Using the default profile for Firefox in 0.9.62
I would like to allow Firefox access to a specific path under /media/drive/bla/bla/bla
What do i need to put under firefox.local ?
I tried noblacklist and whitelist but it doesnt work for /media/xxx
Try --noblacklist=/media or --ignore=disable-mnt
ignore disable-mnt
Edit: smitsohu was 1 second faster :rofl:
smitsohu: 2020-08-09T19:57:32Z
rusty-snake: 2020-08-09T19:57:33Z
Thanks guys.
Try
--noblacklist=/mediaor--ignore=disable-mnt
If i try either only --noblacklist=/media OR only --ignore=disable-mnt - this allows it but at the same time, it allows ALL drives to be accessed and obviously i dont want to allow other drives to be compromised/visible, however if i try only a complete specific path such as /media/dir1/dir2/dir3/dir4 it doesnt allow it as i originally mentioned.
So what i did was (as @rusty-snake also mentioned):
ignore disable-mnt
noblacklist /media/dir1/dir2/dir3/dir4
whitelist /media/dir1/dir2/dir3/dir4
This allowed Firefox the specific device's dir path but at the same time disallows all other drives mounted which is great, so is this the correct way to go about this?
Is there no other way besides ignore disable-mnt ?
@rusty-snake your comment here, i tried it, but firstly i get the error Error: only directories in user home or /tmp are supported by mkdir
It seems i cant get this to work. I dont want to blacklist specific drives. i actually want to blacklist or disable-mnt on all drives but one.
Is there another way to do this?
Basically since the below works and disallows the rest of the drives but with disable-mnt ignored, my question is, is this ok or is there a way the app could still get into the rest of the drives somehow?
ignore disable-mnt
noblacklist /media/dir1/dir2/dir3/dir4
whitelist /media/dir1/dir2/dir3/dir4
is there a way the app could still get into the rest of the drives somehow
noblacklist /media/dir1/dir2/dir3/dir4 this line is redundant, since there is no such backlist.
whitelist /media/dir1/dir2/dir3/dir4 this makes /media containing only dir1 or if dir1 is not present when the sandbox is started /media empty. However using gio/gvfs/kio over D-Bus may allow the app to see more drivers (but I don't believe that D-Bus is used to access files, this is very likely still done with open).
@rusty-snake thanks, noted.
Can you please explain what you mean its likely done with open ?
I'm closing here due to inactivity, please fell free to request to reopen if you still have this issue.
Most helpful comment
ignore disable-mntEdit: smitsohu was 1 second faster :rofl:
smitsohu: 2020-08-09T19:57:32Z
rusty-snake: 2020-08-09T19:57:33Z