aboutsummaryrefslogtreecommitdiffstats
path: root/etc/inc
diff options
context:
space:
mode:
Diffstat (limited to 'etc/inc')
-rw-r--r--etc/inc/allow-common-devel.inc5
-rw-r--r--etc/inc/allow-ruby.inc1
-rw-r--r--etc/inc/disable-common.inc8
-rw-r--r--etc/inc/disable-devel.inc2
-rw-r--r--etc/inc/disable-exec.inc1
-rw-r--r--etc/inc/disable-interpreters.inc1
-rw-r--r--etc/inc/disable-proc.inc82
-rw-r--r--etc/inc/disable-programs.inc355
-rw-r--r--etc/inc/whitelist-run-common.inc4
9 files changed, 279 insertions, 180 deletions
diff --git a/etc/inc/allow-common-devel.inc b/etc/inc/allow-common-devel.inc
index 011bbe226..4e460fc10 100644
--- a/etc/inc/allow-common-devel.inc
+++ b/etc/inc/allow-common-devel.inc
@@ -27,5 +27,8 @@ noblacklist ${HOME}/.python-history
27noblacklist ${HOME}/.python_history 27noblacklist ${HOME}/.python_history
28noblacklist ${HOME}/.pythonhist 28noblacklist ${HOME}/.pythonhist
29 29
30# Ruby
31noblacklist ${HOME}/.bundle
32
30# Rust 33# Rust
31noblacklist ${HOME}/.cargo/* 34noblacklist ${HOME}/.cargo
diff --git a/etc/inc/allow-ruby.inc b/etc/inc/allow-ruby.inc
index a8c701219..00276cac7 100644
--- a/etc/inc/allow-ruby.inc
+++ b/etc/inc/allow-ruby.inc
@@ -4,3 +4,4 @@ include allow-ruby.local
4 4
5noblacklist ${PATH}/ruby 5noblacklist ${PATH}/ruby
6noblacklist /usr/lib/ruby 6noblacklist /usr/lib/ruby
7noblacklist /usr/lib64/ruby
diff --git a/etc/inc/disable-common.inc b/etc/inc/disable-common.inc
index ae84ee38a..f3d685d18 100644
--- a/etc/inc/disable-common.inc
+++ b/etc/inc/disable-common.inc
@@ -458,7 +458,7 @@ blacklist /sbin
458blacklist /usr/local/sbin 458blacklist /usr/local/sbin
459blacklist /usr/sbin 459blacklist /usr/sbin
460 460
461# system management 461# system management and various SUID executables
462blacklist ${PATH}/at 462blacklist ${PATH}/at
463blacklist ${PATH}/busybox 463blacklist ${PATH}/busybox
464blacklist ${PATH}/chage 464blacklist ${PATH}/chage
@@ -493,6 +493,12 @@ blacklist ${PATH}/umount
493blacklist ${PATH}/unix_chkpwd 493blacklist ${PATH}/unix_chkpwd
494blacklist ${PATH}/xev 494blacklist ${PATH}/xev
495blacklist ${PATH}/xinput 495blacklist ${PATH}/xinput
496blacklist /usr/lib/openssh/ssh-keysign
497blacklist ${PATH}/passwd
498blacklist /usr/lib/xorg/Xorg.wrap
499blacklist /usr/lib/policykit-1/polkit-agent-helper-1
500blacklist /usr/lib/dbus-1.0/dbus-daemon-launch-helper
501blacklist /usr/lib/eject/dmcrypt-get-device
496 502
497# other SUID binaries 503# other SUID binaries
498blacklist /usr/lib/virtualbox 504blacklist /usr/lib/virtualbox
diff --git a/etc/inc/disable-devel.inc b/etc/inc/disable-devel.inc
index e74b1b40b..98bf5ecc8 100644
--- a/etc/inc/disable-devel.inc
+++ b/etc/inc/disable-devel.inc
@@ -60,9 +60,7 @@ blacklist /usr/lib/tcc
60blacklist ${PATH}/valgrind* 60blacklist ${PATH}/valgrind*
61blacklist /usr/lib/valgrind 61blacklist /usr/lib/valgrind
62 62
63
64# Source-Code 63# Source-Code
65
66blacklist /usr/src 64blacklist /usr/src
67blacklist /usr/local/src 65blacklist /usr/local/src
68blacklist /usr/include 66blacklist /usr/include
