From d46c4e73075c6a63694d694c3d4593dee94dcc19 Mon Sep 17 00:00:00 2001 From: Neo00001 <40570803+Neo00001@users.noreply.github.com> Date: Sun, 24 Jan 2021 10:42:32 +0000 Subject: Update disable-programs.inc --- etc/inc/disable-programs.inc | 2 ++ 1 file changed, 2 insertions(+) diff --git a/etc/inc/disable-programs.inc b/etc/inc/disable-programs.inc index 1d1de6044..d24713fe5 100644 --- a/etc/inc/disable-programs.inc +++ b/etc/inc/disable-programs.inc @@ -275,6 +275,8 @@ blacklist ${HOME}/.config/katevirc blacklist ${HOME}/.config/kazam blacklist ${HOME}/.config/kdeconnect blacklist ${HOME}/.config/kdenliverc +blacklist ${HOME}/.config/kdiff3fileitemactionrc +blacklist ${HOME}/.config/kdiff3rc blacklist ${HOME}/.config/kfindrc blacklist ${HOME}/.config/kgetrc blacklist ${HOME}/.config/kid3rc -- cgit v1.2.3-54-g00ecf From c6bb292ad141647ec13211c3e717588ec87bf141 Mon Sep 17 00:00:00 2001 From: Neo00001 <40570803+Neo00001@users.noreply.github.com> Date: Sun, 24 Jan 2021 10:45:54 +0000 Subject: Update firecfg.config --- src/firecfg/firecfg.config | 1 + 1 file changed, 1 insertion(+) diff --git a/src/firecfg/firecfg.config b/src/firecfg/firecfg.config index 109f89f39..d6fcdb38f 100644 --- a/src/firecfg/firecfg.config +++ b/src/firecfg/firecfg.config @@ -390,6 +390,7 @@ kazam kcalc # kdeinit4 kdenlive +kdiff3 keepass keepass2 keepassx -- cgit v1.2.3-54-g00ecf From 60566656eeaca17360996a705a84565ee0138410 Mon Sep 17 00:00:00 2001 From: Neo00001 <40570803+Neo00001@users.noreply.github.com> Date: Sun, 24 Jan 2021 10:48:55 +0000 Subject: Create kdiff3.profile --- etc/profile-a-l/kdiff3.profile | 43 ++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 43 insertions(+) create mode 100644 etc/profile-a-l/kdiff3.profile diff --git a/etc/profile-a-l/kdiff3.profile b/etc/profile-a-l/kdiff3.profile new file mode 100644 index 000000000..a5012d1ad --- /dev/null +++ b/etc/profile-a-l/kdiff3.profile @@ -0,0 +1,43 @@ +# Firejail profile for kdiff3 +# Description: KDiff3 is a file and folder diff and merge tool. +# This file is overwritten after every install/update +# Persistent local customizations +include kdiff3.local +# Persistent global definitions +include globals.local + +noblacklist ${HOME}/.config/kdiff3fileitemactionrc +noblacklist ${HOME}/.config/kdiff3rc + +include disable-common.inc +include disable-devel.inc +include disable-exec.inc +include disable-interpreters.inc +include disable-passwdmgr.inc +include disable-programs.inc +include disable-shell.inc +include disable-xdg.inc + +include whitelist-runuser-common.inc +include whitelist-usr-share-common.inc +include whitelist-var-common.inc + +apparmor +caps.drop all +machine-id +net none +nodvd +nogroups +nonewprivs +noroot +nosound +notv +nou2f +novideo +seccomp +shell none + +disable-mnt +private-bin kdiff3 +private-cache +private-dev -- cgit v1.2.3-54-g00ecf From 7d373bdc585cd9abb5f4464993f1d56cb5972b6a Mon Sep 17 00:00:00 2001 From: Neo00001 <40570803+Neo00001@users.noreply.github.com> Date: Sun, 24 Jan 2021 17:37:46 +0000 Subject: Update kdiff3.profile --- etc/profile-a-l/kdiff3.profile | 19 ++++++++++++++----- 1 file changed, 14 insertions(+), 5 deletions(-) diff --git a/etc/profile-a-l/kdiff3.profile b/etc/profile-a-l/kdiff3.profile index a5012d1ad..8290e07f2 100644 --- a/etc/profile-a-l/kdiff3.profile +++ b/etc/profile-a-l/kdiff3.profile @@ -9,18 +9,22 @@ include globals.local noblacklist ${HOME}/.config/kdiff3fileitemactionrc noblacklist ${HOME}/.config/kdiff3rc -include disable-common.inc +# Uncomment the next line (or put it into your kdiff3.local) if you don't need to compare files in disable-common.inc. +#include disable-common.inc include disable-devel.inc include disable-exec.inc include disable-interpreters.inc include disable-passwdmgr.inc -include disable-programs.inc +# Uncomment the next line (or put it into your kdiff3.local) if you don't need to compare files in disable-programs.inc. +#include disable-programs.inc include disable-shell.inc include disable-xdg.inc - + include whitelist-runuser-common.inc -include whitelist-usr-share-common.inc -include whitelist-var-common.inc +# Uncomment the next lines (or put it into your kdiff3.local) if you don't need to compare files in /usr/share. +#include whitelist-usr-share-common.inc +# Uncomment the next line (or put it into your kdiff3.local) if you don't need to compare files in /var. +#include whitelist-var-common.inc apparmor caps.drop all @@ -35,9 +39,14 @@ notv nou2f novideo seccomp +seccomp.block-secondary shell none +tracelog disable-mnt private-bin kdiff3 private-cache private-dev + +dbus-user none +dbus-system none -- cgit v1.2.3-54-g00ecf