Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

profiles: safeguard single line comments #5950

Closed
wants to merge 86 commits into from
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
86 commits
Select commit Hold shift + click to select a range
eaa29cc
akonadi_control: safeguard single line comments
glitsj16 Aug 11, 2023
8e244f7
artha: safeguard single line comments
glitsj16 Aug 11, 2023
c74f8c3
atril: safeguard single line comments
glitsj16 Aug 11, 2023
12eec45
audio-recorder: safeguard single line comments
glitsj16 Aug 11, 2023
7b193f4
authenticator: safeguard single line comments
glitsj16 Aug 11, 2023
45caf53
autokey-common: safeguard single line comments
glitsj16 Aug 11, 2023
f1c2992
bcompare: safeguard single line comments
glitsj16 Aug 11, 2023
23b31f0
cameramonitor: safeguard single line comments
glitsj16 Aug 11, 2023
918fe78
chromium-common: safeguard single line comments
glitsj16 Aug 11, 2023
cd4f101
clac: safeguard single line comments
glitsj16 Aug 11, 2023
8d8811a
clawsker: safeguard single line comments
glitsj16 Aug 11, 2023
574d7d4
clipgrab: safeguard single line comments
glitsj16 Aug 11, 2023
c34ef18
dconf-editor: safeguard single line comments
glitsj16 Aug 11, 2023
1a6c79f
ddgtk: safeguard single line comments
glitsj16 Aug 11, 2023
3faeedd
devhelp: safeguard single line comments
glitsj16 Aug 11, 2023
d663a1d
d-feet: safeguard single line comments
glitsj16 Aug 11, 2023
d69e6bc
digikam: safeguard single line comments
glitsj16 Aug 11, 2023
9e974bb
dig: safeguard single line comments
glitsj16 Aug 11, 2023
9ff9daf
display: safeguard single line comments
glitsj16 Aug 11, 2023
a36ce1b
drawio: safeguard single line comments
glitsj16 Aug 11, 2023
215cb0c
enpass: safeguard single line comments
glitsj16 Aug 11, 2023
15a5005
evince: safeguard single line comments
glitsj16 Aug 11, 2023
31b9c06
Update ffmpeg.profile
glitsj16 Aug 11, 2023
0810f81
file-roller: safeguard single line comments
glitsj16 Aug 11, 2023
a408587
ffmpeg: safeguard single line comments
glitsj16 Aug 11, 2023
0f56518
filezilla: safeguard single line comments
glitsj16 Aug 11, 2023
a8631cc
firefox: safeguard single line comments
glitsj16 Aug 11, 2023
f77805f
font-manager: safeguard single line comments
glitsj16 Aug 11, 2023
a03c795
galculator: safeguard single line comments
glitsj16 Aug 11, 2023
1e09497
geary: safeguard single line comments
glitsj16 Aug 11, 2023
04ae077
gedit: safeguard single line comments
glitsj16 Aug 11, 2023
17ceac1
gmpc: safeguard single line comments
glitsj16 Aug 11, 2023
90e0928
gnome-contacts: safeguard single line comments
glitsj16 Aug 11, 2023
52adb41
gnome-pie: safeguard single line comments
glitsj16 Aug 11, 2023
9262221
gnome-schedule: safeguard single line comments
glitsj16 Aug 11, 2023
16c64b1
gnome-system-log: safeguard single line comments
glitsj16 Aug 11, 2023
13afcda
gucharmap: safeguard single line comments
glitsj16 Aug 11, 2023
b84093b
hexchat: safeguard single line comments
glitsj16 Aug 11, 2023
07e8271
inkscape: safeguard single line comments
glitsj16 Aug 11, 2023
621ab48
k3b: safeguard single line comments
glitsj16 Aug 11, 2023
86465c6
kcalc: safeguard single line comments
glitsj16 Aug 11, 2023
ff920f7
kdeinit4: safeguard single line comments
glitsj16 Aug 11, 2023
c2bd012
kfind: safeguard single line comments
glitsj16 Aug 11, 2023
3579add