diff --git a/etc/inc/disable-exec.inc b/etc/inc/disable-exec.inc
index 9b5c40a2b..d7dcef7e7 100644
--- a/etc/inc/disable-exec.inc
+++ b/etc/inc/disable-exec.inc
@@ -6,6 +6,7 @@ noexec ${HOME}
6noexec ${RUNUSER} 6noexec ${RUNUSER}
7noexec /dev/mqueue 7noexec /dev/mqueue
8noexec /dev/shm 8noexec /dev/shm
9noexec /run/shm
9noexec /tmp 10noexec /tmp
10# /var is noexec by default for unprivileged users 11# /var is noexec by default for unprivileged users
11# except there is a writable-var option, so just in case: 12# except there is a writable-var option, so just in case:
diff --git a/etc/inc/disable-interpreters.inc b/etc/inc/disable-interpreters.inc
index 5d8a236fb..804869e2a 100644
--- a/etc/inc/disable-interpreters.inc
+++ b/etc/inc/disable-interpreters.inc
@@ -48,6 +48,7 @@ blacklist /usr/share/php*
48# Ruby 48# Ruby
49blacklist ${PATH}/ruby 49blacklist ${PATH}/ruby
50blacklist /usr/lib/ruby 50blacklist /usr/lib/ruby
51blacklist /usr/lib64/ruby
51 52
52# Programs using python: deluge, firefox addons, filezilla, cherrytree, xchat, hexchat, libreoffice, scribus 53# Programs using python: deluge, firefox addons, filezilla, cherrytree, xchat, hexchat, libreoffice, scribus
53# Python 2 54# Python 2
diff --git a/etc/inc/disable-proc.inc b/etc/inc/disable-proc.inc
new file mode 100644
index 000000000..81a8883f3
--- /dev/null
+++ b/etc/inc/disable-proc.inc
@@ -0,0 +1,82 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include disable-proc.local
4
5blacklist /proc/acpi
6blacklist /proc/asound
7blacklist /proc/bootconfig
8blacklist /proc/buddyinfo
9blacklist /proc/cgroups
10blacklist /proc/cmdline
11blacklist /proc/config.gz
12blacklist /proc/consoles
13#blacklist /proc/cpuinfo
14blacklist /proc/crypto
15blacklist /proc/devices
16blacklist /proc/diskstats
17blacklist /proc/dma
18#blacklist /proc/driver
19blacklist /proc/dynamic_debug
20blacklist /proc/execdomains
21blacklist /proc/fb
22#blacklist /proc/filesystems
23blacklist /proc/fs
24blacklist /proc/i8k
25blacklist /proc/interrupts
26blacklist /proc/iomem
27blacklist /proc/ioports
28blacklist /proc/irq
29blacklist /proc/kallsyms
30blacklist /proc/kcore
31blacklist /proc/keys
32blacklist /proc/key-users
33blacklist /proc/kmsg
34blacklist /proc/kpagecgroup
35blacklist /proc/kpagecount
36blacklist /proc/kpageflags
37blacklist /proc/latency_stats
38#blacklist /proc/loadavg
39blacklist /proc/locks
40blacklist /proc/mdstat
41#blacklist /proc/meminfo
42blacklist /proc/misc
43#blacklist /proc/modules
44#blacklist /proc/mounts
45blacklist /proc/mtrr
46#blacklist /proc/net
47blacklist /proc/partitions
48blacklist /proc/pressure
49blacklist /proc/sched_debug
50blacklist /proc/schedstat
51blacklist /proc/scsi
52#blacklist /proc/self
53blacklist /proc/slabinfo
54blacklist /proc/softirqs
55blacklist /proc/spl
56#blacklist /proc/stat
57blacklist /proc/swaps
58#blacklist /proc/sys
59blacklist /proc/sysrq-trigger
60blacklist /proc/sysvipc
61#blacklist /proc/thread-self
62blacklist /proc/timer_list
63blacklist /proc/tty
64#blacklist /proc/uptime
