname,hosts,resolv.conf,pki,ssl,ca-certificates,crypto-policies,alsa,asound.conf,pulse,machine-id,ld.so.cache 37private-etc alternatives,fonts,hostname,hosts,resolv.conf,pki,ssl,ca-certificates,crypto-policies,alsa,asound.conf,pulse,machine-id,ld.so.cache
38private-tmp 38private-tmp
39 39
40noexec /tmp 40noexec /tmp
diff --git a/etc/steam.profile b/etc/steam.profile
index 775b6c875..9d348347e 100644
--- a/etc/steam.profile
+++ b/etc/steam.profile
@@ -74,5 +74,5 @@ shell none
74# private-dev should be commented for controllers 74# private-dev should be commented for controllers
75private-dev 75private-dev
76# private-etc breaks a small selection of games on some systems, comment to support those 76# private-etc breaks a small selection of games on some systems, comment to support those
77private-etc asound.conf,ca-certificates,dbus-1,drirc,fonts,group,gtk-2.0,gtk-3.0,host.conf,hostname,hosts,ld.so.cache,ld.so.preload,ld.so.conf,ld.so.conf.d,localtime,lsb-release,machine-id,mime.types,passwd,pulse,resolv.conf,ssl,pki,services,crypto-policies,alternatives,bumblebee,nvidia,os-release 77private-etc alternatives,asound.conf,ca-certificates,dbus-1,drirc,fonts,group,gtk-2.0,gtk-3.0,host.conf,hostname,hosts,ld.so.cache,ld.so.preload,ld.so.conf,ld.so.conf.d,localtime,lsb-release,machine-id,mime.types,passwd,pulse,resolv.conf,ssl,pki,services,crypto-policies,alternatives,bumblebee,nvidia,os-release
78private-tmp 78private-tmp
diff --git a/etc/strings.profile b/etc/strings.profile
index f243606ec..3ef3ffcb1 100644
--- a/etc/strings.profile
+++ b/etc/strings.profile
@@ -24,7 +24,7 @@ tracelog
24private-bin strings 24private-bin strings
25private-cache 25private-cache
26private-dev 26private-dev
27private-etc none 27private-etc alternatives
28private-lib 28private-lib
29 29
30memory-deny-write-execute 30memory-deny-write-execute
diff --git a/etc/supertux2.profile b/etc/supertux2.profile
index fc523ce0a..793e4126c 100644
--- a/etc/supertux2.profile
+++ b/etc/supertux2.profile
@@ -34,5 +34,5 @@ shell none
34disable-mnt 34disable-mnt
35# private-bin supertux2 35# private-bin supertux2
36private-dev 36private-dev
37# private-etc none 37# private-etc alternatives
38private-tmp 38private-tmp
diff --git a/etc/supertuxkart.profile b/etc/supertuxkart.profile
index 9f65a2fa1..696ac4de0 100644
--- a/etc/supertuxkart.profile
+++ b/etc/supertuxkart.profile
@@ -46,7 +46,7 @@ disable-mnt
46private-bin supertuxkart 46private-bin supertuxkart
47private-cache 47private-cache
48private-dev 48private-dev
49private-etc resolv.conf,ca-certificates,ssl,hosts,machine-id,xdg,openal,crypto-policies,pki,drirc,system-fips,selinux 49private-etc alternatives,resolv.conf,ca-certificates,ssl,hosts,machine-id,xdg,openal,crypto-policies,pki,drirc,system-fips,selinux
50private-tmp 50private-tmp
51private-opt none 51private-opt none
52private-srv none 52private-srv none
diff --git a/etc/surf.profile b/etc/surf.profile
index 3a1b1f383..4fad4a81d 100644
--- a/etc/surf.profile
+++ b/etc/surf.profile
@@ -32,7 +32,7 @@ tracelog
32disable-mnt 32disable-mnt
33private-bin ls,surf,sh,bash,curl,dmenu,printf,sed,sleep,st,stterm,xargs,xprop 33private-bin ls,surf,sh,bash,curl,dmenu,printf,sed,sleep,st,stterm,xargs,xprop
34private-dev 34private-dev
35private-etc passwd,group,hosts,resolv.conf,fonts,ssl,pki,ca-certificates,crypto-policies 35private-etc alternatives,passwd,group,hosts,resolv.conf,fonts,ssl,pki,ca-certificates,crypto-policies
36private-tmp 36private-tmp
37 37
38noexec ${HOME} 38noexec ${HOME}
diff --git a/etc/tar.profile b/etc/tar.profile
index 9a5f00f65..d228051e8 100644
--- a/etc/tar.profile
+++ b/etc/tar.profile
@@ -26,7 +26,7 @@ tracelog
26# support compressed archives 26# support compressed archives
27private-bin sh,bash,tar,gtar,compress,gzip,lzma,xz,bzip2,lbzip2,lzip,lzop 27private-bin sh,bash,tar,gtar,compress,gzip,lzma,xz,bzip2,lbzip2,lzip,lzop
28private-dev 28private-dev
29private-etc passwd,group,localtime 29private-etc alternatives,passwd,group,localtime
30private-lib 30private-lib
31 31
32# Debian based distributions need this for 'dpkg --unpack' (incl. synaptic) 32# Debian based distributions need this for 'dpkg --unpack' (incl. synaptic)
diff --git a/etc/terasology.profile b/etc/terasology.profile
index 22038e0b4..43865b6fb 100644
--- a/etc/terasology.profile
+++ b/etc/terasology.profile
@@ -44,7 +44,7 @@ shell none
44 44
45disable-mnt 45disable-mnt
46private-dev 46private-dev
47private-etc asound.conf,ca-certificates,dbus-1,drirc,fonts,group,gtk-2.0,gtk-3.0,host.conf,hostname,hosts,ld.so.cache,ld.so.preload,localtime,lsb-release,machine-id,mime.types,passwd,pulse,resolv.conf,ssl,java-8-openjdk,java-7-openjdk,pki,crypto-policies 47private-etc alternatives,asound.conf,ca-certificates,dbus-1,drirc,fonts,group,gtk-2.0,gtk-3.0,host.conf,hostname,hosts,ld.so.cache,ld.so.preload,localtime,lsb-release,machine-id,mime.types,passwd,pulse,resolv.conf,ssl,java-8-openjdk,java-7-openjdk,pki,crypto-policies
48private-tmp 48private-tmp
49 49
50noexec ${HOME} 50noexec ${HOME}
diff --git a/etc/tilp.profile b/etc/tilp.profile
index ecacd1deb..2643c9a84 100644
--- a/etc/tilp.profile
+++ b/etc/tilp.profile
@@ -29,7 +29,7 @@ tracelog
29disable-mnt 29disable-mnt
30private-bin tilp 30private-bin tilp
31private-cache 31private-cache
32private-etc fonts 32private-etc alternatives,fonts
33private-tmp 33private-tmp
34 34
35noexec ${HOME} 35noexec ${HOME}
diff --git a/etc/tor.profile b/etc/tor.profile
index 04a6c3abb..418352639 100644
--- a/etc/tor.profile
+++ b/etc/tor.profile
@@ -46,7 +46,7 @@ private
46private-bin tor,bash 46private-bin tor,bash
47private-cache 47private-cache
48private-dev 48private-dev
49private-etc tor,passwd,ca-certificates,ssl,pki,crypto-policies 49private-etc alternatives,tor,passwd,ca-certificates,ssl,pki,crypto-policies
50private-tmp 50private-tmp
51 51
52noexec ${HOME} 52noexec ${HOME}
diff --git a/etc/torbrowser-launcher.profile b/etc/torbrowser-launcher.profile
index a9244683f..2b1cc6549 100644
--- a/etc/torbrowser-launcher.profile
+++ b/etc/torbrowser-launcher.profile
@@ -49,7 +49,7 @@ shell none
49disable-mnt 49disable-mnt
50private-bin bash,cp,dirname,env,expr,file,getconf,gpg,grep,id,ln,mkdir,python*,readlink,rm,sed,sh,tail,tar,tclsh,test,tor-browser-en,torbrowser-launcher,xz 50private-bin bash,cp,dirname,env,expr,file,getconf,gpg,grep,id,ln,mkdir,python*,readlink,rm,sed,sh,tail,tar,tclsh,test,tor-browser-en,torbrowser-launcher,xz
51private-dev 51private-dev
