aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
-rw-r--r--etc/7z.profile21
-rw-r--r--etc/atool.profile4
-rw-r--r--etc/bibletime.profile4
-rw-r--r--etc/cpio.profile4
-rw-r--r--etc/curl.profile4
-rw-r--r--etc/dnscrypt-proxy.profile4
-rw-r--r--etc/dnsmasq.profile4
-rw-r--r--etc/elinks.profile4
-rw-r--r--etc/exiftool.profile4
-rw-r--r--etc/franz.profile5
-rw-r--r--etc/git.profile4
-rw-r--r--etc/google-play-music-desktop-player.profile9
-rw-r--r--etc/gpg-agent.profile4
-rw-r--r--etc/gpg.profile4
-rw-r--r--etc/links.profile4
-rw-r--r--etc/mutt.profile4
-rw-r--r--etc/natron.profile5
-rw-r--r--etc/nyx.profile7
-rw-r--r--etc/server.profile4
-rw-r--r--etc/signal-desktop.profile5
-rw-r--r--etc/skypeforlinux.profile7
-rw-r--r--etc/spotify.profile4
-rw-r--r--etc/ssh-agent.profile4
-rw-r--r--etc/tar.profile17
-rw-r--r--etc/terasology.profile5
-rw-r--r--etc/unbound.profile4
-rw-r--r--etc/unrar.profile21
-rw-r--r--etc/unzip.profile28
-rw-r--r--etc/uudeview.profile21
-rw-r--r--etc/viewnior.profile4
-rw-r--r--etc/w3m.profile4
-rw-r--r--etc/wget.profile4
-rw-r--r--etc/xiphos.profile6
-rw-r--r--etc/xzdec.profile21
34 files changed, 163 insertions, 95 deletions
diff --git a/etc/7z.profile b/etc/7z.profile
index 44ab377b3..ee2b493f8 100644
--- a/etc/7z.profile
+++ b/etc/7z.profile
@@ -4,23 +4,34 @@ quiet
4# Persistent local customizations 4# Persistent local customizations
5include 7z.local 5include 7z.local
6# Persistent global definitions 6# Persistent global definitions
7# added by included profile 7include globals.local
8#include globals.local
9 8
10blacklist /tmp/.X11-unix 9blacklist /tmp/.X11-unix
11 10
12ignore noroot 11include disable-common.inc
12include disable-devel.inc
13include disable-exec.inc
14include disable-interpreters.inc
15include disable-passwdmgr.inc
16include disable-programs.inc
17
18caps.drop all
19ipc-namespace
20machine-id
13net none 21net none
14no3d 22no3d
15nodbus 23nodbus
16nodvd 24nodvd
25#nogroups
26nonewprivs
27#noroot
17nosound 28nosound
18notv 29notv
19nou2f 30nou2f
20novideo 31novideo
32protocol unix
33seccomp
21shell none 34shell none
22tracelog 35tracelog
23 36
24private-dev 37private-dev
25
26include default.profile
diff --git a/etc/atool.profile b/etc/atool.profile
index 4ea3c02dc..3df32baac 100644
--- a/etc/atool.profile
+++ b/etc/atool.profile
@@ -7,11 +7,11 @@ include atool.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10blacklist /tmp/.X11-unix
11
12# Allow perl (blacklisted by disable-interpreters.inc) 10# Allow perl (blacklisted by disable-interpreters.inc)
13include allow-perl.inc 11include allow-perl.inc
14 12
13blacklist /tmp/.X11-unix
14
15include disable-common.inc 15include disable-common.inc
16# include disable-devel.inc 16# include disable-devel.inc
17include disable-exec.inc 17include disable-exec.inc
diff --git a/etc/bibletime.profile b/etc/bibletime.profile
index c41aafd47..4f1b05c88 100644
--- a/etc/bibletime.profile
+++ b/etc/bibletime.profile
@@ -6,12 +6,12 @@ include bibletime.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9blacklist ${HOME}/.bashrc
10
11noblacklist ${HOME}/.bibletime 9noblacklist ${HOME}/.bibletime
12noblacklist ${HOME}/.sword 10noblacklist ${HOME}/.sword
13noblacklist ${HOME}/.local/share/bibletime 11noblacklist ${HOME}/.local/share/bibletime
14 12
13blacklist ${HOME}/.bashrc
14
15include disable-common.inc 15include disable-common.inc
16include disable-devel.inc 16include disable-devel.inc
17include disable-exec.inc 17include disable-exec.inc
diff --git a/etc/cpio.profile b/etc/cpio.profile
index b6f7e7f9f..0bb45f5cd 100644
--- a/etc/cpio.profile
+++ b/etc/cpio.profile
