aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
-rw-r--r--etc/inc/allow-common-devel.inc6
-rw-r--r--etc/inc/disable-common.inc10
-rw-r--r--etc/inc/disable-programs.inc30
-rw-r--r--etc/inc/whitelist-common.inc1
-rw-r--r--etc/profile-a-l/etr.profile4
-rw-r--r--etc/profile-a-l/frozen-bubble.profile5
-rw-r--r--etc/profile-a-l/gnome-chess.profile4
-rw-r--r--etc/profile-a-l/gnome-hexgl.profile2
-rw-r--r--etc/profile-m-z/megaglest.profile4
-rw-r--r--etc/profile-m-z/minetest.profile3
-rw-r--r--etc/profile-m-z/ostrichriders.profile2
-rw-r--r--etc/profile-m-z/pingus.profile10
-rw-r--r--etc/profile-m-z/scorched3d-wrapper.profile3
-rw-r--r--etc/profile-m-z/scorched3d.profile3
-rw-r--r--etc/profile-m-z/supertux2.profile5
-rw-r--r--etc/profile-m-z/torcs.profile4
-rw-r--r--etc/profile-m-z/transmission-gtk.profile1
17 files changed, 91 insertions, 6 deletions
diff --git a/etc/inc/allow-common-devel.inc b/etc/inc/allow-common-devel.inc
index 63174eda6..7cd087b14 100644
--- a/etc/inc/allow-common-devel.inc
+++ b/etc/inc/allow-common-devel.inc
@@ -12,10 +12,16 @@ noblacklist ${HOME}/.gradle
12noblacklist ${HOME}/.java 12noblacklist ${HOME}/.java
13 13
14# Python 14# Python
15noblacklist ${HOME}/.pylint.d
15noblacklist ${HOME}/.python-history 16noblacklist ${HOME}/.python-history
16noblacklist ${HOME}/.python_history 17noblacklist ${HOME}/.python_history
17noblacklist ${HOME}/.pythonhist 18noblacklist ${HOME}/.pythonhist
18 19
19# Rust 20# Rust
21noblacklist ${HOME}/.cargo/advisory-db
20noblacklist ${HOME}/.cargo/config 22noblacklist ${HOME}/.cargo/config
23noblacklist ${HOME}/.cargo/git
21noblacklist ${HOME}/.cargo/registry 24noblacklist ${HOME}/.cargo/registry
25noblacklist ${HOME}/.cargo/.crates.toml
26noblacklist ${HOME}/.cargo/.crates2.json
27noblacklist ${HOME}/.cargo/.package-cache
diff --git a/etc/inc/disable-common.inc b/etc/inc/disable-common.inc
index 92c6cd2a8..3fd3cc7b2 100644
--- a/etc/inc/disable-common.inc
+++ b/etc/inc/disable-common.inc
@@ -149,8 +149,9 @@ read-only ${HOME}/.config/dconf
149blacklist ${HOME}/.config/systemd 149blacklist ${HOME}/.config/systemd
150blacklist ${HOME}/.local/share/systemd 150blacklist ${HOME}/.local/share/systemd
151blacklist /var/lib/systemd 151blacklist /var/lib/systemd
152# blacklist /var/run/systemd 152blacklist ${PATH}/systemd-run
153# creates problems on Arch where /etc/resolv.conf is a symlink to /var/run/systemd/resolve/resolv.conf 153# creates problems on Arch where /etc/resolv.conf is a symlink to /var/run/systemd/resolve/resolv.conf
154#blacklist /var/run/systemd
154 155
155# openrc 156# openrc
156blacklist /etc/runlevels/ 157blacklist /etc/runlevels/
@@ -308,13 +309,17 @@ read-only ${HOME}/bin
308read-only ${HOME}/.bin 309read-only ${HOME}/.bin
309read-only ${HOME}/.local/bin 310read-only ${HOME}/.local/bin
310read-only ${HOME}/.cargo/bin 311read-only ${HOME}/.cargo/bin
311read-only ${HOME}/.cargo/env
312 312
313# Write-protection for desktop entries 313# Write-protection for desktop entries
314read-only ${HOME}/.config/menus 314read-only ${HOME}/.config/menus
315read-only ${HOME}/.gnome/apps 315read-only ${HOME}/.gnome/apps
316read-only ${HOME}/.local/share/applications 316read-only ${HOME}/.local/share/applications
317 317
318read-only ${HOME}/.config/mimeapps.list
319read-only ${HOME}/.config/user-dirs.dirs
320read-only ${HOME}/.config/user-dirs.locale
321read-only ${HOME}/.local/share/mime
322
318# Write-protection for thumbnailer dir 323# Write-protection for thumbnailer dir
319read-only ${HOME}/.local/share/thumbnailers 324read-only ${HOME}/.local/share/thumbnailers
320 325
@@ -451,6 +456,7 @@ blacklist /vmlinuz*
451blacklist /.snapshots 456blacklist /.snapshots
452 457
453# flatpak 458# flatpak
459blacklist ${HOME}/.cache/flatpak
454blacklist ${HOME}/.config/flatpak 460blacklist ${HOME}/.config/flatpak
455blacklist ${HOME}/.local/share/flatpak/app 461blacklist ${HOME}/.local/share/flatpak/app
456blacklist ${HOME}/.local/share/flatpak/appstream 462blacklist ${HOME}/.local/share/flatpak/appstream
diff --git a/etc/inc/disable-programs.inc b/etc/inc/disable-programs.inc
index 9e6af8785..89189b533 100644
--- a/etc/inc/disable-programs.inc
+++ b/etc/inc/disable-programs.inc
@@ -54,8 +54,13 @@ blacklist ${HOME}/.bibletime
54blacklist ${HOME}/.bitcoin 54blacklist ${HOME}/.bitcoin
55blacklist ${HOME}/.bogofilter 55blacklist ${HOME}/.bogofilter
56blacklist ${HOME}/.bzf 56blacklist ${HOME}/.bzf
57blacklist ${HOME}/.cargo/registry 57blacklist ${HOME}/.cargo/advisory-db
58blacklist ${HOME}/.cargo/config 58blacklist ${HOME}/.cargo/config
59blacklist ${HOME}/.cargo/git
60blacklist ${HOME}/.cargo/registry
61blacklist ${HOME}/.cargo/.crates.toml
62blacklist ${HOME}/.cargo/.crates2.json
63blacklist ${HOME}/.cargo/.package-cache
59blacklist ${HOME}/.claws-mail 64blacklist ${HOME}/.claws-mail
60blacklist ${HOME}/.cliqz 65blacklist ${HOME}/.cliqz
61blacklist ${HOME}/.clonk 66blacklist ${HOME}/.clonk
@@ -75,6 +80,7 @@ blacklist ${HOME}/.config/Code - OSS
75blacklist ${HOME}/.config/Code Industry 80blacklist ${HOME}/.config/Code Industry
76blacklist ${HOME}/.config/Cryptocat 81blacklist ${HOME}/.config/Cryptocat
77blacklist ${HOME}/.config/Debauchee/Barrier.conf 82blacklist ${HOME}/.config/Debauchee/Barrier.conf
83blacklist ${HOME}/.config/Dharkael
78blacklist ${HOME}/.config/Enox 84blacklist ${HOME}/.config/Enox
79blacklist ${HOME}/.config/Ferdi 85blacklist ${HOME}/.config/Ferdi
80blacklist ${HOME}/.config/Franz 86blacklist ${HOME}/.config/Franz
@@ -118,6 +124,7 @@ blacklist ${HOME}/.config/Slack
118blacklist ${HOME}/.config/Standard Notes 124blacklist ${HOME}/.config/Standard Notes
119blacklist ${HOME}/.config/SubDownloader 125blacklist ${HOME}/.config/SubDownloader
120blacklist ${HOME}/.config/Thunar 126blacklist ${HOME}/.config/Thunar
127blacklist ${HOME}/.config/Unknown Organization
121blacklist ${HOME}/.config/VirtualBox 128blacklist ${HOME}/.config/VirtualBox
122blacklist ${HOME}/.config/Wire 129blacklist ${HOME}/.config/Wire
123blacklist ${HOME}/.config/Zeal 130blacklist ${HOME}/.config/Zeal
@@ -125,6 +132,7 @@ blacklist ${HOME}/.config/abiword
125blacklist ${HOME}/.config/agenda 132blacklist ${HOME}/.config/agenda
126blacklist ${HOME}/.config/akonadi* 133blacklist ${HOME}/.config/akonadi*
127blacklist ${HOME}/.config/akregatorrc 134blacklist ${HOME}/.config/akregatorrc
135blacklist ${HOME}/.config/alacritty
128blacklist ${HOME}/.config/ardour4 136blacklist ${HOME}/.config/ardour4
129blacklist ${HOME}/.config/ardour5 137blacklist ${HOME}/.config/ardour5
130blacklist ${HOME}/.config/aria2 138blacklist ${HOME}/.config/aria2
@@ -136,6 +144,7 @@ blacklist ${HOME}/.config/atril
136blacklist ${HOME}/.config/audacious 144blacklist ${HOME}/.config/audacious
137blacklist ${HOME}/.config/autokey 145blacklist ${HOME}/.config/autokey
138blacklist ${HOME}/.config/aweather 146blacklist ${HOME}/.config/aweather
147blacklist ${HOME}/.config/backintime
139blacklist ${HOME}/.config/baloofilerc 148blacklist ${HOME}/.config/baloofilerc
140blacklist ${HOME}/.config/baloorc 149blacklist ${HOME}/.config/baloorc
141blacklist ${HOME}/.config/blender 150blacklist ${HOME}/.config/blender
@@ -195,14 +204,18 @@ blacklist ${HOME}/.config/geeqie
195blacklist ${HOME}/.config/ghb 204blacklist ${HOME}/.config/ghb
196blacklist ${HOME}/.config/ghostwriter 205blacklist ${HOME}/.config/ghostwriter
197blacklist ${HOME}/.config/git 206blacklist ${HOME}/.config/git
207blacklist ${HOME}/.config/glade.conf
198blacklist ${HOME}/.config/globaltime 208blacklist ${HOME}/.config/globaltime
199blacklist ${HOME}/.config/gmpc 209blacklist ${HOME}/.config/gmpc
200blacklist ${HOME}/.config/gnome-builder 210blacklist ${HOME}/.config/gnome-builder
201blacklist ${HOME}/.config/gnome-chess 211blacklist ${HOME}/.config/gnome-chess
212blacklist ${HOME}/.config/gnome-control-center
213blacklist ${HOME}/.config/gnome-initial-setup-done
202blacklist ${HOME}/.config/gnome-latex 214blacklist ${HOME}/.config/gnome-latex
203blacklist ${HOME}/.config/gnome-mplayer 215blacklist ${HOME}/.config/gnome-mplayer
204blacklist ${HOME}/.config/gnome-mpv 216blacklist ${HOME}/.config/gnome-mpv
205blacklist ${HOME}/.config/gnome-pie 217blacklist ${HOME}/.config/gnome-pie
218blacklist ${HOME}/.config/gnome-session
206blacklist ${HOME}/.config/godot 219blacklist ${HOME}/.config/godot
207blacklist ${HOME}/.config/google-chrome 220blacklist ${HOME}/.config/google-chrome
208blacklist ${HOME}/.config/google-chrome-beta 221blacklist ${HOME}/.config/google-chrome-beta
@@ -255,6 +268,7 @@ blacklist ${HOME}/.config/mate/eom
255blacklist ${HOME}/.config/mate/mate-dictionary 268blacklist ${HOME}/.config/mate/mate-dictionary
256blacklist ${HOME}/.config/meld 269blacklist ${HOME}/.config/meld
257blacklist ${HOME}/.config/meteo-qt 270blacklist ${HOME}/.config/meteo-qt
271blacklist ${HOME}/.config/menulibre.cfg
258blacklist ${HOME}/.config/mfusion 272blacklist ${HOME}/.config/mfusion
259blacklist ${HOME}/.config/Microsoft 273blacklist ${HOME}/.config/Microsoft
260blacklist ${HOME}/.config/midori 274blacklist ${HOME}/.config/midori
@@ -264,6 +278,7 @@ blacklist ${HOME}/.config/mpd
264blacklist ${HOME}/.config/mps-youtube 278blacklist ${HOME}/.config/mps-youtube
265blacklist ${HOME}/.config/mpv 279blacklist ${HOME}/.config/mpv
266blacklist ${HOME}/.config/mupen64plus 280blacklist ${HOME}/.config/mupen64plus
281blacklist ${HOME}/.config/mutter
267blacklist ${HOME}/.config/mypaint 282blacklist ${HOME}/.config/mypaint
268blacklist ${HOME}/.config/nano 283blacklist ${HOME}/.config/nano
269blacklist ${HOME}/.config/nautilus 284blacklist ${HOME}/.config/nautilus
@@ -362,6 +377,7 @@ blacklist ${HOME}/.config/zoomus.conf
362blacklist ${HOME}/.config/Zulip 377blacklist ${HOME}/.config/Zulip
363blacklist ${HOME}/.conkeror.mozdev.org 378blacklist ${HOME}/.conkeror.mozdev.org
364blacklist ${HOME}/.crawl 379blacklist ${HOME}/.crawl
380blacklist ${HOME}/.cups
365blacklist ${HOME}/.curlrc 381blacklist ${HOME}/.curlrc
366blacklist ${HOME}/.dashcore 382blacklist ${HOME}/.dashcore
367blacklist ${HOME}/.devilspie 383blacklist ${HOME}/.devilspie
@@ -400,6 +416,7 @@ blacklist ${HOME}/.gradle
400blacklist ${HOME}/.gramps 416blacklist ${HOME}/.gramps
401blacklist ${HOME}/.guayadeque 417blacklist ${HOME}/.guayadeque
402blacklist ${HOME}/.hashcat 418blacklist ${HOME}/.hashcat
419blacklist ${HOME}/.hex-a-hop
403blacklist ${HOME}/.hedgewars 420blacklist ${HOME}/.hedgewars
404blacklist ${HOME}/.hugin 421blacklist ${HOME}/.hugin
405blacklist ${HOME}/.i2p 422blacklist ${HOME}/.i2p
@@ -515,6 +532,7 @@ blacklist ${HOME}/.local/share/agenda
515blacklist ${HOME}/.local/share/apps/korganizer 532blacklist ${HOME}/.local/share/apps/korganizer
516blacklist ${HOME}/.local/share/aspyr-media 533blacklist ${HOME}/.local/share/aspyr-media
517blacklist ${HOME}/.local/share/autokey 534blacklist ${HOME}/.local/share/autokey
535blacklist ${HOME}/.local/share/backintime
518blacklist ${HOME}/.local/share/baloo 536blacklist ${HOME}/.local/share/baloo
519blacklist ${HOME}/.local/share/barrier 537blacklist ${HOME}/.local/share/barrier
520blacklist ${HOME}/.local/share/bibletime 538blacklist ${HOME}/.local/share/bibletime
@@ -545,8 +563,9 @@ blacklist ${HOME}/.local/share/geeqie
545blacklist ${HOME}/.local/share/ghostwriter 563blacklist ${HOME}/.local/share/ghostwriter
546blacklist ${HOME}/.local/share/gitg 564blacklist ${HOME}/.local/share/gitg
547blacklist ${HOME}/.local/share/gnome-2048 565blacklist ${HOME}/.local/share/gnome-2048
548blacklist ${HOME}/.local/share/gnome-chess 566blacklist ${HOME}/.local/share/gnome-boxes
549blacklist ${HOME}/.local/share/gnome-builder 567blacklist ${HOME}/.local/share/gnome-builder
568blacklist ${HOME}/.local/share/gnome-chess
550blacklist ${HOME}/.local/share/gnome-klotski 569blacklist ${HOME}/.local/share/gnome-klotski
551blacklist ${HOME}/.local/share/gnome-latex 570blacklist ${HOME}/.local/share/gnome-latex
552blacklist ${HOME}/.local/share/gnome-mines 571blacklist ${HOME}/.local/share/gnome-mines
@@ -672,6 +691,7 @@ blacklist ${HOME}/.penguin-command
672blacklist ${HOME}/.pingus 691blacklist ${HOME}/.pingus
673blacklist ${HOME}/.pioneer 692blacklist ${HOME}/.pioneer
674blacklist ${HOME}/.purple 693blacklist ${HOME}/.purple
694blacklist ${HOME}/.pylint.d
675blacklist ${HOME}/.qemu-launcher 695blacklist ${HOME}/.qemu-launcher
676blacklist ${HOME}/.qgis2 696blacklist ${HOME}/.qgis2
677blacklist ${HOME}/.qmmp 697blacklist ${HOME}/.qmmp
@@ -702,6 +722,7 @@ blacklist ${HOME}/.config/teams-for-linux
702blacklist ${HOME}/.tb 722blacklist ${HOME}/.tb
703blacklist ${HOME}/.tconn 723blacklist ${HOME}/.tconn
704blacklist ${HOME}/.teeworlds 724blacklist ${HOME}/.teeworlds
725blacklist ${HOME}/.texlive2018
705blacklist ${HOME}/.thunderbird 726blacklist ${HOME}/.thunderbird
706blacklist ${HOME}/.tilp 727blacklist ${HOME}/.tilp
707blacklist ${HOME}/.tooling 728blacklist ${HOME}/.tooling
