aboutsummaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
authorLibravatar Fred-Barclay <Fred-Barclay@users.noreply.github.com>2017-11-17 12:29:11 -0600
committerLibravatar Fred-Barclay <Fred-Barclay@users.noreply.github.com>2017-11-17 12:32:32 -0600
commiteb4b505ac2537c320c044cf5fad595ecef41bbca (patch)
tree6216a34146aed50fdf700191914b287795d83adc /etc
parentFix #1651 - dropbox failed to start (diff)
downloadfirejail-eb4b505ac2537c320c044cf5fad595ecef41bbca.tar.gz
firejail-eb4b505ac2537c320c044cf5fad595ecef41bbca.tar.zst
firejail-eb4b505ac2537c320c044cf5fad595ecef41bbca.zip
Consistent home directory nomenclature
Diffstat (limited to 'etc')
-rw-r--r--etc/0ad.profile18
-rw-r--r--etc/2048-qt.profile4
-rw-r--r--etc/Mathematica.profile10
-rw-r--r--etc/Thunar.profile4
-rw-r--r--etc/abrowser.profile44
-rw-r--r--etc/ark.profile2
-rw-r--r--etc/atom.profile4
-rw-r--r--etc/atril.profile6
-rw-r--r--etc/audacious.profile4
-rw-r--r--etc/audacity.profile2
-rw-r--r--etc/aweather.profile6
-rw-r--r--etc/baloo_file.profile2
-rw-r--r--etc/bibletime.profile10
-rw-r--r--etc/blender.profile2
-rw-r--r--etc/brasero.profile2
-rw-r--r--etc/brave.profile24
-rw-r--r--etc/caja.profile6
-rw-r--r--etc/calibre.profile4
-rw-r--r--etc/catfish.profile2
-rw-r--r--etc/chromium.profile22
-rw-r--r--etc/claws-mail.profile6
-rw-r--r--etc/clementine.profile2
-rw-r--r--etc/cliqz.profile94
-rw-r--r--etc/conkeror.profile22
-rw-r--r--etc/corebird.profile2
-rw-r--r--etc/cower.profile8
-rw-r--r--etc/curl.profile2
-rw-r--r--etc/cyberfox.profile74
-rw-r--r--etc/darktable.profile4
-rw-r--r--etc/dia.profile2
-rw-r--r--etc/dillo.profile10
-rw-r--r--etc/dolphin.profile4
-rw-r--r--etc/dosbox.profile2
-rw-r--r--etc/dragon.profile2
-rw-r--r--etc/dropbox.profile22
-rw-r--r--etc/elinks.profile2
-rw-r--r--etc/emacs.profile4
-rw-r--r--etc/enchant.profile2
-rw-r--r--etc/eog.profile8
-rw-r--r--etc/eom.profile8
-rw-r--r--etc/etr.profile6
-rw-r--r--etc/evince.profile2
-rw-r--r--etc/evolution.profile12
-rw-r--r--etc/firefox.profile110
-rw-r--r--etc/flashpeak-slimjet.profile18
-rw-r--r--etc/fossamail.profile18
-rw-r--r--etc/franz.profile18
-rw-r--r--etc/frozen-bubble.profile6
-rw-r--r--etc/galculator.profile6
-rw-r--r--etc/geary.profile14
-rw-r--r--etc/geeqie.profile6
-rw-r--r--etc/gimp.profile2
-rw-r--r--etc/git.profile14
-rw-r--r--etc/gitter.profile8
-rw-r--r--etc/gjs.profile8
-rw-r--r--etc/gnome-books.profile2
-rw-r--r--etc/gnome-chess.profile2
-rw-r--r--etc/gnome-documents.profile2
-rw-r--r--etc/gnome-mplayer.profile2
-rw-r--r--etc/gnome-music.profile2
-rw-r--r--etc/gnome-photos.profile2
-rw-r--r--etc/gnome-weather.profile2
-rw-r--r--etc/google-chrome-beta.profile18
-rw-r--r--etc/google-chrome-unstable.profile18
-rw-r--r--etc/google-chrome.profile18
-rw-r--r--etc/google-play-music-desktop-player.profile8
-rw-r--r--etc/gpa.profile2
-rw-r--r--etc/gpg-agent.profile2
-rw-r--r--etc/gpg.profile2
-rw-r--r--etc/gpicview.profile2
-rw-r--r--etc/gpredict.profile4
-rw-r--r--etc/gthumb.profile4
-rw-r--r--etc/gwenview.profile18
-rw-r--r--etc/handbrake.profile2
-rw-r--r--etc/hedgewars.profile4
-rw-r--r--etc/hexchat.profile4
-rw-r--r--etc/icecat.profile44
-rw-r--r--etc/icedove.profile18
-rw-r--r--etc/inox.profile18
-rw-r--r--etc/iridium.profile16
-rw-r--r--etc/jitsi.profile2
-rw-r--r--etc/k3b.profile6
-rw-r--r--etc/kate.profile12
-rw-r--r--etc/kget.profile8
-rw-r--r--etc/kino.profile4
-rw-r--r--etc/knotes.profile2
-rw-r--r--etc/kopete.profile8
-rw-r--r--etc/krunner.profile6
-rw-r--r--etc/ktorrent.profile36
-rw-r--r--etc/kwin_x11.profile6
-rw-r--r--etc/kwrite.profile14
-rw-r--r--etc/less.profile2
-rw-r--r--etc/libreoffice.profile2
-rw-r--r--etc/liferea.profile18
-rw-r--r--etc/lximage-qt.profile2
-rw-r--r--etc/lxmusic.profile4
-rw-r--r--etc/makepkg.profile22
-rw-r--r--etc/mediathekview.profile20
-rw-r--r--etc/midori.profile40
-rw-r--r--etc/mousepad.profile2
-rw-r--r--etc/musescore.profile8
-rw-r--r--etc/mutt.profile44
-rw-r--r--etc/nautilus.profile8
-rw-r--r--etc/netsurf.profile12
-rw-r--r--etc/nylas.profile8
-rw-r--r--etc/okular.profile18
-rw-r--r--etc/open-invaders.profile6
-rw-r--r--etc/opera-beta.profile16
-rw-r--r--etc/opera.profile24
-rw-r--r--etc/palemoon.profile42
-rw-r--r--etc/pcmanfm.profile4
-rw-r--r--etc/pingus.profile6
-rw-r--r--etc/pix.profile4
-rw-r--r--etc/psi-plus.profile12
-rw-r--r--etc/qbittorrent.profile24
-rw-r--r--etc/qemu-launcher.profile2
-rw-r--r--etc/qtox.profile4
-rw-r--r--etc/quiterss.profile8
-rw-r--r--etc/qupzilla.profile4
-rw-r--r--etc/qutebrowser.profile16
-rw-r--r--etc/rambox.profile12
-rw-r--r--etc/ranger.profile2
-rw-r--r--etc/ristretto.profile4
-rw-r--r--etc/scribus.profile28
-rw-r--r--etc/seamonkey.profile44
-rw-r--r--etc/signal-desktop.profile6
-rw-r--r--etc/simple-scan.profile2
-rw-r--r--etc/simutrans.profile6
-rw-r--r--etc/snap.profile2
-rw-r--r--etc/ssh-agent.profile2
-rw-r--r--etc/ssh.profile2
-rw-r--r--etc/stellarium.profile12
-rw-r--r--etc/supertux2.profile6
-rw-r--r--etc/surf.profile4
-rw-r--r--etc/thunderbird.profile26
-rw-r--r--etc/torbrowser-launcher.profile12
-rw-r--r--etc/totem.profile4
-rw-r--r--etc/transmission-gtk.profile8
-rw-r--r--etc/transmission-qt.profile8
-rw-r--r--etc/tuxguitar.profile4
-rw-r--r--etc/uget-gtk.profile4
-rw-r--r--etc/unknown-horizons.profile6
-rw-r--r--etc/uzbl-browser.profile20
-rw-r--r--etc/viewnior.profile10
-rw-r--r--etc/vim.profile6
-rw-r--r--etc/virtualbox.profile8
-rw-r--r--etc/vivaldi.profile12
-rw-r--r--etc/vym.profile2
-rw-r--r--etc/w3m.profile2
-rw-r--r--etc/warzone2100.profile10
-rw-r--r--etc/waterfox.profile106
-rw-r--r--etc/wget.profile2
-rw-r--r--etc/whitelist-common.inc100
-rw-r--r--etc/wire.profile4
-rw-r--r--etc/xfburn.profile2
-rw-r--r--etc/xiphos.profile8
-rw-r--r--etc/xplayer.profile4
-rw-r--r--etc/xreader.profile6
-rw-r--r--etc/xviewer.profile8
-rw-r--r--etc/yandex-browser.profile30
-rw-r--r--etc/zathura.profile8
-rw-r--r--etc/zoom.profile8
162 files changed, 984 insertions, 984 deletions
diff --git a/etc/0ad.profile b/etc/0ad.profile
index 9ca9834a8..057dcf49e 100644
--- a/etc/0ad.profile
+++ b/etc/0ad.profile
@@ -5,21 +5,21 @@ include /etc/firejail/0ad.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.cache/0ad 8noblacklist ${HOME}/.cache/0ad
9noblacklist ~/.config/0ad 9noblacklist ${HOME}/.config/0ad
10noblacklist ~/.local/share/0ad 10noblacklist ${HOME}/.local/share/0ad
11 11
12include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-devel.inc 13include /etc/firejail/disable-devel.inc
14include /etc/firejail/disable-passwdmgr.inc 14include /etc/firejail/disable-passwdmgr.inc
15include /etc/firejail/disable-programs.inc 15include /etc/firejail/disable-programs.inc
16 16
17mkdir ~/.cache/0ad 17mkdir ${HOME}/.cache/0ad
18mkdir ~/.config/0ad 18mkdir ${HOME}/.config/0ad
19mkdir ~/.local/share/0ad 19mkdir ${HOME}/.local/share/0ad
20whitelist ~/.cache/0ad 20whitelist ${HOME}/.cache/0ad
21whitelist ~/.config/0ad 21whitelist ${HOME}/.config/0ad
22whitelist ~/.local/share/0ad 22whitelist ${HOME}/.local/share/0ad
23include /etc/firejail/whitelist-common.inc 23include /etc/firejail/whitelist-common.inc
24 24
25caps.drop all 25caps.drop all
diff --git a/etc/2048-qt.profile b/etc/2048-qt.profile
index 964a9e5fa..fa29925c4 100644
--- a/etc/2048-qt.profile
+++ b/etc/2048-qt.profile
@@ -5,8 +5,8 @@ include /etc/firejail/2048-qt.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.config/2048-qt 8noblacklist ${HOME}/.config/2048-qt
9noblacklist ~/.config/xiaoyong 9noblacklist ${HOME}/.config/xiaoyong
10 10
11include /etc/firejail/disable-common.inc 11include /etc/firejail/disable-common.inc
12include /etc/firejail/disable-devel.inc 12include /etc/firejail/disable-devel.inc
diff --git a/etc/Mathematica.profile b/etc/Mathematica.profile
index 924f74389..1ceaaf8dc 100644
--- a/etc/Mathematica.profile
+++ b/etc/Mathematica.profile
@@ -13,11 +13,11 @@ include /etc/firejail/disable-devel.inc
13include /etc/firejail/disable-passwdmgr.inc 13include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc 14include /etc/firejail/disable-programs.inc
15 15
16mkdir ~/.Mathematica 16mkdir ${HOME}/.Mathematica
17mkdir ~/.Wolfram Research 17mkdir ${HOME}/.Wolfram Research
18whitelist ~/.Mathematica 18whitelist ${HOME}/.Mathematica
19whitelist ~/.Wolfram Research 19whitelist ${HOME}/.Wolfram Research
20whitelist ~/Documents/Wolfram Mathematica 20whitelist ${HOME}/Documents/Wolfram Mathematica
21include /etc/firejail/whitelist-common.inc 21include /etc/firejail/whitelist-common.inc
22 22
23caps.drop all 23caps.drop all
diff --git a/etc/Thunar.profile b/etc/Thunar.profile
index f4a5c9f54..29cfebe13 100644
--- a/etc/Thunar.profile
+++ b/etc/Thunar.profile
@@ -6,8 +6,8 @@ include /etc/firejail/Thunar.local
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ${HOME}/.local/share/Trash 8noblacklist ${HOME}/.local/share/Trash
9noblacklist ~/.config/Thunar 9noblacklist ${HOME}/.config/Thunar
10noblacklist ~/.config/xfce4/xfconf/xfce-perchannel-xml/thunar.xml 10noblacklist ${HOME}/.config/xfce4/xfconf/xfce-perchannel-xml/thunar.xml
11 11
12include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-devel.inc 13include /etc/firejail/disable-devel.inc
diff --git a/etc/abrowser.profile b/etc/abrowser.profile
index 3251ef8aa..5c964bad1 100644
--- a/etc/abrowser.profile
+++ b/etc/abrowser.profile
@@ -5,34 +5,34 @@ include /etc/firejail/abrowser.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.cache/mozilla 8noblacklist ${HOME}/.cache/mozilla
9noblacklist ~/.mozilla 9noblacklist ${HOME}/.mozilla
10noblacklist ~/.pki 10noblacklist ${HOME}/.pki
11 11
12include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-devel.inc 13include /etc/firejail/disable-devel.inc
14include /etc/firejail/disable-programs.inc 14include /etc/firejail/disable-programs.inc
15 15
16mkdir ~/.cache/mozilla/abrowser 16mkdir ${HOME}/.cache/mozilla/abrowser
17mkdir ~/.mozilla 17mkdir ${HOME}/.mozilla
18whitelist ${DOWNLOADS} 18whitelist ${DOWNLOADS}
19whitelist ~/.cache/gnome-mplayer/plugin 19whitelist ${HOME}/.cache/gnome-mplayer/plugin
20whitelist ~/.cache/mozilla/abrowser 20whitelist ${HOME}/.cache/mozilla/abrowser
21whitelist ~/.config/gnome-mplayer 21whitelist ${HOME}/.config/gnome-mplayer
22whitelist ~/.config/pipelight-silverlight5.1 22whitelist ${HOME}/.config/pipelight-silverlight5.1
23whitelist ~/.config/pipelight-widevine 23whitelist ${HOME}/.config/pipelight-widevine
24whitelist ~/.keysnail.js 24whitelist ${HOME}/.keysnail.js
25whitelist ~/.lastpass 25whitelist ${HOME}/.lastpass
26whitelist ~/.mozilla 26whitelist ${HOME}/.mozilla
27whitelist ~/.pentadactyl 27whitelist ${HOME}/.pentadactyl
28whitelist ~/.pentadactylrc 28whitelist ${HOME}/.pentadactylrc
29whitelist ~/.pki 29whitelist ${HOME}/.pki
30whitelist ~/.vimperator 30whitelist ${HOME}/.vimperator
31whitelist ~/.vimperatorrc 31whitelist ${HOME}/.vimperatorrc
32whitelist ~/.wine-pipelight 32whitelist ${HOME}/.wine-pipelight
33whitelist ~/.wine-pipelight64 33whitelist ${HOME}/.wine-pipelight64
34whitelist ~/.zotero 34whitelist ${HOME}/.zotero
35whitelist ~/dwhelper 35whitelist ${HOME}/dwhelper
36include /etc/firejail/whitelist-common.inc 36include /etc/firejail/whitelist-common.inc
37 37
38caps.drop all 38caps.drop all
diff --git a/etc/ark.profile b/etc/ark.profile
index 404206992..76b1d9394 100644
--- a/etc/ark.profile
+++ b/etc/ark.profile
@@ -7,7 +7,7 @@ include /etc/firejail/globals.local
7 7
8# blacklist /run/user/*/bus 8# blacklist /run/user/*/bus
9 9
10noblacklist ~/.config/arkrc 10noblacklist ${HOME}/.config/arkrc
11 11
12include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-devel.inc 13include /etc/firejail/disable-devel.inc
diff --git a/etc/atom.profile b/etc/atom.profile
index dc8db46dc..de09275cc 100644
--- a/etc/atom.profile
+++ b/etc/atom.profile
@@ -7,8 +7,8 @@ include /etc/firejail/globals.local
7 7
8# blacklist /run/user/*/bus 8# blacklist /run/user/*/bus
9 9
10noblacklist ~/.atom 10noblacklist ${HOME}/.atom
11noblacklist ~/.config/Atom 11noblacklist ${HOME}/.config/Atom
12 12
13include /etc/firejail/disable-common.inc 13include /etc/firejail/disable-common.inc
14include /etc/firejail/disable-passwdmgr.inc 14include /etc/firejail/disable-passwdmgr.inc
diff --git a/etc/atril.profile b/etc/atril.profile
index 50592ec3a..81d9e50d0 100644
--- a/etc/atril.profile
+++ b/etc/atril.profile
@@ -5,10 +5,10 @@ include /etc/firejail/atril.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.config/atril 8noblacklist ${HOME}/.config/atril
9 9
10#noblacklist ~/.local/share 10#noblacklist ${HOME}/.local/share
11# it seems to use only ~/.local/share/webkitgtk 11# it seems to use only ${HOME}/.local/share/webkitgtk
12 12
13include /etc/firejail/disable-common.inc 13include /etc/firejail/disable-common.inc
14include /etc/firejail/disable-devel.inc 14include /etc/firejail/disable-devel.inc
diff --git a/etc/audacious.profile b/etc/audacious.profile
index 7e2b91773..9a11022e3 100644
--- a/etc/audacious.profile
+++ b/etc/audacious.profile
@@ -5,8 +5,8 @@ include /etc/firejail/audacious.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.config/Audaciousrc 8noblacklist ${HOME}/.config/Audaciousrc
9noblacklist ~/.config/audacious 9noblacklist ${HOME}/.config/audacious
10 10
11include /etc/firejail/disable-common.inc 11include /etc/firejail/disable-common.inc
12include /etc/firejail/disable-devel.inc 12include /etc/firejail/disable-devel.inc
diff --git a/etc/audacity.profile b/etc/audacity.profile
index 52e32badb..e173fa65a 100644
--- a/etc/audacity.profile
+++ b/etc/audacity.profile
@@ -7,7 +7,7 @@ include /etc/firejail/globals.local
7 7
8blacklist /run/user/*/bus 8blacklist /run/user/*/bus
9 9
10noblacklist ~/.audacity-data 10noblacklist ${HOME}/.audacity-data
11 11
12include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-devel.inc 13include /etc/firejail/disable-devel.inc
diff --git a/etc/aweather.profile b/etc/aweather.profile
index 62cebdbe5..2a4a9b591 100644
--- a/etc/aweather.profile
+++ b/etc/aweather.profile
@@ -5,15 +5,15 @@ include /etc/firejail/aweather.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.config/aweather 8noblacklist ${HOME}/.config/aweather
9 9
10include /etc/firejail/disable-common.inc 10include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-devel.inc 11include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-passwdmgr.inc 12include /etc/firejail/disable-passwdmgr.inc
13include /etc/firejail/disable-programs.inc 13include /etc/firejail/disable-programs.inc
14 14
15mkdir ~/.config/aweather 15mkdir ${HOME}/.config/aweather
16whitelist ~/.config/aweather 16whitelist ${HOME}/.config/aweather
17include /etc/firejail/whitelist-common.inc 17include /etc/firejail/whitelist-common.inc
18include /etc/firejail/whitelist-var-common.inc 18include /etc/firejail/whitelist-var-common.inc
19 19
diff --git a/etc/baloo_file.profile b/etc/baloo_file.profile
index a4fe05cf7..f6dbb480b 100644
--- a/etc/baloo_file.profile
+++ b/etc/baloo_file.profile
@@ -41,7 +41,7 @@ private-tmp
41noexec ${HOME} 41noexec ${HOME}
42noexec /tmp 42noexec /tmp
43 43
44# Make home directory read-only and allow writing only to ~/.local/share 44# Make home directory read-only and allow writing only to ${HOME}/.local/share
45# Note: Baloo will not be able to update the "first run" key in its configuration files. 45# Note: Baloo will not be able to update the "first run" key in its configuration files.
46# read-only ${HOME} 46# read-only ${HOME}
47# read-write ${HOME}/.local/share 47# read-write ${HOME}/.local/share
diff --git a/etc/bibletime.profile b/etc/bibletime.profile
index 73d31c205..455a0e2a0 100644
--- a/etc/bibletime.profile
+++ b/etc/bibletime.profile
@@ -5,12 +5,12 @@ include /etc/firejail/bibletime.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8blacklist ~/.Xauthority 8blacklist ${HOME}/.Xauthority
9blacklist ~/.bashrc 9blacklist ${HOME}/.bashrc
10 10
11noblacklist ~/.bibletime 11noblacklist ${HOME}/.bibletime
12noblacklist ~/.config/qt5ct 12noblacklist ${HOME}/.config/qt5ct
13noblacklist ~/.sword 13noblacklist ${HOME}/.sword
14 14
15include /etc/firejail/disable-common.inc 15include /etc/firejail/disable-common.inc
16include /etc/firejail/disable-devel.inc 16include /etc/firejail/disable-devel.inc
diff --git a/etc/blender.profile b/etc/blender.profile
index f7ecbce55..29df27759 100644
--- a/etc/blender.profile
+++ b/etc/blender.profile
@@ -5,7 +5,7 @@ include /etc/firejail/blender.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.config/blender 8noblacklist ${HOME}/.config/blender
9 9
10include /etc/firejail/disable-common.inc 10include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-devel.inc 11include /etc/firejail/disable-devel.inc
diff --git a/etc/brasero.profile b/etc/brasero.profile
index eff4cba43..f90d4688a 100644
--- a/etc/brasero.profile
+++ b/etc/brasero.profile
@@ -5,7 +5,7 @@ include /etc/firejail/brasero.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.config/brasero 8noblacklist ${HOME}/.config/brasero
9 9
10include /etc/firejail/disable-common.inc 10include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-devel.inc 11include /etc/firejail/disable-devel.inc
diff --git a/etc/brave.profile b/etc/brave.profile
index 4a908c884..476d1575a 100644
--- a/etc/brave.profile
+++ b/etc/brave.profile
@@ -5,25 +5,25 @@ include /etc/firejail/brave.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.config/brave 8noblacklist ${HOME}/.config/brave
9# brave uses gpg for built-in password manager 9# brave uses gpg for built-in password manager
10noblacklist ~/.gnupg 10noblacklist ${HOME}/.gnupg
11noblacklist ~/.pki 11noblacklist ${HOME}/.pki
12 12
13include /etc/firejail/disable-common.inc 13include /etc/firejail/disable-common.inc
14include /etc/firejail/disable-devel.inc 14include /etc/firejail/disable-devel.inc
15include /etc/firejail/disable-programs.inc 15include /etc/firejail/disable-programs.inc
16 16
17mkdir ~/.config/brave 17mkdir ${HOME}/.config/brave
18mkdir ~/.pki 18mkdir ${HOME}/.pki
19whitelist ${DOWNLOADS} 19whitelist ${DOWNLOADS}
20whitelist ~/.config/KeePass 20whitelist ${HOME}/.config/KeePass
21whitelist ~/.config/brave 21whitelist ${HOME}/.config/brave
22whitelist ~/.config/keepass 22whitelist ${HOME}/.config/keepass
23whitelist ~/.config/lastpass 23whitelist ${HOME}/.config/lastpass
24whitelist ~/.keepass 24whitelist ${HOME}/.keepass
25whitelist ~/.lastpass 25whitelist ${HOME}/.lastpass
26whitelist ~/.pki 26whitelist ${HOME}/.pki
27include /etc/firejail/whitelist-common.inc 27include /etc/firejail/whitelist-common.inc
28 28
29# caps.drop all 29# caps.drop all
diff --git a/etc/caja.profile b/etc/caja.profile
index 83b6befa3..c3d5fa7c4 100644
--- a/etc/caja.profile
+++ b/etc/caja.profile
@@ -8,9 +8,9 @@ include /etc/firejail/globals.local
8# Caja is started by systemd on most systems. Therefore it is not firejailed by default. Since there 8# Caja is started by systemd on most systems. Therefore it is not firejailed by default. Since there
9# is already a caja process running on MATE desktops firejail will have no effect. 9# is already a caja process running on MATE desktops firejail will have no effect.