52private-etc fonts,hostname,hosts,resolv.conf,pki,ssl,ca-certificates,crypto-policies,alsa,asound.conf,pulse,machine-id,ld.so.cache 52private-etc alternatives,fonts,hostname,hosts,resolv.conf,pki,ssl,ca-certificates,crypto-policies,alsa,asound.conf,pulse,machine-id,ld.so.cache
53private-tmp 53private-tmp
54 54
55noexec /tmp 55noexec /tmp
diff --git a/etc/totem.profile b/etc/totem.profile
index 3055ea542..fd473b03c 100644
--- a/etc/totem.profile
+++ b/etc/totem.profile
@@ -36,7 +36,7 @@ private-bin totem
36# totem needs access to ~/.cache/tracker or it exits 36# totem needs access to ~/.cache/tracker or it exits
37#private-cache 37#private-cache
38private-dev 38private-dev
39# private-etc fonts,machine-id,pulse,asound.conf,ca-certificates,ssl,pki,crypto-policies 39# private-etc alternatives,fonts,machine-id,pulse,asound.conf,ca-certificates,ssl,pki,crypto-policies
40private-tmp 40private-tmp
41 41
42noexec ${HOME} 42noexec ${HOME}
diff --git a/etc/tracker.profile b/etc/tracker.profile
index 6d86b2951..c1779ae3e 100644
--- a/etc/tracker.profile
+++ b/etc/tracker.profile
@@ -33,5 +33,5 @@ tracelog
33 33
34# private-bin tracker 34# private-bin tracker
35# private-dev 35# private-dev
36# private-etc fonts 36# private-etc alternatives,fonts
37# private-tmp 37# private-tmp
diff --git a/etc/transmission-cli.profile b/etc/transmission-cli.profile
index 81b52ec7c..89b9b21dc 100644
--- a/etc/transmission-cli.profile
+++ b/etc/transmission-cli.profile
@@ -33,7 +33,7 @@ tracelog
33 33
34# private-bin transmission-cli 34# private-bin transmission-cli
35private-dev 35private-dev
36private-etc ca-certificates,ssl,pki,crypto-policies 36private-etc alternatives,ca-certificates,ssl,pki,crypto-policies
37private-tmp 37private-tmp
38 38
39memory-deny-write-execute 39memory-deny-write-execute
diff --git a/etc/transmission-show.profile b/etc/transmission-show.profile
index 248eb977e..6154ad15b 100644
--- a/etc/transmission-show.profile
+++ b/etc/transmission-show.profile
@@ -31,5 +31,5 @@ shell none
31tracelog 31tracelog
32 32
33private-dev 33private-dev
34private-etc none 34private-etc alternatives
35private-tmp 35private-tmp
diff --git a/etc/unknown-horizons.profile b/etc/unknown-horizons.profile
index f62f018a6..36d1319d1 100644
--- a/etc/unknown-horizons.profile
+++ b/etc/unknown-horizons.profile
@@ -29,5 +29,5 @@ shell none
29 29
30# private-bin unknown-horizons 30# private-bin unknown-horizons
31private-dev 31private-dev
32# private-etc ca-certificates,ssl,pki,crypto-policies 32# private-etc alternatives,ca-certificates,ssl,pki,crypto-policies
33private-tmp 33private-tmp
diff --git a/etc/unrar.profile b/etc/unrar.profile
index 00fe0887b..bc5fced9f 100644
--- a/etc/unrar.profile
+++ b/etc/unrar.profile
@@ -25,7 +25,7 @@ tracelog
25 25
26private-bin unrar 26private-bin unrar
27private-dev 27private-dev
28private-etc passwd,group,localtime 28private-etc alternatives,passwd,group,localtime
29private-tmp 29private-tmp
30 30
31include default.profile 31include default.profile
diff --git a/etc/unzip.profile b/etc/unzip.profile
index 8e659c256..1859a2248 100644
--- a/etc/unzip.profile
+++ b/etc/unzip.profile
@@ -25,7 +25,7 @@ tracelog
25 25
26private-bin unzip 26private-bin unzip
27private-dev 27private-dev
28private-etc passwd,group,localtime 28private-etc alternatives,passwd,group,localtime
29 29
30# GNOME Shell integration (chrome-gnome-shell) 30# GNOME Shell integration (chrome-gnome-shell)
