diff options
Diffstat (limited to 'etc/profile-m-z')
34 files changed, 125 insertions, 22 deletions
diff --git a/etc/profile-m-z/QMediathekView.profile b/etc/profile-m-z/QMediathekView.profile index 589dcfeb6..5ab302218 100644 --- a/etc/profile-m-z/QMediathekView.profile +++ b/etc/profile-m-z/QMediathekView.profile | |||
@@ -53,7 +53,7 @@ private-cache | |||
53 | private-dev | 53 | private-dev |
54 | private-tmp | 54 | private-tmp |
55 | 55 | ||
56 | # dbus-user none | 56 | dbus-user none |
57 | # dbus-system none | 57 | dbus-system none |
58 | 58 | ||
59 | #memory-deny-write-execute - breaks on Arch (see issue #1803) | 59 | #memory-deny-write-execute - breaks on Arch (see issue #1803) |
diff --git a/etc/profile-m-z/megaglest.profile b/etc/profile-m-z/megaglest.profile index 19f9edf05..37ac9e304 100644 --- a/etc/profile-m-z/megaglest.profile +++ b/etc/profile-m-z/megaglest.profile | |||
@@ -14,6 +14,7 @@ include disable-exec.inc | |||
14 | include disable-interpreters.inc | 14 | include disable-interpreters.inc |
15 | include disable-passwdmgr.inc | 15 | include disable-passwdmgr.inc |
16 | include disable-programs.inc | 16 | include disable-programs.inc |
17 | include disable-shell.inc | ||
17 | include disable-xdg.inc | 18 | include disable-xdg.inc |
18 | 19 | ||
19 | mkdir ${HOME}/.megaglest | 20 | mkdir ${HOME}/.megaglest |
@@ -37,6 +38,7 @@ nou2f | |||
37 | novideo | 38 | novideo |
38 | protocol unix,inet,inet6,netlink | 39 | protocol unix,inet,inet6,netlink |
39 | seccomp | 40 | seccomp |
41 | seccomp.block-secondary | ||
40 | shell none | 42 | shell none |
41 | tracelog | 43 | tracelog |
42 | 44 | ||
diff --git a/etc/profile-m-z/meld.profile b/etc/profile-m-z/meld.profile index 385700648..6ceeb867f 100644 --- a/etc/profile-m-z/meld.profile +++ b/etc/profile-m-z/meld.profile | |||
@@ -62,6 +62,7 @@ nou2f | |||
62 | novideo | 62 | novideo |
63 | protocol unix,inet,inet6 | 63 | protocol unix,inet,inet6 |
64 | seccomp | 64 | seccomp |
65 | seccomp.block-secondary | ||
65 | shell none | 66 | shell none |
66 | tracelog | 67 | tracelog |
67 | 68 | ||
diff --git a/etc/profile-m-z/menulibre.profile b/etc/profile-m-z/menulibre.profile index 3468bc22d..c70090a25 100644 --- a/etc/profile-m-z/menulibre.profile +++ b/etc/profile-m-z/menulibre.profile | |||
@@ -44,6 +44,7 @@ nou2f | |||
44 | novideo | 44 | novideo |
45 | protocol unix | 45 | protocol unix |
46 | seccomp | 46 | seccomp |
47 | seccomp.block-secondary | ||
47 | shell none | 48 | shell none |
48 | tracelog | 49 | tracelog |
49 | 50 | ||
diff --git a/etc/profile-m-z/minetest.profile b/etc/profile-m-z/minetest.profile index a22d2c2e3..666af323d 100644 --- a/etc/profile-m-z/minetest.profile +++ b/etc/profile-m-z/minetest.profile | |||
@@ -47,12 +47,14 @@ nou2f | |||
47 | novideo | 47 | novideo |
48 | protocol unix,inet,inet6 | 48 | protocol unix,inet,inet6 |
49 | seccomp | 49 | seccomp |
50 | seccomp.block-secondary | ||
50 | shell none | 51 | shell none |
51 | tracelog | 52 | tracelog |
52 | 53 | ||
53 | disable-mnt | 54 | disable-mnt |
54 | private-bin minetest | 55 | private-bin minetest,rm |
55 | private-cache | 56 | # cache is used for storing assets when connecting to servers |
57 | #private-cache | ||
56 | private-dev | 58 | private-dev |
57 | # private-etc needs to be updated, see #1702 | 59 | # private-etc needs to be updated, see #1702 |
58 | #private-etc alternatives,asound.conf,ca-certificates,crypto-policies,drirc,fonts,group,host.conf,hostname,hosts,ld.so.cache,ld.so.preload,localtime,machine-id,nsswitch.conf,passwd,pki,pulse,resolv.conf,ssl | 60 | #private-etc alternatives,asound.conf,ca-certificates,crypto-policies,drirc,fonts,group,host.conf,hostname,hosts,ld.so.cache,ld.so.preload,localtime,machine-id,nsswitch.conf,passwd,pki,pulse,resolv.conf,ssl |
