From 94a0123568785386f907cd0fef7d5fc80ffb7d75 Mon Sep 17 00:00:00 2001 From: Tad Date: Tue, 24 Jul 2018 08:43:40 -0400 Subject: Initial adding of disable-xdg.inc --- etc/2048-qt.profile | 5 +++++ etc/Fritzing.profile | 2 ++ etc/android-studio.profile | 2 ++ etc/aosp.profile | 1 + etc/apktool.profile | 1 + etc/arch-audit.profile | 1 + etc/archaudit-report.profile | 1 + etc/disable-xdg.inc | 2 +- etc/gnome-books.profile | 2 ++ etc/gnome-calculator.profile | 1 + etc/gnome-chess.profile | 1 + etc/gnome-clocks.profile | 1 + etc/gnome-contacts.profile | 3 ++- etc/gnome-documents.profile | 2 ++ etc/gnome-font-viewer.profile | 1 + etc/gnome-logs.profile | 1 + etc/gnome-maps.profile | 1 + etc/gnome-weather.profile | 1 + 18 files changed, 27 insertions(+), 2 deletions(-) diff --git a/etc/2048-qt.profile b/etc/2048-qt.profile index 2e74e74e3..1e7472bd9 100644 --- a/etc/2048-qt.profile +++ b/etc/2048-qt.profile @@ -14,6 +14,11 @@ include /etc/firejail/disable-interpreters.inc include /etc/firejail/disable-passwdmgr.inc include /etc/firejail/disable-programs.inc +mkdir ${HOME}/.config/2048-qt +mkdir ${HOME}/.config/xiaoyong +whitelist ${HOME}/.config/2048-qt +whitelist ${HOME}/.config/xiaoyong +include /etc/firejail/whitelist-common.inc include /etc/firejail/whitelist-var-common.inc caps.drop all diff --git a/etc/Fritzing.profile b/etc/Fritzing.profile index 453b9979e..1eb103b47 100644 --- a/etc/Fritzing.profile +++ b/etc/Fritzing.profile @@ -6,12 +6,14 @@ include /etc/firejail/Fritzing.local include /etc/firejail/globals.local noblacklist ${HOME}/.config/Fritzing +noblacklist ${DOCUMENTS} include /etc/firejail/disable-common.inc include /etc/firejail/disable-devel.inc include /etc/firejail/disable-interpreters.inc include /etc/firejail/disable-passwdmgr.inc include /etc/firejail/disable-programs.inc +include /etc/firejail/disable-xdg.inc include /etc/firejail/whitelist-var-common.inc diff --git a/etc/android-studio.profile b/etc/android-studio.profile index d845bd4b9..a69bf3966 100644 --- a/etc/android-studio.profile +++ b/etc/android-studio.profile @@ -15,10 +15,12 @@ noblacklist ${HOME}/.java noblacklist ${HOME}/.local/share/JetBrains noblacklist ${HOME}/.ssh noblacklist ${HOME}/.tooling +noblacklist ${DOCUMENTS} include /etc/firejail/disable-common.inc include /etc/firejail/disable-passwdmgr.inc include /etc/firejail/disable-programs.inc +include /etc/firejail/disable-xdg.inc caps.drop all netfilter diff --git a/etc/aosp.profile b/etc/aosp.profile index 5ceef9348..8622d6acd 100644 --- a/etc/aosp.profile +++ b/etc/aosp.profile @@ -21,6 +21,7 @@ noblacklist ${HOME}/.tooling include /etc/firejail/disable-common.inc include /etc/firejail/disable-passwdmgr.inc include /etc/firejail/disable-programs.inc +include /etc/firejail/disable-xdg.inc include /etc/firejail/whitelist-var-common.inc diff --git a/etc/apktool.profile b/etc/apktool.profile index ded17ca58..2203d7b8c 100644 --- a/etc/apktool.profile +++ b/etc/apktool.profile @@ -9,6 +9,7 @@ include /etc/firejail/globals.local include /etc/firejail/disable-common.inc include /etc/firejail/disable-passwdmgr.inc include /etc/firejail/disable-programs.inc +include /etc/firejail/disable-xdg.inc caps.drop all net none diff --git