aboutsummaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
authorLibravatar Tad <tad@spotco.us>2018-07-24 12:52:13 -0400
committerLibravatar Tad <tad@spotco.us>2018-07-24 12:52:13 -0400
commite5aba00d010e9e3af3e626bedb8acf8ae37b3b75 (patch)
tree55fd2a36c7953e137dfc7ca0734cc56eb0fb6f4d /etc
parentMerge pull request #2060 from SkewedZeppelin/disable-xdg (diff)
downloadfirejail-e5aba00d010e9e3af3e626bedb8acf8ae37b3b75.tar.gz
firejail-e5aba00d010e9e3af3e626bedb8acf8ae37b3b75.tar.zst
firejail-e5aba00d010e9e3af3e626bedb8acf8ae37b3b75.zip
Add disable-xdg.inc to ~100 profiles
Diffstat (limited to 'etc')
-rw-r--r--etc/amarok.profile2
-rw-r--r--etc/android-studio.profile2
-rw-r--r--etc/ardour5.profile3
-rw-r--r--etc/arduino.profile2
-rw-r--r--etc/asunder.profile2
-rw-r--r--etc/atril.profile2
-rw-r--r--etc/audacious.profile2
-rw-r--r--etc/audacity.profile3
-rw-r--r--etc/bitlbee.profile1
-rw-r--r--etc/calibre.profile2
-rw-r--r--etc/cherrytree.profile2
-rw-r--r--etc/clementine.profile2
-rw-r--r--etc/clipit.profile1
-rw-r--r--etc/cmus.profile2
-rw-r--r--etc/conky.profile2
-rw-r--r--etc/corebird.profile1
-rw-r--r--etc/darktable.profile2
-rw-r--r--etc/deadbeef.profile2
-rw-r--r--etc/dex2jar.profile1
-rw-r--r--etc/dia.profile2
-rw-r--r--etc/digikam.profile2
-rw-r--r--etc/disable-xdg.inc6
-rw-r--r--etc/display.profile3
-rw-r--r--etc/dnscrypt-proxy.profile1
-rw-r--r--etc/dnsmasq.profile1
-rw-r--r--etc/dosbox.profile1
-rw-r--r--etc/dragon.profile3
-rw-r--r--etc/elinks.profile1
-rw-r--r--etc/enchant.profile1
-rw-r--r--etc/enpass.profile6
-rw-r--r--etc/evince.profile2
-rw-r--r--etc/fbreader.profile2
-rw-r--r--etc/fontforge.profile2
-rw-r--r--etc/freecad.profile2
-rw-r--r--etc/gimp.profile3
-rw-r--r--etc/globaltime.profile1
-rw-r--r--etc/gnome-mpv.profile3
-rw-r--r--etc/gnome-music.profile2
-rw-r--r--etc/goobox.profile2
-rw-r--r--etc/guayadeque.profile2
-rw-r--r--etc/gucharmap.profile1
-rw-r--r--etc/handbrake.profile3
-rw-r--r--etc/hashcat.profile2
-rw-r--r--etc/inkscape.profile3
-rw-r--r--etc/jd-gui.profile1
-rw-r--r--etc/k3b.profile2
-rw-r--r--etc/keepass.profile2
-rw-r--r--etc/keepassx.profile2
-rw-r--r--etc/keepassxc.profile2
-rw-r--r--etc/kodi.profile4
-rw-r--r--etc/krita.profile3
-rw-r--r--etc/kwrite.profile2
-rw-r--r--etc/libreoffice.profile2
-rw-r--r--etc/lollypop.profile6
-rw-r--r--etc/luminance-hdr.profile2
-rw-r--r--etc/lxmusic.profile2
-rw-r--r--etc/lynx.profile1
-rw-r--r--etc/mpd.profile2
-rw-r--r--etc/mpv.profile3
-rw-r--r--etc/mupdf.profile3
-rw-r--r--etc/musescore.profile3
-rw-r--r--etc/obs.profile4
-rw-r--r--etc/okular.profile2
-rw-r--r--etc/orage.profile1
-rw-r--r--etc/parole.profile3
-rw-r--r--etc/pdfchain.profile3
-rw-r--r--etc/pdfmod.profile2
-rw-r--r--etc/pdfsam.profile3
-rw-r--r--etc/peek.profile3
-rw-r--r--etc/picard.profile2
-rw-r--r--etc/ping.profile1
-rw-r--r--etc/pinta.profile3
-rw-r--r--etc/pithos.profile1
-rw-r--r--etc/ppsspp.profile2
-rw-r--r--etc/qlipper.profile1
-rw-r--r--etc/qmmp.profile2
-rw-r--r--etc/qpdfview.profile2
-rw-r--r--etc/remmina.profile1
-rw-r--r--etc/rhythmbox.profile2
-rw-r--r--etc/sayonara.profile2
-rw-r--r--etc/scallion.profile2
-rw-r--r--etc/scribus.profile3
-rw-r--r--etc/sdat2img.profile1
-rw-r--r--etc/silentarmy.profile1
-rw-r--r--etc/simple-scan.profile2
-rw-r--r--etc/skanlite.profile3
-rw-r--r--etc/smplayer.profile3
-rw-r--r--etc/smtube.profile2
-rw-r--r--etc/soundconverter.profile3
-rw-r--r--etc/sqlitebrowser.profile2
-rw-r--r--etc/start-tor-browser.profile1
-rw-r--r--etc/tor.profile1
-rw-r--r--etc/totem.profile3
-rw-r--r--etc/uefitool.profile3
-rw-r--r--etc/unbound.profile1
-rw-r--r--etc/viking.profile2
-rw-r--r--etc/vlc.profile3
-rw-r--r--etc/w3m.profile1
-rw-r--r--etc/wireshark.profile2
-rw-r--r--etc/xcalc.profile1
-rw-r--r--etc/xmr-stak.profile1
-rw-r--r--etc/xpdf.profile2
-rw-r--r--etc/youtube-dl.profile3
-rw-r--r--etc/zathura.profile2
104 files changed, 214 insertions, 9 deletions
diff --git a/etc/amarok.profile b/etc/amarok.profile
index 8fa919131..aff78e210 100644
--- a/etc/amarok.profile
+++ b/etc/amarok.profile
@@ -5,12 +5,14 @@ include /etc/firejail/amarok.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ${MUSIC}
8 9
9include /etc/firejail/disable-common.inc 10include /etc/firejail/disable-common.inc
10include /etc/firejail/disable-devel.inc 11include /etc/firejail/disable-devel.inc
11include /etc/firejail/disable-interpreters.inc 12include /etc/firejail/disable-interpreters.inc
12include /etc/firejail/disable-passwdmgr.inc 13include /etc/firejail/disable-passwdmgr.inc
13include /etc/firejail/disable-programs.inc 14include /etc/firejail/disable-programs.inc
15include /etc/firejail/disable-xdg.inc
14 16
15include /etc/firejail/whitelist-var-common.inc 17include /etc/firejail/whitelist-var-common.inc
16 18
diff --git a/etc/android-studio.profile b/etc/android-studio.profile
index a69bf3966..d845bd4b9 100644
--- a/etc/android-studio.profile
+++ b/etc/android-studio.profile
@@ -15,12 +15,10 @@ noblacklist ${HOME}/.java
15noblacklist ${HOME}/.local/share/JetBrains 15noblacklist ${HOME}/.local/share/JetBrains
16noblacklist ${HOME}/.ssh 16noblacklist ${HOME}/.ssh
17noblacklist ${HOME}/.tooling 17noblacklist ${HOME}/.tooling
18noblacklist ${DOCUMENTS}
19 18
20include /etc/firejail/disable-common.inc 19include /etc/firejail/disable-common.inc
21include /etc/firejail/disable-passwdmgr.inc 20include /etc/firejail/disable-passwdmgr.inc
22include /etc/firejail/disable-programs.inc 21include /etc/firejail/disable-programs.inc
23include /etc/firejail/disable-xdg.inc
24 22
25caps.drop all 23caps.drop all
26netfilter 24netfilter
diff --git a/etc/ardour5.profile b/etc/ardour5.profile
index c2090af98..aaac62bc8 100644
--- a/etc/ardour5.profile
+++ b/etc/ardour5.profile
@@ -9,12 +9,15 @@ noblacklist ${HOME}/.config/ardour4
9noblacklist ${HOME}/.config/ardour5 9noblacklist ${HOME}/.config/ardour5
10noblacklist ${HOME}/.lv2 10noblacklist ${HOME}/.lv2
11noblacklist ${HOME}/.vst 11noblacklist ${HOME}/.vst
12noblacklist ${DOCUMENTS}
13noblacklist ${MUSIC}
12 14
13include /etc/firejail/disable-common.inc 15include /etc/firejail/disable-common.inc
14include /etc/firejail/disable-devel.inc 16include /etc/firejail/disable-devel.inc
15include /etc/firejail/disable-interpreters.inc 17include /etc/firejail/disable-interpreters.inc
16include /etc/firejail/disable-passwdmgr.inc 18include /etc/firejail/disable-passwdmgr.inc
17include /etc/firejail/disable-programs.inc 19include /etc/firejail/disable-programs.inc
20include /etc/firejail/disable-xdg.inc
18 21
19caps.drop all 22caps.drop all
20ipc-namespace 23ipc-namespace
diff --git a/etc/arduino.profile b/etc/arduino.profile
index c8850ccb0..0ff242450 100644
--- a/etc/arduino.profile
+++ b/etc/arduino.profile
@@ -8,6 +8,7 @@ include /etc/firejail/globals.local
8noblacklist ${HOME}/.arduino15 8noblacklist ${HOME}/.arduino15
9noblacklist ${HOME}/.java 9noblacklist ${HOME}/.java
10noblacklist ${HOME}/Arduino 10noblacklist ${HOME}/Arduino
11noblacklist ${DOCUMENTS}
11 12
12# Allow access to java 13# Allow access to java
13noblacklist ${PATH}/java 14noblacklist ${PATH}/java
@@ -20,6 +21,7 @@ include /etc/firejail/disable-devel.inc
20include /etc/firejail/disable-interpreters.inc 21include /etc/firejail/disable-interpreters.inc
21include /etc/firejail/disable-passwdmgr.inc 22include /etc/firejail/disable-passwdmgr.inc
22include /etc/firejail/disable-programs.inc 23include /etc/firejail/disable-programs.inc
24include /etc/firejail/disable-xdg.inc
23 25
24caps.drop all 26caps.drop all
25netfilter 27netfilter
diff --git a/etc/asunder.profile b/etc/asunder.profile
index 1787ad0cc..4cd340bf8 100644
--- a/etc/asunder.profile
+++ b/etc/asunder.profile
@@ -9,12 +9,14 @@ noblacklist ${HOME}/.config/asunder
9noblacklist ${HOME}/.asunder_album_genre 9noblacklist ${HOME}/.asunder_album_genre
10noblacklist ${HOME}/.asunder_album_title 10noblacklist ${HOME}/.asunder_album_title
11noblacklist ${HOME}/.asunder_album_artist 11noblacklist ${HOME}/.asunder_album_artist
12noblacklist ${MUSIC}
12 13
13include /etc/firejail/disable-common.inc 14include /etc/firejail/disable-common.inc
14include /etc/firejail/disable-devel.inc 15include /etc/firejail/disable-devel.inc
15include /etc/firejail/disable-interpreters.inc 16include /etc/firejail/disable-interpreters.inc
16include /etc/firejail/disable-passwdmgr.inc 17include /etc/firejail/disable-passwdmgr.inc
17include /etc/firejail/disable-programs.inc 18include /etc/firejail/disable-programs.inc
19include /etc/firejail/disable-xdg.inc
18 20
19include /etc/firejail/whitelist-var-common.inc 21include /etc/firejail/whitelist-var-common.inc
20 22
diff --git a/etc/atril.profile b/etc/atril.profile
index 95120681c..48902ec4a 100644
--- a/etc/atril.profile
+++ b/etc/atril.profile
@@ -7,6 +7,7 @@ include /etc/firejail/globals.local
7 7
8noblacklist ${HOME}/.cache/atril 8noblacklist ${HOME}/.cache/atril
9noblacklist ${HOME}/.config/atril 9noblacklist ${HOME}/.config/atril
10noblacklist ${DOCUMENTS}
10 11
11#noblacklist ${HOME}/.local/share 12#noblacklist ${HOME}/.local/share
12# it seems to use only ${HOME}/.local/share/webkitgtk 13# it seems to use only ${HOME}/.local/share/webkitgtk
@@ -16,6 +17,7 @@ include /etc/firejail/disable-devel.inc
16include /etc/firejail/disable-interpreters.inc 17include /etc/firejail/disable-interpreters.inc
17include /etc/firejail/disable-passwdmgr.inc 18include /etc/firejail/disable-passwdmgr.inc
18include /etc/firejail/disable-programs.inc 19include /etc/firejail/disable-programs.inc
20include /etc/firejail/disable-xdg.inc
19 21
20include /etc/firejail/whitelist-var-common.inc 22include /etc/firejail/whitelist-var-common.inc
21 23
diff --git a/etc/audacious.profile b/etc/audacious.profile
index 8d3689487..cbbe15c46 100644
--- a/etc/audacious.profile
+++ b/etc/audacious.profile
@@ -7,12 +7,14 @@ include /etc/firejail/globals.local
7 7
8noblacklist ${HOME}/.config/Audaciousrc 8noblacklist ${HOME}/.config/Audaciousrc
9noblacklist ${HOME}/.config/audacious 9noblacklist ${HOME}/.config/audacious
10noblacklist ${MUSIC}
10 11
11include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
12include /etc/firejail/disable-devel.inc 13include /etc/firejail/disable-devel.inc
13include /etc/firejail/disable-interpreters.inc 14include /etc/firejail/disable-interpreters.inc
14include /etc/firejail/disable-passwdmgr.inc 15include /etc/firejail/disable-passwdmgr.inc
15include /etc/firejail/disable-programs.inc 16include /etc/firejail/disable-programs.inc
17include /etc/firejail/disable-xdg.inc
16 18
17include /etc/firejail/whitelist-var-common.inc 19include /etc/firejail/whitelist-var-common.inc
18 20
diff --git a/etc/audacity.profile b/etc/audacity.profile
index c5e54ee24..d3c9ee4ac 100644
--- a/etc/audacity.profile
+++ b/etc/audacity.profile
@@ -6,12 +6,15 @@ include /etc/firejail/audacity.local
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ${HOME}/.audacity-data 8noblacklist ${HOME}/.audacity-data
9noblacklist ${DOCUMENTS}
10noblacklist ${MUSIC}
9 11