65#blacklist /proc/version
66blacklist /proc/version_signature
67blacklist /proc/vmallocinfo
68#blacklist /proc/vmstat
69#blacklist /proc/zoneinfo
70
71blacklist /proc/sys/abi
72blacklist /proc/sys/crypto
73blacklist /proc/sys/debug
74blacklist /proc/sys/dev
75blacklist /proc/sys/fs
76blacklist /proc/sys/net
77blacklist /proc/sys/user
78blacklist /proc/sys/vm
79
80noblacklist /proc/sys/kernel/osrelease
81noblacklist /proc/sys/kernel/yama
82blacklist /proc/sys/*/*
diff --git a/etc/inc/disable-programs.inc b/etc/inc/disable-programs.inc
index 4941630a2..e78f15e10 100644
--- a/etc/inc/disable-programs.inc
+++ b/etc/inc/disable-programs.inc
@@ -49,11 +49,184 @@ blacklist ${HOME}/.bibletime
49blacklist ${HOME}/.bitcoin 49blacklist ${HOME}/.bitcoin
50blacklist ${HOME}/.blobby 50blacklist ${HOME}/.blobby
51blacklist ${HOME}/.bogofilter 51blacklist ${HOME}/.bogofilter
52blacklist ${HOME}/.bundle
52blacklist ${HOME}/.bzf 53blacklist ${HOME}/.bzf
53blacklist ${HOME}/.cargo/* 54blacklist ${HOME}/.cache/0ad
55blacklist ${HOME}/.cache/8pecxstudios
56blacklist ${HOME}/.cache/Authenticator
57blacklist ${HOME}/.cache/BraveSoftware
58blacklist ${HOME}/.cache/Clementine
59blacklist ${HOME}/.cache/ENCOM/Spectral
60blacklist ${HOME}/.cache/Enox
61blacklist ${HOME}/.cache/Enpass
62blacklist ${HOME}/.cache/Ferdi
63blacklist ${HOME}/.cache/Flavio Tordini
64blacklist ${HOME}/.cache/Franz
65blacklist ${HOME}/.cache/GoldenDict
66blacklist ${HOME}/.cache/INRIA
67blacklist ${HOME}/.cache/INRIA/Natron
68blacklist ${HOME}/.cache/JetBrains/CLion*
69blacklist ${HOME}/.cache/KDE/neochat
70blacklist ${HOME}/.cache/Mendeley Ltd.
71blacklist ${HOME}/.cache/MusicBrainz
72blacklist ${HOME}/.cache/NewsFlashGTK
73blacklist ${HOME}/.cache/Otter
74blacklist ${HOME}/.cache/PawelStolowski
75blacklist ${HOME}/.cache/Psi
76blacklist ${HOME}/.cache/QuiteRss
77blacklist ${HOME}/.cache/Quotient/quaternion
78blacklist ${HOME}/.cache/Shortwave
79blacklist ${HOME}/.cache/Tox
80blacklist ${HOME}/.cache/Zeal
81blacklist ${HOME}/.cache/agenda
82blacklist ${HOME}/.cache/akonadi*
83blacklist ${HOME}/.cache/atril
84blacklist ${HOME}/.cache/attic
85blacklist ${HOME}/.cache/babl
86blacklist ${HOME}/.cache/bnox
87blacklist ${HOME}/.cache/borg
88blacklist ${HOME}/.cache/calibre
89blacklist ${HOME}/.cache/cantata
90blacklist ${HOME}/.cache/champlain
91blacklist ${HOME}/.cache/chromium
92blacklist ${HOME}/.cache/chromium-dev
93blacklist ${HOME}/.cache/cliqz
94blacklist ${HOME}/.cache/com.github.johnfactotum.Foliate
95blacklist ${HOME}/.cache/darktable
96blacklist ${HOME}/.cache/deja-dup
97blacklist ${HOME}/.cache/discover
98blacklist ${HOME}/.cache/dnox
99blacklist ${HOME}/.cache/dolphin
100blacklist ${HOME}/.cache/dolphin-emu
101blacklist ${HOME}/.cache/ephemeral
102blacklist ${HOME}/.cache/epiphany
103blacklist ${HOME}/.cache/evolution
104blacklist ${HOME}/.cache/falkon
105blacklist ${HOME}/.cache/feedreader
106blacklist ${HOME}/.cache/firedragon
107blacklist ${HOME}/.cache/flaska.net/trojita
108blacklist ${HOME}/.cache/folks