@@ -7,11 +7,11 @@ include cpio.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10blacklist /tmp/.X11-unix
11
12noblacklist /sbin 10noblacklist /sbin
13noblacklist /usr/sbin 11noblacklist /usr/sbin
14 12
13blacklist /tmp/.X11-unix
14
15include disable-common.inc 15include disable-common.inc
16# include disable-devel.inc 16# include disable-devel.inc
17include disable-exec.inc 17include disable-exec.inc
diff --git a/etc/curl.profile b/etc/curl.profile
index 2703c6fe8..b8b91d278 100644
--- a/etc/curl.profile
+++ b/etc/curl.profile
@@ -7,10 +7,10 @@ include curl.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10blacklist /tmp/.X11-unix
11
12noblacklist ${HOME}/.curlrc 10noblacklist ${HOME}/.curlrc
13 11
12blacklist /tmp/.X11-unix
13
14include disable-common.inc 14include disable-common.inc
15include disable-exec.inc 15include disable-exec.inc
16include disable-passwdmgr.inc 16include disable-passwdmgr.inc
diff --git a/etc/dnscrypt-proxy.profile b/etc/dnscrypt-proxy.profile
index 0dc0cc793..ffced747b 100644
--- a/etc/dnscrypt-proxy.profile
+++ b/etc/dnscrypt-proxy.profile
@@ -6,11 +6,11 @@ include dnscrypt-proxy.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9blacklist /tmp/.X11-unix
10
11noblacklist /sbin 9noblacklist /sbin
12noblacklist /usr/sbin 10noblacklist /usr/sbin
13 11
12blacklist /tmp/.X11-unix
13
14include disable-common.inc 14include disable-common.inc
15include disable-devel.inc 15include disable-devel.inc
16include disable-interpreters.inc 16include disable-interpreters.inc
diff --git a/etc/dnsmasq.profile b/etc/dnsmasq.profile
index bb41b71d1..daf4795c3 100644
--- a/etc/dnsmasq.profile
+++ b/etc/dnsmasq.profile
@@ -6,11 +6,11 @@ include dnsmasq.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9blacklist /tmp/.X11-unix
10
11noblacklist /sbin 9noblacklist /sbin
12noblacklist /usr/sbin 10noblacklist /usr/sbin
13 11
12blacklist /tmp/.X11-unix
13
14include disable-common.inc 14include disable-common.inc
15include disable-devel.inc 15include disable-devel.inc
16include disable-interpreters.inc 16include disable-interpreters.inc
diff --git a/etc/elinks.profile b/etc/elinks.profile
index 842a0db04..980fa7617 100644
--- a/etc/elinks.profile
+++ b/etc/elinks.profile
@@ -6,10 +6,10 @@ include elinks.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9blacklist /tmp/.X11-unix
10
11noblacklist ${HOME}/.elinks 9noblacklist ${HOME}/.elinks
12 10
11blacklist /tmp/.X11-unix
12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
15include disable-interpreters.inc 15include disable-interpreters.inc
diff --git a/etc/exiftool.profile b/etc/exiftool.profile
index b33d73233..52e090b89 100644
--- a/etc/exiftool.profile
+++ b/etc/exiftool.profile
@@ -6,11 +6,11 @@ include exiftool.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9blacklist /tmp/.X11-unix
10
11# Allow perl (blacklisted by disable-interpreters.inc) 9# Allow perl (blacklisted by disable-interpreters.inc)
12include allow-perl.inc 10include allow-perl.inc
13 11
12blacklist /tmp/.X11-unix
13
14include disable-common.inc 14include disable-common.inc
15include disable-devel.inc 15include disable-devel.inc
16include disable-exec.inc 16include disable-exec.inc
diff --git a/etc/franz.profile b/etc/franz.profile
index d6445ff8e..e917e5517 100644
--- a/etc/franz.profile
+++ b/etc/franz.profile
@@ -5,6 +5,8 @@ include franz.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8ignore noexec /tmp
9
8noblacklist ${HOME}/.cache/Franz 10noblacklist ${HOME}/.cache/Franz
9noblacklist ${HOME}/.config/Franz 11noblacklist ${HOME}/.config/Franz
10noblacklist ${HOME}/.pki 12noblacklist ${HOME}/.pki
