aboutsummaryrefslogtreecommitdiffstats
path: root/etc/profile-m-z
diff options
context:
space:
mode:
Diffstat (limited to 'etc/profile-m-z')
-rw-r--r--etc/profile-m-z/Maelstrom.profile1
-rw-r--r--etc/profile-m-z/QMediathekView.profile1
-rw-r--r--etc/profile-m-z/QOwnNotes.profile1
-rw-r--r--etc/profile-m-z/XMind.profile1
-rw-r--r--etc/profile-m-z/Xephyr.profile1
-rw-r--r--etc/profile-m-z/Xvfb.profile1
-rw-r--r--etc/profile-m-z/ZeGrapher.profile1
-rw-r--r--etc/profile-m-z/macrofusion.profile1
-rw-r--r--etc/profile-m-z/magicor.profile1
-rw-r--r--etc/profile-m-z/man.profile1
-rw-r--r--etc/profile-m-z/manaplus.profile1
-rw-r--r--etc/profile-m-z/marker.profile1
-rw-r--r--etc/profile-m-z/masterpdfeditor.profile1
-rw-r--r--etc/profile-m-z/mate-calc.profile1
-rw-r--r--etc/profile-m-z/mate-color-select.profile1
-rw-r--r--etc/profile-m-z/mate-dictionary.profile1
-rw-r--r--etc/profile-m-z/mcabber.profile1
-rw-r--r--etc/profile-m-z/mdr.profile1
-rw-r--r--etc/profile-m-z/mediainfo.profile1
-rw-r--r--etc/profile-m-z/mediathekview.profile1
-rw-r--r--etc/profile-m-z/megaglest.profile1
-rw-r--r--etc/profile-m-z/meld.profile1
-rw-r--r--etc/profile-m-z/mendeleydesktop.profile1
-rw-r--r--etc/profile-m-z/menulibre.profile1
-rw-r--r--etc/profile-m-z/meteo-qt.profile1
-rw-r--r--etc/profile-m-z/mindless.profile1
-rw-r--r--etc/profile-m-z/minecraft-launcher.profile7
-rw-r--r--etc/profile-m-z/minetest.profile1
-rw-r--r--etc/profile-m-z/minitube.profile1
-rw-r--r--etc/profile-m-z/mirage.profile1
-rw-r--r--etc/profile-m-z/mirrormagic.profile1
-rw-r--r--etc/profile-m-z/mocp.profile1
-rw-r--r--etc/profile-m-z/mousepad.profile1
-rw-r--r--etc/profile-m-z/mp3splt-gtk.profile1
-rw-r--r--etc/profile-m-z/mp3splt.profile1
-rw-r--r--etc/profile-m-z/mpDris2.profile1
-rw-r--r--etc/profile-m-z/mpd.profile1
-rw-r--r--etc/profile-m-z/mpg123.profile1
-rw-r--r--etc/profile-m-z/mplayer.profile1
-rw-r--r--etc/profile-m-z/mpsyt.profile1
-rw-r--r--etc/profile-m-z/mpv.profile1
-rw-r--r--etc/profile-m-z/mrrescue.profile10
-rw-r--r--etc/profile-m-z/ms-office.profile1
-rw-r--r--etc/profile-m-z/mtpaint.profile1
-rw-r--r--etc/profile-m-z/multimc5.profile1
-rw-r--r--etc/profile-m-z/mupdf.profile1
-rw-r--r--etc/profile-m-z/musictube.profile1
-rw-r--r--etc/profile-m-z/musixmatch.profile2
-rw-r--r--etc/profile-m-z/mutt.profile1
-rw-r--r--etc/profile-m-z/mypaint.profile1
-rw-r--r--etc/profile-m-z/nano.profile7
-rw-r--r--etc/profile-m-z/ncdu.profile1
-rw-r--r--etc/profile-m-z/neochat.profile66
-rw-r--r--etc/profile-m-z/neomutt.profile1
-rw-r--r--etc/profile-m-z/netactview.profile1
-rw-r--r--etc/profile-m-z/nethack-vultures.profile1
-rw-r--r--etc/profile-m-z/nethack.profile1
-rw-r--r--etc/profile-m-z/neverball-wrapper.profile14
-rw-r--r--etc/profile-m-z/neverball.profile17
-rw-r--r--etc/profile-m-z/neverputt-wrapper.profile14
-rw-r--r--etc/profile-m-z/newsboat.profile1
-rw-r--r--etc/profile-m-z/newsflash.profile1
-rw-r--r--etc/profile-m-z/nextcloud.profile1
-rw-r--r--etc/profile-m-z/nheko.profile1
-rw-r--r--etc/profile-m-z/nicotine.profile1
-rw-r--r--etc/profile-m-z/nitroshare.profile1
-rw-r--r--etc/profile-m-z/node.profile11
-rw-r--r--etc/profile-m-z/nodejs-common.profile50
-rw-r--r--etc/profile-m-z/nomacs.profile1
-rw-r--r--etc/profile-m-z/notify-send.profile1
-rw-r--r--etc/profile-m-z/npm.profile18
-rw-r--r--etc/profile-m-z/nslookup.profile1
-rw-r--r--etc/profile-m-z/nvm.profile13
-rw-r--r--etc/profile-m-z/nylas.profile1
-rw-r--r--etc/profile-m-z/nyx.profile1
-rw-r--r--etc/profile-m-z/obs.profile1
-rw-r--r--etc/profile-m-z/ocenaudio.profile1
-rw-r--r--etc/profile-m-z/odt2txt.profile1
-rw-r--r--etc/profile-m-z/okular.profile9
-rw-r--r--etc/profile-m-z/onboard.profile1
-rw-r--r--etc/profile-m-z/onionshare-gui.profile1
-rw-r--r--etc/profile-m-z/open-invaders.profile1
-rw-r--r--etc/profile-m-z/openarena.profile1
-rw-r--r--etc/profile-m-z/opencity.profile1
-rw-r--r--etc/profile-m-z/openclonk.profile1
-rw-r--r--etc/profile-m-z/openmw.profile1
-rw-r--r--etc/profile-m-z/openshot.profile1
-rw-r--r--etc/profile-m-z/openttd.profile1
-rw-r--r--etc/profile-m-z/orage.profile1
-rw-r--r--etc/profile-m-z/ostrichriders.profile3
-rw-r--r--etc/profile-m-z/otter-browser.profile1
-rw-r--r--etc/profile-m-z/pandoc.profile1
-rw-r--r--etc/profile-m-z/patch.profile1
-rw-r--r--etc/profile-m-z/pavucontrol.profile1
-rw-r--r--etc/profile-m-z/pdfchain.profile1
-rw-r--r--etc/profile-m-z/pdfmod.profile1
-rw-r--r--etc/profile-m-z/pdfsam.profile1
-rw-r--r--etc/profile-m-z/pdftotext.profile1
-rw-r--r--etc/profile-m-z/peek.profile1
-rw-r--r--etc/profile-m-z/penguin-command.profile1
-rw-r--r--etc/profile-m-z/photoflare.profile1
-rw-r--r--etc/profile-m-z/picard.profile1
-rw-r--r--etc/profile-m-z/pidgin.profile1
-rw-r--r--etc/profile-m-z/pinball-wrapper.profile14
-rw-r--r--etc/profile-m-z/pinball.profile53
-rw-r--r--etc/profile-m-z/ping.profile1
-rw-r--r--etc/profile-m-z/pingus.profile6
-rw-r--r--etc/profile-m-z/pinta.profile1
-rw-r--r--etc/profile-m-z/pioneer.profile1
-rw-r--r--etc/profile-m-z/pithos.profile1
-rw-r--r--etc/profile-m-z/pitivi.profile1
-rw-r--r--etc/profile-m-z/pix.profile1
-rw-r--r--etc/profile-m-z/pkglog.profile1
-rw-r--r--etc/profile-m-z/pluma.profile3
-rw-r--r--etc/profile-m-z/plv.profile1
-rw-r--r--etc/profile-m-z/pngquant.profile1
-rw-r--r--etc/profile-m-z/polari.profile1
-rw-r--r--etc/profile-m-z/pragha.profile1
-rw-r--r--etc/profile-m-z/profanity.profile1
-rw-r--r--etc/profile-m-z/psi-plus.profile1
-rw-r--r--etc/profile-m-z/psi.profile1
-rw-r--r--etc/profile-m-z/pybitmessage.profile1
-rw-r--r--etc/profile-m-z/pycharm-community.profile1
-rw-r--r--etc/profile-m-z/qbittorrent.profile1
-rw-r--r--etc/profile-m-z/qgis.profile1
-rw-r--r--etc/profile-m-z/qlipper.profile1
-rw-r--r--etc/profile-m-z/qmmp.profile1
-rw-r--r--etc/profile-m-z/qnapi.profile1
-rw-r--r--etc/profile-m-z/qpdfview.profile1
-rw-r--r--etc/profile-m-z/qrencode.profile1
-rw-r--r--etc/profile-m-z/qtox.profile1
-rw-r--r--etc/profile-m-z/quaternion.profile1
-rw-r--r--etc/profile-m-z/quiterss.profile1
-rw-r--r--etc/profile-m-z/quodlibet.profile1
-rw-r--r--etc/profile-m-z/redeclipse.profile1
-rw-r--r--etc/profile-m-z/redshift.profile1
-rw-r--r--etc/profile-m-z/regextester.profile12
-rw-r--r--etc/profile-m-z/remmina.profile1
-rw-r--r--etc/profile-m-z/rhythmbox.profile1
-rw-r--r--etc/profile-m-z/ricochet.profile1
-rw-r--r--etc/profile-m-z/ripperx.profile1
-rw-r--r--etc/profile-m-z/ristretto.profile1
-rw-r--r--etc/profile-m-z/rsync-download_only.profile1
-rw-r--r--etc/profile-m-z/rtorrent.profile1
-rw-r--r--etc/profile-m-z/rtv.profile1
-rw-r--r--etc/profile-m-z/sayonara.profile1
-rw-r--r--etc/profile-m-z/scallion.profile1
-rw-r--r--etc/profile-m-z/scorched3d-wrapper.profile7
-rw-r--r--etc/profile-m-z/scorched3d.profile3
-rw-r--r--etc/profile-m-z/scorchwentbonkers.profile1
-rw-r--r--etc/profile-m-z/scribus.profile1
-rw-r--r--etc/profile-m-z/sdat2img.profile1
-rw-r--r--etc/profile-m-z/seahorse-adventures.profile1
-rw-r--r--etc/profile-m-z/seahorse.profile1
-rw-r--r--etc/profile-m-z/server.profile1
-rw-r--r--etc/profile-m-z/servo.profile1
-rw-r--r--etc/profile-m-z/shellcheck.profile1
-rw-r--r--etc/profile-m-z/shortwave.profile1
-rw-r--r--etc/profile-m-z/shotcut.profile1
-rw-r--r--etc/profile-m-z/shotwell.profile1
-rw-r--r--etc/profile-m-z/signal-cli.profile1
-rw-r--r--etc/profile-m-z/silentarmy.profile1
-rw-r--r--etc/profile-m-z/simplescreenrecorder.profile1
-rw-r--r--etc/profile-m-z/simutrans.profile1
-rw-r--r--etc/profile-m-z/slashem.profile1
-rw-r--r--etc/profile-m-z/smplayer.profile1
-rw-r--r--etc/profile-m-z/smtube.profile1
-rw-r--r--etc/profile-m-z/smuxi-frontend-gnome.profile1
-rw-r--r--etc/profile-m-z/softmaker-common.profile1
-rw-r--r--etc/profile-m-z/sol.profile1
-rw-r--r--etc/profile-m-z/sound-juicer.profile1
-rw-r--r--etc/profile-m-z/soundconverter.profile1
-rw-r--r--etc/profile-m-z/spectacle.profile3
-rw-r--r--etc/profile-m-z/spectral.profile1
-rw-r--r--etc/profile-m-z/spotify.profile3
-rw-r--r--etc/profile-m-z/sqlitebrowser.profile1
-rw-r--r--etc/profile-m-z/ssh.profile1
-rw-r--r--etc/profile-m-z/standardnotes-desktop.profile1
-rw-r--r--etc/profile-m-z/steam.profile39
-rw-r--r--etc/profile-m-z/stellarium.profile1
-rw-r--r--etc/profile-m-z/straw-viewer.profile1
-rw-r--r--etc/profile-m-z/strawberry.profile1
-rw-r--r--etc/profile-m-z/strings.profile1
-rw-r--r--etc/profile-m-z/subdownloader.profile1
-rw-r--r--etc/profile-m-z/supertux2.profile4
-rw-r--r--etc/profile-m-z/supertuxkart-wrapper.profile14
-rw-r--r--etc/profile-m-z/surf.profile1
-rw-r--r--etc/profile-m-z/sushi.profile1
-rw-r--r--etc/profile-m-z/synfigstudio.profile1
-rw-r--r--etc/profile-m-z/sysprof.profile17
-rw-r--r--etc/profile-m-z/tcpdump.profile1
-rw-r--r--etc/profile-m-z/teamspeak3.profile1
-rw-r--r--etc/profile-m-z/teeworlds.profile1
-rw-r--r--etc/profile-m-z/telegram.profile1
-rw-r--r--etc/profile-m-z/terasology.profile1
-rw-r--r--etc/profile-m-z/tmux.profile1
-rw-r--r--etc/profile-m-z/tor.profile1
-rw-r--r--etc/profile-m-z/torbrowser-launcher.profile1
-rw-r--r--etc/profile-m-z/torcs.profile1
-rw-r--r--etc/profile-m-z/totem.profile1
-rw-r--r--etc/profile-m-z/transgui.profile1
-rw-r--r--etc/profile-m-z/transmission-common.profile1
-rw-r--r--etc/profile-m-z/tremulous.profile1
-rw-r--r--etc/profile-m-z/trojita.profile1
-rw-r--r--etc/profile-m-z/truecraft.profile1
-rw-r--r--etc/profile-m-z/tuxguitar.profile1
-rw-r--r--etc/profile-m-z/tvbrowser.profile1
-rw-r--r--etc/profile-m-z/udiskie.profile1
-rw-r--r--etc/profile-m-z/uefitool.profile1
-rw-r--r--etc/profile-m-z/uget-gtk.profile1
-rw-r--r--etc/profile-m-z/unbound.profile1
-rw-r--r--etc/profile-m-z/unf.profile1
-rw-r--r--etc/profile-m-z/unknown-horizons.profile1
-rw-r--r--etc/profile-m-z/utox.profile1
-rw-r--r--etc/profile-m-z/uudeview.profile1
-rw-r--r--etc/profile-m-z/viewnior.profile1
-rw-r--r--etc/profile-m-z/viking.profile1
-rw-r--r--etc/profile-m-z/vim.profile1
-rw-r--r--etc/profile-m-z/virtualbox.profile2
-rw-r--r--etc/profile-m-z/vlc.profile1
-rw-r--r--etc/profile-m-z/vmware-view.profile1
-rw-r--r--etc/profile-m-z/vym.profile1
-rw-r--r--etc/profile-m-z/w3m.profile1
-rw-r--r--etc/profile-m-z/warmux.profile1
-rw-r--r--etc/profile-m-z/warsow.profile1
-rw-r--r--etc/profile-m-z/warzone2100.profile1
-rw-r--r--etc/profile-m-z/webstorm.profile1
-rw-r--r--etc/profile-m-z/webui-aria2.profile1
-rw-r--r--etc/profile-m-z/wesnoth.profile1
-rw-r--r--etc/profile-m-z/wget.profile1
-rw-r--r--etc/profile-m-z/whois.profile1
-rw-r--r--etc/profile-m-z/widelands.profile1
-rw-r--r--etc/profile-m-z/wine.profile1
-rw-r--r--etc/profile-m-z/wireshark.profile7
-rw-r--r--etc/profile-m-z/wordwarvi.profile1
-rw-r--r--etc/profile-m-z/wps.profile1
-rw-r--r--etc/profile-m-z/x-terminal-emulator.profile1
-rw-r--r--etc/profile-m-z/x2goclient.profile1
-rw-r--r--etc/profile-m-z/xbill.profile1
-rw-r--r--etc/profile-m-z/xcalc.profile1
-rw-r--r--etc/profile-m-z/xed.profile1
-rw-r--r--etc/profile-m-z/xfce4-dict.profile1
-rw-r--r--etc/profile-m-z/xfce4-mixer.profile3
-rw-r--r--etc/profile-m-z/xfce4-notes.profile1
-rw-r--r--etc/profile-m-z/xfce4-screenshooter.profile1
-rw-r--r--etc/profile-m-z/xiphos.profile1
-rw-r--r--etc/profile-m-z/xmms.profile1
-rw-r--r--etc/profile-m-z/xmr-stak.profile1
-rw-r--r--etc/profile-m-z/xonotic.profile7
-rw-r--r--etc/profile-m-z/xournal.profile1
-rw-r--r--etc/profile-m-z/xpdf.profile1
-rw-r--r--etc/profile-m-z/xplayer.profile1
-rw-r--r--etc/profile-m-z/xpra.profile1
-rw-r--r--etc/profile-m-z/xreader.profile1
-rw-r--r--etc/profile-m-z/xviewer.profile1
-rw-r--r--etc/profile-m-z/yarn.profile20
-rw-r--r--etc/profile-m-z/yelp.profile1
-rw-r--r--etc/profile-m-z/youtube-dl-gui.profile1
-rw-r--r--etc/profile-m-z/youtube-dl.profile1
-rw-r--r--etc/profile-m-z/youtube-viewer.profile1
-rw-r--r--etc/profile-m-z/zaproxy.profile1
-rw-r--r--etc/profile-m-z/zart.profile1
-rw-r--r--etc/profile-m-z/zathura.profile1
-rw-r--r--etc/profile-m-z/zeal.profile1
-rw-r--r--etc/profile-m-z/zulip.profile1
265 files changed, 607 insertions, 84 deletions
diff --git a/etc/profile-m-z/Maelstrom.profile b/etc/profile-m-z/Maelstrom.profile
index 77bce4179..62d0a8b3a 100644
--- a/etc/profile-m-z/Maelstrom.profile
+++ b/etc/profile-m-z/Maelstrom.profile
@@ -26,6 +26,7 @@ ipc-namespace
26net none 26net none
27nodvd 27nodvd
28nogroups 28nogroups
29noinput
29#nonewprivs 30#nonewprivs
30#noroot 31#noroot
31notv 32notv
diff --git a/etc/profile-m-z/QMediathekView.profile b/etc/profile-m-z/QMediathekView.profile
index 5ab302218..86120587b 100644
--- a/etc/profile-m-z/QMediathekView.profile
+++ b/etc/profile-m-z/QMediathekView.profile
@@ -37,6 +37,7 @@ netfilter
37# no3d 37# no3d
38nodvd 38nodvd
39nogroups 39nogroups
40noinput
40nonewprivs 41nonewprivs
41noroot 42noroot
42notv 43notv
diff --git a/etc/profile-m-z/QOwnNotes.profile b/etc/profile-m-z/QOwnNotes.profile
index e2dcf17e0..660378089 100644
--- a/etc/profile-m-z/QOwnNotes.profile
+++ b/etc/profile-m-z/QOwnNotes.profile
@@ -36,6 +36,7 @@ netfilter
36no3d 36no3d
37nodvd 37nodvd
38nogroups 38nogroups
39noinput
39nonewprivs 40nonewprivs
40noroot 41noroot
41nosound 42nosound
diff --git a/etc/profile-m-z/XMind.profile b/etc/profile-m-z/XMind.profile
index 7e7c0c3cd..d78e04595 100644
--- a/etc/profile-m-z/XMind.profile
+++ b/etc/profile-m-z/XMind.profile
@@ -23,6 +23,7 @@ caps.drop all
23netfilter 23netfilter
24nodvd 24nodvd
25nogroups 25nogroups
26noinput
26nonewprivs 27nonewprivs
27noroot 28noroot
28notv 29notv
diff --git a/etc/profile-m-z/Xephyr.profile b/etc/profile-m-z/Xephyr.profile
index ab5fdf942..5cf5161ce 100644
--- a/etc/profile-m-z/Xephyr.profile
+++ b/etc/profile-m-z/Xephyr.profile
@@ -22,6 +22,7 @@ caps.drop all
22# Xephyr needs to be allowed access to the abstract Unix socket namespace. 22# Xephyr needs to be allowed access to the abstract Unix socket namespace.
23nodvd 23nodvd
24nogroups 24nogroups
25noinput
25nonewprivs 26nonewprivs
26# In noroot mode, Xephyr cannot create a socket in the real /tmp/.X11-unix. 27# In noroot mode, Xephyr cannot create a socket in the real /tmp/.X11-unix.
27# noroot 28# noroot
diff --git a/etc/profile-m-z/Xvfb.profile b/etc/profile-m-z/Xvfb.profile
index 937d02d60..1acd43023 100644
--- a/etc/profile-m-z/Xvfb.profile
+++ b/etc/profile-m-z/Xvfb.profile
@@ -25,6 +25,7 @@ caps.drop all
25# Xvfb needs to be allowed access to the abstract Unix socket namespace. 25# Xvfb needs to be allowed access to the abstract Unix socket namespace.
26nodvd 26nodvd
27nogroups 27nogroups
28noinput
28nonewprivs 29nonewprivs
29# In noroot mode, Xvfb cannot create a socket in the real /tmp/.X11-unix. 30# In noroot mode, Xvfb cannot create a socket in the real /tmp/.X11-unix.
