aboutsummaryrefslogtreecommitdiffstats
path: root/etc
Commit message (Collapse)AuthorAge
* Add alteratives and ld.so.cache to all private-etc linesLibravatar rusty-snake2021-10-27
| | | | Command is the same as in d8d97acb
* Add disable-proc to firefox-commonLibravatar rusty-snake2021-10-23
|
* Remove 'none' from private-etc linesLibravatar rusty-snake2021-10-23
|
* wrc: whitelist journal socketsLibravatar smitsohu2021-10-23
| | | | fixes --tracelog among other things
* add wrc to several profilesLibravatar smitsohu2021-10-23
|
* promote /run/udev/data to wrcLibravatar smitsohu2021-10-23
|
* disable-exec: add /run/shmLibravatar smitsohu2021-10-23
|
* Merge pull request #4628 from smitsohu/aaLibravatar netblue302021-10-21
|\ | | | | add basic Firejail support to AppArmor base abstraction (#3226)
| * add basic Firejail support to AppArmor base abstraction (#3226)Libravatar smitsohu2021-10-21
| |
* | Merge pull request #4600 from crocket/masterLibravatar netblue302021-10-21
|\ \ | | | | | | Add profiles for imv, retroarch, and torbrowser
| * | Add profiles for imv, retroarch, and torbrowserLibravatar crocket2021-10-17
| | | | | | | | | | | | | | | imv, retroarch, and torbrowser are also added to firecfg.config
* | | Merge pull request #4612 from jose1711/blobwars_fixLibravatar netblue302021-10-21
|\ \ \ | | | | | | | | blobwars: add path to game assets compatible with Arch
| * | | blobwars: add path to game assets compatible with ArchLibravatar Jose Riha2021-10-17
| | | |
* | | | Merge pull request #4613 from jose1711/joystick_supportLibravatar netblue302021-10-21
|\ \ \ \ | | | | | | | | | | Drop noinput for games with joystick/gamepad support
| * | | | Drop noinput for games with joystick/gamepad supportLibravatar Jose Riha2021-10-17
| |/ / / | | | | | | | | | | | | Fixes #4608
* | | | Merge pull request #4621 from jose1711/tremulous_archfixLibravatar netblue302021-10-21
|\ \ \ \ | | | | | | | | | | Fix tremulous profile for Arch users
| * | | | Update etc/profile-m-z/tremulous.profileLibravatar Jose Riha2021-10-19
| | | | | | | | | | | | | | | Co-authored-by: Kelvin M. Klann <kmk3.code@protonmail.com>
| * | | | Update etc/profile-m-z/tremulous.profileLibravatar Jose Riha2021-10-19
| | | | | | | | | | | | | | | Co-authored-by: Kelvin M. Klann <kmk3.code@protonmail.com>
| * | | | Update etc/profile-m-z/tremulous.profileLibravatar Jose Riha2021-10-19
| | | | | | | | | | | | | | | Co-authored-by: rusty-snake <41237666+rusty-snake@users.noreply.github.com>
| * | | | Fix tremulous profile for Arch usersLibravatar Jose Riha2021-10-18
| |/ / /
* | | | Merge pull request #4622 from jose1711/jumnbump_fixLibravatar netblue302021-10-21
|\ \ \ \ | | | | | | | | | | Fix jumpnbump for Arch users
| * | | | Fix jumpnbump for Arch usersLibravatar Jose Riha2021-10-19
| |/ / / | | | | | | | | | | | | Fixes #4611.
* | | | Merge pull request #4624 from jose1711/warsow_archfixLibravatar netblue302021-10-21
|\ \ \ \ | | | | | | | | | | Fix warsow profile for Arch users
| * | | | Update etc/profile-m-z/warsow.profileLibravatar Jose Riha2021-10-19
| | | | | | | | | | | | | | | Co-authored-by: Kelvin M. Klann <kmk3.code@protonmail.com>
| * | | | Update etc/profile-m-z/warsow.profileLibravatar Jose Riha2021-10-19
| | | | | | | | | | | | | | | Co-authored-by: rusty-snake <41237666+rusty-snake@users.noreply.github.com>
| * | | | Update etc/profile-m-z/warsow.profileLibravatar Jose Riha2021-10-19
| | | | | | | | | | | | | | | Co-authored-by: rusty-snake <41237666+rusty-snake@users.noreply.github.com>
| * | | | Fix warsow profile for Arch usersLibravatar Jose Riha2021-10-19
| |/ / / | | | | | | | | | | | | | | | | | | | | Warsow uses a shell wrapper hence requires some modifications. Netlink was added to protocols as the game was segfaulting after changing resolution and saving the setting.
* | | | Merge pull request #4521 from rusty-snake/disable-proc.incLibravatar smitsohu2021-10-20
|\ \ \ \ | |/ / / |/| | | Create disable-proc.inc
| * | | Update disable-proc.incLibravatar rusty-snake2021-10-09
| | | |
| * | | Update disable-proc.incLibravatar rusty-snake2021-09-10
| | | |
| * | | Create disable-proc.incLibravatar rusty-snake2021-09-09
| | | |
* | | | add /run/shm to wrcLibravatar smitsohu2021-10-16
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | found in Debian Bullseye. /run/shm is a symbolic link to /dev/shm, and whitelisting it will just recreate the symbolic link.
