Skip to content

Kernel overlay + chroot? #5672

Answered by smitsohu
Graveflo asked this question in Q&A
Feb 20, 2023 · 2 comments · 5 replies
Discussion options

You must be logged in to vote

First, I would like to say that I am aware of the security concerns with using overlay and firejail. I wouldn't say that I completely understand the interactions.

The only real reason there is no overlayfs support in Firejail is that the old feature was broken beyond repair, and now the project needs a new direction where to head with this functionality.

Why is chroot disabled by default?

I think the perception was that this option is not used so often, and it was disabled to reduce Firejails default attack surface. That said, it is meant to be used, and it is generally safe for everyone to enable.

Does this interaction with overlay and chroot make sense? Is is not advisable to do so…

Replies: 2 comments 5 replies

Comment options

You must be logged in to vote
0 replies
Answer selected by Graveflo
Comment options

You must be logged in to vote
5 replies
@Graveflo
Comment options

@smitsohu
Comment options

@Graveflo
Comment options

@smitsohu
Comment options

@glitsj16
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants