aboutsummaryrefslogtreecommitdiffstats
path: root/etc
Commit message (Collapse)AuthorAge
* rsync-download_only: fix local override name (#5695)Libravatar glitsj162023-02-28
|
* minor clarify userns comments (#5686)Libravatar pirate4867431862023-02-26
| | | Co-authored-by: pirate486743186 <>
* parsecd: ordering fixes (#5682)Libravatar glitsj162023-02-25
|
* Merge pull request #5646 from NetSysFire/parsecdLibravatar netblue302023-02-24
|\ | | | | New profile: parsecd
| * parsecd.profile: more white and blacklistingLibravatar NetSysFire2023-02-24
| |
| * New profile: parsecdLibravatar NetSysFire2023-02-18
| |
* | Merge pull request #5674 from kmk3/fix-ws-add-editorconfigLibravatar netblue302023-02-24
|\ \ | | | | | | build: Fix whitespace and add .editorconfig
| * | Trim trailing whitespaceLibravatar Kelvin M. Klann2023-02-19
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Commands used to search and replace: $ git grep -Ilz '[[:blank:]]$' | xargs -0 -I '{}' sh -c "printf '%s\n' \"\$(sed -E \ 's/[[:blank:]]+$//' '{}')\" >'{}'" This fixes all of the "trailing whitespace" errors raised by git: $ git diff --check 4b825dc642cb6eb9a060e54bf8d69288fbee4904..HEAD | grep '^[^+]' | cut -f 3 -d : | LC_ALL=C sort | uniq -c 72 space before tab in indent. 4 trailing whitespace.
| * | Fix EOL at EOFLibravatar Kelvin M. Klann2023-02-19
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Commands used to search and replace: $ git grep -Ilz '.' | xargs -0 -I '{}' sh -c \ "printf '%s\n' \"\$(cat '{}')\" >'{}'" The above commands ensure that there is exaclty 1 line terminator at EOF (rather than 0 or more than 1) on all non-empty text files. This fixes all of the "new blank line at EOF" errors raised by git: $ git diff --check 4b825dc642cb6eb9a060e54bf8d69288fbee4904..HEAD | grep '^[^+]' | cut -f 3 -d : | LC_ALL=C sort | uniq -c 21 new blank line at EOF. 72 space before tab in indent. 4 trailing whitespace.
* | | more private-etcLibravatar netblue302023-02-24
| | |
* | | New profiles: qpdf and redirects (#5675)Libravatar glitsj162023-02-23
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | * Create qpdf.profile and redirects qpdf (CLI) provides PDF metadata cleaning. See privacy-handbuch.de[1] for details. The site offers pdf-meta-clean.sh[2], which works very well with firejailed qpdf. [1] https://www.privacy-handbuch.de/handbuch_43a.htm [2] https://www.privacy-handbuch.de/download/pdf-meta-clean.sh * RELNOTES: add qpdf and redirects to new profiles section * firecfg.config: add qpdf and redirects * qpdf: use 'seccomp socket' instead of 'protocol unix' See https://github.com/netblue30/firejail/issues/639. Thanks @rusty-snake in code review.
* | | apostrophe: drop whitelist covered by wusc (#5671)Libravatar glitsj162023-02-23
| | |
* | | disable-common.inc: add systemd v253 blacklists (#5669)Libravatar glitsj162023-02-23
|/ / | | | | | | | | | | | | | | | | | | | | | | | | | | Arch Linux got systemd v253: https://github.com/archlinux/svntogit-packages/commit/05d0aedb2b83a2e1ba07cab47205772f82cb4814 It adds a few new files we should blacklist in `disable-common.inc`: - /etc/credstore - /etc/credstore.encrypted - /run/credentials/systemd-sysctl.service - /run/credentials/systemd-sysusers.service - /run/credentials/systemd-tmpfiles-setup.service - /run/credentials/systemd-tmpfiles-setup-dev.service
* | merges, testing, private-etcLibravatar netblue302023-02-16
| |
* | wusc: allow hyphenation (#5666)Libravatar glitsj162023-02-15
| |
* | com.github.johnfactotum.Foliate: fix .local include (#5665)Libravatar glitsj162023-02-15
| |
* | qutebrowser: allow userscripts by default (#5649)Libravatar glitsj162023-02-15
| | | | | | | | | | | | | | Fixes #5639. qutebrowser: drop apparmor Suggested in PR review.
