-
Notifications
You must be signed in to change notification settings - Fork 555
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Bug: Cannot whitelist home folders correctly #2059
Labels
information_old
(Deprecated; use "doc-todo" or "needinfo" instead) Information was/is required
Comments
Looking at the docs (
|
chiraag-nataraj
added
the
information_old
(Deprecated; use "doc-todo" or "needinfo" instead) Information was/is required
label
Jul 24, 2018
I'm going to close this as discussion should probably move over to #2041. |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
information_old
(Deprecated; use "doc-todo" or "needinfo" instead) Information was/is required
It appears there is some error prevention logic that prevents whitelisting home folders when run as root
sudo firejail --noprofile --whitelist=/home/user ls
Outputs error and says invalid whitelist path
Strangely, so does the following even though it IS the root home folder:
sudo firejail --noprofile --whitelist=/root ls
This command will succeed even though it is NOT the root home folder and does not even exist:
sudo firejail --noprofile --whitelist=/home/root ls
This command will also fail even though it explictly sets the homefolder of root to another:
sudo (
export HOME="/home/user"
firejail --noprofile --whitelist=/home/user ls
)
None of these cases should really be failing. If there is some strange error correction going on, then the last one where the HOME is set should work.
The text was updated successfully, but these errors were encountered: