From fe0f975f447d59977d90c3226cc8c623b31b20b3 Mon Sep 17 00:00:00 2001 From: netblue30 Date: Mon, 5 Jul 2021 07:23:31 -0400 Subject: move whitelist/blacklist to allow/deny --- etc/profile-a-l/brave.profile | 22 +++++++++++----------- 1 file changed, 11 insertions(+), 11 deletions(-) (limited to 'etc/profile-a-l/brave.profile') diff --git a/etc/profile-a-l/brave.profile b/etc/profile-a-l/brave.profile index 09548c761..bc2d7a6a1 100644 --- a/etc/profile-a-l/brave.profile +++ b/etc/profile-a-l/brave.profile @@ -14,24 +14,24 @@ ignore noexec /tmp # Alternatively you can add 'ignore apparmor' to your brave.local. ignore noexec ${HOME} -noblacklist ${HOME}/.cache/BraveSoftware -noblacklist ${HOME}/.config/BraveSoftware -noblacklist ${HOME}/.config/brave -noblacklist ${HOME}/.config/brave-flags.conf +nodeny ${HOME}/.cache/BraveSoftware +nodeny ${HOME}/.config/BraveSoftware +nodeny ${HOME}/.config/brave +nodeny ${HOME}/.config/brave-flags.conf # brave uses gpg for built-in password manager -noblacklist ${HOME}/.gnupg +nodeny ${HOME}/.gnupg mkdir ${HOME}/.cache/BraveSoftware mkdir ${HOME}/.config/BraveSoftware mkdir ${HOME}/.config/brave -whitelist ${HOME}/.cache/BraveSoftware -whitelist ${HOME}/.config/BraveSoftware -whitelist ${HOME}/.config/brave -whitelist ${HOME}/.config/brave-flags.conf -whitelist ${HOME}/.gnupg +allow ${HOME}/.cache/BraveSoftware +allow ${HOME}/.config/BraveSoftware +allow ${HOME}/.config/brave +allow ${HOME}/.config/brave-flags.conf +allow ${HOME}/.gnupg # Brave sandbox needs read access to /proc/config.gz -noblacklist /proc/config.gz +nodeny /proc/config.gz # Redirect include chromium-common.profile -- cgit v1.2.3-70-g09d2