[GH-ISSUE #136] Need To Allow Process Fork Whitelisting #88

Closed
opened 2026-05-05 05:01:01 -06:00 by gitea-mirror · 6 comments
Owner

Originally created by @ilikenwf on GitHub (Nov 15, 2015).
Original GitHub issue: https://github.com/netblue30/firejail/issues/136

I am unable to launch default applications (eg Transgui for transmission) with the current stable release on Archlinux, which makes downloading Linux isos somwhat more troublesome as it requires saving the torrent (or whatever other file) to ~/Downloads and then opening it externally.

At one point, I managed to launch transgui but due to the nature of the sandboxing, the configuration wasn't there since we don't have that directory whitelisted. Is this seccomp.

Originally created by @ilikenwf on GitHub (Nov 15, 2015). Original GitHub issue: https://github.com/netblue30/firejail/issues/136 I am unable to launch default applications (eg Transgui for transmission) with the current stable release on Archlinux, which makes downloading Linux isos somwhat more troublesome as it requires saving the torrent (or whatever other file) to ~/Downloads and then opening it externally. At one point, I managed to launch transgui but due to the nature of the sandboxing, the configuration wasn't there since we don't have that directory whitelisted. Is this seccomp.
gitea-mirror 2026-05-05 05:01:01 -06:00
  • closed this issue
  • added the
    bug
    label
Author
Owner

@netblue30 commented on GitHub (Nov 16, 2015):

Transmission doesn't whitelist any file or directory, all directories should be available under /home/user. What exactly is your setup?

<!-- gh-comment-id:157025223 --> @netblue30 commented on GitHub (Nov 16, 2015): Transmission doesn't whitelist any file or directory, all directories should be available under /home/user. What exactly is your setup?
Author
Owner

@ilikenwf commented on GitHub (Nov 16, 2015):

Firefox running in firejail, while attempting to add a torrent or magnet
link via Firefox's associations, to transmission GUI, which can either be
open or closed.

Both ways no longer work, I'd have to look at my backups and see what
version of Firejail I was running previously, but that version did work
with my filetype associations for opening things.

On Mon, Nov 16, 2015 at 7:18 AM, netblue30 notifications@github.com wrote:

Transmission doesn't whitelist any file or directory, all directories
should be available under /home/user. What exactly is your setup?


Reply to this email directly or view it on GitHub
https://github.com/netblue30/firejail/issues/136#issuecomment-157025223.

<!-- gh-comment-id:157059907 --> @ilikenwf commented on GitHub (Nov 16, 2015): Firefox running in firejail, while attempting to add a torrent or magnet link via Firefox's associations, to transmission GUI, which can either be open or closed. Both ways no longer work, I'd have to look at my backups and see what version of Firejail I was running previously, but that version did work with my filetype associations for opening things. On Mon, Nov 16, 2015 at 7:18 AM, netblue30 notifications@github.com wrote: > Transmission doesn't whitelist any file or directory, all directories > should be available under /home/user. What exactly is your setup? > > — > Reply to this email directly or view it on GitHub > https://github.com/netblue30/firejail/issues/136#issuecomment-157025223.
Author
Owner

@netblue30 commented on GitHub (Nov 17, 2015):

I use transmission-gtk myself. I have firefox working in a sandbox, and transmission-gtk open in another sandbox. I grab with the mouse the magnet link and release it in the transmission window and it works.

If you click on a torrent or a magnet, firefox associations will instruct the browser to start transmission in the same sandbox. Your sandbox whitelisting should take in account the fact that you intend to run both firefox and transmission. I will investigate further.

<!-- gh-comment-id:157375831 --> @netblue30 commented on GitHub (Nov 17, 2015): I use transmission-gtk myself. I have firefox working in a sandbox, and transmission-gtk open in another sandbox. I grab with the mouse the magnet link and release it in the transmission window and it works. If you click on a torrent or a magnet, firefox associations will instruct the browser to start transmission in the same sandbox. Your sandbox whitelisting should take in account the fact that you intend to run both firefox and transmission. I will investigate further.
Author
Owner

@ilikenwf commented on GitHub (Nov 17, 2015):

Ah, nice. I would use gtk if it would stop crashing (unrelated).

I didn't consider dragging - I'll have to try that.

On Tue, Nov 17, 2015 at 7:55 AM, netblue30 notifications@github.com wrote:

I use transmission-gtk myself. I have firefox working in a sandbox, and
transmission-gtk open in another sandbox. I grab with the mouse the magnet
link and release it in the transmission window and it works.

If you click on a torrent or a magnet, firefox associations will instruct
the browser to start transmission in the same sandbox. Your sandbox
whitelisting should take in account the fact that you intend to run both
firefox and transmission. I will investigate further.


Reply to this email directly or view it on GitHub
https://github.com/netblue30/firejail/issues/136#issuecomment-157375831.

<!-- gh-comment-id:157425657 --> @ilikenwf commented on GitHub (Nov 17, 2015): Ah, nice. I would use gtk if it would stop crashing (unrelated). I didn't consider dragging - I'll have to try that. On Tue, Nov 17, 2015 at 7:55 AM, netblue30 notifications@github.com wrote: > I use transmission-gtk myself. I have firefox working in a sandbox, and > transmission-gtk open in another sandbox. I grab with the mouse the magnet > link and release it in the transmission window and it works. > > If you click on a torrent or a magnet, firefox associations will instruct > the browser to start transmission in the same sandbox. Your sandbox > whitelisting should take in account the fact that you intend to run both > firefox and transmission. I will investigate further. > > — > Reply to this email directly or view it on GitHub > https://github.com/netblue30/firejail/issues/136#issuecomment-157375831.
Author
Owner

@netblue30 commented on GitHub (Nov 17, 2015):

Try transmission-qt, it's the same thing, just another graphic toolkit.

<!-- gh-comment-id:157440091 --> @netblue30 commented on GitHub (Nov 17, 2015): Try transmission-qt, it's the same thing, just another graphic toolkit.
Author
Owner

@ilikenwf commented on GitHub (Nov 17, 2015):

Yeah, its what I use, and despite being an xfce user it is more stable.
On Nov 17, 2015 1:24 PM, "netblue30" notifications@github.com wrote:

Try transmission-qt, it's the same thing, just another graphic toolkit.


Reply to this email directly or view it on GitHub
https://github.com/netblue30/firejail/issues/136#issuecomment-157440091.

<!-- gh-comment-id:157489373 --> @ilikenwf commented on GitHub (Nov 17, 2015): Yeah, its what I use, and despite being an xfce user it is more stable. On Nov 17, 2015 1:24 PM, "netblue30" notifications@github.com wrote: > Try transmission-qt, it's the same thing, just another graphic toolkit. > > — > Reply to this email directly or view it on GitHub > https://github.com/netblue30/firejail/issues/136#issuecomment-157440091.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference: github-starred/firejail#88
No description provided.