From 925ff6fecd88bd75735f7b4218a262860904269b Mon Sep 17 00:00:00 2001 From: rusty-snake <41237666+rusty-snake@users.noreply.github.com> Date: Mon, 9 Aug 2021 08:50:53 +0200 Subject: Correct directory for sway.profile and io.github.lainsce.Notejot.profile --- etc/profile-a-l/io.github.lainsce.Notejot.profile | 61 +++++++++++++++++++++++ etc/profile-a-l/sway.profile | 19 ------- etc/profile-m-z/io.github.lainsce.Notejot.profile | 61 ----------------------- etc/profile-m-z/sway.profile | 19 +++++++ 4 files changed, 80 insertions(+), 80 deletions(-) create mode 100644 etc/profile-a-l/io.github.lainsce.Notejot.profile delete mode 100644 etc/profile-a-l/sway.profile delete mode 100644 etc/profile-m-z/io.github.lainsce.Notejot.profile create mode 100644 etc/profile-m-z/sway.profile (limited to 'etc') diff --git a/etc/profile-a-l/io.github.lainsce.Notejot.profile b/etc/profile-a-l/io.github.lainsce.Notejot.profile new file mode 100644 index 000000000..afd5d44a4 --- /dev/null +++ b/etc/profile-a-l/io.github.lainsce.Notejot.profile @@ -0,0 +1,61 @@ +# Firejail profile for notejot +# Description: Jot your ideas +# This file is overwritten after every install/update +# Persistent local customizations +include io.github.lainsce.Notejot.local +# Persistent global definitions +include globals.local + +noblacklist ${HOME}/.cache/io.github.lainsce.Notejot +noblacklist ${HOME}/.local/share/io.github.lainsce.Notejot + +include disable-common.inc +include disable-devel.inc +include disable-exec.inc +include disable-interpreters.inc +include disable-passwdmgr.inc +include disable-programs.inc +include disable-shell.inc +include disable-xdg.inc + +mkdir ${HOME}/.cache/io.github.lainsce.Notejot +mkdir ${HOME}/.local/share/io.github.lainsce.Notejot +whitelist ${HOME}/.cache/io.github.lainsce.Notejot +whitelist ${HOME}/.local/share/io.github.lainsce.Notejot +whitelist /usr/libexec/webkit2gtk-4.0 +include whitelist-common.inc +include whitelist-runuser-common.inc +include whitelist-usr-share-common.inc +include whitelist-var-common.inc + +apparmor +caps.drop all +machine-id +net none +no3d +nodvd +nogroups +noinput +nonewprivs +noroot +nosound +notv +nou2f +novideo +protocol unix +seccomp +seccomp.block-secondary +shell none +tracelog + +disable-mnt +private-bin io.github.lainsce.Notejot +private-cache +private-dev +private-etc alternatives,dconf,fonts,gtk-3.0,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,pango,X11 +private-tmp + +dbus-user filter +dbus-user.own io.github.lainsce.Notejot +dbus-user.talk ca.desrt.dconf +dbus-system none diff --git a/etc/profile-a-l/sway.profile b/etc/profile-a-l/sway.profile deleted file mode 100644 index 4637419bf..000000000 --- a/etc/profile-a-l/sway.profile +++ /dev/null @@ -1,19 +0,0 @@ -# Firejail profile for Sway -# Description: i3-compatible Wayland compositor -# This file is overwritten after every install/update -# Persistent local customizations -include sway.local -# Persistent global definitions -include globals.local - -# all applications started in sway will run in this profile -noblacklist ${HOME}/.config/sway -# sway uses ~/.config/i3 as fallback if there is no ~/.config/sway -noblacklist ${HOME}/.config/i3 -include disable-common.inc - -caps.drop all -netfilter -noroot -protocol unix,inet,inet6 -seccomp diff --git a/etc/profile-m-z/io.github.lainsce.Notejot.profile b/etc/profile-m-z/io.github.lainsce.Notejot.profile deleted file mode 100644 index afd5d44a4..000000000 --- a/etc/profile-m-z/io.github.lainsce.Notejot.profile +++ /dev/null @@ -1,61 +0,0 @@ -# Firejail profile for notejot -# Description: Jot your ideas -# This file is overwritten after every install/update -# Persistent local customizations -include io.github.lainsce.Notejot.local -# Persistent global definitions -include globals.local - -noblacklist ${HOME}/.cache/io.github.lainsce.Notejot -noblacklist ${HOME}/.local/share/io.github.lainsce.Notejot - -include disable-common.inc -include disable-devel.inc -include disable-exec.inc -include disable-interpreters.inc -include disable-passwdmgr.inc -include disable-programs.inc -include disable-shell.inc -include disable-xdg.inc - -mkdir ${HOME}/.cache/io.github.lainsce.Notejot -mkdir ${HOME}/.local/share/io.github.lainsce.Notejot -whitelist ${HOME}/.cache/io.github.lainsce.Notejot -whitelist ${HOME}/.local/share/io.github.lainsce.Notejot -whitelist /usr/libexec/webkit2gtk-4.0 -include whitelist-common.inc -include whitelist-runuser-common.inc -include whitelist-usr-share-common.inc -include whitelist-var-common.inc - -apparmor -caps.drop all -machine-id -net none -no3d -nodvd -nogroups -noinput -nonewprivs -noroot -nosound -notv -nou2f -novideo -protocol unix -seccomp -seccomp.block-secondary -shell none -tracelog - -disable-mnt -private-bin io.github.lainsce.Notejot -private-cache -private-dev -private-etc alternatives,dconf,fonts,gtk-3.0,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,pango,X11 -private-tmp - -dbus-user filter -dbus-user.own io.github.lainsce.Notejot -dbus-user.talk ca.desrt.dconf -dbus-system none diff --git a/etc/profile-m-z/sway.profile b/etc/profile-m-z/sway.profile new file mode 100644 index 000000000..4637419bf --- /dev/null +++ b/etc/profile-m-z/sway.profile @@ -0,0 +1,19 @@ +# Firejail profile for Sway +# Description: i3-compatible Wayland compositor +# This file is overwritten after every install/update +# Persistent local customizations +include sway.local +# Persistent global definitions +include globals.local + +# all applications started in sway will run in this profile +noblacklist ${HOME}/.config/sway +# sway uses ~/.config/i3 as fallback if there is no ~/.config/sway +noblacklist ${HOME}/.config/i3 +include disable-common.inc + +caps.drop all +netfilter +noroot +protocol unix,inet,inet6 +seccomp -- cgit v1.2.3-70-g09d2