Anyone of you know/tried firejail yet on GoboLinux?
Robert Alexander <[email protected]> Tue, 18 Sep 2018 23:58:18 +0200
| Newsgroups | gmane.linux.distributions.gobo.general |
|---|---|
| Message-ID | <CAFie_ABsV9u7sfzE3BRwu7QG8V=+DoBcPLhF_dJMDY8Qu7sUVg@mail.gmail.com> |
--===============2253186484551003143== Content-Type: multipart/alternative; boundary="0000000000007c562305762c6533" --0000000000007c562305762c6533 Content-Type: text/plain; charset="UTF-8" Hello GoboFolks, This email here is mostly about "firejail" ( see https://firejail.wordpress.com/ ) and a question or two pertaining to it. After reading the project's description, it did remind me a little bit about GoboLinux. Relevant part that felt similar to me, to some extent: - "[...] restricting the running environment of untrusted applications using Linux namespaces and seccomp-bpf. It allows a process and all its descendants to have their own private view of the globally shared kernel resources, such as the network stack, process table, mount table. [...]" Now I assume this is not necessarily the same as /System/Index/ or viewfs or anything like that - but I can't help but feel that it is still related in some way to the idea. After all, if we look at unionfs (I think), or chroot-compile or just chroots in general, we may want to have programs see only "relevant parts" of the system during compilation. So things such as a process table or network stacks, but also software such as docker (isn't docker like taken from GoboLinux, as idea ... ;) ), is in some way similar to ideas that spawned off in GoboLinux. Managing resources, be them files, process, or anything really. Including in restricted environments. And htop sort of also taps into that - we selectively view relevant processes. :) (Perhaps one could control them too, though that is not the scope of htop; just in theory that could be done, even though ncurses scares me to no ends). Not sure if this makes sense what I am trying to say but, to me, the ideas seem vaguely similar to one another. I have not tested firejail so far, largely due to my inertia and laziness; or, worded differently, because I have lots of other things to do in general, many of which have little to nothing to do with computers. But I still like to at the least have a look at what things are new. (I noticed the link to it on distrowatch; that is how I found it actually). - Has anyone of you tried firejail so far? And, even more importantly, can say a thing or two how/if it works (also on GoboLinux)? I haven't really followed developments such as linux cgroups or "micro-control" of these capabilities very much at all. I am mostly just content when things work, in a simple way ... :P On a side note, "holiday season" is slowly wearing off in central europe, and the heat wave is also gone, more or less,so ... *cracks fingers to try to do something productive again* --0000000000007c562305762c6533 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"><div dir=3D"ltr">Hello GoboFolks,<br><br>This email here i= s mostly about "firejail" ( see <a href=3D"https://firejail.wordp= ress.com/">https://firejail.wordpress.com/</a> )<br></div><div>and a questi= on or two pertaining to it.<br></div><div dir=3D"ltr"><br>After reading the= project's description, it did remind me a little bit about GoboLinux.<= br><br>Relevant part that felt similar to me, to some extent:<br><br>- &quo= t;[...] restricting the running environment of untrusted applications<br>us= ing Linux namespaces and seccomp-bpf. It allows a process and all<br>its de= scendants to have their own private view of the globally shared<br>kernel r= esources, such as the network stack, process table, mount<br>table. [...]&q= uot;<br><br>Now I assume this is not necessarily the same as /System/Index/= or<br>viewfs or anything like that - but I can't help but feel that it= is still related<br>in some way to the idea. After all, if we look at unio= nfs (I think), or chroot-compile<br>or just chroots in general, we may want= to have programs see only "relevant<br>parts" of the system duri= ng compilation. So things such as a process table or<br>network stacks, but= also software such as docker (isn't docker=C2=A0 like taken from <br>G= oboLinux, as idea ... ;) ), is in some way similar to ideas that spawned of= f<br>in GoboLinux. Managing resources, be them files, process, or anything = really.<br>Including in restricted environments. And htop sort of also taps= into that - we<br>selectively view relevant processes. :) (Perhaps one cou= ld control them too,<br></div><div>though that is not the scope of htop; ju= st in theory that could be done, even<br></div><div>though ncurses scares m= e to no ends).<br></div><div dir=3D"ltr"><br>Not sure if this makes sense w= hat I am trying to say but, to me, the ideas<br>seem vaguely similar to one= another.<br><br>I have not tested firejail so far, largely due to my inert= ia and laziness;<br>or, worded differently, because I have lots of other th= ings to do in general,<br>many of which have little to nothing to do with c= omputers. But I still like<br>to at the least have a look at what things ar= e new. (I noticed the link to<br>it on distrowatch; that is how I found it = actually).<br><br>- Has anyone of you tried firejail so far? And, even more= importantly, can<br>say a thing or two how/if it works (also on GoboLinux)= ?<br><br>I haven't really followed developments such as linux cgroups o= r "micro-control"<br>of these capabilities very much at all. I am= mostly just content when things<br>work, in a simple way ... :P<br><br></d= iv><div>On a side note, "holiday season" is slowly wearing off in= central europe,<br></div><div>and the heat wave is also gone, more or less= ,so ... *cracks fingers to try<br>to do something productive again*<br></di= v></div> --0000000000007c562305762c6533-- --===============2253186484551003143== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KZ29ib2xpbnV4 LXVzZXJzIG1haWxpbmcgbGlzdApnb2JvbGludXgtdXNlcnNAbGlzdHMuZ29ib2xpbnV4Lm9yZwpo dHRwOi8vbGlzdHMuZ29ib2xpbnV4Lm9yZy9tYWlsbWFuL2xpc3RpbmZvL2dvYm9saW51eC11c2Vy cwo= --===============2253186484551003143==--