From 096d0de5f8bb253d0c1035796464bc5982f06f81 Mon Sep 17 00:00:00 2001 From: rusty-snake <41237666+rusty-snake@users.noreply.github.com> Date: Mon, 16 Nov 2020 11:41:35 +0100 Subject: from my overrides - add seccomp.block-secondary to a lot profiles - add wruc to firefox-common and ignore it in TB and firefox-common-addons - harden dia, gnome-keyring, libreoffice, megaglest, pngquant, ghostwriter, rhythmbox, sqlitebrowser --- etc/profile-a-l/dia.profile | 13 +++++++++++-- 1 file changed, 11 insertions(+), 2 deletions(-) (limited to 'etc/profile-a-l/dia.profile') diff --git a/etc/profile-a-l/dia.profile b/etc/profile-a-l/dia.profile index 52bf1c7f8..e409eb044 100644 --- a/etc/profile-a-l/dia.profile +++ b/etc/profile-a-l/dia.profile @@ -9,16 +9,24 @@ include globals.local noblacklist ${HOME}/.dia noblacklist ${DOCUMENTS} +include allow-python2.inc +include allow-python3.inc + include disable-common.inc include disable-devel.inc include disable-exec.inc -include allow-python2.inc -include allow-python3.inc include disable-interpreters.inc include disable-passwdmgr.inc include disable-programs.inc include disable-xdg.inc +#mkdir ${HOME}/.dia +#whitelist ${HOME}/.dia +#whitelist ${DOCUMENTS} +#include whitelist-common.inc +whitelist /usr/share/dia +include whitelist-runuser-common.inc +include whitelist-usr-share-common.inc include whitelist-var-common.inc apparmor @@ -36,6 +44,7 @@ novideo protocol unix seccomp shell none +tracelog disable-mnt #private-bin dia -- cgit v1.2.3-54-g00ecf