@@ -12,6 +14,7 @@ noblacklist ${HOME}/.local/share/pki
12 14
13include disable-common.inc 15include disable-common.inc
14include disable-devel.inc 16include disable-devel.inc
17include disable-exec.inc
15include disable-interpreters.inc 18include disable-interpreters.inc
16include disable-programs.inc 19include disable-programs.inc
17 20
@@ -41,5 +44,3 @@ shell none
41disable-mnt 44disable-mnt
42private-dev 45private-dev
43private-tmp 46private-tmp
44
45noexec ${HOME}
diff --git a/etc/git.profile b/etc/git.profile
index 0eb69faed..f7c812e65 100644
--- a/etc/git.profile
+++ b/etc/git.profile
@@ -7,8 +7,6 @@ include git.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10blacklist /tmp/.X11-unix
11
12noblacklist ${HOME}/.config/git 10noblacklist ${HOME}/.config/git
13noblacklist ${HOME}/.config/nano 11noblacklist ${HOME}/.config/nano
14noblacklist ${HOME}/.emacs 12noblacklist ${HOME}/.emacs
@@ -22,6 +20,8 @@ noblacklist ${HOME}/.ssh
22noblacklist ${HOME}/.vim 20noblacklist ${HOME}/.vim
23noblacklist ${HOME}/.viminfo 21noblacklist ${HOME}/.viminfo
24 22
23blacklist /tmp/.X11-unix
24
25include disable-common.inc 25include disable-common.inc
26include disable-exec.inc 26include disable-exec.inc
27include disable-passwdmgr.inc 27include disable-passwdmgr.inc
diff --git a/etc/google-play-music-desktop-player.profile b/etc/google-play-music-desktop-player.profile
index 4932c9e42..daa385234 100644
--- a/etc/google-play-music-desktop-player.profile
+++ b/etc/google-play-music-desktop-player.profile
@@ -5,14 +5,19 @@ include google-play-music-desktop-player.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8# noexec /tmp breaks mpris support
9ignore noexec /tmp
10
8noblacklist ${HOME}/.config/Google Play Music Desktop Player 11noblacklist ${HOME}/.config/Google Play Music Desktop Player
9 12
10include disable-common.inc 13include disable-common.inc
11include disable-devel.inc 14include disable-devel.inc
15include disable-exec.inc
12include disable-interpreters.inc 16include disable-interpreters.inc
13include disable-passwdmgr.inc 17include disable-passwdmgr.inc
14include disable-programs.inc 18include disable-programs.inc
15 19
20mkdir ${HOME}/.config/Google Play Music Desktop Player
16# whitelist ${HOME}/.config/pulse 21# whitelist ${HOME}/.config/pulse
17# whitelist ${HOME}/.pulse 22# whitelist ${HOME}/.pulse
18whitelist ${HOME}/.config/Google Play Music Desktop Player 23whitelist ${HOME}/.config/Google Play Music Desktop Player
@@ -35,7 +40,3 @@ shell none
35disable-mnt 40disable-mnt
36private-dev 41private-dev
37private-tmp 42private-tmp
38
39noexec ${HOME}
40# noexec /tmp breaks mpris support
41#noexec /tmp
diff --git a/etc/gpg-agent.profile b/etc/gpg-agent.profile
index 7181837d5..61b485df5 100644
--- a/etc/gpg-agent.profile
+++ b/etc/gpg-agent.profile
@@ -6,10 +6,10 @@ include gpg-agent.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9blacklist /tmp/.X11-unix
10
11noblacklist ${HOME}/.gnupg 9noblacklist ${HOME}/.gnupg
12 10
11blacklist /tmp/.X11-unix
12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
15include disable-interpreters.inc 15include disable-interpreters.inc
diff --git a/etc/gpg.profile b/etc/gpg.profile
index 51662b59c..99ad1b888 100644
--- a/etc/gpg.profile
+++ b/etc/gpg.profile
@@ -6,10 +6,10 @@ include gpg.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9blacklist /tmp/.X11-unix
10
11noblacklist ${HOME}/.gnupg 9noblacklist ${HOME}/.gnupg
12 10
11blacklist /tmp/.X11-unix
12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
15include disable-interpreters.inc 15include disable-interpreters.inc
diff --git a/etc/links.profile b/etc/links.profile
index 99b445fe0..bd0b0cc92 100644
--- a/etc/links.profile
+++ b/etc/links.profile
@@ -6,10 +6,10 @@ include links.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9blacklist /tmp/.X11-unix
10
11noblacklist ${HOME}/.links 9noblacklist ${HOME}/.links
12 10
11blacklist /tmp/.X11-unix
12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
15include disable-exec.inc 15include disable-exec.inc
diff --git a/etc/mutt.profile b/etc/mutt.profile
index cc3a323e0..419e17e95 100644
--- a/etc/mutt.profile
+++ b/etc/mutt.profile
@@ -6,8 +6,6 @@ include mutt.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9blacklist /tmp/.X11-unix
10
11noblacklist /var/mail 9noblacklist /var/mail
12noblacklist /var/spool/mail 10noblacklist /var/spool/mail
13noblacklist ${HOME}/.Mail 11noblacklist ${HOME}/.Mail
@@ -34,6 +32,8 @@ noblacklist ${HOME}/mail
34noblacklist ${HOME}/postponed 32noblacklist ${HOME}/postponed
35noblacklist ${HOME}/sent 33noblacklist ${HOME}/sent
36 34
35blacklist /tmp/.X11-unix
36
37include disable-common.inc 37include disable-common.inc
38include disable-devel.inc 38include disable-devel.inc
39include disable-interpreters.inc 39include disable-interpreters.inc
diff --git a/etc/natron.profile b/etc/natron.profile
index 329f79f9b..7ad217b72 100644
--- a/etc/natron.profile
+++ b/etc/natron.profile
@@ -8,7 +8,6 @@ include globals.local
8noblacklist ${HOME}/.Natron 8noblacklist ${HOME}/.Natron
9noblacklist ${HOME}/.cache/INRIA/Natron 9noblacklist ${HOME}/.cache/INRIA/Natron
10noblacklist ${HOME}/.config/INRIA 10noblacklist ${HOME}/.config/INRIA
11noblacklist /opt/natron
12 11
13# Allow python (blacklisted by disable-interpreters.inc) 12# Allow python (blacklisted by disable-interpreters.inc)
14include allow-python2.inc 13include allow-python2.inc
@@ -29,9 +28,9 @@ nogroups
29nonewprivs 28nonewprivs
30noroot 29noroot
31notv 30notv
32protocol unix,inet,inet6 31nou2f
32protocol unix
33seccomp 33seccomp
34shell none 34shell none
35 35
36private-bin natron,Natron,NatronRenderer 36private-bin natron,Natron,NatronRenderer
37
diff --git a/etc/nyx.profile b/etc/nyx.profile
index f50014a4d..1ea33ac4d 100644
--- a/etc/nyx.profile
+++ b/etc/nyx.profile
@@ -11,8 +11,6 @@ include allow-python2.inc
11include allow-python3.inc 11include allow-python3.inc
12 12
13noblacklist ${HOME}/.nyx 13noblacklist ${HOME}/.nyx
14mkdir ${HOME}/.nyx
15whitelist ${HOME}/.nyx
16 14
17include disable-common.inc 15include disable-common.inc
18include disable-devel.inc 16include disable-devel.inc
@@ -22,6 +20,11 @@ include disable-passwdmgr.inc
22include disable-programs.inc 20include disable-programs.inc
23include disable-xdg.inc 21include disable-xdg.inc
24 22
23mkdir ${HOME}/.nyx
24whitelist ${HOME}/.nyx
25include whitelist-common.inc
26include whitelist-var-common.inc
27
25caps.drop all 28caps.drop all
26netfilter 29netfilter
27no3d 30no3d
diff --git a/etc/server.profile b/etc/server.profile
index 686268a18..6e077ff84 100644
--- a/etc/server.profile
+++ b/etc/server.profile
@@ -9,12 +9,12 @@ include globals.local
9# it allows /sbin and /usr/sbin directories - this is where servers are installed 9# it allows /sbin and /usr/sbin directories - this is where servers are installed
10# depending on your usage, you can enable some of the commands below: 10# depending on your usage, you can enable some of the commands below:
11 11
12blacklist /tmp/.X11-unix
13
14noblacklist /sbin 12noblacklist /sbin
15noblacklist /usr/sbin 13noblacklist /usr/sbin
16# noblacklist /var/opt 14# noblacklist /var/opt
17 15
16blacklist /tmp/.X11-unix
17
18include disable-common.inc 18include disable-common.inc
19# include disable-devel.inc 19# include disable-devel.inc
20# include disable-exec.inc 20# include disable-exec.inc
diff --git a/etc/signal-desktop.profile b/etc/signal-desktop.profile
index 008cd218e..04696a918 100644
--- a/etc/signal-desktop.profile
+++ b/etc/signal-desktop.profile
@@ -5,10 +5,13 @@ include signal-desktop.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8ignore noexec /tmp
9
8noblacklist ${HOME}/.config/Signal 10noblacklist ${HOME}/.config/Signal
9 11
10include disable-common.inc 12include disable-common.inc
11include disable-devel.inc 13include disable-devel.inc
14include disable-exec.inc
12include disable-interpreters.inc 15include disable-interpreters.inc
13include disable-programs.inc 16include disable-programs.inc
14include disable-passwdmgr.inc 17include disable-passwdmgr.inc
@@ -34,5 +37,3 @@ shell none
34disable-mnt 37disable-mnt
35private-dev 38private-dev
36private-tmp 39private-tmp
37
38noexec ${HOME}
diff --git a/etc/skypeforlinux.profile b/etc/skypeforlinux.profile
index ad200be37..eae7dada0 100644
--- a/etc/skypeforlinux.profile
+++ b/etc/skypeforlinux.profile
@@ -5,10 +5,14 @@ include skypeforlinux.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8# breaks Skype
9ignore noexec /tmp
10
8noblacklist ${HOME}/.config/skypeforlinux 11noblacklist ${HOME}/.config/skypeforlinux
9 12
10include disable-common.inc 13include disable-common.inc
11include disable-devel.inc 14include disable-devel.inc
15include disable-exec.inc
12include disable-interpreters.inc 16include disable-interpreters.inc
13include disable-passwdmgr.inc 17include disable-passwdmgr.inc
14include disable-programs.inc 18include disable-programs.inc
@@ -28,6 +32,3 @@ disable-mnt
28private-cache 32private-cache
29# private-dev - needs /dev/disk 33# private-dev - needs /dev/disk
30private-tmp 34private-tmp
31
32noexec ${HOME}
33# noexec /tmp - breaks Skype
diff --git a/etc/spotify.profile b/etc/spotify.profile
index 00c2aabe2..2d5c4a48f 100644
--- a/etc/spotify.profile
+++ b/etc/spotify.profile
@@ -5,12 +5,12 @@ include spotify.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8blacklist ${HOME}/.bashrc
9
10noblacklist ${HOME}/.cache/spotify 8noblacklist ${HOME}/.cache/spotify
11noblacklist ${HOME}/.config/spotify 9noblacklist ${HOME}/.config/spotify
12noblacklist ${HOME}/.local/share/spotify 10noblacklist ${HOME}/.local/share/spotify
13 11
12blacklist ${HOME}/.bashrc
13
14include disable-common.inc 14include disable-common.inc
15include disable-devel.inc 15include disable-devel.inc
16include disable-exec.inc 16include disable-exec.inc
diff --git a/etc/ssh-agent.profile b/etc/ssh-agent.profile
index 8aafca8aa..9af747b62 100644
--- a/etc/ssh-agent.profile
+++ b/etc/ssh-agent.profile
@@ -6,12 +6,12 @@ include ssh-agent.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9blacklist /tmp/.X11-unix
10
11noblacklist /etc/ssh 9noblacklist /etc/ssh
12noblacklist /tmp/ssh-* 10noblacklist /tmp/ssh-*
13noblacklist ${HOME}/.ssh 11noblacklist ${HOME}/.ssh
14 12
13blacklist /tmp/.X11-unix
14
15include disable-common.inc 15include disable-common.inc
16include disable-passwdmgr.inc 16include disable-passwdmgr.inc
17include disable-programs.inc 17include disable-programs.inc
diff --git a/etc/tar.profile b/etc/tar.profile
index 14fc00d21..b6a874217 100644
--- a/etc/tar.profile
+++ b/etc/tar.profile
@@ -5,17 +5,19 @@ quiet
5# Persistent local customizations 5# Persistent local customizations
6include tar.local 6include tar.local
7# Persistent global definitions 7# Persistent global definitions