diff --git a/etc/profile-m-z/mpv.profile b/etc/profile-m-z/mpv.profile index 389b64535..ce3bfe421 100644 --- a/etc/profile-m-z/mpv.profile +++ b/etc/profile-m-z/mpv.profile | |||
@@ -67,6 +67,7 @@ noroot | |||
67 | nou2f | 67 | nou2f |
68 | protocol unix,inet,inet6,netlink | 68 | protocol unix,inet,inet6,netlink |
69 | seccomp | 69 | seccomp |
70 | seccomp.block-secondary | ||
70 | shell none | 71 | shell none |
71 | tracelog | 72 | tracelog |
72 | 73 | ||
diff --git a/etc/profile-m-z/ostrichriders.profile b/etc/profile-m-z/ostrichriders.profile index cc44d5a48..3bfda7946 100644 --- a/etc/profile-m-z/ostrichriders.profile +++ b/etc/profile-m-z/ostrichriders.profile | |||
@@ -42,7 +42,7 @@ tracelog | |||
42 | disable-mnt | 42 | disable-mnt |
43 | private-bin ostrichriders | 43 | private-bin ostrichriders |
44 | private-cache | 44 | private-cache |
45 | # private-dev should be commented for controllers | 45 | # comment the following line if you need controller support |
46 | private-dev | 46 | private-dev |
47 | private-tmp | 47 | private-tmp |
48 | 48 | ||
diff --git a/etc/profile-m-z/patch.profile b/etc/profile-m-z/patch.profile index 8663fb453..6cbaa66ad 100644 --- a/etc/profile-m-z/patch.profile +++ b/etc/profile-m-z/patch.profile | |||
@@ -37,6 +37,7 @@ nou2f | |||
37 | novideo | 37 | novideo |
38 | protocol unix | 38 | protocol unix |
39 | seccomp | 39 | seccomp |
40 | seccomp.block-secondary | ||
40 | shell none | 41 | shell none |
41 | tracelog | 42 | tracelog |
42 | x11 none | 43 | x11 none |
diff --git a/etc/profile-m-z/pdftotext.profile b/etc/profile-m-z/pdftotext.profile index eee42424f..2a7d0cec1 100644 --- a/etc/profile-m-z/pdftotext.profile +++ b/etc/profile-m-z/pdftotext.profile | |||
@@ -13,6 +13,7 @@ noblacklist ${DOCUMENTS} | |||
13 | 13 | ||
14 | include disable-common.inc | 14 | include disable-common.inc |
15 | include disable-devel.inc | 15 | include disable-devel.inc |
16 | include disable-exec.inc | ||
16 | include disable-interpreters.inc | 17 | include disable-interpreters.inc |
17 | include disable-passwdmgr.inc | 18 | include disable-passwdmgr.inc |
18 | include disable-programs.inc | 19 | include disable-programs.inc |
@@ -40,6 +41,7 @@ nou2f | |||
40 | novideo | 41 | novideo |
41 | protocol unix | 42 | protocol unix |
42 | seccomp | 43 | seccomp |
44 | seccomp.block-secondary | ||
43 | shell none | 45 | shell none |
44 | tracelog | 46 | tracelog |
45 | x11 none | 47 | x11 none |
diff --git a/etc/profile-m-z/peek.profile b/etc/profile-m-z/peek.profile index 28a7da404..710a533a9 100644 --- a/etc/profile-m-z/peek.profile +++ b/etc/profile-m-z/peek.profile | |||
@@ -41,6 +41,7 @@ nou2f | |||
41 | novideo | 41 | novideo |
42 | protocol unix | 42 | protocol unix |
43 | seccomp | 43 | seccomp |
44 | seccomp.block-secondary | ||
44 | shell none | 45 | shell none |
45 | tracelog | 46 | tracelog |
46 | 47 | ||
diff --git a/etc/profile-m-z/pngquant.profile b/etc/profile-m-z/pngquant.profile index 83905b108..3513e91cc 100644 --- a/etc/profile-m-z/pngquant.profile +++ b/etc/profile-m-z/pngquant.profile | |||
@@ -7,6 +7,8 @@ include pngquant.local | |||
7 | # Persistent global definitions | 7 | # Persistent global definitions |
8 | include globals.local | 8 | include globals.local |
9 | 9 | ||
10 | noblacklist ${PICTURES} | ||
11 | |||
10 | blacklist ${RUNUSER}/wayland-* | 12 | blacklist ${RUNUSER}/wayland-* |
11 | 13 | ||
12 | include disable-common.inc | 14 | include disable-common.inc |
@@ -16,6 +18,7 @@ include disable-interpreters.inc | |||
16 | include disable-passwdmgr.inc | 18 | include disable-passwdmgr.inc |
17 | include disable-programs.inc | 19 | include disable-programs.inc |
18 | include disable-shell.inc | 20 | include disable-shell.inc |
21 | include disable-xdg.inc | ||
19 | 22 | ||
20 | include whitelist-runuser-common.inc | 23 | include whitelist-runuser-common.inc |
21 | include whitelist-usr-share-common.inc | 24 | include whitelist-usr-share-common.inc |
diff --git a/etc/profile-m-z/ppsspp.profile b/etc/profile-m-z/ppsspp.profile index c62e53151..c71553bcd 100644 --- a/etc/profile-m-z/ppsspp.profile +++ b/etc/profile-m-z/ppsspp.profile | |||
@@ -32,7 +32,7 @@ protocol unix,netlink | |||
32 | seccomp | 32 | seccomp |
33 | shell none | 33 | shell none |
34 | 34 | ||
35 | # private-dev is disabled to allow controller support | 35 | # uncomment the following line if you do not need controller support |
36 | #private-dev | 36 | #private-dev |
37 | private-etc alternatives,asound.conf,ca-certificates,crypto-policies,drirc,fonts,group,host.conf,hostname,hosts,ld.so.cache,ld.so.preload,localtime,machine-id,nsswitch.conf,passwd,pki,pulse,resolv.conf,ssl | 37 | private-etc alternatives,asound.conf,ca-certificates,crypto-policies,drirc,fonts,group,host.conf,hostname,hosts,ld.so.cache,ld.so.preload,localtime,machine-id,nsswitch.conf,passwd,pki,pulse,resolv.conf,ssl |
38 | private-opt ppsspp | 38 | private-opt ppsspp |
diff --git a/etc/profile-m-z/rhythmbox.profile b/etc/profile-m-z/rhythmbox.profile index f906ec31d..9fb7dc713 100644 --- a/etc/profile-m-z/rhythmbox.profile +++ b/etc/profile-m-z/rhythmbox.profile | |||
@@ -45,10 +45,12 @@ nou2f | |||
45 | novideo | 45 | novideo |
46 | protocol unix,inet,inet6,netlink | 46 | protocol unix,inet,inet6,netlink |
47 | seccomp | 47 | seccomp |
48 | seccomp.block-secondary | ||
48 | shell none | 49 | shell none |
49 | tracelog | 50 | tracelog |
50 | 51 | ||
51 | private-bin rhythmbox,rhythmbox-client | 52 | private-bin rhythmbox,rhythmbox-client |
53 | private-cache | ||
52 | private-dev | 54 | private-dev |
53 | private-tmp | 55 | private-tmp |
54 | 56 | ||
@@ -57,6 +59,7 @@ dbus-user.own org.gnome.Rhythmbox3 | |||
57 | dbus-user.own org.mpris.MediaPlayer2.rhythmbox | 59 | dbus-user.own org.mpris.MediaPlayer2.rhythmbox |
58 | dbus-user.own org.gnome.UPnP.MediaServer2.Rhythmbox | 60 | dbus-user.own org.gnome.UPnP.MediaServer2.Rhythmbox |
59 | dbus-user.talk ca.desrt.dconf | 61 | dbus-user.talk ca.desrt.dconf |
62 | dbus-user.talk org.gtk.vfs.* | ||
60 | dbus-user.talk org.freedesktop.Notifications | 63 | dbus-user.talk org.freedesktop.Notifications |
61 | dbus-user.talk org.gnome.SettingsDaemon.MediaKeys | 64 | dbus-user.talk org.gnome.SettingsDaemon.MediaKeys |
62 | dbus-system filter | 65 | dbus-system filter |
diff --git a/etc/profile-m-z/shellcheck.profile b/etc/profile-m-z/shellcheck.profile index 6cd70c2ea..c67a88161 100644 --- a/etc/profile-m-z/shellcheck.profile +++ b/etc/profile-m-z/shellcheck.profile | |||
@@ -40,6 +40,7 @@ nou2f | |||
40 | novideo | 40 | novideo |
41 | protocol unix | 41 | protocol unix |
42 | seccomp | 42 | seccomp |
43 | seccomp.block-secondary | ||
43 | shell none | 44 | shell none |
44 | tracelog | 45 | tracelog |
45 | x11 none | 46 | x11 none |
diff --git a/etc/profile-m-z/sqlitebrowser.profile b/etc/profile-m-z/sqlitebrowser.profile index cdb20b4e0..110434736 100644 --- a/etc/profile-m-z/sqlitebrowser.profile +++ b/etc/profile-m-z/sqlitebrowser.profile | |||
@@ -18,6 +18,7 @@ include disable-programs.inc | |||
18 | include disable-shell.inc | 18 | include disable-shell.inc |