* | | | Merge pull request #4599 from rusty-snake/use-allow-trayLibravatar netblue302021-10-10
|\ \ \ \ | | | | | | | | | | Use ?ALLOW_TRAY: (#4510) in profiles
| * | | | Use ?ALLOW_TRAY: (#4510) in profilesLibravatar rusty-snake2021-10-09
| | |/ / | |/| |
* / | | moving out of youtube, and some cleanupLibravatar netblue302021-10-09
|/ / /
* | | Merge pull request #4587 from kmk3/fix-vscodiumLibravatar netblue302021-10-09
|\ \ \ | | | | | | | | Fix vscodium
| * | | Add codium.profile as a redirect to vscodium.profileLibravatar Kelvin M. Klann2021-10-04
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Both base names are valid: $ grep '^NAME' /etc/os-release NAME="Artix Linux" $ pacman -Q vscodium-bin vscodium-bin 1.60.2-2 $ pacman -Qlq vscodium-bin | grep -v -e '/$' -e /resources/ | grep /bin/ /usr/bin/codium /usr/bin/vscodium /usr/share/vscodium-bin/bin/codium Note: The first two paths are symlinks to the third one. Fixes #3871.
| * | | vscodium.profile: add missing pathsLibravatar Kelvin M. Klann2021-10-04
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | It creates the following directories on startup: * ~/.config/VSCodium * ~/.vscode-oss Environment: $ grep '^NAME' /etc/os-release NAME="Artix Linux" $ pacman -Q vscodium-bin vscodium-bin 1.60.2-2 Note: The following entry is already on disable-programs.inc: noblacklist ${HOME}/.vscode-oss It was added on commit de90834a8 ("Update disable-programs.inc", 2019-03-02). Relates to #3871.
| * | | vscodium.profile: fix wrong program name in the commentsLibravatar Kelvin M. Klann2021-10-04
| | |/ | |/| | | | | | | Added on commit 4bb7dee49 ("small changes", 2019-02-07).
* | | Merge pull request #4510 from rusty-snake/allow-tray-conditionLibravatar netblue302021-10-09
|\ \ \ | | | | | | | | Add new condition ALLOW_TRAY
| * | | Add new condition ALLOW_TRAYLibravatar rusty-snake2021-09-04
| | | |
* | | | Merge pull request #4519 from rusty-snake/build-systemsLibravatar netblue302021-10-09
|\ \ \ \ | | | | | | | | | | Add profiles for build-systems (/package-managers)
| * | | | Drop private-bin from build-systemsLibravatar rusty-snake2021-09-11
| | | | |
| * | | | build-systems-common: Make whitelist opt-inLibravatar rusty-snake2021-09-11
| | | | |
| * | | | Add profiles for build-systems (/package-managers)Libravatar rusty-snake2021-09-08
| | |_|/ | |/| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Profiles: bunler, cargo (refactor), cmake (untested), make, meson, pip All redirect to build-systems-common.profile Other fixes: - blacklist ${HOME}/.bundle - blacklist ${HOME}/.cargo/* -> blacklist ${HOME}/.cargo - blacklist /usr/lib64/ruby
* | | | Merge pull request #4371 from chrpinedo/patch-1Libravatar smitsohu2021-10-05
|\ \ \ \ | |_|_|/ |/| | | Correct amule.profile for upnp
| * | | Comment to use UPnP with amule.profileLibravatar Christian Pinedo2021-10-02
| | | | | | | | | | | | | | | | In order UPnP to work netlink protocol must be enabled.
* | | | Profile fixes and hardeningLibravatar rusty-snake2021-09-30
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | * cheese - fix: dbus-user.own org.gnome.Cheese - fix: whitelist /usr/share/gstreamer-1.0 - fix: include allow-python3.inc - hardening: include disable-shell.inc - hardening: include whitelist-run-common.inc and whitelist /run/udev/data - hardening: whitelist /usr/libexec/gstreamer-1.0/gst-plugin-scanner - hardening: noinput - hardening: nosound - hardening: seccomp.block-secondary - hardening: private-dev * geekbench (closes #4576) - fix: noblacklist /sbin and noblacklist /usr/sbin - fix: noblacklist, blacklist, mkdir, whitelist, read-write ${HOME}/.geekbench5 - fix: comment/remove private-bin, private-lib, private-opt * inkscape - add quiet for cli usage * musixmatch (#4518) - allow chroot * pandoc - fix: include allow-bin-sh.inc - fix: drop private-bin - hardening: include whitelist-runuser-common.inc - hardening: seccomp.block-secondary
* | | | Rework D-Bus policy of nhekoLibravatar rusty-snake2021-09-29
| | | | | | | | | | | | | | | | | | | | - Allow org.freedesktop.secrets, fixes #4584 - Improve comments about notifications and systray
* | | | trim excess whitespaceLibravatar a13460542021-09-25
| | | |