From 347dbc8cff7f0e17445cd547268455a09cba1f16 Mon Sep 17 00:00:00 2001 From: netblue30 Date: Wed, 11 Nov 2015 08:08:11 -0500 Subject: added whitelist-common.inc --- etc/chromium.profile | 7 +------ etc/firefox.profile | 11 +---------- etc/spotify.profile | 7 +------ etc/whitelist-common.inc | 13 +++++++++++++ 4 files changed, 16 insertions(+), 22 deletions(-) create mode 100644 etc/whitelist-common.inc (limited to 'etc') diff --git a/etc/chromium.profile b/etc/chromium.profile index 077ec62d0..980e539d5 100644 --- a/etc/chromium.profile +++ b/etc/chromium.profile @@ -12,10 +12,5 @@ netfilter whitelist ~/Downloads whitelist ~/Загрузки whitelist ~/.config/chromium +include /etc/firejail/whitelist-common.inc -# common -whitelist ~/.fonts -whitelist ~/.fonts.d -whitelist ~/.fontconfig -whitelist ~/.fonts.conf -whitelist ~/.fonts.conf.d diff --git a/etc/firefox.profile b/etc/firefox.profile index 954068d47..809363fd6 100644 --- a/etc/firefox.profile +++ b/etc/firefox.profile @@ -15,17 +15,8 @@ whitelist ~/Загрузки whitelist ~/dwhelper whitelist ~/.zotero whitelist ~/.lastpass -whitelist ~/.gtkrc-2.0 -whitelist ~/.config/gtk-3.0 -whitelist ~/.themes/ whitelist ~/.vimperatorrc whitelist ~/.vimperator whitelist ~/.pentadactylrc whitelist ~/.pentadactyl - -# common -whitelist ~/.fonts -whitelist ~/.fonts.d -whitelist ~/.fontconfig -whitelist ~/.fonts.conf -whitelist ~/.fonts.conf.d +include /etc/firejail/whitelist-common.inc \ No newline at end of file diff --git a/etc/spotify.profile b/etc/spotify.profile index f77f900cf..414660857 100644 --- a/etc/spotify.profile +++ b/etc/spotify.profile @@ -10,6 +10,7 @@ include /etc/firejail/disable-devel.inc whitelist ${HOME}/.config/spotify whitelist ${HOME}/.local/share/spotify whitelist ${HOME}/.cache/spotify +include /etc/firejail/whitelist-common.inc caps.drop all seccomp @@ -17,9 +18,3 @@ protocol unix,inet,inet6 netfilter noroot -# common -whitelist ~/.fonts -whitelist ~/.fonts.d -whitelist ~/.fontconfig -whitelist ~/.fonts.conf -whitelist ~/.fonts.conf.d diff --git a/etc/whitelist-common.inc b/etc/whitelist-common.inc new file mode 100644 index 000000000..e0c2975df --- /dev/null +++ b/etc/whitelist-common.inc @@ -0,0 +1,13 @@ +# common whitelist for all profiles + +# fonts +whitelist ~/.fonts +whitelist ~/.fonts.d +whitelist ~/.fontconfig +whitelist ~/.fonts.conf +whitelist ~/.fonts.conf.d + +# gtk +whitelist ~/.gtkrc-2.0 +whitelist ~/.config/gtk-3.0 +whitelist ~/.themes/ -- cgit v1.2.3-70-g09d2