10 10
11# noblacklist ~/.config/caja - disable-programs.inc is disabled, see below 11# noblacklist ${HOME}/.config/caja - disable-programs.inc is disabled, see below
12# noblacklist ~/.local/share/Trash 12# noblacklist ${HOME}/.local/share/Trash
13# noblacklist ~/.local/share/caja-python 13# noblacklist ${HOME}/.local/share/caja-python
14 14
15include /etc/firejail/disable-common.inc 15include /etc/firejail/disable-common.inc
16include /etc/firejail/disable-devel.inc 16include /etc/firejail/disable-devel.inc
diff --git a/etc/calibre.profile b/etc/calibre.profile
index 844231032..e4ed87753 100644
--- a/etc/calibre.profile
+++ b/etc/calibre.profile
@@ -5,8 +5,8 @@ include /etc/firejail/calibre.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.cache/calibre 8noblacklist ${HOME}/.cache/calibre
9noblacklist ~/.config/calibre 9noblacklist ${HOME}/.config/calibre
10 10
11include /etc/firejail/disable-common.inc 11include /etc/firejail/disable-common.inc
12# include /etc/firejail/disable-devel.inc 12# include /etc/firejail/disable-devel.inc
diff --git a/etc/catfish.profile b/etc/catfish.profile
index 139951680..6d5ec1c52 100644
--- a/etc/catfish.profile
+++ b/etc/catfish.profile
@@ -10,7 +10,7 @@ include /etc/firejail/globals.local
10 10
11blacklist /run/user/*/bus 11blacklist /run/user/*/bus
12 12
13noblacklist ~/.config/catfish 13noblacklist ${HOME}/.config/catfish
14 14
15include /etc/firejail/disable-common.inc 15include /etc/firejail/disable-common.inc
16# include /etc/firejail/disable-devel.inc 16# include /etc/firejail/disable-devel.inc
diff --git a/etc/chromium.profile b/etc/chromium.profile
index 0c7058a11..281d8bf76 100644
--- a/etc/chromium.profile
+++ b/etc/chromium.profile
@@ -5,23 +5,23 @@ include /etc/firejail/chromium.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.cache/chromium 8noblacklist ${HOME}/.cache/chromium
9noblacklist ~/.config/chromium 9noblacklist ${HOME}/.config/chromium
10noblacklist ~/.config/chromium-flags.conf 10noblacklist ${HOME}/.config/chromium-flags.conf
11noblacklist ~/.pki 11noblacklist ${HOME}/.pki
12 12
13include /etc/firejail/disable-common.inc 13include /etc/firejail/disable-common.inc
14include /etc/firejail/disable-devel.inc 14include /etc/firejail/disable-devel.inc
15include /etc/firejail/disable-programs.inc 15include /etc/firejail/disable-programs.inc
16 16
17mkdir ~/.cache/chromium 17mkdir ${HOME}/.cache/chromium
18mkdir ~/.config/chromium 18mkdir ${HOME}/.config/chromium
19mkdir ~/.pki 19mkdir ${HOME}/.pki
20whitelist ${DOWNLOADS} 20whitelist ${DOWNLOADS}
21whitelist ~/.cache/chromium 21whitelist ${HOME}/.cache/chromium
22whitelist ~/.config/chromium 22whitelist ${HOME}/.config/chromium
23whitelist ~/.config/chromium-flags.conf 23whitelist ${HOME}/.config/chromium-flags.conf
24whitelist ~/.pki 24whitelist ${HOME}/.pki
25include /etc/firejail/whitelist-common.inc 25include /etc/firejail/whitelist-common.inc
26include /etc/firejail/whitelist-var-common.inc 26include /etc/firejail/whitelist-var-common.inc
27 27
diff --git a/etc/claws-mail.profile b/etc/claws-mail.profile
index 4ab49163b..319515bde 100644
--- a/etc/claws-mail.profile
+++ b/etc/claws-mail.profile
@@ -5,9 +5,9 @@ include /etc/firejail/claws-mail.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.claws-mail 8noblacklist ${HOME}/.claws-mail
9noblacklist ~/.gnupg 9noblacklist ${HOME}/.gnupg
10noblacklist ~/.signature 10noblacklist ${HOME}/.signature
11 11
12include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-devel.inc 13include /etc/firejail/disable-devel.inc
diff --git a/etc/clementine.profile b/etc/clementine.profile
index 619086437..f4a3301b6 100644
--- a/etc/clementine.profile
+++ b/etc/clementine.profile
@@ -5,7 +5,7 @@ include /etc/firejail/clementine.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.config/Clementine 8noblacklist ${HOME}/.config/Clementine
9 9
10include /etc/firejail/disable-common.inc 10include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-devel.inc 11include /etc/firejail/disable-devel.inc
diff --git a/etc/cliqz.profile b/etc/cliqz.profile
index d61d46dca..086dfa233 100644
--- a/etc/cliqz.profile
+++ b/etc/cliqz.profile
@@ -5,60 +5,60 @@ include /etc/firejail/cliqz.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.cache/cliqz 8noblacklist ${HOME}/.cache/cliqz
9noblacklist ~/.config/cliqz 9noblacklist ${HOME}/.config/cliqz
10noblacklist ~/.config/okularpartrc 10noblacklist ${HOME}/.config/okularpartrc
11noblacklist ~/.config/okularrc 11noblacklist ${HOME}/.config/okularrc
12noblacklist ~/.config/qpdfview 12noblacklist ${HOME}/.config/qpdfview
13noblacklist ~/.kde/share/apps/okular 13noblacklist ${HOME}/.kde/share/apps/okular
14noblacklist ~/.kde/share/config/okularpartrc 14noblacklist ${HOME}/.kde/share/config/okularpartrc
15noblacklist ~/.kde/share/config/okularrc 15noblacklist ${HOME}/.kde/share/config/okularrc
16noblacklist ~/.kde4/share/apps/okular 16noblacklist ${HOME}/.kde4/share/apps/okular
17noblacklist ~/.kde4/share/config/okularpartrc 17noblacklist ${HOME}/.kde4/share/config/okularpartrc
18noblacklist ~/.kde4/share/config/okularrc 18noblacklist ${HOME}/.kde4/share/config/okularrc
19# noblacklist ~/.local/share/gnome-shell/extensions 19# noblacklist ${HOME}/.local/share/gnome-shell/extensions
20noblacklist ~/.local/share/okular 20noblacklist ${HOME}/.local/share/okular
21noblacklist ~/.local/share/qpdfview 21noblacklist ${HOME}/.local/share/qpdfview
22 22
23noblacklist ~/.pki 23noblacklist ${HOME}/.pki
24 24
25include /etc/firejail/disable-common.inc 25include /etc/firejail/disable-common.inc
26include /etc/firejail/disable-devel.inc 26include /etc/firejail/disable-devel.inc
27include /etc/firejail/disable-programs.inc 27include /etc/firejail/disable-programs.inc
28 28
29mkdir ~/.cache/mozilla/firefox 29mkdir ${HOME}/.cache/mozilla/firefox
30mkdir ~/.mozilla 30mkdir ${HOME}/.mozilla
31mkdir ~/.pki 31mkdir ${HOME}/.pki
32whitelist ${DOWNLOADS} 32whitelist ${DOWNLOADS}
33whitelist ~/.cache/gnome-mplayer/plugin 33whitelist ${HOME}/.cache/gnome-mplayer/plugin
34whitelist ~/.cache/mozilla/firefox 34whitelist ${HOME}/.cache/mozilla/firefox
35whitelist ~/.config/gnome-mplayer 35whitelist ${HOME}/.config/gnome-mplayer
36whitelist ~/.config/okularpartrc 36whitelist ${HOME}/.config/okularpartrc
37whitelist ~/.config/okularrc 37whitelist ${HOME}/.config/okularrc
38whitelist ~/.config/pipelight-silverlight5.1 38whitelist ${HOME}/.config/pipelight-silverlight5.1
39whitelist ~/.config/pipelight-widevine 39whitelist ${HOME}/.config/pipelight-widevine
40whitelist ~/.config/qpdfview 40whitelist ${HOME}/.config/qpdfview
41whitelist ~/.kde/share/apps/okular 41whitelist ${HOME}/.kde/share/apps/okular
42whitelist ~/.kde/share/config/okularpartrc 42whitelist ${HOME}/.kde/share/config/okularpartrc
43whitelist ~/.kde/share/config/okularrc 43whitelist ${HOME}/.kde/share/config/okularrc
44whitelist ~/.kde4/share/apps/okular 44whitelist ${HOME}/.kde4/share/apps/okular
45whitelist ~/.kde4/share/config/okularpartrc 45whitelist ${HOME}/.kde4/share/config/okularpartrc
46whitelist ~/.kde4/share/config/okularrc 46whitelist ${HOME}/.kde4/share/config/okularrc
47whitelist ~/.keysnail.js 47whitelist ${HOME}/.keysnail.js
48whitelist ~/.lastpass 48whitelist ${HOME}/.lastpass
49whitelist ~/.local/share/gnome-shell/extensions 49whitelist ${HOME}/.local/share/gnome-shell/extensions
50whitelist ~/.local/share/okular 50whitelist ${HOME}/.local/share/okular
51whitelist ~/.local/share/qpdfview 51whitelist ${HOME}/.local/share/qpdfview
52whitelist ~/.mozilla 52whitelist ${HOME}/.mozilla
53whitelist ~/.pentadactyl 53whitelist ${HOME}/.pentadactyl
54whitelist ~/.pentadactylrc 54whitelist ${HOME}/.pentadactylrc
55whitelist ~/.pki 55whitelist ${HOME}/.pki
56whitelist ~/.vimperator 56whitelist ${HOME}/.vimperator
57whitelist ~/.vimperatorrc 57whitelist ${HOME}/.vimperatorrc
58whitelist ~/.wine-pipelight 58whitelist ${HOME}/.wine-pipelight
59whitelist ~/.wine-pipelight64 59whitelist ${HOME}/.wine-pipelight64
60whitelist ~/.zotero 60whitelist ${HOME}/.zotero
61whitelist ~/dwhelper 61whitelist ${HOME}/dwhelper
62include /etc/firejail/whitelist-common.inc 62include /etc/firejail/whitelist-common.inc
63include /etc/firejail/whitelist-var-common.inc 63include /etc/firejail/whitelist-var-common.inc
64 64
diff --git a/etc/conkeror.profile b/etc/conkeror.profile
index f6a9eefb6..38c4fdd68 100644
--- a/etc/conkeror.profile
+++ b/etc/conkeror.profile
@@ -10,17 +10,17 @@ noblacklist ${HOME}/.conkeror.mozdev.org
10include /etc/firejail/disable-common.inc 10include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-programs.inc 11include /etc/firejail/disable-programs.inc
12 12
13whitelist ~/.conkeror.mozdev.org 13whitelist ${HOME}/.conkeror.mozdev.org
14whitelist ~/.conkerorrc 14whitelist ${HOME}/.conkerorrc
15whitelist ~/.gtkrc-2.0 15whitelist ${HOME}/.gtkrc-2.0
16whitelist ~/.lastpass 16whitelist ${HOME}/.lastpass
17whitelist ~/.pentadactyl 17whitelist ${HOME}/.pentadactyl
18whitelist ~/.pentadactylrc 18whitelist ${HOME}/.pentadactylrc
19whitelist ~/.vimperator 19whitelist ${HOME}/.vimperator
20whitelist ~/.vimperatorrc 20whitelist ${HOME}/.vimperatorrc
21whitelist ~/.zotero 21whitelist ${HOME}/.zotero
22whitelist ~/Downloads 22whitelist ${HOME}/Downloads
23whitelist ~/dwhelper 23whitelist ${HOME}/dwhelper
24include /etc/firejail/whitelist-common.inc 24include /etc/firejail/whitelist-common.inc
25 25
26caps.drop all 26caps.drop all
diff --git a/etc/corebird.profile b/etc/corebird.profile
index 99a3335ef..3c9740cb7 100644
--- a/etc/corebird.profile
+++ b/etc/corebird.profile
@@ -5,7 +5,7 @@ include /etc/firejail/corebird.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.config/corebird 8noblacklist ${HOME}/.config/corebird
9 9
10include /etc/firejail/disable-common.inc 10include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-devel.inc 11include /etc/firejail/disable-devel.inc
diff --git a/etc/cower.profile b/etc/cower.profile
index 5e5c367c4..565c417ed 100644
--- a/etc/cower.profile
+++ b/etc/cower.profile
@@ -2,8 +2,8 @@
2# This file is overwritten after every install/update 2# This file is overwritten after every install/update
3 3
4# This profile could be significantly strengthened by adding the following to cower.local 4# This profile could be significantly strengthened by adding the following to cower.local
5# whitelist ~/<Your Build Folder> 5# whitelist ${HOME}/<Your Build Folder>
6# whitelist ~/.config/cower/ 6# whitelist ${HOME}/.config/cower/
7 7
8quiet 8quiet
9 9
@@ -12,8 +12,8 @@ include /etc/firejail/cower.local
12# Persistent global definitions 12# Persistent global definitions
13include /etc/firejail/globals.local 13include /etc/firejail/globals.local
14 14
15noblacklist ~/.config/cower/config 15noblacklist ${HOME}/.config/cower/config
16read-only ~/.config/cower/config 16read-only ${HOME}/.config/cower/config
17 17
18noblacklist /var/lib/pacman 18noblacklist /var/lib/pacman
19 19
diff --git a/etc/curl.profile b/etc/curl.profile
index 972bbe9cc..521cd20cc 100644
--- a/etc/curl.profile
+++ b/etc/curl.profile
@@ -8,7 +8,7 @@ include /etc/firejail/globals.local
8 8
9blacklist /tmp/.X11-unix 9blacklist /tmp/.X11-unix
10 10
11noblacklist ~/.curlrc 11noblacklist ${HOME}/.curlrc
12 12
13include /etc/firejail/disable-common.inc 13include /etc/firejail/disable-common.inc
14include /etc/firejail/disable-passwdmgr.inc 14include /etc/firejail/disable-passwdmgr.inc
diff --git a/etc/cyberfox.profile b/etc/cyberfox.profile
index 63f6ea845..a670f6aa3 100644
--- a/etc/cyberfox.profile
+++ b/etc/cyberfox.profile
@@ -5,49 +5,49 @@ include /etc/firejail/cyberfox.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.8pecxstudios 8noblacklist ${HOME}/.8pecxstudios
9noblacklist ~/.cache/8pecxstudios 9noblacklist ${HOME}/.cache/8pecxstudios
10noblacklist ~/.config/okularpartrc 10noblacklist ${HOME}/.config/okularpartrc
11noblacklist ~/.config/okularrc 11noblacklist ${HOME}/.config/okularrc
12noblacklist ~/.config/qpdfview 12noblacklist ${HOME}/.config/qpdfview
13noblacklist ~/.kde/share/apps/okular 13noblacklist ${HOME}/.kde/share/apps/okular
14noblacklist ~/.kde4/share/apps/okular 14noblacklist ${HOME}/.kde4/share/apps/okular
15noblacklist ~/.local/share/okular 15noblacklist ${HOME}/.local/share/okular
16noblacklist ~/.local/share/qpdfview 16noblacklist ${HOME}/.local/share/qpdfview
17noblacklist ~/.pki 17noblacklist ${HOME}/.pki
18 18
19include /etc/firejail/disable-common.inc 19include /etc/firejail/disable-common.inc
20include /etc/firejail/disable-devel.inc 20include /etc/firejail/disable-devel.inc
21include /etc/firejail/disable-programs.inc 21include /etc/firejail/disable-programs.inc
22 22
23mkdir ~/.8pecxstudios 23mkdir ${HOME}/.8pecxstudios
24mkdir ~/.cache/8pecxstudios 24mkdir ${HOME}/.cache/8pecxstudios
25mkdir ~/.pki 25mkdir ${HOME}/.pki
26whitelist ${DOWNLOADS} 26whitelist ${DOWNLOADS}
27whitelist ~/.8pecxstudios 27whitelist ${HOME}/.8pecxstudios
28whitelist ~/.cache/8pecxstudios 28whitelist ${HOME}/.cache/8pecxstudios
29whitelist ~/.cache/gnome-mplayer/plugin 29whitelist ${HOME}/.cache/gnome-mplayer/plugin
30whitelist ~/.config/gnome-mplayer 30whitelist ${HOME}/.config/gnome-mplayer
31whitelist ~/.config/okularpartrc 31whitelist ${HOME}/.config/okularpartrc
32whitelist ~/.config/okularrc 32whitelist ${HOME}/.config/okularrc
33whitelist ~/.config/pipelight-silverlight5.1 33whitelist ${HOME}/.config/pipelight-silverlight5.1
34whitelist ~/.config/pipelight-widevine 34whitelist ${HOME}/.config/pipelight-widevine
35whitelist ~/.config/qpdfview 35whitelist ${HOME}/.config/qpdfview
36whitelist ~/.kde/share/apps/okular 36whitelist ${HOME}/.kde/share/apps/okular
37whitelist ~/.kde4/share/apps/okular 37whitelist ${HOME}/.kde4/share/apps/okular
38whitelist ~/.keysnail.js 38whitelist ${HOME}/.keysnail.js
39whitelist ~/.lastpass 39whitelist ${HOME}/.lastpass
40whitelist ~/.local/share/okular 40whitelist ${HOME}/.local/share/okular
41whitelist ~/.local/share/qpdfview 41whitelist ${HOME}/.local/share/qpdfview
42whitelist ~/.pentadactyl 42whitelist ${HOME}/.pentadactyl
43whitelist ~/.pentadactylrc 43whitelist ${HOME}/.pentadactylrc
44whitelist ~/.pki 44whitelist ${HOME}/.pki
45whitelist ~/.vimperator 45whitelist ${HOME}/.vimperator
46whitelist ~/.vimperatorrc 46whitelist ${HOME}/.vimperatorrc
47whitelist ~/.wine-pipelight 47whitelist ${HOME}/.wine-pipelight
48whitelist ~/.wine-pipelight64 48whitelist ${HOME}/.wine-pipelight64
49whitelist ~/.zotero 49whitelist ${HOME}/.zotero
50whitelist ~/dwhelper 50whitelist ${HOME}/dwhelper
51include /etc/firejail/whitelist-common.inc 51include /etc/firejail/whitelist-common.inc
52 52
53caps.drop all 53caps.drop all
diff --git a/etc/darktable.profile b/etc/darktable.profile
index c2dc0b42c..176ffaca1 100644
--- a/etc/darktable.profile
+++ b/etc/darktable.profile
@@ -5,8 +5,8 @@ include /etc/firejail/darktable.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.cache/darktable 8noblacklist ${HOME}/.cache/darktable
9noblacklist ~/.config/darktable 9noblacklist ${HOME}/.config/darktable
10 10
11include /etc/firejail/disable-common.inc 11include /etc/firejail/disable-common.inc
12include /etc/firejail/disable-devel.inc 12include /etc/firejail/disable-devel.inc
diff --git a/etc/dia.profile b/etc/dia.profile
index bf3c384ab..b1a723da0 100644
--- a/etc/dia.profile
+++ b/etc/dia.profile
@@ -7,7 +7,7 @@ include /etc/firejail/globals.local
7 7
8blacklist /run/user/*/bus 8blacklist /run/user/*/bus
9 9
10noblacklist ~/.dia 10noblacklist ${HOME}/.dia
11 11
12include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-devel.inc 13include /etc/firejail/disable-devel.inc
diff --git a/etc/dillo.profile b/etc/dillo.profile
index 840a568d8..6afb999e7 100644
--- a/etc/dillo.profile
+++ b/etc/dillo.profile
@@ -5,18 +5,18 @@ include /etc/firejail/dillo.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.dillo 8noblacklist ${HOME}/.dillo
9 9
10include /etc/firejail/disable-common.inc 10include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-devel.inc 11include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-passwdmgr.inc 12include /etc/firejail/disable-passwdmgr.inc
13include /etc/firejail/disable-programs.inc 13include /etc/firejail/disable-programs.inc
14 14
15mkdir ~/.dillo 15mkdir ${HOME}/.dillo
16mkdir ~/.fltk 16mkdir ${HOME}/.fltk
17whitelist ${DOWNLOADS} 17whitelist ${DOWNLOADS}
18whitelist ~/.dillo 18whitelist ${HOME}/.dillo
19whitelist ~/.fltk 19whitelist ${HOME}/.fltk
20include /etc/firejail/whitelist-common.inc 20include /etc/firejail/whitelist-common.inc
21include /etc/firejail/whitelist-var-common.inc 21include /etc/firejail/whitelist-var-common.inc
22 22
diff --git a/etc/dolphin.profile b/etc/dolphin.profile
index fe72ee654..c1604826e 100644
--- a/etc/dolphin.profile
+++ b/etc/dolphin.profile
@@ -8,8 +8,8 @@ include /etc/firejail/globals.local
8# warning: firejail is currently not effectively constraining dolphin since used services are started by kdeinit5 8# warning: firejail is currently not effectively constraining dolphin since used services are started by kdeinit5
9 9
10noblacklist ${HOME}/.local/share/Trash 10noblacklist ${HOME}/.local/share/Trash
11# noblacklist ~/.config/dolphinrc - diable-programs.inc is disabled, see below 11# noblacklist ${HOME}/.config/dolphinrc - diable-programs.inc is disabled, see below
12# noblacklist ~/.local/share/dolphin 12# noblacklist ${HOME}/.local/share/dolphin
13 13
14include /etc/firejail/disable-common.inc 14include /etc/firejail/disable-common.inc
15include /etc/firejail/disable-devel.inc 15include /etc/firejail/disable-devel.inc
diff --git a/etc/dosbox.profile b/etc/dosbox.profile
index a64578e5c..736c7da2f 100644
--- a/etc/dosbox.profile
+++ b/etc/dosbox.profile
@@ -5,7 +5,7 @@ include /etc/firejail/dosbox.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.dosbox 8noblacklist ${HOME}/.dosbox
9 9
10include /etc/firejail/disable-common.inc 10include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-devel.inc 11include /etc/firejail/disable-devel.inc
diff --git a/etc/dragon.profile b/etc/dragon.profile
index c37f81ac9..76544010f 100644
--- a/etc/dragon.profile
+++ b/etc/dragon.profile
@@ -5,7 +5,7 @@ include /etc/firejail/dragon.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.config/dragonplayerrc 8noblacklist ${HOME}/.config/dragonplayerrc
9 9
10include /etc/firejail/disable-common.inc 10include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-devel.inc 11include /etc/firejail/disable-devel.inc
diff --git a/etc/dropbox.profile b/etc/dropbox.profile
index ec268c09b..138b3912a 100644
--- a/etc/dropbox.profile
+++ b/etc/dropbox.profile
@@ -5,23 +5,23 @@ include /etc/firejail/dropbox.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.config/autostart 8noblacklist ${HOME}/.config/autostart
9noblacklist ~/.dropbox 9noblacklist ${HOME}/.dropbox
10noblacklist ~/.dropbox-dist 10noblacklist ${HOME}/.dropbox-dist
11 11
12include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-devel.inc 13include /etc/firejail/disable-devel.inc
14include /etc/firejail/disable-passwdmgr.inc 14include /etc/firejail/disable-passwdmgr.inc
15include /etc/firejail/disable-programs.inc 15include /etc/firejail/disable-programs.inc
16 16
17mkdir ~/.dropbox 17mkdir ${HOME}/.dropbox
18mkdir ~/.dropbox-dist 18mkdir ${HOME}/.dropbox-dist
19mkdir ~/Dropbox 19mkdir ${HOME}/Dropbox
20mkfile ~/.config/autostart/dropbox.desktop 20mkfile ${HOME}/.config/autostart/dropbox.desktop
21whitelist ~/.config/autostart/dropbox.desktop 21whitelist ${HOME}/.config/autostart/dropbox.desktop
22whitelist ~/.dropbox 22whitelist ${HOME}/.dropbox
23whitelist ~/.dropbox-dist 23whitelist ${HOME}/.dropbox-dist
24whitelist ~/Dropbox 24whitelist ${HOME}/Dropbox
25include /etc/firejail/whitelist-common.inc 25include /etc/firejail/whitelist-common.inc
26 26
27caps.drop all 27caps.drop all
diff --git a/etc/elinks.profile b/etc/elinks.profile
index 10fd19f71..aca30c933 100644
--- a/etc/elinks.profile
+++ b/etc/elinks.profile
@@ -7,7 +7,7 @@ include /etc/firejail/globals.local
7 7
8blacklist /tmp/.X11-unix 8blacklist /tmp/.X11-unix
9 9
10noblacklist ~/.elinks 10noblacklist ${HOME}/.elinks
11 11
12include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-devel.inc 13include /etc/firejail/disable-devel.inc
diff --git a/etc/emacs.profile b/etc/emacs.profile
index 8351d6c42..8700bc8e6 100644
--- a/etc/emacs.profile
