aboutsummaryrefslogtreecommitdiffstats
path: root/etc/profile-a-l
Commit message (Collapse)AuthorAge
...
* goldendict: whitelist path to documentation and localesLibravatar Jose Riha2021-12-01
|
* move whitelists down according to profile.templateLibravatar glitsj162021-11-30
|
* add noblacklists tooLibravatar glitsj162021-11-30
| | | As suggested in https://github.com/netblue30/firejail/pull/4727#discussion_r759402234.
* additional whitelist pathsLibravatar glitsj162021-11-30
|
* etc: Remove comments about nogroups and noroot on nvidiaLibravatar Kelvin M. Klann2021-11-29
| | | | | | | | | | | | | | | | | | | | | | | | `nogroups` should not have been causing issues with rendering on nvidia since commit 623e68216 ("temporary fix for nvidia/nogroups/noroot issue (#3644, #841)", 2020-10-02) and commit cb460c32c ("more nvidia (#3644)", 2020-10-03), which had made it a no-op on nvidia. And the handling of the "render" and "video" groups are independent to the handling of `nogroups` now; see the previous 3 commits. Commits which introduced the comments on each profile: * kodi.profile: commit ce462b6b1 ("fix #3501", 2020-07-16) * mpsyt.profile: commit e17b48fca ("new profile mpsyt.profile", 2018-11-28) * mpv.profile: commit cc7c48983 ("Document #1945", 2018-07-25) * steam.profile: commit d6f8169dd ("steam fixes; #841, #3267", 2020-03-15) Commands used to find the comments: git grep -i nvidia -- etc/profile-* | grep -v private-etc Relates to #4632.
* Merge pull request #4438 from caydey/masterLibravatar netblue302021-11-23
|\ | | | | Added `quiet` to some CLI profiles
| * Added "quiet" to profileLibravatar caydey2021-08-03
| |
* | Profile fixesLibravatar rusty-snake2021-11-14
| | | | | | | | | | | | | | | | - Update RELNOTES and README.md - disable-common.inc - blacklist ${HOME}/.local/share/ibus-typing-booster - blacklist /run/timeshift (closes #4660) - fix audacity.profile (closes #4659)
* | Merge pull request #4635 from smitsohu/noorphansLibravatar netblue302021-11-13
|\ \ | | | | | | deterministic-shutdown option
| * | deterministic-shutdown optionLibravatar smitsohu2021-10-28
| | |
* | | telnet and ftpLibravatar netblue302021-11-12
| | |
* | | disable-common.inc: disable chrome-sandboxLibravatar netblue302021-11-09
| | |
* | | Add alteratives and ld.so.cache to all private-etc linesLibravatar rusty-snake2021-10-27
|/ / | | | | | | Command is the same as in d8d97acb
* | Add disable-proc to firefox-commonLibravatar rusty-snake2021-10-23
| |
* | Remove 'none' from private-etc linesLibravatar rusty-snake2021-10-23
| |
* | add wrc to several profilesLibravatar smitsohu2021-10-23
| |
* | promote /run/udev/data to wrcLibravatar smitsohu2021-10-23
| |
* | Merge pull request #4600 from crocket/masterLibravatar netblue302021-10-21
|\ \ | | | | | | Add profiles for imv, retroarch, and torbrowser
| * | Add profiles for imv, retroarch, and torbrowserLibravatar crocket2021-10-17
| | | | | | | | | | | | | | | imv, retroarch, and torbrowser are also added to firecfg.config
* | | Merge pull request #4612 from jose1711/blobwars_fixLibravatar netblue302021-10-21
|\ \ \ | | | | | | | | blobwars: add path to game assets compatible with Arch
| * | | blobwars: add path to game assets compatible with ArchLibravatar Jose Riha2021-10-17
| | | |
* | | | Merge pull request #4613 from jose1711/joystick_supportLibravatar netblue302021-10-21
|\ \ \ \ | | | | | | | | | | Drop noinput for games with joystick/gamepad support
| * | | | Drop noinput for games with joystick/gamepad supportLibravatar Jose Riha2021-10-17
| |/ / / | | | | | | | | | | | | Fixes #4608
* / / / Fix jumpnbump for Arch usersLibravatar Jose Riha2021-10-19
|/ / / | | | | | | | | | Fixes #4611.
* | | Merge pull request #4599 from rusty-snake/use-allow-trayLibravatar netblue302021-10-10
|\ \ \ | | | | | | | | Use ?ALLOW_TRAY: (#4510) in profiles
| * | | Use ?ALLOW_TRAY: (#4510) in profilesLibravatar rusty-snake2021-10-09
| |/ /
* / / moving out of youtube, and some cleanupLibravatar netblue302021-10-09
|/ /
* | Merge pull request #4587 from kmk3/fix-vscodiumLibravatar netblue302021-10-09
|\ \ | | | | | | Fix vscodium
| * | Add codium.profile as a redirect to vscodium.profileLibravatar Kelvin M. Klann2021-10-04
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Both base names are valid: $ grep '^NAME' /etc/os-release NAME="Artix Linux" $ pacman -Q vscodium-bin vscodium-bin 1.60.2-2 $ pacman -Qlq vscodium-bin | grep -v -e '/$' -e /resources/ | grep /bin/ /usr/bin/codium /usr/bin/vscodium /usr/share/vscodium-bin/bin/codium Note: The first two paths are symlinks to the third one. Fixes #3871.