30#noroot 31#noroot
diff --git a/etc/profile-m-z/ZeGrapher.profile b/etc/profile-m-z/ZeGrapher.profile
index 02c5a043d..7686c3442 100644
--- a/etc/profile-m-z/ZeGrapher.profile
+++ b/etc/profile-m-z/ZeGrapher.profile
@@ -27,6 +27,7 @@ machine-id
27net none 27net none
28nodvd 28nodvd
29nogroups 29nogroups
30noinput
30nonewprivs 31nonewprivs
31noroot 32noroot
32nosound 33nosound
diff --git a/etc/profile-m-z/macrofusion.profile b/etc/profile-m-z/macrofusion.profile
index 2e0071b47..d1dcb6fe0 100644
--- a/etc/profile-m-z/macrofusion.profile
+++ b/etc/profile-m-z/macrofusion.profile
@@ -26,6 +26,7 @@ ipc-namespace
26net none 26net none
27nodvd 27nodvd
28nogroups 28nogroups
29noinput
29nonewprivs 30nonewprivs
30noroot 31noroot
31nosound 32nosound
diff --git a/etc/profile-m-z/magicor.profile b/etc/profile-m-z/magicor.profile
index d26aed0bb..8a27b2626 100644
--- a/etc/profile-m-z/magicor.profile
+++ b/etc/profile-m-z/magicor.profile
@@ -32,6 +32,7 @@ caps.drop all
32net none 32net none
33nodvd 33nodvd
34nogroups 34nogroups
35noinput
35nonewprivs 36nonewprivs
36notv 37notv
37nou2f 38nou2f
diff --git a/etc/profile-m-z/man.profile b/etc/profile-m-z/man.profile
index e199d29d1..bd510fcac 100644
--- a/etc/profile-m-z/man.profile
+++ b/etc/profile-m-z/man.profile
@@ -42,6 +42,7 @@ net none
42no3d 42no3d
43nodvd 43nodvd
44nogroups 44nogroups
45noinput
45nonewprivs 46nonewprivs
46noroot 47noroot
47nosound 48nosound
diff --git a/etc/profile-m-z/manaplus.profile b/etc/profile-m-z/manaplus.profile
index eba77c8f2..f59a56ac6 100644
--- a/etc/profile-m-z/manaplus.profile
+++ b/etc/profile-m-z/manaplus.profile
@@ -31,6 +31,7 @@ ipc-namespace
31netfilter 31netfilter
32nodvd 32nodvd
33nogroups 33nogroups
34noinput
34nonewprivs 35nonewprivs
35noroot 36noroot
36notv 37notv
diff --git a/etc/profile-m-z/marker.profile b/etc/profile-m-z/marker.profile
index 84039aca3..087c02964 100644
--- a/etc/profile-m-z/marker.profile
+++ b/etc/profile-m-z/marker.profile
@@ -38,6 +38,7 @@ netfilter
38no3d 38no3d
39nodvd 39nodvd
40nogroups 40nogroups
41noinput
41nonewprivs 42nonewprivs
42noroot 43noroot
43nosound 44nosound
diff --git a/etc/profile-m-z/masterpdfeditor.profile b/etc/profile-m-z/masterpdfeditor.profile
index e4da0c66a..de1135071 100644
--- a/etc/profile-m-z/masterpdfeditor.profile
+++ b/etc/profile-m-z/masterpdfeditor.profile
@@ -23,6 +23,7 @@ caps.drop all
23machine-id 23machine-id
24nodvd 24nodvd
25nogroups 25nogroups
26noinput
26nonewprivs 27nonewprivs
27noroot 28noroot
28nosound 29nosound
diff --git a/etc/profile-m-z/mate-calc.profile b/etc/profile-m-z/mate-calc.profile
index ce418d68f..39ee7439d 100644
--- a/etc/profile-m-z/mate-calc.profile
+++ b/etc/profile-m-z/mate-calc.profile
@@ -30,6 +30,7 @@ net none
30no3d 30no3d
31nodvd 31nodvd
32nogroups 32nogroups
33noinput
33nonewprivs 34nonewprivs
34noroot 35noroot
35nosound 36nosound
diff --git a/etc/profile-m-z/mate-color-select.profile b/etc/profile-m-z/mate-color-select.profile
index d30965922..007bab30d 100644
--- a/etc/profile-m-z/mate-color-select.profile
+++ b/etc/profile-m-z/mate-color-select.profile
@@ -21,6 +21,7 @@ netfilter
21no3d 21no3d
22nodvd 22nodvd
23nogroups 23nogroups
24noinput
24nonewprivs 25nonewprivs
25noroot 26noroot
26nosound 27nosound
diff --git a/etc/profile-m-z/mate-dictionary.profile b/etc/profile-m-z/mate-dictionary.profile
index 2267bbb50..ae1fcbf62 100644
--- a/etc/profile-m-z/mate-dictionary.profile
+++ b/etc/profile-m-z/mate-dictionary.profile
@@ -25,6 +25,7 @@ netfilter
25no3d 25no3d
26nodvd 26nodvd
27nogroups 27nogroups
28noinput
28nonewprivs 29nonewprivs
29noroot 30noroot
30nosound 31nosound
diff --git a/etc/profile-m-z/mcabber.profile b/etc/profile-m-z/mcabber.profile
index b63de6c3e..38d2d8d63 100644
--- a/etc/profile-m-z/mcabber.profile
+++ b/etc/profile-m-z/mcabber.profile
@@ -19,6 +19,7 @@ include disable-shell.inc
19caps.drop all 19caps.drop all
20netfilter 20netfilter
21nodvd 21nodvd
22noinput
22nonewprivs 23nonewprivs
23noroot 24noroot
24nosound 25nosound
diff --git a/etc/profile-m-z/mdr.profile b/etc/profile-m-z/mdr.profile
index fb97daa27..5d3f8dc41 100644
--- a/etc/profile-m-z/mdr.profile
+++ b/etc/profile-m-z/mdr.profile
@@ -29,6 +29,7 @@ net none
29no3d 29no3d
30nodvd 30nodvd
31nogroups 31nogroups
32noinput
32nonewprivs 33nonewprivs
33noroot 34noroot
34nosound 35nosound
diff --git a/etc/profile-m-z/mediainfo.profile b/etc/profile-m-z/mediainfo.profile
index be7c8cbca..17363624f 100644
--- a/etc/profile-m-z/mediainfo.profile
+++ b/etc/profile-m-z/mediainfo.profile
@@ -27,6 +27,7 @@ net none
27no3d 27no3d
28nodvd 28nodvd
29nogroups 29nogroups
30noinput
30nonewprivs 31nonewprivs
31noroot 32noroot
32nosound 33nosound
diff --git a/etc/profile-m-z/mediathekview.profile b/etc/profile-m-z/mediathekview.profile
index 95cd673c6..0063badd8 100644
--- a/etc/profile-m-z/mediathekview.profile
+++ b/etc/profile-m-z/mediathekview.profile
@@ -34,6 +34,7 @@ caps.drop all
34netfilter 34netfilter
35nodvd 35nodvd
36nogroups 36nogroups
37noinput
37nonewprivs 38nonewprivs
38noroot 39noroot
39notv 40notv
diff --git a/etc/profile-m-z/megaglest.profile b/etc/profile-m-z/megaglest.profile
index 37ac9e304..972838729 100644
--- a/etc/profile-m-z/megaglest.profile
+++ b/etc/profile-m-z/megaglest.profile
@@ -31,6 +31,7 @@ ipc-namespace
31netfilter 31netfilter
32nodvd 32nodvd
33nogroups 33nogroups
34noinput
34nonewprivs 35nonewprivs
35noroot 36noroot
36notv 37notv
diff --git a/etc/profile-m-z/meld.profile b/etc/profile-m-z/meld.profile
index 900523b81..1225cc107 100644
--- a/etc/profile-m-z/meld.profile
+++ b/etc/profile-m-z/meld.profile
@@ -56,6 +56,7 @@ netfilter
56no3d 56no3d
57nodvd 57nodvd
58nogroups 58nogroups
59noinput
59nonewprivs 60nonewprivs
60noroot 61noroot
61nosound 62nosound
diff --git a/etc/profile-m-z/mendeleydesktop.profile b/etc/profile-m-z/mendeleydesktop.profile
index 6022b110a..c0bdbb230 100644
--- a/etc/profile-m-z/mendeleydesktop.profile
+++ b/etc/profile-m-z/mendeleydesktop.profile
@@ -31,6 +31,7 @@ caps.drop all
31netfilter 31netfilter
32nodvd 32nodvd
33nogroups 33nogroups
34noinput
34nonewprivs 35nonewprivs
35noroot 36noroot
36notv 37notv
diff --git a/etc/profile-m-z/menulibre.profile b/etc/profile-m-z/menulibre.profile
index e29e4bc70..2081b8c96 100644
--- a/etc/profile-m-z/menulibre.profile
+++ b/etc/profile-m-z/menulibre.profile
@@ -37,6 +37,7 @@ net none
37nodvd 37nodvd
38no3d 38no3d
39nogroups 39nogroups
40noinput
40nonewprivs 41nonewprivs
41noroot 42noroot
42nosound 43nosound
diff --git a/etc/profile-m-z/meteo-qt.profile b/etc/profile-m-z/meteo-qt.profile
index c8b0a0ff1..85ed7bc74 100644
--- a/etc/profile-m-z/meteo-qt.profile
+++ b/etc/profile-m-z/meteo-qt.profile
@@ -31,6 +31,7 @@ caps.drop all
31netfilter 31netfilter
32nodvd 32nodvd
33nogroups 33nogroups
34noinput
34nonewprivs 35nonewprivs
35noroot 36noroot
36nosound 37nosound
diff --git a/etc/profile-m-z/mindless.profile b/etc/profile-m-z/mindless.profile
index 6108c0b69..fbf6b58e8 100644
--- a/etc/profile-m-z/mindless.profile
+++ b/etc/profile-m-z/mindless.profile
@@ -26,6 +26,7 @@ net none
26no3d 26no3d
27nodvd 27nodvd
28nogroups 28nogroups
29noinput
29nonewprivs 30nonewprivs
30noroot 31noroot
31nosound 32nosound
diff --git a/etc/profile-m-z/minecraft-launcher.profile b/etc/profile-m-z/minecraft-launcher.profile
index 8c7d18c58..2536d0b38 100644
--- a/etc/profile-m-z/minecraft-launcher.profile
+++ b/etc/profile-m-z/minecraft-launcher.profile
@@ -6,7 +6,8 @@ include minecraft-launcher.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9# On some distros executable may be in '/opt/minecraft-launcher/', if so, run 'firejail /opt/minecraft-launcher/minecraft-launcher' to start it. 9# Some distros put the executable in /opt/minecraft-launcher.
10# Run 'firejail /opt/minecraft-launcher/minecraft-launcher' to start it.
10 11
11ignore noexec ${HOME} 12ignore noexec ${HOME}
12 13
@@ -35,6 +36,7 @@ caps.drop all
35netfilter 36netfilter
36nodvd 37nodvd
37nogroups 38nogroups
39noinput
38nonewprivs 40nonewprivs
39noroot 41noroot
40notv 42notv
@@ -49,7 +51,8 @@ disable-mnt
49private-bin java,java-config,minecraft-launcher 51private-bin java,java-config,minecraft-launcher
50private-cache 52private-cache
51private-dev 53private-dev
52# If multiplayer or realms break add your own java folder from /etc or comment the line below. 54# If multiplayer or realms break, add 'private-etc <your-own-java-folder-from-/etc>'
55# or 'ignore private-etc' to your minecraft-launcher.local.
53private-etc alternatives,asound.conf,ati,ca-certificates,crypto-policies,drirc,fonts,group,gtk-2.0,gtk-3.0,host.conf,hostname,hosts,java-10-openjdk,java-11-openjdk,java-12-openjdk,java-13-openjdk,java-14-openjdk,java-7-openjdk,java-8-openjdk,java-9-openjdk,java-openjdk,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,localtime,login.defs,machine-id,mime.types,nvidia,passwd,pki,pulse,resolv.conf,selinux,services,ssl,timezone,X11,xdg 56private-etc alternatives,asound.conf,ati,ca-certificates,crypto-policies,drirc,fonts,group,gtk-2.0,gtk-3.0,host.conf,hostname,hosts,java-10-openjdk,java-11-openjdk,java-12-openjdk,java-13-openjdk,java-14-openjdk,java-7-openjdk,java-8-openjdk,java-9-openjdk,java-openjdk,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,localtime,login.defs,machine-id,mime.types,nvidia,passwd,pki,pulse,resolv.conf,selinux,services,ssl,timezone,X11,xdg
54private-opt minecraft-launcher 57private-opt minecraft-launcher
55private-tmp 58private-tmp
diff --git a/etc/profile-m-z/minetest.profile b/etc/profile-m-z/minetest.profile
index 666af323d..cad1adbda 100644
--- a/etc/profile-m-z/minetest.profile
+++ b/etc/profile-m-z/minetest.profile
@@ -40,6 +40,7 @@ ipc-namespace
40netfilter 40netfilter
41nodvd 41nodvd
42nogroups 42nogroups
43noinput
43nonewprivs 44nonewprivs
44noroot 45noroot
45notv 46notv
diff --git a/etc/profile-m-z/minitube.profile b/etc/profile-m-z/minitube.profile
index 78ef5e398..3fe3428d0 100644
--- a/etc/profile-m-z/minitube.profile
+++ b/etc/profile-m-z/minitube.profile
@@ -40,6 +40,7 @@ caps.drop all
40netfilter 40netfilter
41nodvd 41nodvd
42nogroups 42nogroups
43noinput
43nonewprivs 44nonewprivs
44noroot 45noroot
45notv 46notv
diff --git a/etc/profile-m-z/mirage.profile b/etc/profile-m-z/mirage.profile
index e0ebb4895..505009283 100644
--- a/etc/profile-m-z/mirage.profile
+++ b/etc/profile-m-z/mirage.profile
@@ -41,6 +41,7 @@ caps.drop all
41netfilter 41netfilter
42nodvd 42nodvd
43nogroups 43nogroups
44noinput
44nonewprivs 45nonewprivs
45noroot 46noroot
46notv 47notv
diff --git a/etc/profile-m-z/mirrormagic.profile b/etc/profile-m-z/mirrormagic.profile
index ded84bf7e..58dfd56f5 100644
--- a/etc/profile-m-z/mirrormagic.profile
+++ b/etc/profile-m-z/mirrormagic.profile
@@ -29,6 +29,7 @@ caps.drop all
29net none 29net none
30nodvd 30nodvd
31nogroups 31nogroups
32noinput
32nonewprivs 33nonewprivs
33noroot 34noroot
34notv 35notv
diff --git a/etc/profile-m-z/mocp.profile b/etc/profile-m-z/mocp.profile
index 6fc7a4d67..e71ba4569 100644
--- a/etc/profile-m-z/mocp.profile
+++ b/etc/profile-m-z/mocp.profile
@@ -29,6 +29,7 @@ netfilter
29no3d 29no3d
30nodvd 30nodvd
31nogroups 31nogroups
32noinput
32nonewprivs 33nonewprivs
33noroot 34noroot
34notv 35notv
diff --git a/etc/profile-m-z/mousepad.profile b/etc/profile-m-z/mousepad.profile
index 5f15b71e2..98063fa7c 100644
--- a/etc/profile-m-z/mousepad.profile
+++ b/etc/profile-m-z/mousepad.profile
@@ -23,6 +23,7 @@ caps.drop all
23net none 23net none
24nodvd 24nodvd
25nogroups 25nogroups
26noinput
26nonewprivs 27nonewprivs
27noroot 28noroot
28nosound 29nosound
diff --git a/etc/profile-m-z/mp3splt-gtk.profile b/etc/profile-m-z/mp3splt-gtk.profile
index 3481a4a82..37ce60e04 100644
--- a/etc/profile-m-z/mp3splt-gtk.profile
+++ b/etc/profile-m-z/mp3splt-gtk.profile
@@ -24,6 +24,7 @@ net none
24no3d 24no3d
25nodvd 25nodvd
26nogroups 26nogroups
27noinput
27nonewprivs 28nonewprivs
28noroot 29noroot
29notv 30notv
diff --git a/etc/profile-m-z/mp3splt.profile b/etc/profile-m-z/mp3splt.profile
index c65754a03..070de8451 100644
--- a/etc/profile-m-z/mp3splt.profile
+++ b/etc/profile-m-z/mp3splt.profile
@@ -28,6 +28,7 @@ net none
28no3d 28no3d
29nodvd 29nodvd
30nogroups 30nogroups
31noinput
31nonewprivs 32nonewprivs
32noroot 33noroot
33nosound 34nosound
diff --git a/etc/profile-m-z/mpDris2.profile b/etc/profile-m-z/mpDris2.profile
index 4ba1dfbd6..55a0b5897 100644
--- a/etc/profile-m-z/mpDris2.profile
+++ b/etc/profile-m-z/mpDris2.profile
@@ -36,6 +36,7 @@ netfilter
36no3d 36no3d
37nodvd 37nodvd
38nogroups 38nogroups
39noinput
39nonewprivs 40nonewprivs
40noroot 41noroot
41nosound 42nosound
diff --git a/etc/profile-m-z/mpd.profile b/etc/profile-m-z/mpd.profile
index 3fda87a48..b517d4ab2 100644
--- a/etc/profile-m-z/mpd.profile
+++ b/etc/profile-m-z/mpd.profile
@@ -26,6 +26,7 @@ caps.drop all
26netfilter 26netfilter
27no3d 27no3d
28nodvd 28nodvd
29noinput
29nonewprivs 30nonewprivs
30noroot 31noroot
31notv 32notv
diff --git a/etc/profile-m-z/mpg123.profile b/etc/profile-m-z/mpg123.profile
index b1ab81c1e..25187e894 100644
--- a/etc/profile-m-z/mpg123.profile
+++ b/etc/profile-m-z/mpg123.profile
@@ -25,6 +25,7 @@ caps.drop all
25netfilter 25netfilter
26no3d 26no3d
27nogroups 27nogroups
28noinput
28nonewprivs 29nonewprivs
29noroot 30noroot
30notv 31notv
diff --git a/etc/profile-m-z/mplayer.profile b/etc/profile-m-z/mplayer.profile
index 58384e33c..5d023b7f1 100644
--- a/etc/profile-m-z/mplayer.profile
+++ b/etc/profile-m-z/mplayer.profile
@@ -28,6 +28,7 @@ caps.drop all
28# net none - mplayer can be used for streaming. 28# net none - mplayer can be used for streaming.
29netfilter 29netfilter
30# nogroups 30# nogroups
31noinput
31nonewprivs 32nonewprivs
32noroot 33noroot
33nou2f 34nou2f
diff --git a/etc/profile-m-z/mpsyt.profile b/etc/profile-m-z/mpsyt.profile
index bdf50421b..bfe57a132 100644
--- a/etc/profile-m-z/mpsyt.profile
+++ b/etc/profile-m-z/mpsyt.profile
@@ -53,6 +53,7 @@ netfilter
53nodvd 53nodvd
54# Seems to cause issues with Nvidia drivers sometimes 54# Seems to cause issues with Nvidia drivers sometimes
55nogroups 55nogroups
56noinput
56nonewprivs 57nonewprivs
57noroot 58noroot
58notv 59notv
diff --git a/etc/profile-m-z/mpv.profile b/etc/profile-m-z/mpv.profile
index 1804389c3..310f36ea1 100644
--- a/etc/profile-m-z/mpv.profile
+++ b/etc/profile-m-z/mpv.profile
@@ -63,6 +63,7 @@ caps.drop all
63netfilter 63netfilter
64# nogroups seems to cause issues with Nvidia drivers sometimes 64# nogroups seems to cause issues with Nvidia drivers sometimes
65nogroups 65nogroups
66noinput
66nonewprivs 67nonewprivs
67noroot 68noroot
68nou2f 69nou2f
diff --git a/etc/profile-m-z/mrrescue.profile b/etc/profile-m-z/mrrescue.profile
index f02a4f357..035a7e625 100644
--- a/etc/profile-m-z/mrrescue.profile
+++ b/etc/profile-m-z/mrrescue.profile
@@ -8,18 +8,26 @@ include globals.local
8 8
9noblacklist ${HOME}/.local/share/love 9noblacklist ${HOME}/.local/share/love
10 10
11# Allow /bin/sh (blacklisted by disable-shell.inc)
12include allow-bin-sh.inc
13
14# Allow lua (blacklisted by disable-interpreters.inc)
15include allow-lua.inc
16
11include disable-common.inc 17include disable-common.inc
12include disable-devel.inc 18include disable-devel.inc
13include disable-exec.inc 19include disable-exec.inc
14include disable-interpreters.inc 20include disable-interpreters.inc
15include disable-passwdmgr.inc 21include disable-passwdmgr.inc
16include disable-programs.inc 22include disable-programs.inc
23include disable-shell.inc
17include disable-xdg.inc 24include disable-xdg.inc
18 25
19mkdir ${HOME}/.local/share/love 26mkdir ${HOME}/.local/share/love
20whitelist ${HOME}/.local/share/love 27whitelist ${HOME}/.local/share/love
21whitelist /usr/share/mrrescue 28whitelist /usr/share/mrrescue
22include whitelist-common.inc 29include whitelist-common.inc
30include whitelist-runuser-common.inc
23include whitelist-usr-share-common.inc 31include whitelist-usr-share-common.inc
24include whitelist-var-common.inc 32include whitelist-var-common.inc
25 33
@@ -28,6 +36,7 @@ caps.drop all
28net none 36net none
29nodvd 37nodvd
30nogroups 38nogroups
39noinput
31nonewprivs 40nonewprivs
32noroot 41noroot
33notv 42notv
@@ -35,6 +44,7 @@ nou2f
35novideo 44novideo
36protocol unix,netlink 45protocol unix,netlink
37seccomp 46seccomp
47seccomp.block-secondary
38shell none 48shell none
39tracelog 49tracelog
40 50
diff --git a/etc/profile-m-z/ms-office.profile b/etc/profile-m-z/ms-office.profile
index a6892d698..38fc84ecc 100644
--- a/etc/profile-m-z/ms-office.profile
+++ b/etc/profile-m-z/ms-office.profile
@@ -23,6 +23,7 @@ caps.drop all
23netfilter 23netfilter
24nodvd 24nodvd
25nogroups 25nogroups
26noinput
26nonewprivs 27nonewprivs
27noroot 28noroot
28notv 29notv
diff --git a/etc/profile-m-z/mtpaint.profile b/etc/profile-m-z/mtpaint.profile
index 9f1f0f53d..85c3ee9f2 100644
--- a/etc/profile-m-z/mtpaint.profile
+++ b/etc/profile-m-z/mtpaint.profile
@@ -28,6 +28,7 @@ net none
28nodvd 28nodvd
29no3d 29no3d
30nogroups 30nogroups
31noinput
31nonewprivs 32nonewprivs
32noroot 33noroot
33nosound 34nosound
diff --git a/etc/profile-m-z/multimc5.profile b/etc/profile-m-z/multimc5.profile
index 475307418..6df681df1 100644
--- a/etc/profile-m-z/multimc5.profile
+++ b/etc/profile-m-z/multimc5.profile
@@ -31,6 +31,7 @@ caps.drop all
31netfilter 31netfilter
32nodvd 32nodvd
33nogroups 33nogroups
34noinput
34nonewprivs 35nonewprivs
35noroot 36noroot
36notv 37notv
diff --git a/etc/profile-m-z/mupdf.profile b/etc/profile-m-z/mupdf.profile
index a3e56170a..9e4609c48 100644
--- a/etc/profile-m-z/mupdf.profile
+++ b/etc/profile-m-z/mupdf.profile
@@ -24,6 +24,7 @@ machine-id
24net none 24net none
25nodvd 25nodvd
26nogroups 26nogroups
27noinput
27nonewprivs 28nonewprivs
28noroot 29noroot
29nosound 30nosound
diff --git a/etc/profile-m-z/musictube.profile b/etc/profile-m-z/musictube.profile
index dbfd12619..04500ac6a 100644
--- a/etc/profile-m-z/musictube.profile
+++ b/etc/profile-m-z/musictube.profile
@@ -36,6 +36,7 @@ caps.drop all
36netfilter 36netfilter
37nodvd 37nodvd
38nogroups 38nogroups
39noinput
39nonewprivs 40nonewprivs
40noroot 41noroot
41notv 42notv
diff --git a/etc/profile-m-z/musixmatch.profile b/etc/profile-m-z/musixmatch.profile
index a6b85a8e4..74b3e9a5f 100644
--- a/etc/profile-m-z/musixmatch.profile
+++ b/etc/profile-m-z/musixmatch.profile
@@ -20,9 +20,11 @@ netfilter
20no3d 20no3d
21nodvd 21nodvd
22nogroups 22nogroups
23noinput
23nonewprivs 24nonewprivs
24noroot 25noroot
25nogroups 26nogroups
27noinput
26nosound 28nosound
27notv 29notv
28nou2f 30nou2f
diff --git a/etc/profile-m-z/mutt.profile b/etc/profile-m-z/mutt.profile
index 2c6e047d8..debf81659 100644
--- a/etc/profile-m-z/mutt.profile
+++ b/etc/profile-m-z/mutt.profile
@@ -119,6 +119,7 @@ netfilter
119no3d 119no3d
120nodvd 120nodvd
121nogroups 121nogroups
122noinput
122nonewprivs 123nonewprivs
123noroot 124noroot
124nosound 125nosound
diff --git a/etc/profile-m-z/mypaint.profile b/etc/profile-m-z/mypaint.profile
index c592e8477..d8d487fe7 100644
--- a/etc/profile-m-z/mypaint.profile
+++ b/etc/profile-m-z/mypaint.profile
@@ -30,6 +30,7 @@ net none
30no3d 30no3d
31nodvd 31nodvd
32nogroups 32nogroups
33noinput
33nonewprivs 34nonewprivs
34noroot 35noroot
35nosound 36nosound
diff --git a/etc/profile-m-z/nano.profile b/etc/profile-m-z/nano.profile
index 2a4625896..4698c2287 100644
--- a/etc/profile-m-z/nano.profile
+++ b/etc/profile-m-z/nano.profile
@@ -30,6 +30,7 @@ net none
30no3d 30no3d
31nodvd 31nodvd
32nogroups 32nogroups
33noinput
33nonewprivs 34nonewprivs
34noroot 35noroot
35nosound 36nosound
@@ -46,8 +47,12 @@ x11 none
46private-bin nano,rnano 47private-bin nano,rnano
47private-cache 48private-cache
48private-dev 49private-dev
49# Comment the next line if you want to edit files in /etc directly 50# Add the next lines to your nano.local if you want to edit files in /etc directly.
