mirror of
https://github.com/netblue30/firejail.git
synced 2026-05-15 14:16:14 -06:00
[GH-ISSUE #791] warzone2100 profile #537
Labels
No labels
LTS merge
LTS merge
bug
bug
converted-to-discussion
doc-todo
documentation
duplicate
enhancement
file-transfer
firecfg
firejail-in-firejail
firetools
graphics
help wanted
information_old
installation
invalid
modif
moved
needinfo
networking
notabug
notourbug
old-version
overlayfs
packaging
profile-request
pull-request
question
question_old
removal
runtime-permissions
sandbox-ipc
security
stale
wiki
wiki
wontfix
wordpress
workaround
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference: github-starred/firejail#537
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @Laurent092 on GitHub (Sep 18, 2016).
Original GitHub issue: https://github.com/netblue30/firejail/issues/791
Hi netblue,
I tried to launch warzone2100 on debian 8.6 in a terminal : "firejail warzone2100" and i get this reply :
"Reading profile /etc/firejail/warzone2100.profile
Reading profile /etc/firejail/disable-common.inc
Reading profile /etc/firejail/disable-devel.inc
Reading profile /etc/firejail/disable-passwdmgr.inc
Reading profile /etc/firejail/disable-programs.inc
Parent pid 5395, child pid 5396
Blacklist violations are logged to syslog
Child process initialized
info |09:36:56: [realmain:1145] Using /home/francois/.warzone2100-3.1/logs/WZlog-0918_093656.txt debug file
X Error of failed request: BadValue (integer parameter out of range for operation)
Major opcode of failed request: 155 (GLX)
Minor opcode of failed request: 3 (X_GLXCreateContext)
Value in failed request: 0x0
Serial number of failed request: 26
Current serial number in output stream: 27
Parent is shutting down, bye..."
Thanks ;)
Laurent.
@netblue30 commented on GitHub (Sep 18, 2016):
In a text editor open /etc/firejail/warzone2100.profile and comment out (add a #) the lines there. One of them is creating the problem, I would suspect private-dev. Also, can you do a "ls -l /dev", I am looking for the nvidia driver files to add them to private-dev by default. Thanks.
@Laurent092 commented on GitHub (Sep 21, 2016):
$ ls -l /dev
total 0
crw------- 1 root root 10, 235 sept. 21 13:48 autofs
drwxr-xr-x 2 root root 100 sept. 21 13:48 block
drwxr-xr-x 2 root root 60 sept. 21 13:48 bsg
crw------- 1 root root 10, 234 sept. 21 13:48 btrfs-control
drwxr-xr-x 3 root root 60 sept. 21 13:48 bus
drwxr-xr-x 2 root root 2960 sept. 21 13:48 char
crw------- 1 root root 5, 1 sept. 21 13:48 console
lrwxrwxrwx 1 root root 11 sept. 21 13:48 core -> /proc/kcore
drwxr-xr-x 2 root root 60 sept. 21 13:47 cpu
crw------- 1 root root 10, 62 sept. 21 13:48 cpu_dma_latency
crw------- 1 root root 10, 203 sept. 21 13:48 cuse
drwxr-xr-x 4 root root 80 sept. 21 13:48 disk
drwxr-xr-x 2 root root 60 sept. 21 13:48 dri
lrwxrwxrwx 1 root root 13 sept. 21 13:48 fd -> /proc/self/fd
crw-rw-rw- 1 root root 1, 7 sept. 21 13:48 full
crw-rw-rw- 1 root root 10, 229 sept. 21 13:48 fuse
crw------- 1 root root 251, 0 sept. 21 13:48 hidraw0
crw------- 1 root root 251, 1 sept. 21 13:48 hidraw1
crw------- 1 root root 10, 228 sept. 21 13:48 hpet
drwxr-xr-x 2 root root 0 sept. 21 13:48 hugepages
lrwxrwxrwx 1 root root 25 sept. 21 13:48 initctl -> /run/systemd/initctl/fifo
drwxr-xr-x 4 root root 380 sept. 21 13:48 input