10include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-devel.inc 13include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-interpreters.inc 14include /etc/firejail/disable-interpreters.inc
13include /etc/firejail/disable-passwdmgr.inc 15include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc 16include /etc/firejail/disable-programs.inc
17include /etc/firejail/disable-xdg.inc
15 18
16include /etc/firejail/whitelist-var-common.inc 19include /etc/firejail/whitelist-var-common.inc
17 20
diff --git a/etc/bitlbee.profile b/etc/bitlbee.profile
index 6507aeadb..10ef34d07 100644
--- a/etc/bitlbee.profile
+++ b/etc/bitlbee.profile
@@ -14,6 +14,7 @@ include /etc/firejail/disable-devel.inc
14include /etc/firejail/disable-interpreters.inc 14include /etc/firejail/disable-interpreters.inc
15include /etc/firejail/disable-passwdmgr.inc 15include /etc/firejail/disable-passwdmgr.inc
16include /etc/firejail/disable-programs.inc 16include /etc/firejail/disable-programs.inc
17include /etc/firejail/disable-xdg.inc
17 18
18netfilter 19netfilter
19no3d 20no3d
diff --git a/etc/calibre.profile b/etc/calibre.profile
index 436ac3234..09839161e 100644
--- a/etc/calibre.profile
+++ b/etc/calibre.profile
@@ -7,11 +7,13 @@ include /etc/firejail/globals.local
7 7
8noblacklist ${HOME}/.cache/calibre 8noblacklist ${HOME}/.cache/calibre
9noblacklist ${HOME}/.config/calibre 9noblacklist ${HOME}/.config/calibre
10noblacklist ${DOCUMENTS}
10 11
11include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
12include /etc/firejail/disable-devel.inc 13include /etc/firejail/disable-devel.inc
13include /etc/firejail/disable-passwdmgr.inc 14include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc 15include /etc/firejail/disable-programs.inc
16include /etc/firejail/disable-xdg.inc
15 17
16include /etc/firejail/whitelist-var-common.inc 18include /etc/firejail/whitelist-var-common.inc
17 19
diff --git a/etc/cherrytree.profile b/etc/cherrytree.profile
index c63cfad8d..8397da00c 100644
--- a/etc/cherrytree.profile
+++ b/etc/cherrytree.profile
@@ -6,6 +6,7 @@ include /etc/firejail/cherrytree.local
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ${HOME}/.config/cherrytree 8noblacklist ${HOME}/.config/cherrytree
9noblacklist ${DOCUMENTS}
9 10
10# Allow python (blacklisted by disable-interpreters.inc) 11# Allow python (blacklisted by disable-interpreters.inc)
11noblacklist ${PATH}/python2* 12noblacklist ${PATH}/python2*
@@ -18,6 +19,7 @@ include /etc/firejail/disable-devel.inc
18include /etc/firejail/disable-interpreters.inc 19include /etc/firejail/disable-interpreters.inc
19include /etc/firejail/disable-passwdmgr.inc 20include /etc/firejail/disable-passwdmgr.inc
20include /etc/firejail/disable-programs.inc 21include /etc/firejail/disable-programs.inc
22include /etc/firejail/disable-xdg.inc
21 23
22caps.drop all 24caps.drop all
23netfilter 25netfilter
diff --git a/etc/clementine.profile b/etc/clementine.profile
index ce4b8deb8..e13fd3f66 100644
--- a/etc/clementine.profile
+++ b/etc/clementine.profile
@@ -7,12 +7,14 @@ include /etc/firejail/globals.local
7 7
8noblacklist ${HOME}/.cache/Clementine 8noblacklist ${HOME}/.cache/Clementine
9noblacklist ${HOME}/.config/Clementine 9noblacklist ${HOME}/.config/Clementine
10noblacklist ${MUSIC}
10 11
11include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
12include /etc/firejail/disable-devel.inc 13include /etc/firejail/disable-devel.inc
13include /etc/firejail/disable-interpreters.inc 14include /etc/firejail/disable-interpreters.inc
14include /etc/firejail/disable-passwdmgr.inc 15include /etc/firejail/disable-passwdmgr.inc
15include /etc/firejail/disable-programs.inc 16include /etc/firejail/disable-programs.inc
17include /etc/firejail/disable-xdg.inc
16 18
17include /etc/firejail/whitelist-var-common.inc 19include /etc/firejail/whitelist-var-common.inc
18 20
diff --git a/etc/clipit.profile b/etc/clipit.profile
index 3134fdc3e..866108aee 100644
--- a/etc/clipit.profile
+++ b/etc/clipit.profile
@@ -13,6 +13,7 @@ include /etc/firejail/disable-devel.inc
13include /etc/firejail/disable-interpreters.inc 13include /etc/firejail/disable-interpreters.inc
14include /etc/firejail/disable-passwdmgr.inc 14include /etc/firejail/disable-passwdmgr.inc
15include /etc/firejail/disable-programs.inc 15include /etc/firejail/disable-programs.inc
16include /etc/firejail/disable-xdg.inc
16 17
17caps.drop all 18caps.drop all
18netfilter 19netfilter
diff --git a/etc/cmus.profile b/etc/cmus.profile
index 03f234913..3331bde22 100644
--- a/etc/cmus.profile
+++ b/etc/cmus.profile
@@ -6,12 +6,14 @@ include /etc/firejail/cmus.local
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ${HOME}/.config/cmus 8noblacklist ${HOME}/.config/cmus
9noblacklist ${MUSIC}
9 10
10include /etc/firejail/disable-common.inc 11include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-devel.inc 12include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-interpreters.inc 13include /etc/firejail/disable-interpreters.inc
13include /etc/firejail/disable-passwdmgr.inc 14include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc 15include /etc/firejail/disable-programs.inc
16include /etc/firejail/disable-xdg.inc
15 17
16caps.drop all 18caps.drop all
17netfilter 19netfilter
diff --git a/etc/conky.profile b/etc/conky.profile
index af275b915..4d2bcfa38 100644
--- a/etc/conky.profile
+++ b/etc/conky.profile
@@ -5,12 +5,14 @@ include /etc/firejail/conky.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ${PICTURES}
8 9
9include /etc/firejail/disable-common.inc 10include /etc/firejail/disable-common.inc
10include /etc/firejail/disable-devel.inc 11include /etc/firejail/disable-devel.inc
11include /etc/firejail/disable-interpreters.inc 12include /etc/firejail/disable-interpreters.inc
12include /etc/firejail/disable-passwdmgr.inc 13include /etc/firejail/disable-passwdmgr.inc
13include /etc/firejail/disable-programs.inc 14include /etc/firejail/disable-programs.inc
15include /etc/firejail/disable-xdg.inc
14 16
15caps.drop all 17caps.drop all
16ipc-namespace 18ipc-namespace
diff --git a/etc/corebird.profile b/etc/corebird.profile
index a99a6b732..da1869f65 100644
--- a/etc/corebird.profile
+++ b/etc/corebird.profile
@@ -12,6 +12,7 @@ include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-interpreters.inc 12include /etc/firejail/disable-interpreters.inc
13include /etc/firejail/disable-passwdmgr.inc 13include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc 14include /etc/firejail/disable-programs.inc
15include /etc/firejail/disable-xdg.inc
15 16
16include /etc/firejail/whitelist-var-common.inc 17include /etc/firejail/whitelist-var-common.inc
17 18
diff --git a/etc/darktable.profile b/etc/darktable.profile
index 511e4e475..607a587a1 100644
--- a/etc/darktable.profile
+++ b/etc/darktable.profile
@@ -7,12 +7,14 @@ include /etc/firejail/globals.local
7 7
8noblacklist ${HOME}/.cache/darktable 8noblacklist ${HOME}/.cache/darktable
9noblacklist ${HOME}/.config/darktable 9noblacklist ${HOME}/.config/darktable
10noblacklist ${PICTURES}
10 11
11include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
12include /etc/firejail/disable-devel.inc 13include /etc/firejail/disable-devel.inc
13include /etc/firejail/disable-interpreters.inc 14include /etc/firejail/disable-interpreters.inc
14include /etc/firejail/disable-passwdmgr.inc 15include /etc/firejail/disable-passwdmgr.inc
15include /etc/firejail/disable-programs.inc 16include /etc/firejail/disable-programs.inc
17include /etc/firejail/disable-xdg.inc
16 18
17caps.drop all 19caps.drop all
18netfilter 20netfilter
diff --git a/etc/deadbeef.profile b/etc/deadbeef.profile
index 53383d88d..8eb5776e7 100644
--- a/etc/deadbeef.profile
+++ b/etc/deadbeef.profile
@@ -6,12 +6,14 @@ include /etc/firejail/deadbeef.local
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ${HOME}/.config/deadbeef 8noblacklist ${HOME}/.config/deadbeef
9noblacklist ${MUSIC}
9 10
10include /etc/firejail/disable-common.inc 11include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-devel.inc 12include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-interpreters.inc 13include /etc/firejail/disable-interpreters.inc
13include /etc/firejail/disable-passwdmgr.inc 14include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc 15include /etc/firejail/disable-programs.inc
16include /etc/firejail/disable-xdg.inc
15 17
16caps.drop all 18caps.drop all
17netfilter 19netfilter
diff --git a/etc/dex2jar.profile b/etc/dex2jar.profile
index aeef46413..b61d68e06 100644
--- a/etc/dex2jar.profile
+++ b/etc/dex2jar.profile
@@ -17,6 +17,7 @@ include /etc/firejail/disable-devel.inc
17include /etc/firejail/disable-interpreters.inc 17include /etc/firejail/disable-interpreters.inc
18include /etc/firejail/disable-passwdmgr.inc 18include /etc/firejail/disable-passwdmgr.inc
19include /etc/firejail/disable-programs.inc 19include /etc/firejail/disable-programs.inc
20include /etc/firejail/disable-xdg.inc
20 21
21caps.drop all 22caps.drop all
22net none 23net none
diff --git a/etc/dia.profile b/etc/dia.profile
index fca14236f..fed5107aa 100644
--- a/etc/dia.profile
+++ b/etc/dia.profile
@@ -6,12 +6,14 @@ include /etc/firejail/dia.local
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ${HOME}/.dia 8noblacklist ${HOME}/.dia
9noblacklist ${DOCUMENTS}
9 10
10include /etc/firejail/disable-common.inc 11include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-devel.inc 12include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-interpreters.inc 13include /etc/firejail/disable-interpreters.inc
13include /etc/firejail/disable-passwdmgr.inc 14include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc 15include /etc/firejail/disable-programs.inc
16include /etc/firejail/disable-xdg.inc
15 17
16caps.drop all 18caps.drop all
17net none 19net none
diff --git a/etc/digikam.profile b/etc/digikam.profile
index 819b8fe41..2e1947419 100644
--- a/etc/digikam.profile
+++ b/etc/digikam.profile
@@ -9,12 +9,14 @@ noblacklist ${HOME}/.config/digikam
9noblacklist ${HOME}/.config/digikamrc 9noblacklist ${HOME}/.config/digikamrc
10noblacklist ${HOME}/.kde/share/apps/digikam 10noblacklist ${HOME}/.kde/share/apps/digikam
11noblacklist ${HOME}/.kde4/share/apps/digikam 11noblacklist ${HOME}/.kde4/share/apps/digikam
12noblacklist ${PICTURES}
12 13
13include /etc/firejail/disable-common.inc 14include /etc/firejail/disable-common.inc
14include /etc/firejail/disable-devel.inc 15include /etc/firejail/disable-devel.inc
15include /etc/firejail/disable-interpreters.inc 16include /etc/firejail/disable-interpreters.inc
16include /etc/firejail/disable-passwdmgr.inc 17include /etc/firejail/disable-passwdmgr.inc
17include /etc/firejail/disable-programs.inc 18include /etc/firejail/disable-programs.inc
19include /etc/firejail/disable-xdg.inc
18 20
19include /etc/firejail/whitelist-var-common.inc 21include /etc/firejail/whitelist-var-common.inc
20 22
diff --git a/etc/disable-xdg.inc b/etc/disable-xdg.inc
index 554e3a7d5..519f00afb 100644
--- a/etc/disable-xdg.inc
+++ b/etc/disable-xdg.inc
@@ -2,9 +2,11 @@
2# Persistent customizations should go in a .local file. 2# Persistent customizations should go in a .local file.