109blacklist ${HOME}/.cache/font-manager
110blacklist ${HOME}/.cache/fossamail
111blacklist ${HOME}/.cache/fractal
112blacklist ${HOME}/.cache/freecol
113blacklist ${HOME}/.cache/gajim
114blacklist ${HOME}/.cache/geary
115blacklist ${HOME}/.cache/geeqie
116blacklist ${HOME}/.cache/gegl-0.4
117blacklist ${HOME}/.cache/gfeeds
118blacklist ${HOME}/.cache/gimp
119blacklist ${HOME}/.cache/gnome-boxes
120blacklist ${HOME}/.cache/gnome-builder
121blacklist ${HOME}/.cache/gnome-control-center
122blacklist ${HOME}/.cache/gnome-recipes
123blacklist ${HOME}/.cache/gnome-screenshot
124blacklist ${HOME}/.cache/gnome-software
125blacklist ${HOME}/.cache/gnome-twitch
126blacklist ${HOME}/.cache/godot
127blacklist ${HOME}/.cache/google-chrome
128blacklist ${HOME}/.cache/google-chrome-beta
129blacklist ${HOME}/.cache/google-chrome-unstable
130blacklist ${HOME}/.cache/gradio
131blacklist ${HOME}/.cache/gummi
132blacklist ${HOME}/.cache/icedove
133blacklist ${HOME}/.cache/inkscape
134blacklist ${HOME}/.cache/inox
135blacklist ${HOME}/.cache/io.github.lainsce.Notejot
136blacklist ${HOME}/.cache/iridium
137blacklist ${HOME}/.cache/kcmshell5
138blacklist ${HOME}/.cache/kdenlive
139blacklist ${HOME}/.cache/keepassxc
140blacklist ${HOME}/.cache/kfind
141blacklist ${HOME}/.cache/kinfocenter
142blacklist ${HOME}/.cache/kmail2
143blacklist ${HOME}/.cache/krunner
144blacklist ${HOME}/.cache/krunnerbookmarkrunnerfirefoxdbfile.sqlite*
145blacklist ${HOME}/.cache/kscreenlocker_greet
146blacklist ${HOME}/.cache/ksmserver-logout-greeter
147blacklist ${HOME}/.cache/ksplashqml
148blacklist ${HOME}/.cache/kube
149blacklist ${HOME}/.cache/kwin
150blacklist ${HOME}/.cache/libgweather
151blacklist ${HOME}/.cache/librewolf
152blacklist ${HOME}/.cache/liferea
153blacklist ${HOME}/.cache/lutris
154blacklist ${HOME}/.cache/marker
155blacklist ${HOME}/.cache/matrix-mirage
156blacklist ${HOME}/.cache/microsoft-edge-beta
157blacklist ${HOME}/.cache/microsoft-edge-dev
158blacklist ${HOME}/.cache/midori
159blacklist ${HOME}/.cache/minetest
160blacklist ${HOME}/.cache/mirage
161blacklist ${HOME}/.cache/moonchild productions/basilisk
162blacklist ${HOME}/.cache/moonchild productions/pale moon
163blacklist ${HOME}/.cache/mozilla
164blacklist ${HOME}/.cache/ms-excel-online
165blacklist ${HOME}/.cache/ms-office-online
166blacklist ${HOME}/.cache/ms-onenote-online
167blacklist ${HOME}/.cache/ms-outlook-online
168blacklist ${HOME}/.cache/ms-powerpoint-online
169blacklist ${HOME}/.cache/ms-skype-online
170blacklist ${HOME}/.cache/ms-word-online
171blacklist ${HOME}/.cache/mutt
172blacklist ${HOME}/.cache/mypaint
173blacklist ${HOME}/.cache/netsurf
174blacklist ${HOME}/.cache/nheko
175blacklist ${HOME}/.cache/okular
176blacklist ${HOME}/.cache/opera
177blacklist ${HOME}/.cache/opera-beta
178blacklist ${HOME}/.cache/org.gabmus.gfeeds
179blacklist ${HOME}/.cache/org.gnome.Books
180blacklist ${HOME}/.cache/org.gnome.Maps
181blacklist ${HOME}/.cache/pdfmod
182blacklist ${HOME}/.cache/peek
183blacklist ${HOME}/.cache/pip
