From f6f1cc2f83ccf2878fe36b9c5d303557dae85f67 Mon Sep 17 00:00:00 2001 From: Tad Date: Fri, 25 Aug 2017 16:41:27 -0400 Subject: Fix MulitMC5 and Xonotic --- etc/disable-programs.inc | 1 + etc/lollypop.profile | 2 +- etc/multimc5.profile | 5 +++-- etc/xonotic.profile | 3 ++- 4 files changed, 7 insertions(+), 4 deletions(-) diff --git a/etc/disable-programs.inc b/etc/disable-programs.inc index d02377036..736ac1e89 100644 --- a/etc/disable-programs.inc +++ b/etc/disable-programs.inc @@ -296,6 +296,7 @@ blacklist ${HOME}/.local/share/ktorrentrc blacklist ${HOME}/.local/share/kwrite blacklist ${HOME}/.local/share/lollypop blacklist ${HOME}/.local/share/meld +blacklist ${HOME}/.local/share/multimc blacklist ${HOME}/.local/share/multimc5 blacklist ${HOME}/.local/share/mupen64plus blacklist ${HOME}/.local/share/nautilus diff --git a/etc/lollypop.profile b/etc/lollypop.profile index 587a46353..c0c762c02 100644 --- a/etc/lollypop.profile +++ b/etc/lollypop.profile @@ -25,7 +25,7 @@ seccomp shell none private-dev -private-etc fonts +private-etc asound.conf,ca-certificates,fonts,host.conf,hostname,hosts,pulse,resolv.conf,ssl private-tmp noexec ${HOME} diff --git a/etc/multimc5.profile b/etc/multimc5.profile index 161a38583..3423c2a88 100644 --- a/etc/multimc5.profile +++ b/etc/multimc5.profile @@ -6,6 +6,7 @@ include /etc/firejail/multimc5.local include /etc/firejail/globals.local noblacklist ${HOME}/.java +noblacklist ${HOME}/.local/share/multimc noblacklist ${HOME}/.local/share/multimc5 noblacklist ${HOME}/.multimc5 @@ -14,8 +15,8 @@ include /etc/firejail/disable-devel.inc include /etc/firejail/disable-passwdmgr.inc include /etc/firejail/disable-programs.inc -mkdir ${HOME}/.local/share/multimc5 -mkdir ${HOME}/.multimc5 +mkdir ${HOME}/.local/share/multimc +whitelist ${HOME}/.local/share/multimc whitelist ${HOME}/.local/share/multimc5 whitelist ${HOME}/.multimc5 include /etc/firejail/whitelist-common.inc diff --git a/etc/xonotic.profile b/etc/xonotic.profile index 3df7a5e94..6dc62c33b 100644 --- a/etc/xonotic.profile +++ b/etc/xonotic.profile @@ -31,7 +31,8 @@ shell none disable-mnt private-bin bash,blind-id,darkplaces-glx,darkplaces-sdl,dash,dirname,grep,ldd,netstat,ps,readlink,sh,uname,xonotic,xonotic-glx,xonotic-linux32-dedicated,xonotic-linux32-glx,xonotic-linux32-sdl,xonotic-linux64-dedicated,xonotic-linux64-glx,xonotic-linux64-sdl,xonotic-sdl private-dev -private-etc asound.conf,ca-certificates,drirc,fonts,group,host.conf,hostname,hosts,ld.so.cache,ld.so.preload,localtime,nsswitch.conf,passwd,pulse,resolv.conf,ssl +# private-etc breaks audio on some distros +#private-etc asound.conf,ca-certificates,drirc,fonts,group,host.conf,hostname,hosts,ld.so.cache,ld.so.preload,localtime,nsswitch.conf,passwd,pulse,resolv.conf,ssl private-tmp noexec ${HOME} -- cgit v1.2.3-54-g00ecf