3include /etc/firejail/disable-xdg.local 3include /etc/firejail/disable-xdg.local
4 4
5#blacklist ${DESKTOP}
6blacklist ${DOCUMENTS} 5blacklist ${DOCUMENTS}
7#blacklist ${DOWNLOADS}
8blacklist ${MUSIC} 6blacklist ${MUSIC}
9blacklist ${PICTURES} 7blacklist ${PICTURES}
10blacklist ${VIDEOS} 8blacklist ${VIDEOS}
9
10# The following should be considered catch-all directories
11#blacklist ${DESKTOP}
12#blacklist ${DOWNLOADS}
diff --git a/etc/display.profile b/etc/display.profile
index 01196f5ac..41a426375 100644
--- a/etc/display.profile
+++ b/etc/display.profile
@@ -5,6 +5,8 @@ include /etc/firejail/display.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ${PICTURES}
9
8# Allow python (blacklisted by disable-interpreters.inc) 10# Allow python (blacklisted by disable-interpreters.inc)
9noblacklist ${PATH}/python2* 11noblacklist ${PATH}/python2*
10noblacklist ${PATH}/python3* 12noblacklist ${PATH}/python3*
@@ -16,6 +18,7 @@ include /etc/firejail/disable-devel.inc
16include /etc/firejail/disable-interpreters.inc 18include /etc/firejail/disable-interpreters.inc
17include /etc/firejail/disable-passwdmgr.inc 19include /etc/firejail/disable-passwdmgr.inc
18include /etc/firejail/disable-programs.inc 20include /etc/firejail/disable-programs.inc
21include /etc/firejail/disable-xdg.inc
19 22
20include /etc/firejail/whitelist-var-common.inc 23include /etc/firejail/whitelist-var-common.inc
21 24
diff --git a/etc/dnscrypt-proxy.profile b/etc/dnscrypt-proxy.profile
index 0971451c4..f8f593c83 100644
--- a/etc/dnscrypt-proxy.profile
+++ b/etc/dnscrypt-proxy.profile
@@ -15,6 +15,7 @@ include /etc/firejail/disable-devel.inc
15include /etc/firejail/disable-interpreters.inc 15include /etc/firejail/disable-interpreters.inc
16include /etc/firejail/disable-passwdmgr.inc 16include /etc/firejail/disable-passwdmgr.inc
17include /etc/firejail/disable-programs.inc 17include /etc/firejail/disable-programs.inc
18include /etc/firejail/disable-xdg.inc
18 19
19caps.keep ipc_lock,net_bind_service,setgid,setuid,sys_chroot 20caps.keep ipc_lock,net_bind_service,setgid,setuid,sys_chroot
20no3d 21no3d
diff --git a/etc/dnsmasq.profile b/etc/dnsmasq.profile
index fc1209c1e..6d3bb920d 100644
--- a/etc/dnsmasq.profile
+++ b/etc/dnsmasq.profile
@@ -15,6 +15,7 @@ include /etc/firejail/disable-devel.inc
15include /etc/firejail/disable-interpreters.inc 15include /etc/firejail/disable-interpreters.inc
16include /etc/firejail/disable-passwdmgr.inc 16include /etc/firejail/disable-passwdmgr.inc
17include /etc/firejail/disable-programs.inc 17include /etc/firejail/disable-programs.inc
18include /etc/firejail/disable-xdg.inc
18 19
19caps.keep net_admin,net_bind_service,net_raw,setgid,setuid 20caps.keep net_admin,net_bind_service,net_raw,setgid,setuid
20no3d 21no3d
diff --git a/etc/dosbox.profile b/etc/dosbox.profile
index 79514c373..a2606e7e1 100644
--- a/etc/dosbox.profile
+++ b/etc/dosbox.profile
@@ -12,6 +12,7 @@ include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-interpreters.inc 12include /etc/firejail/disable-interpreters.inc
13include /etc/firejail/disable-passwdmgr.inc 13include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc 14include /etc/firejail/disable-programs.inc
15include /etc/firejail/disable-xdg.inc
15 16
16include /etc/firejail/whitelist-var-common.inc 17include /etc/firejail/whitelist-var-common.inc
17 18
diff --git a/etc/dragon.profile b/etc/dragon.profile
index bdaa12e75..9d7bb5748 100644
--- a/etc/dragon.profile
+++ b/etc/dragon.profile
@@ -6,12 +6,15 @@ include /etc/firejail/dragon.local
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ${HOME}/.config/dragonplayerrc 8noblacklist ${HOME}/.config/dragonplayerrc
9noblacklist ${MUSIC}
10noblacklist ${VIDEOS}
9 11
10include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-devel.inc 13include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-interpreters.inc 14include /etc/firejail/disable-interpreters.inc
13include /etc/firejail/disable-passwdmgr.inc 15include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc 16include /etc/firejail/disable-programs.inc
17include /etc/firejail/disable-xdg.inc
15 18
16include /etc/firejail/whitelist-var-common.inc 19include /etc/firejail/whitelist-var-common.inc
17 20
diff --git a/etc/elinks.profile b/etc/elinks.profile
index 6878c4fe0..61fbab3cc 100644
--- a/etc/elinks.profile
+++ b/etc/elinks.profile
@@ -14,6 +14,7 @@ include /etc/firejail/disable-devel.inc
14include /etc/firejail/disable-interpreters.inc 14include /etc/firejail/disable-interpreters.inc
15include /etc/firejail/disable-passwdmgr.inc 15include /etc/firejail/disable-passwdmgr.inc
16include /etc/firejail/disable-programs.inc 16include /etc/firejail/disable-programs.inc
17include /etc/firejail/disable-xdg.inc
17 18
18caps.drop all 19caps.drop all
19netfilter 20netfilter
diff --git a/etc/enchant.profile b/etc/enchant.profile
index a495122dc..5a4050102 100644
--- a/etc/enchant.profile
+++ b/etc/enchant.profile
@@ -12,6 +12,7 @@ include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-interpreters.inc 12include /etc/firejail/disable-interpreters.inc
13include /etc/firejail/disable-passwdmgr.inc 13include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc 14include /etc/firejail/disable-programs.inc
15include /etc/firejail/disable-xdg.inc
15 16
16caps.drop all 17caps.drop all
17netfilter 18netfilter
diff --git a/etc/enpass.profile b/etc/enpass.profile
index 2ee7a97f6..3a30f8b04 100644
--- a/etc/enpass.profile
+++ b/etc/enpass.profile
@@ -4,13 +4,15 @@ include /etc/firejail/enpass.local
4# Persistent global definitions 4# Persistent global definitions
5include /etc/firejail/globals.local 5include /etc/firejail/globals.local
6 6
7noblacklist ${HOME}/.config/Sinew Software Systems
8noblacklist ${DOCUMENTS}
9
7include /etc/firejail/disable-common.inc 10include /etc/firejail/disable-common.inc
8include /etc/firejail/disable-devel.inc 11include /etc/firejail/disable-devel.inc
9include /etc/firejail/disable-interpreters.inc 12include /etc/firejail/disable-interpreters.inc
10include /etc/firejail/disable-passwdmgr.inc 13include /etc/firejail/disable-passwdmgr.inc
11include /etc/firejail/disable-programs.inc 14include /etc/firejail/disable-programs.inc
12 15include /etc/firejail/disable-xdg.inc
13noblacklist ${HOME}/.config/Sinew Software Systems
14 16
15include /etc/firejail/whitelist-var-common.inc 17include /etc/firejail/whitelist-var-common.inc
16 18
diff --git a/etc/evince.profile b/etc/evince.profile
index 40de5b731..d4074d0aa 100644
--- a/etc/evince.profile
+++ b/etc/evince.profile
@@ -6,12 +6,14 @@ include /etc/firejail/evince.local
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ${HOME}/.config/evince 8noblacklist ${HOME}/.config/evince
9noblacklist ${DOCUMENTS}
9 10
10include /etc/firejail/disable-common.inc 11include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-devel.inc 12include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-interpreters.inc 13include /etc/firejail/disable-interpreters.inc
13include /etc/firejail/disable-passwdmgr.inc 14include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc 15include /etc/firejail/disable-programs.inc
16include /etc/firejail/disable-xdg.inc
15 17
16include /etc/firejail/whitelist-var-common.inc 18include /etc/firejail/whitelist-var-common.inc
17 19
diff --git a/etc/fbreader.profile b/etc/fbreader.profile
index 573099429..a5ddd3bf1 100644
--- a/etc/fbreader.profile
+++ b/etc/fbreader.profile
@@ -6,12 +6,14 @@ include /etc/firejail/fbreader.local
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ${HOME}/.FBReader 8noblacklist ${HOME}/.FBReader
9noblacklist ${DOCUMENTS}
9 10
10include /etc/firejail/disable-common.inc 11include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-devel.inc 12include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-interpreters.inc 13include /etc/firejail/disable-interpreters.inc
13include /etc/firejail/disable-passwdmgr.inc 14include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc 15include /etc/firejail/disable-programs.inc
16include /etc/firejail/disable-xdg.inc
15 17
16include /etc/firejail/whitelist-var-common.inc 18include /etc/firejail/whitelist-var-common.inc
17 19
diff --git a/etc/fontforge.profile b/etc/fontforge.profile
index c80588a8b..e4e763099 100644
--- a/etc/fontforge.profile
+++ b/etc/fontforge.profile
@@ -6,6 +6,7 @@ include /etc/firejail/fontforge.local
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ${HOME}/.FontForge 8noblacklist ${HOME}/.FontForge
9noblacklist ${DOCUMENTS}
9 10
10# Allow python (blacklisted by disable-interpreters.inc) 11# Allow python (blacklisted by disable-interpreters.inc)
11noblacklist ${PATH}/python2* 12noblacklist ${PATH}/python2*
@@ -18,6 +19,7 @@ include /etc/firejail/disable-devel.inc
18include /etc/firejail/disable-interpreters.inc 19include /etc/firejail/disable-interpreters.inc
19include /etc/firejail/disable-passwdmgr.inc 20include /etc/firejail/disable-passwdmgr.inc
20include /etc/firejail/disable-programs.inc 21include /etc/firejail/disable-programs.inc
22include /etc/firejail/disable-xdg.inc
21 23
22caps.drop all 24caps.drop all
23netfilter 25netfilter
diff --git a/etc/freecad.profile b/etc/freecad.profile
index 9ea4e0f2b..8c714f37d 100644
--- a/etc/freecad.profile
+++ b/etc/freecad.profile
@@ -6,12 +6,14 @@ include /etc/firejail/freecad.local
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ${HOME}/.config/FreeCAD 8noblacklist ${HOME}/.config/FreeCAD
9noblacklist ${DOCUMENTS}
9 10
10include /etc/firejail/disable-common.inc 11include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-devel.inc 12include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-interpreters.inc 13include /etc/firejail/disable-interpreters.inc
13include /etc/firejail/disable-passwdmgr.inc 14include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc 15include /etc/firejail/disable-programs.inc
16include /etc/firejail/disable-xdg.inc
15 17
16caps.drop all 18caps.drop all
17ipc-namespace 19ipc-namespace
diff --git a/etc/gimp.profile b/etc/gimp.profile
index 36e354e3a..b8a297e84 100644
--- a/etc/gimp.profile
+++ b/etc/gimp.profile
@@ -7,10 +7,13 @@ include /etc/firejail/globals.local
7 7
8noblacklist ${HOME}/.config/GIMP 8noblacklist ${HOME}/.config/GIMP
9noblacklist ${HOME}/.gimp* 9noblacklist ${HOME}/.gimp*
10noblacklist ${DOCUMENTS}
11noblacklist ${PICTURES}
10 12
11include /etc/firejail/disable-common.inc 13include /etc/firejail/disable-common.inc
12include /etc/firejail/disable-passwdmgr.inc 14include /etc/firejail/disable-passwdmgr.inc
13include /etc/firejail/disable-programs.inc 15include /etc/firejail/disable-programs.inc
16include /etc/firejail/disable-xdg.inc
14 17
15include /etc/firejail/whitelist-var-common.inc 18include /etc/firejail/whitelist-var-common.inc
16 19
diff --git a/etc/globaltime.profile b/etc/globaltime.profile
index 0df6b5e63..e414abf8c 100644
--- a/etc/globaltime.profile
+++ b/etc/globaltime.profile
@@ -12,6 +12,7 @@ include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-interpreters.inc 12include /etc/firejail/disable-interpreters.inc
13include /etc/firejail/disable-passwdmgr.inc 13include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc 14include /etc/firejail/disable-programs.inc
15include /etc/firejail/disable-xdg.inc
15 16
16caps.drop all 17caps.drop all
17netfilter 18netfilter
diff --git a/etc/gnome-mpv.profile b/etc/gnome-mpv.profile
index e834e8ec7..f11ceacca 100644
--- a/etc/gnome-mpv.profile
+++ b/etc/gnome-mpv.profile
@@ -6,12 +6,15 @@ include /etc/firejail/gnome-mpv.local
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ${HOME}/.config/gnome-mpv 8noblacklist ${HOME}/.config/gnome-mpv
9noblacklist ${MUSIC}
10noblacklist ${VIDEOS}
9 11
