mirror of
https://github.com/netblue30/firejail.git
synced 2026-05-15 14:16:14 -06:00
That is, make "X11" lowercase so that the order of the includes in the
disable- section remain the same when sorted with `LC_ALL=C`, as is the
case for most of the other sections. That is also likely to be the
default in text editors (such as in vim on Arch), so this should make
the disable- section more consistent and easier to sort when editing the
profile.
Also, keep the old include as a redirect to the new one for now to avoid
breakage.
Commands used to search and replace:
git mv etc/inc/disable-X11.inc etc/inc/disable-x11.inc
git grep -Ilz 'disable-X11' -- etc | xargs -0 \
perl -pi -e 's/disable-X11/disable-x11/'
Relates to #4462 #4854 #6070 #6289.
This is a follow-up to #6286.
68 lines
1.4 KiB
Text
68 lines
1.4 KiB
Text
# Firejail profile for git
|
|
# Description: Fast, scalable, distributed revision control system
|
|
# This file is overwritten after every install/update
|
|
quiet
|
|
# Persistent local customizations
|
|
include git.local
|
|
# Persistent global definitions
|
|
include globals.local
|
|
|
|
noblacklist ${HOME}/.config/git
|
|
noblacklist ${HOME}/.config/nano
|
|
noblacklist ${HOME}/.emacs
|
|
noblacklist ${HOME}/.emacs.d
|
|
noblacklist ${HOME}/.gitconfig
|
|
noblacklist ${HOME}/.git-credential-cache
|
|
noblacklist ${HOME}/.git-credentials
|
|
noblacklist ${HOME}/.gnupg
|
|
noblacklist ${HOME}/.nanorc
|
|
noblacklist ${HOME}/.vim
|
|
noblacklist ${HOME}/.viminfo
|
|
|
|
# Allow environment variables (rmenv'ed by disable-common.inc)
|
|
ignore rmenv GH_TOKEN
|
|
ignore rmenv GITHUB_TOKEN
|
|
ignore rmenv GH_ENTERPRISE_TOKEN
|
|
ignore rmenv GITHUB_ENTERPRISE_TOKEN
|
|
|
|
# Allow ssh (blacklisted by disable-common.inc)
|
|
include allow-ssh.inc
|
|
|
|
blacklist ${RUNUSER}/wayland-*
|
|
|
|
include disable-common.inc
|
|
include disable-exec.inc
|
|
include disable-programs.inc
|
|
include disable-x11.inc
|
|
|
|
whitelist /usr/share/git
|
|
whitelist /usr/share/git-core
|
|
whitelist /usr/share/gitgui
|
|
whitelist /usr/share/gitweb
|
|
whitelist /usr/share/nano
|
|
include whitelist-usr-share-common.inc
|
|
include whitelist-var-common.inc
|
|
|
|
apparmor
|
|
caps.drop all
|
|
ipc-namespace
|
|
machine-id
|
|
netfilter
|
|
no3d
|
|
nodvd
|
|
nogroups
|
|
noinput
|
|
nonewprivs
|
|
noroot
|
|
nosound
|
|
notv
|
|
nou2f
|
|
novideo
|
|
protocol unix,inet,inet6
|
|
seccomp
|
|
|
|
private-cache
|
|
private-dev
|
|
|
|
memory-deny-write-execute
|
|
restrict-namespaces
|