Mephistopheles: "Let's install Firejail again..."
And I did. After it screwed up my system or rather my Calibre and its merry gang and I deleted it all when realizing I was in way over my head. Okay, I swore by all that's holy I will never, ever type "$ sudo firecfg" into a terminal again. And keeping the uninstall instructions handy, just in case.
But I installed it all anyway, Firejail, Firejail-profile and Firetool. By the way, Firetool once again sits there and seems to do nothing. As I see it, all I can do with it is pick one single application from its list and put it in a temporary sandbox. After kicking the Firejail icons out of the panel, it seems to be gone. At least little Max says so:
So do I understand that right that Firetools allows to put up a temporary sandbox that will be gone as soon the Firejail icons are removed from the panel?
Does anyone know if I could put a folder i.e. a directory in a sandbox? I tried with Firetools, but it won't let me.
Then, I tried to put Librewolf into Firejail, this time using the terminal:
Seems it didn't work, and all I can see is the damn thing obviously doesn't like my new icons... what the fig?? I mean, what on earth have the icons to do with anything? I mean, if I load an image in, say, mirage, it doesn't tell me, "Hey, I don't like that horse in that picture, load another one..."
At least it didn't have any lasting effect:
Most websites I saw seem to go the all or nothing route, a ka "do firecfg and it takes care of everything".
What, if I only want, say Firefox, Librewolf, and Thunderbird in a sandbox? Then, maybe, another sandbox that will keep programs like maybe Clementine or Calibre from poking around in the internet looking for titles or whatnot - which I don't want them to do. I put everything in there myself and that's that. If I need a title or a cover or whatever I go look for it myself.
Or rather: do I even need Firejail?
And I did. After it screwed up my system or rather my Calibre and its merry gang and I deleted it all when realizing I was in way over my head. Okay, I swore by all that's holy I will never, ever type "$ sudo firecfg" into a terminal again. And keeping the uninstall instructions handy, just in case.
But I installed it all anyway, Firejail, Firejail-profile and Firetool. By the way, Firetool once again sits there and seems to do nothing. As I see it, all I can do with it is pick one single application from its list and put it in a temporary sandbox. After kicking the Firejail icons out of the panel, it seems to be gone. At least little Max says so:
Code:
owl@Max:~
$ firejail --list
owl@Max:~
So do I understand that right that Firetools allows to put up a temporary sandbox that will be gone as soon the Firejail icons are removed from the panel?
Does anyone know if I could put a folder i.e. a directory in a sandbox? I tried with Firetools, but it won't let me.
Then, I tried to put Librewolf into Firejail, this time using the terminal:
Code:
$ firejail librewolf
Reading profile /etc/firejail/librewolf.profile
Reading profile /etc/firejail/whitelist-usr-share-common.inc
Reading profile /etc/firejail/firefox-common.profile
Reading profile /etc/firejail/disable-common.inc
Reading profile /etc/firejail/disable-devel.inc
Reading profile /etc/firejail/disable-exec.inc
Reading profile /etc/firejail/disable-interpreters.inc
Reading profile /etc/firejail/disable-proc.inc
Reading profile /etc/firejail/disable-programs.inc
Reading profile /etc/firejail/whitelist-common.inc
Reading profile /etc/firejail/whitelist-run-common.inc
Reading profile /etc/firejail/whitelist-runuser-common.inc
Reading profile /etc/firejail/whitelist-var-common.inc
Warning: networking feature is disabled in Firejail configuration file
Seccomp list in: !chroot, check list: @default-keep, prelist: unknown,
Parent pid 28099, child pid 28102
Warning: An abstract unix socket for session D-BUS might still be available. Use --net or remove unix from --protocol set.
Seccomp list in: !chroot, check list: @default-keep, prelist: unknown,
Warning: cleaning all supplementary groups
Warning: Replacing profile instead of stacking it. It is a legacy behavior that can result in relaxation of the protection. It is here as a temporary measure to unbreak the software that has been broken by switching to the stacking behavior.
Warning: Cannot confine the application using AppArmor.
Maybe firejail-default AppArmor profile is not loaded into the kernel.
As root, run "aa-enforce firejail-default" to load it.
Child process initialized in 232.90 ms
[Parent 9, Main Thread] WARNING: Theme directory scalable/actions of theme buuf-icons-for-plasma has no size field
: 'glib warning', file /root/.local/share/bsys6/work/librewolf-144.0-1/toolkit/xre/nsSigHandlers.cpp:201
(librewolf:9): Gtk-WARNING **: 14:48:57.181: Theme directory scalable/actions of theme buuf-icons-for-plasma has no size field
[Parent 9, Main Thread] WARNING: Theme directory scalable/actions/small/16x16 of theme buuf-icons-for-plasma has no size field
: 'glib warning', file /root/.local/share/bsys6/work/librewolf-144.0-1/toolkit/xre/nsSigHandlers.cpp:201
(librewolf:9): Gtk-WARNING **: 14:48:57.181: Theme directory scalable/actions/small/16x16 of theme buuf-icons-for-plasma has no size field
[Parent 9, Main Thread] WARNING: Theme directory scalable/actions/small/22x22 of theme buuf-icons-for-plasma has no size field
: 'glib warning', file /root/.local/share/bsys6/work/librewolf-144.0-1/toolkit/xre/nsSigHandlers.cpp:201
(librewolf:9): Gtk-WARNING **: 14:48:57.181: Theme directory scalable/actions/small/22x22 of theme buuf-icons-for-plasma has no size field
Parent is shutting down, bye...
owl@Max:~
Seems it didn't work, and all I can see is the damn thing obviously doesn't like my new icons... what the fig?? I mean, what on earth have the icons to do with anything? I mean, if I load an image in, say, mirage, it doesn't tell me, "Hey, I don't like that horse in that picture, load another one..."
At least it didn't have any lasting effect:
Code:
owl@Max:~
$ firejail --list
owl@Max:~
Most websites I saw seem to go the all or nothing route, a ka "do firecfg and it takes care of everything".
What, if I only want, say Firefox, Librewolf, and Thunderbird in a sandbox? Then, maybe, another sandbox that will keep programs like maybe Clementine or Calibre from poking around in the internet looking for titles or whatnot - which I don't want them to do. I put everything in there myself and that's that. If I need a title or a cover or whatever I go look for it myself.
Or rather: do I even need Firejail?