a/etc/arch-audit.profile b/etc/arch-audit.profile index 0987ce149..956f0d63a 100644 --- a/etc/arch-audit.profile +++ b/etc/arch-audit.profile @@ -14,6 +14,7 @@ include /etc/firejail/disable-devel.inc include /etc/firejail/disable-interpreters.inc include /etc/firejail/disable-passwdmgr.inc include /etc/firejail/disable-programs.inc +include /etc/firejail/disable-xdg.inc caps.drop all ipc-namespace diff --git a/etc/archaudit-report.profile b/etc/archaudit-report.profile index f4340faf3..27b15412f 100644 --- a/etc/archaudit-report.profile +++ b/etc/archaudit-report.profile @@ -14,6 +14,7 @@ include /etc/firejail/disable-devel.inc include /etc/firejail/disable-interpreters.inc include /etc/firejail/disable-passwdmgr.inc include /etc/firejail/disable-programs.inc +include /etc/firejail/disable-xdg.inc include /etc/firejail/whitelist-common.inc diff --git a/etc/disable-xdg.inc b/etc/disable-xdg.inc index 5d29fa8d3..554e3a7d5 100644 --- a/etc/disable-xdg.inc +++ b/etc/disable-xdg.inc @@ -4,7 +4,7 @@ include /etc/firejail/disable-xdg.local #blacklist ${DESKTOP} blacklist ${DOCUMENTS} -blacklist ${DOWNLOADS} +#blacklist ${DOWNLOADS} blacklist ${MUSIC} blacklist ${PICTURES} blacklist ${VIDEOS} diff --git a/etc/gnome-books.profile b/etc/gnome-books.profile index 4274981b5..6fc2671d8 100644 --- a/etc/gnome-books.profile +++ b/etc/gnome-books.profile @@ -8,12 +8,14 @@ include /etc/firejail/globals.local # when gjs apps are started via gnome-shell, firejail is not applied because systemd will start them noblacklist ${HOME}/.cache/org.gnome.Books +noblacklist ${DOCUMENTS} include /etc/firejail/disable-common.inc include /etc/firejail/disable-devel.inc include /etc/firejail/disable-interpreters.inc include /etc/firejail/disable-passwdmgr.inc include /etc/firejail/disable-programs.inc +include /etc/firejail/disable-xdg.inc include /etc/firejail/whitelist-var-common.inc diff --git a/etc/gnome-calculator.profile b/etc/gnome-calculator.profile index b915b0bce..6ace0b3ec 100644 --- a/etc/gnome-calculator.profile +++ b/etc/gnome-calculator.profile @@ -11,6 +11,7 @@ include /etc/firejail/disable-devel.inc include /etc/firejail/disable-passwdmgr.inc include /etc/firejail/disable-interpreters.inc include /etc/firejail/disable-programs.inc +include /etc/firejail/disable-xdg.inc include /etc/firejail/whitelist-common.inc include /etc/firejail/whitelist-var-common.inc diff --git a/etc/gnome-chess.profile b/etc/gnome-chess.profile index 59a3d59af..8422e1836 100644 --- a/etc/gnome-chess.profile +++ b/etc/gnome-chess.profile @@ -12,6 +12,7 @@ include /etc/firejail/disable-devel.inc include /etc/firejail/disable-interpreters.inc include /etc/firejail/disable-passwdmgr.inc include /etc/firejail/disable-programs.inc +include /etc/firejail/disable-xdg.inc include /etc/firejail/whitelist-var-common.inc diff --git a/etc/gnome-clocks.profile b/etc/gnome-clocks.profile index 103a5ff73..4251f70ed 100644 --- a/etc/gnome-clocks.profile +++ b/etc/gnome-clocks.profile @@ -11,6 +11,7 @@ include /etc/firejail/disable-devel.inc include /etc/firejail/disable-interpreters.inc include /etc/firejail/disable-passwdmgr.inc include /etc/firejail/disable-programs.inc +include /etc/firejail/disable-xdg.inc