[GH-ISSUE #5837] Add a profile for x2goserver #3111

Closed
opened 2026-05-05 09:44:37 -06:00 by gitea-mirror · 1 comment
Owner

Originally created by @mabra on GitHub (May 24, 2023).
Original GitHub issue: https://github.com/netblue30/firejail/issues/5837

In my setup (to protect me from attempts of browsers to access any identifyable properties), I am using Firefox in a KVM machine and use this over x2go.
Found not way, to make sound possible, everything else looks working.

Describe the solution you'd like

I am not that deep in Linux, but seeing(!!), that an unprotected Fox communicates over the LO interface, while the jailed version cannot. From my understanding, the x2goserver uses the LO interface to redirect (the window and even) the sound, where the x2goagant bridges the traffic (from LO to the right interface). Using a terminal over x2go can "paplay" a sound.

Need a profile for the x2goserver!?
The network in this situation is already well protected by iptables and there is NO way out, except for a lan-based squid proxy (no auto, interface per browser-profile). In my situation, protecting Firefox to use the network is not necessary at all!?
Found no way to run Firefox with the normal network (probably too deept in the docs?), keeping all other protections by firejail in place.

Describe alternatives you've considered

Searching internet, considering netcat - too complicated for me at the moment.

Originally created by @mabra on GitHub (May 24, 2023). Original GitHub issue: https://github.com/netblue30/firejail/issues/5837 ### Is your feature request related to a problem? Please describe. In my setup (to protect me from attempts of browsers to access any identifyable properties), I am using Firefox in a KVM machine and use this over x2go. Found not way, to make sound possible, everything else looks working. ### Describe the solution you'd like I am not that deep in Linux, but seeing(!!), that an unprotected Fox communicates over the LO interface, while the jailed version cannot. From my understanding, the x2goserver uses the LO interface to redirect (the window and even) the sound, where the x2goagant bridges the traffic (from LO to the right interface). Using a terminal over x2go can "paplay" a sound. Need a profile for the x2goserver!? The network in this situation is already well protected by iptables and there is NO way out, except for a lan-based squid proxy (no auto, interface per browser-profile). In my situation, protecting Firefox to use the network is not necessary at all!? Found no way to run Firefox with the normal network (probably too deept in the docs?), keeping all other protections by firejail in place. ### Describe alternatives you've considered Searching internet, considering netcat - too complicated for me at the moment.
gitea-mirror 2026-05-05 09:44:37 -06:00
Author
Owner

@kmk3 commented on GitHub (Sep 10, 2024):

Duplicate of #1139

<!-- gh-comment-id:2340446492 --> @kmk3 commented on GitHub (Sep 10, 2024): Duplicate of #1139
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference: github-starred/firejail#3111
No description provided.