@@ -779,6 +800,7 @@ blacklist ${HOME}/.cache/chromium-dev
779blacklist ${HOME}/.cache/cliqz 800blacklist ${HOME}/.cache/cliqz
780blacklist ${HOME}/.cache/com.github.johnfactotum.Foliate 801blacklist ${HOME}/.cache/com.github.johnfactotum.Foliate
781blacklist ${HOME}/.cache/darktable 802blacklist ${HOME}/.cache/darktable
803blacklist ${HOME}/.cache/deja-dup
782blacklist ${HOME}/.cache/discover 804blacklist ${HOME}/.cache/discover
783blacklist ${HOME}/.cache/dnox 805blacklist ${HOME}/.cache/dnox
784blacklist ${HOME}/.cache/dolphin 806blacklist ${HOME}/.cache/dolphin
@@ -795,9 +817,12 @@ blacklist ${HOME}/.cache/gegl-0.4
795blacklist ${HOME}/.cache/geeqie 817blacklist ${HOME}/.cache/geeqie
796blacklist ${HOME}/.cache/gfeeds 818blacklist ${HOME}/.cache/gfeeds
797blacklist ${HOME}/.cache/gimp 819blacklist ${HOME}/.cache/gimp
820blacklist ${HOME}/.cache/gnome-boxes
798blacklist ${HOME}/.cache/gnome-builder 821blacklist ${HOME}/.cache/gnome-builder
822blacklist ${HOME}/.cache/gnome-control-center
799blacklist ${HOME}/.cache/gnome-recipes 823blacklist ${HOME}/.cache/gnome-recipes
800blacklist ${HOME}/.cache/gnome-screenshot 824blacklist ${HOME}/.cache/gnome-screenshot
825blacklist ${HOME}/.cache/gnome-software
801blacklist ${HOME}/.cache/gnome-twitch 826blacklist ${HOME}/.cache/gnome-twitch
802blacklist ${HOME}/.cache/godot 827blacklist ${HOME}/.cache/godot
803blacklist ${HOME}/.cache/google-chrome 828blacklist ${HOME}/.cache/google-chrome
@@ -848,6 +873,7 @@ blacklist ${HOME}/.cache/org.gnome.Books
848blacklist ${HOME}/.cache/org.gnome.Maps 873blacklist ${HOME}/.cache/org.gnome.Maps
849blacklist ${HOME}/.cache/pdfmod 874blacklist ${HOME}/.cache/pdfmod
850blacklist ${HOME}/.cache/peek 875blacklist ${HOME}/.cache/peek
876blacklist ${HOME}/.cache/pip
851blacklist ${HOME}/.cache/plasmashell 877blacklist ${HOME}/.cache/plasmashell
852blacklist ${HOME}/.cache/plasmashellbookmarkrunnerfirefoxdbfile.sqlite* 878blacklist ${HOME}/.cache/plasmashellbookmarkrunnerfirefoxdbfile.sqlite*
853blacklist ${HOME}/.cache/qBittorrent 879blacklist ${HOME}/.cache/qBittorrent
diff --git a/etc/inc/whitelist-common.inc b/etc/inc/whitelist-common.inc
index 9c1b7b92c..a691b306c 100644
--- a/etc/inc/whitelist-common.inc
+++ b/etc/inc/whitelist-common.inc
@@ -38,6 +38,7 @@ whitelist ${HOME}/.pangorc
38# gtk 38# gtk
39whitelist ${HOME}/.config/gtk-2.0 39whitelist ${HOME}/.config/gtk-2.0
40whitelist ${HOME}/.config/gtk-3.0 40whitelist ${HOME}/.config/gtk-3.0
41whitelist ${HOME}/.config/gtk-4.0
41whitelist ${HOME}/.config/gtkrc 42whitelist ${HOME}/.config/gtkrc
42whitelist ${HOME}/.config/gtkrc-2.0 43whitelist ${HOME}/.config/gtkrc-2.0
43whitelist ${HOME}/.gnome2 44whitelist ${HOME}/.gnome2
diff --git a/etc/profile-a-l/etr.profile b/etc/profile-a-l/etr.profile
index 7afcd01d7..72f588366 100644
--- a/etc/profile-a-l/etr.profile
+++ b/etc/profile-a-l/etr.profile
@@ -9,6 +9,7 @@ include globals.local
9noblacklist ${HOME}/.etr 9noblacklist ${HOME}/.etr
10 10
11include disable-common.inc 11include disable-common.inc
12include disable-devel.inc
12include disable-exec.inc 13include disable-exec.inc
13include disable-interpreters.inc 14include disable-interpreters.inc
14include disable-passwdmgr.inc 15include disable-passwdmgr.inc