* | merges, disable sort.py in profile checks temporarely, two more private-etc ↵Libravatar netblue302023-02-14
| | | | | | | | profiles
* | Merge pull request #5653 from slowpeek/masterLibravatar netblue302023-02-14
|\ \ | | | | | | disable-programs.inc: blacklist sendgmail config
| * | Blacklist sendgmail configLibravatar slowpeek2023-02-11
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | sendgmail is a cli tool by Google that "uses Gmail in order to mimic sendmail for git send-email" as per its own description. In other words it is a basic sendmail replacement with OAuth2 support to send emails from Gmail accounts. https://github.com/google/gmail-oauth2-tools/tree/master/go/sendgmail Config files location depends on "xdg" build tag. Without the tag it would be "~/.sendgmail.*". With the tag it is either under "$XDG_CONFIG_HOME/sendgmail" if set or "~/.config/sendgmail" otherwise.
* | | Merge pull request #5660 from glitsj16/tmc-fixLibravatar netblue302023-02-14
|\ \ \ | | | | | | | | transmission-cli: allow web client
| * | | transmission-cli: allow web clientLibravatar glitsj162023-02-14
| | | |
* | | | Prevent access to LUKS keyfileLibravatar Netcarver2023-02-14
|/ / /
* / / private-etc: kdiff3, gzip, gunzip, tar etcLibravatar netblue302023-02-10
|/ /
* | private-etc: more on gcryptLibravatar netblue302023-02-09
| |
* | private-etc: moving gcrypt from tls-ca to x11 groupLibravatar netblue302023-02-08
| |
* | private-etc: libreoffice, audacity, forzen-bubble, transmission, ↵Libravatar netblue302023-02-08
|/ | | | md5sum/sha512sum, more sysutils testing, fix electron-hardened.inc.profile
* re-fix private-etcLibravatar glitsj162023-02-06
|
* private-etc: pushing vulkan into games groupLibravatar netblue302023-02-06
|
* Merge pull request #5642 from glitsj16/private-etc-ephemeralLibravatar netblue302023-02-06
|\ | | | | ephemeral: use newly introduced private-etc @groups syntax
| * ephemeral: use newly introduced private-etc @groups syntaxLibravatar glitsj162023-02-06
| |
* | Merge branch 'master' into private-etc-fixesLibravatar netblue302023-02-06
|\|
| * private-etc: java directory fixesLibravatar netblue302023-02-05
| |
| * private-etc: groups modifiedLibravatar netblue302023-02-05
| |
* | xiphos: fix private-etcLibravatar glitsj162023-02-05
| | | | | | There is no `/etc/ssli` AFAIK. Existing typo prior to private-etc rework likely caused this.
* | whois: fix private-etcLibravatar glitsj162023-02-05
| | | | | | There is no `/etc/jwhois.conf` AFAIK. Existing typo prior to private-etc rework likely caused this.
* | marker: fix private-etcLibravatar glitsj162023-02-05
| | | | | | `dconfgtk-3.0` was missing a `,` prior to the private-etc rework.
* | ghostwriter: fix private-etcLibravatar glitsj162023-02-05
| | | | | | There is no `/etc/groups` AFAIK. Existing typo prior to private-etc rework likely caused this.
* | email-common: fix private-etcLibravatar glitsj162023-02-05
| | | | | | There is no `/etc/groups` AFAIK. Existing typo prior to private-etc rework likely caused this.
* | discord-common: fix private-etcLibravatar glitsj162023-02-05
| | | | | | `passwd` is already in @default group.
* | aria2c: fix private-etcLibravatar glitsj162023-02-05
|/ | | There is no `/etc/groups` AFAIK. Existing typo prior to private-etc rework likely caused this.
* private-etc: big profile changesLibravatar netblue302023-02-05
|
* Merge pull request #5635 from kmk3/dc-add-ro-editor-browserLibravatar netblue302023-01-31
|\ | | | | disable-common.inc: add more ro editor/browser paths
| * disable-common.inc: make ~/.config/nano read-onlyLibravatar Kelvin M. Klann2023-01-30
| | | | | | | | | | | | Similarly to the existing ~/.nanorc entry. Taken from nano.profile.
| * disable-common.inc: add more ro editor/browser pathsLibravatar Kelvin M. Klann2023-01-30
| | | | | | | | | | | | | | | | | | Move some paths from mutt.profile and neomutt.profile. Added on commit 6b9bfad37 ("Fix python; add read-only to editors/cli browsers;re-add cache directory", 2020-12-29) / PR #3849. Misc: This is a follow-up to #5626.
* | Merge pull request #5631 from glitsj16/inkscapeLibravatar netblue302023-01-31
|\ \ | | | | | | inkscape: additional hardening and settings saving via D-Bus
| * | inkscape: rebase and drop mdwe commentLibravatar glitsj162023-01-31
| | |
| * | Merge branch 'netblue30:master' into inkscapeLibravatar glitsj162023-01-31
| |\|
| * | inkscape: additional hardening and settings saving functionality via D-BusLibravatar glitsj162023-01-29
| | |
* | | Merge branch 'netblue30:master' into warzone2100Libravatar glitsj162023-01-31
|\ \ \ | | |/ | |/|