Skip to content

Commit 5d0822c

Browse files
committed
private-etc: big profile changes
1 parent f64a9cc commit 5d0822c

File tree

319 files changed

+345
-347
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

319 files changed

+345
-347
lines changed

etc/profile-a-l/1password.profile

+1-1
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,7 @@ noblacklist ${HOME}/.config/1Password
1111
mkdir ${HOME}/.config/1Password
1212
whitelist ${HOME}/.config/1Password
1313

14-
private-etc alternatives,ca-certificates,crypto-policies,fonts,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,localtime,machine-id,nsswitch.conf,pki,resolv.conf,ssl
14+
private-etc @tls-ca
1515

1616
# Needed for keychain things, talking to Firefox, possibly other things? Not sure how to narrow down
1717
ignore dbus-user none

etc/profile-a-l/abiword.profile

+1-1
Original file line numberDiff line numberDiff line change
@@ -41,7 +41,7 @@ tracelog
4141
private-bin abiword
4242
private-cache
4343
private-dev
44-
private-etc alternatives,fonts,gtk-3.0,ld.so.cache,ld.so.preload,passwd
44+
private-etc @x11
4545
private-tmp
4646

4747
# dbus-user none

etc/profile-a-l/agetpkg.profile

+1-1
Original file line numberDiff line numberDiff line change
@@ -49,7 +49,7 @@ tracelog
4949
private-bin agetpkg,python3
5050
private-cache
5151
private-dev
52-
private-etc alternatives,ca-certificates,crypto-policies,ld.so.cache,ld.so.preload,pki,resolv.conf,ssl
52+
private-etc @tls-ca
5353
private-tmp
5454

5555
dbus-user none

etc/profile-a-l/alacarte.profile

+1-1
Original file line numberDiff line numberDiff line change
@@ -52,7 +52,7 @@ disable-mnt
5252
# private-bin alacarte,bash,python*,sh
5353
private-cache
5454
private-dev
55-
private-etc alternatives,dconf,fonts,gtk-3.0,ld.so.cache,ld.so.preload,locale.alias,locale.conf,login.defs,mime.types,nsswitch.conf,passwd,pki,X11,xdg
55+
private-etc @tls-ca,@x11,mime.types
5656
private-tmp
5757

5858
dbus-user none

etc/profile-a-l/alienarena.profile

+1-1
Original file line numberDiff line numberDiff line change
@@ -43,7 +43,7 @@ disable-mnt
4343
private-bin alienarena
4444
private-cache
4545
private-dev
46-
private-etc alsa,alternatives,asound.conf,bumblebee,ca-certificates,crypto-policies,drirc,fonts,glvnd,host.conf,hostname,hosts,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,locale,locale.alias,locale.conf,localtime,machine-id,nsswitch.conf,nvidia,pango,pki,protocols,pulse,resolv.conf,rpc,services,ssl,X11
46+
private-etc @tls-ca,@x11,bumblebee,glvnd,host.conf,rpc,services
4747
private-tmp
4848

4949
dbus-user none

etc/profile-a-l/alpine.profile

+1-1
Original file line numberDiff line numberDiff line change
@@ -90,7 +90,7 @@ disable-mnt
9090
private-bin alpine
9191
private-cache
9292
private-dev
93-
private-etc alternatives,c-client.cf,ca-certificates,crypto-policies,host.conf,hostname,hosts,krb5.keytab,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,locale,locale.alias,locale.conf,localtime,mailcap,mime.types,nsswitch.conf,passwd,pine.conf,pinerc.fixed,pki,protocols,resolv.conf,rpc,services,ssl,terminfo,xdg
93+
private-etc @tls-ca,@x11,c-client.cf,host.conf,krb5.keytab,mailcap,mime.types,pine.conf,pinerc.fixed,rpc,services,terminfo
9494
private-tmp
9595
writable-run-user
9696
writable-var

etc/profile-a-l/anki.profile

+1-1
Original file line numberDiff line numberDiff line change
@@ -49,7 +49,7 @@ disable-mnt
4949
private-bin anki,python*
5050
private-cache
5151
private-dev
52-
private-etc alternatives,ca-certificates,fonts,gtk-2.0,hostname,hosts,ld.so.cache,ld.so.preload,machine-id,pki,resolv.conf,ssl,Trolltech.conf
52+
private-etc @tls-ca,@x11,Trolltech.conf
5353
private-tmp
5454

5555
dbus-user none

etc/profile-a-l/apostrophe.profile

+1-1
Original file line numberDiff line numberDiff line change
@@ -62,7 +62,7 @@ disable-mnt
6262
private-bin apostrophe,fmtutil,kpsewhich,mktexfmt,pandoc,pdftex,perl,python3*,sh,xdvipdfmx,xelatex,xetex
6363
private-cache
6464
private-dev
65-
private-etc alternatives,dconf,fonts,gtk-3.0,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,pango,texlive,X11
65+
private-etc @x11,texlive
6666
private-tmp
6767

6868
dbus-user filter

etc/profile-a-l/aria2c.profile

+1-1
Original file line numberDiff line numberDiff line change
@@ -45,7 +45,7 @@ private-bin aria2c,gzip
4545
# Add 'private-cache' to your aria2c.local if you don't use Lutris/winetricks (see issue #2772).
4646
#private-cache
4747
private-dev
48-
private-etc alternatives,ca-certificates,crypto-policies,groups,ld.so.cache,ld.so.preload,login.defs,machine-id,nsswitch.conf,passwd,pki,resolv.conf,ssl
48+
private-etc @tls-ca,groups
4949
private-lib libreadline.so.*
5050
private-tmp
5151

etc/profile-a-l/arm.profile

+1-1
Original file line numberDiff line numberDiff line change
@@ -42,7 +42,7 @@ tracelog
4242
disable-mnt
4343
private-bin arm,bash,ldconfig,lsof,ps,python*,sh,tor
4444
private-dev
45-
private-etc alternatives,ca-certificates,crypto-policies,ld.so.cache,ld.so.preload,passwd,pki,resolv.conf,ssl,tor
45+
private-etc @tls-ca,tor
4646
private-tmp
4747

4848
restrict-namespaces

etc/profile-a-l/artha.profile

+1-1
Original file line numberDiff line numberDiff line change
@@ -54,7 +54,7 @@ disable-mnt
5454
private-bin artha,enchant,notify-send
5555
private-cache
5656
private-dev
57-
private-etc alternatives,fonts,ld.so.cache,ld.so.preload,machine-id
57+
private-etc
5858
private-lib libnotify.so.*
5959
private-tmp
6060

etc/profile-a-l/atool.profile

+1-1
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,7 @@ include allow-perl.inc
1313
noroot
1414

1515
# without login.defs atool complains and uses UID/GID 1000 by default
16-
private-etc alternatives,group,ld.so.cache,ld.so.preload,login.defs,passwd,resolv.conf
16+
private-etc
1717
private-tmp
1818

1919
# Redirect

etc/profile-a-l/atril.profile

+1-1
Original file line numberDiff line numberDiff line change
@@ -41,7 +41,7 @@ tracelog
4141

4242
private-bin 7z,7za,7zr,atril,atril-previewer,atril-thumbnailer,sh,tar,unrar,unzip,zipnote
4343
private-dev
44-
private-etc alternatives,fonts,ld.so.cache,ld.so.preload
44+
private-etc
4545
# atril uses webkit gtk to display epub files
4646
# waiting for globbing support in private-lib; for now hardcoding it to webkit2gtk-4.0
4747
#private-lib webkit2gtk-4.0 - problems on Arch with the new version of WebKit

etc/profile-a-l/audio-recorder.profile

+1-1
Original file line numberDiff line numberDiff line change
@@ -43,7 +43,7 @@ tracelog
4343
disable-mnt
4444
# private-bin audio-recorder
4545
private-cache
46-
private-etc alternatives,fonts,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload
46+
private-etc
4747
private-tmp
4848

4949
dbus-user filter

etc/profile-a-l/authenticator-rs.profile

+1-1
Original file line numberDiff line numberDiff line change
@@ -46,7 +46,7 @@ disable-mnt
4646
private-bin authenticator-rs
4747
private-cache
4848
private-dev
49-
private-etc alternatives,ca-certificates,crypto-policies,dconf,fonts,gtk-2.0,gtk-3.0,ld.so.cache,ld.so.preload,pki,resolv.conf,ssl,xdg
49+
private-etc @tls-ca,@x11
5050
private-tmp
5151

5252
dbus-user filter

etc/profile-a-l/authenticator.profile

+1-1
Original file line numberDiff line numberDiff line change
@@ -38,7 +38,7 @@ seccomp
3838
disable-mnt
3939
# private-bin authenticator,python*
4040
private-dev
41-
private-etc alternatives,ca-certificates,crypto-policies,fonts,ld.so.cache,ld.so.preload,pki,resolv.conf,ssl
41+
private-etc @tls-ca
4242
private-tmp
4343

4444
# makes settings immutable

etc/profile-a-l/ballbuster.profile

+1-1
Original file line numberDiff line numberDiff line change
@@ -44,7 +44,7 @@ disable-mnt
4444
private-bin ballbuster
4545
private-cache
4646
private-dev
47-
private-etc alsa,alternatives,asound.conf,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,machine-id,pulse
47+
private-etc
4848
private-tmp
4949

5050
dbus-user none

etc/profile-a-l/bibletime.profile

+1-1
Original file line numberDiff line numberDiff line change
@@ -51,7 +51,7 @@ disable-mnt
5151
# private-bin bibletime
5252
private-cache
5353
private-dev
54-
private-etc alternatives,ca-certificates,crypto-policies,fonts,ld.so.cache,ld.so.preload,login.defs,machine-id,passwd,pki,resolv.conf,ssl,sword,sword.conf
54+
private-etc @tls-ca,sword,sword.conf
5555
private-tmp
5656

5757
dbus-user none

etc/profile-a-l/bijiben.profile

+1-1
Original file line numberDiff line numberDiff line change
@@ -50,7 +50,7 @@ disable-mnt
5050
private-bin bijiben
5151
# private-cache -- access to .cache/tracker is required
5252
private-dev
53-
private-etc alternatives,dconf,fonts,gtk-3.0,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload
53+
private-etc @x11
5454
private-tmp
5555

5656
dbus-user filter

etc/profile-a-l/bitwarden.profile

+1-1
Original file line numberDiff line numberDiff line change
@@ -23,7 +23,7 @@ no3d
2323
nosound
2424

2525
?HAS_APPIMAGE: ignore private-dev
26-
private-etc alternatives,ca-certificates,crypto-policies,fonts,hosts,ld.so.cache,ld.so.preload,nsswitch.conf,pki,resolv.conf,ssl
26+
private-etc @tls-ca
2727
private-opt Bitwarden
2828

2929
# Redirect

etc/profile-a-l/bless.profile

+1-1
Original file line numberDiff line numberDiff line change
@@ -34,7 +34,7 @@ seccomp
3434
# private-bin bash,bless,mono,sh
3535
private-cache
3636
private-dev
37-
private-etc alternatives,fonts,ld.so.cache,ld.so.preload,mono
37+
private-etc mono
3838
private-tmp
3939

4040
dbus-user none

etc/profile-a-l/blobby.profile

+1-1
Original file line numberDiff line numberDiff line change
@@ -40,7 +40,7 @@ tracelog
4040
disable-mnt
4141
private-bin blobby
4242
private-dev
43-
private-etc alsa,alternatives,asound.conf,drirc,group,hosts,ld.so.cache,ld.so.preload,login.defs,machine-id,passwd,pulse
43+
private-etc @x11
4444
private-lib
4545
private-tmp
4646

etc/profile-a-l/blobwars.profile

+1-1
Original file line numberDiff line numberDiff line change
@@ -42,7 +42,7 @@ disable-mnt
4242
private-bin blobwars
4343
private-cache
4444
private-dev
45-
private-etc alternatives,ld.so.cache,ld.so.preload,machine-id
45+
private-etc
4646
private-tmp
4747

4848
dbus-user none

etc/profile-a-l/bsdtar.profile

+1-1
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ include bsdtar.local
66
# Persistent global definitions
77
include globals.local
88

9-
private-etc alternatives,group,ld.so.cache,ld.so.preload,localtime,passwd
9+
private-etc
1010

1111
# Redirect
1212
include archiver-common.profile

etc/profile-a-l/cameramonitor.profile

+1-1
Original file line numberDiff line numberDiff line change
@@ -45,7 +45,7 @@ tracelog
4545
disable-mnt
4646
private-bin cameramonitor,python*
4747
private-cache
48-
private-etc alternatives,fonts,ld.so.cache,ld.so.preload
48+
private-etc
4949
private-tmp
5050

5151
# dbus-user none

etc/profile-a-l/cargo.profile

+1-1
Original file line numberDiff line numberDiff line change
@@ -16,7 +16,7 @@ noblacklist ${HOME}/.cargo/credentials.toml
1616
#whitelist ${HOME}/.rustup
1717

1818
#private-bin cargo,rustc
19-
private-etc alternatives,ca-certificates,crypto-policies,group,host.conf,hostname,hosts,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,locale,locale.alias,locale.conf,localtime,magic,magic.mgc,nsswitch.conf,passwd,pki,protocols,resolv.conf,rpc,services,ssl
19+
private-etc @tls-ca,host.conf,magic,magic.mgc,rpc,services
2020

2121
memory-deny-write-execute
2222

etc/profile-a-l/cawbird.profile

+1-1
Original file line numberDiff line numberDiff line change
@@ -38,7 +38,7 @@ disable-mnt
3838
private-bin cawbird
3939
private-cache
4040
private-dev
41-
private-etc alternatives,ca-certificates,crypto-policies,fonts,gtk-2.0,gtk-3.0,host.conf,hostname,hosts,ld.so.cache,ld.so.preload,mime.types,nsswitch.conf,pki,resolv.conf,ssl,X11,xdg
41+
private-etc @tls-ca,@x11,host.conf,mime.types
4242
private-tmp
4343

4444
# dbus-user none

etc/profile-a-l/celluloid.profile

+1-1
Original file line numberDiff line numberDiff line change
@@ -52,7 +52,7 @@ tracelog
5252

5353
private-bin celluloid,env,gnome-mpv,python*,youtube-dl
5454
private-cache
55-
private-etc alternatives,ca-certificates,crypto-policies,dconf,drirc,fonts,gtk-3.0,hosts,ld.so.cache,ld.so.preload,libva.conf,localtime,machine-id,pkcs11,pki,resolv.conf,selinux,ssl,xdg
55+
private-etc @tls-ca,@x11,libva.conf,pkcs11,selinux
5656
private-dev
5757
private-tmp
5858

etc/profile-a-l/chatterino.profile

+1-1
Original file line numberDiff line numberDiff line change
@@ -70,7 +70,7 @@ private-bin chatterino,cvlc,env,ffmpeg,mpv,nvlc,pgrep,python*,qvlc,rvlc,streamli
7070
# private-cache may cause issues with mpv (see #2838)
7171
private-cache
7272
private-dev
73-
private-etc alsa,alternatives,asound.conf,ca-certificates,dbus-1,fonts,hostname,hosts,kde4rc,kde5rc,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,locale,locale.alias,locale.conf,localtime,machine-id,nvidia,passwd,pulse,resolv.conf,rpc,services,ssl,Trolltech.conf,X11
73+
private-etc @tls-ca,@x11,dbus-1,rpc,services,Trolltech.conf
7474
private-srv none
7575
private-tmp
7676

etc/profile-a-l/cheese.profile

+1-1
Original file line numberDiff line numberDiff line change
@@ -51,7 +51,7 @@ disable-mnt
5151
private-bin cheese
5252
private-cache
5353
private-dev
54-
private-etc alternatives,clutter-1.0,dconf,drirc,fonts,gtk-3.0,ld.so.cache,ld.so.preload
54+
private-etc @x11,clutter-1.0
5555
private-tmp
5656