8# added by included profile 8include globals.local
9#include globals.local
10 9
11blacklist /tmp/.X11-unix 10blacklist /tmp/.X11-unix
12 11
12include disable-common.inc
13include disable-devel.inc
13include disable-exec.inc 14include disable-exec.inc
14include disable-interpreters.inc 15include disable-interpreters.inc
15 16include disable-passwdmgr.inc
16ignore noroot 17include disable-programs.inc
17 18
18apparmor 19apparmor
20caps.drop all
19hostname tar 21hostname tar
20ipc-namespace 22ipc-namespace
21machine-id 23machine-id
@@ -24,10 +26,14 @@ no3d
24nodbus 26nodbus
25nodvd 27nodvd
26nogroups 28nogroups
29nonewprivs
30#noroot
27nosound 31nosound
28notv 32notv
29nou2f 33nou2f
30novideo 34novideo
35protocol unix
36seccomp
31shell none 37shell none
32tracelog 38tracelog
33 39
@@ -39,8 +45,5 @@ private-etc alternatives,passwd,group,localtime
39private-lib libfakeroot 45private-lib libfakeroot
40 46
41memory-deny-write-execute 47memory-deny-write-execute
42
43# Debian based distributions need this for 'dpkg --unpack' (incl. synaptic) 48# Debian based distributions need this for 'dpkg --unpack' (incl. synaptic)
44writable-var 49writable-var
45
46include default.profile
diff --git a/etc/terasology.profile b/etc/terasology.profile
index b01b4fdb3..2a7212395 100644
--- a/etc/terasology.profile
+++ b/etc/terasology.profile
@@ -5,6 +5,8 @@ include terasology.local
5# Persistent global definitions 5# Persistent global definitions
6include globals.local 6include globals.local
7 7
8ignore noexec /tmp
9
8noblacklist ${HOME}/.java 10noblacklist ${HOME}/.java
9noblacklist ${HOME}/.local/share/terasology 11noblacklist ${HOME}/.local/share/terasology
10 12
@@ -13,6 +15,7 @@ include allow-java.inc
13 15
14include disable-common.inc 16include disable-common.inc
15include disable-devel.inc 17include disable-devel.inc
18include disable-exec.inc
16include disable-interpreters.inc 19include disable-interpreters.inc
17include disable-passwdmgr.inc 20include disable-passwdmgr.inc
18include disable-programs.inc 21include disable-programs.inc
@@ -43,5 +46,3 @@ disable-mnt
43private-dev 46private-dev
44private-etc alternatives,asound.conf,ca-certificates,dbus-1,drirc,fonts,group,gtk-2.0,gtk-3.0,host.conf,hostname,hosts,ld.so.cache,ld.so.preload,localtime,lsb-release,machine-id,mime.types,passwd,pulse,resolv.conf,ssl,java-8-openjdk,java-7-openjdk,pki,crypto-policies 47private-etc alternatives,asound.conf,ca-certificates,dbus-1,drirc,fonts,group,gtk-2.0,gtk-3.0,host.conf,hostname,hosts,ld.so.cache,ld.so.preload,localtime,lsb-release,machine-id,mime.types,passwd,pulse,resolv.conf,ssl,java-8-openjdk,java-7-openjdk,pki,crypto-policies
45private-tmp 48private-tmp
46
47noexec ${HOME}
diff --git a/etc/unbound.profile b/etc/unbound.profile
index 6e4b5ed1c..8e7a4a8a8 100644
--- a/etc/unbound.profile
+++ b/etc/unbound.profile
@@ -6,11 +6,11 @@ include unbound.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9blacklist /tmp/.X11-unix
10
11noblacklist /sbin 9noblacklist /sbin
12noblacklist /usr/sbin 10noblacklist /usr/sbin
13 11
12blacklist /tmp/.X11-unix
13
14include disable-common.inc 14include disable-common.inc
15include disable-devel.inc 15include disable-devel.inc
16include disable-interpreters.inc 16include disable-interpreters.inc
diff --git a/etc/unrar.profile b/etc/unrar.profile
index 7fe37f061..5b55f30d2 100644
--- a/etc/unrar.profile
+++ b/etc/unrar.profile
@@ -5,21 +5,34 @@ quiet
5# Persistent local customizations 5# Persistent local customizations
6include unrar.local 6include unrar.local
7# Persistent global definitions 7# Persistent global definitions
8# added by included profile 8include globals.local