31noblacklist ${HOME}/.local/share/gnome-shell 31noblacklist ${HOME}/.local/share/gnome-shell
diff --git a/etc/uudeview.profile b/etc/uudeview.profile
index 3bd0ebe70..9710b1b9f 100644
--- a/etc/uudeview.profile
+++ b/etc/uudeview.profile
@@ -23,6 +23,6 @@ tracelog
23private-bin uudeview 23private-bin uudeview
24private-cache 24private-cache
25private-dev 25private-dev
26private-etc ld.so.preload 26private-etc alternatives,ld.so.preload
27 27
28include default.profile 28include default.profile
diff --git a/etc/viewnior.profile b/etc/viewnior.profile
index 4c22f8e6f..94b6c2052 100644
--- a/etc/viewnior.profile
+++ b/etc/viewnior.profile
@@ -38,7 +38,7 @@ tracelog
38private-bin viewnior 38private-bin viewnior
39private-cache 39private-cache
40private-dev 40private-dev
41private-etc fonts 41private-etc alternatives,fonts
42private-tmp 42private-tmp
43 43
44# memory-deny-write-executes breaks on Arch - see issue #1808 44# memory-deny-write-executes breaks on Arch - see issue #1808
diff --git a/etc/w3m.profile b/etc/w3m.profile
index c03df49cd..143ac4f63 100644
--- a/etc/w3m.profile
+++ b/etc/w3m.profile
@@ -36,5 +36,5 @@ tracelog
36# private-bin w3m 36# private-bin w3m
37private-cache 37private-cache
38private-dev 38private-dev
39private-etc resolv.conf,ssl,pki,ca-certificates,crypto-policies 39private-etc alternatives,resolv.conf,ssl,pki,ca-certificates,crypto-policies
40private-tmp 40private-tmp
diff --git a/etc/waterfox.profile b/etc/waterfox.profile
index 3dc21958d..7875ccb1e 100644
--- a/etc/waterfox.profile
+++ b/etc/waterfox.profile
@@ -22,7 +22,7 @@ whitelist ${HOME}/.waterfox
22# waterfox requires a shell to launch on Arch. We can possibly remove sh though. 22# waterfox requires a shell to launch on Arch. We can possibly remove sh though.
23#private-bin waterfox,which,sh,dbus-launch,dbus-send,env,bash 23#private-bin waterfox,which,sh,dbus-launch,dbus-send,env,bash
24# private-etc must first be enabled in firefox-common.profile 24# private-etc must first be enabled in firefox-common.profile
25#private-etc waterfox 25#private-etc alternatives,waterfox
26 26
27# Redirect 27# Redirect
28include firefox-common.profile 28include firefox-common.profile
diff --git a/etc/wget.profile b/etc/wget.profile
index 87c0501da..c0a6f0d21 100644
--- a/etc/wget.profile
+++ b/etc/wget.profile
@@ -35,7 +35,7 @@ shell none
35 35
36# private-bin wget 36# private-bin wget
37private-dev 37private-dev
38# private-etc resolv.conf,ca-certificates,ssl,pki,crypto-policies 38# private-etc alternatives,resolv.conf,ca-certificates,ssl,pki,crypto-policies
39# private-tmp 39# private-tmp
40 40
41noexec ${HOME} 41noexec ${HOME}
diff --git a/etc/whois.profile b/etc/whois.profile
index 78236c02f..0e9eb05a5 100644
--- a/etc/whois.profile
+++ b/etc/whois.profile
@@ -38,7 +38,7 @@ private
38private-bin sh,bash,whois 38private-bin sh,bash,whois
39private-cache 39private-cache
40private-dev 40private-dev
41# private-etc hosts,services,whois.conf 41# private-etc alternatives,hosts,services,whois.conf
42private-lib 42private-lib
43private-tmp 43private-tmp
44 44
diff --git a/etc/wire-desktop.profile b/etc/wire-desktop.profile
index f464a2fb9..e974e4304 100644
--- a/etc/wire-desktop.profile
+++ b/etc/wire-desktop.profile
@@ -37,5 +37,5 @@ shell none
37disable-mnt 37disable-mnt