51#ignore private-etc
52#writable-etc
50private-etc alternatives,nanorc 53private-etc alternatives,nanorc
54# Add the next line to your nano.local if you want to edit files in /var directly.
55#writable-var
51 56
52dbus-user none 57dbus-user none
53dbus-system none 58dbus-system none
diff --git a/etc/profile-m-z/ncdu.profile b/etc/profile-m-z/ncdu.profile
index 651804bf1..063e30366 100644
--- a/etc/profile-m-z/ncdu.profile
+++ b/etc/profile-m-z/ncdu.profile
@@ -16,6 +16,7 @@ net none
16no3d 16no3d
17nodvd 17nodvd
18nogroups 18nogroups
19noinput
19nonewprivs 20nonewprivs
20noroot 21noroot
21nosound 22nosound
diff --git a/etc/profile-m-z/neochat.profile b/etc/profile-m-z/neochat.profile
new file mode 100644
index 000000000..9f00448c8
--- /dev/null
+++ b/etc/profile-m-z/neochat.profile
@@ -0,0 +1,66 @@
1# Firejail profile for neochat
2# Description: Matrix Client
3# This file is overwritten after every install/update
4# Persistent local customizations
5include neochat.local
6# Persistent global definitions
7include globals.local
8
9noblacklist ${HOME}/.cache/KDE/neochat
10noblacklist ${HOME}/.config/KDE
11noblacklist ${HOME}/.config/KDE/neochat
12noblacklist ${HOME}/.config/neochatrc
13noblacklist ${HOME}/.config/neochat.notifyrc
14noblacklist ${HOME}/.local/share/KDE/neochat
15
16include disable-common.inc
17include disable-devel.inc
18include disable-exec.inc
19include disable-interpreters.inc
20include disable-passwdmgr.inc
21include disable-programs.inc
22include disable-shell.inc
23include disable-xdg.inc
24
25mkdir ${HOME}/.cache/KDE/neochat
26mkdir ${HOME}/.local/share/KDE/neochat
27whitelist ${HOME}/.cache/KDE/neochat
28whitelist ${HOME}/.local/share/KDE/neochat
29whitelist ${DOWNLOADS}
30include whitelist-1793-workaround.inc
31include whitelist-common.inc
32include whitelist-runuser-common.inc
33include whitelist-usr-share-common.inc
34include whitelist-var-common.inc
35
36apparmor
37caps.drop all
38machine-id
39netfilter
40nodvd
41nogroups
42noinput
43nonewprivs
44noroot
45nosound
46notv
47nou2f
48novideo
49protocol unix,inet,inet6
50seccomp
51seccomp.block-secondary
52shell none
53tracelog
54
55disable-mnt
56private-bin neochat
57private-dev
58private-etc alternatives,ca-certificates,crypto-policies,dbus-1,fonts,host.conf,hostname,hosts,kde4rc,kde5rc,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,locale,locale.alias,locale.conf,localtime,machine-id,mime.types,nsswitch.conf,pango,pki,protocols,resolv.conf,rpc,services,ssl,Trolltech.conf,X11,xdg
59private-tmp
60
61dbus-user filter
62dbus-user.own org.kde.neochat
63dbus-user.talk org.freedesktop.Notifications
64dbus-user.talk org.kde.StatusNotifierWatcher
65dbus-user.talk org.kde.kwalletd5
66dbus-system none
diff --git a/etc/profile-m-z/neomutt.profile b/etc/profile-m-z/neomutt.profile
index 26865b90a..fafa129e4 100644
--- a/etc/profile-m-z/neomutt.profile
+++ b/etc/profile-m-z/neomutt.profile
@@ -122,6 +122,7 @@ netfilter
122no3d 122no3d
123nodvd 123nodvd
124nogroups 124nogroups
125noinput
125nonewprivs 126nonewprivs
126noroot 127noroot
127nosound 128nosound
diff --git a/etc/profile-m-z/netactview.profile b/etc/profile-m-z/netactview.profile
index fd73cea89..5d45dd7bc 100644
--- a/etc/profile-m-z/netactview.profile
+++ b/etc/profile-m-z/netactview.profile
@@ -32,6 +32,7 @@ netfilter
32no3d 32no3d
33nodvd 33nodvd
34nogroups 34nogroups
35noinput
35nonewprivs 36nonewprivs
36noroot 37noroot
37nosound 38nosound
diff --git a/etc/profile-m-z/nethack-vultures.profile b/etc/profile-m-z/nethack-vultures.profile
index 4daa8054b..c9a537370 100644
--- a/etc/profile-m-z/nethack-vultures.profile
+++ b/etc/profile-m-z/nethack-vultures.profile
@@ -26,6 +26,7 @@ ipc-namespace
26net none 26net none
27nodvd 27nodvd
28nogroups 28nogroups
29noinput
29#nonewprivs 30#nonewprivs
30#noroot 31#noroot
31notv 32notv
diff --git a/etc/profile-m-z/nethack.profile b/etc/profile-m-z/nethack.profile
index c8c927db2..b57abe260 100644
--- a/etc/profile-m-z/nethack.profile
+++ b/etc/profile-m-z/nethack.profile
@@ -25,6 +25,7 @@ net none
25no3d 25no3d
26nodvd 26nodvd
27nogroups 27nogroups
28noinput
28#nonewprivs 29#nonewprivs
29#noroot 30#noroot
30nosound 31nosound
diff --git a/etc/profile-m-z/neverball-wrapper.profile b/etc/profile-m-z/neverball-wrapper.profile
new file mode 100644
index 000000000..534e41dd1
--- /dev/null
+++ b/etc/profile-m-z/neverball-wrapper.profile
@@ -0,0 +1,14 @@
1# Firejail profile for neverball-wrapper
2# This file is overwritten after every install/update
3# Persistent local customizations
4include neverball-wrapper.local
5# Persistent global definitions
6# added by included profile
7#include globals.local
8
9include allow-opengl-game.inc
10
11private-bin neverball-wrapper
12
13# Redirect
14include neverball.profile
diff --git a/etc/profile-m-z/neverball.profile b/etc/profile-m-z/neverball.profile
index 84c634549..ecfbb14e4 100644
--- a/etc/profile-m-z/neverball.profile
+++ b/etc/profile-m-z/neverball.profile
@@ -14,26 +14,39 @@ include disable-exec.inc
14include disable-interpreters.inc 14include disable-interpreters.inc
15include disable-passwdmgr.inc 15include disable-passwdmgr.inc
16include disable-programs.inc 16include disable-programs.inc
17include disable-shell.inc
18include disable-xdg.inc
17 19
18mkdir ${HOME}/.neverball 20mkdir ${HOME}/.neverball
19whitelist ${HOME}/.neverball 21whitelist ${HOME}/.neverball
22whitelist /usr/share/neverball
20include whitelist-common.inc 23include whitelist-common.inc
24include whitelist-runuser-common.inc
25include whitelist-usr-share-common.inc
26include whitelist-var-common.inc
21 27
22caps.drop all 28caps.drop all
23netfilter 29net none
24nodvd 30nodvd
25nogroups 31nogroups
32noinput
26nonewprivs 33nonewprivs
27noroot 34noroot
28notv 35notv
29nou2f 36nou2f
30novideo 37novideo
31protocol unix,netlink 38protocol unix
32seccomp 39seccomp
40seccomp.block-secondary
33shell none 41shell none
42tracelog
34 43
35disable-mnt 44disable-mnt
36private-bin neverball 45private-bin neverball
46private-cache
37private-dev 47private-dev
48private-etc alternatives,fonts,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,locale,machine-id
38private-tmp 49private-tmp
39 50
51dbus-user none
52dbus-system none
diff --git a/etc/profile-m-z/neverputt-wrapper.profile b/etc/profile-m-z/neverputt-wrapper.profile
new file mode 100644
index 000000000..dacd113cc
--- /dev/null
+++ b/etc/profile-m-z/neverputt-wrapper.profile
@@ -0,0 +1,14 @@
1# Firejail profile for neverputt-wrapper
2# This file is overwritten after every install/update
3# Persistent local customizations
4include neverputt-wrapper.local
5# Persistent global definitions
6# added by included profile
7#include globals.local
8
9include allow-opengl-game.inc
10
11private-bin neverputt-wrapper
12
13# Redirect
14include neverputt.profile
diff --git a/etc/profile-m-z/newsboat.profile b/etc/profile-m-z/newsboat.profile
index 23c2de43c..13bc3a615 100644
--- a/etc/profile-m-z/newsboat.profile
+++ b/etc/profile-m-z/newsboat.profile
@@ -40,6 +40,7 @@ netfilter
40no3d 40no3d
41nodvd 41nodvd
42nogroups 42nogroups
43noinput
43nonewprivs 44nonewprivs
44noroot 45noroot
45notv 46notv
diff --git a/etc/profile-m-z/newsflash.profile b/etc/profile-m-z/newsflash.profile
index d0ac83baf..18d8c6ed4 100644
--- a/etc/profile-m-z/newsflash.profile
+++ b/etc/profile-m-z/newsflash.profile
@@ -36,6 +36,7 @@ machine-id
36netfilter 36netfilter
37nodvd 37nodvd
38nogroups 38nogroups
39noinput
39nonewprivs 40nonewprivs
40noroot 41noroot
41nosound 42nosound
diff --git a/etc/profile-m-z/nextcloud.profile b/etc/profile-m-z/nextcloud.profile
index 53dd3a05a..9fd76fbe7 100644
--- a/etc/profile-m-z/nextcloud.profile
+++ b/etc/profile-m-z/nextcloud.profile
@@ -47,6 +47,7 @@ netfilter
47no3d 47no3d
48nodvd 48nodvd
49nogroups 49nogroups
50noinput
50nonewprivs 51nonewprivs
51noroot 52noroot
52nosound 53nosound
diff --git a/etc/profile-m-z/nheko.profile b/etc/profile-m-z/nheko.profile
index 1b5da8d27..f8062891c 100644
--- a/etc/profile-m-z/nheko.profile
+++ b/etc/profile-m-z/nheko.profile
@@ -36,6 +36,7 @@ caps.drop all
36netfilter 36netfilter
37nodvd 37nodvd
38nogroups 38nogroups
39noinput
39nonewprivs 40nonewprivs
40noroot 41noroot
41notv 42notv
diff --git a/etc/profile-m-z/nicotine.profile b/etc/profile-m-z/nicotine.profile
index 3bf32a3db..1c7dbc009 100644
--- a/etc/profile-m-z/nicotine.profile
+++ b/etc/profile-m-z/nicotine.profile
@@ -36,6 +36,7 @@ netfilter
36no3d 36no3d
37nodvd 37nodvd
38nogroups 38nogroups
39noinput
39nonewprivs 40nonewprivs
40noroot 41noroot
41nosound 42nosound
diff --git a/etc/profile-m-z/nitroshare.profile b/etc/profile-m-z/nitroshare.profile
index 1743a771e..8dba84f02 100644
--- a/etc/profile-m-z/nitroshare.profile
+++ b/etc/profile-m-z/nitroshare.profile
@@ -28,6 +28,7 @@ netfilter
28no3d 28no3d
29nodvd 29nodvd
30nogroups 30nogroups
31noinput
31nonewprivs 32nonewprivs
32noroot 33noroot
33nosound 34nosound
diff --git a/etc/profile-m-z/node.profile b/etc/profile-m-z/node.profile
new file mode 100644
index 000000000..cd48ed3c7
--- /dev/null
+++ b/etc/profile-m-z/node.profile
@@ -0,0 +1,11 @@
1# Firejail profile for node
2# Description: Evented I/O for V8 javascript
3quiet
4# This file is overwritten after every install/update
5# Persistent local customizations
6include node.local
7# Persistent global definitions
8include globals.local
9
10# Redirect
11include nodejs-common.profile
diff --git a/etc/profile-m-z/nodejs-common.profile b/etc/profile-m-z/nodejs-common.profile
index 202905631..fa69f9214 100644
--- a/etc/profile-m-z/nodejs-common.profile
+++ b/etc/profile-m-z/nodejs-common.profile
@@ -10,6 +10,20 @@ include nodejs-common.local
10blacklist /tmp/.X11-unix 10blacklist /tmp/.X11-unix
11blacklist ${RUNUSER} 11blacklist ${RUNUSER}
12 12
13ignore read-only ${HOME}/.npm-packages
14ignore read-only ${HOME}/.npmrc
15ignore read-only ${HOME}/.nvm
16ignore read-only ${HOME}/.yarnrc
17
18noblacklist ${HOME}/.node-gyp
19noblacklist ${HOME}/.npm
20noblacklist ${HOME}/.npmrc
21noblacklist ${HOME}/.nvm
22noblacklist ${HOME}/.yarn
23noblacklist ${HOME}/.yarn-config
24noblacklist ${HOME}/.yarncache
25noblacklist ${HOME}/.yarnrc
26
13ignore noexec ${HOME} 27ignore noexec ${HOME}
14 28
15include allow-bin-sh.inc 29include allow-bin-sh.inc
@@ -21,6 +35,32 @@ include disable-programs.inc
21include disable-shell.inc 35include disable-shell.inc
22include disable-xdg.inc 36include disable-xdg.inc
23 37
38# If you want whitelisting, change ${HOME}/Projects below to your node projects directory
39# and add the next lines to your nodejs-common.local.
40#mkdir ${HOME}/.node-gyp
41#mkdir ${HOME}/.npm
42#mkdir ${HOME}/.npm-packages
43#mkfile ${HOME}/.npmrc
44#mkdir ${HOME}/.nvm
45#mkdir ${HOME}/.yarn
46#mkdir ${HOME}/.yarn-config
47#mkdir ${HOME}/.yarncache
48#mkfile ${HOME}/.yarnrc
49#whitelist ${HOME}/.node-gyp
50#whitelist ${HOME}/.npm
51#whitelist ${HOME}/.npm-packages
52#whitelist ${HOME}/.npmrc
53#whitelist ${HOME}/.nvm
54#whitelist ${HOME}/.yarn
55#whitelist ${HOME}/.yarn-config
56#whitelist ${HOME}/.yarncache
57#whitelist ${HOME}/.yarnrc
58#whitelist ${HOME}/Projects
59#include whitelist-common.inc
60
61whitelist /usr/share/doc/node
62whitelist /usr/share/nvm
63whitelist /usr/share/systemtap/tapset/node.stp
24include whitelist-runuser-common.inc 64include whitelist-runuser-common.inc
25include whitelist-usr-share-common.inc 65include whitelist-usr-share-common.inc
26include whitelist-var-common.inc 66include whitelist-var-common.inc
@@ -32,6 +72,7 @@ netfilter
32no3d 72no3d
33nodvd 73nodvd
34nogroups 74nogroups
75noinput
35nonewprivs 76nonewprivs
36noroot 77noroot
37nosound 78nosound
@@ -45,10 +86,11 @@ shell none
45 86
46disable-mnt 87disable-mnt
47private-dev 88private-dev
48# May need to add `passwd` to `private-etc` below to enable debugging with some IDEs 89private-etc alternatives,ca-certificates,crypto-policies,group,host.conf,hostname,hosts,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,locale,locale.alias,locale.conf,localtime,login.defs,mime.types,nsswitch.conf,passwd,pki,protocols,resolv.conf,rpc,services,ssl,xdg
49private-etc alternatives,ca-certificates,crypto-policies,host.conf,hostname,hosts,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,locale,locale.alias,locale.conf,localtime,login.defs,mime.types,nsswitch.conf,pki,protocols,resolv.conf,rpc,services,ssl,xdg 90#private-tmp
50# May need to be commented out in order to enable debugging with some IDEs
51private-tmp
52 91
53dbus-user none 92dbus-user none
54dbus-system none 93dbus-system none
94
95# Add the next line to your nodejs-common.local if you prefer to disable gatsby telemetry.
96#env GATSBY_TELEMETRY_DISABLED=1
diff --git a/etc/profile-m-z/nomacs.profile b/etc/profile-m-z/nomacs.profile
index d081c9cb7..a36dee874 100644
--- a/etc/profile-m-z/nomacs.profile
+++ b/etc/profile-m-z/nomacs.profile
@@ -27,6 +27,7 @@ machine-id
27netfilter 27netfilter
28nodvd 28nodvd
29nogroups 29nogroups
30noinput
30nonewprivs 31nonewprivs
31noroot 32noroot
32nosound 33nosound
diff --git a/etc/profile-m-z/notify-send.profile b/etc/profile-m-z/notify-send.profile
index ff292f409..650118c98 100644
--- a/etc/profile-m-z/notify-send.profile
+++ b/etc/profile-m-z/notify-send.profile
@@ -32,6 +32,7 @@ net none
32no3d 32no3d
33nodvd 33nodvd
34nogroups 34nogroups
35noinput
35nonewprivs 36nonewprivs
36noroot 37noroot
37nosound 38nosound
diff --git a/etc/profile-m-z/npm.profile b/etc/profile-m-z/npm.profile
index f51d58782..4d8beea5a 100644
--- a/etc/profile-m-z/npm.profile
+++ b/etc/profile-m-z/npm.profile
@@ -7,23 +7,5 @@ include npm.local
7# Persistent global definitions 7# Persistent global definitions
8include globals.local 8include globals.local
9 9
10ignore read-only ${HOME}/.npm-packages
11ignore read-only ${HOME}/.npmrc
12
13noblacklist ${HOME}/.node-gyp
14noblacklist ${HOME}/.npm
15noblacklist ${HOME}/.npmrc
16
17# If you want whitelisting, change ${HOME}/Projects below to your npm projects directory
18# and add the next lines to your npm.local.
19#mkdir ${HOME}/.node-gyp
20#mkdir ${HOME}/.npm
21#mkfile ${HOME}/.npmrc
22#whitelist ${HOME}/.node-gyp
23#whitelist ${HOME}/.npm
24#whitelist ${HOME}/.npmrc
25#whitelist ${HOME}/Projects
26#include whitelist-common.inc
27
28# Redirect 10# Redirect
29include nodejs-common.profile 11include nodejs-common.profile
diff --git a/etc/profile-m-z/nslookup.profile b/etc/profile-m-z/nslookup.profile
index 17798a6fb..c7a131a2c 100644
--- a/etc/profile-m-z/nslookup.profile
+++ b/etc/profile-m-z/nslookup.profile
@@ -33,6 +33,7 @@ netfilter
33no3d 33no3d
34nodvd 34nodvd
35nogroups 35nogroups
36noinput
36nonewprivs 37nonewprivs
37noroot 38noroot
38nosound 39nosound
diff --git a/etc/profile-m-z/nvm.profile b/etc/profile-m-z/nvm.profile
new file mode 100644
index 000000000..80da22834
--- /dev/null
+++ b/etc/profile-m-z/nvm.profile
@@ -0,0 +1,13 @@
1# Firejail profile for nvm
2# Description: Node Version Manager - Simple bash script to manage multiple active node.js versions
3quiet
4# This file is overwritten after every install/update
5# Persistent local customizations
6include nvm.local
7# Persistent global definitions
8include globals.local
9
10ignore noroot
11
12# Redirect
13include nodejs-common.profile
diff --git a/etc/profile-m-z/nylas.profile b/etc/profile-m-z/nylas.profile
index c959eb991..fe0c2116b 100644
--- a/etc/profile-m-z/nylas.profile
+++ b/etc/profile-m-z/nylas.profile
@@ -25,6 +25,7 @@ caps.drop all
25netfilter 25netfilter
26nodvd 26nodvd
27nogroups 27nogroups
28noinput
28nonewprivs 29nonewprivs
29noroot 30noroot
30nosound 31nosound
diff --git a/etc/profile-m-z/nyx.profile b/etc/profile-m-z/nyx.profile
index 9e27dafab..d040d42af 100644
--- a/etc/profile-m-z/nyx.profile
+++ b/etc/profile-m-z/nyx.profile
@@ -31,6 +31,7 @@ netfilter
31no3d 31no3d
32nodvd 32nodvd
33nogroups 33nogroups
34noinput
34nonewprivs 35nonewprivs
35noroot 36noroot
36nosound 37nosound
diff --git a/etc/profile-m-z/obs.profile b/etc/profile-m-z/obs.profile
index 4277bdab3..9345cee4f 100644
--- a/etc/profile-m-z/obs.profile
+++ b/etc/profile-m-z/obs.profile
@@ -27,6 +27,7 @@ include whitelist-var-common.inc
27caps.drop all 27caps.drop all
28nodvd 28nodvd
29nogroups 29nogroups
30noinput
30nonewprivs 31nonewprivs
31noroot 32noroot
32notv 33notv
diff --git a/etc/profile-m-z/ocenaudio.profile b/etc/profile-m-z/ocenaudio.profile
index be3618e31..7be68a201 100644
--- a/etc/profile-m-z/ocenaudio.profile
+++ b/etc/profile-m-z/ocenaudio.profile
@@ -32,6 +32,7 @@ netfilter
32no3d 32no3d
33nodvd 33nodvd
34nogroups 34nogroups
35noinput
35nonewprivs 36nonewprivs
36noroot 37noroot
37notv 38notv
diff --git a/etc/profile-m-z/odt2txt.profile b/etc/profile-m-z/odt2txt.profile
index 6201b6fba..6163d2e22 100644
--- a/etc/profile-m-z/odt2txt.profile
+++ b/etc/profile-m-z/odt2txt.profile
@@ -23,6 +23,7 @@ net none
23no3d 23no3d
24nodvd 24nodvd
25nogroups 25nogroups
26noinput
26nonewprivs 27nonewprivs
27noroot 28noroot
28nosound 29nosound
diff --git a/etc/profile-m-z/okular.profile b/etc/profile-m-z/okular.profile
index e21ac997a..ab8ccf623 100644
--- a/etc/profile-m-z/okular.profile
+++ b/etc/profile-m-z/okular.profile
@@ -28,10 +28,16 @@ include disable-programs.inc
28include disable-shell.inc 28include disable-shell.inc
29include disable-xdg.inc 29include disable-xdg.inc
30 30
31whitelist /usr/share/config.kcfg 31whitelist /usr/share/config.kcfg/gssettings.kcfg
32whitelist /usr/share/config.kcfg/pdfsettings.kcfg
33whitelist /usr/share/config.kcfg/okular.kcfg
34whitelist /usr/share/config.kcfg/okular_core.kcfg
35whitelist /usr/share/ghostscript
36whitelist /usr/share/kconf_update/okular.upd
32whitelist /usr/share/kxmlgui5/okular 37whitelist /usr/share/kxmlgui5/okular
33whitelist /usr/share/okular 38whitelist /usr/share/okular
34whitelist /usr/share/poppler 39whitelist /usr/share/poppler
40include whitelist-runuser-common.inc
35include whitelist-usr-share-common.inc 41include whitelist-usr-share-common.inc
36include whitelist-var-common.inc 42include whitelist-var-common.inc
37 43
@@ -42,6 +48,7 @@ machine-id
42netfilter 48netfilter
43nodvd 49nodvd
44nogroups 50nogroups
51noinput
45nonewprivs 52nonewprivs
46noroot 53noroot
47nosound 54nosound
diff --git a/etc/profile-m-z/onboard.profile b/etc/profile-m-z/onboard.profile
index 152bd7ac5..5b367b639 100644
--- a/etc/profile-m-z/onboard.profile
+++ b/etc/profile-m-z/onboard.profile
@@ -36,6 +36,7 @@ net none
36nodvd 36nodvd
37no3d 37no3d
38nogroups 38nogroups
39noinput
39nonewprivs 40nonewprivs
40noroot 41noroot
41notv 42notv
diff --git a/etc/profile-m-z/onionshare-gui.profile b/etc/profile-m-z/onionshare-gui.profile
index 5bfcd0527..960df9034 100644
--- a/etc/profile-m-z/onionshare-gui.profile
+++ b/etc/profile-m-z/onionshare-gui.profile
@@ -25,6 +25,7 @@ netfilter
25no3d 25no3d
26nodvd 26nodvd
27nogroups 27nogroups
28noinput
28nonewprivs 29nonewprivs
29noroot 30noroot
30nosound 31nosound
diff --git a/etc/profile-m-z/open-invaders.profile b/etc/profile-m-z/open-invaders.profile
index e18599d1d..7a840d4a9 100644
--- a/etc/profile-m-z/open-invaders.profile
+++ b/etc/profile-m-z/open-invaders.profile
@@ -26,6 +26,7 @@ caps.drop all
26net none 26net none
27nodvd 27nodvd
28nogroups 28nogroups
29noinput
29nonewprivs 30nonewprivs
30noroot 31noroot
31notv 32notv
diff --git a/etc/profile-m-z/openarena.profile b/etc/profile-m-z/openarena.profile
index 88d5d0e1e..36ce0316f 100644
--- a/etc/profile-m-z/openarena.profile
+++ b/etc/profile-m-z/openarena.profile
@@ -29,6 +29,7 @@ caps.drop all
29netfilter 29netfilter
30nodvd 30nodvd
31nogroups 31nogroups
32noinput
32nonewprivs 33nonewprivs
33noroot 34noroot
34notv 35notv
diff --git a/etc/profile-m-z/opencity.profile b/etc/profile-m-z/opencity.profile
index cb8a511ad..a3d371e15 100644
--- a/etc/profile-m-z/opencity.profile
+++ b/etc/profile-m-z/opencity.profile
@@ -28,6 +28,7 @@ ipc-namespace
28net none 28net none
29nodvd 29nodvd
30nogroups 30nogroups
31noinput
31nonewprivs 32nonewprivs
32noroot 33noroot
33notv 34notv
diff --git a/etc/profile-m-z/openclonk.profile b/etc/profile-m-z/openclonk.profile
index a6760617c..32b40df42 100644
--- a/etc/profile-m-z/openclonk.profile
+++ b/etc/profile-m-z/openclonk.profile
@@ -29,6 +29,7 @@ ipc-namespace
29netfilter 29netfilter
30nodvd 30nodvd
31nogroups 31nogroups
32noinput
32nonewprivs 33nonewprivs
33noroot 34noroot
34notv 35notv
diff --git a/etc/profile-m-z/openmw.profile b/etc/profile-m-z/openmw.profile
index 89b146619..d1fe67aed 100644
--- a/etc/profile-m-z/openmw.profile
+++ b/etc/profile-m-z/openmw.profile
@@ -39,6 +39,7 @@ netfilter
39# Add 'ignore nodvd' to your openmw.local when installing from disc. 39# Add 'ignore nodvd' to your openmw.local when installing from disc.