* | | Merge pull request #4519 from rusty-snake/build-systemsLibravatar netblue302021-10-09
|\ \ \ | | | | | | | | Add profiles for build-systems (/package-managers)
| * | | Drop private-bin from build-systemsLibravatar rusty-snake2021-09-11
| | | |
| * | | build-systems-common: Make whitelist opt-inLibravatar rusty-snake2021-09-11
| | | |
| * | | Add profiles for build-systems (/package-managers)Libravatar rusty-snake2021-09-08
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Profiles: bunler, cargo (refactor), cmake (untested), make, meson, pip All redirect to build-systems-common.profile Other fixes: - blacklist ${HOME}/.bundle - blacklist ${HOME}/.cargo/* -> blacklist ${HOME}/.cargo - blacklist /usr/lib64/ruby
* | | | Merge pull request #4371 from chrpinedo/patch-1Libravatar smitsohu2021-10-05
|\ \ \ \ | |_|/ / |/| | | Correct amule.profile for upnp
| * | | Comment to use UPnP with amule.profileLibravatar Christian Pinedo2021-10-02
| | | | | | | | | | | | | | | | In order UPnP to work netlink protocol must be enabled.
* | | | Profile fixes and hardeningLibravatar rusty-snake2021-09-30
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | * cheese - fix: dbus-user.own org.gnome.Cheese - fix: whitelist /usr/share/gstreamer-1.0 - fix: include allow-python3.inc - hardening: include disable-shell.inc - hardening: include whitelist-run-common.inc and whitelist /run/udev/data - hardening: whitelist /usr/libexec/gstreamer-1.0/gst-plugin-scanner - hardening: noinput - hardening: nosound - hardening: seccomp.block-secondary - hardening: private-dev * geekbench (closes #4576) - fix: noblacklist /sbin and noblacklist /usr/sbin - fix: noblacklist, blacklist, mkdir, whitelist, read-write ${HOME}/.geekbench5 - fix: comment/remove private-bin, private-lib, private-opt * inkscape - add quiet for cli usage * musixmatch (#4518) - allow chroot * pandoc - fix: include allow-bin-sh.inc - fix: drop private-bin - hardening: include whitelist-runuser-common.inc - hardening: seccomp.block-secondary
* | | | trim excess whitespaceLibravatar a13460542021-09-25
| | | |
* | | | Merge pull request #4559 from rusty-snake/private-etc_ld.so.preloadLibravatar netblue302021-09-24
|\ \ \ \ | | | | | | | | | | Add ld.so.preload to all private-etc lines
| * | | | Add ld.so.preload to all private-etc linesLibravatar rusty-snake2021-09-18
| | |/ / | |/| | | | | | | | | | | | | | | | | | | | | | | | | | Command: sed -i -E "s/^private-etc /private-etc ld.so.preload,/" \ $(grep -LE "^private-etc .*ld.so.preload" etc/profile-*/*) \ && python3 contrib/sort.py etc/profile-*/*
* | | | Merge pull request #4564 from lecso7/masterLibravatar netblue302021-09-24
|\ \ \ \ | | | | | | | | | | Create goldendict.profile
| * | | | Create goldendict.profileLibravatar lecso72021-09-20
| | | | |
* | | | | Merge pull request #4572 from a1346054/newline-fixLibravatar netblue302021-09-24
|\ \ \ \ \ | | | | | | | | | | | | Add missing final newlines
| * | | | | add missing final newlines at end of filesLibravatar a13460542021-09-22
| |/ / / /
* / / / / fix spelling (#4573)Libravatar a13460542021-09-22
|/ / / /
* | | | Let programs outside librewolf sandbox open new tabs in librewolf (#4546)Libravatar crocket2021-09-19
| | | |
* | | | Fix #4555 - Allow evince to read .cbz file formatLibravatar lecso72021-09-19
|/ / / | | | | | | | | | | | | Enable evince to display archived images (.cbz) file with plugin installed.
* | | Merge pull request #4493 from pirate486743186/fix-duplicate-globalLibravatar rusty-snake2021-09-08
|\ \ \ | | | | | | | | fix duplicate globals
| * | | fix duplicate globalLibravatar pirate4867431862021-08-30
| | | |
* | | | Fix #4367 -- gimp 2.10.22-3: gegl:introspect brokenLibravatar rusty-snake2021-09-08
| | | |
* | | | Rework pipewire/waylandLibravatar rusty-snake2021-09-07
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | - closes #4483 -- mpv requires whitelisting /usr/share/pipewire - wruc: whitelist pipewire-?, pipewire is becoming more popular and was developed with isolation (container/sandbox) in mind. - wruc: whitelist wayland-? instead of only -0 and -1 - wusc: whitelist /usr/share/pipewire - remove these wruc/wusc lines from other profiles - firefox-common-addons: Make ignore wruc work again (#4512) - firefox: org.freedesktop.portal.Desktop should be enough