crw-r--r-- 1 root root 1, 11 sept. 21 13:48 kmsg
lrwxrwxrwx 1 root root 28 sept. 21 13:48 log -> /run/systemd/journal/dev-log
crw-rw---- 1 root disk 10, 237 sept. 21 13:48 loop-control
drwxr-xr-x 2 root root 60 sept. 21 13:48 mapper
crw------- 1 root root 10, 227 sept. 21 13:48 mcelog
crw-r----- 1 root kmem 1, 1 sept. 21 13:48 mem
drwxrwxrwt 2 root root 40 sept. 21 13:47 mqueue
drwxr-xr-x 2 root root 60 sept. 21 13:48 net
crw------- 1 root root 10, 61 sept. 21 13:48 network_latency
crw------- 1 root root 10, 60 sept. 21 13:48 network_throughput
crw-rw-rw- 1 root root 1, 3 sept. 21 13:48 null
crw-rw-rw- 1 root root 195, 0 sept. 21 13:48 nvidia0
crw-rw-rw- 1 root root 195, 255 sept. 21 13:48 nvidiactl
crw-r----- 1 root kmem 1, 4 sept. 21 13:48 port
crw------- 1 root root 108, 0 sept. 21 13:48 ppp
crw------- 1 root root 10, 1 sept. 21 13:48 psaux
crw-rw-rw- 1 root tty 5, 2 sept. 21 20:06 ptmx
drwxr-xr-x 2 root root 0 sept. 21 13:47 pts
crw-rw-rw- 1 root root 1, 8 sept. 21 13:48 random
lrwxrwxrwx 1 root root 4 sept. 21 13:48 rtc -> rtc0
crw------- 1 root root 254, 0 sept. 21 13:48 rtc0
brw-rw---- 1 root disk 8, 0 sept. 21 13:48 sda
brw-rw---- 1 root disk 8, 1 sept. 21 13:48 sda1
brw-rw---- 1 root disk 8, 2 sept. 21 13:48 sda2
crw-rw---- 1 root disk 21, 0 sept. 21 13:48 sg0
drwxrwxrwt 2 root root 40 sept. 21 13:48 shm
crw------- 1 root root 10, 231 sept. 21 13:48 snapshot
drwxr-xr-x 3 root root 220 sept. 21 13:48 snd
lrwxrwxrwx 1 root root 15 sept. 21 13:48 stderr -> /proc/self/fd/2
lrwxrwxrwx 1 root root 15 sept. 21 13:48 stdin -> /proc/self/fd/0
lrwxrwxrwx 1 root root 15 sept. 21 13:48 stdout -> /proc/self/fd/1
crw-rw-rw- 1 root tty 5, 0 sept. 21 13:48 tty
crw--w---- 1 root tty 4, 0 sept. 21 13:48 tty0
crw--w---- 1 root tty 4, 1 sept. 21 13:48 tty1
crw--w---- 1 root tty 4, 10 sept. 21 13:48 tty10
crw--w---- 1 root tty 4, 11 sept. 21 13:48 tty11
crw--w---- 1 root tty 4, 12 sept. 21 13:48 tty12
crw--w---- 1 root tty 4, 13 sept. 21 13:48 tty13
crw--w---- 1 root tty 4, 14 sept. 21 13:48 tty14
crw--w---- 1 root tty 4, 15 sept. 21 13:48 tty15
crw--w---- 1 root tty 4, 16 sept. 21 13:48 tty16
crw--w---- 1 root tty 4, 17 sept. 21 13:48 tty17
crw--w---- 1 root tty 4, 18 sept. 21 13:48 tty18
crw--w---- 1 root tty 4, 19 sept. 21 13:48 tty19
crw--w---- 1 root tty 4, 2 sept. 21 13:48 tty2
crw--w---- 1 root tty 4, 20 sept. 21 13:48 tty20
crw--w---- 1 root tty 4, 21 sept. 21 13:48 tty21
crw--w---- 1 root tty 4, 22 sept. 21 13:48 tty22
crw--w---- 1 root tty 4, 23 sept. 21 13:48 tty23
crw--w---- 1 root tty 4, 24 sept. 21 13:48 tty24
crw--w---- 1 root tty 4, 25 sept. 21 13:48 tty25
crw--w---- 1 root tty 4, 26 sept. 21 13:48 tty26
crw--w---- 1 root tty 4, 27 sept. 21 13:48 tty27
crw--w---- 1 root tty 4, 28 sept. 21 13:48 tty28
crw--w---- 1 root tty 4, 29 sept. 21 13:48 tty29
crw--w---- 1 root tty 4, 3 sept. 21 13:48 tty3
crw--w---- 1 root tty 4, 30 sept. 21 13:48 tty30
crw--w---- 1 root tty 4, 31 sept. 21 13:48 tty31
crw--w---- 1 root tty 4, 32 sept. 21 13:48 tty32
crw--w---- 1 root tty 4, 33 sept. 21 13:48 tty33
crw--w---- 1 root tty 4, 34 sept. 21 13:48 tty34
crw--w---- 1 root tty 4, 35 sept. 21 13:48 tty35
crw--w---- 1 root tty 4, 36 sept. 21 13:48 tty36
crw--w---- 1 root tty 4, 37 sept. 21 13:48 tty37
crw--w---- 1 root tty 4, 38 sept. 21 13:48 tty38
crw--w---- 1 root tty 4, 39 sept. 21 13:48 tty39