@@ -17,7 +18,10 @@ include disable-xdg.inc
17 18
18mkdir ${HOME}/.etr 19mkdir ${HOME}/.etr
19whitelist ${HOME}/.etr 20whitelist ${HOME}/.etr
21whitelist /usr/share/etr
20include whitelist-common.inc 22include whitelist-common.inc
23include whitelist-runuser-common.inc
24include whitelist-usr-share-common.inc
21include whitelist-var-common.inc 25include whitelist-var-common.inc
22 26
23apparmor 27apparmor
diff --git a/etc/profile-a-l/frozen-bubble.profile b/etc/profile-a-l/frozen-bubble.profile
index d1dc64bb9..9245ae3a9 100644
--- a/etc/profile-a-l/frozen-bubble.profile
+++ b/etc/profile-a-l/frozen-bubble.profile
@@ -17,10 +17,14 @@ include disable-exec.inc
17include disable-interpreters.inc 17include disable-interpreters.inc
18include disable-passwdmgr.inc 18include disable-passwdmgr.inc
19include disable-programs.inc 19include disable-programs.inc
20include disable-xdg.inc
20 21
21mkdir ${HOME}/.frozen-bubble 22mkdir ${HOME}/.frozen-bubble
22whitelist ${HOME}/.frozen-bubble 23whitelist ${HOME}/.frozen-bubble
24whitelist /usr/share/perl5
23include whitelist-common.inc 25include whitelist-common.inc
26include whitelist-runuser-common.inc
27include whitelist-usr-share-common.inc
24include whitelist-var-common.inc 28include whitelist-var-common.inc
25 29
26apparmor 30apparmor
@@ -36,6 +40,7 @@ novideo
36protocol unix,netlink 40protocol unix,netlink
37seccomp 41seccomp
38shell none 42shell none
43tracelog
39 44
40disable-mnt 45disable-mnt
41# private-bin frozen-bubble 46# private-bin frozen-bubble
diff --git a/etc/profile-a-l/gnome-chess.profile b/etc/profile-a-l/gnome-chess.profile
index 2e2e86ac9..c1d2a34c0 100644
--- a/etc/profile-a-l/gnome-chess.profile
+++ b/etc/profile-a-l/gnome-chess.profile
@@ -17,6 +17,10 @@ include disable-passwdmgr.inc
17include disable-programs.inc 17include disable-programs.inc
18include disable-xdg.inc 18include disable-xdg.inc
19 19
20#mkdir ${HOME}/.local/share/gnome-chess
21#whitelist ${HOME}/.local/share/gnome-chess
22#include whitelist-common.inc
23
20whitelist /usr/share/gnuchess 24whitelist /usr/share/gnuchess
21whitelist /usr/share/gnome-chess 25whitelist /usr/share/gnome-chess
22include whitelist-runuser-common.inc 26include whitelist-runuser-common.inc
diff --git a/etc/profile-a-l/gnome-hexgl.profile b/etc/profile-a-l/gnome-hexgl.profile
index 873a47ea9..59fe330a1 100644
--- a/etc/profile-a-l/gnome-hexgl.profile
+++ b/etc/profile-a-l/gnome-hexgl.profile
@@ -40,7 +40,7 @@ private
40private-bin gnome-hexgl 40private-bin gnome-hexgl
41private-cache 41private-cache
42private-dev 42private-dev
43private-etc machine-id 43private-etc alsa,asound.conf,machine-id,pulse
44private-tmp 44private-tmp
45 45
46dbus-user none 46dbus-user none
diff --git a/etc/profile-m-z/megaglest.profile b/etc/profile-m-z/megaglest.profile
index 86e7f129e..19f9edf05 100644
--- a/etc/profile-m-z/megaglest.profile
+++ b/etc/profile-m-z/megaglest.profile
@@ -18,9 +18,13 @@ include disable-xdg.inc
18 18
19mkdir ${HOME}/.megaglest 19mkdir ${HOME}/.megaglest
20whitelist ${HOME}/.megaglest 20whitelist ${HOME}/.megaglest
21whitelist /usr/share/megaglest
21include whitelist-common.inc 22include whitelist-common.inc
23include whitelist-runuser-common.inc
