Firejail: Split up disable-mnt

Created on 9 Oct 2018  路  6Comments  路  Source: netblue30/firejail

We should split disable-mnt into two different directives (disable-mnt and disable-media) to make things more granular.

enhancement

Most helpful comment

I think splitting disable-media will only add maintenance burden as there will be yet another option to add to each profile. Changing it behavior to work as --blacklist=/media --blacklist=/run/media --blacklist=/mnt which will be overridable by --noblacklist sounds much better.

All 6 comments

Alternate proposal by @smitsohu: Turn disable-mnt into a set of ordinary blacklist commands, which can be overridden as usual with noblacklist.

Adding some advertisement for my own proposal: I doesn't change the meaning of an existing option and hence doesn't create a need to update existing profiles.
Also I recall people actually trying to noblacklist /media or /mnt in order to get their setup running, and posting to the bug tracker because that didn't work.

We have disable-mnt in firetools GUI. Replacing it with blacklists in profile files should be fine.

@smitsohu Would disable-mnt just blacklist /mnt as a whole?

@Fred-Barclay Like it does currently, yes.

I think splitting disable-media will only add maintenance burden as there will be yet another option to add to each profile. Changing it behavior to work as --blacklist=/media --blacklist=/run/media --blacklist=/mnt which will be overridable by --noblacklist sounds much better.

Was this page helpful?
0 / 5 - 0 ratings

Related issues

SkewedZeppelin picture SkewedZeppelin  路  3Comments

ghost picture ghost  路  3Comments

ericschdt picture ericschdt  路  3Comments

polyzen picture polyzen  路  4Comments

reinerh picture reinerh  路  3Comments