Firejail: Expand the directories that are possible for whitelisting

Created on 10 Jul 2016  路  5Comments  路  Source: netblue30/firejail

Currently only $HOME, /dev, /media, /opt, /var, and /tmp can be used for whitelisting. It would be very helpful there could be an option to include other directories.

Or if that is too cumbersome, perhaps could you allow for /data/ to be whitelisted?? I noticed one other person wanting to use that particular directory.

enhancement

Most helpful comment

No problem, it can definitely be done in a generic way. I also have a similar request for /lib and /usr/lib and such.

So, I will bring in a generic whitelist for any directory under /, and private-lib support.

All 5 comments

Some other directories are covered by --private options:

--private-bin: handles /bin, /sbin, /usr/bin, /usr/sbin, /usr/local/bin, /usr/local/sbin

--private-etc: /etc

What other directory do you have in mind?

/data
Sorry if it's not POSIX compliant... Otherwise I have to manually remove/modify a lot of whitelists in de default configs. But if you had a generic way of allowing people to choose, you wouldn't need to respond to every new request from erratic users. :-)

No problem, it can definitely be done in a generic way. I also have a similar request for /lib and /usr/lib and such.

So, I will bring in a generic whitelist for any directory under /, and private-lib support.

@netblue30,

I will bring in a generic whitelist for any directory under /

I'd VERY like to finally see that ASAP (and same for mkdir too)! 馃榾

Is it something that blocks you from doing that? Or, will you, at least, accept a PR with such modifications?

Let's move this to #2041, since private-lib has been added, but generic whitelist has not (yet) made it in.

Was this page helpful?
0 / 5 - 0 ratings

Related issues

Fincer picture Fincer  路  4Comments

ghost picture ghost  路  3Comments

dandelionred picture dandelionred  路  3Comments

reinerh picture reinerh  路  3Comments

ericschdt picture ericschdt  路  3Comments