+++ b/etc/emacs.profile
@@ -5,8 +5,8 @@ include /etc/firejail/emacs.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.emacs 8noblacklist ${HOME}/.emacs
9noblacklist ~/.emacs.d 9noblacklist ${HOME}/.emacs.d
10 10
11include /etc/firejail/disable-common.inc 11include /etc/firejail/disable-common.inc
12include /etc/firejail/disable-passwdmgr.inc 12include /etc/firejail/disable-passwdmgr.inc
diff --git a/etc/enchant.profile b/etc/enchant.profile
index b7034b937..8178bb2c8 100644
--- a/etc/enchant.profile
+++ b/etc/enchant.profile
@@ -5,7 +5,7 @@ include /etc/firejail/enchant.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.config/enchant 8noblacklist ${HOME}/.config/enchant
9 9
10include /etc/firejail/disable-common.inc 10include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-devel.inc 11include /etc/firejail/disable-devel.inc
diff --git a/etc/eog.profile b/etc/eog.profile
index c07268e14..cf6b1c1c6 100644
--- a/etc/eog.profile
+++ b/etc/eog.profile
@@ -7,10 +7,10 @@ include /etc/firejail/globals.local
7 7
8# blacklist /run/user/*/bus - makes settings immutable 8# blacklist /run/user/*/bus - makes settings immutable
9 9
10noblacklist ~/.Steam 10noblacklist ${HOME}/.Steam
11noblacklist ~/.config/eog 11noblacklist ${HOME}/.config/eog
12noblacklist ~/.local/share/Trash 12noblacklist ${HOME}/.local/share/Trash
13noblacklist ~/.steam 13noblacklist ${HOME}/.steam
14 14
15include /etc/firejail/disable-common.inc 15include /etc/firejail/disable-common.inc
16include /etc/firejail/disable-devel.inc 16include /etc/firejail/disable-devel.inc
diff --git a/etc/eom.profile b/etc/eom.profile
index 5e0008ab3..4edd8fafe 100644
--- a/etc/eom.profile
+++ b/etc/eom.profile
@@ -7,10 +7,10 @@ include /etc/firejail/globals.local
7 7
8# blacklist /run/user/*/bus - makes settings immutable 8# blacklist /run/user/*/bus - makes settings immutable
9 9
10noblacklist ~/.Steam 10noblacklist ${HOME}/.Steam
11noblacklist ~/.config/mate/eom 11noblacklist ${HOME}/.config/mate/eom
12noblacklist ~/.local/share/Trash 12noblacklist ${HOME}/.local/share/Trash
13noblacklist ~/.steam 13noblacklist ${HOME}/.steam
14 14
15include /etc/firejail/disable-common.inc 15include /etc/firejail/disable-common.inc
16include /etc/firejail/disable-devel.inc 16include /etc/firejail/disable-devel.inc
diff --git a/etc/etr.profile b/etc/etr.profile
index 579aa570a..ad2e5be5d 100644
--- a/etc/etr.profile
+++ b/etc/etr.profile
@@ -7,14 +7,14 @@ include /etc/firejail/globals.local
7 7
8blacklist /run/user/*/bus 8blacklist /run/user/*/bus
9 9
10noblacklist ~/.etr 10noblacklist ${HOME}/.etr
11 11
12include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-passwdmgr.inc 13include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc 14include /etc/firejail/disable-programs.inc
15 15
16mkdir ~/.etr 16mkdir ${HOME}/.etr
17whitelist ~/.etr 17whitelist ${HOME}/.etr
18include /etc/firejail/whitelist-common.inc 18include /etc/firejail/whitelist-common.inc
19include /etc/firejail/whitelist-var-common.inc 19include /etc/firejail/whitelist-var-common.inc
20 20
diff --git a/etc/evince.profile b/etc/evince.profile
index b68d272df..7118d3c08 100644
--- a/etc/evince.profile
+++ b/etc/evince.profile
@@ -7,7 +7,7 @@ include /etc/firejail/globals.local
7 7
8# blacklist /run/user/*/bus 8# blacklist /run/user/*/bus
9 9
10noblacklist ~/.config/evince 10noblacklist ${HOME}/.config/evince
11 11
12include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-devel.inc 13include /etc/firejail/disable-devel.inc
diff --git a/etc/evolution.profile b/etc/evolution.profile
index e74c68f63..90a0c4ec4 100644
--- a/etc/evolution.profile
+++ b/etc/evolution.profile
@@ -7,12 +7,12 @@ include /etc/firejail/globals.local
7 7
8noblacklist /var/mail 8noblacklist /var/mail
9noblacklist /var/spool/mail 9noblacklist /var/spool/mail
10# noblacklist ~/.bogofilter 10# noblacklist ${HOME}/.bogofilter
11noblacklist ~/.cache/evolution 11noblacklist ${HOME}/.cache/evolution
12noblacklist ~/.config/evolution 12noblacklist ${HOME}/.config/evolution
13noblacklist ~/.gnupg 13noblacklist ${HOME}/.gnupg
14noblacklist ~/.local/share/evolution 14noblacklist ${HOME}/.local/share/evolution
15noblacklist ~/.pki 15noblacklist ${HOME}/.pki
16 16
17include /etc/firejail/disable-common.inc 17include /etc/firejail/disable-common.inc
18include /etc/firejail/disable-devel.inc 18include /etc/firejail/disable-devel.inc
diff --git a/etc/firefox.profile b/etc/firefox.profile
index 2423b149c..b76c16385 100644
--- a/etc/firefox.profile
+++ b/etc/firefox.profile
@@ -5,67 +5,67 @@ include /etc/firejail/firefox.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.cache/mozilla 8noblacklist ${HOME}/.cache/mozilla
9noblacklist ~/.config/okularpartrc 9noblacklist ${HOME}/.config/okularpartrc
10noblacklist ~/.config/okularrc 10noblacklist ${HOME}/.config/okularrc
11noblacklist ~/.config/qpdfview 11noblacklist ${HOME}/.config/qpdfview
12noblacklist ~/.kde/share/apps/kget 12noblacklist ${HOME}/.kde/share/apps/kget
13noblacklist ~/.kde/share/apps/okular 13noblacklist ${HOME}/.kde/share/apps/okular
14noblacklist ~/.kde/share/config/kgetrc 14noblacklist ${HOME}/.kde/share/config/kgetrc
15noblacklist ~/.kde/share/config/okularpartrc 15noblacklist ${HOME}/.kde/share/config/okularpartrc
16noblacklist ~/.kde/share/config/okularrc 16noblacklist ${HOME}/.kde/share/config/okularrc
17noblacklist ~/.kde4/share/apps/kget 17noblacklist ${HOME}/.kde4/share/apps/kget
18noblacklist ~/.kde4/share/apps/okular 18noblacklist ${HOME}/.kde4/share/apps/okular
19noblacklist ~/.kde4/share/config/kgetrc 19noblacklist ${HOME}/.kde4/share/config/kgetrc
20noblacklist ~/.kde4/share/config/okularpartrc 20noblacklist ${HOME}/.kde4/share/config/okularpartrc
21noblacklist ~/.kde4/share/config/okularrc 21noblacklist ${HOME}/.kde4/share/config/okularrc
22# noblacklist ~/.local/share/gnome-shell/extensions 22# noblacklist ${HOME}/.local/share/gnome-shell/extensions
23noblacklist ~/.local/share/okular 23noblacklist ${HOME}/.local/share/okular
24noblacklist ~/.local/share/qpdfview 24noblacklist ${HOME}/.local/share/qpdfview
25noblacklist ~/.mozilla 25noblacklist ${HOME}/.mozilla
26noblacklist ~/.pki 26noblacklist ${HOME}/.pki
27 27
28include /etc/firejail/disable-common.inc 28include /etc/firejail/disable-common.inc
29include /etc/firejail/disable-devel.inc 29include /etc/firejail/disable-devel.inc
30include /etc/firejail/disable-programs.inc 30include /etc/firejail/disable-programs.inc
31 31
32mkdir ~/.cache/mozilla/firefox 32mkdir ${HOME}/.cache/mozilla/firefox
33mkdir ~/.mozilla 33mkdir ${HOME}/.mozilla
34mkdir ~/.pki 34mkdir ${HOME}/.pki
35whitelist ${DOWNLOADS} 35whitelist ${DOWNLOADS}
36whitelist ~/.cache/gnome-mplayer/plugin 36whitelist ${HOME}/.cache/gnome-mplayer/plugin
37whitelist ~/.cache/mozilla/firefox 37whitelist ${HOME}/.cache/mozilla/firefox
38whitelist ~/.config/gnome-mplayer 38whitelist ${HOME}/.config/gnome-mplayer
39whitelist ~/.config/okularpartrc 39whitelist ${HOME}/.config/okularpartrc
40whitelist ~/.config/okularrc 40whitelist ${HOME}/.config/okularrc
41whitelist ~/.config/pipelight-silverlight5.1 41whitelist ${HOME}/.config/pipelight-silverlight5.1
42whitelist ~/.config/pipelight-widevine 42whitelist ${HOME}/.config/pipelight-widevine
43whitelist ~/.config/qpdfview 43whitelist ${HOME}/.config/qpdfview
44whitelist ~/.kde/share/apps/kget 44whitelist ${HOME}/.kde/share/apps/kget
45whitelist ~/.kde/share/apps/okular 45whitelist ${HOME}/.kde/share/apps/okular
46whitelist ~/.kde/share/config/kgetrc 46whitelist ${HOME}/.kde/share/config/kgetrc
47whitelist ~/.kde/share/config/okularpartrc 47whitelist ${HOME}/.kde/share/config/okularpartrc
48whitelist ~/.kde/share/config/okularrc 48whitelist ${HOME}/.kde/share/config/okularrc
49whitelist ~/.kde4/share/apps/kget 49whitelist ${HOME}/.kde4/share/apps/kget
50whitelist ~/.kde4/share/apps/okular 50whitelist ${HOME}/.kde4/share/apps/okular
51whitelist ~/.kde4/share/config/kgetrc 51whitelist ${HOME}/.kde4/share/config/kgetrc
52whitelist ~/.kde4/share/config/okularpartrc 52whitelist ${HOME}/.kde4/share/config/okularpartrc
53whitelist ~/.kde4/share/config/okularrc 53whitelist ${HOME}/.kde4/share/config/okularrc
54whitelist ~/.keysnail.js 54whitelist ${HOME}/.keysnail.js
55whitelist ~/.lastpass 55whitelist ${HOME}/.lastpass
56whitelist ~/.local/share/gnome-shell/extensions 56whitelist ${HOME}/.local/share/gnome-shell/extensions
57whitelist ~/.local/share/okular 57whitelist ${HOME}/.local/share/okular
58whitelist ~/.local/share/qpdfview 58whitelist ${HOME}/.local/share/qpdfview
59whitelist ~/.mozilla 59whitelist ${HOME}/.mozilla
60whitelist ~/.pentadactyl 60whitelist ${HOME}/.pentadactyl
61whitelist ~/.pentadactylrc 61whitelist ${HOME}/.pentadactylrc
62whitelist ~/.pki 62whitelist ${HOME}/.pki
63whitelist ~/.vimperator 63whitelist ${HOME}/.vimperator
64whitelist ~/.vimperatorrc 64whitelist ${HOME}/.vimperatorrc
65whitelist ~/.wine-pipelight 65whitelist ${HOME}/.wine-pipelight
66whitelist ~/.wine-pipelight64 66whitelist ${HOME}/.wine-pipelight64
67whitelist ~/.zotero 67whitelist ${HOME}/.zotero
68whitelist ~/dwhelper 68whitelist ${HOME}/dwhelper
69include /etc/firejail/whitelist-common.inc 69include /etc/firejail/whitelist-common.inc
70include /etc/firejail/whitelist-var-common.inc 70include /etc/firejail/whitelist-var-common.inc
71 71
diff --git a/etc/flashpeak-slimjet.profile b/etc/flashpeak-slimjet.profile
index 18db4c597..feb4087f4 100644
--- a/etc/flashpeak-slimjet.profile
+++ b/etc/flashpeak-slimjet.profile
@@ -10,21 +10,21 @@ include /etc/firejail/globals.local
10# to run it is as follows: 10# to run it is as follows:
11# firejail flashpeak-slimjet --no-sandbox 11# firejail flashpeak-slimjet --no-sandbox
12 12
13noblacklist ~/.cache/slimjet 13noblacklist ${HOME}/.cache/slimjet
14noblacklist ~/.config/slimjet 14noblacklist ${HOME}/.config/slimjet
15noblacklist ~/.pki 15noblacklist ${HOME}/.pki
16 16
17include /etc/firejail/disable-common.inc 17include /etc/firejail/disable-common.inc
18include /etc/firejail/disable-devel.inc 18include /etc/firejail/disable-devel.inc
19include /etc/firejail/disable-programs.inc 19include /etc/firejail/disable-programs.inc
20 20
21mkdir ~/.cache/slimjet 21mkdir ${HOME}/.cache/slimjet
22mkdir ~/.config/slimjet 22mkdir ${HOME}/.config/slimjet
23mkdir ~/.pki 23mkdir ${HOME}/.pki
24whitelist ${DOWNLOADS} 24whitelist ${DOWNLOADS}
25whitelist ~/.cache/slimjet 25whitelist ${HOME}/.cache/slimjet
26whitelist ~/.config/slimjet 26whitelist ${HOME}/.config/slimjet
27whitelist ~/.pki 27whitelist ${HOME}/.pki
28include /etc/firejail/whitelist-common.inc 28include /etc/firejail/whitelist-common.inc
29 29
30caps.drop all 30caps.drop all
diff --git a/etc/fossamail.profile b/etc/fossamail.profile
index cef522c53..4316c0988 100644
--- a/etc/fossamail.profile
+++ b/etc/fossamail.profile
@@ -5,16 +5,16 @@ include /etc/firejail/fossamail.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.cache/fossamail 8noblacklist ${HOME}/.cache/fossamail
9noblacklist ~/.fossamail 9noblacklist ${HOME}/.fossamail
10noblacklist ~/.gnupg 10noblacklist ${HOME}/.gnupg
11 11
12mkdir ~/.cache/fossamail 12mkdir ${HOME}/.cache/fossamail
13mkdir ~/.fossamail 13mkdir ${HOME}/.fossamail
14mkdir ~/.gnupg 14mkdir ${HOME}/.gnupg
15whitelist ~/.cache/fossamail 15whitelist ${HOME}/.cache/fossamail
16whitelist ~/.fossamail 16whitelist ${HOME}/.fossamail
17whitelist ~/.gnupg 17whitelist ${HOME}/.gnupg
18include /etc/firejail/whitelist-common.inc 18include /etc/firejail/whitelist-common.inc
19 19
20# allow browsers 20# allow browsers
diff --git a/etc/franz.profile b/etc/franz.profile
index bceeaf3b4..42b14fa2f 100644
--- a/etc/franz.profile
+++ b/etc/franz.profile
@@ -5,21 +5,21 @@ include /etc/firejail/franz.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.cache/Franz 8noblacklist ${HOME}/.cache/Franz
9noblacklist ~/.config/Franz 9noblacklist ${HOME}/.config/Franz
10noblacklist ~/.pki 10noblacklist ${HOME}/.pki
11 11
12include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-devel.inc 13include /etc/firejail/disable-devel.inc
14include /etc/firejail/disable-programs.inc 14include /etc/firejail/disable-programs.inc
15 15
16mkdir ~/.cache/Franz 16mkdir ${HOME}/.cache/Franz
17mkdir ~/.config/Franz 17mkdir ${HOME}/.config/Franz
18mkdir ~/.pki 18mkdir ${HOME}/.pki
19whitelist ${DOWNLOADS} 19whitelist ${DOWNLOADS}
20whitelist ~/.cache/Franz 20whitelist ${HOME}/.cache/Franz
21whitelist ~/.config/Franz 21whitelist ${HOME}/.config/Franz
22whitelist ~/.pki 22whitelist ${HOME}/.pki
23include /etc/firejail/whitelist-common.inc 23include /etc/firejail/whitelist-common.inc
24 24
25caps.drop all 25caps.drop all
diff --git a/etc/frozen-bubble.profile b/etc/frozen-bubble.profile
index 0480faf6f..0660137e0 100644
--- a/etc/frozen-bubble.profile
+++ b/etc/frozen-bubble.profile
@@ -7,14 +7,14 @@ include /etc/firejail/globals.local
7 7
8blacklist /run/user/*/bus 8blacklist /run/user/*/bus
9 9
10noblacklist ~/.frozen-bubble 10noblacklist ${HOME}/.frozen-bubble
11 11
12include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-passwdmgr.inc 13include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc 14include /etc/firejail/disable-programs.inc
15 15
16mkdir ~/.frozen-bubble 16mkdir ${HOME}/.frozen-bubble
17whitelist ~/.frozen-bubble 17whitelist ${HOME}/.frozen-bubble
18include /etc/firejail/whitelist-common.inc 18include /etc/firejail/whitelist-common.inc
19include /etc/firejail/whitelist-var-common.inc 19include /etc/firejail/whitelist-var-common.inc
20 20
diff --git a/etc/galculator.profile b/etc/galculator.profile
index fdb9e3f1d..0923d7e55 100644
--- a/etc/galculator.profile
+++ b/etc/galculator.profile
@@ -7,15 +7,15 @@ include /etc/firejail/globals.local
7 7
8blacklist /run/user/*/bus 8blacklist /run/user/*/bus
9 9
10noblacklist ~/.config/galculator 10noblacklist ${HOME}/.config/galculator
11 11
12include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-devel.inc 13include /etc/firejail/disable-devel.inc
14include /etc/firejail/disable-passwdmgr.inc 14include /etc/firejail/disable-passwdmgr.inc
15include /etc/firejail/disable-programs.inc 15include /etc/firejail/disable-programs.inc
16 16
17mkdir ~/.config/galculator 17mkdir ${HOME}/.config/galculator
18whitelist ~/.config/galculator 18whitelist ${HOME}/.config/galculator
19include /etc/firejail/whitelist-common.inc 19include /etc/firejail/whitelist-common.inc
20include /etc/firejail/whitelist-var-common.inc 20include /etc/firejail/whitelist-var-common.inc
21 21
diff --git a/etc/geary.profile b/etc/geary.profile
index 3ab4a21d8..36c00efa0 100644
--- a/etc/geary.profile
+++ b/etc/geary.profile
@@ -8,18 +8,18 @@ include /etc/firejail/globals.local
8# Users have Geary set to open a browser by clicking a link in an email 8# Users have Geary set to open a browser by clicking a link in an email
9# We are not allowed to blacklist browser-specific directories 9# We are not allowed to blacklist browser-specific directories
10 10
11noblacklist ~/.gnupg 11noblacklist ${HOME}/.gnupg
12noblacklist ~/.local/share/geary 12noblacklist ${HOME}/.local/share/geary
13 13
14mkdir ~/.gnupg 14mkdir ${HOME}/.gnupg
15mkdir ~/.local/share/geary 15mkdir ${HOME}/.local/share/geary
16whitelist ~/.gnupg 16whitelist ${HOME}/.gnupg
17whitelist ~/.local/share/geary 17whitelist ${HOME}/.local/share/geary
18include /etc/firejail/whitelist-common.inc 18include /etc/firejail/whitelist-common.inc
19 19
20ignore private-tmp 20ignore private-tmp
21 21
22read-only ~/.config/mimeapps.list 22read-only ${HOME}/.config/mimeapps.list
23 23
24# allow browsers 24# allow browsers
25# Redirect 25# Redirect
diff --git a/etc/geeqie.profile b/etc/geeqie.profile
index a50fd4370..27ee343af 100644
--- a/etc/geeqie.profile
+++ b/etc/geeqie.profile
@@ -5,9 +5,9 @@ include /etc/firejail/geeqie.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.cache/geeqie 8noblacklist ${HOME}/.cache/geeqie
9noblacklist ~/.config/geeqie 9noblacklist ${HOME}/.config/geeqie
10noblacklist ~/.local/share/geeqie 10noblacklist ${HOME}/.local/share/geeqie
11 11
12include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-devel.inc 13include /etc/firejail/disable-devel.inc
diff --git a/etc/gimp.profile b/etc/gimp.profile
index b398813f6..2a0698cc3 100644
--- a/etc/gimp.profile
+++ b/etc/gimp.profile
@@ -30,7 +30,7 @@ shell none
30private-dev 30private-dev
31private-tmp 31private-tmp
32 32
33# gimp plugins are installed by the user in ~/.gimp-2.8/plug-ins/ directory 33# gimp plugins are installed by the user in ${HOME}/.gimp-2.8/plug-ins/ directory
34# if you are not using external plugins, you can enable noexec statement below 34# if you are not using external plugins, you can enable noexec statement below
35# noexec ${HOME} 35# noexec ${HOME}
36noexec /tmp 36noexec /tmp
diff --git a/etc/git.profile b/etc/git.profile
index 14fb55118..7dac03b1b 100644
--- a/etc/git.profile
+++ b/etc/git.profile
@@ -8,13 +8,13 @@ include /etc/firejail/globals.local
8 8
9blacklist /tmp/.X11-unix 9blacklist /tmp/.X11-unix
10 10
11noblacklist ~/.emacs 11noblacklist ${HOME}/.emacs
12noblacklist ~/.emacs.d 12noblacklist ${HOME}/.emacs.d
13noblacklist ~/.gitconfig 13noblacklist ${HOME}/.gitconfig
14noblacklist ~/.gnupg 14noblacklist ${HOME}/.gnupg
15noblacklist ~/.ssh 15noblacklist ${HOME}/.ssh
16noblacklist ~/.vim 16noblacklist ${HOME}/.vim
17noblacklist ~/.viminfo 17noblacklist ${HOME}/.viminfo
18 18
19include /etc/firejail/disable-common.inc 19include /etc/firejail/disable-common.inc
20include /etc/firejail/disable-passwdmgr.inc 20include /etc/firejail/disable-passwdmgr.inc
diff --git a/etc/gitter.profile b/etc/gitter.profile
index 3e84455f1..a3bbabd10 100644
--- a/etc/gitter.profile
+++ b/etc/gitter.profile
@@ -5,8 +5,8 @@ include /etc/firejail/gitter.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.config/autostart 8noblacklist ${HOME}/.config/autostart
9noblacklist ~/.config/Gitter 9noblacklist ${HOME}/.config/Gitter
10 10
11include /etc/firejail/disable-common.inc 11include /etc/firejail/disable-common.inc
12include /etc/firejail/disable-devel.inc 12include /etc/firejail/disable-devel.inc
@@ -14,8 +14,8 @@ include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc 14include /etc/firejail/disable-programs.inc
15 15
16whitelist ${DOWNLOADS} 16whitelist ${DOWNLOADS}
17whitelist ~/.config/autostart 17whitelist ${HOME}/.config/autostart
18whitelist ~/.config/Gitter 18whitelist ${HOME}/.config/Gitter
19include /etc/firejail/whitelist-var-common.inc 19include /etc/firejail/whitelist-var-common.inc
20 20
21caps.drop all 21caps.drop all
diff --git a/etc/gjs.profile b/etc/gjs.profile
index a856d35b5..32faeb8df 100644
--- a/etc/gjs.profile
+++ b/etc/gjs.profile
@@ -7,10 +7,10 @@ include /etc/firejail/globals.local
7 7
8# when gjs apps are started via gnome-shell, firejail is not applied because systemd will start them 8# when gjs apps are started via gnome-shell, firejail is not applied because systemd will start them
9 9
10noblacklist ~/.cache/libgweather 10noblacklist ${HOME}/.cache/libgweather
11noblacklist ~/.cache/org.gnome.Books 11noblacklist ${HOME}/.cache/org.gnome.Books
12noblacklist ~/.config/libreoffice 12noblacklist ${HOME}/.config/libreoffice
13noblacklist ~/.local/share/gnome-photos 13noblacklist ${HOME}/.local/share/gnome-photos
14 14
15include /etc/firejail/disable-common.inc 15include /etc/firejail/disable-common.inc
16include /etc/firejail/disable-devel.inc 16include /etc/firejail/disable-devel.inc
diff --git a/etc/gnome-books.profile b/etc/gnome-books.profile
index 6998a3a42..bd21cd39f 100644
--- a/etc/gnome-books.profile
+++ b/etc/gnome-books.profile
@@ -7,7 +7,7 @@ include /etc/firejail/globals.local
7 7
8# when gjs apps are started via gnome-shell, firejail is not applied because systemd will start them 8# when gjs apps are started via gnome-shell, firejail is not applied because systemd will start them
9 9
10noblacklist ~/.cache/org.gnome.Books 10noblacklist ${HOME}/.cache/org.gnome.Books
11 11
12include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-devel.inc 13include /etc/firejail/disable-devel.inc
diff --git a/etc/gnome-chess.profile b/etc/gnome-chess.profile
index 4caf971dd..f1f04d889 100644
--- a/etc/gnome-chess.profile
+++ b/etc/gnome-chess.profile
@@ -5,7 +5,7 @@ include /etc/firejail/gnome-chess.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.local/share/gnome-chess 8noblacklist ${HOME}/.local/share/gnome-chess