38private-bin wire-desktop 38private-bin wire-desktop
39private-dev 39private-dev
40private-etc fonts,machine-id,resolv.conf,ca-certificates,ssl,pki,crypto-policies 40private-etc alternatives,fonts,machine-id,resolv.conf,ca-certificates,ssl,pki,crypto-policies
41private-tmp 41private-tmp
diff --git a/etc/wireshark.profile b/etc/wireshark.profile
index 4f1142826..a08b97d05 100644
--- a/etc/wireshark.profile
+++ b/etc/wireshark.profile
@@ -45,7 +45,7 @@ tracelog
45 45
46# private-bin wireshark 46# private-bin wireshark
47private-dev 47private-dev
48# private-etc fonts,group,hosts,machine-id,passwd,ca-certificates,ssl,pki,crypto-policies 48# private-etc alternatives,fonts,group,hosts,machine-id,passwd,ca-certificates,ssl,pki,crypto-policies
49private-tmp 49private-tmp
50 50
51noexec ${HOME} 51noexec ${HOME}
diff --git a/etc/xed.profile b/etc/xed.profile
index 7dffae05a..cd565f684 100644
--- a/etc/xed.profile
+++ b/etc/xed.profile
@@ -42,7 +42,7 @@ tracelog
42 42
43private-bin xed 43private-bin xed
44private-dev 44private-dev
45# private-etc fonts 45# private-etc alternatives,fonts
46private-tmp 46private-tmp
47 47
48# xed uses python plugins, memory-deny-write-execute breaks python 48# xed uses python plugins, memory-deny-write-execute breaks python
diff --git a/etc/xfburn.profile b/etc/xfburn.profile
index 3dc525755..1cb7f568a 100644
--- a/etc/xfburn.profile
+++ b/etc/xfburn.profile
@@ -29,5 +29,5 @@ tracelog
29 29
30# private-bin xfburn 30# private-bin xfburn
31# private-dev 31# private-dev
32# private-etc fonts 32# private-etc alternatives,fonts
33# private-tmp 33# private-tmp
diff --git a/etc/xiphos.profile b/etc/xiphos.profile
index 6adfcd819..3ad03e2c6 100644
--- a/etc/xiphos.profile
+++ b/etc/xiphos.profile
@@ -38,5 +38,5 @@ tracelog
38 38
39private-bin xiphos 39private-bin xiphos
40private-dev 40private-dev
41private-etc fonts,resolv.conf,sword,ca-certificates,ssl,pki,crypto-policies 41private-etc alternatives,fonts,resolv.conf,sword,ca-certificates,ssl,pki,crypto-policies
42private-tmp 42private-tmp
diff --git a/etc/xmr-stak.profile b/etc/xmr-stak.profile
index 25b2b8c91..99c9676b8 100644
--- a/etc/xmr-stak.profile
+++ b/etc/xmr-stak.profile
@@ -37,7 +37,7 @@ disable-mnt
37private ${HOME}/.xmr-stak 37private ${HOME}/.xmr-stak
38private-bin xmr-stak 38private-bin xmr-stak
39private-dev 39private-dev
40private-etc ca-certificates,crypto-policies,nsswitch.conf,pki,resolv.conf,ssl 40private-etc alternatives,ca-certificates,crypto-policies,nsswitch.conf,pki,resolv.conf,ssl
41#private-lib libxmrstak_opencl_backend,libxmrstak_cuda_backend 41#private-lib libxmrstak_opencl_backend,libxmrstak_cuda_backend
42private-opt cuda 42private-opt cuda
43private-tmp 43private-tmp
diff --git a/etc/xonotic.profile b/etc/xonotic.profile
index 054cf4896..9d422a01e 100644
--- a/etc/xonotic.profile
+++ b/etc/xonotic.profile
@@ -36,7 +36,7 @@ shell none
36disable-mnt 36disable-mnt
37private-bin bash,blind-id,darkplaces-glx,darkplaces-sdl,dirname,grep,ldd,netstat,ps,readlink,sh,uname,xonotic,xonotic-glx,xonotic-linux32-dedicated,xonotic-linux32-glx,xonotic-linux32-sdl,xonotic-linux64-dedicated,xonotic-linux64-glx,xonotic-linux64-sdl,xonotic-sdl 37private-bin bash,blind-id,darkplaces-glx,darkplaces-sdl,dirname,grep,ldd,netstat,ps,readlink,sh,uname,xonotic,xonotic-glx,xonotic-linux32-dedicated,xonotic-linux32-glx,xonotic-linux32-sdl,xonotic-linux64-dedicated,xonotic-linux64-glx,xonotic-linux64-sdl,xonotic-sdl
