mirror of
https://github.com/netblue30/firejail.git
synced 2026-05-15 14:16:14 -06:00
[GH-ISSUE #1735] New (detailed) firejail tutorial available - fact check review appreciated #1175
Labels
No labels
LTS merge
LTS merge
bug
bug
converted-to-discussion
doc-todo
documentation
duplicate
enhancement
file-transfer
firecfg
firejail-in-firejail
firetools
graphics
help wanted
information_old
installation
invalid
modif
moved
needinfo
networking
notabug
notourbug
old-version
overlayfs
packaging
profile-request
pull-request
question
question_old
removal
runtime-permissions
sandbox-ipc
security
stale
wiki
wiki
wontfix
wordpress
workaround
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference: github-starred/firejail#1175
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @sakaki- on GitHub (Jan 16, 2018).
Original GitHub issue: https://github.com/netblue30/firejail/issues/1735
Hi @netblue30,
I have just published a detailed addendum (first mentioned in #1600) to my EFI Install Guide on the Gentoo wiki, covering the use of
firejailto X11-sandboxfirefox(and potentially other applications) - the new document can be viewed here.While the installation instructions themselves are obviously quite Gentoo-specific, I have also included a fairly in-depth "background" section at the start (covering namespaces, seccomp etc.)... I've tried to make this as accurate as possible (based on your online docs, manpages and the source) but if you (or any of the other
firejailcontributors) could take a quick look and let me know of any obvious errors, I'd very much appreciate it.Thanks again for making
firejailavailable!sakaki
sakaki@deciban.com
@SkewedZeppelin commented on GitHub (Jan 16, 2018):
I'm not @netblue30, but I've read through most of it (skipped some Gentoo specific parts), and it is quite nice. 👍 I only have a few minor comments as listed below.
An easier way would be to run xlsclients.
Why not make a package for all those scripts?
OT: that is a neat way of managing that
IANAL, but afaik you could deploy the icon in a business environment as long as you aren't selling it to anyone. eg. an internal IT department could deploy that icon+.desktop file with no issue, but an (external and paid-for/contracted) MSP deploying that onto a businesses network would violate it.Reading some more it seems to depend on the specific license and location.Consider adding https://github.com/pyllyukko/user.js, the relaxed branch variant is very usable for day-to-day use.
Extra comments:
@sakaki- commented on GitHub (Jan 17, 2018):
@SpotComms, many thanks for taking the time to look through the doc. To your comments:
Agreed, I'll add that in. (The only nice thing about
xeyesis that you can leave it running in a corner and it acts as a constant reminder when you are using an X11 app.)I probably will at some point, I put the (baseline) scripts in as a teaching aid, really.
That's nice, hadn't seen it before. I'll add it.
No reason not to mention it... I'll add this too.
Wayland has got reasonably usable now (even with nvidia proprietary drivers), so I'm planning to change the GNOME install chapter of the guide to have the Wayland USE flag set by default (you can always elect to have a regular X11 session when logging in anyhow, so there's nothing really to lose by doing this).
Best, sakaki
@sakaki- commented on GitHub (Jan 23, 2018):
Hi, I've now removed the draft marker and linked this page into the EFI guide itself. Thanks for the comments received in this thread, and by email.
If you get a chance, perhaps you could put a link to this somewhere in the
firejailonline docs, or blog?Full URL: https://wiki.gentoo.org/wiki/Sakaki%27s_EFI_Install_Guide/Sandboxing_the_Firefox_Browser_with_Firejail
Thanks! sakaki
@sakaki- commented on GitHub (Jan 24, 2018):
Closing now so as not to clog your issues list ^-^