9 9
10include /etc/firejail/disable-common.inc 10include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-devel.inc 11include /etc/firejail/disable-devel.inc
diff --git a/etc/gnome-documents.profile b/etc/gnome-documents.profile
index 3254f3fbc..40bb63538 100644
--- a/etc/gnome-documents.profile
+++ b/etc/gnome-documents.profile
@@ -7,7 +7,7 @@ include /etc/firejail/globals.local
7 7
8# when gjs apps are started via gnome-shell, firejail is not applied because systemd will start them 8# when gjs apps are started via gnome-shell, firejail is not applied because systemd will start them
9 9
10noblacklist ~/.config/libreoffice 10noblacklist ${HOME}/.config/libreoffice
11 11
12include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-devel.inc 13include /etc/firejail/disable-devel.inc
diff --git a/etc/gnome-mplayer.profile b/etc/gnome-mplayer.profile
index 166994374..c9626950e 100644
--- a/etc/gnome-mplayer.profile
+++ b/etc/gnome-mplayer.profile
@@ -5,7 +5,7 @@ include /etc/firejail/gnome-mplayer.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.config/gnome-mplayer 8noblacklist ${HOME}/.config/gnome-mplayer
9 9
10include /etc/firejail/disable-common.inc 10include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-devel.inc 11include /etc/firejail/disable-devel.inc
diff --git a/etc/gnome-music.profile b/etc/gnome-music.profile
index 17288d500..f052563be 100644
--- a/etc/gnome-music.profile
+++ b/etc/gnome-music.profile
@@ -5,7 +5,7 @@ include /etc/firejail/gnome-music.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.local/share/gnome-music 8noblacklist ${HOME}/.local/share/gnome-music
9 9
10include /etc/firejail/disable-common.inc 10include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-devel.inc 11include /etc/firejail/disable-devel.inc
diff --git a/etc/gnome-photos.profile b/etc/gnome-photos.profile
index f9be4c4de..f3b00a868 100644
--- a/etc/gnome-photos.profile
+++ b/etc/gnome-photos.profile
@@ -7,7 +7,7 @@ include /etc/firejail/globals.local
7 7
8# when gjs apps are started via gnome-shell, firejail is not applied because systemd will start them 8# when gjs apps are started via gnome-shell, firejail is not applied because systemd will start them
9 9
10noblacklist ~/.local/share/gnome-photos 10noblacklist ${HOME}/.local/share/gnome-photos
11 11
12include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-devel.inc 13include /etc/firejail/disable-devel.inc
diff --git a/etc/gnome-weather.profile b/etc/gnome-weather.profile
index e5804687c..0423b06dd 100644
--- a/etc/gnome-weather.profile
+++ b/etc/gnome-weather.profile
@@ -7,7 +7,7 @@ include /etc/firejail/globals.local
7 7
8# when gjs apps are started via gnome-shell, firejail is not applied because systemd will start them 8# when gjs apps are started via gnome-shell, firejail is not applied because systemd will start them
9 9
10noblacklist ~/.cache/libgweather 10noblacklist ${HOME}/.cache/libgweather
11 11
12include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-devel.inc 13include /etc/firejail/disable-devel.inc
diff --git a/etc/google-chrome-beta.profile b/etc/google-chrome-beta.profile
index ac457b92f..9c7306b85 100644
--- a/etc/google-chrome-beta.profile
+++ b/etc/google-chrome-beta.profile
@@ -5,21 +5,21 @@ include /etc/firejail/google-chrome-beta.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.cache/google-chrome-beta 8noblacklist ${HOME}/.cache/google-chrome-beta
9noblacklist ~/.config/google-chrome-beta 9noblacklist ${HOME}/.config/google-chrome-beta
10noblacklist ~/.pki 10noblacklist ${HOME}/.pki
11 11
12include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-devel.inc 13include /etc/firejail/disable-devel.inc
14include /etc/firejail/disable-programs.inc 14include /etc/firejail/disable-programs.inc
15 15
16mkdir ~/.cache/google-chrome-beta 16mkdir ${HOME}/.cache/google-chrome-beta
17mkdir ~/.config/google-chrome-beta 17mkdir ${HOME}/.config/google-chrome-beta
18mkdir ~/.pki 18mkdir ${HOME}/.pki
19whitelist ${DOWNLOADS} 19whitelist ${DOWNLOADS}
20whitelist ~/.cache/google-chrome-beta 20whitelist ${HOME}/.cache/google-chrome-beta
21whitelist ~/.config/google-chrome-beta 21whitelist ${HOME}/.config/google-chrome-beta
22whitelist ~/.pki 22whitelist ${HOME}/.pki
23include /etc/firejail/whitelist-common.inc 23include /etc/firejail/whitelist-common.inc
24 24
25caps.keep sys_chroot,sys_admin 25caps.keep sys_chroot,sys_admin
diff --git a/etc/google-chrome-unstable.profile b/etc/google-chrome-unstable.profile
index 3d7a9a715..bb05b3e99 100644
--- a/etc/google-chrome-unstable.profile
+++ b/etc/google-chrome-unstable.profile
@@ -5,21 +5,21 @@ include /etc/firejail/google-chrome-unstable.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.cache/google-chrome-unstable 8noblacklist ${HOME}/.cache/google-chrome-unstable
9noblacklist ~/.config/google-chrome-unstable 9noblacklist ${HOME}/.config/google-chrome-unstable
10noblacklist ~/.pki 10noblacklist ${HOME}/.pki
11 11
12include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-devel.inc 13include /etc/firejail/disable-devel.inc
14include /etc/firejail/disable-programs.inc 14include /etc/firejail/disable-programs.inc
15 15
16mkdir ~/.cache/google-chrome-unstable 16mkdir ${HOME}/.cache/google-chrome-unstable
17mkdir ~/.config/google-chrome-unstable 17mkdir ${HOME}/.config/google-chrome-unstable
18mkdir ~/.pki 18mkdir ${HOME}/.pki
19whitelist ${DOWNLOADS} 19whitelist ${DOWNLOADS}
20whitelist ~/.cache/google-chrome-unstable 20whitelist ${HOME}/.cache/google-chrome-unstable
21whitelist ~/.config/google-chrome-unstable 21whitelist ${HOME}/.config/google-chrome-unstable
22whitelist ~/.pki 22whitelist ${HOME}/.pki
23include /etc/firejail/whitelist-common.inc 23include /etc/firejail/whitelist-common.inc
24 24
25caps.keep sys_chroot,sys_admin 25caps.keep sys_chroot,sys_admin
diff --git a/etc/google-chrome.profile b/etc/google-chrome.profile
index 6e5175989..2e9524e16 100644
--- a/etc/google-chrome.profile
+++ b/etc/google-chrome.profile
@@ -5,21 +5,21 @@ include /etc/firejail/google-chrome.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.cache/google-chrome 8noblacklist ${HOME}/.cache/google-chrome
9noblacklist ~/.config/google-chrome 9noblacklist ${HOME}/.config/google-chrome
10noblacklist ~/.pki 10noblacklist ${HOME}/.pki
11 11
12include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-devel.inc 13include /etc/firejail/disable-devel.inc
14include /etc/firejail/disable-programs.inc 14include /etc/firejail/disable-programs.inc
15 15
16mkdir ~/.cache/google-chrome 16mkdir ${HOME}/.cache/google-chrome
17mkdir ~/.config/google-chrome 17mkdir ${HOME}/.config/google-chrome
18mkdir ~/.pki 18mkdir ${HOME}/.pki
19whitelist ${DOWNLOADS} 19whitelist ${DOWNLOADS}
20whitelist ~/.cache/google-chrome 20whitelist ${HOME}/.cache/google-chrome
21whitelist ~/.config/google-chrome 21whitelist ${HOME}/.config/google-chrome
22whitelist ~/.pki 22whitelist ${HOME}/.pki
23include /etc/firejail/whitelist-common.inc 23include /etc/firejail/whitelist-common.inc
24include /etc/firejail/whitelist-var-common.inc 24include /etc/firejail/whitelist-var-common.inc
25 25
diff --git a/etc/google-play-music-desktop-player.profile b/etc/google-play-music-desktop-player.profile
index 11ca13090..58473d5c8 100644
--- a/etc/google-play-music-desktop-player.profile
+++ b/etc/google-play-music-desktop-player.profile
@@ -5,16 +5,16 @@ include /etc/firejail/google-play-music-desktop-player.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.config/Google Play Music Desktop Player 8noblacklist ${HOME}/.config/Google Play Music Desktop Player
9 9
10include /etc/firejail/disable-common.inc 10include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-devel.inc 11include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-passwdmgr.inc 12include /etc/firejail/disable-passwdmgr.inc
13include /etc/firejail/disable-programs.inc 13include /etc/firejail/disable-programs.inc
14 14
15# whitelist ~/.config/pulse 15# whitelist ${HOME}/.config/pulse
16# whitelist ~/.pulse 16# whitelist ${HOME}/.pulse
17whitelist ~/.config/Google Play Music Desktop Player 17whitelist ${HOME}/.config/Google Play Music Desktop Player
18include /etc/firejail/whitelist-common.inc 18include /etc/firejail/whitelist-common.inc
19 19
20caps.drop all 20caps.drop all
diff --git a/etc/gpa.profile b/etc/gpa.profile
index 8d721e2c0..725c744ed 100644
--- a/etc/gpa.profile
+++ b/etc/gpa.profile
@@ -5,7 +5,7 @@ include /etc/firejail/gpa.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.gnupg 8noblacklist ${HOME}/.gnupg
9 9
10include /etc/firejail/disable-common.inc 10include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-devel.inc 11include /etc/firejail/disable-devel.inc
diff --git a/etc/gpg-agent.profile b/etc/gpg-agent.profile
index 8fd2ce232..c59c624fc 100644
--- a/etc/gpg-agent.profile
+++ b/etc/gpg-agent.profile
@@ -7,7 +7,7 @@ include /etc/firejail/globals.local
7 7
8blacklist /tmp/.X11-unix 8blacklist /tmp/.X11-unix
9 9
10noblacklist ~/.gnupg 10noblacklist ${HOME}/.gnupg
11 11
12include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-devel.inc 13include /etc/firejail/disable-devel.inc
diff --git a/etc/gpg.profile b/etc/gpg.profile
index 8c39f85e3..cd2b30e9e 100644
--- a/etc/gpg.profile
+++ b/etc/gpg.profile
@@ -7,7 +7,7 @@ include /etc/firejail/globals.local
7 7
8blacklist /tmp/.X11-unix 8blacklist /tmp/.X11-unix
9 9
10noblacklist ~/.gnupg 10noblacklist ${HOME}/.gnupg
11 11
12include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-devel.inc 13include /etc/firejail/disable-devel.inc
diff --git a/etc/gpicview.profile b/etc/gpicview.profile
index 5ed447ac4..8d47d9c31 100644
--- a/etc/gpicview.profile
+++ b/etc/gpicview.profile
@@ -7,7 +7,7 @@ include /etc/firejail/globals.local
7 7
8blacklist /run/user/*/bus 8blacklist /run/user/*/bus
9 9
10noblacklist ~/.config/gpicview 10noblacklist ${HOME}/.config/gpicview
11 11
12include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-devel.inc 13include /etc/firejail/disable-devel.inc
diff --git a/etc/gpredict.profile b/etc/gpredict.profile
index f204366c5..029c37290 100644
--- a/etc/gpredict.profile
+++ b/etc/gpredict.profile
@@ -5,14 +5,14 @@ include /etc/firejail/gpredict.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.config/Gpredict 8noblacklist ${HOME}/.config/Gpredict
9 9
10include /etc/firejail/disable-common.inc 10include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-devel.inc 11include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-passwdmgr.inc 12include /etc/firejail/disable-passwdmgr.inc
13include /etc/firejail/disable-programs.inc 13include /etc/firejail/disable-programs.inc
14 14
15whitelist ~/.config/Gpredict 15whitelist ${HOME}/.config/Gpredict
16include /etc/firejail/whitelist-common.inc 16include /etc/firejail/whitelist-common.inc
17 17
18caps.drop all 18caps.drop all
diff --git a/etc/gthumb.profile b/etc/gthumb.profile
index 287e214e1..5d066c141 100644
--- a/etc/gthumb.profile
+++ b/etc/gthumb.profile
@@ -6,8 +6,8 @@ include /etc/firejail/gthumb.local
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ${HOME}/.config/gthumb 8noblacklist ${HOME}/.config/gthumb
9noblacklist ~/.Steam 9noblacklist ${HOME}/.Steam
10noblacklist ~/.steam 10noblacklist ${HOME}/.steam
11 11
12include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-devel.inc 13include /etc/firejail/disable-devel.inc
diff --git a/etc/gwenview.profile b/etc/gwenview.profile
index 891c9865e..efaf94f4c 100644
--- a/etc/gwenview.profile
+++ b/etc/gwenview.profile
@@ -7,15 +7,15 @@ include /etc/firejail/globals.local
7 7
8# blacklist /run/user/*/bus 8# blacklist /run/user/*/bus
9 9
10noblacklist ~/.config/gwenviewrc 10noblacklist ${HOME}/.config/gwenviewrc
11noblacklist ~/.config/org.kde.gwenviewrc 11noblacklist ${HOME}/.config/org.kde.gwenviewrc
12noblacklist ~/.gimp* 12noblacklist ${HOME}/.gimp*
13noblacklist ~/.kde/share/apps/gwenview 13noblacklist ${HOME}/.kde/share/apps/gwenview
14noblacklist ~/.kde/share/config/gwenviewrc 14noblacklist ${HOME}/.kde/share/config/gwenviewrc
15noblacklist ~/.kde4/share/apps/gwenview 15noblacklist ${HOME}/.kde4/share/apps/gwenview
16noblacklist ~/.kde4/share/config/gwenviewrc 16noblacklist ${HOME}/.kde4/share/config/gwenviewrc
17noblacklist ~/.local/share/gwenview 17noblacklist ${HOME}/.local/share/gwenview
18noblacklist ~/.local/share/org.kde.gwenview 18noblacklist ${HOME}/.local/share/org.kde.gwenview
19 19
20include /etc/firejail/disable-common.inc 20include /etc/firejail/disable-common.inc
21include /etc/firejail/disable-devel.inc 21include /etc/firejail/disable-devel.inc
diff --git a/etc/handbrake.profile b/etc/handbrake.profile
index 5235e91f2..f8554d50c 100644
--- a/etc/handbrake.profile
+++ b/etc/handbrake.profile
@@ -5,7 +5,7 @@ include /etc/firejail/handbrake.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.config/ghb 8noblacklist ${HOME}/.config/ghb
9 9
10include /etc/firejail/disable-common.inc 10include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-devel.inc 11include /etc/firejail/disable-devel.inc
diff --git a/etc/hedgewars.profile b/etc/hedgewars.profile
index e2775ffce..6f9117fae 100644
--- a/etc/hedgewars.profile
+++ b/etc/hedgewars.profile
@@ -12,8 +12,8 @@ include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-passwdmgr.inc 12include /etc/firejail/disable-passwdmgr.inc
13include /etc/firejail/disable-programs.inc 13include /etc/firejail/disable-programs.inc
14 14
15mkdir ~/.hedgewars 15mkdir ${HOME}/.hedgewars
16whitelist ~/.hedgewars 16whitelist ${HOME}/.hedgewars
17include /etc/firejail/whitelist-common.inc 17include /etc/firejail/whitelist-common.inc
18 18
19caps.drop all 19caps.drop all
diff --git a/etc/hexchat.profile b/etc/hexchat.profile
index 5945665cc..634ced575 100644
--- a/etc/hexchat.profile
+++ b/etc/hexchat.profile
@@ -13,8 +13,8 @@ include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-devel.inc 13include /etc/firejail/disable-devel.inc
14include /etc/firejail/disable-programs.inc 14include /etc/firejail/disable-programs.inc
15 15
16mkdir ~/.config/hexchat 16mkdir ${HOME}/.config/hexchat
17whitelist ~/.config/hexchat 17whitelist ${HOME}/.config/hexchat
18include /etc/firejail/whitelist-common.inc 18include /etc/firejail/whitelist-common.inc
19include /etc/firejail/whitelist-var-common.inc 19include /etc/firejail/whitelist-var-common.inc
20 20
diff --git a/etc/icecat.profile b/etc/icecat.profile
index ab7e62180..74c51926a 100644
--- a/etc/icecat.profile
+++ b/etc/icecat.profile
@@ -5,34 +5,34 @@ include /etc/firejail/icecat.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.cache/mozilla 8noblacklist ${HOME}/.cache/mozilla
9noblacklist ~/.mozilla 9noblacklist ${HOME}/.mozilla
10noblacklist ~/.pki 10noblacklist ${HOME}/.pki
11 11
12include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-devel.inc 13include /etc/firejail/disable-devel.inc
14include /etc/firejail/disable-programs.inc 14include /etc/firejail/disable-programs.inc
15 15
16mkdir ~/.cache/mozilla/icecat 16mkdir ${HOME}/.cache/mozilla/icecat
17mkdir ~/.mozilla 17mkdir ${HOME}/.mozilla
18whitelist ${DOWNLOADS} 18whitelist ${DOWNLOADS}
19whitelist ~/.cache/gnome-mplayer/plugin 19whitelist ${HOME}/.cache/gnome-mplayer/plugin
20whitelist ~/.cache/mozilla/icecat 20whitelist ${HOME}/.cache/mozilla/icecat
21whitelist ~/.config/gnome-mplayer 21whitelist ${HOME}/.config/gnome-mplayer
22whitelist ~/.config/pipelight-silverlight5.1 22whitelist ${HOME}/.config/pipelight-silverlight5.1
23whitelist ~/.config/pipelight-widevine 23whitelist ${HOME}/.config/pipelight-widevine
24whitelist ~/.keysnail.js 24whitelist ${HOME}/.keysnail.js
25whitelist ~/.lastpass 25whitelist ${HOME}/.lastpass
26whitelist ~/.mozilla 26whitelist ${HOME}/.mozilla
27whitelist ~/.pentadactyl 27whitelist ${HOME}/.pentadactyl
28whitelist ~/.pentadactylrc 28whitelist ${HOME}/.pentadactylrc
29whitelist ~/.pki 29whitelist ${HOME}/.pki
30whitelist ~/.vimperator 30whitelist ${HOME}/.vimperator
31whitelist ~/.vimperatorrc 31whitelist ${HOME}/.vimperatorrc
32whitelist ~/.wine-pipelight 32whitelist ${HOME}/.wine-pipelight
33whitelist ~/.wine-pipelight64 33whitelist ${HOME}/.wine-pipelight64
34whitelist ~/.zotero 34whitelist ${HOME}/.zotero
35whitelist ~/dwhelper 35whitelist ${HOME}/dwhelper
36include /etc/firejail/whitelist-common.inc 36include /etc/firejail/whitelist-common.inc
37 37
38caps.drop all 38caps.drop all
diff --git a/etc/icedove.profile b/etc/icedove.profile
index 46861d9f2..80cff3878 100644
--- a/etc/icedove.profile
+++ b/etc/icedove.profile
@@ -8,16 +8,16 @@ include /etc/firejail/globals.local
8# Users have icedove set to open a browser by clicking a link in an email 8# Users have icedove set to open a browser by clicking a link in an email
9# We are not allowed to blacklist browser-specific directories 9# We are not allowed to blacklist browser-specific directories
10 10
11noblacklist ~/.cache/icedove 11noblacklist ${HOME}/.cache/icedove
12noblacklist ~/.gnupg 12noblacklist ${HOME}/.gnupg
13noblacklist ~/.icedove 13noblacklist ${HOME}/.icedove
14 14
15mkdir ~/.cache/icedove 15mkdir ${HOME}/.cache/icedove
16mkdir ~/.gnupg 16mkdir ${HOME}/.gnupg
17mkdir ~/.icedove 17mkdir ${HOME}/.icedove
18whitelist ~/.cache/icedove 18whitelist ${HOME}/.cache/icedove
19whitelist ~/.gnupg 19whitelist ${HOME}/.gnupg
20whitelist ~/.icedove 20whitelist ${HOME}/.icedove
21include /etc/firejail/whitelist-common.inc 21include /etc/firejail/whitelist-common.inc
22 22
23ignore private-tmp 23ignore private-tmp
diff --git a/etc/inox.profile b/etc/inox.profile
index 221acd309..fbc654434 100644
--- a/etc/inox.profile
+++ b/etc/inox.profile
@@ -5,20 +5,20 @@ include /etc/firejail/inox.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.cache/inox 8noblacklist ${HOME}/.cache/inox
9noblacklist ~/.config/inox 9noblacklist ${HOME}/.config/inox
10noblacklist ~/.pki 10noblacklist ${HOME}/.pki
11 11
12include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-programs.inc 13include /etc/firejail/disable-programs.inc
14 14
15mkdir ~/.cache/inox 15mkdir ${HOME}/.cache/inox
16mkdir ~/.config/inox 16mkdir ${HOME}/.config/inox
17mkdir ~/.pki 17mkdir ${HOME}/.pki
18whitelist ${DOWNLOADS} 18whitelist ${DOWNLOADS}
19whitelist ~/.cache/inox 19whitelist ${HOME}/.cache/inox
20whitelist ~/.config/inox 20whitelist ${HOME}/.config/inox
21whitelist ~/.pki 21whitelist ${HOME}/.pki
22include /etc/firejail/whitelist-common.inc 22include /etc/firejail/whitelist-common.inc
23include /etc/firejail/whitelist-var-common.inc 23include /etc/firejail/whitelist-var-common.inc
24 24
diff --git a/etc/iridium.profile b/etc/iridium.profile
index 5b1268f4e..76026722f 100644
--- a/etc/iridium.profile
+++ b/etc/iridium.profile
@@ -5,21 +5,21 @@ include /etc/firejail/iridium.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.cache/iridium 8noblacklist ${HOME}/.cache/iridium
9noblacklist ~/.config/iridium 9noblacklist ${HOME}/.config/iridium
10 10
11include /etc/firejail/disable-common.inc 11include /etc/firejail/disable-common.inc
12# chromium/iridium is distributed with a perl script on Arch 12# chromium/iridium is distributed with a perl script on Arch
13# include /etc/firejail/disable-devel.inc 13# include /etc/firejail/disable-devel.inc
14include /etc/firejail/disable-programs.inc 14include /etc/firejail/disable-programs.inc
15 15
16mkdir ~/.cache/iridium 16mkdir ${HOME}/.cache/iridium
17mkdir ~/.config/iridium 17mkdir ${HOME}/.config/iridium
18mkdir ~/.pki 18mkdir ${HOME}/.pki
19whitelist ${DOWNLOADS} 19whitelist ${DOWNLOADS}
20whitelist ~/.cache/iridium 20whitelist ${HOME}/.cache/iridium
21whitelist ~/.config/iridium 21whitelist ${HOME}/.config/iridium
22whitelist ~/.pki 22whitelist ${HOME}/.pki
23include /etc/firejail/whitelist-common.inc 23include /etc/firejail/whitelist-common.inc
24include /etc/firejail/whitelist-var-common.inc 24include /etc/firejail/whitelist-var-common.inc
25 25
diff --git a/etc/jitsi.profile b/etc/jitsi.profile
index 78a57ff46..bfccdf281 100644
--- a/etc/jitsi.profile
+++ b/etc/jitsi.profile
@@ -5,7 +5,7 @@ include /etc/firejail/jitsi.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.jitsi 8noblacklist ${HOME}/.jitsi
9 9
10include /etc/firejail/disable-common.inc 10include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-devel.inc 11include /etc/firejail/disable-devel.inc
diff --git a/etc/k3b.profile b/etc/k3b.profile