10include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-devel.inc 13include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-interpreters.inc 14include /etc/firejail/disable-interpreters.inc
13include /etc/firejail/disable-passwdmgr.inc 15include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc 16include /etc/firejail/disable-programs.inc
17include /etc/firejail/disable-xdg.inc
15 18
16include /etc/firejail/whitelist-var-common.inc 19include /etc/firejail/whitelist-var-common.inc
17 20
diff --git a/etc/gnome-music.profile b/etc/gnome-music.profile
index eec61b8db..90fb9814f 100644
--- a/etc/gnome-music.profile
+++ b/etc/gnome-music.profile
@@ -6,6 +6,7 @@ include /etc/firejail/gnome-music.local
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ${HOME}/.local/share/gnome-music 8noblacklist ${HOME}/.local/share/gnome-music
9noblacklist ${MUSIC}
9 10
10# Allow python (blacklisted by disable-interpreters.inc) 11# Allow python (blacklisted by disable-interpreters.inc)
11noblacklist ${PATH}/python2* 12noblacklist ${PATH}/python2*
@@ -18,6 +19,7 @@ include /etc/firejail/disable-devel.inc
18include /etc/firejail/disable-interpreters.inc 19include /etc/firejail/disable-interpreters.inc
19include /etc/firejail/disable-passwdmgr.inc 20include /etc/firejail/disable-passwdmgr.inc
20include /etc/firejail/disable-programs.inc 21include /etc/firejail/disable-programs.inc
22include /etc/firejail/disable-xdg.inc
21 23
22include /etc/firejail/whitelist-var-common.inc 24include /etc/firejail/whitelist-var-common.inc
23 25
diff --git a/etc/goobox.profile b/etc/goobox.profile
index ed7b4e761..5e5aad95b 100644
--- a/etc/goobox.profile
+++ b/etc/goobox.profile
@@ -5,12 +5,14 @@ include /etc/firejail/goobox.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ${MUSIC}
8 9
9include /etc/firejail/disable-common.inc 10include /etc/firejail/disable-common.inc
10include /etc/firejail/disable-devel.inc 11include /etc/firejail/disable-devel.inc
11include /etc/firejail/disable-interpreters.inc 12include /etc/firejail/disable-interpreters.inc
12include /etc/firejail/disable-passwdmgr.inc 13include /etc/firejail/disable-passwdmgr.inc
13include /etc/firejail/disable-programs.inc 14include /etc/firejail/disable-programs.inc
15include /etc/firejail/disable-xdg.inc
14 16
15caps.drop all 17caps.drop all
16netfilter 18netfilter
diff --git a/etc/guayadeque.profile b/etc/guayadeque.profile
index e7e3f828c..775c79521 100644
--- a/etc/guayadeque.profile
+++ b/etc/guayadeque.profile
@@ -6,12 +6,14 @@ include /etc/firejail/guayadeque.local
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ${HOME}/.guayadeque 8noblacklist ${HOME}/.guayadeque
9noblacklist ${MUSIC}
9 10
10include /etc/firejail/disable-common.inc 11include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-devel.inc 12include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-interpreters.inc 13include /etc/firejail/disable-interpreters.inc
13include /etc/firejail/disable-passwdmgr.inc 14include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc 15include /etc/firejail/disable-programs.inc
16include /etc/firejail/disable-xdg.inc
15 17
16caps.drop all 18caps.drop all
17netfilter 19netfilter
diff --git a/etc/gucharmap.profile b/etc/gucharmap.profile
index 60a13af3a..db2e69f8a 100644
--- a/etc/gucharmap.profile
+++ b/etc/gucharmap.profile
@@ -11,6 +11,7 @@ include /etc/firejail/disable-devel.inc
11include /etc/firejail/disable-interpreters.inc 11include /etc/firejail/disable-interpreters.inc
12include /etc/firejail/disable-passwdmgr.inc 12include /etc/firejail/disable-passwdmgr.inc
13include /etc/firejail/disable-programs.inc 13include /etc/firejail/disable-programs.inc
14include /etc/firejail/disable-xdg.inc
14 15
15caps.drop all 16caps.drop all
16netfilter 17netfilter
diff --git a/etc/handbrake.profile b/etc/handbrake.profile
index 6f2f3bf7f..e467eaeb5 100644
--- a/etc/handbrake.profile
+++ b/etc/handbrake.profile
@@ -6,12 +6,15 @@ include /etc/firejail/handbrake.local
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ${HOME}/.config/ghb 8noblacklist ${HOME}/.config/ghb
9noblacklist ${MUSIC}
10noblacklist ${VIDEOS}
9 11
10include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-devel.inc 13include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-interpreters.inc 14include /etc/firejail/disable-interpreters.inc
13include /etc/firejail/disable-passwdmgr.inc 15include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc 16include /etc/firejail/disable-programs.inc
17include /etc/firejail/disable-xdg.inc
15 18
16include /etc/firejail/whitelist-var-common.inc 19include /etc/firejail/whitelist-var-common.inc
17 20
diff --git a/etc/hashcat.profile b/etc/hashcat.profile
index 0fb8b8704..712a09697 100644
--- a/etc/hashcat.profile
+++ b/etc/hashcat.profile
@@ -8,12 +8,14 @@ include /etc/firejail/globals.local
8 8
9noblacklist ${HOME}/.hashcat 9noblacklist ${HOME}/.hashcat
10noblacklist /usr/include 10noblacklist /usr/include
11noblacklist ${DOCUMENTS}
11 12
12include /etc/firejail/disable-common.inc 13include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-devel.inc 14include /etc/firejail/disable-devel.inc
14include /etc/firejail/disable-interpreters.inc 15include /etc/firejail/disable-interpreters.inc
15include /etc/firejail/disable-passwdmgr.inc 16include /etc/firejail/disable-passwdmgr.inc
16include /etc/firejail/disable-programs.inc 17include /etc/firejail/disable-programs.inc
18include /etc/firejail/disable-xdg.inc
17 19
18caps.drop all 20caps.drop all
19net none 21net none
diff --git a/etc/inkscape.profile b/etc/inkscape.profile
index 0f5ca9d39..e709d488d 100644
--- a/etc/inkscape.profile
+++ b/etc/inkscape.profile
@@ -8,12 +8,15 @@ include /etc/firejail/globals.local
8noblacklist ${HOME}/.cache/inkscape 8noblacklist ${HOME}/.cache/inkscape
9noblacklist ${HOME}/.config/inkscape 9noblacklist ${HOME}/.config/inkscape
10noblacklist ${HOME}/.inkscape 10noblacklist ${HOME}/.inkscape
11noblacklist ${DOCUMENTS}
12noblacklist ${PICTURES}
11 13
12include /etc/firejail/disable-common.inc 14include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-devel.inc 15include /etc/firejail/disable-devel.inc
14include /etc/firejail/disable-interpreters.inc 16include /etc/firejail/disable-interpreters.inc
15include /etc/firejail/disable-passwdmgr.inc 17include /etc/firejail/disable-passwdmgr.inc
16include /etc/firejail/disable-programs.inc 18include /etc/firejail/disable-programs.inc
19include /etc/firejail/disable-xdg.inc
17 20
18include /etc/firejail/whitelist-var-common.inc 21include /etc/firejail/whitelist-var-common.inc
19 22
diff --git a/etc/jd-gui.profile b/etc/jd-gui.profile
index ca23cedfa..81e538153 100644
--- a/etc/jd-gui.profile
+++ b/etc/jd-gui.profile
@@ -19,6 +19,7 @@ include /etc/firejail/disable-devel.inc
19include /etc/firejail/disable-interpreters.inc 19include /etc/firejail/disable-interpreters.inc
20include /etc/firejail/disable-passwdmgr.inc 20include /etc/firejail/disable-passwdmgr.inc
21include /etc/firejail/disable-programs.inc 21include /etc/firejail/disable-programs.inc
22include /etc/firejail/disable-xdg.inc
22 23
23caps.drop all 24caps.drop all
24net none 25net none
diff --git a/etc/k3b.profile b/etc/k3b.profile
index 38ad97354..8474c490d 100644
--- a/etc/k3b.profile
+++ b/etc/k3b.profile
@@ -8,12 +8,14 @@ include /etc/firejail/globals.local
8noblacklist ${HOME}/.config/k3brc 8noblacklist ${HOME}/.config/k3brc
9noblacklist ${HOME}/.kde/share/config/k3brc 9noblacklist ${HOME}/.kde/share/config/k3brc
10noblacklist ${HOME}/.kde4/share/config/k3brc 10noblacklist ${HOME}/.kde4/share/config/k3brc
11noblacklist ${MUSIC}
11 12
12include /etc/firejail/disable-common.inc 13include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-devel.inc 14include /etc/firejail/disable-devel.inc
14include /etc/firejail/disable-interpreters.inc 15include /etc/firejail/disable-interpreters.inc
15include /etc/firejail/disable-passwdmgr.inc 16include /etc/firejail/disable-passwdmgr.inc
16include /etc/firejail/disable-programs.inc 17include /etc/firejail/disable-programs.inc
18include /etc/firejail/disable-xdg.inc
17 19
18include /etc/firejail/whitelist-var-common.inc 20include /etc/firejail/whitelist-var-common.inc
19 21
diff --git a/etc/keepass.profile b/etc/keepass.profile
index 03f27d3fa..7b0935030 100644
--- a/etc/keepass.profile
+++ b/etc/keepass.profile
@@ -12,12 +12,14 @@ noblacklist ${HOME}/.config/keepass
12noblacklist ${HOME}/.keepass 12noblacklist ${HOME}/.keepass
13noblacklist ${HOME}/.local/share/KeePass 13noblacklist ${HOME}/.local/share/KeePass
14noblacklist ${HOME}/.local/share/keepass 14noblacklist ${HOME}/.local/share/keepass
15noblacklist ${DOCUMENTS}
15 16
16include /etc/firejail/disable-common.inc 17include /etc/firejail/disable-common.inc
17include /etc/firejail/disable-devel.inc 18include /etc/firejail/disable-devel.inc
18include /etc/firejail/disable-interpreters.inc 19include /etc/firejail/disable-interpreters.inc
19include /etc/firejail/disable-passwdmgr.inc 20include /etc/firejail/disable-passwdmgr.inc
20include /etc/firejail/disable-programs.inc 21include /etc/firejail/disable-programs.inc
22include /etc/firejail/disable-xdg.inc
21 23
22caps.drop all 24caps.drop all
23netfilter 25netfilter
diff --git a/etc/keepassx.profile b/etc/keepassx.profile
index 7a5e57d72..e749a1dfc 100644
--- a/etc/keepassx.profile
+++ b/etc/keepassx.profile
@@ -9,12 +9,14 @@ noblacklist ${HOME}/*.kdb
9noblacklist ${HOME}/*.kdbx 9noblacklist ${HOME}/*.kdbx
10noblacklist ${HOME}/.config/keepassx 10noblacklist ${HOME}/.config/keepassx
11noblacklist ${HOME}/.keepassx 11noblacklist ${HOME}/.keepassx
12noblacklist ${DOCUMENTS}
12 13
13include /etc/firejail/disable-common.inc 14include /etc/firejail/disable-common.inc
14include /etc/firejail/disable-devel.inc 15include /etc/firejail/disable-devel.inc
15include /etc/firejail/disable-interpreters.inc 16include /etc/firejail/disable-interpreters.inc
16include /etc/firejail/disable-passwdmgr.inc 17include /etc/firejail/disable-passwdmgr.inc
17include /etc/firejail/disable-programs.inc 18include /etc/firejail/disable-programs.inc
19include /etc/firejail/disable-xdg.inc
18 20
19include /etc/firejail/whitelist-var-common.inc 21include /etc/firejail/whitelist-var-common.inc
20 22
diff --git a/etc/keepassxc.profile b/etc/keepassxc.profile
index 0edb375b3..b7bcc7b87 100644
--- a/etc/keepassxc.profile
+++ b/etc/keepassxc.profile
@@ -11,12 +11,14 @@ noblacklist ${HOME}/.config/keepassxc
11noblacklist ${HOME}/.keepassxc 11noblacklist ${HOME}/.keepassxc
12# 2.2.4 needs this path when compiled with "Native messaging browser extension" 12# 2.2.4 needs this path when compiled with "Native messaging browser extension"
13noblacklist ${HOME}/.mozilla 13noblacklist ${HOME}/.mozilla
14noblacklist ${DOCUMENTS}
14 15
15include /etc/firejail/disable-common.inc 16include /etc/firejail/disable-common.inc
16include /etc/firejail/disable-devel.inc 17include /etc/firejail/disable-devel.inc
17include /etc/firejail/disable-interpreters.inc 18include /etc/firejail/disable-interpreters.inc
18include /etc/firejail/disable-passwdmgr.inc 19include /etc/firejail/disable-passwdmgr.inc
19include /etc/firejail/disable-programs.inc 20include /etc/firejail/disable-programs.inc
21include /etc/firejail/disable-xdg.inc
20 22
21include /etc/firejail/whitelist-var-common.inc 23include /etc/firejail/whitelist-var-common.inc
22 24
diff --git a/etc/kodi.profile b/etc/kodi.profile
index 85058da3e..9726304cc 100644
--- a/etc/kodi.profile
+++ b/etc/kodi.profile
@@ -6,6 +6,9 @@ include /etc/firejail/kodi.local
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ${HOME}/.kodi 8noblacklist ${HOME}/.kodi
9noblacklist ${MUSIC}
10noblacklist ${PICTURES}
11noblacklist ${VIDEOS}
9 12
10# Allow python (blacklisted by disable-interpreters.inc) 13# Allow python (blacklisted by disable-interpreters.inc)
11noblacklist ${PATH}/python2* 14noblacklist ${PATH}/python2*
@@ -18,6 +21,7 @@ include /etc/firejail/disable-devel.inc
18include /etc/firejail/disable-interpreters.inc 21include /etc/firejail/disable-interpreters.inc
19include /etc/firejail/disable-passwdmgr.inc 22include /etc/firejail/disable-passwdmgr.inc
20include /etc/firejail/disable-programs.inc 23include /etc/firejail/disable-programs.inc
24include /etc/firejail/disable-xdg.inc
21 25
22include /etc/firejail/whitelist-var-common.inc 26include /etc/firejail/whitelist-var-common.inc
23 27
diff --git a/etc/krita.profile b/etc/krita.profile
index 01f7b6ff8..723a8623a 100644
--- a/etc/krita.profile
+++ b/etc/krita.profile
@@ -7,6 +7,8 @@ include /etc/firejail/globals.local
7 7
8noblacklist ${HOME}/.config/kritarc 8noblacklist ${HOME}/.config/kritarc
9noblacklist ${HOME}/.local/share/krita 9noblacklist ${HOME}/.local/share/krita
10noblacklist ${DOCUMENTS}
11noblacklist ${PICTURES}
10 12
11# Allow python (blacklisted by disable-interpreters.inc) 13# Allow python (blacklisted by disable-interpreters.inc)
12noblacklist ${PATH}/python2* 14noblacklist ${PATH}/python2*
@@ -19,6 +21,7 @@ include /etc/firejail/disable-devel.inc
19include /etc/firejail/disable-interpreters.inc 21include /etc/firejail/disable-interpreters.inc
20include /etc/firejail/disable-passwdmgr.inc 22include /etc/firejail/disable-passwdmgr.inc
21include /etc/firejail/disable-programs.inc 23include /etc/firejail/disable-programs.inc
24include /etc/firejail/disable-xdg.inc
22 25
23apparmor 26apparmor
24caps.drop all 27caps.drop all
diff --git a/etc/kwrite.profile b/etc/kwrite.profile
index e416a5591..3297be3b6 100644
--- a/etc/kwrite.profile
+++ b/etc/kwrite.profile
@@ -12,12 +12,14 @@ noblacklist ${HOME}/.config/katesyntaxhighlightingrc
12noblacklist ${HOME}/.config/katevirc 12noblacklist ${HOME}/.config/katevirc
13noblacklist ${HOME}/.config/kwriterc 13noblacklist ${HOME}/.config/kwriterc
14noblacklist ${HOME}/.local/share/kwrite 14noblacklist ${HOME}/.local/share/kwrite
15noblacklist ${DOCUMENTS}
15 16
16include /etc/firejail/disable-common.inc 17include /etc/firejail/disable-common.inc
17include /etc/firejail/disable-devel.inc 18include /etc/firejail/disable-devel.inc
18include /etc/firejail/disable-interpreters.inc 19include /etc/firejail/disable-interpreters.inc
19include /etc/firejail/disable-passwdmgr.inc 20include /etc/firejail/disable-passwdmgr.inc
20include /etc/firejail/disable-programs.inc 21include /etc/firejail/disable-programs.inc
22include /etc/firejail/disable-xdg.inc
21 23
22include /etc/firejail/whitelist-var-common.inc 24include /etc/firejail/whitelist-var-common.inc
23 25
diff --git a/etc/libreoffice.profile b/etc/libreoffice.profile
index 4aafd7c7a..3caebf208 100644
--- a/etc/libreoffice.profile
+++ b/etc/libreoffice.profile
@@ -8,6 +8,7 @@ include /etc/firejail/globals.local
8noblacklist ${HOME}/.java 8noblacklist ${HOME}/.java
9noblacklist /usr/local/sbin 9noblacklist /usr/local/sbin
10noblacklist ${HOME}/.config/libreoffice 10noblacklist ${HOME}/.config/libreoffice
11noblacklist ${DOCUMENTS}
11 12
12# libreoffice uses java; if you don't care about java functionality, 13# libreoffice uses java; if you don't care about java functionality,
13# comment the next four lines 14# comment the next four lines
@@ -20,6 +21,7 @@ include /etc/firejail/disable-common.inc
20include /etc/firejail/disable-devel.inc 21include /etc/firejail/disable-devel.inc
21include /etc/firejail/disable-passwdmgr.inc 22include /etc/firejail/disable-passwdmgr.inc
22include /etc/firejail/disable-programs.inc 23include /etc/firejail/disable-programs.inc
24include /etc/firejail/disable-xdg.inc
23 25
24include /etc/firejail/whitelist-var-common.inc 26include /etc/firejail/whitelist-var-common.inc
25 27
diff --git a/etc/lollypop.profile b/etc/lollypop.profile
index 1eef6db3b..ed893f53e 100644
--- a/etc/lollypop.profile
+++ b/etc/lollypop.profile
@@ -5,19 +5,21 @@ include /etc/firejail/lollypop.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ${HOME}/.local/share/lollypop
9noblacklist ${MUSIC}
10
8# Allow python (blacklisted by disable-interpreters.inc) 11# Allow python (blacklisted by disable-interpreters.inc)
9noblacklist ${PATH}/python2* 12noblacklist ${PATH}/python2*
10noblacklist ${PATH}/python3* 13noblacklist ${PATH}/python3*
11noblacklist /usr/lib/python2* 14noblacklist /usr/lib/python2*
12noblacklist /usr/lib/python3* 15noblacklist /usr/lib/python3*
13 16
14noblacklist ${HOME}/.local/share/lollypop
15
16include /etc/firejail/disable-common.inc 17include /etc/firejail/disable-common.inc
17include /etc/firejail/disable-devel.inc 18include /etc/firejail/disable-devel.inc
18include /etc/firejail/disable-interpreters.inc 19include /etc/firejail/disable-interpreters.inc
19include /etc/firejail/disable-passwdmgr.inc 20include /etc/firejail/disable-passwdmgr.inc
20include /etc/firejail/disable-programs.inc 21include /etc/firejail/disable-programs.inc
22include /etc/firejail/disable-xdg.inc
21 23
22caps.drop all 24caps.drop all
23netfilter 25netfilter
diff --git a/etc/luminance-hdr.profile b/etc/luminance-hdr.profile
index 8104a2886..05a1c2bb5 100644
--- a/etc/luminance-hdr.profile
+++ b/etc/luminance-hdr.profile
@@ -6,12 +6,14 @@ include /etc/firejail/luminance-hdr.local
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ${HOME}/.config/Luminance 8noblacklist ${HOME}/.config/Luminance
9noblacklist ${PICTURES}
9 10
10include /etc/firejail/disable-common.inc 11include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-devel.inc 12include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-interpreters.inc 13include /etc/firejail/disable-interpreters.inc
13include /etc/firejail/disable-passwdmgr.inc 14include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc 15include /etc/firejail/disable-programs.inc
16include /etc/firejail/disable-xdg.inc
15 17
16caps.drop all 18caps.drop all
17netfilter 19netfilter
diff --git a/etc/lxmusic.profile b/etc/lxmusic.profile
index 5962c7dc7..44aa0537b 100644
--- a/etc/lxmusic.profile
+++ b/etc/lxmusic.profile
@@ -7,12 +7,14 @@ include /etc/firejail/globals.local
7 7
8noblacklist ${HOME}/.cache/xmms2 8noblacklist ${HOME}/.cache/xmms2
9noblacklist ${HOME}/.config/xmms2 9noblacklist ${HOME}/.config/xmms2
10noblacklist ${MUSIC}
10 11
11include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
12include /etc/firejail/disable-devel.inc 13include /etc/firejail/disable-devel.inc
13include /etc/firejail/disable-interpreters.inc 14include /etc/firejail/disable-interpreters.inc
14include /etc/firejail/disable-passwdmgr.inc 15include /etc/firejail/disable-passwdmgr.inc
15include /etc/firejail/disable-programs.inc 16include /etc/firejail/disable-programs.inc
17include /etc/firejail/disable-xdg.inc
16 18
17include /etc/firejail/whitelist-var-common.inc 19include /etc/firejail/whitelist-var-common.inc
18 20
diff --git a/etc/lynx.profile b/etc/lynx.profile
index ba5322787..0f4de2fee 100644
--- a/etc/lynx.profile
+++ b/etc/lynx.profile
@@ -12,6 +12,7 @@ include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-interpreters.inc 12include /etc/firejail/disable-interpreters.inc
13include /etc/firejail/disable-passwdmgr.inc 13include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc 14include /etc/firejail/disable-programs.inc
15include /etc/firejail/disable-xdg.inc
15 16
16caps.drop all 17caps.drop all
17netfilter 18netfilter
diff --git a/etc/mpd.profile b/etc/mpd.profile
index 2ad520633..50ef915ce 100644
--- a/etc/mpd.profile
+++ b/etc/mpd.profile
@@ -8,12 +8,14 @@ include /etc/firejail/globals.local
8noblacklist ${HOME}/.config/mpd 8noblacklist ${HOME}/.config/mpd
9noblacklist ${HOME}/.mpd 9noblacklist ${HOME}/.mpd
10noblacklist ${HOME}/.mpdconf 10noblacklist ${HOME}/.mpdconf
11noblacklist ${MUSIC}
11 12
12include /etc/firejail/disable-common.inc 13include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-devel.inc 14include /etc/firejail/disable-devel.inc
14include /etc/firejail/disable-interpreters.inc 15include /etc/firejail/disable-interpreters.inc
15include /etc/firejail/disable-passwdmgr.inc 16include /etc/firejail/disable-passwdmgr.inc
16include /etc/firejail/disable-programs.inc 17include /etc/firejail/disable-programs.inc
18include /etc/firejail/disable-xdg.inc
17 19
18caps.drop all 20caps.drop all
19netfilter 21netfilter
diff --git a/etc/mpv.profile b/etc/mpv.profile
index 18233c31b..93a574881 100644
--- a/etc/mpv.profile
+++ b/etc/mpv.profile
@@ -7,6 +7,8 @@ include /etc/firejail/globals.local
7 7
8noblacklist ${HOME}/.config/mpv 8noblacklist ${HOME}/.config/mpv
9noblacklist ${HOME}/.netrc 9noblacklist ${HOME}/.netrc
10noblacklist ${MUSIC}
11noblacklist ${VIDEOS}
10 12
11# Allow python (blacklisted by disable-interpreters.inc) 13# Allow python (blacklisted by disable-interpreters.inc)
12noblacklist ${PATH}/python2* 14noblacklist ${PATH}/python2*
@@ -19,6 +21,7 @@ include /etc/firejail/disable-devel.inc
19include /etc/firejail/disable-interpreters.inc 21include /etc/firejail/disable-interpreters.inc
20include /etc/firejail/disable-passwdmgr.inc 22include /etc/firejail/disable-passwdmgr.inc
21include /etc/firejail/disable-programs.inc 23include /etc/firejail/disable-programs.inc
24include /etc/firejail/disable-xdg.inc
22 25
23include /etc/firejail/whitelist-var-common.inc 26include /etc/firejail/whitelist-var-common.inc
24 27
diff --git a/etc/mupdf.profile b/etc/mupdf.profile
index 9ccdf60a8..632e3c66a 100644
--- a/etc/mupdf.profile
+++ b/etc/mupdf.profile
@@ -5,11 +5,14 @@ include /etc/firejail/mupdf.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ${DOCUMENTS}
9
8include /etc/firejail/disable-common.inc 10include /etc/firejail/disable-common.inc
9include /etc/firejail/disable-devel.inc 11include /etc/firejail/disable-devel.inc
10include /etc/firejail/disable-interpreters.inc 12include /etc/firejail/disable-interpreters.inc
11include /etc/firejail/disable-passwdmgr.inc 13include /etc/firejail/disable-passwdmgr.inc
12include /etc/firejail/disable-programs.inc 14include /etc/firejail/disable-programs.inc
15include /etc/firejail/disable-xdg.inc
13 16
14include /etc/firejail/whitelist-var-common.inc 17include /etc/firejail/whitelist-var-common.inc
15 18
diff --git a/etc/musescore.profile b/etc/musescore.profile
index 5b07a59da..4e28051a4 100644
--- a/etc/musescore.profile
+++ b/etc/musescore.profile
@@ -9,12 +9,15 @@ noblacklist ${HOME}/.config/MusE
9noblacklist ${HOME}/.config/MuseScore 9noblacklist ${HOME}/.config/MuseScore
10noblacklist ${HOME}/.local/share/data/MusE 10noblacklist ${HOME}/.local/share/data/MusE
11noblacklist ${HOME}/.local/share/data/MuseScore 11noblacklist ${HOME}/.local/share/data/MuseScore
12noblacklist ${DOCUMENTS}
13noblacklist ${MUSIC}
12 14
13include /etc/firejail/disable-common.inc 15include /etc/firejail/disable-common.inc
14include /etc/firejail/disable-devel.inc 16include /etc/firejail/disable-devel.inc
15include /etc/firejail/disable-interpreters.inc 17include /etc/firejail/disable-interpreters.inc
16include /etc/firejail/disable-passwdmgr.inc 18include /etc/firejail/disable-passwdmgr.inc
17include /etc/firejail/disable-programs.inc 19include /etc/firejail/disable-programs.inc
20include /etc/firejail/disable-xdg.inc
18 21
19include /etc/firejail/whitelist-var-common.inc 22include /etc/firejail/whitelist-var-common.inc
20 23
diff --git a/etc/obs.profile b/etc/obs.profile
index 7529dd1bb..6d638e6e6 100644
--- a/etc/obs.profile
+++ b/etc/obs.profile
@@ -6,12 +6,16 @@ include /etc/firejail/obs.local
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ${HOME}/.config/obs-studio 8noblacklist ${HOME}/.config/obs-studio
9noblacklist ${MUSIC}
10noblacklist ${PICTURES}
11noblacklist ${VIDEOS}
9 12
