| Commit message (Collapse) | Author | Age |
| |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
This check was broken by commit 34d004892 ("private-etc: corss-distro
test for curl, gimp, inkscape, firefox, warzone2100", 2023-01-28).
private-etc is currently being reworked and the files in question may no
longer be required.
Output of running the check:
$ ./ci/check/profiles/private-etc-always-required.sh etc/inc/*.inc etc/{profile-a-l,profile-m-z}/*.profile
etc/profile-a-l/curl.profile misses alternatives
etc/profile-a-l/curl.profile misses ld.so.cache
etc/profile-a-l/curl.profile misses ld.so.preload
etc/profile-a-l/firefox-common.profile misses alternatives
etc/profile-a-l/firefox-common.profile misses ld.so.cache
etc/profile-a-l/firefox-common.profile misses ld.so.preload
etc/profile-a-l/gimp.profile misses alternatives
etc/profile-a-l/gimp.profile misses ld.so.cache
etc/profile-a-l/gimp.profile misses ld.so.preload
etc/profile-a-l/inkscape.profile misses alternatives
etc/profile-a-l/inkscape.profile misses ld.so.cache
etc/profile-a-l/inkscape.profile misses ld.so.preload
etc/profile-m-z/warzone2100.profile misses alternatives
etc/profile-m-z/warzone2100.profile misses ld.so.cache
etc/profile-m-z/warzone2100.profile misses ld.so.preload
Relates to #4643 #5610.
|
|
|
|
|
|
| |
Command used:
$ ./ci/check/profiles/sort.py etc/inc/*.inc etc/profile-*/*.profile
|
|
|
|
| |
This is necessary if I want to launch a terminal editor from
qutebrowser.
|
| |
|
| |
|
| |
|
| |
|
|\ |
|
| |
| |
| |
| | |
Closes #5601
|
|/ |
|
|
|
|
| |
groups added
|
| |
|
| |
|
|
|
|
|
|
|
| |
It is currently only used on the "install" target.
This amends commit 16afd8c8e ("Add basic gtksourceview language-spec
(#5502)", 2022-12-04).
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
* zoom.profile: whitelist ~/.config/zoom.conf
With Zoom version 5.12.6, Zoom changed how they handle encrypting the local
database. This change resulted in the new file zoom.conf being used. As it is
not allowed by the current profile, this could lead to users losing their chat
history if they cannot be retrieved from the cloud (e.g. when e2e encryption is
used).
* zoom.profile: noblacklist ~/.config/zoom.conf
Additional blacklisting for other programs to the configuration file.
|
| |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 2.1.38 to 2.1.39.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](https://github.com/github/codeql-action/compare/515828d97454b8354517688ddc5b48402b723750...a34ca99b4610d924e04c68db79e503e1f79f9f02)
---
updated-dependencies:
- dependency-name: github/codeql-action
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
|
| |
|
|\
| |
| | |
private-etc rework fixes
|
| | |
|
| | |
|
| | |
|
| | |
|
| | |
|
| | |
|
| | |
|
| | |
|
| | |
|
| | |
|
|/ |
|
| |
|
| |
|
|
|
|
| |
feature
|
|
|
|
| |
Relates to #5589 #5599 #5600.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
Commands used to find the profiles and print the RELNOTES items:
$ git log --reverse --pretty= --name-only --diff-filter=A \
0.9.70..0.9.72 -- etc/inc etc/net etc/profile-* | cut -f 3 -d / |
sed -E -e 's/^([^.]+)\.profile$/\1/' -e 's/$/,/' | tr '\n' ' ' |
fold -s -w 61 | sed 's/^/ * new profiles: /'; echo
Based on the commands from commit a320957a1 ("RELNOTES: add missing new
profiles", 2022-06-09) / PR #5184.
Note: 61 is used in fold because it's 79 (the default `textwidth` / `tw`
in vim) minus 18 (the length of " * new profiles: ").
Note2: ".profile" is only trimmed if it's the only suffix, to make it
clear that a new etc/profile-a-l/foo.inc.profile is not a new
etc/inc/foo.inc profile.
Note3: Keep the commas at the end because removing them could need
another `fold` to make the output exactly equivalent to
writing/formatting the items manually.
Note4: There were no profiles removed in 0.9.72:
$ git log --reverse --pretty= --name-only --diff-filter=D \
0.9.70..0.9.72 -- etc/inc etc/net etc/profile-*
$
|
|\
| |
| | |
modif: Stop forwarding own double-dash to the shell
|
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| | |
Currently, if double-dash ("--") is passed to firejail, it is forwarded
to the user shell:
$ firejail --debug --noprofile -- echo test 2>&1 |
grep -e execvp -e test
Building quoted command line: 'echo' 'test'
Building quoted command line: 'echo' 'test'
Running 'echo' 'test' command through /bin/bash
execvp argument 0: /bin/bash
execvp argument 1: -c
execvp argument 2: --
execvp argument 3: 'echo' 'test'
test
This causes issues when the user shell does not accept "--" / is not
POSIX-compatible:
$ /bin/bash -c -- 'echo test'
test
$ /bin/fish -c -- 'echo test'
fish: Unknown command: --
fish:
--
^
Fixes #5599.
Relates to #3434.
Reported-by: @iltep64
Reported-by: @ferreum
|
| | |
|
| | |
|
| | |
|
| | |
|
|\ \ |
|
| | |
| | |
| | |
| | | |
(in Debian CI only sh is getting printed)
|
|/ / |
|
|\ \ |
|
| |\ \
| | | |
| | | | |
docs: remove apparmor options in --help when building without apparmor support
|
| | | | |
|
| | | | |
|
|/ / / |
|