[GH-ISSUE #1041] Ability to launch an entire xsession from lightdm? #708

Open
opened 2026-05-05 06:29:11 -06:00 by gitea-mirror · 5 comments
Owner

Originally created by @aanderse on GitHub (Jan 11, 2017).
Original GitHub issue: https://github.com/netblue30/firejail/issues/1041

Hello,

I'm looking to have an entire user xsession (and every application/process that can be launched by a user) run under a firejail environment. I essentially want to sandbox a user from the rest of the system as soon as they login to either lightdm or ssh. Is this possible, and if so how do I go about setting this up?

Thank you,
Aaron

Originally created by @aanderse on GitHub (Jan 11, 2017). Original GitHub issue: https://github.com/netblue30/firejail/issues/1041 Hello, I'm looking to have an entire user xsession (and every application/process that can be launched by a user) run under a firejail environment. I essentially want to sandbox a user from the rest of the system as soon as they login to either lightdm or ssh. Is this possible, and if so how do I go about setting this up? Thank you, Aaron
gitea-mirror added the
enhancement
label 2026-05-05 06:29:11 -06:00
Author
Owner

@netblue30 commented on GitHub (Jan 12, 2017):

This would be very cool! I'll try it out.

<!-- gh-comment-id:272186995 --> @netblue30 commented on GitHub (Jan 12, 2017): This would be very cool! I'll try it out.
Author
Owner

@chiraag-nataraj commented on GitHub (Jul 26, 2018):

But wouldn't that sandbox necessarily have to be somewhat lax? And if so, how useful is it really?

<!-- gh-comment-id:407936580 --> @chiraag-nataraj commented on GitHub (Jul 26, 2018): But wouldn't that sandbox necessarily have to be somewhat lax? And if so, how useful is it really?
Author
Owner

@aanderse commented on GitHub (Jul 26, 2018):

For something like Kodi I would find it very useful.

<!-- gh-comment-id:407938409 --> @aanderse commented on GitHub (Jul 26, 2018): For something like Kodi I would find it very useful.
Author
Owner

@chiraag-nataraj commented on GitHub (Jul 26, 2018):

Hmm, I see. So more for a special-purpose X session.

<!-- gh-comment-id:407939499 --> @chiraag-nataraj commented on GitHub (Jul 26, 2018): Hmm, I see. So more for a special-purpose X session.
Author
Owner

@chiraag-nataraj commented on GitHub (Jul 30, 2018):

What happens if you change the session files to launch firejail lightdm or similar? I have no idea how these programs work anymore (I launch my X session with startx...), but I think the files are either in /etc or /usr/share.

<!-- gh-comment-id:408976122 --> @chiraag-nataraj commented on GitHub (Jul 30, 2018): What happens if you change the session files to launch `firejail lightdm` or similar? I have no idea how these programs work anymore (I launch my X session with `startx`...), but I think the files are either in `/etc` or `/usr/share`.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference: github-starred/firejail#708
No description provided.