crw--w---- 1 root tty 4, 4 sept. 21 13:48 tty4
crw--w---- 1 root tty 4, 40 sept. 21 13:48 tty40
crw--w---- 1 root tty 4, 41 sept. 21 13:48 tty41
crw--w---- 1 root tty 4, 42 sept. 21 13:48 tty42
crw--w---- 1 root tty 4, 43 sept. 21 13:48 tty43
crw--w---- 1 root tty 4, 44 sept. 21 13:48 tty44
crw--w---- 1 root tty 4, 45 sept. 21 13:48 tty45
crw--w---- 1 root tty 4, 46 sept. 21 13:48 tty46
crw--w---- 1 root tty 4, 47 sept. 21 13:48 tty47
crw--w---- 1 root tty 4, 48 sept. 21 13:48 tty48
crw--w---- 1 root tty 4, 49 sept. 21 13:48 tty49
crw--w---- 1 root tty 4, 5 sept. 21 13:48 tty5
crw--w---- 1 root tty 4, 50 sept. 21 13:48 tty50
crw--w---- 1 root tty 4, 51 sept. 21 13:48 tty51
crw--w---- 1 root tty 4, 52 sept. 21 13:48 tty52
crw--w---- 1 root tty 4, 53 sept. 21 13:48 tty53
crw--w---- 1 root tty 4, 54 sept. 21 13:48 tty54
crw--w---- 1 root tty 4, 55 sept. 21 13:48 tty55
crw--w---- 1 root tty 4, 56 sept. 21 13:48 tty56
crw--w---- 1 root tty 4, 57 sept. 21 13:48 tty57
crw--w---- 1 root tty 4, 58 sept. 21 13:48 tty58
crw--w---- 1 root tty 4, 59 sept. 21 13:48 tty59
crw--w---- 1 root tty 4, 6 sept. 21 13:48 tty6
crw--w---- 1 root tty 4, 60 sept. 21 13:48 tty60
crw--w---- 1 root tty 4, 61 sept. 21 13:48 tty61
crw--w---- 1 root tty 4, 62 sept. 21 13:48 tty62
crw--w---- 1 root tty 4, 63 sept. 21 13:48 tty63
crw--w---- 1 root tty 4, 7 sept. 21 13:48 tty7
crw--w---- 1 root tty 4, 8 sept. 21 13:48 tty8
crw--w---- 1 root tty 4, 9 sept. 21 13:48 tty9
crw-rw---- 1 root dialout 4, 64 sept. 21 13:48 ttyS0
crw-rw---- 1 root dialout 4, 65 sept. 21 13:48 ttyS1
crw-rw---- 1 root dialout 4, 66 sept. 21 13:48 ttyS2
crw-rw---- 1 root dialout 4, 67 sept. 21 13:48 ttyS3
crw------- 1 root root 10, 239 sept. 21 13:48 uhid
crw------- 1 root root 10, 223 sept. 21 13:48 uinput
crw-rw-rw- 1 root root 1, 9 sept. 21 13:48 urandom
drwxr-xr-x 2 root root 60 sept. 21 13:48 usb
crw-rw---- 1 root tty 7, 0 sept. 21 13:48 vcs
crw-rw---- 1 root tty 7, 1 sept. 21 13:48 vcs1
crw-rw---- 1 root tty 7, 2 sept. 21 13:48 vcs2
crw-rw---- 1 root tty 7, 3 sept. 21 13:48 vcs3
crw-rw---- 1 root tty 7, 4 sept. 21 13:48 vcs4
crw-rw---- 1 root tty 7, 5 sept. 21 13:48 vcs5
crw-rw---- 1 root tty 7, 6 sept. 21 13:48 vcs6
crw-rw---- 1 root tty 7, 7 sept. 21 13:48 vcs7
crw-rw---- 1 root tty 7, 128 sept. 21 13:48 vcsa
crw-rw---- 1 root tty 7, 129 sept. 21 13:48 vcsa1
crw-rw---- 1 root tty 7, 130 sept. 21 13:48 vcsa2
crw-rw---- 1 root tty 7, 131 sept. 21 13:48 vcsa3
crw-rw---- 1 root tty 7, 132 sept. 21 13:48 vcsa4
crw-rw---- 1 root tty 7, 133 sept. 21 13:48 vcsa5
crw-rw---- 1 root tty 7, 134 sept. 21 13:48 vcsa6
crw-rw---- 1 root tty 7, 135 sept. 21 13:48 vcsa7
drwxr-xr-x 2 root root 60 sept. 21 13:48 vfio
crw------- 1 root root 10, 63 sept. 21 13:48 vga_arbiter
crw------- 1 root root 10, 137 sept. 21 13:48 vhci
crw------- 1 root root 10, 238 sept. 21 13:48 vhost-net
crw------- 1 root root 10, 130 sept. 21 13:48 watchdog
crw------- 1 root root 253, 0 sept. 21 13:48 watchdog0
prw-r----- 1 root adm 0 sept. 21 13:48 xconsole
crw-rw-rw- 1 root root 1, 5 sept. 21 13:48 zero
@netblue30 commented on GitHub (Sep 22, 2016):
The problem was --private-dev was removing nvidiactl and nvidia0 drivers. I put a fix in git, now --private-dev also keeps nvidia0 and nvidiactl drivers. Thanks for the bug.
restricted-networkprevent use of netfilter #3658