kmail: safeguard single line comments
glitsj16 Aug 11, 2023
eb6c56e
ktorrent: safeguard single line comments
glitsj16 Aug 11, 2023
42eae2b
kwrite: safeguard single line comments
glitsj16 Aug 11, 2023
b4641c1
midori: safeguard single line comments
glitsj16 Aug 11, 2023
6d7cd24
mpDris2: safeguard single line comments
glitsj16 Aug 11, 2023
afde5d1
mplayer: safeguard single line comments
glitsj16 Aug 11, 2023
7d6d6b0
mpv: safeguard single line comments
glitsj16 Aug 11, 2023
937ca32
mullvad-browser: safeguard single line comments
glitsj16 Aug 11, 2023
a1f3b9b
mumble: safeguard single line comments
glitsj16 Aug 11, 2023
00d8529
noprofile: safeguard single line comments
glitsj16 Aug 11, 2023
a391b8e
notable: safeguard single line comments
glitsj16 Aug 11, 2023
4e327b7
okular: safeguard single line comments
glitsj16 Aug 11, 2023
7d003b5
onionshare-gui: safeguard single line comments
glitsj16 Aug 11, 2023
1c619c7
openclonk: safeguard single line comments
glitsj16 Aug 11, 2023
830404a
orage: safeguard single line comments
glitsj16 Aug 11, 2023
80d6cf3
parsecd: safeguard single line comments
glitsj16 Aug 11, 2023
1eecf30
PCSX2: safeguard single line comments
glitsj16 Aug 11, 2023
b9f1ce9
ping: safeguard single line comments
glitsj16 Aug 11, 2023
31510e4
pluma: safeguard single line comments
glitsj16 Aug 11, 2023
467c083
plv: safeguard single line comments
glitsj16 Aug 11, 2023
131b8fb
psi: safeguard single line comments
glitsj16 Aug 11, 2023
acf854e
pycharm-community: safeguard single line comments
glitsj16 Aug 11, 2023
8028666
qbittorrent: safeguard single line comments
glitsj16 Aug 11, 2023
3fcb9df
QMediathekView: safeguard single line comments
glitsj16 Aug 11, 2023
f9d5405
qtox: safeguard single line comments
glitsj16 Aug 11, 2023
3578913
sniffnet: safeguard single line comments
glitsj16 Aug 11, 2023
225a0bf
sqlitebrowser: safeguard single line comments
glitsj16 Aug 11, 2023
353fb06
ssh: safeguard single line comments
glitsj16 Aug 11, 2023
516bfad
subdownloader: safeguard single line comments
glitsj16 Aug 11, 2023
2293150
sysprof: safeguard single line comments
glitsj16 Aug 11, 2023
1251234
torbrowser-launcher: safeguard single line comments
glitsj16 Aug 11, 2023
8df94a3
totem: safeguard single line comments
glitsj16 Aug 11, 2023
48203fb
viewnior: safeguard single line comments
glitsj16 Aug 11, 2023
2bef220
warzone2100: safeguard single line comments
glitsj16 Aug 11, 2023
c3f1698
wireshark: safeguard single line comments
glitsj16 Aug 11, 2023
77a186c
xed: safeguard single line comments
glitsj16 Aug 11, 2023
1c86341
xfce4-mixer: safeguard single line comments
glitsj16 Aug 11, 2023
d01aee2
xplayer: safeguard single line comments
glitsj16 Aug 11, 2023
0ce1d9e
xviewer: safeguard single line comments
glitsj16 Aug 11, 2023
059a500
yelp: safeguard single line comments
glitsj16 Aug 11, 2023
c7e9a93
zeal: safeguard single line comments
glitsj16 Aug 11, 2023
97e4737
disable-common.inc: safeguard single line comments
glitsj16 Aug 11, 2023
664a39a
disable-devel.inc: safeguard single line comments
glitsj16 Aug 11, 2023
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
12 changes: 6 additions & 6 deletions etc/inc/disable-common.inc
Original file line number Diff line number Diff line change
Expand Up @@ -33,7 +33,7 @@ blacklist-nolog ${HOME}/.viminfo
blacklist-nolog /tmp/clipmenu*

# X11 session autostart
# blacklist ${HOME}/.xpra - this will kill --x11=xpra cmdline option for all programs
#blacklist ${HOME}/.xpra # this will kill --x11=xpra cmdline option for all programs
blacklist ${HOME}/.Xsession
blacklist ${HOME}/.blackbox
blacklist ${HOME}/.config/autostart
Expand Down Expand Up @@ -241,8 +241,9 @@ blacklist /var/lib/mysql/mysql.sock
blacklist /var/lib/mysqld/mysql.sock
blacklist /var/lib/pacman
blacklist /var/lib/upower
# blacklist /var/log - a virtual /var/log directory (mostly empty) is build up by default for
# every sandbox, unless --writable-var-log switch is activated
# A virtual /var/log directory (mostly empty) is build up by default for
# every sandbox, unless --writable-var-log switch is activated.
#blacklist /var/log
blacklist /var/mail
blacklist /var/opt
blacklist /var/run/acpid.socket
Expand Down Expand Up @@ -560,7 +561,7 @@ blacklist ${PATH}/bmon
blacklist ${PATH}/fping
blacklist ${PATH}/fping6
blacklist ${PATH}/hostname
# blacklist ${PATH}/ip - breaks --ip=dhcp
#blacklist ${PATH}/ip # breaks --ip=dhcp
blacklist ${PATH}/mtr
blacklist ${PATH}/mtr-packet
blacklist ${PATH}/netstat
Expand Down Expand Up @@ -588,8 +589,7 @@ blacklist /tmp/tmux-*
blacklist ${PATH}/gnome-terminal
blacklist ${PATH}/gnome-terminal.wrapper
blacklist ${PATH}/kgx
# blacklist ${PATH}/konsole
# konsole doesn't seem to have this problem - last tested on Ubuntu 16.04
#blacklist ${PATH}/konsole # doesn't seem to have this problem (last tested on Ubuntu 16.04)
blacklist ${PATH}/lilyterm
blacklist ${PATH}/lxterminal
blacklist ${PATH}/mate-terminal
Expand Down
6 changes: 2 additions & 4 deletions etc/inc/disable-devel.inc
Original file line number Diff line number Diff line change
Expand Up @@ -8,8 +8,7 @@ include disable-devel.local
blacklist ${PATH}/clang*
blacklist ${PATH}/lldb*
blacklist ${PATH}/llvm*
# see issue #2106 - it disables hardware acceleration in Firefox on Radeon GPU
# blacklist /usr/lib/llvm*
#blacklist /usr/lib/llvm* # breaks hardware acceleration in Firefox on Radeon GPU (see #2106)

# GCC
blacklist ${PATH}/as
Expand All @@ -26,8 +25,7 @@ blacklist ${PATH}/*-gcc*
blacklist ${PATH}/*-g++*
blacklist ${PATH}/*-gcc*
blacklist ${PATH}/*-g++*
# seems to create problems on Gentoo
#blacklist /usr/lib/gcc
#blacklist /usr/lib/gcc # seems to create problems on Gentoo

#Go
blacklist ${PATH}/gccgo
Expand Down
2 changes: 1 addition & 1 deletion etc/profile-a-l/akonadi_control.profile
Original file line number Diff line number Diff line change
Expand Up @@ -53,6 +53,6 @@ novideo
tracelog

private-dev
# private-tmp - breaks programs that depend on akonadi
# private-tmp # breaks programs that depend on akonadi

# restrict-namespaces
2 changes: 1 addition & 1 deletion etc/profile-a-l/artha.profile
Original file line number Diff line number Diff line change
Expand Up @@ -35,7 +35,7 @@ include whitelist-var-common.inc
apparmor
caps.drop all
ipc-namespace
# net none - breaks on Ubuntu
# net none # breaks on Ubuntu
no3d
nodvd
nogroups
Expand Down
2 changes: 1 addition & 1 deletion etc/profile-a-l/atril.profile
Original file line number Diff line number Diff line change
Expand Up @@ -44,7 +44,7 @@ private-dev
private-etc
# atril uses webkit gtk to display epub files
# waiting for globbing support in private-lib; for now hardcoding it to webkit2gtk-4.0
#private-lib webkit2gtk-4.0 - problems on Arch with the new version of WebKit
#private-lib webkit2gtk-4.0 # problems on Arch with the new version of WebKit
private-tmp

# webkit gtk killed by memory-deny-write-execute
Expand Down
2 changes: 1 addition & 1 deletion etc/profile-a-l/audio-recorder.profile
Original file line number Diff line number Diff line change
Expand Up @@ -50,5 +50,5 @@ dbus-user filter
dbus-user.talk ca.desrt.dconf
dbus-system none

# memory-deny-write-execute - breaks on Arch
# memory-deny-write-execute # breaks on Arch
restrict-namespaces
2 changes: 1 addition & 1 deletion etc/profile-a-l/authenticator.profile
Original file line number Diff line number Diff line change
Expand Up @@ -45,5 +45,5 @@ private-tmp
# dbus-user none
# dbus-system none

#memory-deny-write-execute - breaks on Arch (see issue #1803)
#memory-deny-write-execute # breaks on Arch (see issue #1803)
restrict-namespaces
2 changes: 1 addition & 1 deletion etc/profile-a-l/autokey-common.profile
Original file line number Diff line number Diff line change
Expand Up @@ -38,5 +38,5 @@ private-cache
private-dev
private-tmp

#memory-deny-write-execute - breaks on Arch (see issue #1803)
#memory-deny-write-execute # breaks on Arch (see issue #1803)
restrict-namespaces
2 changes: 1 addition & 1 deletion etc/profile-a-l/bcompare.profile
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,7 @@ include disable-exec.inc
include disable-interpreters.inc
# Add the next line to your bcompare.local if you don't need to compare files in disable-programs.inc.
#include disable-programs.inc
#include disable-shell.inc - breaks launch
#include disable-shell.inc # breaks launch
include disable-write-mnt.inc

apparmor
Expand Down
2 changes: 1 addition & 1 deletion etc/profile-a-l/cameramonitor.profile
Original file line number Diff line number Diff line change
Expand Up @@ -51,5 +51,5 @@ private-tmp
# dbus-user none
# dbus-system none

# memory-deny-write-execute - breaks on Arch
# memory-deny-write-execute # breaks on Arch
restrict-namespaces
4 changes: 2 additions & 2 deletions etc/profile-a-l/chromium-common.profile
Original file line number Diff line number Diff line change
Expand Up @@ -33,13 +33,13 @@ include whitelist-run-common.inc
?BROWSER_DISABLE_U2F: nou2f

?BROWSER_DISABLE_U2F: private-dev
#private-tmp - issues when using multiple browser sessions
#private-tmp # issues when using multiple browser sessions

blacklist ${PATH}/curl
blacklist ${PATH}/wget
blacklist ${PATH}/wget2

#dbus-user none - prevents access to passwords saved in GNOME Keyring and KWallet, also breaks Gnome connector.
#dbus-user none # prevents access to passwords saved in GNOME Keyring and KWallet, also breaks Gnome connector.

# The file dialog needs to work without d-bus.
?HAS_NODBUS: env NO_CHROME_KDE_FILE_DIALOG=1
Expand Down
4 changes: 2 additions & 2 deletions etc/profile-a-l/clac.profile
Original file line number Diff line number Diff line change
Expand Up @@ -16,10 +16,10 @@ include disable-interpreters.inc
include disable-proc.inc
include disable-programs.inc
include disable-shell.inc
#include disable-X11.inc - x11 none
#include disable-X11.inc # x11 none
include disable-xdg.inc

#include whitelist-common.inc - see #903
#include whitelist-common.inc # see #903
include whitelist-run-common.inc
include whitelist-runuser-common.inc
include whitelist-usr-share-common.inc
Expand Down
2 changes: 1 addition & 1 deletion etc/profile-a-l/clawsker.profile
Original file line number Diff line number Diff line change
Expand Up @@ -50,5 +50,5 @@ private-tmp
dbus-user none
dbus-system none

#memory-deny-write-execute - breaks on Arch (see issue #1803)
#memory-deny-write-execute # breaks on Arch (see issue #1803)
restrict-namespaces
2 changes: 1 addition & 1 deletion etc/profile-a-l/clipgrab.profile
Original file line number Diff line number Diff line change
Expand Up @@ -45,7 +45,7 @@ private-cache
private-dev
private-tmp

# 'dbus-user none' breaks tray menu - add 'dbus-user none' to your clipgrab.local if you don't need it.
# 'dbus-user none' breaks tray menu. Add 'dbus-user none' to your clipgrab.local if you don't need it.
# dbus-user none
# dbus-system none

Expand Down
4 changes: 2 additions & 2 deletions etc/profile-a-l/d-feet.profile
Original file line number Diff line number Diff line change
Expand Up @@ -31,7 +31,7 @@ include whitelist-var-common.inc
apparmor
caps.drop all
ipc-namespace
# net none - breaks on Ubuntu
#net none # breaks on Ubuntu
no3d
nodvd
nogroups
Expand All @@ -52,5 +52,5 @@ private-dev
private-etc dbus-1
private-tmp

#memory-deny-write-execute - breaks on Arch (see issue #1803)
#memory-deny-write-execute # breaks on Arch (see issue #1803)
restrict-namespaces
2 changes: 1 addition & 1 deletion etc/profile-a-l/dconf-editor.profile
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,7 @@ include whitelist-var-common.inc

apparmor
caps.drop all
# net none - breaks application on older versions
#net none # breaks application on older versions
no3d
nodvd
nogroups
Expand Down
2 changes: 1 addition & 1 deletion etc/profile-a-l/ddgtk.profile
Original file line number Diff line number Diff line change
Expand Up @@ -50,5 +50,5 @@ private-tmp
dbus-user none
dbus-system none

# memory-deny-write-execute - breaks on Arch
#memory-deny-write-execute # breaks on Arch
restrict-namespaces
4 changes: 2 additions & 2 deletions etc/profile-a-l/devhelp.profile
Original file line number Diff line number Diff line change
Expand Up @@ -23,7 +23,7 @@ include whitelist-usr-share-common.inc

apparmor
caps.drop all
# net none - makes settings immutable
#net none # makes settings immutable
nodvd
nogroups
noinput
Expand All @@ -48,6 +48,6 @@ private-tmp
# dbus-user none
# dbus-system none

#memory-deny-write-execute - breaks on Arch (see issue #1803)
#memory-deny-write-execute # breaks on Arch (see issue #1803)
read-only ${HOME}
restrict-namespaces
2 changes: 1 addition & 1 deletion etc/profile-a-l/dig.profile
Original file line number Diff line number Diff line change
Expand Up @@ -20,7 +20,7 @@ include disable-exec.inc
include disable-programs.inc
include disable-xdg.inc

#mkfile ${HOME}/.digrc - see #903
#mkfile ${HOME}/.digrc # see #903
whitelist ${HOME}/.digrc
include whitelist-common.inc
include whitelist-usr-share-common.inc
Expand Down
2 changes: 1 addition & 1 deletion etc/profile-a-l/digikam.profile
Original file line number Diff line number Diff line change
Expand Up @@ -37,7 +37,7 @@ protocol unix,inet,inet6,netlink
# QtWebengine needs chroot to set up its own sandbox
seccomp !chroot