19 | include disable-xdg.inc | 19 | include disable-xdg.inc |
20 | 20 | ||
21 | include whitelist-runuser-common.inc | ||
21 | include whitelist-usr-share-common.inc | 22 | include whitelist-usr-share-common.inc |
22 | include whitelist-var-common.inc | 23 | include whitelist-var-common.inc |
23 | 24 | ||
@@ -35,6 +36,7 @@ nou2f | |||
35 | novideo | 36 | novideo |
36 | protocol unix,inet,inet6,netlink | 37 | protocol unix,inet,inet6,netlink |
37 | seccomp | 38 | seccomp |
39 | seccomp.block-secondary | ||
38 | shell none | 40 | shell none |
39 | 41 | ||
40 | private-bin sqlitebrowser | 42 | private-bin sqlitebrowser |
diff --git a/etc/profile-m-z/steam.profile b/etc/profile-m-z/steam.profile index 7292f189c..adf9c9317 100644 --- a/etc/profile-m-z/steam.profile +++ b/etc/profile-m-z/steam.profile | |||
@@ -109,7 +109,7 @@ shell none | |||
109 | # picture viewers are needed for viewing screenshots | 109 | # picture viewers are needed for viewing screenshots |
110 | #private-bin eog,eom,gthumb,pix,viewnior,xviewer | 110 | #private-bin eog,eom,gthumb,pix,viewnior,xviewer |
111 | 111 | ||
112 | # private-dev should be commented for controllers | 112 | # comment the following line if you need controller support |
113 | private-dev | 113 | private-dev |
114 | # private-etc breaks a small selection of games on some systems, comment to support those | 114 | # private-etc breaks a small selection of games on some systems, comment to support those |
115 | private-etc alternatives,asound.conf,bumblebee,ca-certificates,crypto-policies,dbus-1,drirc,fonts,group,gtk-2.0,gtk-3.0,host.conf,hostname,hosts,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,localtime,lsb-release,machine-id,mime.types,nvidia,os-release,passwd,pki,pulse,resolv.conf,services,ssl | 115 | private-etc alternatives,asound.conf,bumblebee,ca-certificates,crypto-policies,dbus-1,drirc,fonts,group,gtk-2.0,gtk-3.0,host.conf,hostname,hosts,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,localtime,lsb-release,machine-id,mime.types,nvidia,os-release,passwd,pki,pulse,resolv.conf,services,ssl |
diff --git a/etc/profile-m-z/straw-viewer.profile b/etc/profile-m-z/straw-viewer.profile new file mode 100644 index 000000000..721ad38ee --- /dev/null +++ b/etc/profile-m-z/straw-viewer.profile | |||
@@ -0,0 +1,58 @@ | |||
1 | # Firejail profile for straw-viewer | ||
2 | # Description: Fork of youtube-viewer acts like an invidious frontend | ||
3 | quiet | ||
4 | # This file is overwritten after every install/update | ||
5 | # Persistent local customizations | ||
6 | include straw-viewer.local | ||
7 | # Persistent global definitions | ||
8 | include globals.local | ||
9 | |||
10 | noblacklist ${HOME}/.cache/straw-viewer | ||
11 | noblacklist ${HOME}/.config/straw-viewer | ||
12 | |||
13 | include allow-lua.inc | ||
14 | include allow-perl.inc | ||
15 | include allow-python2.inc | ||
16 | include allow-python3.inc | ||
17 | |||
18 | include disable-common.inc | ||
19 | include disable-devel.inc | ||
20 | include disable-exec.inc | ||
21 | include disable-interpreters.inc | ||
22 | include disable-passwdmgr.inc | ||
23 | include disable-programs.inc | ||
24 | include disable-xdg.inc | ||
25 | |||
26 | mkdir ${HOME}/.config/straw-viewer | ||
27 | mkdir ${HOME}/.cache/straw-viewer | ||
28 | whitelist ${HOME}/.cache/straw-viewer | ||
29 | whitelist ${HOME}/.config/straw-viewer | ||
30 | whitelist ${DOWNLOADS} | ||
31 | include whitelist-common.inc | ||
32 | include whitelist-usr-share-common.inc | ||
33 | include whitelist-var-common.inc | ||
34 | |||
35 | apparmor | ||
36 | caps.drop all | ||
37 | netfilter | ||
38 | nodvd | ||
39 | nogroups | ||
40 | nonewprivs | ||
