private-bin, yet /bin is fully populated and executable? #6898
Unanswered
PhysicsIsAwesome
asked this question in
Q&A
Replies: 2 comments
-
|
You looked already inside these files ? include whitelist-common.inc Filesystem Whitelistingwhitelist /run/systemd/resolve/io.systemd.Resolve ? |
Beta Was this translation helpful? Give feedback.
0 replies
-
|
I suspect , you can't execute other binarys then ls , example : uptime |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Hey,
I have the following profile and run it with
firejail --appimage --profile=joplin /opt/joplin/Joplin.AppImageit contains aprivate-binstatement, so only thelsbinary (as an example) is intended to be visible. Yet when I join viafirejail --join=idand runls /bin, all the binaries of the host's /bin are still there and executable from within the sandbox. Is there anyone who can explain why this does not work?joplin Profile:
Beta Was this translation helpful? Give feedback.
All reactions