40nodvd 40nodvd
41nogroups 41nogroups
42noinput
42nonewprivs 43nonewprivs
43noroot 44noroot
44notv 45notv
diff --git a/etc/profile-m-z/openshot.profile b/etc/profile-m-z/openshot.profile
index ac960345a..6118630c4 100644
--- a/etc/profile-m-z/openshot.profile
+++ b/etc/profile-m-z/openshot.profile
@@ -30,6 +30,7 @@ caps.drop all
30net none 30net none
31nodvd 31nodvd
32nogroups 32nogroups
33noinput
33nonewprivs 34nonewprivs
34noroot 35noroot
35notv 36notv
diff --git a/etc/profile-m-z/openttd.profile b/etc/profile-m-z/openttd.profile
index b71883d68..546958bb7 100644
--- a/etc/profile-m-z/openttd.profile
+++ b/etc/profile-m-z/openttd.profile
@@ -28,6 +28,7 @@ ipc-namespace
28net none 28net none
29nodvd 29nodvd
30nogroups 30nogroups
31noinput
31nonewprivs 32nonewprivs
32noroot 33noroot
33notv 34notv
diff --git a/etc/profile-m-z/orage.profile b/etc/profile-m-z/orage.profile
index 4e12892d6..4e4d8bea5 100644
--- a/etc/profile-m-z/orage.profile
+++ b/etc/profile-m-z/orage.profile
@@ -22,6 +22,7 @@ netfilter
22no3d 22no3d
23nodvd 23nodvd
24nogroups 24nogroups
25noinput
25nonewprivs 26nonewprivs
26noroot 27noroot
27# nosound - calendar application, It must be able to play sound to wake you up. 28# nosound - calendar application, It must be able to play sound to wake you up.
diff --git a/etc/profile-m-z/ostrichriders.profile b/etc/profile-m-z/ostrichriders.profile
index 3bfda7946..310b90919 100644
--- a/etc/profile-m-z/ostrichriders.profile
+++ b/etc/profile-m-z/ostrichriders.profile
@@ -29,6 +29,8 @@ ipc-namespace
29net none 29net none
30nodvd 30nodvd
31nogroups 31nogroups
32# Add 'ignore noinput' to your ostrichriders.local if you need controller support.
33noinput
32nonewprivs 34nonewprivs
33noroot 35noroot
34notv 36notv
@@ -42,7 +44,6 @@ tracelog
42disable-mnt 44disable-mnt
43private-bin ostrichriders 45private-bin ostrichriders
44private-cache 46private-cache
45# comment the following line if you need controller support
46private-dev 47private-dev
47private-tmp 48private-tmp
48 49
diff --git a/etc/profile-m-z/otter-browser.profile b/etc/profile-m-z/otter-browser.profile
index aa26ddd4e..20a4e25ed 100644
--- a/etc/profile-m-z/otter-browser.profile
+++ b/etc/profile-m-z/otter-browser.profile
@@ -41,6 +41,7 @@ caps.drop all
41netfilter 41netfilter
42nodvd 42nodvd
43nogroups 43nogroups
44noinput
44nonewprivs 45nonewprivs
45noroot 46noroot
46notv 47notv
diff --git a/etc/profile-m-z/pandoc.profile b/etc/profile-m-z/pandoc.profile
index d2dcef0d0..513b4119e 100644
--- a/etc/profile-m-z/pandoc.profile
+++ b/etc/profile-m-z/pandoc.profile
@@ -31,6 +31,7 @@ net none
31no3d 31no3d
32nodvd 32nodvd
33nogroups 33nogroups
34noinput
34nonewprivs 35nonewprivs
35noroot 36noroot
36nosound 37nosound
diff --git a/etc/profile-m-z/patch.profile b/etc/profile-m-z/patch.profile
index b034efde9..0de968185 100644
--- a/etc/profile-m-z/patch.profile
+++ b/etc/profile-m-z/patch.profile
@@ -28,6 +28,7 @@ net none
28no3d 28no3d
29nodvd 29nodvd
30nogroups 30nogroups
31noinput
31nonewprivs 32nonewprivs
32noroot 33noroot
33nosound 34nosound
diff --git a/etc/profile-m-z/pavucontrol.profile b/etc/profile-m-z/pavucontrol.profile
index f7d3576da..b46fb3026 100644
--- a/etc/profile-m-z/pavucontrol.profile
+++ b/etc/profile-m-z/pavucontrol.profile
@@ -31,6 +31,7 @@ netfilter
31no3d 31no3d
32nodvd 32nodvd
33nogroups 33nogroups
34noinput
34nonewprivs 35nonewprivs
35noroot 36noroot
36notv 37notv
diff --git a/etc/profile-m-z/pdfchain.profile b/etc/profile-m-z/pdfchain.profile
index 4b6da4d6f..d72417914 100644
--- a/etc/profile-m-z/pdfchain.profile
+++ b/etc/profile-m-z/pdfchain.profile
@@ -22,6 +22,7 @@ ipc-namespace
22net none 22net none
23no3d 23no3d
24nogroups 24nogroups
25noinput
25nonewprivs 26nonewprivs
26noroot 27noroot
27nosound 28nosound
diff --git a/etc/profile-m-z/pdfmod.profile b/etc/profile-m-z/pdfmod.profile
index fb3c42526..a19826555 100644
--- a/etc/profile-m-z/pdfmod.profile
+++ b/etc/profile-m-z/pdfmod.profile
@@ -27,6 +27,7 @@ net none
27no3d 27no3d
28nodvd 28nodvd
29nogroups 29nogroups
30noinput
30nonewprivs 31nonewprivs
31noroot 32noroot
32nosound 33nosound
diff --git a/etc/profile-m-z/pdfsam.profile b/etc/profile-m-z/pdfsam.profile
index 2f4227159..e2808d4d2 100644
--- a/etc/profile-m-z/pdfsam.profile
+++ b/etc/profile-m-z/pdfsam.profile
@@ -25,6 +25,7 @@ net none
25no3d 25no3d
26nodvd 26nodvd
27nogroups 27nogroups
28noinput
28nonewprivs 29nonewprivs
29noroot 30noroot
30nosound 31nosound
diff --git a/etc/profile-m-z/pdftotext.profile b/etc/profile-m-z/pdftotext.profile
index 6bbd30b22..d3902a51c 100644
--- a/etc/profile-m-z/pdftotext.profile
+++ b/etc/profile-m-z/pdftotext.profile
@@ -32,6 +32,7 @@ net none
32no3d 32no3d
33nodvd 33nodvd
34nogroups 34nogroups
35noinput
35nonewprivs 36nonewprivs
36noroot 37noroot
37nosound 38nosound
diff --git a/etc/profile-m-z/peek.profile b/etc/profile-m-z/peek.profile
index 710a533a9..c33953687 100644
--- a/etc/profile-m-z/peek.profile
+++ b/etc/profile-m-z/peek.profile
@@ -33,6 +33,7 @@ net none
33no3d 33no3d
34nodvd 34nodvd
35nogroups 35nogroups
36noinput
36nonewprivs 37nonewprivs
37noroot 38noroot
38nosound 39nosound
diff --git a/etc/profile-m-z/penguin-command.profile b/etc/profile-m-z/penguin-command.profile
index db0d84496..f5ad0321d 100644
--- a/etc/profile-m-z/penguin-command.profile
+++ b/etc/profile-m-z/penguin-command.profile
@@ -25,6 +25,7 @@ caps.drop all
25net none 25net none
26nodvd 26nodvd
27nogroups 27nogroups
28noinput
28nonewprivs 29nonewprivs
29noroot 30noroot
30notv 31notv
diff --git a/etc/profile-m-z/photoflare.profile b/etc/profile-m-z/photoflare.profile
index 9e6b4a87d..40068ff78 100644
--- a/etc/profile-m-z/photoflare.profile
+++ b/etc/profile-m-z/photoflare.profile
@@ -28,6 +28,7 @@ net none
28nodvd 28nodvd
29no3d 29no3d
30nogroups 30nogroups
31noinput
31nonewprivs 32nonewprivs
32noroot 33noroot
33nosound 34nosound
diff --git a/etc/profile-m-z/picard.profile b/etc/profile-m-z/picard.profile
index 15fc7a454..a5ea47088 100644
--- a/etc/profile-m-z/picard.profile
+++ b/etc/profile-m-z/picard.profile
@@ -28,6 +28,7 @@ caps.drop all
28no3d 28no3d
29nodvd 29nodvd
30nogroups 30nogroups
31noinput
31nonewprivs 32nonewprivs
32noroot 33noroot
33nosound 34nosound
diff --git a/etc/profile-m-z/pidgin.profile b/etc/profile-m-z/pidgin.profile
index e81e78ca7..26872e9a1 100644
--- a/etc/profile-m-z/pidgin.profile
+++ b/etc/profile-m-z/pidgin.profile
@@ -32,6 +32,7 @@ caps.drop all
32netfilter 32netfilter
33nodvd 33nodvd
34nogroups 34nogroups
35noinput
35nonewprivs 36nonewprivs
36noroot 37noroot
37notv 38notv
diff --git a/etc/profile-m-z/pinball-wrapper.profile b/etc/profile-m-z/pinball-wrapper.profile
new file mode 100644
index 000000000..2b5ed6e27
--- /dev/null
+++ b/etc/profile-m-z/pinball-wrapper.profile
@@ -0,0 +1,14 @@
1# Firejail profile for pinball-wrapper
2# This file is overwritten after every install/update
3# Persistent local customizations
4include pinball-wrapper.local
5# Persistent global definitions
6# added by included profile
7#include globals.local
8
9include allow-opengl-game.inc
10
11private-bin pinball-wrapper
12
13# Redirect
14include pinball.profile
diff --git a/etc/profile-m-z/pinball.profile b/etc/profile-m-z/pinball.profile
new file mode 100644
index 000000000..ab433e729
--- /dev/null
+++ b/etc/profile-m-z/pinball.profile
@@ -0,0 +1,53 @@
1# Firejail profile for pinball
2# Description: Emilia 3D Pinball Game
3# This file is overwritten after every install/update
4# Persistent local customizations
5include pinball.local
6# Persistent global definitions
7include globals.local
8
9noblacklist ${HOME}/.config/emilia
10
11include disable-common.inc
12include disable-devel.inc
13include disable-exec.inc
14include disable-interpreters.inc
15include disable-passwdmgr.inc
16include disable-programs.inc
17include disable-shell.inc
18include disable-xdg.inc
19
20mkdir ${HOME}/.config/emilia
21whitelist ${HOME}/.config/emilia
22whitelist /usr/share/pinball
23include whitelist-common.inc
24include whitelist-runuser-common.inc
25include whitelist-usr-share-common.inc
26include whitelist-var-common.inc
27
28apparmor
29caps.drop all
30net none
31nodvd
32nogroups
33noinput
34nonewprivs
35noroot
36notv
37nou2f
38novideo
39protocol unix
40seccomp
41seccomp.block-secondary
42shell none
43tracelog
44
45disable-mnt
46private-bin pinball
47private-cache
48private-dev
49private-etc alsa,alternatives,asound.conf,fonts,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,locale,machine-id,pulse
50private-tmp
51
52dbus-user none
53dbus-system none
diff --git a/etc/profile-m-z/ping.profile b/etc/profile-m-z/ping.profile
index 03b548ffa..e914007c0 100644
--- a/etc/profile-m-z/ping.profile
+++ b/etc/profile-m-z/ping.profile
@@ -31,6 +31,7 @@ netfilter
31no3d 31no3d
32nodvd 32nodvd
33nogroups 33nogroups
34noinput
34# ping needs to rise privileges, noroot and nonewprivs will kill it 35# ping needs to rise privileges, noroot and nonewprivs will kill it
35#nonewprivs 36#nonewprivs
36#noroot 37#noroot
diff --git a/etc/profile-m-z/pingus.profile b/etc/profile-m-z/pingus.profile
index ebfd236aa..3889d87d2 100644
--- a/etc/profile-m-z/pingus.profile
+++ b/etc/profile-m-z/pingus.profile
@@ -8,12 +8,16 @@ include globals.local
8 8
9noblacklist ${HOME}/.pingus 9noblacklist ${HOME}/.pingus
10 10
11# Allow /bin/sh (blacklisted by disable-shell.inc)
12include allow-bin-sh.inc
13
11include disable-common.inc 14include disable-common.inc
12include disable-devel.inc 15include disable-devel.inc
13include disable-exec.inc 16include disable-exec.inc
14include disable-interpreters.inc 17include disable-interpreters.inc
15include disable-passwdmgr.inc 18include disable-passwdmgr.inc
16include disable-programs.inc 19include disable-programs.inc
20include disable-shell.inc
17include disable-xdg.inc 21include disable-xdg.inc
18 22
19mkdir ${HOME}/.pingus 23mkdir ${HOME}/.pingus
@@ -29,6 +33,7 @@ caps.drop all
29net none 33net none
30nodvd 34nodvd
31nogroups 35nogroups
36noinput
32nonewprivs 37nonewprivs
33noroot 38noroot
34notv 39notv
@@ -36,6 +41,7 @@ nou2f
36novideo 41novideo
37protocol unix,netlink 42protocol unix,netlink
38seccomp 43seccomp
44seccomp.block-secondary
39shell none 45shell none
40tracelog 46tracelog
41 47
diff --git a/etc/profile-m-z/pinta.profile b/etc/profile-m-z/pinta.profile
index 7d94972c4..19406c399 100644
--- a/etc/profile-m-z/pinta.profile
+++ b/etc/profile-m-z/pinta.profile
@@ -23,6 +23,7 @@ ipc-namespace
23net none 23net none
24nodvd 24nodvd
25nogroups 25nogroups
26noinput
26nonewprivs 27nonewprivs
27noroot 28noroot
28nosound 29nosound
diff --git a/etc/profile-m-z/pioneer.profile b/etc/profile-m-z/pioneer.profile
index 5f329195b..721b3944a 100644
--- a/etc/profile-m-z/pioneer.profile
+++ b/etc/profile-m-z/pioneer.profile
@@ -27,6 +27,7 @@ ipc-namespace
27net none 27net none
28nodvd 28nodvd
29nogroups 29nogroups
30noinput
30nonewprivs 31nonewprivs
31noroot 32noroot
32notv 33notv
diff --git a/etc/profile-m-z/pithos.profile b/etc/profile-m-z/pithos.profile
index 0864dd0bc..18990f0b2 100644
--- a/etc/profile-m-z/pithos.profile
+++ b/etc/profile-m-z/pithos.profile
@@ -27,6 +27,7 @@ netfilter
27no3d 27no3d
28nodvd 28nodvd
29nogroups 29nogroups
30noinput
30nonewprivs 31nonewprivs
31noroot 32noroot
32notv 33notv
diff --git a/etc/profile-m-z/pitivi.profile b/etc/profile-m-z/pitivi.profile
index c722e29b4..a2dd809c4 100644
--- a/etc/profile-m-z/pitivi.profile
+++ b/etc/profile-m-z/pitivi.profile
@@ -28,6 +28,7 @@ ipc-namespace
28net none 28net none
29nodvd 29nodvd
30nogroups 30nogroups
31noinput
31nonewprivs 32nonewprivs
32noroot 33noroot
33notv 34notv
diff --git a/etc/profile-m-z/pix.profile b/etc/profile-m-z/pix.profile
index a2c35beb5..81d3e9370 100644
--- a/etc/profile-m-z/pix.profile
+++ b/etc/profile-m-z/pix.profile
@@ -20,6 +20,7 @@ include disable-shell.inc
20caps.drop all 20caps.drop all
21nodvd 21nodvd
22nogroups 22nogroups
23noinput
23nonewprivs 24nonewprivs
24noroot 25noroot
25nosound 26nosound
diff --git a/etc/profile-m-z/pkglog.profile b/etc/profile-m-z/pkglog.profile
index cc4f016c5..4eb41b3bd 100644
--- a/etc/profile-m-z/pkglog.profile
+++ b/etc/profile-m-z/pkglog.profile
@@ -29,6 +29,7 @@ net none
29no3d 29no3d
30nodvd 30nodvd
31nogroups 31nogroups
32noinput
32nonewprivs 33nonewprivs
33noroot 34noroot
34nosound 35nosound
diff --git a/etc/profile-m-z/pluma.profile b/etc/profile-m-z/pluma.profile
index 5303eae8a..10e12e5b1 100644
--- a/etc/profile-m-z/pluma.profile
+++ b/etc/profile-m-z/pluma.profile
@@ -29,6 +29,7 @@ machine-id
29no3d 29no3d
30nodvd 30nodvd
31nogroups 31nogroups
32noinput
32nonewprivs 33nonewprivs
33noroot 34noroot
34nosound 35nosound
@@ -49,6 +50,4 @@ private-tmp
49# dbus-user none 50# dbus-user none
50# dbus-system none 51# dbus-system none
51 52
52memory-deny-write-execute
53
54join-or-start pluma 53join-or-start pluma
diff --git a/etc/profile-m-z/plv.profile b/etc/profile-m-z/plv.profile
index 7f7ae4204..5201fd853 100644
--- a/etc/profile-m-z/plv.profile
+++ b/etc/profile-m-z/plv.profile
@@ -32,6 +32,7 @@ net none
32no3d 32no3d
33nodvd 33nodvd
34nogroups 34nogroups
35noinput
35nonewprivs 36nonewprivs
36noroot 37noroot
37nosound 38nosound
diff --git a/etc/profile-m-z/pngquant.profile b/etc/profile-m-z/pngquant.profile
index 3513e91cc..8a181d5a8 100644
--- a/etc/profile-m-z/pngquant.profile
+++ b/etc/profile-m-z/pngquant.profile
@@ -32,6 +32,7 @@ net none
32no3d 32no3d
33nodvd 33nodvd
34nogroups 34nogroups
35noinput
35nonewprivs 36nonewprivs
36noroot 37noroot
37nosound 38nosound
diff --git a/etc/profile-m-z/polari.profile b/etc/profile-m-z/polari.profile
index 87a53775f..a3d4f9851 100644
--- a/etc/profile-m-z/polari.profile
+++ b/etc/profile-m-z/polari.profile
@@ -35,6 +35,7 @@ netfilter
35no3d 35no3d
36nodvd 36nodvd
37nogroups 37nogroups
38noinput
38nonewprivs 39nonewprivs
39noroot 40noroot
40nosound 41nosound
diff --git a/etc/profile-m-z/pragha.profile b/etc/profile-m-z/pragha.profile
index 019c1a547..f138d785e 100644
--- a/etc/profile-m-z/pragha.profile
+++ b/etc/profile-m-z/pragha.profile
@@ -23,6 +23,7 @@ caps.drop all
23netfilter 23netfilter
24no3d 24no3d
25nogroups 25nogroups
26noinput
26nonewprivs 27nonewprivs
27noroot 28noroot
28notv 29notv
diff --git a/etc/profile-m-z/profanity.profile b/etc/profile-m-z/profanity.profile
index a02bcd826..743458725 100644
--- a/etc/profile-m-z/profanity.profile
+++ b/etc/profile-m-z/profanity.profile
@@ -31,6 +31,7 @@ netfilter
31no3d 31no3d
32nodvd 32nodvd
33nogroups 33nogroups
34noinput
34nonewprivs 35nonewprivs
35noroot 36noroot
36nosound 37nosound
diff --git a/etc/profile-m-z/psi-plus.profile b/etc/profile-m-z/psi-plus.profile
index 16fffe517..5ac58b0ac 100644
--- a/etc/profile-m-z/psi-plus.profile
+++ b/etc/profile-m-z/psi-plus.profile
@@ -30,6 +30,7 @@ netfilter
30no3d 30no3d
31nodvd 31nodvd
32nogroups 32nogroups
33noinput
33nonewprivs 34nonewprivs
34noroot 35noroot
35notv 36notv
diff --git a/etc/profile-m-z/psi.profile b/etc/profile-m-z/psi.profile
index 376743b8d..7e0ef99fc 100644
--- a/etc/profile-m-z/psi.profile
+++ b/etc/profile-m-z/psi.profile
@@ -55,6 +55,7 @@ caps.drop all
55netfilter 55netfilter
56nodvd 56nodvd
57nogroups 57nogroups
58noinput
58nonewprivs 59nonewprivs
59noroot 60noroot
60notv 61notv
diff --git a/etc/profile-m-z/pybitmessage.profile b/etc/profile-m-z/pybitmessage.profile
index 034c144c7..60ae37930 100644
--- a/etc/profile-m-z/pybitmessage.profile
+++ b/etc/profile-m-z/pybitmessage.profile
@@ -28,6 +28,7 @@ netfilter
28no3d 28no3d
29nodvd 29nodvd
30nogroups 30nogroups
31noinput
31nonewprivs 32nonewprivs
32noroot 33noroot
33nosound 34nosound
diff --git a/etc/profile-m-z/pycharm-community.profile b/etc/profile-m-z/pycharm-community.profile
index 9ee426a95..00d7239ae 100644
--- a/etc/profile-m-z/pycharm-community.profile
+++ b/etc/profile-m-z/pycharm-community.profile
@@ -22,6 +22,7 @@ caps.drop all
22machine-id 22machine-id
23nodvd 23nodvd
24nogroups 24nogroups
25noinput
25nosound 26nosound
26notv 27notv
27nou2f 28nou2f
diff --git a/etc/profile-m-z/qbittorrent.profile b/etc/profile-m-z/qbittorrent.profile
index 2fb02aefc..506b738cc 100644
--- a/etc/profile-m-z/qbittorrent.profile
+++ b/etc/profile-m-z/qbittorrent.profile
@@ -41,6 +41,7 @@ machine-id
41netfilter 41netfilter
42nodvd 42nodvd
43nogroups 43nogroups
44noinput
44nonewprivs 45nonewprivs
45noroot 46noroot
46nosound 47nosound
diff --git a/etc/profile-m-z/qgis.profile b/etc/profile-m-z/qgis.profile
index eee538383..2e97daea2 100644
--- a/etc/profile-m-z/qgis.profile
+++ b/etc/profile-m-z/qgis.profile
@@ -37,6 +37,7 @@ netfilter
37machine-id 37machine-id
38nodvd 38nodvd
39nogroups 39nogroups
40noinput
40nonewprivs 41nonewprivs
41noroot 42noroot
42nosound 43nosound
diff --git a/etc/profile-m-z/qlipper.profile b/etc/profile-m-z/qlipper.profile
index fb9dca48f..6e94d5845 100644
--- a/etc/profile-m-z/qlipper.profile
+++ b/etc/profile-m-z/qlipper.profile
@@ -21,6 +21,7 @@ netfilter
21no3d 21no3d
22nodvd 22nodvd
23nogroups 23nogroups
24noinput
24nonewprivs 25nonewprivs
25noroot 26noroot
26nosound 27nosound
diff --git a/etc/profile-m-z/qmmp.profile b/etc/profile-m-z/qmmp.profile
index e1f679417..c3d982c17 100644
--- a/etc/profile-m-z/qmmp.profile
+++ b/etc/profile-m-z/qmmp.profile
@@ -21,6 +21,7 @@ caps.drop all
21netfilter 21netfilter
22# no3d 22# no3d
23nogroups 23nogroups
24noinput
24nonewprivs 25nonewprivs
25noroot 26noroot
26notv 27notv
diff --git a/etc/profile-m-z/qnapi.profile b/etc/profile-m-z/qnapi.profile
index 0d1f9c3de..ca11df5be 100644
--- a/etc/profile-m-z/qnapi.profile
+++ b/etc/profile-m-z/qnapi.profile
@@ -33,6 +33,7 @@ ipc-namespace
33netfilter 33netfilter
34nodvd 34nodvd
35nogroups 35nogroups
36noinput
36nonewprivs 37nonewprivs
37noroot 38noroot
38nosound 39nosound
diff --git a/etc/profile-m-z/qpdfview.profile b/etc/profile-m-z/qpdfview.profile
index 80e34334a..be690ffa4 100644
--- a/etc/profile-m-z/qpdfview.profile
+++ b/etc/profile-m-z/qpdfview.profile
@@ -26,6 +26,7 @@ caps.drop all
26machine-id 26machine-id
27nodvd 27nodvd
28nogroups 28nogroups
29noinput
29nonewprivs 30nonewprivs
30noroot 31noroot
31nosound 32nosound
diff --git a/etc/profile-m-z/qrencode.profile b/etc/profile-m-z/qrencode.profile
index 6480651b2..6cbf8519f 100644
--- a/etc/profile-m-z/qrencode.profile
+++ b/etc/profile-m-z/qrencode.profile
@@ -31,6 +31,7 @@ net none
31no3d 31no3d
32nodvd 32nodvd
33nogroups 33nogroups
34noinput
34nonewprivs 35nonewprivs
35noroot 36noroot
36nosound 37nosound
diff --git a/etc/profile-m-z/qtox.profile b/etc/profile-m-z/qtox.profile
index eb8e3e314..8ffe24d11 100644
--- a/etc/profile-m-z/qtox.profile
+++ b/etc/profile-m-z/qtox.profile
@@ -30,6 +30,7 @@ ipc-namespace
30netfilter 30netfilter
31nodvd 31nodvd
32nogroups 32nogroups
33noinput
