Replies: 12 comments 13 replies
-
Probably you don't need a How about disabling Wayland (blacklist ${RUNUSER}/wayland-*) or X11 (blacklist /tmp/.X11-unix)? If your system has /usr/libexec, try to add it:
Do you actually still have that on your system? It got dropped and AFAICT isn't in 0.9.72... Check if you can add these:
If you can use that (which is fine) Check if you can add: |
Beta Was this translation helpful? Give feedback.
-
|
Beta Was this translation helpful? Give feedback.
-
What do you mean by "without its parent default.profile"? |
Beta Was this translation helpful? Give feedback.
-
... neither does So I didn´t include those entries. |
Beta Was this translation helpful? Give feedback.
-
So this is what it looks like now:
|
Beta Was this translation helpful? Give feedback.
-
That might be. 😐 My system is Linux Lite 6.2 .
So it´s using the official Ubuntu repositories, I guess. firejail version 0.9.66 Cheers from Rosika 🙂 |
Beta Was this translation helpful? Give feedback.
-
I did what you recommended, but it was no good for me. 😦 Now I got firejail version 0.9.72-2 but firetools didn´t work with firejail´s new version any longer. But the new version of firetools is awful. It changed my personal layout and anything I created. So I reverted firejail and firetools to the previous version. BTW: I looked up the links you kindly provided.
But I´m back to firejail 0.9.66-2, like I said. Many thanks and many greetings from Rosika 🙂 |
Beta Was this translation helpful? Give feedback.
-
Try moving your prior configuration out of the way and check the firetools issue tracker. Especially #71 might prove informational. Feel free to report your observations there. |
Beta Was this translation helpful? Give feedback.
-
Hi again, 👋 Thanks all for your replies. I looked at https://seclists.org/oss-sec/2022/q2/188 and it says:
O.K., you'were right from the beginning. I´ll have to install the latest firejail version then. 😊 Thanks for the links.
I didn´t know that. Many thanks to both of you and many greetings from Rosika 🙂 |
Beta Was this translation helpful? Give feedback.
-
Hi all, 👋 O.K. Success after all. 👍 I added firejail´s PPA and upgraded It took me some time to edit E.g.:
for getting my old BTW: I found out that in
Now I can get back to editing In the meantime: thanks a lot for your help. ❤️ Many greetings from Rosika |
Beta Was this translation helpful? Give feedback.
-
Hi all, 👋 I´ve updated
I had to comment out Thank you very much @glitsj16 and @rusty-snake for your help. It´s highly appreciated. 👍 Many greetings from Rosika 🙂 |
Beta Was this translation helpful? Give feedback.
-
Sorry for the typo. It should be a thumbs-up, of course. |
Beta Was this translation helpful? Give feedback.
-
Hi all, 👋
as I needed an uncomplicated markdown editor with live preview I got hold of
keenwrite
.It can be found here: https://gitlab.com/DaveJarvis/KeenWrite .
I just had to download
keenwrite.bin
, which seems to be a standalone executable, then:chmod +x keenwrite.bin
. So running the command./keenwrite.bin
from the respective directory would run it.It works well this way but of course I´d like to run it within a private firejail sandbox.
So I wrote a tiny script for it:
It works as desired but as firejail doesn´t provide a dedicated profile for it, the default profile is used.
I wanted to change that to improve sandboxing. 😊
So I copied the contents of
default.profile
to/home/rosika/.config/firejail/keenwrite.bin.profile
and then changed the values to be as permissive asnecessary and to be as restrictive as possible.
I came up with this:
What do you think of it? Is it good enough? Can it be improved somehow?
Thanks a lot for your help in advance.
Many greetings from Rosika 🙂
Beta Was this translation helpful? Give feedback.
All reactions