184blacklist ${HOME}/.cache/pipe-viewer
185blacklist ${HOME}/.cache/plasmashell
186blacklist ${HOME}/.cache/plasmashellbookmarkrunnerfirefoxdbfile.sqlite*
187blacklist ${HOME}/.cache/psi
188blacklist ${HOME}/.cache/qBittorrent
189blacklist ${HOME}/.cache/quodlibet
190blacklist ${HOME}/.cache/qupzilla
191blacklist ${HOME}/.cache/qutebrowser
192blacklist ${HOME}/.cache/rednotebook
193blacklist ${HOME}/.cache/rhythmbox
194blacklist ${HOME}/.cache/shotwell
195blacklist ${HOME}/.cache/simple-scan
196blacklist ${HOME}/.cache/slimjet
197blacklist ${HOME}/.cache/smuxi
198blacklist ${HOME}/.cache/snox
199blacklist ${HOME}/.cache/spotify
200blacklist ${HOME}/.cache/straw-viewer
201blacklist ${HOME}/.cache/strawberry
202blacklist ${HOME}/.cache/supertuxkart
203blacklist ${HOME}/.cache/systemsettings
204blacklist ${HOME}/.cache/telepathy
205blacklist ${HOME}/.cache/thunderbird
206blacklist ${HOME}/.cache/torbrowser
207blacklist ${HOME}/.cache/transmission
208blacklist ${HOME}/.cache/ungoogled-chromium
209blacklist ${HOME}/.cache/vivaldi
210blacklist ${HOME}/.cache/vivaldi-snapshot
211blacklist ${HOME}/.cache/vlc
212blacklist ${HOME}/.cache/vmware
213blacklist ${HOME}/.cache/warsow-2.1
214blacklist ${HOME}/.cache/waterfox
215blacklist ${HOME}/.cache/wesnoth
216blacklist ${HOME}/.cache/winetricks
217blacklist ${HOME}/.cache/xmms2
218blacklist ${HOME}/.cache/xournalpp
219blacklist ${HOME}/.cache/xreader
220blacklist ${HOME}/.cache/yandex-browser
221blacklist ${HOME}/.cache/yandex-browser-beta
222blacklist ${HOME}/.cache/youtube-dl
223blacklist ${HOME}/.cache/youtube-viewer
224blacklist ${HOME}/.cache/yt-dlp
225blacklist ${HOME}/.cache/zim
226blacklist ${HOME}/.cargo
54blacklist ${HOME}/.claws-mail 227blacklist ${HOME}/.claws-mail
55blacklist ${HOME}/.cliqz
56blacklist ${HOME}/.clion* 228blacklist ${HOME}/.clion*
229blacklist ${HOME}/.cliqz
57blacklist ${HOME}/.clonk 230blacklist ${HOME}/.clonk
58blacklist ${HOME}/.config/0ad 231blacklist ${HOME}/.config/0ad
59blacklist ${HOME}/.config/2048-qt 232blacklist ${HOME}/.config/2048-qt
@@ -92,8 +265,8 @@ blacklist ${HOME}/.config/Google Play Music Desktop Player
92blacklist ${HOME}/.config/Gpredict 265blacklist ${HOME}/.config/Gpredict
93blacklist ${HOME}/.config/INRIA 266blacklist ${HOME}/.config/INRIA
94blacklist ${HOME}/.config/InSilmaril 267blacklist ${HOME}/.config/InSilmaril
95blacklist ${HOME}/.config/Jitsi Meet
96blacklist ${HOME}/.config/JetBrains/CLion* 268blacklist ${HOME}/.config/JetBrains/CLion*
269blacklist ${HOME}/.config/Jitsi Meet
97blacklist ${HOME}/.config/KDE/neochat 270blacklist ${HOME}/.config/KDE/neochat
98blacklist ${HOME}/.config/KeePass 271blacklist ${HOME}/.config/KeePass
99blacklist ${HOME}/.config/KeePassXCrc 272blacklist ${HOME}/.config/KeePassXCrc
@@ -142,6 +315,7 @@ blacklist ${HOME}/.config/SubDownloader
142blacklist ${HOME}/.config/Thunar 315blacklist ${HOME}/.config/Thunar
143blacklist ${HOME}/.config/Twitch 316blacklist ${HOME}/.config/Twitch
144blacklist ${HOME}/.config/Unknown Organization 317blacklist ${HOME}/.config/Unknown Organization
