From ba85fa81088a0b468f3fb98d96b535f8d07989c8 Mon Sep 17 00:00:00 2001 From: SYN-cook Date: Fri, 31 Mar 2017 16:24:38 +0200 Subject: tidy up (#1182) * minor reorganization * tidy up * tidy up * tidy up * tidy up * tidy up * tidy up --- etc/disable-common.inc | 11 +++++++---- 1 file changed, 7 insertions(+), 4 deletions(-) (limited to 'etc/disable-common.inc') diff --git a/etc/disable-common.inc b/etc/disable-common.inc index 0ada3314f..451203865 100644 --- a/etc/disable-common.inc +++ b/etc/disable-common.inc @@ -6,11 +6,8 @@ include /etc/firejail/disable-common.local blacklist-nolog ${HOME}/.history blacklist-nolog ${HOME}/.*_history blacklist-nolog ${HOME}/.bash_history -blacklist ${HOME}/.local/share/systemd -blacklist ${HOME}/.config/systemd blacklist-nolog ${HOME}/.adobe blacklist-nolog ${HOME}/.macromedia -read-only ${HOME}/.local/share/applications # X11 session autostart blacklist ${HOME}/.xinitrc @@ -74,6 +71,10 @@ blacklist ${HOME}/.local/share/kservices5 blacklist ${HOME}/.local/share/plasma blacklist ${HOME}/.local/share/solid +# systemd +blacklist ${HOME}/.local/share/systemd +blacklist ${HOME}/.config/systemd + # VirtualBox blacklist ${HOME}/.VirtualBox blacklist ${HOME}/VirtualBox VMs @@ -177,9 +178,11 @@ read-only ${HOME}/.luarocks read-only ${HOME}/.npm-packages # Make the contents of ~/.local read-only, -# except the commonly-used ~/.local/share +# except the commonly-used ~/.local/share, +# but including ~/.local/share/applications read-only ${HOME}/.local read-write ${HOME}/.local/share +read-only ${HOME}/.local/share/applications # top secret blacklist ${HOME}/.ecryptfs -- cgit v1.2.3-70-g09d2