41 | noroot | ||
42 | notv | ||
43 | nou2f | ||
44 | novideo | ||
45 | protocol unix,inet,inet6 | ||
46 | seccomp | ||
47 | shell none | ||
48 | tracelog | ||
49 | |||
50 | disable-mnt | ||
51 | private-bin bash,ffmpeg,ffprobe,gtk-straw-viewer,mpv,perl,python*,sh,smplayer,straw-viewer,stty,vlc,wget,which,youtube-dl | ||
52 | private-cache | ||
53 | private-dev | ||
54 | private-etc alsa,alternatives,asound.conf,ca-certificates,crypto-policies,fonts,gtk-2.0,gtk-3.0,host.conf,hostname,hosts,machine-id,mime.types,nsswitch.conf,passwd,pki,pulse,resolv.conf,ssl,X11,xdg | ||
55 | private-tmp | ||
56 | |||
57 | dbus-user none | ||
58 | dbus-system none | ||
diff --git a/etc/profile-m-z/strings.profile b/etc/profile-m-z/strings.profile index 426b2dc1c..09ada1e25 100644 --- a/etc/profile-m-z/strings.profile +++ b/etc/profile-m-z/strings.profile | |||
@@ -38,6 +38,7 @@ nou2f | |||
38 | novideo | 38 | novideo |
39 | protocol unix | 39 | protocol unix |
40 | seccomp | 40 | seccomp |
41 | seccomp.block-secondary | ||
41 | shell none | 42 | shell none |
42 | tracelog | 43 | tracelog |
43 | x11 none | 44 | x11 none |
diff --git a/etc/profile-m-z/supertux2.profile b/etc/profile-m-z/supertux2.profile index ceaae8fbf..9cc023765 100644 --- a/etc/profile-m-z/supertux2.profile +++ b/etc/profile-m-z/supertux2.profile | |||
@@ -36,6 +36,7 @@ nou2f | |||
36 | novideo | 36 | novideo |
37 | protocol unix,netlink | 37 | protocol unix,netlink |
38 | seccomp | 38 | seccomp |
39 | seccomp.block-secondary | ||
39 | shell none | 40 | shell none |
40 | tracelog | 41 | tracelog |
41 | 42 | ||
diff --git a/etc/profile-m-z/supertuxkart.profile b/etc/profile-m-z/supertuxkart.profile index 40b996794..1b20f5d3d 100644 --- a/etc/profile-m-z/supertuxkart.profile +++ b/etc/profile-m-z/supertuxkart.profile | |||
@@ -41,15 +41,17 @@ noroot | |||
41 | notv | 41 | notv |
42 | nou2f | 42 | nou2f |
43 | novideo | 43 | novideo |
44 | protocol unix,inet,inet6 | 44 | protocol unix,inet,inet6,bluetooth |
45 | seccomp | 45 | seccomp |
46 | seccomp.block-secondary | ||
46 | shell none | 47 | shell none |
47 | tracelog | 48 | tracelog |
48 | 49 | ||
49 | disable-mnt | 50 | disable-mnt |
50 | private-bin supertuxkart | 51 | private-bin supertuxkart |
51 | private-cache | 52 | private-cache |
52 | private-dev | 53 | # uncomment the following line if you do not need controller support |
54 | #private-dev | ||
53 | private-etc alternatives,ca-certificates,crypto-policies,drirc,hosts,machine-id,openal,pki,resolv.conf,ssl | 55 | private-etc alternatives,ca-certificates,crypto-policies,drirc,hosts,machine-id,openal,pki,resolv.conf,ssl |
54 | private-tmp | 56 | private-tmp |
55 | private-opt none | 57 | private-opt none |
diff --git a/etc/profile-m-z/thunderbird.profile b/etc/profile-m-z/thunderbird.profile index e3eb73730..b478fbe1e 100644 --- a/etc/profile-m-z/thunderbird.profile +++ b/etc/profile-m-z/thunderbird.profile | |||
@@ -6,6 +6,8 @@ include thunderbird.local | |||
6 | # Persistent global definitions | 6 | # Persistent global definitions |
7 | include globals.local | 7 | include globals.local |
8 | 8 | ||
9 | ignore include whitelist-runuser-common.inc | ||
10 | |||
9 | # writable-run-user and dbus are needed by enigmail | 11 | # writable-run-user and dbus are needed by enigmail |
10 | ignore dbus-user none | 12 | ignore dbus-user none |
11 | ignore dbus-system none | 13 | ignore dbus-system none |
diff --git a/etc/profile-m-z/transmission-common.profile b/etc/profile-m-z/transmission-common.profile index 9d2e8e990..d601f0f15 100644 --- a/etc/profile-m-z/transmission-common.profile +++ b/etc/profile-m-z/transmission-common.profile | |||