index 58623d823..a9555bccc 100644
--- a/etc/k3b.profile
+++ b/etc/k3b.profile
@@ -5,9 +5,9 @@ include /etc/firejail/k3b.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.config/k3brc 8noblacklist ${HOME}/.config/k3brc
9noblacklist ~/.kde/share/config/k3brc 9noblacklist ${HOME}/.kde/share/config/k3brc
10noblacklist ~/.kde4/share/config/k3brc 10noblacklist ${HOME}/.kde4/share/config/k3brc
11 11
12include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-devel.inc 13include /etc/firejail/disable-devel.inc
diff --git a/etc/kate.profile b/etc/kate.profile
index 85a98d67f..711833d5c 100644
--- a/etc/kate.profile
+++ b/etc/kate.profile
@@ -7,12 +7,12 @@ include /etc/firejail/globals.local
7 7
8# blacklist /run/user/*/bus 8# blacklist /run/user/*/bus
9 9
10noblacklist ~/.config/katepartrc 10noblacklist ${HOME}/.config/katepartrc
11noblacklist ~/.config/katerc 11noblacklist ${HOME}/.config/katerc
12noblacklist ~/.config/kateschemarc 12noblacklist ${HOME}/.config/kateschemarc
13noblacklist ~/.config/katesyntaxhighlightingrc 13noblacklist ${HOME}/.config/katesyntaxhighlightingrc
14noblacklist ~/.config/katevirc 14noblacklist ${HOME}/.config/katevirc
15noblacklist ~/.local/share/kate 15noblacklist ${HOME}/.local/share/kate
16 16
17include /etc/firejail/disable-common.inc 17include /etc/firejail/disable-common.inc
18# include /etc/firejail/disable-devel.inc 18# include /etc/firejail/disable-devel.inc
diff --git a/etc/kget.profile b/etc/kget.profile
index f6d7352c1..25c66e044 100644
--- a/etc/kget.profile
+++ b/etc/kget.profile
@@ -5,10 +5,10 @@ include /etc/firejail/kget.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.kde/share/apps/kget 8noblacklist ${HOME}/.kde/share/apps/kget
9noblacklist ~/.kde/share/config/kgetrc 9noblacklist ${HOME}/.kde/share/config/kgetrc
10noblacklist ~/.kde4/share/apps/kget 10noblacklist ${HOME}/.kde4/share/apps/kget
11noblacklist ~/.kde4/share/config/kgetrc 11noblacklist ${HOME}/.kde4/share/config/kgetrc
12 12
13include /etc/firejail/disable-common.inc 13include /etc/firejail/disable-common.inc
14include /etc/firejail/disable-devel.inc 14include /etc/firejail/disable-devel.inc
diff --git a/etc/kino.profile b/etc/kino.profile
index 240dab8ef..be51786f5 100644
--- a/etc/kino.profile
+++ b/etc/kino.profile
@@ -5,8 +5,8 @@ include /etc/firejail/kino.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.kino-history 8noblacklist ${HOME}/.kino-history
9noblacklist ~/.kinorc 9noblacklist ${HOME}/.kinorc
10 10
11include /etc/firejail/disable-common.inc 11include /etc/firejail/disable-common.inc
12include /etc/firejail/disable-devel.inc 12include /etc/firejail/disable-devel.inc
diff --git a/etc/knotes.profile b/etc/knotes.profile
index 039f1b057..94ada7855 100644
--- a/etc/knotes.profile
+++ b/etc/knotes.profile
@@ -5,7 +5,7 @@ include /etc/firejail/knotes.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.config/knotesrc 8noblacklist ${HOME}/.config/knotesrc
9 9
10include /etc/firejail/disable-common.inc 10include /etc/firejail/disable-common.inc
11# include /etc/firejail/disable-devel.inc 11# include /etc/firejail/disable-devel.inc
diff --git a/etc/kopete.profile b/etc/kopete.profile
index 3e943c162..6d7c22373 100644
--- a/etc/kopete.profile
+++ b/etc/kopete.profile
@@ -5,10 +5,10 @@ include /etc/firejail/kopete.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.kde/share/apps/kopete 8noblacklist ${HOME}/.kde/share/apps/kopete
9noblacklist ~/.kde/share/config/kopeterc 9noblacklist ${HOME}/.kde/share/config/kopeterc
10noblacklist ~/.kde4/share/apps/kopete 10noblacklist ${HOME}/.kde4/share/apps/kopete
11noblacklist ~/.kde4/share/config/kopeterc 11noblacklist ${HOME}/.kde4/share/config/kopeterc
12 12
13include /etc/firejail/disable-common.inc 13include /etc/firejail/disable-common.inc
14include /etc/firejail/disable-devel.inc 14include /etc/firejail/disable-devel.inc
diff --git a/etc/krunner.profile b/etc/krunner.profile
index c3a4c73aa..606b67677 100644
--- a/etc/krunner.profile
+++ b/etc/krunner.profile
@@ -8,9 +8,9 @@ include /etc/firejail/globals.local
8# start a program in krunner: program will run with this generic profile 8# start a program in krunner: program will run with this generic profile
9# open a file in krunner: file viewer will run with its own profile (if firejailed automatically) 9# open a file in krunner: file viewer will run with its own profile (if firejailed automatically)
10 10
11noblacklist ~/.config/krunnerrc 11noblacklist ${HOME}/.config/krunnerrc
12noblacklist ~/.kde/share/config/krunnerrc 12noblacklist ${HOME}/.kde/share/config/krunnerrc
13noblacklist ~/.kde4/share/config/krunnerrc 13noblacklist ${HOME}/.kde4/share/config/krunnerrc
14 14
15include /etc/firejail/disable-common.inc 15include /etc/firejail/disable-common.inc
16# include /etc/firejail/disable-devel.inc 16# include /etc/firejail/disable-devel.inc
diff --git a/etc/ktorrent.profile b/etc/ktorrent.profile
index 99e185ce3..5ea09f925 100644
--- a/etc/ktorrent.profile
+++ b/etc/ktorrent.profile
@@ -5,31 +5,31 @@ include /etc/firejail/ktorrent.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.config/ktorrentrc 8noblacklist ${HOME}/.config/ktorrentrc
9noblacklist ~/.kde/share/apps/ktorrent 9noblacklist ${HOME}/.kde/share/apps/ktorrent
10noblacklist ~/.kde/share/config/ktorrentrc 10noblacklist ${HOME}/.kde/share/config/ktorrentrc
11noblacklist ~/.kde4/share/apps/ktorrent 11noblacklist ${HOME}/.kde4/share/apps/ktorrent
12noblacklist ~/.kde4/share/config/ktorrentrc 12noblacklist ${HOME}/.kde4/share/config/ktorrentrc
13noblacklist ~/.local/share/ktorrent 13noblacklist ${HOME}/.local/share/ktorrent
14 14
15include /etc/firejail/disable-common.inc 15include /etc/firejail/disable-common.inc
16include /etc/firejail/disable-devel.inc 16include /etc/firejail/disable-devel.inc
17include /etc/firejail/disable-passwdmgr.inc 17include /etc/firejail/disable-passwdmgr.inc
18include /etc/firejail/disable-programs.inc 18include /etc/firejail/disable-programs.inc
19 19
20mkdir ~/.kde/share/apps/ktorrent 20mkdir ${HOME}/.kde/share/apps/ktorrent
21mkdir ~/.kde4/share/apps/ktorrent 21mkdir ${HOME}/.kde4/share/apps/ktorrent
22mkdir ~/.local/share/ktorrent 22mkdir ${HOME}/.local/share/ktorrent
23mkfile ~/.config/ktorrentrc 23mkfile ${HOME}/.config/ktorrentrc
24mkfile ~/.kde/share/config/ktorrentrc 24mkfile ${HOME}/.kde/share/config/ktorrentrc
25mkfile ~/.kde4/share/config/ktorrentrc 25mkfile ${HOME}/.kde4/share/config/ktorrentrc
26whitelist ${DOWNLOADS} 26whitelist ${DOWNLOADS}
27whitelist ~/.config/ktorrentrc 27whitelist ${HOME}/.config/ktorrentrc
28whitelist ~/.kde/share/apps/ktorrent 28whitelist ${HOME}/.kde/share/apps/ktorrent
29whitelist ~/.kde/share/config/ktorrentrc 29whitelist ${HOME}/.kde/share/config/ktorrentrc
30whitelist ~/.kde4/share/apps/ktorrent 30whitelist ${HOME}/.kde4/share/apps/ktorrent
31whitelist ~/.kde4/share/config/ktorrentrc 31whitelist ${HOME}/.kde4/share/config/ktorrentrc
32whitelist ~/.local/share/ktorrent 32whitelist ${HOME}/.local/share/ktorrent
33include /etc/firejail/whitelist-common.inc 33include /etc/firejail/whitelist-common.inc
34include /etc/firejail/whitelist-var-common.inc 34include /etc/firejail/whitelist-var-common.inc
35 35
diff --git a/etc/kwin_x11.profile b/etc/kwin_x11.profile
index 0004da72d..8a578f3f3 100644
--- a/etc/kwin_x11.profile
+++ b/etc/kwin_x11.profile
@@ -5,9 +5,9 @@ include /etc/firejail/kwin_x11.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.config/kwinrc 8noblacklist ${HOME}/.config/kwinrc
9noblacklist ~/.config/kwinrulesrc 9noblacklist ${HOME}/.config/kwinrulesrc
10noblacklist ~/.local/share/kwin 10noblacklist ${HOME}/.local/share/kwin
11 11
12include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-devel.inc 13include /etc/firejail/disable-devel.inc
diff --git a/etc/kwrite.profile b/etc/kwrite.profile
index 5d6eba094..807ecf62b 100644
--- a/etc/kwrite.profile
+++ b/etc/kwrite.profile
@@ -7,13 +7,13 @@ include /etc/firejail/globals.local
7 7
8# blacklist /run/user/*/bus 8# blacklist /run/user/*/bus
9 9
10noblacklist ~/.config/katepartrc 10noblacklist ${HOME}/.config/katepartrc
11noblacklist ~/.config/katerc 11noblacklist ${HOME}/.config/katerc
12noblacklist ~/.config/kateschemarc 12noblacklist ${HOME}/.config/kateschemarc
13noblacklist ~/.config/katesyntaxhighlightingrc 13noblacklist ${HOME}/.config/katesyntaxhighlightingrc
14noblacklist ~/.config/katevirc 14noblacklist ${HOME}/.config/katevirc
15noblacklist ~/.config/kwriterc 15noblacklist ${HOME}/.config/kwriterc
16noblacklist ~/.local/share/kwrite 16noblacklist ${HOME}/.local/share/kwrite
17 17
18include /etc/firejail/disable-common.inc 18include /etc/firejail/disable-common.inc
19# include /etc/firejail/disable-devel.inc 19# include /etc/firejail/disable-devel.inc
diff --git a/etc/less.profile b/etc/less.profile
index 3546649af..3b1c5d6bf 100644
--- a/etc/less.profile
+++ b/etc/less.profile
@@ -20,7 +20,7 @@ shell none
20tracelog 20tracelog
21writable-var-log 21writable-var-log
22 22
23# The user can have a custom coloring scritps configured in ~/.lessfilter. 23# The user can have a custom coloring scritps configured in ${HOME}/.lessfilter.
24# Enable private-bin and private-lib if you are not using any filter. 24# Enable private-bin and private-lib if you are not using any filter.
25# private-bin less 25# private-bin less
26# private-lib 26# private-lib
diff --git a/etc/libreoffice.profile b/etc/libreoffice.profile
index 214b49c65..3548a75ad 100644
--- a/etc/libreoffice.profile
+++ b/etc/libreoffice.profile
@@ -7,7 +7,7 @@ include /etc/firejail/globals.local
7 7
8noblacklist ${HOME}/.java 8noblacklist ${HOME}/.java
9noblacklist /usr/local/sbin 9noblacklist /usr/local/sbin
10noblacklist ~/.config/libreoffice 10noblacklist ${HOME}/.config/libreoffice
11 11
12include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-devel.inc 13include /etc/firejail/disable-devel.inc
diff --git a/etc/liferea.profile b/etc/liferea.profile
index afd5fed6b..552a45bbb 100644
--- a/etc/liferea.profile
+++ b/etc/liferea.profile
@@ -5,21 +5,21 @@ include /etc/firejail/liferea.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.cache/liferea 8noblacklist ${HOME}/.cache/liferea
9noblacklist ~/.config/liferea 9noblacklist ${HOME}/.config/liferea
10noblacklist ~/.local/share/liferea 10noblacklist ${HOME}/.local/share/liferea
11 11
12include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-devel.inc 13include /etc/firejail/disable-devel.inc
14include /etc/firejail/disable-passwdmgr.inc 14include /etc/firejail/disable-passwdmgr.inc
15include /etc/firejail/disable-programs.inc 15include /etc/firejail/disable-programs.inc
16 16
17mkdir ~/.cache/liferea 17mkdir ${HOME}/.cache/liferea
18mkdir ~/.config/liferea 18mkdir ${HOME}/.config/liferea
19mkdir ~/.local/share/liferea 19mkdir ${HOME}/.local/share/liferea
20whitelist ~/.cache/liferea 20whitelist ${HOME}/.cache/liferea
21whitelist ~/.config/liferea 21whitelist ${HOME}/.config/liferea
22whitelist ~/.local/share/liferea 22whitelist ${HOME}/.local/share/liferea
23include /etc/firejail/whitelist-common.inc 23include /etc/firejail/whitelist-common.inc
24 24
25caps.drop all 25caps.drop all
diff --git a/etc/lximage-qt.profile b/etc/lximage-qt.profile
index 1a3b26c10..d4bb1b0e8 100644
--- a/etc/lximage-qt.profile
+++ b/etc/lximage-qt.profile
@@ -5,7 +5,7 @@ include /etc/firejail/lximage-qt.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.config/lximage-qt 8noblacklist ${HOME}/.config/lximage-qt
9 9
10include /etc/firejail/disable-common.inc 10include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-devel.inc 11include /etc/firejail/disable-devel.inc
diff --git a/etc/lxmusic.profile b/etc/lxmusic.profile
index 0161ffb63..71d7a056f 100644
--- a/etc/lxmusic.profile
+++ b/etc/lxmusic.profile
@@ -5,8 +5,8 @@ include /etc/firejail/lxmusic.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.cache/xmms2 8noblacklist ${HOME}/.cache/xmms2
9noblacklist ~/.config/xmms2 9noblacklist ${HOME}/.config/xmms2
10 10
11include /etc/firejail/disable-common.inc 11include /etc/firejail/disable-common.inc
12include /etc/firejail/disable-devel.inc 12include /etc/firejail/disable-devel.inc
diff --git a/etc/makepkg.profile b/etc/makepkg.profile
index 96846592d..6d2e6b0ce 100644
--- a/etc/makepkg.profile
+++ b/etc/makepkg.profile
@@ -5,8 +5,8 @@
5# for potential issues and their solutions when Firejailing makepkg 5# for potential issues and their solutions when Firejailing makepkg
6 6
7# This profile could be significantly strengthened by adding the following to makepkg.local 7# This profile could be significantly strengthened by adding the following to makepkg.local
8# whitelist ~/<Your Build Folder> 8# whitelist ${HOME}/<Your Build Folder>
9# whitelist ~/.gnupg 9# whitelist ${HOME}/.gnupg
10 10
11quiet 11quiet
12# Persistent local customizations 12# Persistent local customizations
@@ -16,15 +16,15 @@ include /etc/firejail/globals.local
16 16
17 17
18# Enable severely restricted access to ${HOME}/.gnupg 18# Enable severely restricted access to ${HOME}/.gnupg
19noblacklist ~/.gnupg 19noblacklist ${HOME}/.gnupg
20read-only ~/.gnupg/gpg.conf 20read-only ${HOME}/.gnupg/gpg.conf
21read-only ~/.gnupg/trustdb.gpg 21read-only ${HOME}/.gnupg/trustdb.gpg
22read-only ~/.gnupg/pubring.kbx 22read-only ${HOME}/.gnupg/pubring.kbx
23blacklist ~/.gnupg/random_seed 23blacklist ${HOME}/.gnupg/random_seed
24blacklist ~/.gnupg/pubring.kbx~ 24blacklist ${HOME}/.gnupg/pubring.kbx~
25blacklist ~/.gnupg/private-keys-v1.d 25blacklist ${HOME}/.gnupg/private-keys-v1.d
26blacklist ~/.gnupg/crls.d 26blacklist ${HOME}/.gnupg/crls.d
27blacklist ~/.gnupg/openpgp-revocs.d 27blacklist ${HOME}/.gnupg/openpgp-revocs.d
28 28
29 29
30# Need to be able to read /var/lib/pacman, {Note no capabilities so automatically read-only} 30# Need to be able to read /var/lib/pacman, {Note no capabilities so automatically read-only}
diff --git a/etc/mediathekview.profile b/etc/mediathekview.profile
index dc9946794..9eae27765 100644
--- a/etc/mediathekview.profile
+++ b/etc/mediathekview.profile
@@ -5,16 +5,16 @@ include /etc/firejail/mediathekview.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.config/mpv 8noblacklist ${HOME}/.config/mpv
9noblacklist ~/.config/smplayer 9noblacklist ${HOME}/.config/smplayer
10noblacklist ~/.config/totem 10noblacklist ${HOME}/.config/totem
11noblacklist ~/.config/vlc 11noblacklist ${HOME}/.config/vlc
12noblacklist ~/.config/xplayer 12noblacklist ${HOME}/.config/xplayer
13noblacklist ~/.java 13noblacklist ${HOME}/.java
14noblacklist ~/.local/share/totem 14noblacklist ${HOME}/.local/share/totem
15noblacklist ~/.local/share/xplayer 15noblacklist ${HOME}/.local/share/xplayer
16noblacklist ~/.mediathek3 16noblacklist ${HOME}/.mediathek3
17noblacklist ~/.mplayer 17noblacklist ${HOME}/.mplayer
18 18
19include /etc/firejail/disable-common.inc 19include /etc/firejail/disable-common.inc
20include /etc/firejail/disable-devel.inc 20include /etc/firejail/disable-devel.inc
diff --git a/etc/midori.profile b/etc/midori.profile
index e8373b042..7cb5326fb 100644
--- a/etc/midori.profile
+++ b/etc/midori.profile
@@ -5,32 +5,32 @@ include /etc/firejail/midori.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.config/midori 8noblacklist ${HOME}/.config/midori
9noblacklist ~/.local/share/midori 9noblacklist ${HOME}/.local/share/midori
10# noblacklist ~/.local/share/webkit 10# noblacklist ${HOME}/.local/share/webkit
11# noblacklist ~/.local/share/webkitgtk 11# noblacklist ${HOME}/.local/share/webkitgtk
12noblacklist ~/.pki 12noblacklist ${HOME}/.pki
13 13
14include /etc/firejail/disable-common.inc 14include /etc/firejail/disable-common.inc
15include /etc/firejail/disable-devel.inc 15include /etc/firejail/disable-devel.inc
16include /etc/firejail/disable-programs.inc 16include /etc/firejail/disable-programs.inc
17 17
18mkdir ~/.cache/midori 18mkdir ${HOME}/.cache/midori
19mkdir ~/.config/midori 19mkdir ${HOME}/.config/midori
20mkdir ~/.local/share/midori 20mkdir ${HOME}/.local/share/midori
21mkdir ~/.local/share/webkit 21mkdir ${HOME}/.local/share/webkit
22mkdir ~/.local/share/webkitgtk 22mkdir ${HOME}/.local/share/webkitgtk
23mkdir ~/.pki 23mkdir ${HOME}/.pki
24whitelist ${DOWNLOADS} 24whitelist ${DOWNLOADS}
25whitelist ~/.cache/gnome-mplayer/plugin 25whitelist ${HOME}/.cache/gnome-mplayer/plugin
26whitelist ~/.cache/midori 26whitelist ${HOME}/.cache/midori
27whitelist ~/.config/gnome-mplayer 27whitelist ${HOME}/.config/gnome-mplayer
28whitelist ~/.config/midori 28whitelist ${HOME}/.config/midori
29whitelist ~/.lastpass 29whitelist ${HOME}/.lastpass
30whitelist ~/.local/share/midori 30whitelist ${HOME}/.local/share/midori
31whitelist ~/.local/share/webkit 31whitelist ${HOME}/.local/share/webkit
32whitelist ~/.local/share/webkitgtk 32whitelist ${HOME}/.local/share/webkitgtk
33whitelist ~/.pki 33whitelist ${HOME}/.pki
34include /etc/firejail/whitelist-common.inc 34include /etc/firejail/whitelist-common.inc
35 35
36caps.drop all 36caps.drop all
diff --git a/etc/mousepad.profile b/etc/mousepad.profile
index e44750f99..0f0051c0a 100644
--- a/etc/mousepad.profile
+++ b/etc/mousepad.profile
@@ -5,7 +5,7 @@ include /etc/firejail/mousepad.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.config/Mousepad 8noblacklist ${HOME}/.config/Mousepad
9 9
10include /etc/firejail/disable-common.inc 10include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-devel.inc 11include /etc/firejail/disable-devel.inc
diff --git a/etc/musescore.profile b/etc/musescore.profile
index b3d04c08f..75f86c842 100644
--- a/etc/musescore.profile
+++ b/etc/musescore.profile
@@ -5,10 +5,10 @@ include /etc/firejail/musescore.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.config/MusE 8noblacklist ${HOME}/.config/MusE
9noblacklist ~/.config/MuseScore 9noblacklist ${HOME}/.config/MuseScore
10noblacklist ~/.local/share/data/MusE 10noblacklist ${HOME}/.local/share/data/MusE
11noblacklist ~/.local/share/data/MuseScore 11noblacklist ${HOME}/.local/share/data/MuseScore
12 12
13include /etc/firejail/disable-common.inc 13include /etc/firejail/disable-common.inc
14include /etc/firejail/disable-devel.inc 14include /etc/firejail/disable-devel.inc
diff --git a/etc/mutt.profile b/etc/mutt.profile
index bdd629773..bca72f386 100644
--- a/etc/mutt.profile
+++ b/etc/mutt.profile
@@ -9,28 +9,28 @@ blacklist /tmp/.X11-unix
9 9
10noblacklist /var/mail 10noblacklist /var/mail
11noblacklist /var/spool/mail 11noblacklist /var/spool/mail
12noblacklist ~/.Mail 12noblacklist ${HOME}/.Mail
13noblacklist ~/.bogofilter 13noblacklist ${HOME}/.bogofilter
14noblacklist ~/.cache/mutt 14noblacklist ${HOME}/.cache/mutt
15noblacklist ~/.elinks 15noblacklist ${HOME}/.elinks
16noblacklist ~/.emacs 16noblacklist ${HOME}/.emacs
17noblacklist ~/.emacs.d 17noblacklist ${HOME}/.emacs.d
18noblacklist ~/.gnupg 18noblacklist ${HOME}/.gnupg
19noblacklist ~/.mail 19noblacklist ${HOME}/.mail
20noblacklist ~/.mailcap 20noblacklist ${HOME}/.mailcap
21noblacklist ~/.msmtprc 21noblacklist ${HOME}/.msmtprc
22noblacklist ~/.mutt 22noblacklist ${HOME}/.mutt
23noblacklist ~/.mutt/muttrc 23noblacklist ${HOME}/.mutt/muttrc
24noblacklist ~/.muttrc 24noblacklist ${HOME}/.muttrc
25noblacklist ~/.signature 25noblacklist ${HOME}/.signature
26noblacklist ~/.vim 26noblacklist ${HOME}/.vim
27noblacklist ~/.viminfo 27noblacklist ${HOME}/.viminfo
28noblacklist ~/.vimrc 28noblacklist ${HOME}/.vimrc
29noblacklist ~/.w3m 29noblacklist ${HOME}/.w3m
30noblacklist ~/Mail 30noblacklist ${HOME}/Mail
31noblacklist ~/mail 31noblacklist ${HOME}/mail
32noblacklist ~/postponed 32noblacklist ${HOME}/postponed
33noblacklist ~/sent 33noblacklist ${HOME}/sent
34 34
35include /etc/firejail/disable-common.inc 35include /etc/firejail/disable-common.inc
36include /etc/firejail/disable-devel.inc 36include /etc/firejail/disable-devel.inc
diff --git a/etc/nautilus.profile b/etc/nautilus.profile
index 45d23cae6..5ba0850fc 100644
--- a/etc/nautilus.profile
+++ b/etc/nautilus.profile
@@ -8,10 +8,10 @@ include /etc/firejail/globals.local
8# Nautilus is started by systemd on most systems. Therefore it is not firejailed by default. Since there 8# Nautilus is started by systemd on most systems. Therefore it is not firejailed by default. Since there
9# is already a nautilus process running on gnome desktops firejail will have no effect. 9# is already a nautilus process running on gnome desktops firejail will have no effect.
