diff --git a/etc/disable-common.inc b/etc/disable-common.inc index 71439e10d..06ced4e53 100644 --- a/etc/disable-common.inc +++ b/etc/disable-common.inc @@ -3,6 +3,8 @@ blacklist-nolog ${HOME}/.history blacklist-nolog ${HOME}/.*_history blacklist ${HOME}/.local/share/systemd +blacklist-nolog ${HOME}/.adobe +blacklist-nolog ${HOME}/.macromedia # X11 session autostart blacklist ${HOME}/.xinitrc diff --git a/etc/disable-programs.inc b/etc/disable-programs.inc index 6379253aa..00879b908 100644 --- a/etc/disable-programs.inc +++ b/etc/disable-programs.inc @@ -6,8 +6,6 @@ blacklist ${HOME}/.FBReader blacklist ${HOME}/.wine # HTTP / FTP / Mail -blacklist-nolog ${HOME}/.adobe -blacklist-nolog ${HOME}/.macromedia blacklist ${HOME}/.icedove blacklist ${HOME}/.thunderbird blacklist ${HOME}/.sylpheed-2.0 diff --git a/etc/openbox.profile b/etc/openbox.profile index 8a46e6841..6e2e5d6fd 100644 --- a/etc/openbox.profile +++ b/etc/openbox.profile @@ -1,15 +1,9 @@ -################################ +####################################### # OpenBox window manager profile -# - all applications started in OpenBox will run in -# this profile -################################ +# - all applications started in OpenBox will run in this profile +####################################### include /etc/firejail/disable-common.inc -blacklist ${HOME}/.pki/nssdb -blacklist ${HOME}/.lastpass -blacklist ${HOME}/.keepassx -blacklist ${HOME}/.password-store - caps.drop all seccomp protocol unix,inet,inet6 diff --git a/src/firejail/fs.c b/src/firejail/fs.c index 8a81b6e8e..4695d8d26 100644 --- a/src/firejail/fs.c +++ b/src/firejail/fs.c @@ -732,6 +732,7 @@ void fs_basic_fs(void) { fs_rdonly("/lib"); fs_rdonly("/lib64"); fs_rdonly("/lib32"); + fs_rdonly("/libx32"); fs_rdonly("/usr"); fs_rdonly("/etc"); fs_rdonly("/var");