9#include globals.local
10 9
11blacklist /tmp/.X11-unix 10blacklist /tmp/.X11-unix
12 11
12include disable-common.inc
13include disable-devel.inc
14include disable-exec.inc
15include disable-interpreters.inc
16include disable-passwdmgr.inc
17include disable-programs.inc
18
19caps.drop all
13hostname unrar 20hostname unrar
14ignore noroot 21ipc-namespace
22machine-id
15net none 23net none
16no3d 24no3d
17nodbus 25nodbus
18nodvd 26nodvd
27#nogroups
28nonewprivs
29#noroot
19nosound 30nosound
20notv 31notv
21nou2f 32nou2f
22novideo 33novideo
34protocol unix
35seccomp
23shell none 36shell none
24tracelog 37tracelog
25 38
@@ -27,5 +40,3 @@ private-bin unrar
27private-dev 40private-dev
28private-etc alternatives,passwd,group,localtime 41private-etc alternatives,passwd,group,localtime
29private-tmp 42private-tmp
30
31include default.profile
diff --git a/etc/unzip.profile b/etc/unzip.profile
index be6b6c321..deda8fe64 100644
--- a/etc/unzip.profile
+++ b/etc/unzip.profile
@@ -5,29 +5,41 @@ quiet
5# Persistent local customizations 5# Persistent local customizations
6include unzip.local 6include unzip.local
7# Persistent global definitions 7# Persistent global definitions
8# added by included profile 8include globals.local
9#include globals.local 9
10# GNOME Shell integration (chrome-gnome-shell)
11noblacklist ${HOME}/.local/share/gnome-shell
10 12
11blacklist /tmp/.X11-unix 13blacklist /tmp/.X11-unix
12 14
15include disable-common.inc
16include disable-devel.inc
17include disable-exec.inc
18include disable-interpreters.inc
19include disable-passwdmgr.inc
20include disable-programs.inc
21
22caps.drop all
23ipc-namespace
24machine-id
13hostname unzip 25hostname unzip
14ignore noroot
15net none 26net none
16no3d 27no3d
17nodbus 28nodbus
18nodvd 29nodvd
30#nogroups
31nonewprivs
32noroot
19nosound 33nosound
20notv 34notv
21nou2f 35nou2f
22novideo 36novideo
37protocol unix
38seccomp
23shell none 39shell none
24tracelog 40tracelog
25 41
26private-bin unzip 42private-bin unzip
43private-cache
27private-dev 44private-dev
28private-etc alternatives,passwd,group,localtime 45private-etc alternatives,passwd,group,localtime
29
30# GNOME Shell integration (chrome-gnome-shell)
31noblacklist ${HOME}/.local/share/gnome-shell
32
33include default.profile
diff --git a/etc/uudeview.profile b/etc/uudeview.profile
index 859656fa5..9b7c4f5ba 100644
--- a/etc/uudeview.profile
+++ b/etc/uudeview.profile
@@ -5,18 +5,31 @@ quiet
5# Persistent local customizations 5# Persistent local customizations
6include uudeview.local 6include uudeview.local
7# Persistent global definitions 7# Persistent global definitions
8# added by included profile 8include globals.local
9#include globals.local
10 9
10include disable-common.inc
11include disable-devel.inc
12include disable-exec.inc
13include disable-interpreters.inc
14include disable-passwdmgr.inc
15include disable-programs.inc
16
17caps.drop all
18ipc-namespace
19machine-id
11hostname uudeview 20hostname uudeview
12ignore noroot
13net none 21net none
14nodbus 22nodbus
15nodvd 23nodvd
24#nogroups
25nonewprivs
26#noroot
16nosound 27nosound
17notv 28notv
18nou2f 29nou2f
19novideo 30novideo
31protocol unix
32seccomp
20shell none 33shell none
21tracelog 34tracelog
22 35
@@ -24,5 +37,3 @@ private-bin uudeview
24private-cache 37private-cache
25private-dev 38private-dev
26private-etc alternatives,ld.so.preload 39private-etc alternatives,ld.so.preload
27
28include default.profile
diff --git a/etc/viewnior.profile b/etc/viewnior.profile
index f9fb1cefe..943719e75 100644
--- a/etc/viewnior.profile
+++ b/etc/viewnior.profile