10include /etc/firejail/disable-common.inc 13include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-devel.inc 14include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-interpreters.inc 15include /etc/firejail/disable-interpreters.inc
13include /etc/firejail/disable-passwdmgr.inc 16include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc 17include /etc/firejail/disable-programs.inc
18include /etc/firejail/disable-xdg.inc
15 19
16caps.drop all 20caps.drop all
17nodvd 21nodvd
diff --git a/etc/okular.profile b/etc/okular.profile
index 50b69ceaf..8fe3b9354 100644
--- a/etc/okular.profile
+++ b/etc/okular.profile
@@ -15,12 +15,14 @@ noblacklist ${HOME}/.kde4/share/apps/okular
15noblacklist ${HOME}/.kde4/share/config/okularpartrc 15noblacklist ${HOME}/.kde4/share/config/okularpartrc
16noblacklist ${HOME}/.kde4/share/config/okularrc 16noblacklist ${HOME}/.kde4/share/config/okularrc
17noblacklist ${HOME}/.local/share/okular 17noblacklist ${HOME}/.local/share/okular
18noblacklist ${DOCUMENTS}
18 19
19include /etc/firejail/disable-common.inc 20include /etc/firejail/disable-common.inc
20include /etc/firejail/disable-devel.inc 21include /etc/firejail/disable-devel.inc
21include /etc/firejail/disable-interpreters.inc 22include /etc/firejail/disable-interpreters.inc
22include /etc/firejail/disable-passwdmgr.inc 23include /etc/firejail/disable-passwdmgr.inc
23include /etc/firejail/disable-programs.inc 24include /etc/firejail/disable-programs.inc
25include /etc/firejail/disable-xdg.inc
24 26
25include /etc/firejail/whitelist-var-common.inc 27include /etc/firejail/whitelist-var-common.inc
26 28
diff --git a/etc/orage.profile b/etc/orage.profile
index 2ac420f05..89720ce34 100644
--- a/etc/orage.profile
+++ b/etc/orage.profile
@@ -13,6 +13,7 @@ include /etc/firejail/disable-devel.inc
13include /etc/firejail/disable-interpreters.inc 13include /etc/firejail/disable-interpreters.inc
14include /etc/firejail/disable-passwdmgr.inc 14include /etc/firejail/disable-passwdmgr.inc
15include /etc/firejail/disable-programs.inc 15include /etc/firejail/disable-programs.inc
16include /etc/firejail/disable-xdg.inc
16 17
17caps.drop all 18caps.drop all
18netfilter 19netfilter
diff --git a/etc/parole.profile b/etc/parole.profile
index 36ae97726..f98703bd6 100644
--- a/etc/parole.profile
+++ b/etc/parole.profile
@@ -5,12 +5,15 @@ include /etc/firejail/parole.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ${MUSIC}
9noblacklist ${VIDEOS}
8 10
9include /etc/firejail/disable-common.inc 11include /etc/firejail/disable-common.inc
10include /etc/firejail/disable-devel.inc 12include /etc/firejail/disable-devel.inc
11include /etc/firejail/disable-interpreters.inc 13include /etc/firejail/disable-interpreters.inc
12include /etc/firejail/disable-passwdmgr.inc 14include /etc/firejail/disable-passwdmgr.inc
13include /etc/firejail/disable-programs.inc 15include /etc/firejail/disable-programs.inc
16include /etc/firejail/disable-xdg.inc
14 17
15caps.drop all 18caps.drop all
16netfilter 19netfilter
diff --git a/etc/pdfchain.profile b/etc/pdfchain.profile
index 8da5869e3..f6a615632 100644
--- a/etc/pdfchain.profile
+++ b/etc/pdfchain.profile
@@ -5,11 +5,14 @@ include /etc/firejail/pdfchain.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ${DOCUMENTS}
9
8include /etc/firejail/disable-common.inc 10include /etc/firejail/disable-common.inc
9include /etc/firejail/disable-devel.inc 11include /etc/firejail/disable-devel.inc
10include /etc/firejail/disable-interpreters.inc 12include /etc/firejail/disable-interpreters.inc
11include /etc/firejail/disable-passwdmgr.inc 13include /etc/firejail/disable-passwdmgr.inc
12include /etc/firejail/disable-programs.inc 14include /etc/firejail/disable-programs.inc
15include /etc/firejail/disable-xdg.inc
13 16
14include /etc/firejail/whitelist-var-common.inc 17include /etc/firejail/whitelist-var-common.inc
15 18
diff --git a/etc/pdfmod.profile b/etc/pdfmod.profile
index aa674419d..2e3573121 100644
--- a/etc/pdfmod.profile
+++ b/etc/pdfmod.profile
@@ -7,12 +7,14 @@ include /etc/firejail/globals.local
7 7
8noblacklist ${HOME}/.cache/pdfmod 8noblacklist ${HOME}/.cache/pdfmod
9noblacklist ${HOME}/.config/pdfmod 9noblacklist ${HOME}/.config/pdfmod
10noblacklist ${DOCUMENTS}
10 11
11include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
12include /etc/firejail/disable-devel.inc 13include /etc/firejail/disable-devel.inc
13include /etc/firejail/disable-interpreters.inc 14include /etc/firejail/disable-interpreters.inc
14include /etc/firejail/disable-passwdmgr.inc 15include /etc/firejail/disable-passwdmgr.inc
15include /etc/firejail/disable-programs.inc 16include /etc/firejail/disable-programs.inc
17include /etc/firejail/disable-xdg.inc
16 18
17include /etc/firejail/whitelist-var-common.inc 19include /etc/firejail/whitelist-var-common.inc
18 20
diff --git a/etc/pdfsam.profile b/etc/pdfsam.profile
index fbd7ec179..daae31338 100644
--- a/etc/pdfsam.profile
+++ b/etc/pdfsam.profile
@@ -5,8 +5,8 @@ include /etc/firejail/pdfsam.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8# Allow access to java
9noblacklist ${HOME}/.java 8noblacklist ${HOME}/.java
9noblacklist ${DOCUMENTS}
10 10
11# Allow access to java 11# Allow access to java
12noblacklist ${PATH}/java 12noblacklist ${PATH}/java
@@ -19,6 +19,7 @@ include /etc/firejail/disable-devel.inc
19include /etc/firejail/disable-interpreters.inc 19include /etc/firejail/disable-interpreters.inc
20include /etc/firejail/disable-passwdmgr.inc 20include /etc/firejail/disable-passwdmgr.inc
21include /etc/firejail/disable-programs.inc 21include /etc/firejail/disable-programs.inc
22include /etc/firejail/disable-xdg.inc
22 23
23caps.drop all 24caps.drop all
24machine-id 25machine-id
diff --git a/etc/peek.profile b/etc/peek.profile
index 5d5a32b8a..edc43d006 100644
--- a/etc/peek.profile
+++ b/etc/peek.profile
@@ -6,12 +6,15 @@ include /etc/firejail/peek.local
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ${HOME}/.cache/peek 8noblacklist ${HOME}/.cache/peek
9noblacklist ${PICTURES}
10noblacklist ${VIDEOS}
9 11
10include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-devel.inc 13include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-interpreters.inc 14include /etc/firejail/disable-interpreters.inc
13include /etc/firejail/disable-passwdmgr.inc 15include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc 16include /etc/firejail/disable-programs.inc
17include /etc/firejail/disable-xdg.inc
15 18
16caps.drop all 19caps.drop all
17net none 20net none
diff --git a/etc/picard.profile b/etc/picard.profile
index 484b0e6b2..4031d51f5 100644
--- a/etc/picard.profile
+++ b/etc/picard.profile
@@ -7,6 +7,7 @@ include /etc/firejail/globals.local
7 7
8noblacklist ${HOME}/.cache/MusicBrainz 8noblacklist ${HOME}/.cache/MusicBrainz
9noblacklist ${HOME}/.config/MusicBrainz 9noblacklist ${HOME}/.config/MusicBrainz
10noblacklist ${MUSIC}
10 11
11# Allow python (blacklisted by disable-interpreters.inc) 12# Allow python (blacklisted by disable-interpreters.inc)
12noblacklist ${PATH}/python2* 13noblacklist ${PATH}/python2*
@@ -19,6 +20,7 @@ include /etc/firejail/disable-devel.inc
19include /etc/firejail/disable-interpreters.inc 20include /etc/firejail/disable-interpreters.inc
20include /etc/firejail/disable-passwdmgr.inc 21include /etc/firejail/disable-passwdmgr.inc
21include /etc/firejail/disable-programs.inc 22include /etc/firejail/disable-programs.inc
23include /etc/firejail/disable-xdg.inc
22 24
23caps.drop all 25caps.drop all
24no3d 26no3d
diff --git a/etc/ping.profile b/etc/ping.profile
index d014fb82c..8fd315e44 100644
--- a/etc/ping.profile
+++ b/etc/ping.profile
@@ -12,6 +12,7 @@ include /etc/firejail/disable-interpreters.inc
12include /etc/firejail/disable-passwdmgr.inc 12include /etc/firejail/disable-passwdmgr.inc
13include /etc/firejail/disable-programs.inc 13include /etc/firejail/disable-programs.inc
14include /etc/firejail/whitelist-common.inc 14include /etc/firejail/whitelist-common.inc
15include /etc/firejail/disable-xdg.inc
15 16
16caps.keep net_raw 17caps.keep net_raw
17ipc-namespace 18ipc-namespace
diff --git a/etc/pinta.profile b/etc/pinta.profile
index 010de0d3e..335659430 100644
--- a/etc/pinta.profile
+++ b/etc/pinta.profile
@@ -6,12 +6,15 @@ include /etc/firejail/pinta.local
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ${HOME}/.config/Pinta 8noblacklist ${HOME}/.config/Pinta
9noblacklist ${DOCUMENTS}
10noblacklist ${PICTURES}
9 11
10include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-devel.inc 13include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-interpreters.inc 14include /etc/firejail/disable-interpreters.inc
13include /etc/firejail/disable-passwdmgr.inc 15include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc 16include /etc/firejail/disable-programs.inc
17include /etc/firejail/disable-xdg.inc
15 18
16caps.drop all 19caps.drop all
17ipc-namespace 20ipc-namespace
diff --git a/etc/pithos.profile b/etc/pithos.profile
index c7eac0d53..7f0ba56b8 100644
--- a/etc/pithos.profile
+++ b/etc/pithos.profile
@@ -16,6 +16,7 @@ include /etc/firejail/disable-devel.inc
16include /etc/firejail/disable-interpreters.inc 16include /etc/firejail/disable-interpreters.inc
17include /etc/firejail/disable-passwdmgr.inc 17include /etc/firejail/disable-passwdmgr.inc
18include /etc/firejail/disable-programs.inc 18include /etc/firejail/disable-programs.inc
19include /etc/firejail/disable-xdg.inc
19 20
20include /etc/firejail/whitelist-common.inc 21include /etc/firejail/whitelist-common.inc
21 22
diff --git a/etc/ppsspp.profile b/etc/ppsspp.profile
index e19a7b42a..073108464 100644
--- a/etc/ppsspp.profile
+++ b/etc/ppsspp.profile
@@ -6,6 +6,7 @@ include /etc/firejail/ppsspp.local
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ${HOME}/.config/ppsspp 8noblacklist ${HOME}/.config/ppsspp
9noblacklist ${DOCUMENTS}
9# with >=llvm-4 mesa drivers need llvm stuff 10# with >=llvm-4 mesa drivers need llvm stuff
10noblacklist /usr/lib/llvm* 11noblacklist /usr/lib/llvm*
11 12
@@ -14,6 +15,7 @@ include /etc/firejail/disable-devel.inc
14include /etc/firejail/disable-interpreters.inc 15include /etc/firejail/disable-interpreters.inc
15include /etc/firejail/disable-passwdmgr.inc 16include /etc/firejail/disable-passwdmgr.inc
16include /etc/firejail/disable-programs.inc 17include /etc/firejail/disable-programs.inc
18include /etc/firejail/disable-xdg.inc
17 19
18include /etc/firejail/whitelist-var-common.inc 20include /etc/firejail/whitelist-var-common.inc
19 21
diff --git a/etc/qlipper.profile b/etc/qlipper.profile
index 079270909..a99825a0c 100644
--- a/etc/qlipper.profile
+++ b/etc/qlipper.profile
@@ -12,6 +12,7 @@ include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-interpreters.inc 12include /etc/firejail/disable-interpreters.inc
13include /etc/firejail/disable-passwdmgr.inc 13include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc 14include /etc/firejail/disable-programs.inc
15include /etc/firejail/disable-xdg.inc
15 16
16caps.drop all 17caps.drop all
17netfilter 18netfilter
diff --git a/etc/qmmp.profile b/etc/qmmp.profile
index 2382e9453..5c3873b7f 100644
--- a/etc/qmmp.profile
+++ b/etc/qmmp.profile
@@ -6,11 +6,13 @@ include /etc/firejail/qmmp.local
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ${HOME}/.qmmp 8noblacklist ${HOME}/.qmmp
9noblacklist ${MUSIC}
9 10
10include /etc/firejail/disable-common.inc 11include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-devel.inc 12include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-passwdmgr.inc 13include /etc/firejail/disable-passwdmgr.inc
13include /etc/firejail/disable-programs.inc 14include /etc/firejail/disable-programs.inc
15include /etc/firejail/disable-xdg.inc
14 16
15caps.drop all 17caps.drop all
16netfilter 18netfilter
diff --git a/etc/qpdfview.profile b/etc/qpdfview.profile
index e422d2196..6057bf4f1 100644