10 10
11noblacklist ~/.config/nautilus 11noblacklist ${HOME}/.config/nautilus
12noblacklist ~/.local/share/Trash 12noblacklist ${HOME}/.local/share/Trash
13noblacklist ~/.local/share/nautilus 13noblacklist ${HOME}/.local/share/nautilus
14noblacklist ~/.local/share/nautilus-python 14noblacklist ${HOME}/.local/share/nautilus-python
15 15
16include /etc/firejail/disable-common.inc 16include /etc/firejail/disable-common.inc
17include /etc/firejail/disable-devel.inc 17include /etc/firejail/disable-devel.inc
diff --git a/etc/netsurf.profile b/etc/netsurf.profile
index 64aa068b1..02b35757a 100644
--- a/etc/netsurf.profile
+++ b/etc/netsurf.profile
@@ -5,18 +5,18 @@ include /etc/firejail/netsurf.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.cache/netsurf 8noblacklist ${HOME}/.cache/netsurf
9noblacklist ~/.config/netsurf 9noblacklist ${HOME}/.config/netsurf
10 10
11include /etc/firejail/disable-common.inc 11include /etc/firejail/disable-common.inc
12include /etc/firejail/disable-devel.inc 12include /etc/firejail/disable-devel.inc
13include /etc/firejail/disable-programs.inc 13include /etc/firejail/disable-programs.inc
14 14
15mkdir ~/.cache/netsurf 15mkdir ${HOME}/.cache/netsurf
16mkdir ~/.config/netsurf 16mkdir ${HOME}/.config/netsurf
17whitelist ${DOWNLOADS} 17whitelist ${DOWNLOADS}
18whitelist ~/.cache/netsurf 18whitelist ${HOME}/.cache/netsurf
19whitelist ~/.config/netsurf 19whitelist ${HOME}/.config/netsurf
20include /etc/firejail/whitelist-common.inc 20include /etc/firejail/whitelist-common.inc
21 21
22caps.drop all 22caps.drop all
diff --git a/etc/nylas.profile b/etc/nylas.profile
index d96c6b0d4..c2e1e1fdb 100644
--- a/etc/nylas.profile
+++ b/etc/nylas.profile
@@ -5,8 +5,8 @@ include /etc/firejail/nylas.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.config/Nylas Mail 8noblacklist ${HOME}/.config/Nylas Mail
9noblacklist ~/.nylas-mail 9noblacklist ${HOME}/.nylas-mail
10 10
11include /etc/firejail/disable-common.inc 11include /etc/firejail/disable-common.inc
12include /etc/firejail/disable-devel.inc 12include /etc/firejail/disable-devel.inc
@@ -14,8 +14,8 @@ include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc 14include /etc/firejail/disable-programs.inc
15 15
16whitelist ${DOWNLOADS} 16whitelist ${DOWNLOADS}
17whitelist ~/.config/Nylas Mail 17whitelist ${HOME}/.config/Nylas Mail
18whitelist ~/.nylas-mail 18whitelist ${HOME}/.nylas-mail
19include /etc/firejail/whitelist-common.inc 19include /etc/firejail/whitelist-common.inc
20 20
21caps.drop all 21caps.drop all
diff --git a/etc/okular.profile b/etc/okular.profile
index 4171a28f8..2c2d395c8 100644
--- a/etc/okular.profile
+++ b/etc/okular.profile
@@ -7,15 +7,15 @@ include /etc/firejail/globals.local
7 7
8# blacklist /run/user/*/bus 8# blacklist /run/user/*/bus
9 9
10noblacklist ~/.config/okularpartrc 10noblacklist ${HOME}/.config/okularpartrc
11noblacklist ~/.config/okularrc 11noblacklist ${HOME}/.config/okularrc
12noblacklist ~/.kde/share/apps/okular 12noblacklist ${HOME}/.kde/share/apps/okular
13noblacklist ~/.kde/share/config/okularpartrc 13noblacklist ${HOME}/.kde/share/config/okularpartrc
14noblacklist ~/.kde/share/config/okularrc 14noblacklist ${HOME}/.kde/share/config/okularrc
15noblacklist ~/.kde4/share/apps/okular 15noblacklist ${HOME}/.kde4/share/apps/okular
16noblacklist ~/.kde4/share/config/okularpartrc 16noblacklist ${HOME}/.kde4/share/config/okularpartrc
17noblacklist ~/.kde4/share/config/okularrc 17noblacklist ${HOME}/.kde4/share/config/okularrc
18noblacklist ~/.local/share/okular 18noblacklist ${HOME}/.local/share/okular
19 19
20include /etc/firejail/disable-common.inc 20include /etc/firejail/disable-common.inc
21include /etc/firejail/disable-devel.inc 21include /etc/firejail/disable-devel.inc
diff --git a/etc/open-invaders.profile b/etc/open-invaders.profile
index 20a9b2227..331bfa939 100644
--- a/etc/open-invaders.profile
+++ b/etc/open-invaders.profile
@@ -7,14 +7,14 @@ include /etc/firejail/globals.local
7 7
8blacklist /run/user/*/bus 8blacklist /run/user/*/bus
9 9
10noblacklist ~/.openinvaders 10noblacklist ${HOME}/.openinvaders
11 11
12include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-passwdmgr.inc 13include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc 14include /etc/firejail/disable-programs.inc
15 15
16mkdir ~/.openinvaders 16mkdir ${HOME}/.openinvaders
17whitelist ~/.openinvaders 17whitelist ${HOME}/.openinvaders
18include /etc/firejail/whitelist-common.inc 18include /etc/firejail/whitelist-common.inc
19 19
20caps.drop all 20caps.drop all
diff --git a/etc/opera-beta.profile b/etc/opera-beta.profile
index c295a2082..6079ac7d5 100644
--- a/etc/opera-beta.profile
+++ b/etc/opera-beta.profile
@@ -5,20 +5,20 @@ include /etc/firejail/opera-beta.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.config/opera-beta 8noblacklist ${HOME}/.config/opera-beta
9noblacklist ~/.pki 9noblacklist ${HOME}/.pki
10 10
11include /etc/firejail/disable-common.inc 11include /etc/firejail/disable-common.inc
12include /etc/firejail/disable-devel.inc 12include /etc/firejail/disable-devel.inc
13include /etc/firejail/disable-programs.inc 13include /etc/firejail/disable-programs.inc
14 14
15mkdir ~/.cache/opera 15mkdir ${HOME}/.cache/opera
16mkdir ~/.config/opera-beta 16mkdir ${HOME}/.config/opera-beta
17mkdir ~/.pki 17mkdir ${HOME}/.pki
18whitelist ${DOWNLOADS} 18whitelist ${DOWNLOADS}
19whitelist ~/.cache/opera 19whitelist ${HOME}/.cache/opera
20whitelist ~/.config/opera-beta 20whitelist ${HOME}/.config/opera-beta
21whitelist ~/.pki 21whitelist ${HOME}/.pki
22include /etc/firejail/whitelist-common.inc 22include /etc/firejail/whitelist-common.inc
23 23
24netfilter 24netfilter
diff --git a/etc/opera.profile b/etc/opera.profile
index 553ea6790..2b9b903ac 100644
--- a/etc/opera.profile
+++ b/etc/opera.profile
@@ -5,24 +5,24 @@ include /etc/firejail/opera.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.cache/opera 8noblacklist ${HOME}/.cache/opera
9noblacklist ~/.config/opera 9noblacklist ${HOME}/.config/opera
10noblacklist ~/.opera 10noblacklist ${HOME}/.opera
11noblacklist ~/.pki 11noblacklist ${HOME}/.pki
12 12
13include /etc/firejail/disable-common.inc 13include /etc/firejail/disable-common.inc
14include /etc/firejail/disable-devel.inc 14include /etc/firejail/disable-devel.inc
15include /etc/firejail/disable-programs.inc 15include /etc/firejail/disable-programs.inc
16 16
17mkdir ~/.cache/opera 17mkdir ${HOME}/.cache/opera
18mkdir ~/.config/opera 18mkdir ${HOME}/.config/opera
19mkdir ~/.opera 19mkdir ${HOME}/.opera
20mkdir ~/.pki 20mkdir ${HOME}/.pki
21whitelist ${DOWNLOADS} 21whitelist ${DOWNLOADS}
22whitelist ~/.cache/opera 22whitelist ${HOME}/.cache/opera
23whitelist ~/.config/opera 23whitelist ${HOME}/.config/opera
24whitelist ~/.opera 24whitelist ${HOME}/.opera
25whitelist ~/.pki 25whitelist ${HOME}/.pki
26include /etc/firejail/whitelist-common.inc 26include /etc/firejail/whitelist-common.inc
27 27
28netfilter 28netfilter
diff --git a/etc/palemoon.profile b/etc/palemoon.profile
index 054e876c5..8bdcb7334 100644
--- a/etc/palemoon.profile
+++ b/etc/palemoon.profile
@@ -5,8 +5,8 @@ include /etc/firejail/palemoon.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.cache/moonchild productions/pale moon 8noblacklist ${HOME}/.cache/moonchild productions/pale moon
9noblacklist ~/.moonchild productions/pale moon 9noblacklist ${HOME}/.moonchild productions/pale moon
10 10
11include /etc/firejail/disable-common.inc 11include /etc/firejail/disable-common.inc
12include /etc/firejail/disable-devel.inc 12include /etc/firejail/disable-devel.inc
@@ -14,29 +14,29 @@ include /etc/firejail/disable-programs.inc
14 14
15# These are uncommented in the Firefox profile. If you run into trouble you may 15# These are uncommented in the Firefox profile. If you run into trouble you may
16# want to uncomment (some of) them. 16# want to uncomment (some of) them.
17#whitelist ~/dwhelper 17#whitelist ${HOME}/dwhelper
18#whitelist ~/.zotero 18#whitelist ${HOME}/.zotero
19#whitelist ~/.vimperatorrc 19#whitelist ${HOME}/.vimperatorrc
20#whitelist ~/.vimperator 20#whitelist ${HOME}/.vimperator
21#whitelist ~/.pentadactylrc 21#whitelist ${HOME}/.pentadactylrc
22#whitelist ~/.pentadactyl 22#whitelist ${HOME}/.pentadactyl
23#whitelist ~/.keysnail.js 23#whitelist ${HOME}/.keysnail.js
24#whitelist ~/.config/gnome-mplayer 24#whitelist ${HOME}/.config/gnome-mplayer
25#whitelist ~/.cache/gnome-mplayer/plugin 25#whitelist ${HOME}/.cache/gnome-mplayer/plugin
26#whitelist ~/.pki 26#whitelist ${HOME}/.pki
27#whitelist ~/.lastpass 27#whitelist ${HOME}/.lastpass
28 28
29# For silverlight 29# For silverlight
30#whitelist ~/.wine-pipelight 30#whitelist ${HOME}/.wine-pipelight
31#whitelist ~/.wine-pipelight64 31#whitelist ${HOME}/.wine-pipelight64
32#whitelist ~/.config/pipelight-widevine 32#whitelist ${HOME}/.config/pipelight-widevine
33#whitelist ~/.config/pipelight-silverlight5.1 33#whitelist ${HOME}/.config/pipelight-silverlight5.1
34 34
35mkdir ~/.cache/moonchild productions/pale moon 35mkdir ${HOME}/.cache/moonchild productions/pale moon
36mkdir ~/.moonchild productions 36mkdir ${HOME}/.moonchild productions
37whitelist ${DOWNLOADS} 37whitelist ${DOWNLOADS}
38whitelist ~/.cache/moonchild productions/pale moon 38whitelist ${HOME}/.cache/moonchild productions/pale moon
39whitelist ~/.moonchild productions 39whitelist ${HOME}/.moonchild productions
40include /etc/firejail/whitelist-common.inc 40include /etc/firejail/whitelist-common.inc
41 41
42caps.drop all 42caps.drop all
diff --git a/etc/pcmanfm.profile b/etc/pcmanfm.profile
index 03e7e450f..08c607020 100644
--- a/etc/pcmanfm.profile
+++ b/etc/pcmanfm.profile
@@ -8,8 +8,8 @@ include /etc/firejail/globals.local
8# blacklist /run/user/*/bus 8# blacklist /run/user/*/bus
9 9
10noblacklist ${HOME}/.local/share/Trash 10noblacklist ${HOME}/.local/share/Trash
11# noblacklist ~/.config/libfm - disable-programs.inc is disabled, see below 11# noblacklist ${HOME}/.config/libfm - disable-programs.inc is disabled, see below
12# noblacklist ~/.config/pcmanfm 12# noblacklist ${HOME}/.config/pcmanfm
13 13
14include /etc/firejail/disable-common.inc 14include /etc/firejail/disable-common.inc
15include /etc/firejail/disable-devel.inc 15include /etc/firejail/disable-devel.inc
diff --git a/etc/pingus.profile b/etc/pingus.profile
index c491a2669..65aeedd86 100644
--- a/etc/pingus.profile
+++ b/etc/pingus.profile
@@ -7,14 +7,14 @@ include /etc/firejail/globals.local
7 7
8blacklist /run/user/*/bus 8blacklist /run/user/*/bus
9 9
10noblacklist ~/.pingus 10noblacklist ${HOME}/.pingus
11 11
12include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-passwdmgr.inc 13include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc 14include /etc/firejail/disable-programs.inc
15 15
16mkdir ~/.pingus 16mkdir ${HOME}/.pingus
17whitelist ~/.pingus 17whitelist ${HOME}/.pingus
18include /etc/firejail/whitelist-common.inc 18include /etc/firejail/whitelist-common.inc
19 19
20caps.drop all 20caps.drop all
diff --git a/etc/pix.profile b/etc/pix.profile
index 5440e4634..9eca6f87e 100644
--- a/etc/pix.profile
+++ b/etc/pix.profile
@@ -7,8 +7,8 @@ include /etc/firejail/globals.local
7 7
8noblacklist ${HOME}/.config/pix 8noblacklist ${HOME}/.config/pix
9noblacklist ${HOME}/.local/share/pix 9noblacklist ${HOME}/.local/share/pix
10noblacklist ~/.Steam 10noblacklist ${HOME}/.Steam
11noblacklist ~/.steam 11noblacklist ${HOME}/.steam
12 12
13include /etc/firejail/disable-common.inc 13include /etc/firejail/disable-common.inc
14include /etc/firejail/disable-devel.inc 14include /etc/firejail/disable-devel.inc
diff --git a/etc/psi-plus.profile b/etc/psi-plus.profile
index 72c52d967..8d2ace96a 100644
--- a/etc/psi-plus.profile
+++ b/etc/psi-plus.profile
@@ -13,13 +13,13 @@ include /etc/firejail/disable-devel.inc
13include /etc/firejail/disable-passwdmgr.inc 13include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc 14include /etc/firejail/disable-programs.inc
15 15
16mkdir ~/.cache/psi+ 16mkdir ${HOME}/.cache/psi+
17mkdir ~/.config/psi+ 17mkdir ${HOME}/.config/psi+
18mkdir ~/.local/share/psi+ 18mkdir ${HOME}/.local/share/psi+
19whitelist ${DOWNLOADS} 19whitelist ${DOWNLOADS}
20whitelist ~/.cache/psi+ 20whitelist ${HOME}/.cache/psi+
21whitelist ~/.config/psi+ 21whitelist ${HOME}/.config/psi+
22whitelist ~/.local/share/psi+ 22whitelist ${HOME}/.local/share/psi+
23include /etc/firejail/whitelist-common.inc 23include /etc/firejail/whitelist-common.inc
24 24
25caps.drop all 25caps.drop all
diff --git a/etc/qbittorrent.profile b/etc/qbittorrent.profile
index 32eb7de5b..9c4e6e356 100644
--- a/etc/qbittorrent.profile
+++ b/etc/qbittorrent.profile
@@ -5,25 +5,25 @@ include /etc/firejail/qbittorrent.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.cache/qBittorrent 8noblacklist ${HOME}/.cache/qBittorrent
9noblacklist ~/.config/qBittorrent 9noblacklist ${HOME}/.config/qBittorrent
10noblacklist ~/.config/qBittorrentrc 10noblacklist ${HOME}/.config/qBittorrentrc
11noblacklist ~/.config/qt5ct 11noblacklist ${HOME}/.config/qt5ct
12 12
13include /etc/firejail/disable-common.inc 13include /etc/firejail/disable-common.inc
14include /etc/firejail/disable-devel.inc 14include /etc/firejail/disable-devel.inc
15include /etc/firejail/disable-passwdmgr.inc 15include /etc/firejail/disable-passwdmgr.inc
16include /etc/firejail/disable-programs.inc 16include /etc/firejail/disable-programs.inc
17 17
18mkdir ~/.cache/qBittorrent 18mkdir ${HOME}/.cache/qBittorrent
19mkdir ~/.config/qBittorrent 19mkdir ${HOME}/.config/qBittorrent
20mkdir ~/.local/share/data/qBittorrent 20mkdir ${HOME}/.local/share/data/qBittorrent
21whitelist ${DOWNLOADS} 21whitelist ${DOWNLOADS}
22whitelist ~/.cache/qBittorrent 22whitelist ${HOME}/.cache/qBittorrent
23whitelist ~/.config/qBittorrent 23whitelist ${HOME}/.config/qBittorrent
24whitelist ~/.config/qBittorrentrc 24whitelist ${HOME}/.config/qBittorrentrc
25whitelist ~/.config/qt5ct 25whitelist ${HOME}/.config/qt5ct
26whitelist ~/.local/share/data/qBittorrent 26whitelist ${HOME}/.local/share/data/qBittorrent
27include /etc/firejail/whitelist-common.inc 27include /etc/firejail/whitelist-common.inc
28include /etc/firejail/whitelist-var-common.inc 28include /etc/firejail/whitelist-var-common.inc
29 29
diff --git a/etc/qemu-launcher.profile b/etc/qemu-launcher.profile
index 2738e04bb..20b14c0ca 100644
--- a/etc/qemu-launcher.profile
+++ b/etc/qemu-launcher.profile
@@ -5,7 +5,7 @@ include /etc/firejail/qemu-launcher.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.qemu-launcher 8noblacklist ${HOME}/.qemu-launcher
9 9
10include /etc/firejail/disable-common.inc 10include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-passwdmgr.inc 11include /etc/firejail/disable-passwdmgr.inc
diff --git a/etc/qtox.profile b/etc/qtox.profile
index 226d516ad..917e2cde8 100644
--- a/etc/qtox.profile
+++ b/etc/qtox.profile
@@ -5,8 +5,8 @@ include /etc/firejail/qtox.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.config/qt5ct 8noblacklist ${HOME}/.config/qt5ct
9noblacklist ~/.config/tox 9noblacklist ${HOME}/.config/tox
10 10
11include /etc/firejail/disable-common.inc 11include /etc/firejail/disable-common.inc
12include /etc/firejail/disable-devel.inc 12include /etc/firejail/disable-devel.inc
diff --git a/etc/quiterss.profile b/etc/quiterss.profile
index f820b590e..0d02cacae 100644
--- a/etc/quiterss.profile
+++ b/etc/quiterss.profile
@@ -15,10 +15,10 @@ include /etc/firejail/disable-devel.inc
15include /etc/firejail/disable-passwdmgr.inc 15include /etc/firejail/disable-passwdmgr.inc
16include /etc/firejail/disable-programs.inc 16include /etc/firejail/disable-programs.inc
17 17
18mkdir ~/.cache/QuiteRss 18mkdir ${HOME}/.cache/QuiteRss
19mkdir ~/.config/QuiteRss 19mkdir ${HOME}/.config/QuiteRss
20mkdir ~/.local/share/data 20mkdir ${HOME}/.local/share/data
21mkdir ~/.local/share/data/QuiteRss 21mkdir ${HOME}/.local/share/data/QuiteRss
22whitelist ${HOME}/.cache/QuiteRss 22whitelist ${HOME}/.cache/QuiteRss
23whitelist ${HOME}/.config/QuiteRss/ 23whitelist ${HOME}/.config/QuiteRss/
24whitelist ${HOME}/.config/QuiteRssrc 24whitelist ${HOME}/.config/QuiteRssrc
diff --git a/etc/qupzilla.profile b/etc/qupzilla.profile
index 7b7086bde..74c7355b6 100644
--- a/etc/qupzilla.profile
+++ b/etc/qupzilla.profile
@@ -14,8 +14,8 @@ include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc 14include /etc/firejail/disable-programs.inc
15 15
16whitelist ${DOWNLOADS} 16whitelist ${DOWNLOADS}
17whitelist ~/.cache/qupzilla 17whitelist ${HOME}/.cache/qupzilla
18whitelist ~/.config/qupzilla 18whitelist ${HOME}/.config/qupzilla
19include /etc/firejail/whitelist-common.inc 19include /etc/firejail/whitelist-common.inc
20 20
21caps.drop all 21caps.drop all
diff --git a/etc/qutebrowser.profile b/etc/qutebrowser.profile
index 31721617f..b6834aaad 100644
--- a/etc/qutebrowser.profile
+++ b/etc/qutebrowser.profile
@@ -5,20 +5,20 @@ include /etc/firejail/qutebrowser.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.cache/qutebrowser 8noblacklist ${HOME}/.cache/qutebrowser
9noblacklist ~/.config/qutebrowser 9noblacklist ${HOME}/.config/qutebrowser
10 10
11include /etc/firejail/disable-common.inc 11include /etc/firejail/disable-common.inc
12include /etc/firejail/disable-devel.inc 12include /etc/firejail/disable-devel.inc
13include /etc/firejail/disable-programs.inc 13include /etc/firejail/disable-programs.inc
14 14
15mkdir ~/.cache/qutebrowser 15mkdir ${HOME}/.cache/qutebrowser
16mkdir ~/.config/qutebrowser 16mkdir ${HOME}/.config/qutebrowser
17mkdir ~/.local/share/qutebrowser 17mkdir ${HOME}/.local/share/qutebrowser
18whitelist ${DOWNLOADS} 18whitelist ${DOWNLOADS}
19whitelist ~/.cache/qutebrowser 19whitelist ${HOME}/.cache/qutebrowser
20whitelist ~/.config/qutebrowser 20whitelist ${HOME}/.config/qutebrowser
21whitelist ~/.local/share/qutebrowser 21whitelist ${HOME}/.local/share/qutebrowser
22include /etc/firejail/whitelist-common.inc 22include /etc/firejail/whitelist-common.inc
23 23
24caps.drop all 24caps.drop all
diff --git a/etc/rambox.profile b/etc/rambox.profile
index 2696df86b..f17f1d202 100644
--- a/etc/rambox.profile
+++ b/etc/rambox.profile
@@ -5,18 +5,18 @@ include /etc/firejail/rambox.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.config/Rambox 8noblacklist ${HOME}/.config/Rambox
9noblacklist ~/.pki 9noblacklist ${HOME}/.pki
10 10
11include /etc/firejail/disable-common.inc 11include /etc/firejail/disable-common.inc
12include /etc/firejail/disable-devel.inc 12include /etc/firejail/disable-devel.inc
13include /etc/firejail/disable-programs.inc 13include /etc/firejail/disable-programs.inc
14 14
15mkdir ~/.config/Rambox 15mkdir ${HOME}/.config/Rambox
16mkdir ~/.pki 16mkdir ${HOME}/.pki
17whitelist ${DOWNLOADS} 17whitelist ${DOWNLOADS}
18whitelist ~/.config/Rambox 18whitelist ${HOME}/.config/Rambox
19whitelist ~/.pki 19whitelist ${HOME}/.pki
20include /etc/firejail/whitelist-common.inc 20include /etc/firejail/whitelist-common.inc
21 21
22caps.drop all 22caps.drop all
diff --git a/etc/ranger.profile b/etc/ranger.profile
index 0dac16424..211a1b2d5 100644
--- a/etc/ranger.profile
+++ b/etc/ranger.profile
@@ -11,7 +11,7 @@ blacklist /run/user/*/bus
11noblacklist /usr/bin/perl 11noblacklist /usr/bin/perl
12noblacklist /usr/lib/perl* 12noblacklist /usr/lib/perl*
13noblacklist /usr/share/perl* 13noblacklist /usr/share/perl*
14noblacklist ~/.config/ranger 14noblacklist ${HOME}/.config/ranger
15 15
16include /etc/firejail/disable-common.inc 16include /etc/firejail/disable-common.inc
17include /etc/firejail/disable-devel.inc 17include /etc/firejail/disable-devel.inc
diff --git a/etc/ristretto.profile b/etc/ristretto.profile
index 3de5de34a..114bb30f4 100644
--- a/etc/ristretto.profile
+++ b/etc/ristretto.profile
@@ -6,8 +6,8 @@ include /etc/firejail/ristretto.local
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ${HOME}/.config/ristretto 8noblacklist ${HOME}/.config/ristretto
9noblacklist ~/.Steam 9noblacklist ${HOME}/.Steam
10noblacklist ~/.steam 10noblacklist ${HOME}/.steam
11 11
12include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-devel.inc 13include /etc/firejail/disable-devel.inc
