aboutsummaryrefslogtreecommitdiffstats
path: root/etc/inc
diff options
context:
space:
mode:
Diffstat (limited to 'etc/inc')
-rw-r--r--etc/inc/archiver-common.inc57
-rw-r--r--etc/inc/chromium-common-hardened.inc5
-rw-r--r--etc/inc/feh-network.inc4
-rw-r--r--etc/inc/firefox-common-addons.inc91
4 files changed, 0 insertions, 157 deletions
diff --git a/etc/inc/archiver-common.inc b/etc/inc/archiver-common.inc
deleted file mode 100644
index 74b0b6ef6..000000000
--- a/etc/inc/archiver-common.inc
+++ /dev/null
@@ -1,57 +0,0 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include archiver-common.local
4
5# common profile for archiver/compression tools
6
7blacklist ${RUNUSER}
8
9# WARNING: Users can (un)restrict file access for **all** archivers by
10# commenting/uncommenting the needed include file(s) here or by putting those
11# into archiver-common.local.
12#
13# Another option is to do this **per archiver** in the relevant
14# <archiver>.local. Just beware that things tend to break when overtightening
15# profiles. For example, because you only need to (un)compress files in
16# ${DOWNLOADS}, other applications may need access to ${HOME}/.local/share.
17
18# Uncomment the next line (or put it into your archiver-common.local) if you
19# don't need to compress files in disable-common.inc.
20#include disable-common.inc
21include disable-devel.inc
22include disable-exec.inc
23include disable-interpreters.inc
24include disable-passwdmgr.inc
25# Uncomment the next line (or put it into your archiver-common.local) if you
26# don't need to compress files in disable-programs.inc.
27#include disable-programs.inc
28include disable-shell.inc
29
30apparmor
31caps.drop all
32hostname archiver
33ipc-namespace
34machine-id
35net none
36no3d
37nodvd
38nogroups
39nonewprivs
40#noroot
41nosound
42notv
43nou2f
44novideo
45protocol unix
46seccomp
47shell none
48tracelog
49x11 none
50
51private-cache
52private-dev
53
54dbus-user none
55dbus-system none
56
57memory-deny-write-execute
diff --git a/etc/inc/chromium-common-hardened.inc b/etc/inc/chromium-common-hardened.inc
deleted file mode 100644
index f33ce3115..000000000
--- a/etc/inc/chromium-common-hardened.inc
+++ /dev/null
@@ -1,5 +0,0 @@
1caps.drop all
2nonewprivs
3noroot
4protocol unix,inet,inet6,netlink
5seccomp !chroot
diff --git a/etc/inc/feh-network.inc b/etc/inc/feh-network.inc
deleted file mode 100644
index e94e7205c..000000000
--- a/etc/inc/feh-network.inc
+++ /dev/null
@@ -1,4 +0,0 @@
1ignore net none
2netfilter
3protocol unix,inet,inet6
4private-etc ca-certificates,crypto-policies,hosts,pki,resolv.conf,ssl
diff --git a/etc/inc/firefox-common-addons.inc b/etc/inc/firefox-common-addons.inc
deleted file mode 100644
index ca7731442..000000000
--- a/etc/inc/firefox-common-addons.inc
+++ /dev/null
@@ -1,91 +0,0 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include firefox-common-addons.local
4
5ignore include whitelist-runuser-common.inc
6
7noblacklist ${HOME}/.config/kgetrc
8noblacklist ${HOME}/.config/okularpartrc
9noblacklist ${HOME}/.config/okularrc
10noblacklist ${HOME}/.config/qpdfview
11noblacklist ${HOME}/.kde/share/apps/kget
12noblacklist ${HOME}/.kde/share/apps/okular
13noblacklist ${HOME}/.kde/share/config/kgetrc
14noblacklist ${HOME}/.kde/share/config/okularpartrc
15noblacklist ${HOME}/.kde/share/config/okularrc
16noblacklist ${HOME}/.kde4/share/apps/kget
17noblacklist ${HOME}/.kde4/share/apps/okular
18noblacklist ${HOME}/.kde4/share/config/kgetrc
19noblacklist ${HOME}/.kde4/share/config/okularpartrc
20noblacklist ${HOME}/.kde4/share/config/okularrc
21noblacklist ${HOME}/.local/share/kget
22noblacklist ${HOME}/.local/share/kxmlgui5/okular
23noblacklist ${HOME}/.local/share/okular
24noblacklist ${HOME}/.local/share/qpdfview
25
26whitelist ${HOME}/.cache/gnome-mplayer/plugin
27whitelist ${HOME}/.config/gnome-mplayer
28whitelist ${HOME}/.config/kgetrc
29whitelist ${HOME}/.config/okularpartrc
30whitelist ${HOME}/.config/okularrc
31whitelist ${HOME}/.config/pipelight-silverlight5.1
32whitelist ${HOME}/.config/pipelight-widevine
33whitelist ${HOME}/.config/qpdfview
34whitelist ${HOME}/.kde/share/apps/kget
35whitelist ${HOME}/.kde/share/apps/okular
36whitelist ${HOME}/.kde/share/config/kgetrc
37whitelist ${HOME}/.kde/share/config/okularpartrc
38whitelist ${HOME}/.kde/share/config/okularrc
39whitelist ${HOME}/.kde4/share/apps/kget
40whitelist ${HOME}/.kde4/share/apps/okular
41whitelist ${HOME}/.kde4/share/config/kgetrc
42whitelist ${HOME}/.kde4/share/config/okularpartrc
43whitelist ${HOME}/.kde4/share/config/okularrc
44whitelist ${HOME}/.keysnail.js
45whitelist ${HOME}/.lastpass
46whitelist ${HOME}/.local/share/kget
47whitelist ${HOME}/.local/share/kxmlgui5/okular
48whitelist ${HOME}/.local/share/okular
49whitelist ${HOME}/.local/share/qpdfview
50whitelist ${HOME}/.local/share/tridactyl
51whitelist ${HOME}/.pentadactyl
52whitelist ${HOME}/.pentadactylrc
53whitelist ${HOME}/.tridactylrc
54whitelist ${HOME}/.vimperator
55whitelist ${HOME}/.vimperatorrc
56whitelist ${HOME}/.wine-pipelight
57whitelist ${HOME}/.wine-pipelight64
58whitelist ${HOME}/.zotero
59whitelist ${HOME}/dwhelper
60
61# GNOME Shell integration (chrome-gnome-shell) needs dbus and python
62noblacklist ${HOME}/.local/share/gnome-shell
63whitelist ${HOME}/.local/share/gnome-shell
64ignore dbus-user none
65ignore dbus-system none
66# Allow python (blacklisted by disable-interpreters.inc)
67include allow-python3.inc
68
69# KeePassXC Browser Integration
70#private-bin keepassxc-proxy
71
72# Flash plugin
73# private-etc must first be enabled in firefox-common.profile and in profiles including it.
74#private-etc adobe
75
76# ff2mpv
77#ignore noexec ${HOME}
78#noblacklist ${HOME}/.config/mpv
79#noblacklist ${HOME}/.config/youtube-dl
80#noblacklist ${HOME}/.netrc
81#include allow-lua.inc
82#include allow-python3.inc
83#mkdir ${HOME}/.config/mpv
84#mkdir ${HOME}/.config/youtube-dl
85#whitelist ${HOME}/.config/mpv
86#whitelist ${HOME}/.config/youtube-dl
87#whitelist ${HOME}/.netrc
88#whitelist /usr/share/lua
89#whitelist /usr/share/lua*
90#whitelist /usr/share/vulkan
91#private-bin env,mpv,python3*,waf,youtube-dl