318blacklist ${HOME}/.config/VSCodium
145blacklist ${HOME}/.config/VirtualBox 319blacklist ${HOME}/.config/VirtualBox
146blacklist ${HOME}/.config/Whalebird 320blacklist ${HOME}/.config/Whalebird
147blacklist ${HOME}/.config/Wire 321blacklist ${HOME}/.config/Wire
@@ -496,12 +670,14 @@ blacklist ${HOME}/.frogatto
496blacklist ${HOME}/.frozen-bubble 670blacklist ${HOME}/.frozen-bubble
497blacklist ${HOME}/.funnyboat 671blacklist ${HOME}/.funnyboat
498blacklist ${HOME}/.gallery-dl.conf 672blacklist ${HOME}/.gallery-dl.conf
673blacklist ${HOME}/.geekbench5
499blacklist ${HOME}/.gimp* 674blacklist ${HOME}/.gimp*
500blacklist ${HOME}/.gist 675blacklist ${HOME}/.gist
501blacklist ${HOME}/.gitconfig 676blacklist ${HOME}/.gitconfig
502blacklist ${HOME}/.gl-117 677blacklist ${HOME}/.gl-117
503blacklist ${HOME}/.glaxiumrc 678blacklist ${HOME}/.glaxiumrc
504blacklist ${HOME}/.gnome/gnome-schedule 679blacklist ${HOME}/.gnome/gnome-schedule
680blacklist ${HOME}/.goldendict
505blacklist ${HOME}/.googleearth 681blacklist ${HOME}/.googleearth
506blacklist ${HOME}/.gradle 682blacklist ${HOME}/.gradle
507blacklist ${HOME}/.gramps 683blacklist ${HOME}/.gramps
@@ -954,176 +1130,3 @@ blacklist /var/games/slashem
954blacklist /var/games/vulturesclaw 1130blacklist /var/games/vulturesclaw
955blacklist /var/games/vultureseye 1131blacklist /var/games/vultureseye
956blacklist /var/lib/games/Maelstrom-Scores 1132blacklist /var/lib/games/Maelstrom-Scores
957
958# ${HOME}/.cache directory
959blacklist ${HOME}/.cache/0ad
960blacklist ${HOME}/.cache/8pecxstudios
961blacklist ${HOME}/.cache/Authenticator
962blacklist ${HOME}/.cache/BraveSoftware
963blacklist ${HOME}/.cache/Clementine
964blacklist ${HOME}/.cache/ENCOM/Spectral
965blacklist ${HOME}/.cache/Enox
966blacklist ${HOME}/.cache/Enpass
967blacklist ${HOME}/.cache/Ferdi
968blacklist ${HOME}/.cache/Flavio Tordini
969blacklist ${HOME}/.cache/Franz
970blacklist ${HOME}/.cache/INRIA
971blacklist ${HOME}/.cache/INRIA/Natron
972blacklist ${HOME}/.cache/KDE/neochat
973blacklist ${HOME}/.cache/Mendeley Ltd.
974blacklist ${HOME}/.cache/MusicBrainz
975blacklist ${HOME}/.cache/NewsFlashGTK
976blacklist ${HOME}/.cache/Otter
977blacklist ${HOME}/.cache/PawelStolowski
978blacklist ${HOME}/.cache/Psi
979blacklist ${HOME}/.cache/QuiteRss
980blacklist ${HOME}/.cache/Quotient/quaternion
981blacklist ${HOME}/.cache/Shortwave
982blacklist ${HOME}/.cache/Tox
983blacklist ${HOME}/.cache/Zeal
984blacklist ${HOME}/.cache/agenda
985blacklist ${HOME}/.cache/akonadi*
986blacklist ${HOME}/.cache/atril
987blacklist ${HOME}/.cache/attic
988blacklist ${HOME}/.cache/babl
989blacklist ${HOME}/.cache/bnox
990blacklist ${HOME}/.cache/borg
991blacklist ${HOME}/.cache/calibre
992blacklist ${HOME}/.cache/cantata
993blacklist ${HOME}/.cache/champlain
994blacklist ${HOME}/.cache/chromium
995blacklist ${HOME}/.cache/chromium-dev
996blacklist ${HOME}/.cache/cliqz
997blacklist ${HOME}/.cache/com.github.johnfactotum.Foliate
998blacklist ${HOME}/.cache/darktable
999blacklist ${HOME}/.cache/deja-dup
1000blacklist ${HOME}/.cache/discover
1001blacklist ${HOME}/.cache/dnox
1002blacklist ${HOME}/.cache/dolphin
1003blacklist ${HOME}/.cache/dolphin-emu
1004blacklist ${HOME}/.cache/ephemeral
1005blacklist ${HOME}/.cache/epiphany
1006blacklist ${HOME}/.cache/evolution
1007blacklist ${HOME}/.cache/falkon
1008blacklist ${HOME}/.cache/feedreader
1009blacklist ${HOME}/.cache/firedragon
1010blacklist ${HOME}/.cache/flaska.net/trojita
1011blacklist ${HOME}/.cache/folks
1012blacklist ${HOME}/.cache/font-manager
1013blacklist ${HOME}/.cache/fossamail
1014blacklist ${HOME}/.cache/fractal
1015blacklist ${HOME}/.cache/freecol
1016blacklist ${HOME}/.cache/gajim
1017blacklist ${HOME}/.cache/geary
1018blacklist ${HOME}/.cache/geeqie
1019blacklist ${HOME}/.cache/gegl-0.4
1020blacklist ${HOME}/.cache/gfeeds
1021blacklist ${HOME}/.cache/gimp
1022blacklist ${HOME}/.cache/gnome-boxes
1023blacklist ${HOME}/.cache/gnome-builder
1024blacklist ${HOME}/.cache/gnome-control-center
1025blacklist ${HOME}/.cache/gnome-recipes
1026blacklist ${HOME}/.cache/gnome-screenshot
1027blacklist ${HOME}/.cache/gnome-software
1028blacklist ${HOME}/.cache/gnome-twitch
1029blacklist ${HOME}/.cache/godot
1030blacklist ${HOME}/.cache/google-chrome
1031blacklist ${HOME}/.cache/google-chrome-beta
1032blacklist ${HOME}/.cache/google-chrome-unstable
1033blacklist ${HOME}/.cache/gradio
1034blacklist ${HOME}/.cache/gummi
1035blacklist ${HOME}/.cache/icedove
1036blacklist ${HOME}/.cache/inkscape
1037blacklist ${HOME}/.cache/inox
1038blacklist ${HOME}/.cache/io.github.lainsce.Notejot
1039blacklist ${HOME}/.cache/iridium
1040blacklist ${HOME}/.cache/JetBrains/CLion*
1041blacklist ${HOME}/.cache/kcmshell5
1042blacklist ${HOME}/.cache/kdenlive
1043blacklist ${HOME}/.cache/keepassxc
1044blacklist ${HOME}/.cache/kfind
1045blacklist ${HOME}/.cache/kinfocenter
1046blacklist ${HOME}/.cache/kmail2
1047blacklist ${HOME}/.cache/krunner
1048blacklist ${HOME}/.cache/krunnerbookmarkrunnerfirefoxdbfile.sqlite*
1049blacklist ${HOME}/.cache/kscreenlocker_greet
1050blacklist ${HOME}/.cache/ksmserver-logout-greeter
1051blacklist ${HOME}/.cache/ksplashqml
1052blacklist ${HOME}/.cache/kube
1053blacklist ${HOME}/.cache/kwin
1054blacklist ${HOME}/.cache/libgweather
1055blacklist ${HOME}/.cache/librewolf
1056blacklist ${HOME}/.cache/liferea
1057blacklist ${HOME}/.cache/lutris
1058blacklist ${HOME}/.cache/marker
1059blacklist ${HOME}/.cache/matrix-mirage
1060blacklist ${HOME}/.cache/microsoft-edge-beta
1061blacklist ${HOME}/.cache/microsoft-edge-dev
1062blacklist ${HOME}/.cache/midori
1063blacklist ${HOME}/.cache/minetest
1064blacklist ${HOME}/.cache/mirage
1065blacklist ${HOME}/.cache/moonchild productions/basilisk
1066blacklist ${HOME}/.cache/moonchild productions/pale moon
1067blacklist ${HOME}/.cache/mozilla
1068blacklist ${HOME}/.cache/ms-excel-online
1069blacklist ${HOME}/.cache/ms-office-online
1070blacklist ${HOME}/.cache/ms-onenote-online
1071blacklist ${HOME}/.cache/ms-outlook-online
1072blacklist ${HOME}/.cache/ms-powerpoint-online