@@ -6,12 +6,12 @@ include viewnior.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9blacklist ${HOME}/.bashrc
10
11noblacklist ${HOME}/.Steam 9noblacklist ${HOME}/.Steam
12noblacklist ${HOME}/.config/viewnior 10noblacklist ${HOME}/.config/viewnior
13noblacklist ${HOME}/.steam 11noblacklist ${HOME}/.steam
14 12
13blacklist ${HOME}/.bashrc
14
15include disable-common.inc 15include disable-common.inc
16include disable-devel.inc 16include disable-devel.inc
17include disable-exec.inc 17include disable-exec.inc
diff --git a/etc/w3m.profile b/etc/w3m.profile
index 143ac4f63..d577932e3 100644
--- a/etc/w3m.profile
+++ b/etc/w3m.profile
@@ -6,10 +6,10 @@ include w3m.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9blacklist /tmp/.X11-unix
10
11noblacklist ${HOME}/.w3m 9noblacklist ${HOME}/.w3m
12 10
11blacklist /tmp/.X11-unix
12
13include disable-common.inc 13include disable-common.inc
14include disable-devel.inc 14include disable-devel.inc
15include disable-interpreters.inc 15include disable-interpreters.inc
diff --git a/etc/wget.profile b/etc/wget.profile
index a7ef32e2c..ff10b2316 100644
--- a/etc/wget.profile
+++ b/etc/wget.profile
@@ -7,11 +7,11 @@ include wget.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10blacklist /tmp/.X11-unix
11
12noblacklist ${HOME}/.wget-hsts 10noblacklist ${HOME}/.wget-hsts
13noblacklist ${HOME}/.wgetrc 11noblacklist ${HOME}/.wgetrc
14 12
13blacklist /tmp/.X11-unix
14
15include disable-common.inc 15include disable-common.inc
16include disable-exec.inc 16include disable-exec.inc
17include disable-passwdmgr.inc 17include disable-passwdmgr.inc
diff --git a/etc/xiphos.profile b/etc/xiphos.profile
index 33056395e..043e513bd 100644
--- a/etc/xiphos.profile
+++ b/etc/xiphos.profile
@@ -6,11 +6,11 @@ include xiphos.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9blacklist ${HOME}/.bashrc
10
11noblacklist ${HOME}/.sword 9noblacklist ${HOME}/.sword
12noblacklist ${HOME}/.xiphos 10noblacklist ${HOME}/.xiphos
13 11
12blacklist ${HOME}/.bashrc
13
14include disable-common.inc 14include disable-common.inc
15include disable-devel.inc 15include disable-devel.inc
16include disable-exec.inc 16include disable-exec.inc
@@ -18,6 +18,8 @@ include disable-interpreters.inc
18include disable-passwdmgr.inc 18include disable-passwdmgr.inc
19include disable-programs.inc 19include disable-programs.inc
20 20
21mkdir ${HOME}/.sword
22mkdir ${HOME}/.xiphos
21whitelist ${HOME}/.sword 23whitelist ${HOME}/.sword
22whitelist ${HOME}/.xiphos 24whitelist ${HOME}/.xiphos
23include whitelist-common.inc 25include whitelist-common.inc
diff --git a/etc/xzdec.profile b/etc/xzdec.profile
index a1f265c1e..3adaa557c 100644
--- a/etc/xzdec.profile
+++ b/etc/xzdec.profile
@@ -5,23 +5,34 @@ quiet
5# Persistent local customizations 5# Persistent local customizations
6include xzdec.local 6include xzdec.local
7# Persistent global definitions 7# Persistent global definitions
8# added by included profile 8include globals.local
9#include globals.local
10 9
11blacklist /tmp/.X11-unix 10blacklist /tmp/.X11-unix
12 11
13ignore noroot 12include disable-common.inc
13include disable-devel.inc
14include disable-exec.inc
15include disable-interpreters.inc
16include disable-passwdmgr.inc
17include disable-programs.inc
18
19caps.drop all
20ipc-namespace
21machine-id
14net none 22net none
15no3d 23no3d
16nodbus 24nodbus
17nodvd 25nodvd
26#nogroups
27nonewprivs
28#noroot
18nosound 29nosound
19notv 30notv
20nou2f 31nou2f
21novideo 32novideo
33protocol unix
34seccomp
22shell none 35shell none
23tracelog 36tracelog
24 37
25private-dev 38private-dev
26
27include default.profile