33nonewprivs 34nonewprivs
34noroot 35noroot
35notv 36notv
diff --git a/etc/profile-m-z/quaternion.profile b/etc/profile-m-z/quaternion.profile
index 3041860b3..1d146aa39 100644
--- a/etc/profile-m-z/quaternion.profile
+++ b/etc/profile-m-z/quaternion.profile
@@ -34,6 +34,7 @@ caps.drop all
34netfilter 34netfilter
35nodvd 35nodvd
36nogroups 36nogroups
37noinput
37nonewprivs 38nonewprivs
38noroot 39noroot
39notv 40notv
diff --git a/etc/profile-m-z/quiterss.profile b/etc/profile-m-z/quiterss.profile
index 366cff4ed..9490089b2 100644
--- a/etc/profile-m-z/quiterss.profile
+++ b/etc/profile-m-z/quiterss.profile
@@ -37,6 +37,7 @@ caps.drop all
37netfilter 37netfilter
38nodvd 38nodvd
39nogroups 39nogroups
40noinput
40nonewprivs 41nonewprivs
41noroot 42noroot
42nosound 43nosound
diff --git a/etc/profile-m-z/quodlibet.profile b/etc/profile-m-z/quodlibet.profile
index e3680dcf1..92b02b2bf 100644
--- a/etc/profile-m-z/quodlibet.profile
+++ b/etc/profile-m-z/quodlibet.profile
@@ -46,6 +46,7 @@ netfilter
46no3d 46no3d
47nodvd 47nodvd
48nogroups 48nogroups
49noinput
49nonewprivs 50nonewprivs
50noroot 51noroot
51notv 52notv
diff --git a/etc/profile-m-z/redeclipse.profile b/etc/profile-m-z/redeclipse.profile
index a29205e14..9bc196a16 100644
--- a/etc/profile-m-z/redeclipse.profile
+++ b/etc/profile-m-z/redeclipse.profile
@@ -28,6 +28,7 @@ caps.drop all
28netfilter 28netfilter
29nodvd 29nodvd
30nogroups 30nogroups
31noinput
31nonewprivs 32nonewprivs
32noroot 33noroot
33notv 34notv
diff --git a/etc/profile-m-z/redshift.profile b/etc/profile-m-z/redshift.profile
index 298ab1902..f87c5f67c 100644
--- a/etc/profile-m-z/redshift.profile
+++ b/etc/profile-m-z/redshift.profile
@@ -31,6 +31,7 @@ netfilter
31no3d 31no3d
32nodvd 32nodvd
33nogroups 33nogroups
34noinput
34nonewprivs 35nonewprivs
35noroot 36noroot
36nosound 37nosound
diff --git a/etc/profile-m-z/regextester.profile b/etc/profile-m-z/regextester.profile
index 6fb0d4b5f..f5131c5d0 100644
--- a/etc/profile-m-z/regextester.profile
+++ b/etc/profile-m-z/regextester.profile
@@ -16,9 +16,8 @@ include disable-shell.inc
16include disable-xdg.inc 16include disable-xdg.inc
17 17
18whitelist /usr/share/com.github.artemanufrij.regextester 18whitelist /usr/share/com.github.artemanufrij.regextester
19include whitelist-usr-share-common.inc
20
21include whitelist-common.inc 19include whitelist-common.inc
20include whitelist-usr-share-common.inc
22include whitelist-var-common.inc 21include whitelist-var-common.inc
23 22
24apparmor 23apparmor
@@ -29,6 +28,7 @@ net none
29no3d 28no3d
30nodvd 29nodvd
31nogroups 30nogroups
31noinput
32nonewprivs 32nonewprivs
33noroot 33noroot
34nosound 34nosound
@@ -48,11 +48,9 @@ private-etc alternatives,fonts
48private-lib libgranite.so.* 48private-lib libgranite.so.*
49private-tmp 49private-tmp
50 50
51# makes settings immutable 51dbus-user filter
52# dbus-user none 52dbus-user.talk ca.desrt.dconf
53# dbus-system none 53dbus-system none
54
55memory-deny-write-execute
56 54
57# never write anything 55# never write anything
58read-only ${HOME} 56read-only ${HOME}
diff --git a/etc/profile-m-z/remmina.profile b/etc/profile-m-z/remmina.profile
index d4c7bdf31..aca22f187 100644
--- a/etc/profile-m-z/remmina.profile
+++ b/etc/profile-m-z/remmina.profile
@@ -27,6 +27,7 @@ include whitelist-var-common.inc
27caps.drop all 27caps.drop all
28nodvd 28nodvd
29nogroups 29nogroups
30noinput
30nonewprivs 31nonewprivs
31noroot 32noroot
32notv 33notv
diff --git a/etc/profile-m-z/rhythmbox.profile b/etc/profile-m-z/rhythmbox.profile
index 9fb7dc713..970e8ffba 100644
--- a/etc/profile-m-z/rhythmbox.profile
+++ b/etc/profile-m-z/rhythmbox.profile
@@ -38,6 +38,7 @@ apparmor
38caps.drop all 38caps.drop all
39netfilter 39netfilter
40nogroups 40nogroups
41noinput
41nonewprivs 42nonewprivs
42noroot 43noroot
43notv 44notv
diff --git a/etc/profile-m-z/ricochet.profile b/etc/profile-m-z/ricochet.profile
index 86e3fbfb5..b664a2be3 100644
--- a/etc/profile-m-z/ricochet.profile
+++ b/etc/profile-m-z/ricochet.profile
@@ -26,6 +26,7 @@ netfilter
26no3d 26no3d
27nodvd 27nodvd
28nogroups 28nogroups
29noinput
29nonewprivs 30nonewprivs
30noroot 31noroot
31notv 32notv
diff --git a/etc/profile-m-z/ripperx.profile b/etc/profile-m-z/ripperx.profile
index cf6daada5..be815e714 100644
--- a/etc/profile-m-z/ripperx.profile
+++ b/etc/profile-m-z/ripperx.profile
@@ -25,6 +25,7 @@ caps.drop all
25netfilter 25netfilter
26no3d 26no3d
27nogroups 27nogroups
28noinput
28nonewprivs 29nonewprivs
29noroot 30noroot
30nou2f 31nou2f
diff --git a/etc/profile-m-z/ristretto.profile b/etc/profile-m-z/ristretto.profile
index a1cbdf16c..5572cab5a 100644
--- a/etc/profile-m-z/ristretto.profile
+++ b/etc/profile-m-z/ristretto.profile
@@ -26,6 +26,7 @@ netfilter
26no3d 26no3d
27nodvd 27nodvd
28nogroups 28nogroups
29noinput
29nonewprivs 30nonewprivs
30noroot 31noroot
31nosound 32nosound
diff --git a/etc/profile-m-z/rsync-download_only.profile b/etc/profile-m-z/rsync-download_only.profile
index 4bce35d16..690b44bb1 100644
--- a/etc/profile-m-z/rsync-download_only.profile
+++ b/etc/profile-m-z/rsync-download_only.profile
@@ -34,6 +34,7 @@ netfilter
34no3d 34no3d
35nodvd 35nodvd
36nogroups 36nogroups
37noinput
37nonewprivs 38nonewprivs
38noroot 39noroot
39nosound 40nosound
diff --git a/etc/profile-m-z/rtorrent.profile b/etc/profile-m-z/rtorrent.profile
index 308c1c802..6ef51b7f1 100644
--- a/etc/profile-m-z/rtorrent.profile
+++ b/etc/profile-m-z/rtorrent.profile
@@ -18,6 +18,7 @@ caps.drop all
18machine-id 18machine-id
19netfilter 19netfilter
20nodvd 20nodvd
21noinput
21nonewprivs 22nonewprivs
22noroot 23noroot
23nosound 24nosound
diff --git a/etc/profile-m-z/rtv.profile b/etc/profile-m-z/rtv.profile
index 970545ff6..f0b8d31e9 100644
--- a/etc/profile-m-z/rtv.profile
+++ b/etc/profile-m-z/rtv.profile
@@ -41,6 +41,7 @@ netfilter
41no3d 41no3d
42nodvd 42nodvd
43nogroups 43nogroups
44noinput
44nonewprivs 45nonewprivs
45noroot 46noroot
46nosound 47nosound
diff --git a/etc/profile-m-z/sayonara.profile b/etc/profile-m-z/sayonara.profile
index 6557c0c42..de79913cc 100644
--- a/etc/profile-m-z/sayonara.profile
+++ b/etc/profile-m-z/sayonara.profile
@@ -20,6 +20,7 @@ caps.drop all
20netfilter 20netfilter
21no3d 21no3d
22nogroups 22nogroups
23noinput
23nonewprivs 24nonewprivs
24noroot 25noroot
25notv 26notv
diff --git a/etc/profile-m-z/scallion.profile b/etc/profile-m-z/scallion.profile
index 0f67d4d09..eb8468c3b 100644
--- a/etc/profile-m-z/scallion.profile
+++ b/etc/profile-m-z/scallion.profile
@@ -25,6 +25,7 @@ ipc-namespace
25net none 25net none
26nodvd 26nodvd
27nogroups 27nogroups
28noinput
28nonewprivs 29nonewprivs
29noroot 30noroot
30nosound 31nosound
diff --git a/etc/profile-m-z/scorched3d-wrapper.profile b/etc/profile-m-z/scorched3d-wrapper.profile
index 507d0827e..e76caec1d 100644
--- a/etc/profile-m-z/scorched3d-wrapper.profile
+++ b/etc/profile-m-z/scorched3d-wrapper.profile
@@ -1,10 +1,11 @@
1# Firejail profile for scorched3d 1# Firejail profile for scorched3d-wrapper
2# This file is overwritten after every install/update 2# This file is overwritten after every install/update
3# Persistent local customizations 3# Persistent local customizations
4include scorched3d-wrapper.local 4include scorched3d-wrapper.local
5 5
6whitelist /usr/share/opengl-games-utils 6include allow-opengl-game.inc
7private-bin basename,bash,cut,glxinfo,grep,head,sed,zenity 7
8private-bin scorched3d-wrapper
8 9
9# Redirect 10# Redirect
10include scorched3d.profile 11include scorched3d.profile
diff --git a/etc/profile-m-z/scorched3d.profile b/etc/profile-m-z/scorched3d.profile
index 6a1003c33..aac3e721f 100644
--- a/etc/profile-m-z/scorched3d.profile
+++ b/etc/profile-m-z/scorched3d.profile
@@ -29,6 +29,7 @@ ipc-namespace
29netfilter 29netfilter
30nodvd 30nodvd
31nogroups 31nogroups
32noinput
32nonewprivs 33nonewprivs
33noroot 34noroot
34notv 35notv
@@ -40,7 +41,7 @@ shell none
40tracelog 41tracelog
41 42
42disable-mnt 43disable-mnt
43private-bin scorched3d,scorched3d-wrapper,scorched3dc,scorched3ds 44private-bin scorched3d,scorched3dc,scorched3ds
44private-cache 45private-cache
45private-dev 46private-dev
46private-tmp 47private-tmp
diff --git a/etc/profile-m-z/scorchwentbonkers.profile b/etc/profile-m-z/scorchwentbonkers.profile
index 484ebc38e..2cb1df6b5 100644
--- a/etc/profile-m-z/scorchwentbonkers.profile
+++ b/etc/profile-m-z/scorchwentbonkers.profile
@@ -29,6 +29,7 @@ caps.drop all
29net none 29net none
30nodvd 30nodvd
31nogroups 31nogroups
32noinput
32nonewprivs 33nonewprivs
33noroot 34noroot
34notv 35notv
diff --git a/etc/profile-m-z/scribus.profile b/etc/profile-m-z/scribus.profile
index 22cd10737..1fdeaa145 100644
--- a/etc/profile-m-z/scribus.profile
+++ b/etc/profile-m-z/scribus.profile
@@ -45,6 +45,7 @@ caps.drop all
45net none 45net none
46nodvd 46nodvd
47nogroups 47nogroups
48noinput
48nonewprivs 49nonewprivs
49noroot 50noroot
50nosound 51nosound
diff --git a/etc/profile-m-z/sdat2img.profile b/etc/profile-m-z/sdat2img.profile
index 8d16cd07f..aa2fa9b1b 100644
--- a/etc/profile-m-z/sdat2img.profile
+++ b/etc/profile-m-z/sdat2img.profile
@@ -26,6 +26,7 @@ net none
26no3d 26no3d
27nodvd 27nodvd
28nogroups 28nogroups
29noinput
29nonewprivs 30nonewprivs
30noroot 31noroot
31nosound 32nosound
diff --git a/etc/profile-m-z/seahorse-adventures.profile b/etc/profile-m-z/seahorse-adventures.profile
index cb2e5ef91..131dcbb68 100644
--- a/etc/profile-m-z/seahorse-adventures.profile
+++ b/etc/profile-m-z/seahorse-adventures.profile
@@ -29,6 +29,7 @@ caps.drop all
29net none 29net none
30nodvd 30nodvd
31nogroups 31nogroups
32noinput
32nonewprivs 33nonewprivs
33noroot 34noroot
34notv 35notv
diff --git a/etc/profile-m-z/seahorse.profile b/etc/profile-m-z/seahorse.profile
index 2b82e5d06..d3d8e453f 100644
--- a/etc/profile-m-z/seahorse.profile
+++ b/etc/profile-m-z/seahorse.profile
@@ -46,6 +46,7 @@ netfilter
46no3d 46no3d
47nodvd 47nodvd
48nogroups 48nogroups
49noinput
49nonewprivs 50nonewprivs
50noroot 51noroot
51nosound 52nosound
diff --git a/etc/profile-m-z/server.profile b/etc/profile-m-z/server.profile
index d47f1289a..7d56684db 100644
--- a/etc/profile-m-z/server.profile
+++ b/etc/profile-m-z/server.profile
@@ -60,6 +60,7 @@ machine-id
60no3d 60no3d
61nodvd 61nodvd
62# nogroups 62# nogroups
63noinput
63# nonewprivs 64# nonewprivs
64# noroot 65# noroot
65nosound 66nosound
diff --git a/etc/profile-m-z/servo.profile b/etc/profile-m-z/servo.profile
index dc3fdaf34..df8fbc3e3 100644
--- a/etc/profile-m-z/servo.profile
+++ b/etc/profile-m-z/servo.profile
@@ -29,6 +29,7 @@ caps.drop all
29netfilter 29netfilter
30nodvd 30nodvd
31nogroups 31nogroups
32noinput
32nonewprivs 33nonewprivs
33noroot 34noroot
34notv 35notv
diff --git a/etc/profile-m-z/shellcheck.profile b/etc/profile-m-z/shellcheck.profile
index 2ae298142..b7f398f45 100644
--- a/etc/profile-m-z/shellcheck.profile
+++ b/etc/profile-m-z/shellcheck.profile
@@ -31,6 +31,7 @@ net none
31no3d 31no3d
32nodvd 32nodvd
33nogroups 33nogroups
34noinput
34nonewprivs 35nonewprivs
35noroot 36noroot
36nosound 37nosound
diff --git a/etc/profile-m-z/shortwave.profile b/etc/profile-m-z/shortwave.profile
index ee2314833..d629240ec 100644
--- a/etc/profile-m-z/shortwave.profile
+++ b/etc/profile-m-z/shortwave.profile
@@ -32,6 +32,7 @@ caps.drop all
32netfilter 32netfilter
33nodvd 33nodvd
34nogroups 34nogroups
35noinput
35nonewprivs 36nonewprivs
36noroot 37noroot
37notv 38notv
diff --git a/etc/profile-m-z/shotcut.profile b/etc/profile-m-z/shotcut.profile
index bec0bfbb0..63af4d367 100644
--- a/etc/profile-m-z/shotcut.profile
+++ b/etc/profile-m-z/shotcut.profile
@@ -21,6 +21,7 @@ caps.drop all
21net none 21net none
22nodvd 22nodvd
23nogroups 23nogroups
24noinput
24nonewprivs 25nonewprivs
25noroot 26noroot
26notv 27notv
diff --git a/etc/profile-m-z/shotwell.profile b/etc/profile-m-z/shotwell.profile
index 749029530..ddc8a7743 100644
--- a/etc/profile-m-z/shotwell.profile
+++ b/etc/profile-m-z/shotwell.profile
@@ -35,6 +35,7 @@ machine-id
35netfilter 35netfilter
36nodvd 36nodvd
37nogroups 37nogroups
38noinput
38nonewprivs 39nonewprivs
39noroot 40noroot
40nosound 41nosound
diff --git a/etc/profile-m-z/signal-cli.profile b/etc/profile-m-z/signal-cli.profile
index 6a2f5c434..478377344 100644
--- a/etc/profile-m-z/signal-cli.profile
+++ b/etc/profile-m-z/signal-cli.profile
@@ -31,6 +31,7 @@ netfilter
31no3d 31no3d
32nodvd 32nodvd
33nogroups 33nogroups
34noinput
34nonewprivs 35nonewprivs
35noroot 36noroot
36nosound 37nosound
diff --git a/etc/profile-m-z/silentarmy.profile b/etc/profile-m-z/silentarmy.profile
index 220035ee7..3f3e2a75d 100644
--- a/etc/profile-m-z/silentarmy.profile
+++ b/etc/profile-m-z/silentarmy.profile
@@ -21,6 +21,7 @@ caps.drop all
21netfilter 21netfilter
22nodvd 22nodvd
23nogroups 23nogroups
24noinput
24nonewprivs 25nonewprivs
25noroot 26noroot
26nosound 27nosound
diff --git a/etc/profile-m-z/simplescreenrecorder.profile b/etc/profile-m-z/simplescreenrecorder.profile
index edcc2a0f4..d664f8bf5 100644
--- a/etc/profile-m-z/simplescreenrecorder.profile
+++ b/etc/profile-m-z/simplescreenrecorder.profile
@@ -25,6 +25,7 @@ apparmor
25caps.drop all 25caps.drop all
26nodvd 26nodvd
27nogroups 27nogroups
28noinput
28nonewprivs 29nonewprivs
29noroot 30noroot
30notv 31notv
diff --git a/etc/profile-m-z/simutrans.profile b/etc/profile-m-z/simutrans.profile
index 1b81f2ea1..afaa0f6d8 100644
--- a/etc/profile-m-z/simutrans.profile
+++ b/etc/profile-m-z/simutrans.profile
@@ -25,6 +25,7 @@ caps.drop all
25net none 25net none
26nodvd 26nodvd
27nogroups 27nogroups
28noinput
28nonewprivs 29nonewprivs
29noroot 30noroot
30notv 31notv
diff --git a/etc/profile-m-z/slashem.profile b/etc/profile-m-z/slashem.profile
index ca0516e65..c5a31c237 100644
--- a/etc/profile-m-z/slashem.profile
+++ b/etc/profile-m-z/slashem.profile
@@ -25,6 +25,7 @@ net none
25no3d 25no3d
26nodvd 26nodvd
27nogroups 27nogroups
28noinput
28#nonewprivs 29#nonewprivs
29#noroot 30#noroot
30nosound 31nosound
diff --git a/etc/profile-m-z/smplayer.profile b/etc/profile-m-z/smplayer.profile
index 9d6db4cdb..01547e5c1 100644
--- a/etc/profile-m-z/smplayer.profile
+++ b/etc/profile-m-z/smplayer.profile
@@ -39,6 +39,7 @@ apparmor
39caps.drop all 39caps.drop all
40netfilter 40netfilter
41# nogroups 41# nogroups
42noinput
42nonewprivs 43nonewprivs
43noroot 44noroot
44nou2f 45nou2f
diff --git a/etc/profile-m-z/smtube.profile b/etc/profile-m-z/smtube.profile
index 79bc02979..196950eaf 100644
--- a/etc/profile-m-z/smtube.profile
+++ b/etc/profile-m-z/smtube.profile
@@ -36,6 +36,7 @@ notv
36nou2f 36nou2f
37novideo 37novideo
38nogroups 38nogroups
39noinput
39nonewprivs 40nonewprivs
40noroot 41noroot
41protocol unix,inet,inet6,netlink 42protocol unix,inet,inet6,netlink
diff --git a/etc/profile-m-z/smuxi-frontend-gnome.profile b/etc/profile-m-z/smuxi-frontend-gnome.profile
index 541e5a1c4..c3a9bb858 100644
--- a/etc/profile-m-z/smuxi-frontend-gnome.profile
+++ b/etc/profile-m-z/smuxi-frontend-gnome.profile
@@ -35,6 +35,7 @@ caps.drop all
35netfilter 35netfilter
36nodvd 36nodvd
37nogroups 37nogroups
38noinput
38nonewprivs 39nonewprivs
39noroot 40noroot
40notv 41notv
diff --git a/etc/profile-m-z/softmaker-common.profile b/etc/profile-m-z/softmaker-common.profile
index a8ec5848c..83315231f 100644
--- a/etc/profile-m-z/softmaker-common.profile
+++ b/etc/profile-m-z/softmaker-common.profile
@@ -30,6 +30,7 @@ ipc-namespace
30netfilter 30netfilter
31nodvd 31nodvd
32nogroups 32nogroups
33noinput
33nonewprivs 34nonewprivs
34noroot 35noroot
35notv 36notv
diff --git a/etc/profile-m-z/sol.profile b/etc/profile-m-z/sol.profile
index 44fb8cfe2..6b8a17813 100644
--- a/etc/profile-m-z/sol.profile
+++ b/etc/profile-m-z/sol.profile
@@ -25,6 +25,7 @@ net none
25# no3d 25# no3d
26nodvd 26nodvd
27nogroups 27nogroups
28noinput
28nonewprivs 29nonewprivs
29noroot 30noroot
30# nosound 31# nosound
diff --git a/etc/profile-m-z/sound-juicer.profile b/etc/profile-m-z/sound-juicer.profile
index b9f3768be..ef00fdfff 100644
--- a/etc/profile-m-z/sound-juicer.profile
+++ b/etc/profile-m-z/sound-juicer.profile
@@ -24,6 +24,7 @@ caps.drop all
24netfilter 24netfilter
25no3d 25no3d
26nogroups 26nogroups
27noinput
27nonewprivs 28nonewprivs
28noroot 29noroot
29nosound 30nosound
diff --git a/etc/profile-m-z/soundconverter.profile b/etc/profile-m-z/soundconverter.profile
index bdd6eb7f5..4dbf34100 100644
--- a/etc/profile-m-z/soundconverter.profile
+++ b/etc/profile-m-z/soundconverter.profile
@@ -34,6 +34,7 @@ machine-id
34no3d 34no3d
35nodvd 35nodvd
36nogroups 36nogroups
37noinput
37nonewprivs 38nonewprivs
38noroot 39noroot
39nosound 40nosound
diff --git a/etc/profile-m-z/spectacle.profile b/etc/profile-m-z/spectacle.profile
index cedff0b83..4468f21e7 100644
--- a/etc/profile-m-z/spectacle.profile
+++ b/etc/profile-m-z/spectacle.profile
@@ -26,6 +26,8 @@ include disable-xdg.inc
26mkfile ${HOME}/.config/spectaclerc 26mkfile ${HOME}/.config/spectaclerc
27whitelist ${HOME}/.config/spectaclerc 27whitelist ${HOME}/.config/spectaclerc
28whitelist ${PICTURES} 28whitelist ${PICTURES}
29whitelist /usr/share/kconf_update/spectacle_newConfig.upd
30whitelist /usr/share/kconf_update/spectacle_shortcuts.upd
29include whitelist-common.inc 31include whitelist-common.inc
30include whitelist-runuser-common.inc 32include whitelist-runuser-common.inc
31include whitelist-usr-share-common.inc 33include whitelist-usr-share-common.inc
@@ -38,6 +40,7 @@ net none
38no3d 40no3d
39nodvd 41nodvd
40nogroups 42nogroups
43noinput
41nonewprivs 44nonewprivs
42noroot 45noroot
43nosound 46nosound
diff --git a/etc/profile-m-z/spectral.profile b/etc/profile-m-z/spectral.profile
index bf0f9f3a1..283674517 100644
--- a/etc/profile-m-z/spectral.profile
+++ b/etc/profile-m-z/spectral.profile
@@ -33,6 +33,7 @@ caps.drop all
33netfilter 33netfilter
34nodvd 34nodvd
35nogroups 35nogroups
36noinput
36nonewprivs 37nonewprivs
37noroot 38noroot
38notv 39notv
diff --git a/etc/profile-m-z/spotify.profile b/etc/profile-m-z/spotify.profile
index 1a34cb86d..01bc2bc05 100644
--- a/etc/profile-m-z/spotify.profile
+++ b/etc/profile-m-z/spotify.profile
@@ -31,6 +31,7 @@ caps.drop all
31netfilter 31netfilter
32nodvd 32nodvd
33nogroups 33nogroups
34noinput
34nonewprivs 35nonewprivs
35noroot 36noroot
36notv 37notv
@@ -43,7 +44,7 @@ tracelog
43disable-mnt 44disable-mnt
44private-bin bash,cat,dirname,find,grep,head,rm,sh,spotify,tclsh,touch,zenity 45private-bin bash,cat,dirname,find,grep,head,rm,sh,spotify,tclsh,touch,zenity
45private-dev 46private-dev
46# Comment the next line or put 'ignore private-etc' in your spotify.local if want to see the albums covers or if you want to use the radio 47# If you want to see album covers or want to use the radio, add 'ignore private-etc' to your spotify.local.
