profiles: sort blacklist sections (#6289)

See etc/templates/profile.template.

This is a follow-up to #6286.
This commit is contained in:
Kelvin M. Klann 2024-03-27 12:13:21 +00:00 committed by GitHub
parent e600fd7cf9
commit 0d8fb3d1b4
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
11 changed files with 13 additions and 13 deletions

View file

@ -7,8 +7,8 @@ include bpftop.local
# Persistent global definitions
include globals.local
blacklist /usr/libexec
blacklist ${RUNUSER}
blacklist /usr/libexec
include disable-common.inc
include disable-devel.inc

View file

@ -7,8 +7,8 @@ include cloneit.local
# Persistent global definitions
include globals.local
blacklist /usr/libexec
blacklist ${RUNUSER}
blacklist /usr/libexec
include disable-common.inc
include disable-devel.inc

View file

@ -6,8 +6,8 @@ include deadlink.local
# Persistent global definitions
include globals.local
blacklist /usr/libexec
blacklist ${RUNUSER}
blacklist /usr/libexec
noblacklist ${HOME}/.config/deadlink

View file

@ -7,8 +7,8 @@ include dexios.local
# Persistent global definitions
include globals.local
blacklist /usr/libexec
blacklist ${RUNUSER}
blacklist /usr/libexec
include disable-common.inc
include disable-devel.inc

View file

@ -6,8 +6,8 @@ include editorconfiger.local
# Persistent global definitions
include globals.local
blacklist /usr/libexec
blacklist ${RUNUSER}
blacklist /usr/libexec
include disable-common.inc
include disable-devel.inc

View file

@ -12,8 +12,8 @@ noblacklist ${HOME}/.config/kdiff3rc
# Add the next line to your kdiff3.local if you don't need to compare files in disable-common.inc.
# By default we deny access only to .ssh and .gnupg.
#include disable-common.inc
blacklist ${HOME}/.ssh
blacklist ${HOME}/.gnupg
blacklist ${HOME}/.ssh
include disable-devel.inc
include disable-exec.inc

View file

@ -20,11 +20,11 @@ blacklist ${RUNUSER}/wayland-*
noblacklist ${HOME}/.gnupg
read-only ${HOME}/.gnupg/trustdb.gpg
read-only ${HOME}/.gnupg/pubring.kbx
blacklist ${HOME}/.gnupg/random_seed
blacklist ${HOME}/.gnupg/pubring.kbx~
blacklist ${HOME}/.gnupg/private-keys-v1.d
blacklist ${HOME}/.gnupg/crls.d
blacklist ${HOME}/.gnupg/openpgp-revocs.d
blacklist ${HOME}/.gnupg/private-keys-v1.d
blacklist ${HOME}/.gnupg/pubring.kbx~
blacklist ${HOME}/.gnupg/random_seed
# Arch Linux (based distributions) need access to /var/lib/pacman. As we drop all capabilities this is automatically read-only.
noblacklist /var/lib/pacman

View file

@ -7,8 +7,8 @@ include statusof.local
# Persistent global definitions
include globals.local
blacklist /usr/libexec
blacklist ${RUNUSER}
blacklist /usr/libexec
# Allow python (blacklisted by disable-interpreters.inc)
include allow-python3.inc

View file

@ -6,8 +6,8 @@ include textroom.local
# Persistent global definitions
include globals.local
blacklist /usr/libexec
blacklist ${RUNUSER}/wayland-*
blacklist /usr/libexec
noblacklist ${HOME}/.config/textroom

View file

@ -12,8 +12,8 @@ ignore dbus-user none
noblacklist ${HOME}/.cache/mozilla
noblacklist ${HOME}/.mozilla
blacklist /usr/libexec
blacklist /sys/class/net
blacklist /usr/libexec
mkdir ${HOME}/.cache/mozilla/torbrowser
mkdir ${HOME}/.mozilla

View file

@ -6,8 +6,8 @@ include tvnamer.local
# Persistent global definitions
include globals.local
blacklist /usr/libexec
blacklist ${RUNUSER}
blacklist /usr/libexec
noblacklist ${HOME}/.config/tvnamer
noblacklist ${VIDEOS}