aboutsummaryrefslogtreecommitdiffstats
path: root/todo
diff options
context:
space:
mode:
authorLibravatar netblue30 <netblue30@yahoo.com>2016-07-12 08:21:57 -0400
committerLibravatar netblue30 <netblue30@yahoo.com>2016-07-12 08:21:57 -0400
commit67f8a71cd721b1786dc5b17248316a714ea71869 (patch)
tree2c4ed7ce9d754835b8a9f838ce5a4c5db902214e /todo
parentaudit work (diff)
downloadfirejail-67f8a71cd721b1786dc5b17248316a714ea71869.tar.gz
firejail-67f8a71cd721b1786dc5b17248316a714ea71869.tar.zst
firejail-67f8a71cd721b1786dc5b17248316a714ea71869.zip
whitelist rework
Diffstat (limited to 'todo')
-rw-r--r--todo57
1 files changed, 57 insertions, 0 deletions
diff --git a/todo b/todo
index 88baff216..5ceb4e530 100644
--- a/todo
+++ b/todo
@@ -161,3 +161,60 @@ To disable Vsync
161 161
162$ vblank_mode=0 glxgears 162$ vblank_mode=0 glxgears
163 163
16418. Bring in nvidia drives in private-dev
165
166/dev/nvidia[0-9], /dev/nvidiactl, /dev/nvidia-modset and /dev/nvidia-uvm
167
16819. testing snaps
169
170Install firejail from official repository
171sudo apt-get install firejail
172
173Check firejail version
174firejail --version
175
176Above command outputs: firejail version 0.9.38
177
178Search the snap 'ubuntu clock' application
179sudo snap find ubuntu-clock-app
180
181Install 'ubuntu clock' application using snap
182sudo snap install ubuntu-clock-app
183
184Ubuntu snap packages are installed in /snap/// directory and can be executed from /snap/bin/
185cd /snap/bin/
186ls -l
187
188Note: We see application name is: ubuntu-clock-app.clock
189
190Run application
191/snap/bin/ubuntu-clock-app.clock
192
193Note: Application starts-up without a problem and clock is displayed.
194
195Close application using mouse.
196
197Now try to firejail the application.
198firejail /snap/bin/ubuntu-clock-app.clock
199
200-------- Error message --------
201Reading profile /etc/firejail/generic.profile
202Reading profile /etc/firejail/disable-mgmt.inc
203Reading profile /etc/firejail/disable-secret.inc
204Reading profile /etc/firejail/disable-common.inc
205
206** Note: you can use --noprofile to disable generic.profile **
207
208Parent pid 3770, child pid 3771
209
210Child process initialized
211need to run as root or suid
212
213parent is shutting down, bye...
214-------- End of Error message --------
215
216Try running as root as message instructs.
217sudo firejail /snap/bin/ubuntu-clock-app.clock
218
219extract env for process
220ps e -p <pid> | sed 's/ /\n/g'