--- a/etc/qpdfview.profile
+++ b/etc/qpdfview.profile
@@ -7,12 +7,14 @@ include /etc/firejail/globals.local
7 7
8noblacklist ${HOME}/.config/qpdfview 8noblacklist ${HOME}/.config/qpdfview
9noblacklist ${HOME}/.local/share/qpdfview 9noblacklist ${HOME}/.local/share/qpdfview
10noblacklist ${DOCUMENTS}
10 11
11include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
12include /etc/firejail/disable-devel.inc 13include /etc/firejail/disable-devel.inc
13include /etc/firejail/disable-interpreters.inc 14include /etc/firejail/disable-interpreters.inc
14include /etc/firejail/disable-passwdmgr.inc 15include /etc/firejail/disable-passwdmgr.inc
15include /etc/firejail/disable-programs.inc 16include /etc/firejail/disable-programs.inc
17include /etc/firejail/disable-xdg.inc
16 18
17include /etc/firejail/whitelist-var-common.inc 19include /etc/firejail/whitelist-var-common.inc
18 20
diff --git a/etc/remmina.profile b/etc/remmina.profile
index 50746c60e..71f4bb94f 100644
--- a/etc/remmina.profile
+++ b/etc/remmina.profile
@@ -15,6 +15,7 @@ include /etc/firejail/disable-devel.inc
15include /etc/firejail/disable-interpreters.inc 15include /etc/firejail/disable-interpreters.inc
16include /etc/firejail/disable-passwdmgr.inc 16include /etc/firejail/disable-passwdmgr.inc
17include /etc/firejail/disable-programs.inc 17include /etc/firejail/disable-programs.inc
18include /etc/firejail/disable-xdg.inc
18 19
19caps.drop all 20caps.drop all
20nodvd 21nodvd
diff --git a/etc/rhythmbox.profile b/etc/rhythmbox.profile
index 57e1ce5f0..ca06845a5 100644
--- a/etc/rhythmbox.profile
+++ b/etc/rhythmbox.profile
@@ -5,6 +5,7 @@ include /etc/firejail/rhythmbox.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ${MUSIC}
8 9
9include /etc/firejail/disable-common.inc 10include /etc/firejail/disable-common.inc
10include /etc/firejail/disable-devel.inc 11include /etc/firejail/disable-devel.inc
@@ -12,6 +13,7 @@ include /etc/firejail/disable-devel.inc
12#include /etc/firejail/disable-interpreters.inc 13#include /etc/firejail/disable-interpreters.inc
13include /etc/firejail/disable-passwdmgr.inc 14include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc 15include /etc/firejail/disable-programs.inc
16include /etc/firejail/disable-xdg.inc
15 17
16include /etc/firejail/whitelist-var-common.inc 18include /etc/firejail/whitelist-var-common.inc
17 19
diff --git a/etc/sayonara.profile b/etc/sayonara.profile
index 756bd99eb..8a369be7e 100644
--- a/etc/sayonara.profile
+++ b/etc/sayonara.profile
@@ -6,11 +6,13 @@ include /etc/firejail/sayonara.local
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ${HOME}/.Sayonara 8noblacklist ${HOME}/.Sayonara
9noblacklist ${MUSIC}
9 10
10include /etc/firejail/disable-common.inc 11include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-devel.inc 12include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-passwdmgr.inc 13include /etc/firejail/disable-passwdmgr.inc
13include /etc/firejail/disable-programs.inc 14include /etc/firejail/disable-programs.inc
15include /etc/firejail/disable-xdg.inc
14 16
15caps.drop all 17caps.drop all
16netfilter 18netfilter
diff --git a/etc/scallion.profile b/etc/scallion.profile
index 645f0423c..35cd04f8f 100644
--- a/etc/scallion.profile
+++ b/etc/scallion.profile
@@ -10,11 +10,13 @@ noblacklist ${PATH}/llvm*
10noblacklist /usr/lib/llvm* 10noblacklist /usr/lib/llvm*
11noblacklist ${PATH}/openssl 11noblacklist ${PATH}/openssl
12noblacklist ${PATH}/openssl-1.0 12noblacklist ${PATH}/openssl-1.0
13noblacklist ${DOCUMENTS}
13 14
14include /etc/firejail/disable-common.inc 15include /etc/firejail/disable-common.inc
15include /etc/firejail/disable-interpreters.inc 16include /etc/firejail/disable-interpreters.inc
16include /etc/firejail/disable-passwdmgr.inc 17include /etc/firejail/disable-passwdmgr.inc
17include /etc/firejail/disable-programs.inc 18include /etc/firejail/disable-programs.inc
19include /etc/firejail/disable-xdg.inc
18 20
19include /etc/firejail/whitelist-var-common.inc 21include /etc/firejail/whitelist-var-common.inc
20 22
diff --git a/etc/scribus.profile b/etc/scribus.profile
index c7c8ca72c..f08c57c1b 100644
--- a/etc/scribus.profile
+++ b/etc/scribus.profile
@@ -22,6 +22,8 @@ noblacklist ${HOME}/.kde4/share/config/okularrc
22noblacklist ${HOME}/.local/share/okular 22noblacklist ${HOME}/.local/share/okular
23noblacklist ${HOME}/.local/share/scribus 23noblacklist ${HOME}/.local/share/scribus
24noblacklist ${HOME}/.scribus 24noblacklist ${HOME}/.scribus
25noblacklist ${DOCUMENTS}
26noblacklist ${PICTURES}
25 27
26# Allow python (blacklisted by disable-interpreters.inc) 28# Allow python (blacklisted by disable-interpreters.inc)
27noblacklist ${PATH}/python2* 29noblacklist ${PATH}/python2*
@@ -34,6 +36,7 @@ include /etc/firejail/disable-devel.inc
34include /etc/firejail/disable-interpreters.inc 36include /etc/firejail/disable-interpreters.inc
35include /etc/firejail/disable-passwdmgr.inc 37include /etc/firejail/disable-passwdmgr.inc
36include /etc/firejail/disable-programs.inc 38include /etc/firejail/disable-programs.inc
39include /etc/firejail/disable-xdg.inc
37 40
38include /etc/firejail/whitelist-var-common.inc 41include /etc/firejail/whitelist-var-common.inc
39 42
diff --git a/etc/sdat2img.profile b/etc/sdat2img.profile
index fbe1b2de5..e318dd568 100644
--- a/etc/sdat2img.profile
+++ b/etc/sdat2img.profile
@@ -17,6 +17,7 @@ include /etc/firejail/disable-devel.inc
17include /etc/firejail/disable-interpreters.inc 17include /etc/firejail/disable-interpreters.inc
18include /etc/firejail/disable-passwdmgr.inc 18include /etc/firejail/disable-passwdmgr.inc
19include /etc/firejail/disable-programs.inc 19include /etc/firejail/disable-programs.inc
20include /etc/firejail/disable-xdg.inc
20 21
21caps.drop all 22caps.drop all
22net none 23net none
diff --git a/etc/silentarmy.profile b/etc/silentarmy.profile
index c83c56798..0fa19e610 100644
--- a/etc/silentarmy.profile
+++ b/etc/silentarmy.profile
@@ -11,6 +11,7 @@ include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-interpreters.inc 11include /etc/firejail/disable-interpreters.inc
12include /etc/firejail/disable-passwdmgr.inc 12include /etc/firejail/disable-passwdmgr.inc
13include /etc/firejail/disable-programs.inc 13include /etc/firejail/disable-programs.inc
14include /etc/firejail/disable-xdg.inc
14 15
15include /etc/firejail/whitelist-var-common.inc 16include /etc/firejail/whitelist-var-common.inc
16 17
diff --git a/etc/simple-scan.profile b/etc/simple-scan.profile
index 02c7cc6ed..3e8a4e41b 100644
--- a/etc/simple-scan.profile
+++ b/etc/simple-scan.profile
@@ -6,12 +6,14 @@ include /etc/firejail/simple-scan.local
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ${HOME}/.cache/simple-scan 8noblacklist ${HOME}/.cache/simple-scan
9noblacklist ${DOCUMENTS}
9 10
10include /etc/firejail/disable-common.inc 11include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-devel.inc 12include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-interpreters.inc 13include /etc/firejail/disable-interpreters.inc
13include /etc/firejail/disable-passwdmgr.inc 14include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc 15include /etc/firejail/disable-programs.inc
16include /etc/firejail/disable-xdg.inc
15 17
16caps.drop all 18caps.drop all
17netfilter 19netfilter
diff --git a/etc/skanlite.profile b/etc/skanlite.profile
index ee027bf51..5bac0a90d 100644
--- a/etc/skanlite.profile
+++ b/etc/skanlite.profile
@@ -5,11 +5,14 @@ include /etc/firejail/skanlite.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ${DOCUMENTS}
9
8include /etc/firejail/disable-common.inc 10include /etc/firejail/disable-common.inc
9include /etc/firejail/disable-devel.inc 11include /etc/firejail/disable-devel.inc
10include /etc/firejail/disable-interpreters.inc 12include /etc/firejail/disable-interpreters.inc
11include /etc/firejail/disable-passwdmgr.inc 13include /etc/firejail/disable-passwdmgr.inc
12include /etc/firejail/disable-programs.inc 14include /etc/firejail/disable-programs.inc
15include /etc/firejail/disable-xdg.inc
13 16
14caps.drop all 17caps.drop all
15# net none 18# net none
diff --git a/etc/smplayer.profile b/etc/smplayer.profile
index 63c13ff37..2e792d891 100644
--- a/etc/smplayer.profile
+++ b/etc/smplayer.profile
@@ -7,12 +7,15 @@ include /etc/firejail/globals.local
7 7
8noblacklist ${HOME}/.config/smplayer 8noblacklist ${HOME}/.config/smplayer
9noblacklist ${HOME}/.mplayer 9noblacklist ${HOME}/.mplayer
10noblacklist ${MUSIC}
11noblacklist ${VIDEOS}
10 12
11include /etc/firejail/disable-common.inc 13include /etc/firejail/disable-common.inc
12include /etc/firejail/disable-devel.inc 14include /etc/firejail/disable-devel.inc
13include /etc/firejail/disable-interpreters.inc 15include /etc/firejail/disable-interpreters.inc
14include /etc/firejail/disable-passwdmgr.inc 16include /etc/firejail/disable-passwdmgr.inc
15include /etc/firejail/disable-programs.inc 17include /etc/firejail/disable-programs.inc
18include /etc/firejail/disable-xdg.inc
16 19
17include /etc/firejail/whitelist-var-common.inc 20include /etc/firejail/whitelist-var-common.inc
18 21
diff --git a/etc/smtube.profile b/etc/smtube.profile
index 040a7c754..67de1490c 100644
--- a/etc/smtube.profile
+++ b/etc/smtube.profile
@@ -11,12 +11,14 @@ noblacklist ${HOME}/.config/mpv
11noblacklist ${HOME}/.mplayer 11noblacklist ${HOME}/.mplayer
12noblacklist ${HOME}/.config/vlc 12noblacklist ${HOME}/.config/vlc
13noblacklist ${HOME}/.local/share/vlc 13noblacklist ${HOME}/.local/share/vlc
14noblacklist ${VIDEOS}
14 15
15include /etc/firejail/disable-common.inc 16include /etc/firejail/disable-common.inc
16include /etc/firejail/disable-devel.inc 17include /etc/firejail/disable-devel.inc
17include /etc/firejail/disable-interpreters.inc 18include /etc/firejail/disable-interpreters.inc
18include /etc/firejail/disable-passwdmgr.inc 19include /etc/firejail/disable-passwdmgr.inc
19include /etc/firejail/disable-programs.inc 20include /etc/firejail/disable-programs.inc
21include /etc/firejail/disable-xdg.inc
20 22
21include /etc/firejail/whitelist-var-common.inc 23include /etc/firejail/whitelist-var-common.inc
22 24
diff --git a/etc/soundconverter.profile b/etc/soundconverter.profile
index b15ba266b..a7c8dfce6 100644
--- a/etc/soundconverter.profile
+++ b/etc/soundconverter.profile
@@ -5,6 +5,8 @@ include /etc/firejail/soundconverter.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ${MUSIC}
9
8# Allow python (blacklisted by disable-interpreters.inc) 10# Allow python (blacklisted by disable-interpreters.inc)
9noblacklist ${PATH}/python2* 11noblacklist ${PATH}/python2*
10noblacklist ${PATH}/python3* 12noblacklist ${PATH}/python3*
@@ -16,6 +18,7 @@ include /etc/firejail/disable-devel.inc
16include /etc/firejail/disable-interpreters.inc 18include /etc/firejail/disable-interpreters.inc
17include /etc/firejail/disable-passwdmgr.inc 19include /etc/firejail/disable-passwdmgr.inc
18include /etc/firejail/disable-programs.inc 20include /etc/firejail/disable-programs.inc
21include /etc/firejail/disable-xdg.inc
19 22
20caps.drop all 23caps.drop all
21net none 24net none
diff --git a/etc/sqlitebrowser.profile b/etc/sqlitebrowser.profile
index 7bb7080e3..5fee722bf 100644
--- a/etc/sqlitebrowser.profile
+++ b/etc/sqlitebrowser.profile
@@ -6,12 +6,14 @@ include /etc/firejail/sqlitebrowser.local
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ${HOME}/.config/sqlitebrowser 8noblacklist ${HOME}/.config/sqlitebrowser
9noblacklist ${DOCUMENTS}
9 10
10include /etc/firejail/disable-common.inc 11include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-devel.inc 12include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-interpreters.inc 13include /etc/firejail/disable-interpreters.inc
