-
Notifications
You must be signed in to change notification settings - Fork 558
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Atom 1.48.0 breaks with Firejail 0.9.58.2 #3464
Comments
Can you try #2946 (comment). |
@rusty-snake , adding the following returns the same error:
Running
|
Is |
It was commented out, I tried both |
What's in your globals.local? |
Nothing related actually:
|
I'm out of ideas for now. Maybe you need to also ignore
|
That didn't work either. I will keep playing with the rules and post if I find something. |
Because |
@rusty-snake I'm able to get it to work if I comment out Naturally I want to tighten this down a bit but hopefully I can get a fix in within a day or so. |
@kmotoko can you try with the new profile https://github.com/netblue30/firejail/blob/cb6799523085ddc7caf57b235514e6865a4caeaa/etc/profile-a-l/atom.profile ? Cheers! |
This profile does not work with 0.9.58.2 |
@rusty-snake thanks for catching that! I'll put in a fix under etc-fixes for 0.9.58 and the other distro-supported releases (0.9.52, 0.9.58, and 0.9.60). This would skip 0.9.44, but since Debian 9 goes EOL in less than a month and 0.9.58 is in its backports, it may be better not to patch this one... |
Backporting fixes for Atom 1.48 to firejail 0.9.52, 0.9.58, and 0.9.60 Summary: - remove nonewprivs, noroot, protocol, and seccomp - update caps filter to keep sys_admin and sys_chroot Without these changes Atom 1.48 breaks and refuses to start (due to Electron sandboxing)
Bug and expected behavior
Upgrading from
atom
1.46.0
to1.48.0
breaks startingatom
underfirejail
.atom
to start normally.No profile or disabling firejail
firejail --noprofile PROGRAM
in a shell?atom
starts-up normally.whereis PROGRAM
,firejail --list
,stat $programpath
)?atom
starts-up normally.Reproduce
Steps to reproduce the behavior:
firejail atom
Environment
lsb_release -a
)firejail --version
) exclusive or used git commit (git rev-parse HEAD
)To my knowledge:
git
,GVFS Trash
Yes.
Additional context
I have a strong feeling that the issue is related to change in PR#20799, which fixes the Issue#20756.
My
atom.profile
:My
atom.local
:I gradually commented out certain entries in my
atom.profile
just to test, the following does not preventatom
from starting-up:Checklist
find / -name 'firejail' 2>/dev/null
/fd firejail
to locate profiles ie in/usr/local/etc/firejail/PROGRAM.profile
)debug output
The text was updated successfully, but these errors were encountered: