From d69e0cf1b35cac9185081bd6d95d82024868ae76 Mon Sep 17 00:00:00 2001 From: smitsohu Date: Sun, 4 Nov 2018 19:22:15 +0100 Subject: profile fixes for recursive read-write mounts read-write and read-only are applied in sequence, don't override read-only restrictions in ~/.local/share issue #2200 --- etc/baloo_file.profile | 10 +++++----- etc/disable-common.inc | 10 +++++----- 2 files changed, 10 insertions(+), 10 deletions(-) (limited to 'etc') diff --git a/etc/baloo_file.profile b/etc/baloo_file.profile index 307a16f9c..e094945b7 100644 --- a/etc/baloo_file.profile +++ b/etc/baloo_file.profile @@ -5,6 +5,11 @@ include baloo_file.local # Persistent global definitions include globals.local +# Make home directory read-only and allow writing only to ${HOME}/.local/share +# Note: Baloo will not be able to update the "first run" key in its configuration files. +# read-only ${HOME} +# read-write ${HOME}/.local/share + noblacklist ${HOME}/.config/baloofilerc noblacklist ${HOME}/.kde/share/config/baloofilerc noblacklist ${HOME}/.kde/share/config/baloorc @@ -42,8 +47,3 @@ private-tmp noexec ${HOME} noexec /tmp - -# Make home directory read-only and allow writing only to ${HOME}/.local/share -# Note: Baloo will not be able to update the "first run" key in its configuration files. -# read-only ${HOME} -# read-write ${HOME}/.local/share diff --git a/etc/disable-common.inc b/etc/disable-common.inc index b78af7917..d220f381b 100644 --- a/etc/disable-common.inc +++ b/etc/disable-common.inc @@ -2,6 +2,11 @@ # Persistent customizations should go in a .local file. include disable-common.local +# The following block breaks trash functionality in file managers +#read-only ${HOME}/.local +#read-write ${HOME}/.local/share +blacklist ${HOME}/.local/share/Trash + # History files in $HOME and clipboard managers blacklist-nolog ${HOME}/.*_history blacklist-nolog ${HOME}/.adobe @@ -263,11 +268,6 @@ read-only ${HOME}/.luarocks read-only ${HOME}/.npm-packages read-only ${HOME}/bin -# The following block breaks trash functionality in file managers -#read-only ${HOME}/.local -#read-write ${HOME}/.local/share -blacklist ${HOME}/.local/share/Trash - # Write-protection for desktop entries read-only ${HOME}/.config/menus read-only ${HOME}/.local/share/applications -- cgit v1.2.3-54-g00ecf