aboutsummaryrefslogtreecommitdiffstats
path: root/etc/profile-m-z
diff options
context:
space:
mode:
Diffstat (limited to 'etc/profile-m-z')
-rw-r--r--etc/profile-m-z/Thunar.profile27
-rw-r--r--etc/profile-m-z/nautilus.profile35
-rw-r--r--etc/profile-m-z/nemo.profile32
-rw-r--r--etc/profile-m-z/pcmanfm.profile29
-rw-r--r--etc/profile-m-z/ranger.profile38
5 files changed, 15 insertions, 146 deletions
diff --git a/etc/profile-m-z/Thunar.profile b/etc/profile-m-z/Thunar.profile
index 761440ccc..28acb414b 100644
--- a/etc/profile-m-z/Thunar.profile
+++ b/etc/profile-m-z/Thunar.profile
@@ -6,28 +6,7 @@ include Thunar.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.local/share/Trash 9# Put 'ignore noroot' in your pcmanfm.local if you use MPV+Vulkan (see issue #3012)
10noblacklist ${HOME}/.config/Thunar
11noblacklist ${HOME}/.config/xfce4/xfconf/xfce-perchannel-xml/thunar.xml
12 10
13include disable-common.inc 11# Redirect
14include disable-devel.inc 12include file-manager-common.profile
15include disable-interpreters.inc
16include disable-passwdmgr.inc
17# include disable-programs.inc
18
19allusers
20caps.drop all
21netfilter
22no3d
23nodvd
24nogroups
25nonewprivs
26noroot
27nosound
28notv
29novideo
30protocol unix
31seccomp
32shell none
33tracelog
diff --git a/etc/profile-m-z/nautilus.profile b/etc/profile-m-z/nautilus.profile
index e003488de..e54bea228 100644
--- a/etc/profile-m-z/nautilus.profile
+++ b/etc/profile-m-z/nautilus.profile
@@ -9,36 +9,7 @@ include globals.local
9# Nautilus is started by systemd on most systems. Therefore it is not firejailed by default. Since there 9# Nautilus is started by systemd on most systems. Therefore it is not firejailed by default. Since there
10# is already a nautilus process running on gnome desktops firejail will have no effect. 10# is already a nautilus process running on gnome desktops firejail will have no effect.
11 11
12noblacklist ${HOME}/.config/nautilus 12# Put 'ignore noroot' in your nautilus.local if you use MPV+Vulkan (see issue #3012)
13noblacklist ${HOME}/.local/share/Trash
14noblacklist ${HOME}/.local/share/nautilus
15noblacklist ${HOME}/.local/share/nautilus-python
16 13
17# Allow python (blacklisted by disable-interpreters.inc) 14# Redirect
18include allow-python2.inc 15include file-manager-common.profile
19include allow-python3.inc
20
21include disable-common.inc
22include disable-devel.inc
23include disable-interpreters.inc
24include disable-passwdmgr.inc
25# include disable-programs.inc
26
27allusers
28caps.drop all
29netfilter
30nodvd
31nogroups
32nonewprivs
33noroot
34notv
35novideo
36protocol unix
37seccomp
38shell none
39tracelog
40
41# nautilus needs to be able to start arbitrary applications so we cannot blacklist their files
42# private-bin nautilus
43# private-dev
44# private-tmp
diff --git a/etc/profile-m-z/nemo.profile b/etc/profile-m-z/nemo.profile
index 6a62a3a0c..1b3333e8c 100644
--- a/etc/profile-m-z/nemo.profile
+++ b/etc/profile-m-z/nemo.profile
@@ -6,33 +6,7 @@ include nemo.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/nemo 9# Put 'ignore noroot' in your nemo.local if you use MPV+Vulkan (see issue #3012)
10noblacklist ${HOME}/.local/share/Trash
11noblacklist ${HOME}/.local/share/nemo
12noblacklist ${HOME}/.local/share/nemo-python
13
14# Allow python (blacklisted by disable-interpreters.inc)
15include allow-python2.inc
16include allow-python3.inc
17
18include disable-common.inc
19include disable-devel.inc
20include disable-exec.inc
21include disable-interpreters.inc
22include disable-passwdmgr.inc
23
24allusers
25caps.drop all
26netfilter
27no3d
28nodvd
29nogroups
30nonewprivs
31noroot
32nosound
33notv
34novideo
35protocol unix,inet,inet6
36seccomp
37shell none
38 10
11# Redirect
12include file-manager-common.profile
diff --git a/etc/profile-m-z/pcmanfm.profile b/etc/profile-m-z/pcmanfm.profile
index 4e53f9d6e..5718ab164 100644
--- a/etc/profile-m-z/pcmanfm.profile
+++ b/etc/profile-m-z/pcmanfm.profile
@@ -6,30 +6,7 @@ include pcmanfm.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.local/share/Trash 9# Put 'ignore noroot' in your pcmanfm.local if you use MPV+Vulkan (see issue #3012)
10# noblacklist ${HOME}/.config/libfm - disable-programs.inc is disabled, see below
11# noblacklist ${HOME}/.config/pcmanfm
12 10
13include disable-common.inc 11# Redirect
14include disable-devel.inc 12include file-manager-common.profile
15include disable-interpreters.inc
16include disable-passwdmgr.inc
17# include disable-programs.inc
18
19allusers
20caps.drop all
21# net none - see issue #1467, computer:/// location broken
22no3d
23nodvd
24nonewprivs
25noroot
26nosound
27notv
28novideo
29protocol unix
30seccomp
31shell none
32tracelog
33
34# dbus-user none
35# dbus-system none
diff --git a/etc/profile-m-z/ranger.profile b/etc/profile-m-z/ranger.profile
index af033af1a..8b3fe97d8 100644
--- a/etc/profile-m-z/ranger.profile
+++ b/etc/profile-m-z/ranger.profile
@@ -6,39 +6,7 @@ include ranger.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9noblacklist ${HOME}/.config/nano 9# Put 'ignore noroot' in your ranger.local if you use MPV+Vulkan (see issue #3012)
10noblacklist ${HOME}/.config/ranger
11noblacklist ${HOME}/.nanorc
12 10
13# Allow python (blacklisted by disable-interpreters.inc) 11# Redirect
14include allow-python2.inc 12include file-manager-common.profile
15include allow-python3.inc
16
17# Allow perl
18include allow-perl.inc
19
20include disable-common.inc
21include disable-devel.inc
22include disable-interpreters.inc
23include disable-passwdmgr.inc
24include disable-programs.inc
25
26allusers
27caps.drop all
28net none
29nodvd
30nogroups
31nonewprivs
32noroot
33nosound
34notv
35nou2f
36novideo
37protocol unix
38seccomp
39#x11 none
40
41private-dev
42
43dbus-user none
44dbus-system none