24include whitelist-usr-share-common.inc
22include whitelist-var-common.inc 25include whitelist-var-common.inc
23 26
27apparmor
24caps.drop all 28caps.drop all
25ipc-namespace 29ipc-namespace
26netfilter 30netfilter
diff --git a/etc/profile-m-z/minetest.profile b/etc/profile-m-z/minetest.profile
index 619173024..f201b13d7 100644
--- a/etc/profile-m-z/minetest.profile
+++ b/etc/profile-m-z/minetest.profile
@@ -21,7 +21,10 @@ mkdir ${HOME}/.cache/minetest
21mkdir ${HOME}/.minetest 21mkdir ${HOME}/.minetest
22whitelist ${HOME}/.cache/minetest 22whitelist ${HOME}/.cache/minetest
23whitelist ${HOME}/.minetest 23whitelist ${HOME}/.minetest
24whitelist /usr/share/minetest
24include whitelist-common.inc 25include whitelist-common.inc
26include whitelist-runuser-common.inc
27include whitelist-usr-share-common.inc
25include whitelist-var-common.inc 28include whitelist-var-common.inc
26 29
27caps.drop all 30caps.drop all
diff --git a/etc/profile-m-z/ostrichriders.profile b/etc/profile-m-z/ostrichriders.profile
index 378d267f6..4cd4dae17 100644
--- a/etc/profile-m-z/ostrichriders.profile
+++ b/etc/profile-m-z/ostrichriders.profile
@@ -18,7 +18,9 @@ include disable-xdg.inc
18 18
19mkdir ${HOME}/.ostrichriders 19mkdir ${HOME}/.ostrichriders
20whitelist ${HOME}/.ostrichriders 20whitelist ${HOME}/.ostrichriders
21whitelist /usr/share/ostrichriders
21include whitelist-common.inc 22include whitelist-common.inc
23include whitelist-usr-share-common.inc
22include whitelist-var-common.inc 24include whitelist-var-common.inc
23 25
24caps.drop all 26caps.drop all
diff --git a/etc/profile-m-z/pingus.profile b/etc/profile-m-z/pingus.profile
index cfe45b9c9..0b6a9ad5f 100644
--- a/etc/profile-m-z/pingus.profile
+++ b/etc/profile-m-z/pingus.profile
@@ -14,10 +14,14 @@ include disable-exec.inc
14include disable-interpreters.inc 14include disable-interpreters.inc
15include disable-passwdmgr.inc 15include disable-passwdmgr.inc
16include disable-programs.inc 16include disable-programs.inc
17include disable-xdg.inc
17 18
18mkdir ${HOME}/.pingus 19mkdir ${HOME}/.pingus
19whitelist ${HOME}/.pingus 20whitelist ${HOME}/.pingus
21whitelist /usr/share/pingus
20include whitelist-common.inc 22include whitelist-common.inc
23include whitelist-runuser-common.inc
24include whitelist-usr-share-common.inc
21include whitelist-var-common.inc 25include whitelist-var-common.inc
22 26
23apparmor 27apparmor
@@ -33,9 +37,13 @@ novideo
33protocol unix,netlink 37protocol unix,netlink
34seccomp 38seccomp
35shell none 39shell none
40tracelog
36 41
37# private-bin pingus 42disbale-mnt
43private-bin pingus,pingus.bin,sh
44private-cache
38private-dev 45private-dev
46private-etc machine-id
39private-tmp 47private-tmp
40 48
41dbus-user none 49dbus-user none
diff --git a/etc/profile-m-z/scorched3d-wrapper.profile b/etc/profile-m-z/scorched3d-wrapper.profile
index 9cbb19bff..507d0827e 100644
--- a/etc/profile-m-z/scorched3d-wrapper.profile
+++ b/etc/profile-m-z/scorched3d-wrapper.profile
@@ -3,5 +3,8 @@
3# Persistent local customizations 3# Persistent local customizations
4include scorched3d-wrapper.local 4include scorched3d-wrapper.local
5 5
6whitelist /usr/share/opengl-games-utils
7private-bin basename,bash,cut,glxinfo,grep,head,sed,zenity