diff --git a/etc/scribus.profile b/etc/scribus.profile
index e49d484ed..001b91387 100644
--- a/etc/scribus.profile
+++ b/etc/scribus.profile
@@ -8,20 +8,20 @@ include /etc/firejail/globals.local
8blacklist /run/user/*/bus 8blacklist /run/user/*/bus
9 9
10# Support for PDF readers comes with Scribus 1.5 and higher 10# Support for PDF readers comes with Scribus 1.5 and higher
11noblacklist ~/.config/okularpartrc 11noblacklist ${HOME}/.config/okularpartrc
12noblacklist ~/.config/okularrc 12noblacklist ${HOME}/.config/okularrc
13noblacklist ~/.config/scribus 13noblacklist ${HOME}/.config/scribus
14noblacklist ~/.config/scribusrc 14noblacklist ${HOME}/.config/scribusrc
15noblacklist ~/.gimp* 15noblacklist ${HOME}/.gimp*
16noblacklist ~/.kde/share/apps/okular 16noblacklist ${HOME}/.kde/share/apps/okular
17noblacklist ~/.kde/share/config/okularpartrc 17noblacklist ${HOME}/.kde/share/config/okularpartrc
18noblacklist ~/.kde/share/config/okularrc 18noblacklist ${HOME}/.kde/share/config/okularrc
19noblacklist ~/.kde4/share/apps/okular 19noblacklist ${HOME}/.kde4/share/apps/okular
20noblacklist ~/.kde4/share/config/okularpartrc 20noblacklist ${HOME}/.kde4/share/config/okularpartrc
21noblacklist ~/.kde4/share/config/okularrc 21noblacklist ${HOME}/.kde4/share/config/okularrc
22noblacklist ~/.local/share/okular 22noblacklist ${HOME}/.local/share/okular
23noblacklist ~/.local/share/scribus 23noblacklist ${HOME}/.local/share/scribus
24noblacklist ~/.scribus 24noblacklist ${HOME}/.scribus
25 25
26include /etc/firejail/disable-common.inc 26include /etc/firejail/disable-common.inc
27include /etc/firejail/disable-devel.inc 27include /etc/firejail/disable-devel.inc
diff --git a/etc/seamonkey.profile b/etc/seamonkey.profile
index 36dde66b0..cfd03300a 100644
--- a/etc/seamonkey.profile
+++ b/etc/seamonkey.profile
@@ -5,34 +5,34 @@ include /etc/firejail/seamonkey.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.cache/mozilla 8noblacklist ${HOME}/.cache/mozilla
9noblacklist ~/.mozilla 9noblacklist ${HOME}/.mozilla
10noblacklist ~/.pki 10noblacklist ${HOME}/.pki
11 11
12include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-devel.inc 13include /etc/firejail/disable-devel.inc
14include /etc/firejail/disable-programs.inc 14include /etc/firejail/disable-programs.inc
15 15
16mkdir ~/.cache/mozilla 16mkdir ${HOME}/.cache/mozilla
17mkdir ~/.mozilla 17mkdir ${HOME}/.mozilla
18whitelist ${DOWNLOADS} 18whitelist ${DOWNLOADS}
19whitelist ~/.cache/gnome-mplayer/plugin 19whitelist ${HOME}/.cache/gnome-mplayer/plugin
20whitelist ~/.cache/mozilla 20whitelist ${HOME}/.cache/mozilla
21whitelist ~/.config/gnome-mplayer 21whitelist ${HOME}/.config/gnome-mplayer
22whitelist ~/.config/pipelight-silverlight5.1 22whitelist ${HOME}/.config/pipelight-silverlight5.1
23whitelist ~/.config/pipelight-widevine 23whitelist ${HOME}/.config/pipelight-widevine
24whitelist ~/.keysnail.js 24whitelist ${HOME}/.keysnail.js
25whitelist ~/.lastpass 25whitelist ${HOME}/.lastpass
26whitelist ~/.mozilla 26whitelist ${HOME}/.mozilla
27whitelist ~/.pentadactyl 27whitelist ${HOME}/.pentadactyl
28whitelist ~/.pentadactylrc 28whitelist ${HOME}/.pentadactylrc
29whitelist ~/.pki 29whitelist ${HOME}/.pki
30whitelist ~/.vimperator 30whitelist ${HOME}/.vimperator
31whitelist ~/.vimperatorrc 31whitelist ${HOME}/.vimperatorrc
32whitelist ~/.wine-pipelight 32whitelist ${HOME}/.wine-pipelight
33whitelist ~/.wine-pipelight64 33whitelist ${HOME}/.wine-pipelight64
34whitelist ~/.zotero 34whitelist ${HOME}/.zotero
35whitelist ~/dwhelper 35whitelist ${HOME}/dwhelper
36include /etc/firejail/whitelist-common.inc 36include /etc/firejail/whitelist-common.inc
37 37
38caps.drop all 38caps.drop all
diff --git a/etc/signal-desktop.profile b/etc/signal-desktop.profile
index 88e3eef20..b9f7a6c33 100644
--- a/etc/signal-desktop.profile
+++ b/etc/signal-desktop.profile
@@ -5,16 +5,16 @@ include /etc/firejail/signal-desktop.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.config/Signal 8noblacklist ${HOME}/.config/Signal
9 9
10include /etc/firejail/disable-common.inc 10include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-devel.inc 11include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-programs.inc 12include /etc/firejail/disable-programs.inc
13include /etc/firejail/disable-passwdmgr.inc 13include /etc/firejail/disable-passwdmgr.inc
14 14
15mkdir ~/.config/Signal 15mkdir ${HOME}/.config/Signal
16whitelist ${DOWNLOADS} 16whitelist ${DOWNLOADS}
17whitelist ~/.config/Signal 17whitelist ${HOME}/.config/Signal
18include /etc/firejail/whitelist-common.inc 18include /etc/firejail/whitelist-common.inc
19include /etc/firejail/whitelist-var-common.inc 19include /etc/firejail/whitelist-var-common.inc
20 20
diff --git a/etc/simple-scan.profile b/etc/simple-scan.profile
index edd4db861..b7dc3c57c 100644
--- a/etc/simple-scan.profile
+++ b/etc/simple-scan.profile
@@ -5,7 +5,7 @@ include /etc/firejail/simple-scan.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.cache/simple-scan 8noblacklist ${HOME}/.cache/simple-scan
9 9
10include /etc/firejail/disable-common.inc 10include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-devel.inc 11include /etc/firejail/disable-devel.inc
diff --git a/etc/simutrans.profile b/etc/simutrans.profile
index 1cbd9756c..89d1f2925 100644
--- a/etc/simutrans.profile
+++ b/etc/simutrans.profile
@@ -7,14 +7,14 @@ include /etc/firejail/globals.local
7 7
8blacklist /run/user/*/bus 8blacklist /run/user/*/bus
9 9
10noblacklist ~/.simutrans 10noblacklist ${HOME}/.simutrans
11 11
12include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-passwdmgr.inc 13include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc 14include /etc/firejail/disable-programs.inc
15 15
16mkdir ~/.simutrans 16mkdir ${HOME}/.simutrans
17whitelist ~/.simutrans 17whitelist ${HOME}/.simutrans
18include /etc/firejail/whitelist-common.inc 18include /etc/firejail/whitelist-common.inc
19 19
20caps.drop all 20caps.drop all
diff --git a/etc/snap.profile b/etc/snap.profile
index 38aef7c23..345525c9a 100644
--- a/etc/snap.profile
+++ b/etc/snap.profile
@@ -12,5 +12,5 @@ include /etc/firejail/disable-passwdmgr.inc
12include /etc/firejail/disable-programs.inc 12include /etc/firejail/disable-programs.inc
13 13
14whitelist ${DOWNLOADS} 14whitelist ${DOWNLOADS}
15whitelist ~/snap 15whitelist ${HOME}/snap
16include /etc/firejail/whitelist-common.inc 16include /etc/firejail/whitelist-common.inc
diff --git a/etc/ssh-agent.profile b/etc/ssh-agent.profile
index fa5728d9b..b71c20231 100644
--- a/etc/ssh-agent.profile
+++ b/etc/ssh-agent.profile
@@ -10,7 +10,7 @@ blacklist /tmp/.X11-unix
10 10
11noblacklist /etc/ssh 11noblacklist /etc/ssh
12noblacklist /tmp/ssh-* 12noblacklist /tmp/ssh-*
13noblacklist ~/.ssh 13noblacklist ${HOME}/.ssh
14 14
15include /etc/firejail/disable-common.inc 15include /etc/firejail/disable-common.inc
16include /etc/firejail/disable-passwdmgr.inc 16include /etc/firejail/disable-passwdmgr.inc
diff --git a/etc/ssh.profile b/etc/ssh.profile
index 7ac0b8417..df86a276e 100644
--- a/etc/ssh.profile
+++ b/etc/ssh.profile
@@ -8,7 +8,7 @@ include /etc/firejail/globals.local
8 8
9noblacklist /etc/ssh 9noblacklist /etc/ssh
10noblacklist /tmp/ssh-* 10noblacklist /tmp/ssh-*
11noblacklist ~/.ssh 11noblacklist ${HOME}/.ssh
12 12
13include /etc/firejail/disable-common.inc 13include /etc/firejail/disable-common.inc
14include /etc/firejail/disable-passwdmgr.inc 14include /etc/firejail/disable-passwdmgr.inc
diff --git a/etc/stellarium.profile b/etc/stellarium.profile
index 360b9f881..889a21a60 100644
--- a/etc/stellarium.profile
+++ b/etc/stellarium.profile
@@ -5,18 +5,18 @@ include /etc/firejail/stellarium.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.config/stellarium 8noblacklist ${HOME}/.config/stellarium
9noblacklist ~/.stellarium 9noblacklist ${HOME}/.stellarium
10 10
11include /etc/firejail/disable-common.inc 11include /etc/firejail/disable-common.inc
12include /etc/firejail/disable-devel.inc 12include /etc/firejail/disable-devel.inc
13include /etc/firejail/disable-passwdmgr.inc 13include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc 14include /etc/firejail/disable-programs.inc
15 15
16mkdir ~/.config/stellarium 16mkdir ${HOME}/.config/stellarium
17mkdir ~/.stellarium 17mkdir ${HOME}/.stellarium
18whitelist ~/.config/stellarium 18whitelist ${HOME}/.config/stellarium
19whitelist ~/.stellarium 19whitelist ${HOME}/.stellarium
20include /etc/firejail/whitelist-common.inc 20include /etc/firejail/whitelist-common.inc
21include /etc/firejail/whitelist-var-common.inc 21include /etc/firejail/whitelist-var-common.inc
22 22
diff --git a/etc/supertux2.profile b/etc/supertux2.profile
index 120f0a043..2b5bb07c3 100644
--- a/etc/supertux2.profile
+++ b/etc/supertux2.profile
@@ -7,14 +7,14 @@ include /etc/firejail/globals.local
7 7
8blacklist /run/user/*/bus 8blacklist /run/user/*/bus
9 9
10noblacklist ~/.local/share/supertux2 10noblacklist ${HOME}/.local/share/supertux2
11 11
12include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-passwdmgr.inc 13include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc 14include /etc/firejail/disable-programs.inc
15 15
16mkdir ~/.local/share/supertux2 16mkdir ${HOME}/.local/share/supertux2
17whitelist ~/.local/share/supertux2 17whitelist ${HOME}/.local/share/supertux2
18include /etc/firejail/whitelist-common.inc 18include /etc/firejail/whitelist-common.inc
19include /etc/firejail/whitelist-var-common.inc 19include /etc/firejail/whitelist-var-common.inc
20 20
diff --git a/etc/surf.profile b/etc/surf.profile
index a12212f16..6f7bd16f6 100644
--- a/etc/surf.profile
+++ b/etc/surf.profile
@@ -5,13 +5,13 @@ include /etc/firejail/surf.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.surf 8noblacklist ${HOME}/.surf
9 9
10include /etc/firejail/disable-common.inc 10include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-devel.inc 11include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-programs.inc 12include /etc/firejail/disable-programs.inc
13 13
14mkdir ~/.surf 14mkdir ${HOME}/.surf
15whitelist ${DOWNLOADS} 15whitelist ${DOWNLOADS}
16include /etc/firejail/whitelist-common.inc 16include /etc/firejail/whitelist-common.inc
17 17
diff --git a/etc/thunderbird.profile b/etc/thunderbird.profile
index 52965cf90..8af981d70 100644
--- a/etc/thunderbird.profile
+++ b/etc/thunderbird.profile
@@ -8,19 +8,19 @@ include /etc/firejail/globals.local
8# Users have thunderbird set to open a browser by clicking a link in an email 8# Users have thunderbird set to open a browser by clicking a link in an email
9# We are not allowed to blacklist browser-specific directories 9# We are not allowed to blacklist browser-specific directories
10 10
11noblacklist ~/.cache/thunderbird 11noblacklist ${HOME}/.cache/thunderbird
12noblacklist ~/.gnupg 12noblacklist ${HOME}/.gnupg
13noblacklist ~/.icedove 13noblacklist ${HOME}/.icedove
14noblacklist ~/.thunderbird 14noblacklist ${HOME}/.thunderbird
15 15
16mkdir ~/.cache/thunderbird 16mkdir ${HOME}/.cache/thunderbird
17mkdir ~/.gnupg 17mkdir ${HOME}/.gnupg
18mkdir ~/.icedove 18mkdir ${HOME}/.icedove
19mkdir ~/.thunderbird 19mkdir ${HOME}/.thunderbird
20whitelist ~/.cache/thunderbird 20whitelist ${HOME}/.cache/thunderbird
21whitelist ~/.gnupg 21whitelist ${HOME}/.gnupg
22whitelist ~/.icedove 22whitelist ${HOME}/.icedove
23whitelist ~/.thunderbird 23whitelist ${HOME}/.thunderbird
24include /etc/firejail/whitelist-common.inc 24include /etc/firejail/whitelist-common.inc
25include /etc/firejail/whitelist-var-common.inc 25include /etc/firejail/whitelist-var-common.inc
26 26
@@ -28,7 +28,7 @@ include /etc/firejail/whitelist-var-common.inc
28ignore private-tmp 28ignore private-tmp
29machine-id 29machine-id
30disable-mnt 30disable-mnt
31read-only ~/.config/mimeapps.list 31read-only ${HOME}/.config/mimeapps.list
32 32
33# allow browsers 33# allow browsers
34# Redirect 34# Redirect
diff --git a/etc/torbrowser-launcher.profile b/etc/torbrowser-launcher.profile
index 85af86068..c2e182cea 100644
--- a/etc/torbrowser-launcher.profile
+++ b/etc/torbrowser-launcher.profile
@@ -5,18 +5,18 @@ include /etc/firejail/torbrowser-launcher.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.tor-browser-en 8noblacklist ${HOME}/.tor-browser-en
9noblacklist ~/.config/torbrowser 9noblacklist ${HOME}/.config/torbrowser
10noblacklist ~/.local/share/torbrowser 10noblacklist ${HOME}/.local/share/torbrowser
11 11
12include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-devel.inc 13include /etc/firejail/disable-devel.inc
14include /etc/firejail/disable-passwdmgr.inc 14include /etc/firejail/disable-passwdmgr.inc
15include /etc/firejail/disable-programs.inc 15include /etc/firejail/disable-programs.inc
16 16
17whitelist ~/.tor-browser-en 17whitelist ${HOME}/.tor-browser-en
18whitelist ~/.config/torbrowser 18whitelist ${HOME}/.config/torbrowser
19whitelist ~/.local/share/torbrowser 19whitelist ${HOME}/.local/share/torbrowser
20include /etc/firejail/whitelist-common.inc 20include /etc/firejail/whitelist-common.inc
21 21
22caps.drop all 22caps.drop all
diff --git a/etc/totem.profile b/etc/totem.profile
index ccf292da0..be0617024 100644
--- a/etc/totem.profile
+++ b/etc/totem.profile
@@ -5,8 +5,8 @@ include /etc/firejail/totem.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.config/totem 8noblacklist ${HOME}/.config/totem
9noblacklist ~/.local/share/totem 9noblacklist ${HOME}/.local/share/totem
10 10
11include /etc/firejail/disable-common.inc 11include /etc/firejail/disable-common.inc
12include /etc/firejail/disable-devel.inc 12include /etc/firejail/disable-devel.inc
diff --git a/etc/transmission-gtk.profile b/etc/transmission-gtk.profile
index 0dad515d0..dac1c07b1 100644
--- a/etc/transmission-gtk.profile
+++ b/etc/transmission-gtk.profile
@@ -13,11 +13,11 @@ include /etc/firejail/disable-devel.inc
13include /etc/firejail/disable-passwdmgr.inc 13include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc 14include /etc/firejail/disable-programs.inc
15 15
16mkdir ~/.cache/transmission 16mkdir ${HOME}/.cache/transmission
17mkdir ~/.config/transmission 17mkdir ${HOME}/.config/transmission
18whitelist ${DOWNLOADS} 18whitelist ${DOWNLOADS}
19whitelist ~/.cache/transmission 19whitelist ${HOME}/.cache/transmission
20whitelist ~/.config/transmission 20whitelist ${HOME}/.config/transmission
21include /etc/firejail/whitelist-common.inc 21include /etc/firejail/whitelist-common.inc
22include /etc/firejail/whitelist-var-common.inc 22include /etc/firejail/whitelist-var-common.inc
23 23
diff --git a/etc/transmission-qt.profile b/etc/transmission-qt.profile
index 1da9afb5a..2d3ad0c7a 100644
--- a/etc/transmission-qt.profile
+++ b/etc/transmission-qt.profile
@@ -13,11 +13,11 @@ include /etc/firejail/disable-devel.inc
13include /etc/firejail/disable-passwdmgr.inc 13include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc 14include /etc/firejail/disable-programs.inc
15 15
16mkdir ~/.cache/transmission 16mkdir ${HOME}/.cache/transmission
17mkdir ~/.config/transmission 17mkdir ${HOME}/.config/transmission
18whitelist ${DOWNLOADS} 18whitelist ${DOWNLOADS}
19whitelist ~/.cache/transmission 19whitelist ${HOME}/.cache/transmission
20whitelist ~/.config/transmission 20whitelist ${HOME}/.config/transmission
21include /etc/firejail/whitelist-common.inc 21include /etc/firejail/whitelist-common.inc
22include /etc/firejail/whitelist-var-common.inc 22include /etc/firejail/whitelist-var-common.inc
23 23
diff --git a/etc/tuxguitar.profile b/etc/tuxguitar.profile
index 30e2a619d..1a426cbf6 100644
--- a/etc/tuxguitar.profile
+++ b/etc/tuxguitar.profile
@@ -5,8 +5,8 @@ include /etc/firejail/tuxguitar.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.java 8noblacklist ${HOME}/.java
9noblacklist ~/.tuxguitar* 9noblacklist ${HOME}/.tuxguitar*
10 10
11include /etc/firejail/disable-common.inc 11include /etc/firejail/disable-common.inc
12include /etc/firejail/disable-devel.inc 12include /etc/firejail/disable-devel.inc
diff --git a/etc/uget-gtk.profile b/etc/uget-gtk.profile
index 56ff4f886..8fbc3b7e6 100644
--- a/etc/uget-gtk.profile
+++ b/etc/uget-gtk.profile
@@ -11,9 +11,9 @@ include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-devel.inc 11include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-programs.inc 12include /etc/firejail/disable-programs.inc
13 13
14mkdir ~/.config/uGet 14mkdir ${HOME}/.config/uGet
15whitelist ${DOWNLOADS} 15whitelist ${DOWNLOADS}
16whitelist ~/.config/uGet 16whitelist ${HOME}/.config/uGet
17include /etc/firejail/whitelist-common.inc 17include /etc/firejail/whitelist-common.inc
18 18
19caps.drop all 19caps.drop all
diff --git a/etc/unknown-horizons.profile b/etc/unknown-horizons.profile
index 5f70843d6..34c148ee9 100644
--- a/etc/unknown-horizons.profile
+++ b/etc/unknown-horizons.profile
@@ -5,14 +5,14 @@ include /etc/firejail/unknown-horizons.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.unknown-horizons 8noblacklist ${HOME}/.unknown-horizons
9 9
10include /etc/firejail/disable-common.inc 10include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-passwdmgr.inc 11include /etc/firejail/disable-passwdmgr.inc
12include /etc/firejail/disable-programs.inc 12include /etc/firejail/disable-programs.inc
13 13
14mkdir ~/.unknown-horizons 14mkdir ${HOME}/.unknown-horizons
15whitelist ~/.unknown-horizons 15whitelist ${HOME}/.unknown-horizons
16include /etc/firejail/whitelist-common.inc 16include /etc/firejail/whitelist-common.inc
17 17
18caps.drop all 18caps.drop all
diff --git a/etc/uzbl-browser.profile b/etc/uzbl-browser.profile
index e7c931f30..1070a6c2c 100644
--- a/etc/uzbl-browser.profile
+++ b/etc/uzbl-browser.profile
@@ -5,22 +5,22 @@ include /etc/firejail/uzbl-browser.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.config/uzbl 8noblacklist ${HOME}/.config/uzbl
9noblacklist ~/.gnupg 9noblacklist ${HOME}/.gnupg
10 10
11include /etc/firejail/disable-common.inc 11include /etc/firejail/disable-common.inc
12include /etc/firejail/disable-devel.inc 12include /etc/firejail/disable-devel.inc
13include /etc/firejail/disable-programs.inc 13include /etc/firejail/disable-programs.inc
14 14
15mkdir ~/.config/uzbl 15mkdir ${HOME}/.config/uzbl
16mkdir ~/.gnupg 16mkdir ${HOME}/.gnupg
17mkdir ~/.local/share/uzbl 17mkdir ${HOME}/.local/share/uzbl
18mkdir ~/.password-store 18mkdir ${HOME}/.password-store
19whitelist ${DOWNLOADS} 19whitelist ${DOWNLOADS}
20whitelist ~/.config/uzbl 20whitelist ${HOME}/.config/uzbl
21whitelist ~/.gnupg 21whitelist ${HOME}/.gnupg
22whitelist ~/.local/share/uzbl 22whitelist ${HOME}/.local/share/uzbl
23whitelist ~/.password-store 23whitelist ${HOME}/.password-store
24include /etc/firejail/whitelist-common.inc 24include /etc/firejail/whitelist-common.inc
25 25
26caps.drop all 26caps.drop all
diff --git a/etc/viewnior.profile b/etc/viewnior.profile
index 92d59e732..25e5956ba 100644
--- a/etc/viewnior.profile
+++ b/etc/viewnior.profile
@@ -6,12 +6,12 @@ include /etc/firejail/viewnior.local
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8blacklist /run/user/*/bus 8blacklist /run/user/*/bus
9blacklist ~/.Xauthority 9blacklist ${HOME}/.Xauthority
10blacklist ~/.bashrc 10blacklist ${HOME}/.bashrc
11 11
12noblacklist ~/.Steam 12noblacklist ${HOME}/.Steam
13noblacklist ~/.config/viewnior 13noblacklist ${HOME}/.config/viewnior
14noblacklist ~/.steam 14noblacklist ${HOME}/.steam
15 15
16include /etc/firejail/disable-common.inc 16include /etc/firejail/disable-common.inc
17include /etc/firejail/disable-devel.inc 17include /etc/firejail/disable-devel.inc
diff --git a/etc/vim.profile b/etc/vim.profile
index e1d5da9e3..7fe16e628 100644
--- a/etc/vim.profile
+++ b/etc/vim.profile
@@ -5,9 +5,9 @@ include /etc/firejail/vim.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.vim 8noblacklist ${HOME}/.vim
9noblacklist ~/.viminfo 9noblacklist ${HOME}/.viminfo
10noblacklist ~/.vimrc 10noblacklist ${HOME}/.vimrc
11 11
12include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-passwdmgr.inc 13include /etc/firejail/disable-passwdmgr.inc
diff --git a/etc/virtualbox.profile b/etc/virtualbox.profile
