aboutsummaryrefslogtreecommitdiffstats
path: root/etc/profile-a-l
Commit message (Collapse)AuthorAge
* Add disable-proc to firefox-commonLibravatar rusty-snake2021-10-23
|
* Remove 'none' from private-etc linesLibravatar rusty-snake2021-10-23
|
* add wrc to several profilesLibravatar smitsohu2021-10-23
|
* promote /run/udev/data to wrcLibravatar smitsohu2021-10-23
|
* Merge pull request #4600 from crocket/masterLibravatar netblue302021-10-21
|\ | | | | Add profiles for imv, retroarch, and torbrowser
| * Add profiles for imv, retroarch, and torbrowserLibravatar crocket2021-10-17
| | | | | | | | | | imv, retroarch, and torbrowser are also added to firecfg.config
* | Merge pull request #4612 from jose1711/blobwars_fixLibravatar netblue302021-10-21
|\ \ | | | | | | blobwars: add path to game assets compatible with Arch
| * | blobwars: add path to game assets compatible with ArchLibravatar Jose Riha2021-10-17
| | |
* | | Merge pull request #4613 from jose1711/joystick_supportLibravatar netblue302021-10-21
|\ \ \ | | | | | | | | Drop noinput for games with joystick/gamepad support
| * | | Drop noinput for games with joystick/gamepad supportLibravatar Jose Riha2021-10-17
| |/ / | | | | | | | | | Fixes #4608
* / / Fix jumpnbump for Arch usersLibravatar Jose Riha2021-10-19
|/ / | | | | | | Fixes #4611.
* | Merge pull request #4599 from rusty-snake/use-allow-trayLibravatar netblue302021-10-10
|\ \ | | | | | | Use ?ALLOW_TRAY: (#4510) in profiles
| * | Use ?ALLOW_TRAY: (#4510) in profilesLibravatar rusty-snake2021-10-09
| |/
* / moving out of youtube, and some cleanupLibravatar netblue302021-10-09
|/
* Merge pull request #4587 from kmk3/fix-vscodiumLibravatar netblue302021-10-09
|\ | | | | Fix vscodium
| * Add codium.profile as a redirect to vscodium.profileLibravatar Kelvin M. Klann2021-10-04
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Both base names are valid: $ grep '^NAME' /etc/os-release NAME="Artix Linux" $ pacman -Q vscodium-bin vscodium-bin 1.60.2-2 $ pacman -Qlq vscodium-bin | grep -v -e '/$' -e /resources/ | grep /bin/ /usr/bin/codium /usr/bin/vscodium /usr/share/vscodium-bin/bin/codium Note: The first two paths are symlinks to the third one. Fixes #3871.
* | Merge pull request #4519 from rusty-snake/build-systemsLibravatar netblue302021-10-09
|\ \ | | | | | | Add profiles for build-systems (/package-managers)
| * | Drop private-bin from build-systemsLibravatar rusty-snake2021-09-11
| | |
| * | build-systems-common: Make whitelist opt-inLibravatar rusty-snake2021-09-11
| | |
| * | Add profiles for build-systems (/package-managers)Libravatar rusty-snake2021-09-08
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Profiles: bunler, cargo (refactor), cmake (untested), make, meson, pip All redirect to build-systems-common.profile Other fixes: - blacklist ${HOME}/.bundle - blacklist ${HOME}/.cargo/* -> blacklist ${HOME}/.cargo - blacklist /usr/lib64/ruby
* | | Merge pull request #4371 from chrpinedo/patch-1Libravatar smitsohu2021-10-05
|\ \ \ | |_|/ |/| | Correct amule.profile for upnp
| * | Comment to use UPnP with amule.profileLibravatar Christian Pinedo2021-10-02
| | | | | | | | | | | | In order UPnP to work netlink protocol must be enabled.
