Replies: 6 comments 9 replies
-
You can not execute firejail/etc/profile-m-z/w3m.profile Line 61 in e55c3bf To fix this you can either temporarly add it when you start w3m with The same applies to bash and fish. However if you do not specify a command when joining, firejail uses your shell and has special handling to work even when it's missing in the sandbox IIRC. |
Beta Was this translation helpful? Give feedback.
-
@rusty-snake : I tried it:
It started the browser alright, but joing still failed:
...
Sorry, but I don´t quite understand. Could you explain it further? Many greetings P.S.: I also tried
It didn´t work either. |
Beta Was this translation helpful? Give feedback.
-
So sorry, still no luck: That´s o.k. Then:
also:
Thanks and cheers |
Beta Was this translation helpful? Give feedback.
-
Hi again and thanks for your help.
So (step 2) provided me with this output now:
... which confirms that indeed the DNS server 1.1.1.1 is used by the first command.
That must have been it. It seems my firejail is version 0.9.66. This one doesn´t seem to support "--keep-fd" option. ...
Issuing the command with
Thanks so much for your help. Many greetings from Rosika 🙂 |
Beta Was this translation helpful? Give feedback.
-
From
I was just wondering what the "fs" part stands for. Might it be "file descriptor" by any chance? Cheers from Rosika 🙂 |
Beta Was this translation helpful? Give feedback.
-
Hi @rusty-snake, 👋 thank you so much for providing your hardened DNS setup. It´s much appreciated. 😗 To be honest, I have to take a very close look at it a few times more in order to even begin to understand it a little. But it´s worth the effort.
O.K. E.g. I noticed that
So I might download Fedora and install it in a virtual machine to be able to follow your steps. I´ll also draw my friend´s attention to it as he is also very interested in your DNS setup. BTW: Thanks a lot again for your kind help and perseverance. ❤️ Many greetings from Rosika 🙂 |
Beta Was this translation helpful? Give feedback.
-
Hi all, 👋
I have a query about (probably) firejail permissions.
My system is: Linux Lite 6.2, 64 bit (which is based on Ubuntu).
Here´s the scenario:
I start a browser instance (w3m) in a private directory the following way:
firejail --private=/home/rosika/Musik/kgw/ --dns=1.1.1.1 --dns=9.9.9.9 w3m "duckduckgo.com"
To check the working state of the DNS settings I join the sandbox identified by PID thus (the pid of the running sandbox instance is 30391):
firejail --join=30391
From here I´d like to issue the nslookup command, which doesn´t seem to be allowed:
(BTW: my default shell is fish)
Now I change to bash and try to use the command from there:
Curious thing though: The same procedure seems to work when using it on my Debian system.
What might be the cause of not being allowed to use the nslookup command this way ❓
Is there a way around it?
Thanks a lot in advance.
Many greetings from Rosika 🙂
Beta Was this translation helpful? Give feedback.
All reactions