@@ -39,6 +39,7 @@ nou2f | |||
39 | novideo | 39 | novideo |
40 | protocol unix,inet,inet6 | 40 | protocol unix,inet,inet6 |
41 | seccomp | 41 | seccomp |
42 | seccomp.block-secondary | ||
42 | shell none | 43 | shell none |
43 | tracelog | 44 | tracelog |
44 | 45 | ||
diff --git a/etc/profile-m-z/vivaldi.profile b/etc/profile-m-z/vivaldi.profile index 541942453..fdeb0307f 100644 --- a/etc/profile-m-z/vivaldi.profile +++ b/etc/profile-m-z/vivaldi.profile | |||
@@ -29,9 +29,13 @@ whitelist ${HOME}/.config/vivaldi | |||
29 | whitelist ${HOME}/.config/vivaldi-snapshot | 29 | whitelist ${HOME}/.config/vivaldi-snapshot |
30 | whitelist ${HOME}/.local/lib/vivaldi | 30 | whitelist ${HOME}/.local/lib/vivaldi |
31 | 31 | ||
32 | #private-bin bash,cat,dirname,readlink,rm,vivaldi,vivaldi-stable,vivaldi-snapshot | ||
33 | |||
32 | # breaks vivaldi sync | 34 | # breaks vivaldi sync |
33 | ignore dbus-user none | 35 | ignore dbus-user none |
34 | ignore dbus-system none | 36 | ignore dbus-system none |
35 | 37 | ||
38 | read-write ${HOME}/.local/lib/vivaldi | ||
39 | |||
36 | # Redirect | 40 | # Redirect |
37 | include chromium-common.profile | 41 | include chromium-common.profile |
diff --git a/etc/profile-m-z/w3m.profile b/etc/profile-m-z/w3m.profile index bd33edd6a..0e172333a 100644 --- a/etc/profile-m-z/w3m.profile +++ b/etc/profile-m-z/w3m.profile | |||
@@ -7,6 +7,11 @@ include w3m.local | |||
7 | # Persistent global definitions | 7 | # Persistent global definitions |
8 | include globals.local | 8 | include globals.local |
9 | 9 | ||
10 | # Uncomment or add to your w3m.local if you want to use w3m-img on a vconsole | ||
11 | #ignore nogroups | ||
12 | #ignore private-dev | ||
13 | #ignore private-etc | ||
14 | |||
10 | noblacklist ${HOME}/.w3m | 15 | noblacklist ${HOME}/.w3m |
11 | 16 | ||
12 | blacklist /tmp/.X11-unix | 17 | blacklist /tmp/.X11-unix |
diff --git a/etc/profile-m-z/wget.profile b/etc/profile-m-z/wget.profile index cdb8f0b93..8a64d2d73 100644 --- a/etc/profile-m-z/wget.profile +++ b/etc/profile-m-z/wget.profile | |||
@@ -44,6 +44,7 @@ nou2f | |||
44 | novideo | 44 | novideo |
45 | protocol unix,inet,inet6 | 45 | protocol unix,inet,inet6 |
46 | seccomp | 46 | seccomp |
47 | seccomp.block-secondary | ||
47 | shell none | 48 | shell none |
48 | tracelog | 49 | tracelog |
49 | 50 | ||
diff --git a/etc/profile-m-z/whois.profile b/etc/profile-m-z/whois.profile index 2af1379e0..a9cecb18d 100644 --- a/etc/profile-m-z/whois.profile +++ b/etc/profile-m-z/whois.profile | |||
@@ -39,6 +39,7 @@ nou2f | |||
39 | novideo | 39 | novideo |
40 | protocol inet,inet6 | 40 | protocol inet,inet6 |
41 | seccomp | 41 | seccomp |
42 | seccomp.block-secondary | ||
42 | shell none | 43 | shell none |
43 | tracelog | 44 | tracelog |
44 | 45 | ||
diff --git a/etc/profile-m-z/wine.profile b/etc/profile-m-z/wine.profile index 901340052..6ac74b9da 100644 --- a/etc/profile-m-z/wine.profile +++ b/etc/profile-m-z/wine.profile | |||
@@ -6,6 +6,7 @@ include wine.local | |||
6 | # Persistent global definitions | 6 | # Persistent global definitions |
7 | include globals.local | 7 | include globals.local |
8 | 8 | ||
9 | noblacklist ${HOME}/.cache/winetricks | ||
9 | noblacklist ${HOME}/.Steam | 10 | noblacklist ${HOME}/.Steam |
10 | noblacklist ${HOME}/.local/share/Steam | 11 | noblacklist ${HOME}/.local/share/Steam |
11 | noblacklist ${HOME}/.local/share/steam | 12 | noblacklist ${HOME}/.local/share/steam |
@@ -19,6 +20,8 @@ include disable-interpreters.inc | |||
19 | include disable-passwdmgr.inc | 20 | include disable-passwdmgr.inc |
20 | include disable-programs.inc | 21 | include disable-programs.inc |
21 | 22 | ||
23 | # whitelist /usr/share/wine | ||
24 | # include whitelist-usr-share-common.inc | ||
22 | include whitelist-var-common.inc | 25 | include whitelist-var-common.inc |
23 | 26 | ||
24 | # some applications don't need allow-debuggers, comment the next line | 27 | # some applications don't need allow-debuggers, comment the next line |
diff --git a/etc/profile-m-z/xfce4-mixer.profile b/etc/profile-m-z/xfce4-mixer.profile index 6ff4a1103..78cb2862c 100644 --- a/etc/profile-m-z/xfce4-mixer.profile +++ b/etc/profile-m-z/xfce4-mixer.profile | |||
@@ -19,6 +19,7 @@ include disable-xdg.inc | |||
19 | 19 | ||
20 | mkfile ${HOME}/.config/xfce4/xfconf/xfce-perchannel-xml/xfce4-mixer.xml | 20 | mkfile ${HOME}/.config/xfce4/xfconf/xfce-perchannel-xml/xfce4-mixer.xml |
21 | whitelist ${HOME}/.config/xfce4/xfconf/xfce-perchannel-xml/xfce4-mixer.xml | 21 | whitelist ${HOME}/.config/xfce4/xfconf/xfce-perchannel-xml/xfce4-mixer.xml |
22 | whitelist /usr/share/gstreamer | ||
22 | whitelist /usr/share/xfce4 | 23 | whitelist /usr/share/xfce4 |
23 | whitelist /usr/share/xfce4-mixer | 24 | whitelist /usr/share/xfce4-mixer |
24 | include whitelist-common.inc | 25 | include whitelist-common.inc |
@@ -48,7 +49,9 @@ private-dev | |||
48 | private-etc alternatives,asound.conf,fonts,machine-id,pulse | 49 | private-etc alternatives,asound.conf,fonts,machine-id,pulse |
49 | private-tmp | 50 | private-tmp |
50 | 51 | ||
51 | # dbus-user none | 52 | dbus-user filter |
52 | # dbus-system none | 53 | dbus-user.own org.xfce.xfce4-mixer |
54 | dbus-user.talk org.xfce.Xfconf | ||
55 | dbus-system none | ||
53 | 56 | ||
54 | memory-deny-write-execute | 57 | # memory-deny-write-execute - breaks on Arch |
diff --git a/etc/profile-m-z/xfce4-screenshooter.profile b/etc/profile-m-z/xfce4-screenshooter.profile index b760b44dd..c9200304c 100644 --- a/etc/profile-m-z/xfce4-screenshooter.profile +++ b/etc/profile-m-z/xfce4-screenshooter.profile | |||
@@ -48,4 +48,4 @@ private-tmp | |||
48 | dbus-user none | 48 | dbus-user none |
49 | dbus-system none | 49 | dbus-system none |
50 | 50 | ||
51 | memory-deny-write-execute | 51 | # memory-deny-write-execute -- see #3790 |
diff --git a/etc/profile-m-z/xournal.profile b/etc/profile-m-z/xournal.profile index b842b5307..0c6969e09 100644 --- a/etc/profile-m-z/xournal.profile +++ b/etc/profile-m-z/xournal.profile | |||
@@ -36,6 +36,7 @@ nou2f | |||
36 | novideo | 36 | novideo |
37 | protocol unix | 37 | protocol unix |
38 | seccomp | 38 | seccomp |
39 | seccomp.block-secondary | ||
39 | shell none | 40 | shell none |
40 | tracelog | 41 | tracelog |
41 | 42 | ||
diff --git a/etc/profile-m-z/yelp.profile b/etc/profile-m-z/yelp.profile index fd95ceb04..3ba1dca1a 100644 --- a/etc/profile-m-z/yelp.profile +++ b/etc/profile-m-z/yelp.profile | |||
@@ -20,7 +20,9 @@ include disable-xdg.inc | |||
20 | mkdir ${HOME}/.config/yelp | 20 | mkdir ${HOME}/.config/yelp |
21 | whitelist ${HOME}/.config/yelp | 21 | whitelist ${HOME}/.config/yelp |
22 | whitelist /usr/share/doc | 22 | whitelist /usr/share/doc |
23 | whitelist /usr/share/groff | ||
23 | whitelist /usr/share/help | 24 | whitelist /usr/share/help |
25 | whitelist /usr/share/man | ||
24 | whitelist /usr/share/yelp | 26 | whitelist /usr/share/yelp |
25 | whitelist /usr/share/yelp-tools | 27 | whitelist /usr/share/yelp-tools |
26 | whitelist /usr/share/yelp-xsl | 28 | whitelist /usr/share/yelp-xsl |
@@ -41,14 +43,15 @@ nou2f | |||
41 | novideo | 43 | novideo |
42 | protocol unix | 44 | protocol unix |
43 | seccomp | 45 | seccomp |
46 | seccomp.block-secondary | ||
44 | shell none | 47 | shell none |
