[GH-ISSUE #1244] Using --trace to generate initial profiles #848

Closed
opened 2026-05-05 06:58:29 -06:00 by gitea-mirror · 2 comments
Owner

Originally created by @reinerh on GitHub (Apr 23, 2017).
Original GitHub issue: https://github.com/netblue30/firejail/issues/1244

Petter Reinholdtsen had the idea on the Debian BTS to use the output from the --trace command to generate initial/draft profiles, because it already reports if an application tries to open a file or create a socket.
Maybe an additional tool could parse the trace output and generate a profile out of it.

Originally created by @reinerh on GitHub (Apr 23, 2017). Original GitHub issue: https://github.com/netblue30/firejail/issues/1244 Petter Reinholdtsen had the idea on the [Debian BTS](https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=860942#15) to use the output from the --trace command to generate initial/draft profiles, because it already reports if an application tries to open a file or create a socket. Maybe an additional tool could parse the trace output and generate a profile out of it.
gitea-mirror 2026-05-05 06:58:29 -06:00
Author
Owner

@netblue30 commented on GitHub (Apr 26, 2017):

Btw, it might be a good idea to add the --trace usage to the EXAMPLES section in the firejail(1) manual page. If it had been there, I might have used it instead of creating this BTS report. :)

I'll add and example in the man page. We'll build an "autoprofiler", at least something to create a starting point for building a profile.

<!-- gh-comment-id:297380375 --> @netblue30 commented on GitHub (Apr 26, 2017): > Btw, it might be a good idea to add the --trace usage to the EXAMPLES section in the firejail(1) manual page. If it had been there, I might have used it instead of creating this BTS report. :) I'll add and example in the man page. We'll build an "autoprofiler", at least something to create a starting point for building a profile.
Author
Owner

@chiraag-nataraj commented on GitHub (Jul 23, 2018):

We have the --build command-line argument now, so closing this.

<!-- gh-comment-id:406915894 --> @chiraag-nataraj commented on GitHub (Jul 23, 2018): We have the `--build` command-line argument now, so closing this.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference: github-starred/firejail#848
No description provided.