13include /etc/firejail/disable-passwdmgr.inc 14include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc 15include /etc/firejail/disable-programs.inc
16include /etc/firejail/disable-xdg.inc
15 17
16caps.drop all 18caps.drop all
17net none 19net none
diff --git a/etc/start-tor-browser.profile b/etc/start-tor-browser.profile
index e7eb01eb5..fe9760ad4 100644
--- a/etc/start-tor-browser.profile
+++ b/etc/start-tor-browser.profile
@@ -11,6 +11,7 @@ include /etc/firejail/disable-devel.inc
11include /etc/firejail/disable-interpreters.inc 11include /etc/firejail/disable-interpreters.inc
12include /etc/firejail/disable-passwdmgr.inc 12include /etc/firejail/disable-passwdmgr.inc
13include /etc/firejail/disable-programs.inc 13include /etc/firejail/disable-programs.inc
14include /etc/firejail/disable-xdg.inc
14 15
15include /etc/firejail/whitelist-var-common.inc 16include /etc/firejail/whitelist-var-common.inc
16 17
diff --git a/etc/tor.profile b/etc/tor.profile
index e37fd232c..cbe932104 100644
--- a/etc/tor.profile
+++ b/etc/tor.profile
@@ -21,6 +21,7 @@ include /etc/firejail/disable-devel.inc
21include /etc/firejail/disable-interpreters.inc 21include /etc/firejail/disable-interpreters.inc
22include /etc/firejail/disable-passwdmgr.inc 22include /etc/firejail/disable-passwdmgr.inc
23include /etc/firejail/disable-programs.inc 23include /etc/firejail/disable-programs.inc
24include /etc/firejail/disable-xdg.inc
24 25
25caps.keep setuid,setgid,net_bind_service,dac_read_search 26caps.keep setuid,setgid,net_bind_service,dac_read_search
26ipc-namespace 27ipc-namespace
diff --git a/etc/totem.profile b/etc/totem.profile
index 0b9252d6c..3ac25440b 100644
--- a/etc/totem.profile
+++ b/etc/totem.profile
@@ -7,12 +7,15 @@ include /etc/firejail/globals.local
7 7
8noblacklist ${HOME}/.config/totem 8noblacklist ${HOME}/.config/totem
9noblacklist ${HOME}/.local/share/totem 9noblacklist ${HOME}/.local/share/totem
10noblacklist ${MUSIC}
11noblacklist ${VIDEOS}
10 12
11include /etc/firejail/disable-common.inc 13include /etc/firejail/disable-common.inc
12include /etc/firejail/disable-devel.inc 14include /etc/firejail/disable-devel.inc
13include /etc/firejail/disable-interpreters.inc 15include /etc/firejail/disable-interpreters.inc
14include /etc/firejail/disable-passwdmgr.inc 16include /etc/firejail/disable-passwdmgr.inc
15include /etc/firejail/disable-programs.inc 17include /etc/firejail/disable-programs.inc
18include /etc/firejail/disable-xdg.inc
16 19
17include /etc/firejail/whitelist-var-common.inc 20include /etc/firejail/whitelist-var-common.inc
18 21
diff --git a/etc/uefitool.profile b/etc/uefitool.profile
index 70d694ac9..d4016d061 100644
--- a/etc/uefitool.profile
+++ b/etc/uefitool.profile
@@ -5,11 +5,14 @@ include /etc/firejail/uefitool.local
5# Persistent global definitions 5# Persistent global definitions
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ${DOCUMENTS}
9
8include /etc/firejail/disable-common.inc 10include /etc/firejail/disable-common.inc
9include /etc/firejail/disable-devel.inc 11include /etc/firejail/disable-devel.inc
10include /etc/firejail/disable-interpreters.inc 12include /etc/firejail/disable-interpreters.inc
11include /etc/firejail/disable-passwdmgr.inc 13include /etc/firejail/disable-passwdmgr.inc
12include /etc/firejail/disable-programs.inc 14include /etc/firejail/disable-programs.inc
15include /etc/firejail/disable-xdg.inc
13 16
14caps.drop all 17caps.drop all
15ipc-namespace 18ipc-namespace
diff --git a/etc/unbound.profile b/etc/unbound.profile
index 35bda2edc..3d7ca7285 100644
--- a/etc/unbound.profile
+++ b/etc/unbound.profile
@@ -15,6 +15,7 @@ include /etc/firejail/disable-devel.inc
15include /etc/firejail/disable-interpreters.inc 15include /etc/firejail/disable-interpreters.inc
16include /etc/firejail/disable-passwdmgr.inc 16include /etc/firejail/disable-passwdmgr.inc
17include /etc/firejail/disable-programs.inc 17include /etc/firejail/disable-programs.inc
18include /etc/firejail/disable-xdg.inc
18 19
19whitelist /var/lib/unbound 20whitelist /var/lib/unbound
20whitelist /var/run 21whitelist /var/run
diff --git a/etc/viking.profile b/etc/viking.profile
index fa87b915c..a5a01f544 100644
--- a/etc/viking.profile
+++ b/etc/viking.profile
@@ -7,12 +7,14 @@ include /etc/firejail/globals.local
7 7
8noblacklist ${HOME}/.viking 8noblacklist ${HOME}/.viking
9noblacklist ${HOME}/.viking-maps 9noblacklist ${HOME}/.viking-maps
10noblacklist ${DOCUMENTS}
10 11
11include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
12include /etc/firejail/disable-devel.inc 13include /etc/firejail/disable-devel.inc
13include /etc/firejail/disable-interpreters.inc 14include /etc/firejail/disable-interpreters.inc
14include /etc/firejail/disable-passwdmgr.inc 15include /etc/firejail/disable-passwdmgr.inc
15include /etc/firejail/disable-programs.inc 16include /etc/firejail/disable-programs.inc
17include /etc/firejail/disable-xdg.inc
16 18
17caps.drop all 19caps.drop all
18netfilter 20netfilter
diff --git a/etc/vlc.profile b/etc/vlc.profile
index bda027aaa..41f482d49 100644
--- a/etc/vlc.profile
+++ b/etc/vlc.profile
@@ -8,12 +8,15 @@ include /etc/firejail/globals.local
8noblacklist ${HOME}/.cache/vlc 8noblacklist ${HOME}/.cache/vlc
9noblacklist ${HOME}/.config/vlc 9noblacklist ${HOME}/.config/vlc
10noblacklist ${HOME}/.local/share/vlc 10noblacklist ${HOME}/.local/share/vlc
11noblacklist ${MUSIC}
12noblacklist ${VIDEOS}
11 13
12include /etc/firejail/disable-common.inc 14include /etc/firejail/disable-common.inc
13include /etc/firejail/disable-devel.inc 15include /etc/firejail/disable-devel.inc
14include /etc/firejail/disable-interpreters.inc 16include /etc/firejail/disable-interpreters.inc
15include /etc/firejail/disable-passwdmgr.inc 17include /etc/firejail/disable-passwdmgr.inc
16include /etc/firejail/disable-programs.inc 18include /etc/firejail/disable-programs.inc
19include /etc/firejail/disable-xdg.inc
17 20
18include /etc/firejail/whitelist-var-common.inc 21include /etc/firejail/whitelist-var-common.inc
19 22
diff --git a/etc/w3m.profile b/etc/w3m.profile
index bfc7874cf..22843ca54 100644
--- a/etc/w3m.profile
+++ b/etc/w3m.profile
@@ -14,6 +14,7 @@ include /etc/firejail/disable-devel.inc
14include /etc/firejail/disable-interpreters.inc 14include /etc/firejail/disable-interpreters.inc
15include /etc/firejail/disable-passwdmgr.inc 15include /etc/firejail/disable-passwdmgr.inc
16include /etc/firejail/disable-programs.inc 16include /etc/firejail/disable-programs.inc
17include /etc/firejail/disable-xdg.inc
17 18
18caps.drop all 19caps.drop all
19netfilter 20netfilter
diff --git a/etc/wireshark.profile b/etc/wireshark.profile
index 8ab672279..2b597ba35 100644
--- a/etc/wireshark.profile
+++ b/etc/wireshark.profile
@@ -7,6 +7,7 @@ include /etc/firejail/globals.local
7 7
8noblacklist ${HOME}/.config/wireshark 8noblacklist ${HOME}/.config/wireshark
9noblacklist ${HOME}/.wireshark 9noblacklist ${HOME}/.wireshark
10noblacklist ${DOCUMENTS}
10 11
11# Wireshark can use Lua for scripting 12# Wireshark can use Lua for scripting
12noblacklist ${PATH}/lua* 13noblacklist ${PATH}/lua*
@@ -19,6 +20,7 @@ include /etc/firejail/disable-devel.inc
19include /etc/firejail/disable-interpreters.inc 20include /etc/firejail/disable-interpreters.inc
20include /etc/firejail/disable-passwdmgr.inc 21include /etc/firejail/disable-passwdmgr.inc
21include /etc/firejail/disable-programs.inc 22include /etc/firejail/disable-programs.inc
23include /etc/firejail/disable-xdg.inc
22 24
23include /etc/firejail/whitelist-var-common.inc 25include /etc/firejail/whitelist-var-common.inc
24 26
diff --git a/etc/xcalc.profile b/etc/xcalc.profile
index 9e68ab17d..dd7c66523 100644
--- a/etc/xcalc.profile
+++ b/etc/xcalc.profile
@@ -10,6 +10,7 @@ include /etc/firejail/disable-devel.inc
10include /etc/firejail/disable-interpreters.inc 10include /etc/firejail/disable-interpreters.inc
11include /etc/firejail/disable-passwdmgr.inc 11include /etc/firejail/disable-passwdmgr.inc
12include /etc/firejail/disable-programs.inc 12include /etc/firejail/disable-programs.inc
13include /etc/firejail/disable-xdg.inc
13 14
14include /etc/firejail/whitelist-var-common.inc 15include /etc/firejail/whitelist-var-common.inc
15 16
diff --git a/etc/xmr-stak.profile b/etc/xmr-stak.profile
index ec98d8557..7a445f6a5 100644
--- a/etc/xmr-stak.profile
+++ b/etc/xmr-stak.profile
@@ -13,6 +13,7 @@ include /etc/firejail/disable-devel.inc
13include /etc/firejail/disable-interpreters.inc 13include /etc/firejail/disable-interpreters.inc
14include /etc/firejail/disable-passwdmgr.inc 14include /etc/firejail/disable-passwdmgr.inc
15include /etc/firejail/disable-programs.inc 15include /etc/firejail/disable-programs.inc
16include /etc/firejail/disable-xdg.inc
16 17
17mkdir ${HOME}/.xmr-stak 18mkdir ${HOME}/.xmr-stak
18include /etc/firejail/whitelist-var-common.inc 19include /etc/firejail/whitelist-var-common.inc
diff --git a/etc/xpdf.profile b/etc/xpdf.profile
index e61e9f5a8..b689ccb25 100644
--- a/etc/xpdf.profile
+++ b/etc/xpdf.profile
@@ -6,12 +6,14 @@ include /etc/firejail/xpdf.local
6include /etc/firejail/globals.local 6include /etc/firejail/globals.local
7 7
8noblacklist ${HOME}/.xpdfrc 8noblacklist ${HOME}/.xpdfrc
9noblacklist ${DOCUMENTS}
9 10
10include /etc/firejail/disable-common.inc 11include /etc/firejail/disable-common.inc
11include /etc/firejail/disable-devel.inc 12include /etc/firejail/disable-devel.inc
12include /etc/firejail/disable-interpreters.inc 13include /etc/firejail/disable-interpreters.inc
13include /etc/firejail/disable-passwdmgr.inc 14include /etc/firejail/disable-passwdmgr.inc
14include /etc/firejail/disable-programs.inc 15include /etc/firejail/disable-programs.inc
16include /etc/firejail/disable-xdg.inc
15 17
16include /etc/firejail/whitelist-var-common.inc 18include /etc/firejail/whitelist-var-common.inc
17 19
diff --git a/etc/youtube-dl.profile b/etc/youtube-dl.profile
index 965517293..fcb0a8a52 100644
--- a/etc/youtube-dl.profile
+++ b/etc/youtube-dl.profile
@@ -7,6 +7,8 @@ include /etc/firejail/youtube-dl.local
7include /etc/firejail/globals.local 7include /etc/firejail/globals.local
8 8
9noblacklist ${HOME}/.netrc 9noblacklist ${HOME}/.netrc
10noblacklist ${MUSIC}
11noblacklist ${VIDEOS}
10 12
11# Allow python (blacklisted by disable-interpreters.inc) 13# Allow python (blacklisted by disable-interpreters.inc)
12noblacklist ${PATH}/python2* 14noblacklist ${PATH}/python2*
@@ -19,6 +21,7 @@ include /etc/firejail/disable-devel.inc
19include /etc/firejail/disable-interpreters.inc 21include /etc/firejail/disable-interpreters.inc
20include /etc/firejail/disable-passwdmgr.inc 22include /etc/firejail/disable-passwdmgr.inc
21include /etc/firejail/disable-programs.inc 23include /etc/firejail/disable-programs.inc
24include /etc/firejail/disable-xdg.inc
22 25
23include /etc/firejail/whitelist-var-common.inc 26include /etc/firejail/whitelist-var-common.inc
24 27
diff --git a/etc/zathura.profile b/etc/zathura.profile
index 6cdbbe99b..baeca8d19 100644
--- a/etc/zathura.profile
+++ b/etc/zathura.profile
@@ -7,12 +7,14 @@ include /etc/firejail/globals.local
7 7
8noblacklist ${HOME}/.config/zathura 8noblacklist ${HOME}/.config/zathura
9noblacklist ${HOME}/.local/share/zathura 9noblacklist ${HOME}/.local/share/zathura
10noblacklist ${DOCUMENTS}
10 11
11include /etc/firejail/disable-common.inc 12include /etc/firejail/disable-common.inc
12include /etc/firejail/disable-devel.inc 13include /etc/firejail/disable-devel.inc
13include /etc/firejail/disable-interpreters.inc 14include /etc/firejail/disable-interpreters.inc
14include /etc/firejail/disable-passwdmgr.inc 15include /etc/firejail/disable-passwdmgr.inc
15include /etc/firejail/disable-programs.inc 16include /etc/firejail/disable-programs.inc
17include /etc/firejail/disable-xdg.inc
16 18
17caps.drop all 19caps.drop all
18machine-id 20machine-id