Sunday, 10 December 2017

linux - Is it expected that firejail allows R/W outside of the sandbox without "--overlay" flag?

Just installed firejail on Ubuntu 16.04 (version 0.9.38) and according to this linux-magazine article, by default it should make R/O the entire filesystem:



The programs in the sandbox have only read access to all directories and are thus unable to manipulate any important files.



Now, I tried the following on my computer:



  1. touch /disk5/test.txt

  2. firejail gvim /disk5/test.txt

  3. modify the file and save it (wq!)

  4. cat /disk5/test.txt

  5. does display changes done by gvim during firejail session!


Is this expected behaviour? Wasn't firejail supposed to protect me from overwriting the original file? What have I done wrong? Please note that /disk5 is mounted in the root filesystem, outside of my /home.


Raised a bug on github

No comments:

Post a Comment

Where does Skype save my contact's avatars in Linux?

I'm using Skype on Linux. Where can I find images cached by skype of my contact's avatars? Answer I wanted to get those Skype avat...