1073blacklist ${HOME}/.cache/ms-skype-online
1074blacklist ${HOME}/.cache/ms-word-online
1075blacklist ${HOME}/.cache/mutt
1076blacklist ${HOME}/.cache/mypaint
1077blacklist ${HOME}/.cache/netsurf
1078blacklist ${HOME}/.cache/nheko
1079blacklist ${HOME}/.cache/okular
1080blacklist ${HOME}/.cache/opera
1081blacklist ${HOME}/.cache/opera-beta
1082blacklist ${HOME}/.cache/org.gabmus.gfeeds
1083blacklist ${HOME}/.cache/org.gnome.Books
1084blacklist ${HOME}/.cache/org.gnome.Maps
1085blacklist ${HOME}/.cache/pdfmod
1086blacklist ${HOME}/.cache/peek
1087blacklist ${HOME}/.cache/pip
1088blacklist ${HOME}/.cache/pipe-viewer
1089blacklist ${HOME}/.cache/plasmashell
1090blacklist ${HOME}/.cache/plasmashellbookmarkrunnerfirefoxdbfile.sqlite*
1091blacklist ${HOME}/.cache/psi
1092blacklist ${HOME}/.cache/qBittorrent
1093blacklist ${HOME}/.cache/quodlibet
1094blacklist ${HOME}/.cache/qupzilla
1095blacklist ${HOME}/.cache/qutebrowser
1096blacklist ${HOME}/.cache/rednotebook
1097blacklist ${HOME}/.cache/rhythmbox
1098blacklist ${HOME}/.cache/shotwell
1099blacklist ${HOME}/.cache/simple-scan
1100blacklist ${HOME}/.cache/slimjet
1101blacklist ${HOME}/.cache/smuxi
1102blacklist ${HOME}/.cache/snox
1103blacklist ${HOME}/.cache/spotify
1104blacklist ${HOME}/.cache/straw-viewer
1105blacklist ${HOME}/.cache/strawberry
1106blacklist ${HOME}/.cache/supertuxkart
1107blacklist ${HOME}/.cache/systemsettings
1108blacklist ${HOME}/.cache/telepathy
1109blacklist ${HOME}/.cache/thunderbird
1110blacklist ${HOME}/.cache/torbrowser
1111blacklist ${HOME}/.cache/transmission
1112blacklist ${HOME}/.cache/ungoogled-chromium
1113blacklist ${HOME}/.cache/vivaldi
1114blacklist ${HOME}/.cache/vivaldi-snapshot
1115blacklist ${HOME}/.cache/vlc
1116blacklist ${HOME}/.cache/vmware
1117blacklist ${HOME}/.cache/warsow-2.1
1118blacklist ${HOME}/.cache/waterfox
1119blacklist ${HOME}/.cache/wesnoth
1120blacklist ${HOME}/.cache/winetricks
1121blacklist ${HOME}/.cache/xmms2
1122blacklist ${HOME}/.cache/xournalpp
1123blacklist ${HOME}/.cache/xreader
1124blacklist ${HOME}/.cache/yandex-browser
1125blacklist ${HOME}/.cache/yandex-browser-beta
1126blacklist ${HOME}/.cache/youtube-dl
1127blacklist ${HOME}/.cache/youtube-viewer
1128blacklist ${HOME}/.cache/yt-dlp
1129blacklist ${HOME}/.cache/zim
diff --git a/etc/inc/whitelist-run-common.inc b/etc/inc/whitelist-run-common.inc
index 224d21064..d74655a08 100644
--- a/etc/inc/whitelist-run-common.inc
+++ b/etc/inc/whitelist-run-common.inc
@@ -7,5 +7,9 @@ whitelist /run/cups/cups.sock
7whitelist /run/dbus/system_bus_socket 7whitelist /run/dbus/system_bus_socket
8whitelist /run/media 8whitelist /run/media
9whitelist /run/resolvconf/resolv.conf 9whitelist /run/resolvconf/resolv.conf
10whitelist /run/shm
11whitelist /run/systemd/journal/dev-log
12whitelist /run/systemd/journal/socket
10whitelist /run/systemd/resolve/resolv.conf 13whitelist /run/systemd/resolve/resolv.conf
11whitelist /run/systemd/resolve/stub-resolv.conf 14whitelist /run/systemd/resolve/stub-resolv.conf
15whitelist /run/udev/data