47private-etc alternatives,ca-certificates,crypto-policies,fonts,group,host.conf,hosts,ld.so.cache,machine-id,nsswitch.conf,pki,pulse,resolv.conf,ssl 48private-etc alternatives,ca-certificates,crypto-policies,fonts,group,host.conf,hosts,ld.so.cache,machine-id,nsswitch.conf,pki,pulse,resolv.conf,ssl
48private-opt spotify 49private-opt spotify
49private-srv none 50private-srv none
diff --git a/etc/profile-m-z/sqlitebrowser.profile b/etc/profile-m-z/sqlitebrowser.profile
index 110434736..4dd2c7262 100644
--- a/etc/profile-m-z/sqlitebrowser.profile
+++ b/etc/profile-m-z/sqlitebrowser.profile
@@ -28,6 +28,7 @@ ipc-namespace
28netfilter 28netfilter
29nodvd 29nodvd
30nogroups 30nogroups
31noinput
31nonewprivs 32nonewprivs
32noroot 33noroot
33nosound 34nosound
diff --git a/etc/profile-m-z/ssh.profile b/etc/profile-m-z/ssh.profile
index 7bc731333..a58642192 100644
--- a/etc/profile-m-z/ssh.profile
+++ b/etc/profile-m-z/ssh.profile
@@ -31,6 +31,7 @@ netfilter
31no3d 31no3d
32nodvd 32nodvd
33nogroups 33nogroups
34noinput
34nonewprivs 35nonewprivs
35# noroot - see issue #1543 36# noroot - see issue #1543
36nosound 37nosound
diff --git a/etc/profile-m-z/standardnotes-desktop.profile b/etc/profile-m-z/standardnotes-desktop.profile
index 1292b806b..48a532876 100644
--- a/etc/profile-m-z/standardnotes-desktop.profile
+++ b/etc/profile-m-z/standardnotes-desktop.profile
@@ -27,6 +27,7 @@ machine-id
27netfilter 27netfilter
28nodvd 28nodvd
29nogroups 29nogroups
30noinput
30nonewprivs 31nonewprivs
31noroot 32noroot
32nosound 33nosound
diff --git a/etc/profile-m-z/steam.profile b/etc/profile-m-z/steam.profile
index 0bcbe6da2..06d08f3a2 100644
--- a/etc/profile-m-z/steam.profile
+++ b/etc/profile-m-z/steam.profile
@@ -10,6 +10,7 @@ noblacklist ${HOME}/.config/Epic
10noblacklist ${HOME}/.config/Loop_Hero 10noblacklist ${HOME}/.config/Loop_Hero
11noblacklist ${HOME}/.config/ModTheSpire 11noblacklist ${HOME}/.config/ModTheSpire
12noblacklist ${HOME}/.config/RogueLegacy 12noblacklist ${HOME}/.config/RogueLegacy
13noblacklist ${HOME}/.config/RogueLegacyStorageContainer
13noblacklist ${HOME}/.killingfloor 14noblacklist ${HOME}/.killingfloor
14noblacklist ${HOME}/.klei 15noblacklist ${HOME}/.klei
15noblacklist ${HOME}/.local/share/3909/PapersPlease 16noblacklist ${HOME}/.local/share/3909/PapersPlease
@@ -22,7 +23,8 @@ noblacklist ${HOME}/.local/share/feral-interactive
22noblacklist ${HOME}/.local/share/IntoTheBreach 23noblacklist ${HOME}/.local/share/IntoTheBreach
23noblacklist ${HOME}/.local/share/Paradox Interactive 24noblacklist ${HOME}/.local/share/Paradox Interactive
24noblacklist ${HOME}/.local/share/PillarsOfEternity 25noblacklist ${HOME}/.local/share/PillarsOfEternity
25noblacklist ${HOME}/.local/share/RogueLegacy* 26noblacklist ${HOME}/.local/share/RogueLegacy
27noblacklist ${HOME}/.local/share/RogueLegacyStorageContainer
26noblacklist ${HOME}/.local/share/Steam 28noblacklist ${HOME}/.local/share/Steam
27noblacklist ${HOME}/.local/share/SteamWorldDig 29noblacklist ${HOME}/.local/share/SteamWorldDig
28noblacklist ${HOME}/.local/share/SteamWorld Dig 2 30noblacklist ${HOME}/.local/share/SteamWorld Dig 2
@@ -69,7 +71,7 @@ mkdir ${HOME}/.local/share/feral-interactive
69mkdir ${HOME}/.local/share/IntoTheBreach 71mkdir ${HOME}/.local/share/IntoTheBreach
70mkdir ${HOME}/.local/share/Paradox Interactive 72mkdir ${HOME}/.local/share/Paradox Interactive
71mkdir ${HOME}/.local/share/PillarsOfEternity 73mkdir ${HOME}/.local/share/PillarsOfEternity
72mkdir ${HOME}/.local/share/RogueLegacy* 74mkdir ${HOME}/.local/share/RogueLegacy
73mkdir ${HOME}/.local/share/Steam 75mkdir ${HOME}/.local/share/Steam
74mkdir ${HOME}/.local/share/SteamWorldDig 76mkdir ${HOME}/.local/share/SteamWorldDig
75mkdir ${HOME}/.local/share/SteamWorld Dig 2 77mkdir ${HOME}/.local/share/SteamWorld Dig 2
@@ -86,6 +88,7 @@ whitelist ${HOME}/.config/Epic
86whitelist ${HOME}/.config/Loop_Hero 88whitelist ${HOME}/.config/Loop_Hero
87whitelist ${HOME}/.config/ModTheSpire 89whitelist ${HOME}/.config/ModTheSpire
88whitelist ${HOME}/.config/RogueLegacy 90whitelist ${HOME}/.config/RogueLegacy
91whitelist ${HOME}/.config/RogueLegacyStorageContainer
89whitelist ${HOME}/.config/unity3d 92whitelist ${HOME}/.config/unity3d
90whitelist ${HOME}/.killingfloor 93whitelist ${HOME}/.killingfloor
91whitelist ${HOME}/.klei 94whitelist ${HOME}/.klei
@@ -99,7 +102,8 @@ whitelist ${HOME}/.local/share/feral-interactive
99whitelist ${HOME}/.local/share/IntoTheBreach 102whitelist ${HOME}/.local/share/IntoTheBreach
100whitelist ${HOME}/.local/share/Paradox Interactive 103whitelist ${HOME}/.local/share/Paradox Interactive
101whitelist ${HOME}/.local/share/PillarsOfEternity 104whitelist ${HOME}/.local/share/PillarsOfEternity
102whitelist ${HOME}/.local/share/RogueLegacy* 105whitelist ${HOME}/.local/share/RogueLegacy
106whitelist ${HOME}/.local/share/RogueLegacyStorageContainer
103whitelist ${HOME}/.local/share/Steam 107whitelist ${HOME}/.local/share/Steam
104whitelist ${HOME}/.local/share/SteamWorldDig 108whitelist ${HOME}/.local/share/SteamWorldDig
105whitelist ${HOME}/.local/share/SteamWorld Dig 2 109whitelist ${HOME}/.local/share/SteamWorld Dig 2
@@ -115,39 +119,48 @@ whitelist ${HOME}/.steampid
115include whitelist-common.inc 119include whitelist-common.inc
116include whitelist-var-common.inc 120include whitelist-var-common.inc
117 121
122# NOTE: The following were intentionally left out as they are alternative
123# (i.e.: unnecessary and/or legacy) paths whose existence may potentially
124# clobber other paths (see #4225). If you use any, either add the entry to
125# steam.local or move the contents to a path listed above (or open an issue if
126# it's missing above).
127#mkdir ${HOME}/.config/RogueLegacyStorageContainer
128#mkdir ${HOME}/.local/share/RogueLegacyStorageContainer
129
118caps.drop all 130caps.drop all
119#ipc-namespace 131#ipc-namespace
120netfilter 132netfilter
121nodvd 133nodvd
122# nVidia users may need to comment / ignore nogroups and noroot
123nogroups 134nogroups
124nonewprivs 135nonewprivs
136# If you use nVidia you might need to add 'ignore noroot' to your steam.local.
125noroot 137noroot
126notv 138notv
127nou2f 139nou2f
128# novideo should be commented for VR 140# For VR support add 'ignore novideo' to your steam.local.
129novideo 141novideo
130protocol unix,inet,inet6,netlink 142protocol unix,inet,inet6,netlink
131# seccomp sometimes causes issues (see #2951, #3267), 143# seccomp sometimes causes issues (see #2951, #3267).
132# comment it or add 'ignore seccomp' to steam.local if so. 144# Add 'ignore seccomp' to your steam.local if you experience this.
133seccomp !ptrace 145seccomp !ptrace
134shell none 146shell none
135# tracelog breaks integrated browser 147# tracelog breaks integrated browser
136#tracelog 148#tracelog
137 149
138# private-bin is disabled while in testing, but has been tested working with multiple games 150# private-bin is disabled while in testing, but is known to work with multiple games.
151# Add the next line to your steam.local to enable private-bin.
139#private-bin awk,basename,bash,bsdtar,bzip2,cat,chmod,cksum,cmp,comm,compress,cp,curl,cut,date,dbus-launch,dbus-send,desktop-file-edit,desktop-file-install,desktop-file-validate,dirname,echo,env,expr,file,find,getopt,grep,gtar,gzip,head,hostname,id,lbzip2,ldconfig,ldd,ln,ls,lsb_release,lsof,lspci,lz4,lzip,lzma,lzop,md5sum,mkdir,mktemp,mv,netstat,ps,pulseaudio,python*,readlink,realpath,rm,sed,sh,sha1sum,sha256sum,sha512sum,sleep,sort,steam,steamdeps,steam-native,steam-runtime,sum,tail,tar,tclsh,test,touch,tr,umask,uname,update-desktop-database,wc,wget,which,whoami,xterm,xz,zenity 152#private-bin awk,basename,bash,bsdtar,bzip2,cat,chmod,cksum,cmp,comm,compress,cp,curl,cut,date,dbus-launch,dbus-send,desktop-file-edit,desktop-file-install,desktop-file-validate,dirname,echo,env,expr,file,find,getopt,grep,gtar,gzip,head,hostname,id,lbzip2,ldconfig,ldd,ln,ls,lsb_release,lsof,lspci,lz4,lzip,lzma,lzop,md5sum,mkdir,mktemp,mv,netstat,ps,pulseaudio,python*,readlink,realpath,rm,sed,sh,sha1sum,sha256sum,sha512sum,sleep,sort,steam,steamdeps,steam-native,steam-runtime,sum,tail,tar,tclsh,test,touch,tr,umask,uname,update-desktop-database,wc,wget,which,whoami,xterm,xz,zenity
140# extra programs are available which might be needed for select games 153# Extra programs are available which might be needed for select games.
154# Add the next line to your steam.local to enable support for these programs.
141#private-bin java,java-config,mono 155#private-bin java,java-config,mono
142# picture viewers are needed for viewing screenshots 156# To view screenshots add the next line to your steam.local.
143#private-bin eog,eom,gthumb,pix,viewnior,xviewer 157#private-bin eog,eom,gthumb,pix,viewnior,xviewer
144 158
145# comment the following line if you need controller support
146private-dev 159private-dev
147# private-etc breaks a small selection of games on some systems, comment to support those 160# private-etc breaks a small selection of games on some systems. Add 'ignore private-etc'
161# to your steam.local to support those.
148private-etc alsa,alternatives,asound.conf,bumblebee,ca-certificates,crypto-policies,dbus-1,drirc,fonts,group,gtk-2.0,gtk-3.0,host.conf,hostname,hosts,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,localtime,lsb-release,machine-id,mime.types,nvidia,os-release,passwd,pki,pulse,resolv.conf,services,ssl 162private-etc alsa,alternatives,asound.conf,bumblebee,ca-certificates,crypto-policies,dbus-1,drirc,fonts,group,gtk-2.0,gtk-3.0,host.conf,hostname,hosts,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,localtime,lsb-release,machine-id,mime.types,nvidia,os-release,passwd,pki,pulse,resolv.conf,services,ssl
149private-tmp 163private-tmp
150 164
151# breaks appindicator support
152# dbus-user none 165# dbus-user none
153# dbus-system none 166# dbus-system none
diff --git a/etc/profile-m-z/stellarium.profile b/etc/profile-m-z/stellarium.profile
index 3f93fe591..a752ab53c 100644
--- a/etc/profile-m-z/stellarium.profile
+++ b/etc/profile-m-z/stellarium.profile
@@ -29,6 +29,7 @@ machine-id
29netfilter 29netfilter
30nodvd 30nodvd
31nogroups 31nogroups
32noinput
32nonewprivs 33nonewprivs
33noroot 34noroot
34nosound 35nosound
diff --git a/etc/profile-m-z/straw-viewer.profile b/etc/profile-m-z/straw-viewer.profile
index 2ae35d211..f8108c9d6 100644
--- a/etc/profile-m-z/straw-viewer.profile
+++ b/etc/profile-m-z/straw-viewer.profile
@@ -42,6 +42,7 @@ caps.drop all
42netfilter 42netfilter
43nodvd 43nodvd
44nogroups 44nogroups
45noinput
45nonewprivs 46nonewprivs
46noroot 47noroot
47notv 48notv
diff --git a/etc/profile-m-z/strawberry.profile b/etc/profile-m-z/strawberry.profile
index 0801add28..b87906f55 100644
--- a/etc/profile-m-z/strawberry.profile
+++ b/etc/profile-m-z/strawberry.profile
@@ -28,6 +28,7 @@ caps.drop all
28netfilter 28netfilter
29nodvd 29nodvd
30nogroups 30nogroups
31noinput
31nonewprivs 32nonewprivs
32noroot 33noroot
33notv 34notv
diff --git a/etc/profile-m-z/strings.profile b/etc/profile-m-z/strings.profile
index 6a582532d..1ebcded7f 100644
--- a/etc/profile-m-z/strings.profile
+++ b/etc/profile-m-z/strings.profile
@@ -29,6 +29,7 @@ net none
29no3d 29no3d
30nodvd 30nodvd
31nogroups 31nogroups
32noinput
32nonewprivs 33nonewprivs
33#noroot 34#noroot
34nosound 35nosound
diff --git a/etc/profile-m-z/subdownloader.profile b/etc/profile-m-z/subdownloader.profile
index 428af3737..bbe92fd38 100644
--- a/etc/profile-m-z/subdownloader.profile
+++ b/etc/profile-m-z/subdownloader.profile
@@ -32,6 +32,7 @@ netfilter
32no3d 32no3d
33nodvd 33nodvd
34nogroups 34nogroups
35noinput
35nonewprivs 36nonewprivs
36noroot 37noroot
37nosound 38nosound
diff --git a/etc/profile-m-z/supertux2.profile b/etc/profile-m-z/supertux2.profile
index 9cc023765..dd456f085 100644
--- a/etc/profile-m-z/supertux2.profile
+++ b/etc/profile-m-z/supertux2.profile
@@ -14,6 +14,7 @@ include disable-exec.inc
14include disable-interpreters.inc 14include disable-interpreters.inc
15include disable-passwdmgr.inc 15include disable-passwdmgr.inc
16include disable-programs.inc 16include disable-programs.inc
17include disable-shell.inc
17include disable-xdg.inc 18include disable-xdg.inc
18 19
19mkdir ${HOME}/.local/share/supertux2 20mkdir ${HOME}/.local/share/supertux2
@@ -29,6 +30,7 @@ caps.drop all
29net none 30net none
30nodvd 31nodvd
31nogroups 32nogroups
33noinput
32nonewprivs 34nonewprivs
33noroot 35noroot
34notv 36notv
@@ -42,6 +44,8 @@ tracelog
42 44
43disable-mnt 45disable-mnt
44# private-bin supertux2 46# private-bin supertux2
47private-cache
48private-etc machine-id
45private-dev 49private-dev
46private-tmp 50private-tmp
47 51
diff --git a/etc/profile-m-z/supertuxkart-wrapper.profile b/etc/profile-m-z/supertuxkart-wrapper.profile
new file mode 100644
index 000000000..af8d73deb
--- /dev/null
+++ b/etc/profile-m-z/supertuxkart-wrapper.profile
@@ -0,0 +1,14 @@
1# Firejail profile for supertuxkart-wrapper
2# This file is overwritten after every install/update
3# Persistent local customizations
4include supertuxkart-wrapper.local
5# Persistent global definitions
6# added by included profile
7#include globals.local
8
9include allow-opengl-game.inc
10
11private-bin supertuxkart-wrapper
12
13# Redirect
14include supertuxkart.profile
diff --git a/etc/profile-m-z/surf.profile b/etc/profile-m-z/surf.profile
index 5ad82601d..8db7d2433 100644
--- a/etc/profile-m-z/surf.profile
+++ b/etc/profile-m-z/surf.profile
@@ -22,6 +22,7 @@ include whitelist-common.inc
22caps.drop all 22caps.drop all
23netfilter 23netfilter
24nodvd 24nodvd
25noinput
25nonewprivs 26nonewprivs
26noroot 27noroot
27notv 28notv
diff --git a/etc/profile-m-z/sushi.profile b/etc/profile-m-z/sushi.profile
index 68abd8c94..2a15a5d09 100644
--- a/etc/profile-m-z/sushi.profile
+++ b/etc/profile-m-z/sushi.profile
@@ -24,6 +24,7 @@ caps.drop all
24net none 24net none
25nodvd 25nodvd
26nogroups 26nogroups
27noinput
27nonewprivs 28nonewprivs
28noroot 29noroot
29notv 30notv
diff --git a/etc/profile-m-z/synfigstudio.profile b/etc/profile-m-z/synfigstudio.profile
index a83080cc3..c60186c42 100644
--- a/etc/profile-m-z/synfigstudio.profile
+++ b/etc/profile-m-z/synfigstudio.profile
@@ -20,6 +20,7 @@ caps.drop all
20net none 20net none
21nodvd 21nodvd
22nogroups 22nogroups
23noinput
23nonewprivs 24nonewprivs
24noroot 25noroot
25nosound 26nosound
diff --git a/etc/profile-m-z/sysprof.profile b/etc/profile-m-z/sysprof.profile
index 9e9d2a448..b52b25b96 100644
--- a/etc/profile-m-z/sysprof.profile
+++ b/etc/profile-m-z/sysprof.profile
@@ -15,8 +15,15 @@ include disable-passwdmgr.inc
15include disable-programs.inc 15include disable-programs.inc
16include disable-xdg.inc 16include disable-xdg.inc
17 17
18# help menu functionality (yelp) - comment or add this block prepended with 'ignore' 18# Add the next lines to your sysprof.local if you don't need (yelp) help menu functionality.