# private-dev - prevents libdc1394 loading; this lib is used to connect to a camera device
#private-dev # prevents libdc1394 loading; this lib is used to connect to a camera device
# private-etc alternatives,ca-certificates,crypto-policies,pki,ssl
private-tmp

Expand Down
2 changes: 1 addition & 1 deletion etc/profile-a-l/display.profile
Original file line number Diff line number Diff line change
Expand Up @@ -34,7 +34,7 @@ notv
nou2f
protocol unix
seccomp
# x11 xorg - problems on kubuntu 17.04
#x11 xorg # problems on kubuntu 17.04

private-bin display,python*
private-dev
Expand Down
4 changes: 2 additions & 2 deletions etc/profile-a-l/drawio.profile
Original file line number Diff line number Diff line change
Expand Up @@ -39,7 +39,7 @@ nou2f
novideo
protocol unix
seccomp !chroot
# tracelog - breaks on Arch
#tracelog # breaks on Arch

private-bin drawio
private-cache
Expand All @@ -50,5 +50,5 @@ private-tmp
dbus-user none
dbus-system none

# memory-deny-write-execute - breaks on Arch
#memory-deny-write-execute # breaks on Arch
# restrict-namespaces
2 changes: 1 addition & 1 deletion etc/profile-a-l/enpass.profile
Original file line number Diff line number Diff line change
Expand Up @@ -58,5 +58,5 @@ private-dev
private-opt Enpass
private-tmp

#memory-deny-write-execute - breaks on Arch (see issue #1803)
#memory-deny-write-execute # breaks on Arch (see issue #1803)
restrict-namespaces
2 changes: 1 addition & 1 deletion etc/profile-a-l/evince.profile
Original file line number Diff line number Diff line change
Expand Up @@ -34,7 +34,7 @@ include whitelist-var-common.inc

caps.drop all
machine-id
# net none - breaks AppArmor on Ubuntu systems
#net none # breaks AppArmor on Ubuntu systems
netfilter
no3d
nodvd
Expand Down
2 changes: 1 addition & 1 deletion etc/profile-a-l/ffmpeg.profile
Original file line number Diff line number Diff line change
Expand Up @@ -53,5 +53,5 @@ private-tmp
dbus-user none
dbus-system none

# memory-deny-write-execute - it breaks old versions of ffmpeg
#memory-deny-write-execute # breaks older versions
restrict-namespaces
2 changes: 1 addition & 1 deletion etc/profile-a-l/file-roller.profile
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,7 @@ include whitelist-var-common.inc
apparmor
caps.drop all
machine-id
# net none - breaks on older Ubuntu versions
#net none # breaks on older Ubuntu versions
netfilter
no3d
nodvd
Expand Down
2 changes: 1 addition & 1 deletion etc/profile-a-l/filezilla.profile
Original file line number Diff line number Diff line change
Expand Up @@ -37,7 +37,7 @@ novideo
protocol unix,inet,inet6
seccomp

# private-bin breaks --join if the user has zsh set as $SHELL - adding zsh on private-bin
# private-bin breaks --join if the user has zsh set as $SHELL
private-bin bash,filezilla,fzputtygen,fzsftp,lsb_release,python*,sh,uname,zsh
private-dev
private-tmp
Expand Down
4 changes: 2 additions & 2 deletions etc/profile-a-l/firefox.profile
Original file line number Diff line number Diff line change
Expand Up @@ -39,9 +39,9 @@ whitelist /usr/share/gnome-shell/search-providers/firefox-search-provider.ini
whitelist ${RUNUSER}/*firefox*
whitelist ${RUNUSER}/psd/*firefox*

# firefox requires a shell to launch on Arch - add the next line to your firefox.local to enable private-bin.
# Firefox requires a shell to launch on Arch. Add the next line to your firefox.local to enable private-bin.
#private-bin bash,dbus-launch,dbus-send,env,firefox,sh,which
# Fedora uses shell scripts to launch firefox - add the next line to your firefox.local to enable private-bin.
# Fedora uses shell scripts to launch Firefox. Add the next line to your firefox.local to enable private-bin.
#private-bin basename,bash,cat,dirname,expr,false,firefox,firefox-wayland,getenforce,ln,mkdir,pidof,restorecon,rm,rmdir,sed,sh,tclsh,true,uname
private-etc firefox

Expand Down
4 changes: 2 additions & 2 deletions etc/profile-a-l/font-manager.profile
Original file line number Diff line number Diff line change
Expand Up @@ -33,7 +33,7 @@ include whitelist-var-common.inc
apparmor
caps.drop all
machine-id
# net none - issues on older versions
#net none # issues on older versions
no3d
nodvd
nogroups
Expand All @@ -53,5 +53,5 @@ private-bin font-manager,python*,yelp
private-dev
private-tmp

#memory-deny-write-execute - breaks on Arch (see issue #1803)
#memory-deny-write-execute # breaks on Arch (see issue #1803)
restrict-namespaces
2 changes: 1 addition & 1 deletion etc/profile-a-l/galculator.profile
Original file line number Diff line number Diff line change
Expand Up @@ -48,5 +48,5 @@ private-tmp
dbus-user none
dbus-system none

#memory-deny-write-execute - breaks on Arch (see issue #1803)
#memory-deny-write-execute # breaks on Arch (see issue #1803)
restrict-namespaces
2 changes: 1 addition & 1 deletion etc/profile-a-l/geary.profile
Original file line number Diff line number Diff line change
Expand Up @@ -53,7 +53,7 @@ include whitelist-var-common.inc

apparmor
caps.drop all
#ipc-namespace - may cause issues with X11
#ipc-namespace # may cause issues with X11
#machine-id
netfilter
no3d
Expand Down
7 changes: 3 additions & 4 deletions etc/profile-a-l/gedit.profile
Original file line number Diff line number Diff line change
Expand Up @@ -21,10 +21,10 @@ include disable-programs.inc
include whitelist-runuser-common.inc
include whitelist-var-common.inc

# apparmor - makes settings immutable
#apparmor # makes settings immutable
caps.drop all
machine-id
# net none - makes settings immutable
#net none # makes settings immutable
no3d
nodvd
nogroups
Expand All @@ -46,8 +46,7 @@ private-dev
#private-lib aspell,gconv,gedit,libgspell-1.so.*,libgtksourceview-*,libpeas-gtk-1.0.so.*,libreadline.so.*,libtinfo.so.*
private-tmp

# makes settings immutable
# dbus-user none
#dbus-user none # makes settings immutable
# dbus-system none

restrict-namespaces
2 changes: 1 addition & 1 deletion etc/profile-a-l/gmpc.profile
Original file line number Diff line number Diff line change
Expand Up @@ -50,5 +50,5 @@ writable-run-user
# dbus-user none
# dbus-system none

# memory-deny-write-execute - breaks on Arch
#memory-deny-write-execute # breaks on Arch
restrict-namespaces
2 changes: 1 addition & 1 deletion etc/profile-a-l/gnome-contacts.profile
Original file line number Diff line number Diff line change
Expand Up @@ -21,7 +21,7 @@ include whitelist-var-common.inc

caps.drop all
netfilter
#no3d - breaks on Arch
#no3d # breaks on Arch
nodvd
noinput
nonewprivs
Expand Down
2 changes: 1 addition & 1 deletion etc/profile-a-l/gnome-pie.profile
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@ include disable-exec.inc

caps.drop all
ipc-namespace
# net none - breaks dbus
#net none # breaks dbus
no3d
nodvd
nogroups
Expand Down
Loading