include /etc/firejail/whitelist-var-common.inc diff --git a/etc/gnome-contacts.profile b/etc/gnome-contacts.profile index d4d670998..0e6f70e04 100644 --- a/etc/gnome-contacts.profile +++ b/etc/gnome-contacts.profile @@ -5,15 +5,16 @@ include /etc/firejail/gnome-contacts.local # Persistent global definitions include /etc/firejail/globals.local +noblacklist ${DOCUMENTS} include /etc/firejail/disable-common.inc include /etc/firejail/disable-devel.inc include /etc/firejail/disable-interpreters.inc include /etc/firejail/disable-passwdmgr.inc include /etc/firejail/disable-programs.inc +include /etc/firejail/disable-xdg.inc include /etc/firejail/whitelist-common.inc - include /etc/firejail/whitelist-var-common.inc caps.drop all diff --git a/etc/gnome-documents.profile b/etc/gnome-documents.profile index 8a67d6e5c..a7ebb48c8 100644 --- a/etc/gnome-documents.profile +++ b/etc/gnome-documents.profile @@ -8,12 +8,14 @@ include /etc/firejail/globals.local # when gjs apps are started via gnome-shell, firejail is not applied because systemd will start them noblacklist ${HOME}/.config/libreoffice +noblacklist ${DOCUMENTS} include /etc/firejail/disable-common.inc include /etc/firejail/disable-devel.inc include /etc/firejail/disable-interpreters.inc include /etc/firejail/disable-passwdmgr.inc include /etc/firejail/disable-programs.inc +include /etc/firejail/disable-xdg.inc caps.drop all netfilter diff --git a/etc/gnome-font-viewer.profile b/etc/gnome-font-viewer.profile index ebd937f9b..71cd06643 100644 --- a/etc/gnome-font-viewer.profile +++ b/etc/gnome-font-viewer.profile @@ -11,6 +11,7 @@ include /etc/firejail/disable-devel.inc include /etc/firejail/disable-interpreters.inc include /etc/firejail/disable-passwdmgr.inc include /etc/firejail/disable-programs.inc +include /etc/firejail/disable-xdg.inc include /etc/firejail/whitelist-var-common.inc diff --git a/etc/gnome-logs.profile b/etc/gnome-logs.profile index ca4e5f204..f08142113 100644 --- a/etc/gnome-logs.profile +++ b/etc/gnome-logs.profile @@ -10,6 +10,7 @@ include /etc/firejail/disable-devel.inc include /etc/firejail/disable-interpreters.inc include /etc/firejail/disable-passwdmgr.inc include /etc/firejail/disable-programs.inc +include /etc/firejail/disable-xdg.inc whitelist /var/log/journal include /etc/firejail/whitelist-var-common.inc diff --git a/etc/gnome-maps.profile b/etc/gnome-maps.profile index b5364e48d..da73d9450 100644 --- a/etc/gnome-maps.profile +++ b/etc/gnome-maps.profile @@ -14,6 +14,7 @@ include /etc/firejail/disable-devel.inc include /etc/firejail/disable-interpreters.inc include /etc/firejail/disable-passwdmgr.inc include /etc/firejail/disable-programs.inc +include /etc/firejail/disable-xdg.inc include /etc/firejail/whitelist-var-common.inc diff --git a/etc/gnome-weather.profile b/etc/gnome-weather.profile index 64482b246..28c9e6d86 100644 --- a/etc/gnome-weather.profile +++ b/etc/gnome-weather.profile @@ -14,6 +14,7 @@ include /etc/firejail/disable-devel.inc include /etc/firejail/disable-interpreters.inc include /etc/firejail/disable-passwdmgr.inc include /etc/firejail/disable-programs.inc +include /etc/firejail/disable-xdg.inc include /etc/firejail/whitelist-var-common.inc -- cgit v1.2.3-70-g09d2