8
6# Redirect 9# Redirect
7include scorched3d.profile 10include scorched3d.profile
diff --git a/etc/profile-m-z/scorched3d.profile b/etc/profile-m-z/scorched3d.profile
index b5e51198b..6a1003c33 100644
--- a/etc/profile-m-z/scorched3d.profile
+++ b/etc/profile-m-z/scorched3d.profile
@@ -18,7 +18,10 @@ include disable-xdg.inc
18 18
19mkdir ${HOME}/.scorched3d 19mkdir ${HOME}/.scorched3d
20whitelist ${HOME}/.scorched3d 20whitelist ${HOME}/.scorched3d
21whitelist /usr/share/scorched3d
21include whitelist-common.inc 22include whitelist-common.inc
23include whitelist-runuser-common.inc
24include whitelist-usr-share-common.inc
22include whitelist-var-common.inc 25include whitelist-var-common.inc
23 26
24caps.drop all 27caps.drop all
diff --git a/etc/profile-m-z/supertux2.profile b/etc/profile-m-z/supertux2.profile
index e1cdb114c..ceaae8fbf 100644
--- a/etc/profile-m-z/supertux2.profile
+++ b/etc/profile-m-z/supertux2.profile
@@ -14,10 +14,14 @@ include disable-exec.inc
14include disable-interpreters.inc 14include disable-interpreters.inc
15include disable-passwdmgr.inc 15include disable-passwdmgr.inc
16include disable-programs.inc 16include disable-programs.inc
17include disable-xdg.inc
17 18
18mkdir ${HOME}/.local/share/supertux2 19mkdir ${HOME}/.local/share/supertux2
19whitelist ${HOME}/.local/share/supertux2 20whitelist ${HOME}/.local/share/supertux2
21whitelist /usr/share/supertux2
20include whitelist-common.inc 22include whitelist-common.inc
23include whitelist-runuser-common.inc
24include whitelist-usr-share-common.inc
21include whitelist-var-common.inc 25include whitelist-var-common.inc
22 26
23apparmor 27apparmor
@@ -33,6 +37,7 @@ novideo
33protocol unix,netlink 37protocol unix,netlink
34seccomp 38seccomp
35shell none 39shell none
40tracelog
36 41
37disable-mnt 42disable-mnt
38# private-bin supertux2 43# private-bin supertux2
diff --git a/etc/profile-m-z/torcs.profile b/etc/profile-m-z/torcs.profile
index 8dcd7447b..1ed78934e 100644
--- a/etc/profile-m-z/torcs.profile
+++ b/etc/profile-m-z/torcs.profile
@@ -18,7 +18,10 @@ include disable-xdg.inc
18 18
19mkdir ${HOME}/.torcs 19mkdir ${HOME}/.torcs
20whitelist ${HOME}/.torcs 20whitelist ${HOME}/.torcs
21whitelist /usr/share/games/torcs
22whitelist /var/games/torcs
21include whitelist-common.inc 23include whitelist-common.inc
24include whitelist-usr-share-common.inc
22include whitelist-var-common.inc 25include whitelist-var-common.inc
23 26
24caps.drop all 27caps.drop all
@@ -37,6 +40,7 @@ shell none
37tracelog 40tracelog
38 41
39disable-mnt 42disable-mnt
43private-bin bash,chmod,cp,mkdir,rm,torcs
40private-cache 44private-cache
41private-dev 45private-dev
42private-tmp 46private-tmp
diff --git a/etc/profile-m-z/transmission-gtk.profile b/etc/profile-m-z/transmission-gtk.profile
index baa970307..03111ec56 100644
--- a/etc/profile-m-z/transmission-gtk.profile
+++ b/etc/profile-m-z/transmission-gtk.profile
@@ -10,6 +10,7 @@ include globals.local
10include whitelist-runuser-common.inc 10include whitelist-runuser-common.inc
11 11
12private-bin transmission-gtk 12private-bin transmission-gtk
13private-cache
13 14
14ignore memory-deny-write-execute 15ignore memory-deny-write-execute
15 16