index b01e6d144..61177698a 100644
--- a/etc/virtualbox.profile
+++ b/etc/virtualbox.profile
@@ -16,10 +16,10 @@ include /etc/firejail/disable-common.inc
16include /etc/firejail/disable-passwdmgr.inc 16include /etc/firejail/disable-passwdmgr.inc
17include /etc/firejail/disable-programs.inc 17include /etc/firejail/disable-programs.inc
18 18
19mkdir ~/.config/VirtualBox 19mkdir ${HOME}/.config/VirtualBox
20mkdir ~/VirtualBox VMs 20mkdir ${HOME}/VirtualBox VMs
21whitelist ~/.config/VirtualBox 21whitelist ${HOME}/.config/VirtualBox
22whitelist ~/VirtualBox VMs 22whitelist ${HOME}/VirtualBox VMs
23whitelist ${DOWNLOADS} 23whitelist ${DOWNLOADS}
24include /etc/firejail/whitelist-common.inc 24include /etc/firejail/whitelist-common.inc
25include /etc/firejail/whitelist-var-common.inc 25include /etc/firejail/whitelist-var-common.inc
diff --git a/etc/vivaldi.profile b/etc/vivaldi.profile
index 3cbc5b45c..039c8ed58 100644
--- a/etc/vivaldi.profile
+++ b/etc/vivaldi.profile
@@ -5,18 +5,18 @@ include /etc/firejail/vivaldi.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.cache/vivaldi 8noblacklist ${HOME}/.cache/vivaldi
9noblacklist ~/.config/vivaldi 9noblacklist ${HOME}/.config/vivaldi
10 10
11include /etc/firejail/disable-common.inc 11include /etc/firejail/disable-common.inc
12include /etc/firejail/disable-devel.inc 12include /etc/firejail/disable-devel.inc
13include /etc/firejail/disable-programs.inc 13include /etc/firejail/disable-programs.inc
14 14
15mkdir ~/.cache/vivaldi 15mkdir ${HOME}/.cache/vivaldi
16mkdir ~/.config/vivaldi 16mkdir ${HOME}/.config/vivaldi
17whitelist ${DOWNLOADS} 17whitelist ${DOWNLOADS}
18whitelist ~/.cache/vivaldi 18whitelist ${HOME}/.cache/vivaldi
19whitelist ~/.config/vivaldi 19whitelist ${HOME}/.config/vivaldi
20include /etc/firejail/whitelist-common.inc 20include /etc/firejail/whitelist-common.inc
21include /etc/firejail/whitelist-var-common.inc 21include /etc/firejail/whitelist-var-common.inc
22 22
diff --git a/etc/vym.profile b/etc/vym.profile
index b38d87fde..b73916b0f 100644
--- a/etc/vym.profile
+++ b/etc/vym.profile
@@ -5,7 +5,7 @@ include /etc/firejail/vym.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.config/InSilmaril 8noblacklist ${HOME}/.config/InSilmaril
9 9
10include /etc/firejail/disable-common.inc 10include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-devel.inc 11include /etc/firejail/disable-devel.inc
diff --git a/etc/w3m.profile b/etc/w3m.profile
index eddedd37a..2d56aa660 100644
--- a/etc/w3m.profile
+++ b/etc/w3m.profile
@@ -7,7 +7,7 @@ include /etc/firejail/globals.local
7 7
8blacklist /tmp/.X11-unix 8blacklist /tmp/.X11-unix
9 9
10noblacklist ~/.w3m 10noblacklist ${HOME}/.w3m
11 11
12include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-devel.inc 13include /etc/firejail/disable-devel.inc
diff --git a/etc/warzone2100.profile b/etc/warzone2100.profile
index 43eacdafc..d8d68da64 100644
--- a/etc/warzone2100.profile
+++ b/etc/warzone2100.profile
@@ -5,17 +5,17 @@ include /etc/firejail/warzone2100.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.warzone2100-3.* 8noblacklist ${HOME}/.warzone2100-3.*
9 9
10include /etc/firejail/disable-common.inc 10include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-devel.inc 11include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-passwdmgr.inc 12include /etc/firejail/disable-passwdmgr.inc
13include /etc/firejail/disable-programs.inc 13include /etc/firejail/disable-programs.inc
14 14
15# mkdir ~/.warzone2100-3.1 15# mkdir ${HOME}/.warzone2100-3.1
16# mkdir ~/.warzone2100-3.2 16# mkdir ${HOME}/.warzone2100-3.2
17whitelist ~/.warzone2100-3.1 17whitelist ${HOME}/.warzone2100-3.1
18whitelist ~/.warzone2100-3.2 18whitelist ${HOME}/.warzone2100-3.2
19include /etc/firejail/whitelist-common.inc 19include /etc/firejail/whitelist-common.inc
20include /etc/firejail/whitelist-var-common.inc 20include /etc/firejail/whitelist-var-common.inc
21 21
diff --git a/etc/waterfox.profile b/etc/waterfox.profile
index 53543e97e..b2abb3a5f 100644
--- a/etc/waterfox.profile
+++ b/etc/waterfox.profile
@@ -5,65 +5,65 @@ include /etc/firejail/waterfox.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.cache/mozilla 8noblacklist ${HOME}/.cache/mozilla
9noblacklist ~/.cache/waterfox 9noblacklist ${HOME}/.cache/waterfox
10noblacklist ~/.config/okularpartrc 10noblacklist ${HOME}/.config/okularpartrc
11noblacklist ~/.config/okularrc 11noblacklist ${HOME}/.config/okularrc
12noblacklist ~/.config/qpdfview 12noblacklist ${HOME}/.config/qpdfview
13noblacklist ~/.kde/share/apps/okular 13noblacklist ${HOME}/.kde/share/apps/okular
14noblacklist ~/.kde/share/config/okularpartrc 14noblacklist ${HOME}/.kde/share/config/okularpartrc
15noblacklist ~/.kde/share/config/okularrc 15noblacklist ${HOME}/.kde/share/config/okularrc
16noblacklist ~/.kde4/share/apps/okular 16noblacklist ${HOME}/.kde4/share/apps/okular
17noblacklist ~/.kde4/share/config/okularpartrc 17noblacklist ${HOME}/.kde4/share/config/okularpartrc
18noblacklist ~/.kde4/share/config/okularrc 18noblacklist ${HOME}/.kde4/share/config/okularrc
19# noblacklist ~/.local/share/gnome-shell/extensions 19# noblacklist ${HOME}/.local/share/gnome-shell/extensions
20noblacklist ~/.local/share/okular 20noblacklist ${HOME}/.local/share/okular
21noblacklist ~/.local/share/qpdfview 21noblacklist ${HOME}/.local/share/qpdfview
22noblacklist ~/.mozilla 22noblacklist ${HOME}/.mozilla
23noblacklist ~/.waterfox 23noblacklist ${HOME}/.waterfox
24noblacklist ~/.pki 24noblacklist ${HOME}/.pki
25 25
26include /etc/firejail/disable-common.inc 26include /etc/firejail/disable-common.inc
27include /etc/firejail/disable-devel.inc 27include /etc/firejail/disable-devel.inc
28include /etc/firejail/disable-programs.inc 28include /etc/firejail/disable-programs.inc
29 29
30mkdir ~/.cache/mozilla/firefox 30mkdir ${HOME}/.cache/mozilla/firefox
31mkdir ~/.mozilla 31mkdir ${HOME}/.mozilla
32mkdir ~/.cache/waterfox 32mkdir ${HOME}/.cache/waterfox
33mkdir ~/.waterfox 33mkdir ${HOME}/.waterfox
34mkdir ~/.pki 34mkdir ${HOME}/.pki
35whitelist ${DOWNLOADS} 35whitelist ${DOWNLOADS}
36whitelist ~/.cache/gnome-mplayer/plugin 36whitelist ${HOME}/.cache/gnome-mplayer/plugin
37whitelist ~/.cache/mozilla/firefox 37whitelist ${HOME}/.cache/mozilla/firefox
38whitelist ~/.cache/waterfox 38whitelist ${HOME}/.cache/waterfox
39whitelist ~/.config/gnome-mplayer 39whitelist ${HOME}/.config/gnome-mplayer
40whitelist ~/.config/okularpartrc 40whitelist ${HOME}/.config/okularpartrc
41whitelist ~/.config/okularrc 41whitelist ${HOME}/.config/okularrc
42whitelist ~/.config/pipelight-silverlight5.1 42whitelist ${HOME}/.config/pipelight-silverlight5.1
43whitelist ~/.config/pipelight-widevine 43whitelist ${HOME}/.config/pipelight-widevine
44whitelist ~/.config/qpdfview 44whitelist ${HOME}/.config/qpdfview
45whitelist ~/.kde/share/apps/okular 45whitelist ${HOME}/.kde/share/apps/okular
46whitelist ~/.kde/share/config/okularpartrc 46whitelist ${HOME}/.kde/share/config/okularpartrc
47whitelist ~/.kde/share/config/okularrc 47whitelist ${HOME}/.kde/share/config/okularrc
48whitelist ~/.kde4/share/apps/okular 48whitelist ${HOME}/.kde4/share/apps/okular
49whitelist ~/.kde4/share/config/okularpartrc 49whitelist ${HOME}/.kde4/share/config/okularpartrc
50whitelist ~/.kde4/share/config/okularrc 50whitelist ${HOME}/.kde4/share/config/okularrc
51whitelist ~/.keysnail.js 51whitelist ${HOME}/.keysnail.js
52whitelist ~/.lastpass 52whitelist ${HOME}/.lastpass
53whitelist ~/.local/share/gnome-shell/extensions 53whitelist ${HOME}/.local/share/gnome-shell/extensions
54whitelist ~/.local/share/okular 54whitelist ${HOME}/.local/share/okular
55whitelist ~/.local/share/qpdfview 55whitelist ${HOME}/.local/share/qpdfview
56whitelist ~/.mozilla 56whitelist ${HOME}/.mozilla
57whitelist ~/.waterfox 57whitelist ${HOME}/.waterfox
58whitelist ~/.pentadactyl 58whitelist ${HOME}/.pentadactyl
59whitelist ~/.pentadactylrc 59whitelist ${HOME}/.pentadactylrc
60whitelist ~/.pki 60whitelist ${HOME}/.pki
61whitelist ~/.vimperator 61whitelist ${HOME}/.vimperator
62whitelist ~/.vimperatorrc 62whitelist ${HOME}/.vimperatorrc
63whitelist ~/.wine-pipelight 63whitelist ${HOME}/.wine-pipelight
64whitelist ~/.wine-pipelight64 64whitelist ${HOME}/.wine-pipelight64
65whitelist ~/.zotero 65whitelist ${HOME}/.zotero
66whitelist ~/dwhelper 66whitelist ${HOME}/dwhelper
67include /etc/firejail/whitelist-common.inc 67include /etc/firejail/whitelist-common.inc
68include /etc/firejail/whitelist-var-common.inc 68include /etc/firejail/whitelist-var-common.inc
69 69
diff --git a/etc/wget.profile b/etc/wget.profile
index 510ef18f3..a16d770f2 100644
--- a/etc/wget.profile
+++ b/etc/wget.profile
@@ -8,7 +8,7 @@ include /etc/firejail/globals.local
8 8
9blacklist /tmp/.X11-unix 9blacklist /tmp/.X11-unix
10 10
11noblacklist ~/.wgetrc 11noblacklist ${HOME}/.wgetrc
12 12
13include /etc/firejail/disable-common.inc 13include /etc/firejail/disable-common.inc
14include /etc/firejail/disable-passwdmgr.inc 14include /etc/firejail/disable-passwdmgr.inc
diff --git a/etc/whitelist-common.inc b/etc/whitelist-common.inc
index 0a8bc4685..638f1d7fc 100644
--- a/etc/whitelist-common.inc
+++ b/etc/whitelist-common.inc
@@ -3,61 +3,61 @@ include /etc/firejail/whitelist-common.local
3 3
4# common whitelist for all profiles 4# common whitelist for all profiles
5 5
6whitelist ~/.XCompose 6whitelist ${HOME}/.XCompose
7whitelist ~/.config/mimeapps.list 7whitelist ${HOME}/.config/mimeapps.list
8whitelist ~/.icons 8whitelist ${HOME}/.icons
9whitelist ~/.local/share/icons 9whitelist ${HOME}/.local/share/icons
10whitelist ~/.config/user-dirs.dirs 10whitelist ${HOME}/.config/user-dirs.dirs
11read-only ~/.config/user-dirs.dirs 11read-only ${HOME}/.config/user-dirs.dirs
12whitelist ~/.asoundrc 12whitelist ${HOME}/.asoundrc
13whitelist ~/.config/Trolltech.conf 13whitelist ${HOME}/.config/Trolltech.conf
14whitelist ~/.local/share/mime 14whitelist ${HOME}/.local/share/mime
15whitelist ~/.drirc 15whitelist ${HOME}/.drirc
16whitelist ~/.mime.types 16whitelist ${HOME}/.mime.types
17whitelist ~/.local/share/applications 17whitelist ${HOME}/.local/share/applications
18read-only ~/.local/share/applications 18read-only ${HOME}/.local/share/applications
19whitelist ~/.config/ibus 19whitelist ${HOME}/.config/ibus
20 20
21# fonts 21# fonts
22whitelist ~/.fonts 22whitelist ${HOME}/.fonts
23whitelist ~/.fonts.d 23whitelist ${HOME}/.fonts.d
24whitelist ~/.fontconfig 24whitelist ${HOME}/.fontconfig
25whitelist ~/.fonts.conf 25whitelist ${HOME}/.fonts.conf
26whitelist ~/.fonts.conf.d 26whitelist ${HOME}/.fonts.conf.d
27whitelist ~/.local/share/fonts 27whitelist ${HOME}/.local/share/fonts
28whitelist ~/.config/fontconfig 28whitelist ${HOME}/.config/fontconfig
29whitelist ~/.cache/fontconfig 29whitelist ${HOME}/.cache/fontconfig
30whitelist ~/.pangorc 30whitelist ${HOME}/.pangorc
31 31
32# gtk 32# gtk
33whitelist ~/.gtkrc 33whitelist ${HOME}/.gtkrc
34whitelist ~/.gtkrc-2.0 34whitelist ${HOME}/.gtkrc-2.0
35whitelist ~/.gtk-2.0 35whitelist ${HOME}/.gtk-2.0
36whitelist ~/.config/gtk-2.0 36whitelist ${HOME}/.config/gtk-2.0
37whitelist ~/.config/gtk-3.0 37whitelist ${HOME}/.config/gtk-3.0
38whitelist ~/.config/gtkrc 38whitelist ${HOME}/.config/gtkrc
39whitelist ~/.config/gtkrc-2.0 39whitelist ${HOME}/.config/gtkrc-2.0
40whitelist ~/.themes 40whitelist ${HOME}/.themes
41whitelist ~/.local/share/themes 41whitelist ${HOME}/.local/share/themes
42whitelist ~/.kde/share/config/gtkrc 42whitelist ${HOME}/.kde/share/config/gtkrc
43whitelist ~/.kde/share/config/gtkrc-2.0 43whitelist ${HOME}/.kde/share/config/gtkrc-2.0
44whitelist ~/.kde4/share/config/gtkrc 44whitelist ${HOME}/.kde4/share/config/gtkrc
45whitelist ~/.kde4/share/config/gtkrc-2.0 45whitelist ${HOME}/.kde4/share/config/gtkrc-2.0
46whitelist ~/.gnome2 46whitelist ${HOME}/.gnome2
47whitelist ~/.gnome2-private 47whitelist ${HOME}/.gnome2-private
48 48
49# dconf 49# dconf
50mkdir ~/.config/dconf 50mkdir ${HOME}/.config/dconf
51whitelist ~/.config/dconf 51whitelist ${HOME}/.config/dconf
52 52
53# qt/kde 53# qt/kde
54whitelist ~/.config/kdeglobals 54whitelist ${HOME}/.config/kdeglobals
55whitelist ~/.config/kioslaverc 55whitelist ${HOME}/.config/kioslaverc
56whitelist ~/.kde/share/config/oxygenrc 56whitelist ${HOME}/.kde/share/config/oxygenrc
57whitelist ~/.kde/share/config/kdeglobals 57whitelist ${HOME}/.kde/share/config/kdeglobals
58whitelist ~/.kde/share/config/kioslaverc 58whitelist ${HOME}/.kde/share/config/kioslaverc
59whitelist ~/.kde/share/icons 59whitelist ${HOME}/.kde/share/icons
60whitelist ~/.kde4/share/config/oxygenrc 60whitelist ${HOME}/.kde4/share/config/oxygenrc
61whitelist ~/.kde4/share/config/kdeglobals 61whitelist ${HOME}/.kde4/share/config/kdeglobals
62whitelist ~/.kde4/share/config/kioslaverc 62whitelist ${HOME}/.kde4/share/config/kioslaverc
63whitelist ~/.kde4/share/icons 63whitelist ${HOME}/.kde4/share/icons
diff --git a/etc/wire.profile b/etc/wire.profile
index af14f686f..fc25cbc1e 100644
--- a/etc/wire.profile
+++ b/etc/wire.profile
@@ -8,8 +8,8 @@ include /etc/firejail/globals.local
8# Note: the current beta version of wire is located in /opt/Wire/wire and therefore not in PATH. 8# Note: the current beta version of wire is located in /opt/Wire/wire and therefore not in PATH.
9# To use wire with firejail run "firejail /opt/Wire/wire" 9# To use wire with firejail run "firejail /opt/Wire/wire"
10 10
11noblacklist ~/.config/Wire 11noblacklist ${HOME}/.config/Wire
12noblacklist ~/.config/wire 12noblacklist ${HOME}/.config/wire
13 13
14include /etc/firejail/disable-common.inc 14include /etc/firejail/disable-common.inc
15include /etc/firejail/disable-devel.inc 15include /etc/firejail/disable-devel.inc
diff --git a/etc/xfburn.profile b/etc/xfburn.profile
index ec1aca75f..fc90f67e2 100644
--- a/etc/xfburn.profile
+++ b/etc/xfburn.profile
@@ -5,7 +5,7 @@ include /etc/firejail/xfburn.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.config/xfburn 8noblacklist ${HOME}/.config/xfburn
9 9
10include /etc/firejail/disable-common.inc 10include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-devel.inc 11include /etc/firejail/disable-devel.inc
diff --git a/etc/xiphos.profile b/etc/xiphos.profile
index 5a07d4b74..91b782473 100644
--- a/etc/xiphos.profile
+++ b/etc/xiphos.profile
@@ -5,11 +5,11 @@ include /etc/firejail/xiphos.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8blacklist ~/.Xauthority 8blacklist ${HOME}/.Xauthority
9blacklist ~/.bashrc 9blacklist ${HOME}/.bashrc
10 10
11noblacklist ~/.sword 11noblacklist ${HOME}/.sword
12noblacklist ~/.xiphos 12noblacklist ${HOME}/.xiphos
13 13
14include /etc/firejail/disable-common.inc 14include /etc/firejail/disable-common.inc
15include /etc/firejail/disable-devel.inc 15include /etc/firejail/disable-devel.inc
diff --git a/etc/xplayer.profile b/etc/xplayer.profile
index d4a2fa846..8ea361d79 100644
--- a/etc/xplayer.profile
+++ b/etc/xplayer.profile
@@ -5,8 +5,8 @@ include /etc/firejail/xplayer.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.config/xplayer 8noblacklist ${HOME}/.config/xplayer
9noblacklist ~/.local/share/xplayer 9noblacklist ${HOME}/.local/share/xplayer
10 10
11include /etc/firejail/disable-common.inc 11include /etc/firejail/disable-common.inc
12include /etc/firejail/disable-devel.inc 12include /etc/firejail/disable-devel.inc
diff --git a/etc/xreader.profile b/etc/xreader.profile
index 76fae9fed..00bd1ee2f 100644
--- a/etc/xreader.profile
+++ b/etc/xreader.profile
@@ -5,9 +5,9 @@ include /etc/firejail/xreader.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.cache/xreader 8noblacklist ${HOME}/.cache/xreader
9noblacklist ~/.config/xreader 9noblacklist ${HOME}/.config/xreader
10# noblacklist ~/.local/share 10# noblacklist ${HOME}/.local/share
11 11
12include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-devel.inc 13include /etc/firejail/disable-devel.inc
diff --git a/etc/xviewer.profile b/etc/xviewer.profile
index 5c624c384..7c4ede111 100644
--- a/etc/xviewer.profile
+++ b/etc/xviewer.profile
@@ -7,10 +7,10 @@ include /etc/firejail/globals.local
7 7
8# blacklist /run/user/*/bus - makes settings immutable 8# blacklist /run/user/*/bus - makes settings immutable
9 9
10noblacklist ~/.Steam 10noblacklist ${HOME}/.Steam
11noblacklist ~/.config/xviewer 11noblacklist ${HOME}/.config/xviewer
12noblacklist ~/.local/share/Trash 12noblacklist ${HOME}/.local/share/Trash
13noblacklist ~/.steam 13noblacklist ${HOME}/.steam
14 14
15include /etc/firejail/disable-common.inc 15include /etc/firejail/disable-common.inc
16include /etc/firejail/disable-devel.inc 16include /etc/firejail/disable-devel.inc
diff --git a/etc/yandex-browser.profile b/etc/yandex-browser.profile
index bfb7b9d87..605ce3413 100644
--- a/etc/yandex-browser.profile
+++ b/etc/yandex-browser.profile
@@ -5,27 +5,27 @@ include /etc/firejail/yandex-browser.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.cache/yandex-browser 8noblacklist ${HOME}/.cache/yandex-browser
9noblacklist ~/.cache/yandex-browser-beta 9noblacklist ${HOME}/.cache/yandex-browser-beta
10noblacklist ~/.config/yandex-browser 10noblacklist ${HOME}/.config/yandex-browser
11noblacklist ~/.config/yandex-browser-beta 11noblacklist ${HOME}/.config/yandex-browser-beta
12noblacklist ~/.pki 12noblacklist ${HOME}/.pki
13 13
14include /etc/firejail/disable-common.inc 14include /etc/firejail/disable-common.inc
15include /etc/firejail/disable-devel.inc 15include /etc/firejail/disable-devel.inc
16include /etc/firejail/disable-programs.inc 16include /etc/firejail/disable-programs.inc
17 17
18mkdir ~/.cache/yandex-browser 18mkdir ${HOME}/.cache/yandex-browser
19mkdir ~/.cache/yandex-browser-beta 19mkdir ${HOME}/.cache/yandex-browser-beta
20mkdir ~/.config/yandex-browser 20mkdir ${HOME}/.config/yandex-browser
21mkdir ~/.config/yandex-browser-beta 21mkdir ${HOME}/.config/yandex-browser-beta
22mkdir ~/.pki 22mkdir ${HOME}/.pki
23whitelist ${DOWNLOADS} 23whitelist ${DOWNLOADS}
24whitelist ~/.cache/yandex-browser 24whitelist ${HOME}/.cache/yandex-browser
25whitelist ~/.cache/yandex-browser-beta 25whitelist ${HOME}/.cache/yandex-browser-beta
26whitelist ~/.config/yandex-browser 26whitelist ${HOME}/.config/yandex-browser
27whitelist ~/.config/yandex-browser-beta 27whitelist ${HOME}/.config/yandex-browser-beta
28whitelist ~/.pki 28whitelist ${HOME}/.pki
29include /etc/firejail/whitelist-common.inc 29include /etc/firejail/whitelist-common.inc
30 30
31caps.keep sys_chroot,sys_admin 31caps.keep sys_chroot,sys_admin
diff --git a/etc/zathura.profile b/etc/zathura.profile
index ad64371e8..636d89bef 100644
--- a/etc/zathura.profile
+++ b/etc/zathura.profile
@@ -7,8 +7,8 @@ include /etc/firejail/globals.local
7 7
8blacklist /run/user/*/bus 8blacklist /run/user/*/bus
9 9
10noblacklist ~/.config/zathura 10noblacklist ${HOME}/.config/zathura
11noblacklist ~/.local/share/zathura 11noblacklist ${HOME}/.local/share/zathura
12 12
13include /etc/firejail/disable-common.inc 13include /etc/firejail/disable-common.inc
14include /etc/firejail/disable-devel.inc 14include /etc/firejail/disable-devel.inc
@@ -31,5 +31,5 @@ private-bin zathura
31private-dev 31private-dev
32private-etc fonts 32private-etc fonts
33private-tmp 33private-tmp
34read-only ~/ 34read-only ${HOME}/
35read-write ~/.local/share/zathura/ 35read-write ${HOME}/.local/share/zathura/
diff --git a/etc/zoom.profile b/etc/zoom.profile
index 381df9ab5..061efb44d 100644
--- a/etc/zoom.profile
+++ b/etc/zoom.profile
@@ -5,15 +5,15 @@ include /etc/firejail/zoom.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ~/.config/zoomus.conf 8noblacklist ${HOME}/.config/zoomus.conf
9 9
10include /etc/firejail/disable-common.inc 10include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-devel.inc 11include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-programs.inc 12include /etc/firejail/disable-programs.inc
13 13
14mkdir ~/.zoom 14mkdir ${HOME}/.zoom
15whitelist ~/.cache/zoom 15whitelist ${HOME}/.cache/zoom
16whitelist ~/.zoom 16whitelist ${HOME}/.zoom
17include /etc/firejail/whitelist-common.inc 17include /etc/firejail/whitelist-common.inc
18 18
19caps.drop all 19caps.drop all