Skip to content

What’s the intended error state for “force-nonewprivs yes” + chromium? #5106

Closed Answered by rusty-snake
Foemass asked this question in Q&A
Discussion options

You must be logged in to vote

has unrestricted access to my home folder. Is that intended behavior?

How did you check? Did you saw the view of chromium to the filesystem or the filechooser dialog of a portal?

But I’m wondering what’s meant to happen if I throw all logic to the wind and try it anyway?

If unprivileged userns are disable chromium* will not start. If they are enabled everything¹ works fine and you should enable chromium-common-hardened.inc.

¹ with chromium* but other programs like wireshark still break.

and wanted to check I hadn’t accidentally caused some weird undesirable behavior where any program which attempt to rise privileges spontaneously escapes the sandbox.

  1. Make sure firejail [ARGS] sudo …

Replies: 1 comment 5 replies

Comment options

You must be logged in to vote
5 replies
@Foemass
Comment options

@rusty-snake
Comment options

@Foemass
Comment options

@rusty-snake
Comment options

@Foemass
Comment options

Answer selected by rusty-snake
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants