Replies: 4 comments 3 replies
-
The goal of the default profiles is to cover the most commonly used features. If something commonly used is not working, please open a bug (or better, open a MR 😉). Then it can be fixed in the profile. If it's some niche feature that's rarely used, it might better to keep it's support out of the profile, if it would mean that the jail is opened too much. So profiles are often a compromise of functionality that they cover and how tight the jail is. |
Beta Was this translation helpful? Give feedback.
-
The reason for this is that firejail does not know every translation of the default pictures directory. |
Beta Was this translation helpful? Give feedback.
-
That's what you want, different programs are isolated against each other. If this is important for you, you can change it (see @reinerh's answer) but if we would allow evolution attachments by default, we must allow evolution, thunderbird, gajim, firefox, chomium, ... open the sandbox to wide. Then somebody would come and ask "Why do you allow all these dangerous things by default?"
This should work if you set it in
|
Beta Was this translation helpful? Give feedback.
-
There are three (at least) opinions on who is responsible for sandboxing (if it isn't enforce by the platform e.g. Android).
All that said, the main reason why things break are
|
Beta Was this translation helpful? Give feedback.
-
As i used the
sudo firecfg
method to firejail the common apps, i stumble upon more and more problems on normal operation with these apps.What do i mean with "normal operation" ?
Lets take the app nomacs for example. As jailed app nomacs cannot anymore
What is the purpose in breaking all those standard/needed dir permissions ?
With default profile nomacs is unusable even for basic operation..
Beta Was this translation helpful? Give feedback.
All reactions