4 ms·
I have been using Firejail for a few years now and absolutely love it. It is now a central part of my setup and workflows. Here are two features I use regularly
by pythux 6y ago
I have been using Firejail for a few years now and absolutely love it. It is now a central part of my setup and workflows. Here are two features I use regularly:
- The "virtual home" specified with --private=/path/to/folder runs the app with the specified folder as a home folder. I use this for all the apps I sandbox to make sure my real home does not get polluted by tens of config files, cache, etc. Removing all traces of an app is now as easy as deleting /path/to/folder; I find this pretty neat to keep my home folder organized (each app gets its own home in ~/.sandboxes/<app name>).
- Starting an app with --private (without any argument) will run it into a temporary/disposable home folder which will be cleaned up when the app is stopped. I use it to run some apps I don't really trust and don't need persistence for (e.g. I start Chrome with this option so that I get a fresh home, hence profile, every time I need it, same for Zoom when I need to join a meeting---not very often).
And of course all the profiles that are built-in to customize the sandboxing to most popular apps is great!
I'm really thankful for the work being done on this project.
- colejohnson66 6y agoI do that with Wine: giving each program its own WINEPREFIX. For example, EAC lives under ~/wine/eac. This makes program removal easy as well.
- forgotmypw17 6y agoI do this too! Different Netscape versions don,t get along well on the same "system"
- Vinnl 6y agoIt looks neat, but I'm not familiar with most of the tools and concepts mentioned on its page, so if I were to use it, I'd mostly do so as a "fire and forget" and then hope it does its thing properly. Looking at the readme, that means I'd run `firecfg --fix-sound`, then `sudo firecfg`, and then after a logout and login never look back at it. Would you (or anyone else) happen to know if there's any risks for an unknowledgable user like me to do that, e.g. of breaking my system without knowing how to repair it?
- pythux 6y agoI am far from expert in this but I am not sure I would be comfortable automatically configuring all my apps to run through Firejail using firecfg (if only because in case of breakage it would be harder to understand where it is coming from). In my workflow, I keep things mostly manual and configure each app I want to sandbox explicitly by creating a shortcut (usually I create a "launcher" in /usr/local/bin so that it takes priority over whatever is in /usr/bin). Here is the one I have for Firefox as an example in "/usr/local/bin/firefox": firejail --profile=/etc/firejail/firefox.profile --private=~/.sandboxes/firefox/ /usr/bin/firefox --no-remote $@ In terms of risks, are you mostly concerned about security risks? Or breakage?
- Vinnl 6y agoThanks. I'm concerned about both, but I suppose I consider breakage to be the biggest risk for something of which I hardly know what it does. Your approach sounds viable though, so I might look into setting something similar up for myself as well. Thanks for sharing.
- 0xdeadb00f 6y ago> - The "virtual home" specified with --private=/path/to/folder runs the app with the specified folder as a home folder. I use this for all the apps I sandbox to make sure my real home does not get polluted by tens of config files, cache, etc. I understand firejail does a lot more but FYI, you can do this simply by typing `HOME=/path/to/folder <app>` in your shell. Or do this in a wrapper script, for example: #!/bin/sh export HOME=/path/to/dir firefox
- justaj 6y agoI've been using Linux for just under 3 years now and I had no idea this was a thing. I'm amazed at new things I learn every day. Thanks a lot!