* | | Profile fixes and hardeningLibravatar rusty-snake2021-09-30
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | * cheese - fix: dbus-user.own org.gnome.Cheese - fix: whitelist /usr/share/gstreamer-1.0 - fix: include allow-python3.inc - hardening: include disable-shell.inc - hardening: include whitelist-run-common.inc and whitelist /run/udev/data - hardening: whitelist /usr/libexec/gstreamer-1.0/gst-plugin-scanner - hardening: noinput - hardening: nosound - hardening: seccomp.block-secondary - hardening: private-dev * geekbench (closes #4576) - fix: noblacklist /sbin and noblacklist /usr/sbin - fix: noblacklist, blacklist, mkdir, whitelist, read-write ${HOME}/.geekbench5 - fix: comment/remove private-bin, private-lib, private-opt * inkscape - add quiet for cli usage * musixmatch (#4518) - allow chroot * pandoc - fix: include allow-bin-sh.inc - fix: drop private-bin - hardening: include whitelist-runuser-common.inc - hardening: seccomp.block-secondary
* | | trim excess whitespaceLibravatar a13460542021-09-25
| | |
* | | Merge pull request #4559 from rusty-snake/private-etc_ld.so.preloadLibravatar netblue302021-09-24
|\ \ \ | | | | | | | | Add ld.so.preload to all private-etc lines
| * | | Add ld.so.preload to all private-etc linesLibravatar rusty-snake2021-09-18
| | |/ | |/| | | | | | | | | | | | | | | | | | | Command: sed -i -E "s/^private-etc /private-etc ld.so.preload,/" \ $(grep -LE "^private-etc .*ld.so.preload" etc/profile-*/*) \ && python3 contrib/sort.py etc/profile-*/*
* | | Merge pull request #4564 from lecso7/masterLibravatar netblue302021-09-24
|\ \ \ | | | | | | | | Create goldendict.profile
| * | | Create goldendict.profileLibravatar lecso72021-09-20
| | | |
* | | | Merge pull request #4572 from a1346054/newline-fixLibravatar netblue302021-09-24
|\ \ \ \ | | | | | | | | | | Add missing final newlines
| * | | | add missing final newlines at end of filesLibravatar a13460542021-09-22
| |/ / /
* / / / fix spelling (#4573)Libravatar a13460542021-09-22
|/ / /
* | | Let programs outside librewolf sandbox open new tabs in librewolf (#4546)Libravatar crocket2021-09-19
| | |
* | | Fix #4555 - Allow evince to read .cbz file formatLibravatar lecso72021-09-19
|/ / | | | | | | | | Enable evince to display archived images (.cbz) file with plugin installed.
* | Merge pull request #4493 from pirate486743186/fix-duplicate-globalLibravatar rusty-snake2021-09-08
|\ \ | | | | | | fix duplicate globals
| * | fix duplicate globalLibravatar pirate4867431862021-08-30
| | |
* | | Fix #4367 -- gimp 2.10.22-3: gegl:introspect brokenLibravatar rusty-snake2021-09-08
| | |
* | | Rework pipewire/waylandLibravatar rusty-snake2021-09-07
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | - closes #4483 -- mpv requires whitelisting /usr/share/pipewire - wruc: whitelist pipewire-?, pipewire is becoming more popular and was developed with isolation (container/sandbox) in mind. - wruc: whitelist wayland-? instead of only -0 and -1 - wusc: whitelist /usr/share/pipewire - remove these wruc/wusc lines from other profiles - firefox-common-addons: Make ignore wruc work again (#4512) - firefox: org.freedesktop.portal.Desktop should be enough
* | | Profile fixesLibravatar rusty-snake2021-09-04
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | - disable-programs.inc: blacklist ${HOME}/.local/state/pipewire If you did not yet noticed, on 08th May 2021 the XDG Base Directory Specification 0.8 was resleased (the first update since 2010). New are $XDG_STATE_HOME and $HOME/.local/bin. - keepassxc: mkdirs are necessary - gnote: harden - pngquant: harden
* | | Fix #4506 -- Freetube does not startLibravatar rusty-snake2021-09-03
|/ / | | | | | | Freetube from AUR uses a wrapper script
* | creating gallery-dl.profileLibravatar pirate4867431862021-08-27
| |
* | Update celluloid.profileLibravatar rusty-snake2021-08-16
| | | | | | | | Fix #4469
* | Move disable-passwordmgr.inc into disable-common.inc/disable-programs.inc ↵Libravatar rusty-snake2021-08-12
| | | | | | | | follow up
* | Move disable-passwordmgr.inc into disable-common.inc/disable-programs.inc ↵Libravatar rusty-snake2021-08-12
| | | | | | | | | | (#4461) See #4454
* | Update keepassxc.profileLibravatar rusty-snake2021-08-09
| | | | | | | | | | | | | | - Add whitelist-run-common.inc - Drop netlink (there are no error or borken feature for me (including auto-type)) - Second update for the dbus-policy
* | Correct directory for sway.profile and io.github.lainsce.Notejot.profileLibravatar rusty-snake2021-08-09
| |
* | Revice keepassxc's dbus policyLibravatar rusty-snake2021-08-05
| |
* | Add wru to firefox-common, chromium-common and profile.templateLibravatar rusty-snake2021-08-04
| | | | | | | | | | | | | | Still unresolved: > If someone who use systemd-resolved can say more which resolv.conf is necessary on such system. > whitelist /run/systemd/resolve/resolv.conf > whitelist /run/systemd/resolve/stub-resolv.conf
* | Profile fixesLibravatar rusty-snake2021-08-04
| | | | | | | | | | | | | | | | | | | | - Fix #4157 -- [Feature] Should rmenv GitHub auth tokens There are still more token variables from other program that should be added. - Fix #4093 -- darktable needs read access to liblua* - Fix #4383 -- move noblacklist ${HOME}/.bogofilter to email-common.profile for claws-mail (and other mailers) - Fix xournalpp.profile - syscalls.txt: ausyscall i386 -> firejail --debug-syscalls32
* | Add electron[0-9]{0,2} to all electron redirect …Libravatar rusty-snake2021-08-01
| | | | | | | | …profiles with private-bin
* | Fixup: Fix Firefox 'Profile not found' - whitelist /run/user/xxx/firefoxLibravatar rusty-snake2021-07-28
| |