38private-dev 38private-dev
39private-etc asound.conf,ca-certificates,drirc,fonts,group,host.conf,hostname,hosts,ld.so.cache,ld.so.preload,localtime,nsswitch.conf,passwd,pulse,resolv.conf,ssl,pki,crypto-policies,machine-id 39private-etc alternatives,asound.conf,ca-certificates,drirc,fonts,group,host.conf,hostname,hosts,ld.so.cache,ld.so.preload,localtime,nsswitch.conf,passwd,pulse,resolv.conf,ssl,pki,crypto-policies,machine-id
40private-tmp 40private-tmp
41 41
42noexec ${HOME} 42noexec ${HOME}
diff --git a/etc/xplayer.profile b/etc/xplayer.profile
index b8297295a..0df879d7c 100644
--- a/etc/xplayer.profile
+++ b/etc/xplayer.profile
@@ -40,7 +40,7 @@ tracelog
40 40
41private-bin xplayer,xplayer-audio-preview,xplayer-video-thumbnailer 41private-bin xplayer,xplayer-audio-preview,xplayer-video-thumbnailer
42private-dev 42private-dev
43# private-etc fonts,machine-id,pulse,asound.conf,ca-certificates,ssl,pki,crypto-policies 43# private-etc alternatives,fonts,machine-id,pulse,asound.conf,ca-certificates,ssl,pki,crypto-policies
44private-tmp 44private-tmp
45 45
46noexec ${HOME} 46noexec ${HOME}
diff --git a/etc/xpra.profile b/etc/xpra.profile
index 23f3294bd..2ff6c2a5d 100644
--- a/etc/xpra.profile
+++ b/etc/xpra.profile
@@ -52,5 +52,5 @@ shell none
52# older Xpra versions also use Xvfb 52# older Xpra versions also use Xvfb
53# private-bin xpra,python*,Xvfb,Xorg,sh,xkbcomp,xauth,dbus-launch,pactl,ldconfig,which,strace,bash,cat,ls 53# private-bin xpra,python*,Xvfb,Xorg,sh,xkbcomp,xauth,dbus-launch,pactl,ldconfig,which,strace,bash,cat,ls
54private-dev 54private-dev
55# private-etc ld.so.conf,ld.so.cache,resolv.conf,host.conf,nsswitch.conf,gai.conf,hosts,hostname,machine-id,xpra,X11 55# private-etc alternatives,ld.so.conf,ld.so.cache,resolv.conf,host.conf,nsswitch.conf,gai.conf,hosts,hostname,machine-id,xpra,X11
56private-tmp 56private-tmp
diff --git a/etc/xreader.profile b/etc/xreader.profile
index a879e8b04..e0a3ddee3 100644
--- a/etc/xreader.profile
+++ b/etc/xreader.profile
@@ -38,7 +38,7 @@ tracelog
38 38
39private-bin xreader,xreader-previewer,xreader-thumbnailer 39private-bin xreader,xreader-previewer,xreader-thumbnailer
40private-dev 40private-dev
41private-etc fonts,ld.so.cache 41private-etc alternatives,fonts,ld.so.cache
42private-tmp 42private-tmp
43 43
44memory-deny-write-execute 44memory-deny-write-execute
diff --git a/etc/xviewer.profile b/etc/xviewer.profile
index e6185807e..c73630053 100644
--- a/etc/xviewer.profile
+++ b/etc/xviewer.profile
@@ -38,7 +38,7 @@ tracelog
38 38
39private-bin xviewer 39private-bin xviewer
40private-dev 40private-dev
41#private-etc fonts 41#private-etc alternatives,fonts
42private-lib 42private-lib
43private-tmp 43private-tmp
44 44
diff --git a/etc/zathura.profile b/etc/zathura.profile
index 2eee47fa0..922284353 100644
--- a/etc/zathura.profile
+++ b/etc/zathura.profile
@@ -35,7 +35,7 @@ shell none
35private-bin zathura 35private-bin zathura
36private-cache 36private-cache
37private-dev 37private-dev
38private-etc fonts,machine-id 38private-etc alternatives,fonts,machine-id
39private-tmp 39private-tmp
40 40
41read-only ${HOME}/ 41read-only ${HOME}/