19# to your sysprof.local if you don't need the help functionality 19#ignore noblacklist ${HOME}/.config/yelp
20#ignore mkdir ${HOME}/.config/yelp
21#nowhitelist ${HOME}/.config/yelp
22#nowhitelist /usr/share/help/C/sysprof
23#nowhitelist /usr/share/yelp
24#nowhitelist /usr/share/yelp-tools
25#nowhitelist /usr/share/yelp-xsl
26
20noblacklist ${HOME}/.config/yelp 27noblacklist ${HOME}/.config/yelp
21mkdir ${HOME}/.config/yelp 28mkdir ${HOME}/.config/yelp
22whitelist ${HOME}/.config/yelp 29whitelist ${HOME}/.config/yelp
@@ -39,8 +46,10 @@ net none
39no3d 46no3d
40nodvd 47nodvd
41nogroups 48nogroups
49noinput
42nonewprivs 50nonewprivs
43# Ubuntu 16.04 version needs root privileges - comment or put 'ignore noroot' in sysprof.local if you run Xenial 51# Some older Debian/Ubuntu sysprof versions need root privileges.
52# Add 'ignore noroot' to your sysprof.local if you run one of these.
44noroot 53noroot
45nosound 54nosound
46notv 55notv
@@ -56,7 +65,7 @@ disable-mnt
56private-cache 65private-cache
57private-dev 66private-dev
58private-etc alternatives,fonts,ld.so.cache,machine-id,ssl 67private-etc alternatives,fonts,ld.so.cache,machine-id,ssl
59# private-lib breaks help menu 68# private-lib - breaks help menu
60#private-lib gdk-pixbuf-2.*,gio,gtk3,gvfs/libgvfscommon.so,libgconf-2.so.*,librsvg-2.so.*,libsysprof-2.so,libsysprof-ui-2.so 69#private-lib gdk-pixbuf-2.*,gio,gtk3,gvfs/libgvfscommon.so,libgconf-2.so.*,librsvg-2.so.*,libsysprof-2.so,libsysprof-ui-2.so
61private-tmp 70private-tmp
62 71
diff --git a/etc/profile-m-z/tcpdump.profile b/etc/profile-m-z/tcpdump.profile
index 6f863d7a1..e2ba5893c 100644
--- a/etc/profile-m-z/tcpdump.profile
+++ b/etc/profile-m-z/tcpdump.profile
@@ -28,6 +28,7 @@ netfilter
28no3d 28no3d
29nodvd 29nodvd
30#nogroups 30#nogroups
31noinput
31nonewprivs 32nonewprivs
32#noroot 33#noroot
33nosound 34nosound
diff --git a/etc/profile-m-z/teamspeak3.profile b/etc/profile-m-z/teamspeak3.profile
index c1c666f58..02a2c8ae4 100644
--- a/etc/profile-m-z/teamspeak3.profile
+++ b/etc/profile-m-z/teamspeak3.profile
@@ -27,6 +27,7 @@ netfilter
27no3d 27no3d
28nodvd 28nodvd
29nogroups 29nogroups
30noinput
30nonewprivs 31nonewprivs
31noroot 32noroot
32notv 33notv
diff --git a/etc/profile-m-z/teeworlds.profile b/etc/profile-m-z/teeworlds.profile
index c0d62bec2..be01aee12 100644
--- a/etc/profile-m-z/teeworlds.profile
+++ b/etc/profile-m-z/teeworlds.profile
@@ -27,6 +27,7 @@ ipc-namespace
27netfilter 27netfilter
28nodvd 28nodvd
29nogroups 29nogroups
30noinput
30nonewprivs 31nonewprivs
31noroot 32noroot
32notv 33notv
diff --git a/etc/profile-m-z/telegram.profile b/etc/profile-m-z/telegram.profile
index 38d291324..05c621fb2 100644
--- a/etc/profile-m-z/telegram.profile
+++ b/etc/profile-m-z/telegram.profile
@@ -31,6 +31,7 @@ apparmor
31caps.drop all 31caps.drop all
32netfilter 32netfilter
33nodvd 33nodvd
34noinput
34nonewprivs 35nonewprivs
35noroot 36noroot
36notv 37notv
diff --git a/etc/profile-m-z/terasology.profile b/etc/profile-m-z/terasology.profile
index 36ce6d469..ce2ca1d17 100644
--- a/etc/profile-m-z/terasology.profile
+++ b/etc/profile-m-z/terasology.profile
@@ -30,6 +30,7 @@ ipc-namespace
30net none 30net none
31nodvd 31nodvd
32nogroups 32nogroups
33noinput
33nonewprivs 34nonewprivs
34noroot 35noroot
35notv 36notv
diff --git a/etc/profile-m-z/tmux.profile b/etc/profile-m-z/tmux.profile
index 706f39f24..0139d7515 100644
--- a/etc/profile-m-z/tmux.profile
+++ b/etc/profile-m-z/tmux.profile
@@ -25,6 +25,7 @@ netfilter
25no3d 25no3d
26nodvd 26nodvd
27nogroups 27nogroups
28noinput
28nonewprivs 29nonewprivs
29noroot 30noroot
30nosound 31nosound
diff --git a/etc/profile-m-z/tor.profile b/etc/profile-m-z/tor.profile
index 13d071635..73ef290f4 100644
--- a/etc/profile-m-z/tor.profile
+++ b/etc/profile-m-z/tor.profile
@@ -32,6 +32,7 @@ netfilter
32no3d 32no3d
33nodvd 33nodvd
34nogroups 34nogroups
35noinput
35nonewprivs 36nonewprivs
36nosound 37nosound
37notv 38notv
diff --git a/etc/profile-m-z/torbrowser-launcher.profile b/etc/profile-m-z/torbrowser-launcher.profile
index 3cbfe8d8b..7659ed1e9 100644
--- a/etc/profile-m-z/torbrowser-launcher.profile
+++ b/etc/profile-m-z/torbrowser-launcher.profile
@@ -45,6 +45,7 @@ caps.drop all
45netfilter 45netfilter
46nodvd 46nodvd
47nogroups 47nogroups
48noinput
48nonewprivs 49nonewprivs
49noroot 50noroot
50notv 51notv
diff --git a/etc/profile-m-z/torcs.profile b/etc/profile-m-z/torcs.profile
index 1ed78934e..0f98a8f64 100644
--- a/etc/profile-m-z/torcs.profile
+++ b/etc/profile-m-z/torcs.profile
@@ -29,6 +29,7 @@ ipc-namespace
29net none 29net none
30nodvd 30nodvd
31nogroups 31nogroups
32noinput
32nonewprivs 33nonewprivs
33noroot 34noroot
34notv 35notv
diff --git a/etc/profile-m-z/totem.profile b/etc/profile-m-z/totem.profile
index 90c45c7d0..70d9e0aee 100644
--- a/etc/profile-m-z/totem.profile
+++ b/etc/profile-m-z/totem.profile
@@ -40,6 +40,7 @@ include whitelist-var-common.inc
40caps.drop all 40caps.drop all
41netfilter 41netfilter
42nogroups 42nogroups
43noinput
43nonewprivs 44nonewprivs
44noroot 45noroot
45nou2f 46nou2f
diff --git a/etc/profile-m-z/transgui.profile b/etc/profile-m-z/transgui.profile
index c31055cdc..ea118a9f0 100644
--- a/etc/profile-m-z/transgui.profile
+++ b/etc/profile-m-z/transgui.profile
@@ -31,6 +31,7 @@ machine-id
31netfilter 31netfilter
32nodvd 32nodvd
33nogroups 33nogroups
34noinput
34nonewprivs 35nonewprivs
35noroot 36noroot
36nosound 37nosound
diff --git a/etc/profile-m-z/transmission-common.profile b/etc/profile-m-z/transmission-common.profile
index d601f0f15..82671b709 100644
--- a/etc/profile-m-z/transmission-common.profile
+++ b/etc/profile-m-z/transmission-common.profile
@@ -31,6 +31,7 @@ caps.drop all
31machine-id 31machine-id
32netfilter 32netfilter
33nodvd 33nodvd
34noinput
34nonewprivs 35nonewprivs
35noroot 36noroot
36nosound 37nosound
diff --git a/etc/profile-m-z/tremulous.profile b/etc/profile-m-z/tremulous.profile
index 67463a999..aba563fac 100644
--- a/etc/profile-m-z/tremulous.profile
+++ b/etc/profile-m-z/tremulous.profile
@@ -30,6 +30,7 @@ ipc-namespace
30netfilter 30netfilter
31nodvd 31nodvd
32nogroups 32nogroups
33noinput
33nonewprivs 34nonewprivs
34noroot 35noroot
35notv 36notv
diff --git a/etc/profile-m-z/trojita.profile b/etc/profile-m-z/trojita.profile
index b82aadd13..2d95081f6 100644
--- a/etc/profile-m-z/trojita.profile
+++ b/etc/profile-m-z/trojita.profile
@@ -38,6 +38,7 @@ netfilter
38no3d 38no3d
39nodvd 39nodvd
40nogroups 40nogroups
41noinput
41nonewprivs 42nonewprivs
42noroot 43noroot
43nosound 44nosound
diff --git a/etc/profile-m-z/truecraft.profile b/etc/profile-m-z/truecraft.profile
index e76d52219..749626475 100644
--- a/etc/profile-m-z/truecraft.profile
+++ b/etc/profile-m-z/truecraft.profile
@@ -24,6 +24,7 @@ include whitelist-common.inc
24caps.drop all 24caps.drop all
25nodvd 25nodvd
26nogroups 26nogroups
27noinput
27nonewprivs 28nonewprivs
28noroot 29noroot
29notv 30notv
diff --git a/etc/profile-m-z/tuxguitar.profile b/etc/profile-m-z/tuxguitar.profile
index d2b13d9ee..d0bcbe79f 100644
--- a/etc/profile-m-z/tuxguitar.profile
+++ b/etc/profile-m-z/tuxguitar.profile
@@ -29,6 +29,7 @@ netfilter
29no3d 29no3d
30nodvd 30nodvd
31nogroups 31nogroups
32noinput
32nonewprivs 33nonewprivs
33noroot 34noroot
34notv 35notv
diff --git a/etc/profile-m-z/tvbrowser.profile b/etc/profile-m-z/tvbrowser.profile
index d3dcbfe53..dae7d86da 100644
--- a/etc/profile-m-z/tvbrowser.profile
+++ b/etc/profile-m-z/tvbrowser.profile
@@ -34,6 +34,7 @@ netfilter
34no3d 34no3d
35nodvd 35nodvd
36nogroups 36nogroups
37noinput
37nonewprivs 38nonewprivs
38noroot 39noroot
39notv 40notv
diff --git a/etc/profile-m-z/udiskie.profile b/etc/profile-m-z/udiskie.profile
index 265f6429d..601b818c2 100644
--- a/etc/profile-m-z/udiskie.profile
+++ b/etc/profile-m-z/udiskie.profile
@@ -24,6 +24,7 @@ machine-id
24net none 24net none
25no3d 25no3d
26nogroups 26nogroups
27noinput
27nonewprivs 28nonewprivs
28noroot 29noroot
29nosound 30nosound
diff --git a/etc/profile-m-z/uefitool.profile b/etc/profile-m-z/uefitool.profile
index 8807b0b2c..3e4fdbb03 100644
--- a/etc/profile-m-z/uefitool.profile
+++ b/etc/profile-m-z/uefitool.profile
@@ -21,6 +21,7 @@ net none
21no3d 21no3d
22nodvd 22nodvd
23nogroups 23nogroups
24noinput
24nonewprivs 25nonewprivs
25noroot 26noroot
26nosound 27nosound
diff --git a/etc/profile-m-z/uget-gtk.profile b/etc/profile-m-z/uget-gtk.profile
index c8f28444f..4420099ff 100644
--- a/etc/profile-m-z/uget-gtk.profile
+++ b/etc/profile-m-z/uget-gtk.profile
@@ -23,6 +23,7 @@ include whitelist-var-common.inc
23caps.drop all 23caps.drop all
24netfilter 24netfilter
25nodvd 25nodvd
26noinput
26nonewprivs 27nonewprivs
27noroot 28noroot
28nosound 29nosound
diff --git a/etc/profile-m-z/unbound.profile b/etc/profile-m-z/unbound.profile
index 714a3f2f4..0c077babf 100644
--- a/etc/profile-m-z/unbound.profile
+++ b/etc/profile-m-z/unbound.profile
@@ -31,6 +31,7 @@ machine-id
31netfilter 31netfilter
32no3d 32no3d
33nodvd 33nodvd
34noinput
34nonewprivs 35nonewprivs
35nosound 36nosound
36notv 37notv
diff --git a/etc/profile-m-z/unf.profile b/etc/profile-m-z/unf.profile
index bcd256ba3..6db7ba362 100644
--- a/etc/profile-m-z/unf.profile
+++ b/etc/profile-m-z/unf.profile
@@ -32,6 +32,7 @@ net none
32no3d 32no3d
33nodvd 33nodvd
34nogroups 34nogroups
35noinput
35nonewprivs 36nonewprivs
36noroot 37noroot
37nosound 38nosound
diff --git a/etc/profile-m-z/unknown-horizons.profile b/etc/profile-m-z/unknown-horizons.profile
index 7dc13e284..956492f52 100644
--- a/etc/profile-m-z/unknown-horizons.profile
+++ b/etc/profile-m-z/unknown-horizons.profile
@@ -25,6 +25,7 @@ apparmor
25caps.drop all 25caps.drop all
26nodvd 26nodvd
27nogroups 27nogroups
28noinput
28nonewprivs 29nonewprivs
29noroot 30noroot
30notv 31notv
diff --git a/etc/profile-m-z/utox.profile b/etc/profile-m-z/utox.profile
index cd4374004..dd881f091 100644
--- a/etc/profile-m-z/utox.profile
+++ b/etc/profile-m-z/utox.profile
@@ -30,6 +30,7 @@ ipc-namespace
30netfilter 30netfilter
31nodvd 31nodvd
32nogroups 32nogroups
33noinput
33nonewprivs 34nonewprivs
34noroot 35noroot
35notv 36notv
diff --git a/etc/profile-m-z/uudeview.profile b/etc/profile-m-z/uudeview.profile
index f60c134e0..2adc044e5 100644
--- a/etc/profile-m-z/uudeview.profile
+++ b/etc/profile-m-z/uudeview.profile
@@ -26,6 +26,7 @@ machine-id
26net none 26net none
27nodvd 27nodvd
28#nogroups 28#nogroups
29noinput
29nonewprivs 30nonewprivs
30#noroot 31#noroot
31nosound 32nosound
diff --git a/etc/profile-m-z/viewnior.profile b/etc/profile-m-z/viewnior.profile
index 83727d42b..a9ba344dd 100644
--- a/etc/profile-m-z/viewnior.profile
+++ b/etc/profile-m-z/viewnior.profile
@@ -29,6 +29,7 @@ net none
29no3d 29no3d
30nodvd 30nodvd
31nogroups 31nogroups
32noinput
32nonewprivs 33nonewprivs
33noroot 34noroot
34nosound 35nosound
diff --git a/etc/profile-m-z/viking.profile b/etc/profile-m-z/viking.profile
index 5b6228a94..8f8ef5939 100644
--- a/etc/profile-m-z/viking.profile
+++ b/etc/profile-m-z/viking.profile
@@ -23,6 +23,7 @@ netfilter
23no3d 23no3d
24nodvd 24nodvd
25nogroups 25nogroups
26noinput
26nonewprivs 27nonewprivs
27noroot 28noroot
28nosound 29nosound
diff --git a/etc/profile-m-z/vim.profile b/etc/profile-m-z/vim.profile
index e9a474239..c3cfe5980 100644
--- a/etc/profile-m-z/vim.profile
+++ b/etc/profile-m-z/vim.profile
@@ -23,6 +23,7 @@ caps.drop all
23netfilter 23netfilter
24nodvd 24nodvd
25nogroups 25nogroups
26noinput
26nonewprivs 27nonewprivs
27noroot 28noroot
28notv 29notv
diff --git a/etc/profile-m-z/virtualbox.profile b/etc/profile-m-z/virtualbox.profile
index 64d787bfb..c22fb0ff9 100644
--- a/etc/profile-m-z/virtualbox.profile
+++ b/etc/profile-m-z/virtualbox.profile
@@ -44,7 +44,7 @@ shell none
44tracelog 44tracelog
45 45
46#disable-mnt 46#disable-mnt
47#private-bin basename,bash,env,gawk,grep,ps,readlink,sh,virtualbox,VirtualBox,VBox*,vbox*,whoami 47#private-bin awk,basename,bash,env,gawk,grep,ps,readlink,sh,virtualbox,VirtualBox,VBox*,vbox*,whoami
48private-cache 48private-cache
49private-etc alsa,asound.conf,ca-certificates,conf.d,crypto-policies,dconf,fonts,hostname,hosts,ld.so.cache,localtime,machine-id,pki,pulse,resolv.conf,ssl 49private-etc alsa,asound.conf,ca-certificates,conf.d,crypto-policies,dconf,fonts,hostname,hosts,ld.so.cache,localtime,machine-id,pki,pulse,resolv.conf,ssl
50private-tmp 50private-tmp
diff --git a/etc/profile-m-z/vlc.profile b/etc/profile-m-z/vlc.profile
index 9a12686cd..cd7dccd8a 100644
--- a/etc/profile-m-z/vlc.profile
+++ b/etc/profile-m-z/vlc.profile
@@ -34,6 +34,7 @@ include whitelist-var-common.inc
34caps.drop all 34caps.drop all
35netfilter 35netfilter
36nogroups 36nogroups
37noinput
37nonewprivs 38nonewprivs
38noroot 39noroot
39nou2f 40nou2f
diff --git a/etc/profile-m-z/vmware-view.profile b/etc/profile-m-z/vmware-view.profile
index 0cb6d34d2..f07c31b68 100644
--- a/etc/profile-m-z/vmware-view.profile
+++ b/etc/profile-m-z/vmware-view.profile
@@ -33,6 +33,7 @@ caps.drop all
33netfilter 33netfilter
34nodvd 34nodvd
35nogroups 35nogroups
36noinput
36nonewprivs 37nonewprivs
37noroot 38noroot
38notv 39notv
diff --git a/etc/profile-m-z/vym.profile b/etc/profile-m-z/vym.profile
index fbb53943c..5421c4e4b 100644
--- a/etc/profile-m-z/vym.profile
+++ b/etc/profile-m-z/vym.profile
@@ -20,6 +20,7 @@ netfilter
20no3d 20no3d
21nodvd 21nodvd
22nogroups 22nogroups
23noinput
23nonewprivs 24nonewprivs
24noroot 25noroot
25nosound 26nosound
diff --git a/etc/profile-m-z/w3m.profile b/etc/profile-m-z/w3m.profile
index a43835944..131213ed2 100644
--- a/etc/profile-m-z/w3m.profile
+++ b/etc/profile-m-z/w3m.profile
@@ -33,6 +33,7 @@ netfilter
33no3d 33no3d
34nodvd 34nodvd
35nogroups 35nogroups
36noinput
36nonewprivs 37nonewprivs
37noroot 38noroot
38nosound 39nosound
diff --git a/etc/profile-m-z/warmux.profile b/etc/profile-m-z/warmux.profile
index aaef652fd..1227a202c 100644
--- a/etc/profile-m-z/warmux.profile
+++ b/etc/profile-m-z/warmux.profile
@@ -35,6 +35,7 @@ caps.drop all
35netfilter 35netfilter
36nodvd 36nodvd
37nogroups 37nogroups
38noinput
38nonewprivs 39nonewprivs
39noroot 40noroot
40notv 41notv
diff --git a/etc/profile-m-z/warsow.profile b/etc/profile-m-z/warsow.profile
index 178e0c7b1..e0cd3daad 100644
--- a/etc/profile-m-z/warsow.profile
+++ b/etc/profile-m-z/warsow.profile
@@ -35,6 +35,7 @@ ipc-namespace
35netfilter 35netfilter
36nodvd 36nodvd
37nogroups 37nogroups
38noinput
38nonewprivs 39nonewprivs
39noroot 40noroot
40notv 41notv
diff --git a/etc/profile-m-z/warzone2100.profile b/etc/profile-m-z/warzone2100.profile
index 06a7c3412..420e8927e 100644
--- a/etc/profile-m-z/warzone2100.profile
+++ b/etc/profile-m-z/warzone2100.profile
@@ -31,6 +31,7 @@ caps.drop all
31netfilter 31netfilter
32nodvd 32nodvd
33nogroups 33nogroups
34noinput
34nonewprivs 35nonewprivs
35noroot 36noroot
36notv 37notv
diff --git a/etc/profile-m-z/webstorm.profile b/etc/profile-m-z/webstorm.profile
index e9053f598..69e96d0cd 100644
--- a/etc/profile-m-z/webstorm.profile
+++ b/etc/profile-m-z/webstorm.profile
@@ -31,6 +31,7 @@ caps.drop all
31netfilter 31netfilter
32nodvd 32nodvd
33nogroups 33nogroups
34noinput
34nonewprivs 35nonewprivs
35noroot 36noroot
36notv 37notv
diff --git a/etc/profile-m-z/webui-aria2.profile b/etc/profile-m-z/webui-aria2.profile
index 8928f8116..d5a998f35 100644
--- a/etc/profile-m-z/webui-aria2.profile
+++ b/etc/profile-m-z/webui-aria2.profile
@@ -20,6 +20,7 @@ caps.drop all
20netfilter 20netfilter
21nodvd 21nodvd
22nogroups 22nogroups
23noinput
23nonewprivs 24nonewprivs
24noroot 25noroot
25nosound 26nosound
diff --git a/etc/profile-m-z/wesnoth.profile b/etc/profile-m-z/wesnoth.profile
index 934edfce9..199b3c6f0 100644
--- a/etc/profile-m-z/wesnoth.profile
+++ b/etc/profile-m-z/wesnoth.profile
@@ -26,6 +26,7 @@ include whitelist-common.inc
26 26
27caps.drop all 27caps.drop all
28nodvd 28nodvd
29noinput
29nonewprivs 30nonewprivs
30noroot 31noroot
31notv 32notv
diff --git a/etc/profile-m-z/wget.profile b/etc/profile-m-z/wget.profile
index 8a7042f59..53c4711bd 100644
--- a/etc/profile-m-z/wget.profile
+++ b/etc/profile-m-z/wget.profile
@@ -35,6 +35,7 @@ netfilter
35no3d 35no3d
36nodvd 36nodvd
37nogroups 37nogroups
38noinput
38nonewprivs 39nonewprivs
39noroot 40noroot
40nosound 41nosound
diff --git a/etc/profile-m-z/whois.profile b/etc/profile-m-z/whois.profile
index fa7a16093..93871a5a4 100644
--- a/etc/profile-m-z/whois.profile
+++ b/etc/profile-m-z/whois.profile
@@ -30,6 +30,7 @@ netfilter
30no3d 30no3d