45 | tracelog | 48 | tracelog |
46 | 49 | ||
47 | disable-mnt | 50 | disable-mnt |
48 | private-bin yelp | 51 | private-bin groff,man,tbl,troff,yelp |
49 | private-cache | 52 | private-cache |
50 | private-dev | 53 | private-dev |
51 | private-etc alsa,alternatives,asound.conf,crypto-policies,cups,dconf,drirc,fonts,gcrypt,gtk-3.0,machine-id,openal,os-release,pulse,sgml,xml | 54 | private-etc alsa,alternatives,asound.conf,crypto-policies,cups,dconf,drirc,fonts,gcrypt,groff,gtk-3.0,machine-id,man_db.conf,openal,os-release,pulse,sgml,xml |
52 | private-tmp | 55 | private-tmp |
53 | 56 | ||
54 | dbus-system none | 57 | dbus-system none |
@@ -59,3 +62,4 @@ dbus-system none | |||
59 | # 1. yelp --editor-mode | 62 | # 1. yelp --editor-mode |
60 | # 2. saving the window geometry | 63 | # 2. saving the window geometry |
61 | read-only ${HOME} | 64 | read-only ${HOME} |
65 | read-write ${HOME}/.cache | ||
diff --git a/etc/profile-m-z/youtube-dl.profile b/etc/profile-m-z/youtube-dl.profile index db3535f78..d9dee6891 100644 --- a/etc/profile-m-z/youtube-dl.profile +++ b/etc/profile-m-z/youtube-dl.profile | |||
@@ -52,6 +52,7 @@ nou2f | |||
52 | novideo | 52 | novideo |
53 | protocol unix,inet,inet6 | 53 | protocol unix,inet,inet6 |
54 | seccomp | 54 | seccomp |
55 | seccomp.block-secondary | ||
55 | shell none | 56 | shell none |
56 | tracelog | 57 | tracelog |
57 | 58 | ||
diff --git a/etc/profile-m-z/youtube-viewer.profile b/etc/profile-m-z/youtube-viewer.profile index 513cb0f6e..a3a2afa29 100644 --- a/etc/profile-m-z/youtube-viewer.profile +++ b/etc/profile-m-z/youtube-viewer.profile | |||
@@ -7,10 +7,6 @@ include youtube-viewer.local | |||
7 | # Persistent global definitions | 7 | # Persistent global definitions |
8 | include globals.local | 8 | include globals.local |
9 | 9 | ||
10 | blacklist /tmp/.X11-unix | ||
11 | blacklist ${RUNUSER}/wayland-* | ||
12 | blacklist ${RUNUSER} | ||
13 | |||
14 | noblacklist ${HOME}/.config/youtube-viewer | 10 | noblacklist ${HOME}/.config/youtube-viewer |
15 | 11 | ||
16 | include allow-perl.inc | 12 | include allow-perl.inc |
@@ -47,11 +43,11 @@ shell none | |||
47 | tracelog | 43 | tracelog |
48 | 44 | ||
49 | disable-mnt | 45 | disable-mnt |
50 | # private-bin ffmpeg,ffprobe,firefox,gtk-youtube-viewer,gtk2-youtube-viewer,gtk3-youtube-viewer,mpv,python*,smplayer,sh,which,vlc,youtube-dl,youtube-viewer | 46 | private-bin ffmpeg,ffprobe,firefox,gtk-youtube-viewer,gtk2-youtube-viewer,gtk3-youtube-viewer,mpv,python*,sh,smplayer,stty,vlc,which,youtube-dl,youtube-viewer |
51 | private-cache | 47 | private-cache |
52 | private-dev | 48 | private-dev |
53 | private-etc alsa,alternatives,asound.conf,ca-certificates,crypto-policies,fonts,gtk-2.0,gtk-3.0,host.conf,hostname,hosts,machine-id,mime.types,nsswitch.conf,passwd,pki,pulse,resolv.conf,ssl,X11,xdg | 49 | private-etc alsa,alternatives,asound.conf,ca-certificates,crypto-policies,fonts,gtk-2.0,gtk-3.0,host.conf,hostname,hosts,machine-id,mime.types,nsswitch.conf,passwd,pki,pulse,resolv.conf,ssl,X11,xdg |
54 | private-tmp | 50 | private-tmp |
55 | 51 | ||
56 | dbus-user none | 52 | dbus-user none |
57 | dbus-system none \ No newline at end of file | 53 | dbus-system none |
diff --git a/etc/profile-m-z/zathura.profile b/etc/profile-m-z/zathura.profile index 5274e5b42..86615341f 100644 --- a/etc/profile-m-z/zathura.profile +++ b/etc/profile-m-z/zathura.profile | |||
@@ -28,7 +28,6 @@ include whitelist-var-common.inc | |||
28 | 28 | ||
29 | apparmor | 29 | apparmor |
30 | caps.drop all | 30 | caps.drop all |
31 | ipc-namespace | ||
32 | machine-id | 31 | machine-id |
33 | net none | 32 | net none |
34 | nodvd | 33 | nodvd |