5757
dbus-user filter

etc/profile-a-l/clawsker.profile

+1-1
Original file line numberDiff line numberDiff line change
@@ -43,7 +43,7 @@ disable-mnt
4343
private-bin bash,clawsker,perl,sh,which
4444
private-cache
4545
private-dev
46-
private-etc alternatives,fonts,ld.so.cache,ld.so.preload
46+
private-etc
4747
private-lib girepository-1.*,libdbus-glib-1.so.*,libetpan.so.*,libgirepository-1.*,libgtk-3.so.*,libgtk-x11-2.0.so.*,libstartup-notification-1.so.*,perl*
4848
private-tmp
4949

etc/profile-a-l/cmus.profile

+1-1
Original file line numberDiff line numberDiff line change
@@ -26,6 +26,6 @@ protocol unix,inet,inet6
2626
seccomp
2727

2828
private-bin cmus
29-
private-etc alternatives,asound.conf,ca-certificates,crypto-policies,group,ld.so.cache,ld.so.preload,machine-id,pki,pulse,resolv.conf,ssl
29+
private-etc @tls-ca
3030

3131
restrict-namespaces

etc/profile-a-l/cointop.profile

+1-1
Original file line numberDiff line numberDiff line change
@@ -52,7 +52,7 @@ disable-mnt
5252
private-bin cointop
5353
private-cache
5454
private-dev
55-
private-etc alternatives,ca-certificates,crypto-policies,host.conf,hostname,hosts,ld.so.cache,ld.so.preload,nsswitch.conf,pki,protocols,resolv.conf,rpc,services,ssl
55+
private-etc @tls-ca,host.conf,rpc,services
5656
private-lib
5757
private-tmp
5858

etc/profile-a-l/colorful.profile

+1-1
Original file line numberDiff line numberDiff line change
@@ -44,7 +44,7 @@ disable-mnt
4444
private-bin colorful
4545
private-cache
4646
private-dev
47-
private-etc alsa,alternatives,asound.conf,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,machine-id,pulse
47+
private-etc
4848
private-tmp
4949

5050
dbus-user none

etc/profile-a-l/com.github.bleakgrey.tootle.profile

+1-1
Original file line numberDiff line numberDiff line change
@@ -44,7 +44,7 @@ disable-mnt
4444
private-bin com.github.bleakgrey.tootle
4545
private-cache
4646
private-dev
47-
private-etc alsa,alternatives,asound.conf,ca-certificates,crypto-policies,dconf,fonts,gtk-2.0,gtk-3.0,host.conf,hostname,hosts,ld.so.cache,ld.so.preload,machine-id mime.types,nsswitch.conf,pki,pulse,resolv.conf,ssl,X11,xdg
47+
private-etc @tls-ca,@x11,host.conf,mime.types
4848
private-tmp
4949

5050
# Settings are immutable

etc/profile-a-l/com.github.dahenson.agenda.profile

+1-1
Original file line numberDiff line numberDiff line change
@@ -51,7 +51,7 @@ disable-mnt
5151
private-bin com.github.dahenson.agenda
5252
private-cache
5353
private-dev
54-
private-etc alternatives,dconf,fonts,gtk-3.0,ld.so.cache,ld.so.preload
54+
private-etc @x11
5555
private-tmp
5656

5757
dbus-user filter

etc/profile-a-l/com.github.johnfactotum.Foliate.profile

+1-1
Original file line numberDiff line numberDiff line change
@@ -54,7 +54,7 @@ disable-mnt
5454
private-bin com.github.johnfactotum.Foliate,gjs
5555
private-cache
5656
private-dev
57-
private-etc alternatives,dconf,fonts,gconf,gtk-3.0,ld.so.cache,ld.so.preload
57+
private-etc @x11,gconf
5858
private-tmp
5959

6060
read-only ${HOME}

etc/profile-a-l/com.github.phase1geo.minder.profile

+1-1
Original file line numberDiff line numberDiff line change
@@ -51,7 +51,7 @@ disable-mnt
5151
private-bin com.github.phase1geo.minder
5252
private-cache
5353
private-dev
54-
private-etc alternatives,dconf,fonts,gtk-3.0,ld.so.cache,ld.so.conf,ld.so.conf.d,ld.so.preload,locale,locale.alias,locale.conf,localtime,mime.types,pango,passwd,X11,xdg
54+
private-etc @x11,mime.types
5555
private-tmp
5656

5757
dbus-user filter

etc/profile-a-l/com.github.tchx84.Flatseal.profile

+1-1
Original file line numberDiff line numberDiff line change
@@ -51,7 +51,7 @@ disable-mnt
5151
private-bin com.github.tchx84.Flatseal,gjs
5252
private-cache
5353
private-dev
54-
private-etc alternatives,dconf,fonts,gtk-3.0,ld.so.cache,ld.so.preload
54+
private-etc @x11
5555
private-tmp
5656

5757
dbus-user filter

etc/profile-a-l/coyim.profile

+1-1
Original file line numberDiff line numberDiff line change
@@ -39,7 +39,7 @@ tracelog
3939
disable-mnt
4040
private-cache
4141
private-dev
42-
private-etc alternatives,ca-certificates,crypto-policies,fonts,ld.so.cache,ld.so.preload,machine-id,pki,ssl
42+
private-etc @tls-ca
4343
private-tmp
4444

4545
dbus-user none

etc/profile-a-l/crow.profile

+1-1
Original file line numberDiff line numberDiff line change
@@ -38,7 +38,7 @@ seccomp
3838
disable-mnt
3939
private-bin crow
4040
private-dev
41-
private-etc alternatives,asound.conf,ca-certificates,crypto-policies,dconf,fonts,ld.so.cache,ld.so.preload,machine-id,nsswitch.conf,pki,pulse,resolv.conf,ssl
41+
private-etc @tls-ca,@x11
4242
private-opt none
4343
private-tmp
4444
private-srv none

etc/profile-a-l/d-feet.profile

+1-1
Original file line numberDiff line numberDiff line change
@@ -49,7 +49,7 @@ disable-mnt
4949
private-bin d-feet,python*
5050
private-cache
5151
private-dev
52-
private-etc alternatives,dbus-1,fonts,ld.so.cache,ld.so.preload,machine-id
52+
private-etc dbus-1
5353
private-tmp
5454

5555
#memory-deny-write-execute - breaks on Arch (see issue #1803)

etc/profile-a-l/dbus-send.profile

+1-1
Original file line numberDiff line numberDiff line change
@@ -50,7 +50,7 @@ private
5050
private-bin dbus-send
5151
private-cache
5252
private-dev
53-
private-etc alternatives,dbus-1,ld.so.cache,ld.so.preload
53+
private-etc dbus-1
5454
private-lib libpcre*
5555
private-tmp
5656

etc/profile-a-l/dconf-editor.profile

+1-1
Original file line numberDiff line numberDiff line change
@@ -42,7 +42,7 @@ disable-mnt
4242
private-bin dconf-editor
4343
private-cache
4444
private-dev
45-
private-etc alternatives,dconf,fonts,gtk-3.0,ld.so.cache,ld.so.preload,machine-id
45+
private-etc @x11
4646
private-lib
4747
private-tmp
4848

0 commit comments

Comments
 (0)