31nodvd 31nodvd
32nogroups 32nogroups
33noinput
33nonewprivs 34nonewprivs
34noroot 35noroot
35nosound 36nosound
diff --git a/etc/profile-m-z/widelands.profile b/etc/profile-m-z/widelands.profile
index f18878554..0dc26b11d 100644
--- a/etc/profile-m-z/widelands.profile
+++ b/etc/profile-m-z/widelands.profile
@@ -28,6 +28,7 @@ ipc-namespace
28netfilter 28netfilter
29nodvd 29nodvd
30nogroups 30nogroups
31noinput
31nonewprivs 32nonewprivs
32noroot 33noroot
33notv 34notv
diff --git a/etc/profile-m-z/wine.profile b/etc/profile-m-z/wine.profile
index 67427209f..0ea24aafd 100644
--- a/etc/profile-m-z/wine.profile
+++ b/etc/profile-m-z/wine.profile
@@ -31,6 +31,7 @@ caps.drop all
31netfilter 31netfilter
32nodvd 32nodvd
33nogroups 33nogroups
34noinput
34nonewprivs 35nonewprivs
35noroot 36noroot
36# nosound 37# nosound
diff --git a/etc/profile-m-z/wireshark.profile b/etc/profile-m-z/wireshark.profile
index 6a84246e1..1824026a8 100644
--- a/etc/profile-m-z/wireshark.profile
+++ b/etc/profile-m-z/wireshark.profile
@@ -31,6 +31,7 @@ caps.keep dac_override,net_admin,net_raw
31netfilter 31netfilter
32no3d 32no3d
33# nogroups - breaks network traffic capture for unprivileged users 33# nogroups - breaks network traffic capture for unprivileged users
34noinput
34# nonewprivs - breaks network traffic capture for unprivileged users 35# nonewprivs - breaks network traffic capture for unprivileged users
35# noroot 36# noroot
36nodvd 37nodvd
@@ -39,11 +40,15 @@ notv
39nou2f 40nou2f
40novideo 41novideo
41# protocol unix,inet,inet6,netlink,packet,bluetooth - commented out in case they bring in new protocols 42# protocol unix,inet,inet6,netlink,packet,bluetooth - commented out in case they bring in new protocols
42seccomp 43#seccomp
43shell none 44shell none
44tracelog 45tracelog
45 46
46# private-bin wireshark 47# private-bin wireshark
48private-cache
47private-dev 49private-dev
48# private-etc alternatives,ca-certificates,crypto-policies,fonts,group,hosts,machine-id,passwd,pki,ssl 50# private-etc alternatives,ca-certificates,crypto-policies,fonts,group,hosts,machine-id,passwd,pki,ssl
49private-tmp 51private-tmp
52
53dbus-user none
54dbus-system none
diff --git a/etc/profile-m-z/wordwarvi.profile b/etc/profile-m-z/wordwarvi.profile
index da1210bb8..9c724a5d2 100644
--- a/etc/profile-m-z/wordwarvi.profile
+++ b/etc/profile-m-z/wordwarvi.profile
@@ -30,6 +30,7 @@ net none
30no3d 30no3d
31nodvd 31nodvd
32nogroups 32nogroups
33noinput
33nonewprivs 34nonewprivs
34noroot 35noroot
35notv 36notv
diff --git a/etc/profile-m-z/wps.profile b/etc/profile-m-z/wps.profile
index 2b97d5b0a..a44b6490e 100644
--- a/etc/profile-m-z/wps.profile
+++ b/etc/profile-m-z/wps.profile
@@ -29,6 +29,7 @@ netfilter
29no3d 29no3d
30nodvd 30nodvd
31nogroups 31nogroups
32noinput
32nonewprivs 33nonewprivs
33noroot 34noroot
34nosound 35nosound
diff --git a/etc/profile-m-z/x-terminal-emulator.profile b/etc/profile-m-z/x-terminal-emulator.profile
index fe0781336..141d167a8 100644
--- a/etc/profile-m-z/x-terminal-emulator.profile
+++ b/etc/profile-m-z/x-terminal-emulator.profile
@@ -9,6 +9,7 @@ caps.drop all
9ipc-namespace 9ipc-namespace
10net none 10net none
11nogroups 11nogroups
12noinput
12noroot 13noroot
13nou2f 14nou2f
14protocol unix 15protocol unix
diff --git a/etc/profile-m-z/x2goclient.profile b/etc/profile-m-z/x2goclient.profile
index 6146016b2..557f07cd9 100644
--- a/etc/profile-m-z/x2goclient.profile
+++ b/etc/profile-m-z/x2goclient.profile
@@ -26,6 +26,7 @@ netfilter
26#no3d 26#no3d
27nodvd 27nodvd
28nogroups 28nogroups
29noinput
29nonewprivs 30nonewprivs
30noroot 31noroot
31notv 32notv
diff --git a/etc/profile-m-z/xbill.profile b/etc/profile-m-z/xbill.profile
index cdfebfb29..384f76acc 100644
--- a/etc/profile-m-z/xbill.profile
+++ b/etc/profile-m-z/xbill.profile
@@ -28,6 +28,7 @@ net none
28no3d 28no3d
29nodvd 29nodvd
30nogroups 30nogroups
31noinput
31nonewprivs 32nonewprivs
32noroot 33noroot
33nosound 34nosound
diff --git a/etc/profile-m-z/xcalc.profile b/etc/profile-m-z/xcalc.profile
index 56ce01498..7fb483289 100644
--- a/etc/profile-m-z/xcalc.profile
+++ b/etc/profile-m-z/xcalc.profile
@@ -22,6 +22,7 @@ net none
22no3d 22no3d
23nodvd 23nodvd
24nogroups 24nogroups
25noinput
25nonewprivs 26nonewprivs
26noroot 27noroot
27nosound 28nosound
diff --git a/etc/profile-m-z/xed.profile b/etc/profile-m-z/xed.profile
index b114f9ab5..4a3022e83 100644
--- a/etc/profile-m-z/xed.profile
+++ b/etc/profile-m-z/xed.profile
@@ -31,6 +31,7 @@ machine-id
31no3d 31no3d
32nodvd 32nodvd
33nogroups 33nogroups
34noinput
34nonewprivs 35nonewprivs
35noroot 36noroot
36nosound 37nosound
diff --git a/etc/profile-m-z/xfce4-dict.profile b/etc/profile-m-z/xfce4-dict.profile
index a3e0c4633..ecd321c7e 100644
--- a/etc/profile-m-z/xfce4-dict.profile
+++ b/etc/profile-m-z/xfce4-dict.profile
@@ -23,6 +23,7 @@ netfilter
23no3d 23no3d
24nodvd 24nodvd
25nogroups 25nogroups
26noinput
26nonewprivs 27nonewprivs
27noroot 28noroot
28nosound 29nosound
diff --git a/etc/profile-m-z/xfce4-mixer.profile b/etc/profile-m-z/xfce4-mixer.profile
index 78cb2862c..bb38dbebd 100644
--- a/etc/profile-m-z/xfce4-mixer.profile
+++ b/etc/profile-m-z/xfce4-mixer.profile
@@ -19,7 +19,7 @@ include disable-xdg.inc
19 19
20mkfile ${HOME}/.config/xfce4/xfconf/xfce-perchannel-xml/xfce4-mixer.xml 20mkfile ${HOME}/.config/xfce4/xfconf/xfce-perchannel-xml/xfce4-mixer.xml
21whitelist ${HOME}/.config/xfce4/xfconf/xfce-perchannel-xml/xfce4-mixer.xml 21whitelist ${HOME}/.config/xfce4/xfconf/xfce-perchannel-xml/xfce4-mixer.xml
22whitelist /usr/share/gstreamer 22whitelist /usr/share/gstreamer-*
23whitelist /usr/share/xfce4 23whitelist /usr/share/xfce4
24whitelist /usr/share/xfce4-mixer 24whitelist /usr/share/xfce4-mixer
25include whitelist-common.inc 25include whitelist-common.inc
@@ -33,6 +33,7 @@ netfilter
33no3d 33no3d
34nodvd 34nodvd
35nogroups 35nogroups
36noinput
36nonewprivs 37nonewprivs
37noroot 38noroot
38notv 39notv
diff --git a/etc/profile-m-z/xfce4-notes.profile b/etc/profile-m-z/xfce4-notes.profile
index c3d0930ff..ebfb4333c 100644
--- a/etc/profile-m-z/xfce4-notes.profile
+++ b/etc/profile-m-z/xfce4-notes.profile
@@ -25,6 +25,7 @@ netfilter
25no3d 25no3d
26nodvd 26nodvd
27nogroups 27nogroups
28noinput
28nonewprivs 29nonewprivs
29noroot 30noroot
30nosound 31nosound
diff --git a/etc/profile-m-z/xfce4-screenshooter.profile b/etc/profile-m-z/xfce4-screenshooter.profile
index c9200304c..b1e5bafbf 100644
--- a/etc/profile-m-z/xfce4-screenshooter.profile
+++ b/etc/profile-m-z/xfce4-screenshooter.profile
@@ -29,6 +29,7 @@ netfilter
29no3d 29no3d
30nodvd 30nodvd
31nogroups 31nogroups
32noinput
32nonewprivs 33nonewprivs
33noroot 34noroot
34notv 35notv
diff --git a/etc/profile-m-z/xiphos.profile b/etc/profile-m-z/xiphos.profile
index 188589df3..81d98db7a 100644
--- a/etc/profile-m-z/xiphos.profile
+++ b/etc/profile-m-z/xiphos.profile
@@ -32,6 +32,7 @@ machine-id
32netfilter 32netfilter
33nodvd 33nodvd
34nogroups 34nogroups
35noinput
35nonewprivs 36nonewprivs
36noroot 37noroot
37nosound 38nosound
diff --git a/etc/profile-m-z/xmms.profile b/etc/profile-m-z/xmms.profile
index 9391f68de..25261d925 100644
--- a/etc/profile-m-z/xmms.profile
+++ b/etc/profile-m-z/xmms.profile
@@ -19,6 +19,7 @@ include disable-xdg.inc
19caps.drop all 19caps.drop all
20netfilter 20netfilter
21no3d 21no3d
22noinput
22nonewprivs 23nonewprivs
23noroot 24noroot
24notv 25notv
diff --git a/etc/profile-m-z/xmr-stak.profile b/etc/profile-m-z/xmr-stak.profile
index 3278e295d..e7020f36b 100644
--- a/etc/profile-m-z/xmr-stak.profile
+++ b/etc/profile-m-z/xmr-stak.profile
@@ -24,6 +24,7 @@ ipc-namespace
24netfilter 24netfilter
25nodvd 25nodvd
26nogroups 26nogroups
27noinput
27nonewprivs 28nonewprivs
28noroot 29noroot
29nosound 30nosound
diff --git a/etc/profile-m-z/xonotic.profile b/etc/profile-m-z/xonotic.profile
index aa8cc7d0e..53c9a0a08 100644
--- a/etc/profile-m-z/xonotic.profile
+++ b/etc/profile-m-z/xonotic.profile
@@ -8,12 +8,16 @@ include globals.local
8 8
9noblacklist ${HOME}/.xonotic 9noblacklist ${HOME}/.xonotic
10 10
11include allow-bin-sh.inc
12include allow-opengl-game.inc
13
11include disable-common.inc 14include disable-common.inc
12include disable-devel.inc 15include disable-devel.inc
13include disable-exec.inc 16include disable-exec.inc
14include disable-interpreters.inc 17include disable-interpreters.inc
15include disable-passwdmgr.inc 18include disable-passwdmgr.inc
16include disable-programs.inc 19include disable-programs.inc
20include disable-shell.inc
17include disable-xdg.inc 21include disable-xdg.inc
18 22
19mkdir ${HOME}/.xonotic 23mkdir ${HOME}/.xonotic
@@ -29,6 +33,7 @@ caps.drop all
29netfilter 33netfilter
30nodvd 34nodvd
31nogroups 35nogroups
36noinput
32nonewprivs 37nonewprivs
33noroot 38noroot
34notv 39notv
@@ -41,7 +46,7 @@ tracelog
41 46
42disable-mnt 47disable-mnt
43private-cache 48private-cache
44private-bin basename,bash,blind-id,cut,darkplaces-glx,darkplaces-sdl,dirname,glxinfo,grep,head,ldd,netstat,ps,readlink,sed,sh,uname,xonotic,xonotic-glx,xonotic-linux32-dedicated,xonotic-linux32-glx,xonotic-linux32-sdl,xonotic-linux64-dedicated,xonotic-linux64-glx,xonotic-linux64-sdl,xonotic-sdl,xonotic-sdl-wrapper,zenity 49private-bin blind-id,darkplaces-glx,darkplaces-sdl,dirname,ldd,netstat,ps,readlink,sh,uname,xonotic*
45private-dev 50private-dev
46private-etc alternatives,asound.conf,ca-certificates,crypto-policies,drirc,fonts,group,host.conf,hostname,hosts,ld.so.cache,ld.so.preload,localtime,machine-id,nsswitch.conf,passwd,pki,pulse,resolv.conf,ssl 51private-etc alternatives,asound.conf,ca-certificates,crypto-policies,drirc,fonts,group,host.conf,hostname,hosts,ld.so.cache,ld.so.preload,localtime,machine-id,nsswitch.conf,passwd,pki,pulse,resolv.conf,ssl
47private-tmp 52private-tmp
diff --git a/etc/profile-m-z/xournal.profile b/etc/profile-m-z/xournal.profile
index 0c6969e09..c4f092d50 100644
--- a/etc/profile-m-z/xournal.profile
+++ b/etc/profile-m-z/xournal.profile
@@ -28,6 +28,7 @@ net none
28no3d 28no3d
29nodvd 29nodvd
30nogroups 30nogroups
31noinput
31nonewprivs 32nonewprivs
32noroot 33noroot
33nosound 34nosound
diff --git a/etc/profile-m-z/xpdf.profile b/etc/profile-m-z/xpdf.profile
index cdffe4eb7..1447ec9a7 100644
--- a/etc/profile-m-z/xpdf.profile
+++ b/etc/profile-m-z/xpdf.profile
@@ -26,6 +26,7 @@ net none
26no3d 26no3d
27nodvd 27nodvd
28nogroups 28nogroups
29noinput
29nonewprivs 30nonewprivs
30noroot 31noroot
31nosound 32nosound
diff --git a/etc/profile-m-z/xplayer.profile b/etc/profile-m-z/xplayer.profile
index f0290f461..c3bb3292c 100644
--- a/etc/profile-m-z/xplayer.profile
+++ b/etc/profile-m-z/xplayer.profile
@@ -32,6 +32,7 @@ include whitelist-var-common.inc
32caps.drop all 32caps.drop all
33netfilter 33netfilter
34nogroups 34nogroups
35noinput
35nonewprivs 36nonewprivs
36noroot 37noroot
37nou2f 38nou2f
diff --git a/etc/profile-m-z/xpra.profile b/etc/profile-m-z/xpra.profile
index 1033a7471..6e409e1aa 100644
--- a/etc/profile-m-z/xpra.profile
+++ b/etc/profile-m-z/xpra.profile
@@ -33,6 +33,7 @@ caps.drop all
33# xpra needs to be allowed access to the abstract Unix socket namespace. 33# xpra needs to be allowed access to the abstract Unix socket namespace.
34nodvd 34nodvd
35nogroups 35nogroups
36noinput
36nonewprivs 37nonewprivs
37# In noroot mode, xpra cannot create a socket in the real /tmp/.X11-unix. 38# In noroot mode, xpra cannot create a socket in the real /tmp/.X11-unix.
38#noroot 39#noroot
diff --git a/etc/profile-m-z/xreader.profile b/etc/profile-m-z/xreader.profile
index 643c5a317..3ab35edfc 100644
--- a/etc/profile-m-z/xreader.profile
+++ b/etc/profile-m-z/xreader.profile
@@ -26,6 +26,7 @@ caps.drop all
26no3d 26no3d
27nodvd 27nodvd
28nogroups 28nogroups
29noinput
29nonewprivs 30nonewprivs
30noroot 31noroot
31nosound 32nosound
diff --git a/etc/profile-m-z/xviewer.profile b/etc/profile-m-z/xviewer.profile
index 0ac0f665e..4d454f81c 100644
--- a/etc/profile-m-z/xviewer.profile
+++ b/etc/profile-m-z/xviewer.profile
@@ -26,6 +26,7 @@ caps.drop all
26no3d 26no3d
27nodvd 27nodvd
28nogroups 28nogroups
29noinput
29nonewprivs 30nonewprivs
30noroot 31noroot
31nosound 32nosound
diff --git a/etc/profile-m-z/yarn.profile b/etc/profile-m-z/yarn.profile
index 360bd8442..05b55d071 100644
--- a/etc/profile-m-z/yarn.profile
+++ b/etc/profile-m-z/yarn.profile
@@ -6,25 +6,5 @@ include yarn.local
6# Persistent global definitions 6# Persistent global definitions
7include globals.local 7include globals.local
8 8
9ignore read-only ${HOME}/.yarnrc
10
11noblacklist ${HOME}/.yarn
12noblacklist ${HOME}/.yarn-config
13noblacklist ${HOME}/.yarncache
14noblacklist ${HOME}/.yarnrc
15
16# If you want whitelisting, change ${HOME}/Projects below to your yarn projects directory and
17# add the next lines to you yarn.local.
18#mkdir ${HOME}/.yarn
19#mkdir ${HOME}/.yarn-config
20#mkdir ${HOME}/.yarncache
21#mkfile ${HOME}/.yarnrc
22#whitelist ${HOME}/.yarn
23#whitelist ${HOME}/.yarn-config
24#whitelist ${HOME}/.yarncache
25#whitelist ${HOME}/.yarnrc
26#whitelist ${HOME}/Projects
27#include whitelist-common.inc
28
29# Redirect 9# Redirect
30include nodejs-common.profile 10include nodejs-common.profile
diff --git a/etc/profile-m-z/yelp.profile b/etc/profile-m-z/yelp.profile
index a08a30b52..93054bfed 100644
--- a/etc/profile-m-z/yelp.profile
+++ b/etc/profile-m-z/yelp.profile
@@ -38,6 +38,7 @@ caps.drop all
38net none 38net none
39nodvd 39nodvd
40nogroups 40nogroups
41noinput
41nonewprivs 42nonewprivs
42noroot 43noroot
43# nosound - add the next line to your yelp.local if you don't need sound support. 44# nosound - add the next line to your yelp.local if you don't need sound support.
diff --git a/etc/profile-m-z/youtube-dl-gui.profile b/etc/profile-m-z/youtube-dl-gui.profile
index c072d6267..b52271a2c 100644
--- a/etc/profile-m-z/youtube-dl-gui.profile
+++ b/etc/profile-m-z/youtube-dl-gui.profile
@@ -33,6 +33,7 @@ machine-id
33netfilter 33netfilter
34nodvd 34nodvd
35nogroups 35nogroups
36noinput
36nonewprivs 37nonewprivs
37noroot 38noroot
38nosound 39nosound
diff --git a/etc/profile-m-z/youtube-dl.profile b/etc/profile-m-z/youtube-dl.profile
index 6ce632682..24c4d6db3 100644
--- a/etc/profile-m-z/youtube-dl.profile
+++ b/etc/profile-m-z/youtube-dl.profile
@@ -43,6 +43,7 @@ netfilter
43no3d 43no3d
44nodvd 44nodvd
45nogroups 45nogroups
46noinput
46nonewprivs 47nonewprivs
47noroot 48noroot
48nosound 49nosound
diff --git a/etc/profile-m-z/youtube-viewer.profile b/etc/profile-m-z/youtube-viewer.profile
index b8f97db1d..7d6e9b0eb 100644
--- a/etc/profile-m-z/youtube-viewer.profile
+++ b/etc/profile-m-z/youtube-viewer.profile
@@ -38,6 +38,7 @@ caps.drop all
38netfilter 38netfilter
39nodvd 39nodvd
40nogroups 40nogroups
41noinput
41nonewprivs 42nonewprivs
42noroot 43noroot
43notv 44notv
diff --git a/etc/profile-m-z/zaproxy.profile b/etc/profile-m-z/zaproxy.profile
index 6228ff3bd..5a168feb6 100644
--- a/etc/profile-m-z/zaproxy.profile
+++ b/etc/profile-m-z/zaproxy.profile
@@ -31,6 +31,7 @@ netfilter
31no3d 31no3d
32nodvd 32nodvd
33nogroups 33nogroups
34noinput
34nonewprivs 35nonewprivs
35noroot 36noroot
36nosound 37nosound
diff --git a/etc/profile-m-z/zart.profile b/etc/profile-m-z/zart.profile
index ca35e3b51..10f83aa30 100644
--- a/etc/profile-m-z/zart.profile
+++ b/etc/profile-m-z/zart.profile
@@ -23,6 +23,7 @@ ipc-namespace
23net none 23net none
24nodvd 24nodvd
25nogroups 25nogroups
26noinput
26nonewprivs 27nonewprivs
27noroot 28noroot
28notv 29notv
diff --git a/etc/profile-m-z/zathura.profile b/etc/profile-m-z/zathura.profile
index 86615341f..a39729685 100644
--- a/etc/profile-m-z/zathura.profile
+++ b/etc/profile-m-z/zathura.profile
@@ -32,6 +32,7 @@ machine-id
32net none 32net none
33nodvd 33nodvd
34nogroups 34nogroups
35noinput
35nonewprivs 36nonewprivs
36noroot 37noroot
37nosound 38nosound
diff --git a/etc/profile-m-z/zeal.profile b/etc/profile-m-z/zeal.profile
index 2d0d944fd..2c6f6910f 100644
--- a/etc/profile-m-z/zeal.profile
+++ b/etc/profile-m-z/zeal.profile
@@ -36,6 +36,7 @@ netfilter
36no3d 36no3d
37nodvd 37nodvd
38nogroups 38nogroups
39noinput
39nonewprivs 40nonewprivs
40noroot 41noroot
41nosound 42nosound
diff --git a/etc/profile-m-z/zulip.profile b/etc/profile-m-z/zulip.profile
index 993f2a64b..093da5212 100644
--- a/etc/profile-m-z/zulip.profile
+++ b/etc/profile-m-z/zulip.profile
@@ -31,6 +31,7 @@ netfilter
31no3d 31no3d
32nodvd 32nodvd
33nogroups 33nogroups
34noinput
34nonewprivs 35nonewprivs
35noroot 36noroot
36notv 37notv