Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

No internet access with whitelist-run-common.inc (OpenSUSE) (resolv.conf) #4954

Closed
Kebron718 opened this issue Feb 18, 2022 · 7 comments
Closed
Labels
bug Something isn't working networking Issues related to networking features (--net=, etc)
Milestone

Comments

@Kebron718
Copy link

firejail version: 0.9.68 (installed from official repos)
problem did not exist in earlier versions
Linux distro: openSUSE Leap 15.3

I updated from version 0.9.66 yesterday and lost internet access with e.g. Chromium, Firefox and Thunderbird. The programs seemed to load correctly but there was no network access whatsoever.

Switched between 0.9.68 and 0.9.64 (0.9.66 was not available any more in the openSUSE repos) and discovered that I had to uncomment every entry in

etc/firejail/whitelist-run-common.inc

in order to get internet access back.

I noticed that there is no such file in 0.9.64.

I don’t know whether this problem is limited to openSUSE.

@rusty-snake
Copy link
Collaborator

ls -l /etc/resolv.conf?

@Kebron718
Copy link
Author

Thanks, that did it!

I should have checked the paths in etc/firejail/whitelist-run-common.inc.

Everything checks out but one line:

whitelist /run/NetworkManager/resolv.conf

does not exist in openSUSE. Instead the correct path is

whitelist /run/netconfig/resolv.conf

I guess that could easily be fixed in the SUSE repos ...

@reinerh
Copy link
Collaborator

reinerh commented Feb 18, 2022

I guess that could easily be fixed in the SUSE repos ...

That can also be fixed in firejail upstream. :-)
There are probably other distributions using netconfig.
Do you want to open a Pull Request that adds the whitelist?

@rusty-snake rusty-snake added this to the 0.9.70 milestone Feb 19, 2022
@netblue30 netblue30 added the bug Something isn't working label Feb 22, 2022
@netblue30
Copy link
Owner

Added a fix here: f347e88

@netblue30 netblue30 added the in testing A bugfix that is being tested label Feb 22, 2022
@powerjungle
Copy link
Contributor

Same issue is in OpenSUSE Tumbleweed and this fixes it, thanks!

@sebix
Copy link

sebix commented Feb 28, 2022

Hi,

firejail-package-maintainer in openSUSE here.

Thanks for reporting, debugging and fixing the issue!

Same issue is in OpenSUSE Tumbleweed and this fixes it, thanks!

See status update in https://bugzilla.opensuse.org/show_bug.cgi?id=1196542
I added the patch to the experimental repo, if this problem is fixed for the affected users, I will submit it to Tumbleweed official packages.

btw: firejail 0.9.68 is not part of Leap 15.3 official packages, only as experimental package, same source as for tumbleweed.

@kmk3
Copy link
Collaborator

kmk3 commented Mar 9, 2022

Closing this as it seems to have been fixed by commit bb334a8 ("openSUSE
Leap - whitelist-run-common.inc (#4954)", 2022-02-22).

@kmk3 kmk3 closed this as completed Mar 9, 2022
@rusty-snake rusty-snake removed the in testing A bugfix that is being tested label Jun 21, 2022
@kmk3 kmk3 added the networking Issues related to networking features (--net=, etc) label Sep 2, 2024
@kmk3 kmk3 changed the title No internet access with etc/firejail/whitelist-run-common.inc enabled running openSUSE Leap 15.3 and Firejail version 0.9.68 No internet access with whitelist-run-common.inc Sep 2, 2024
@kmk3 kmk3 changed the title No internet access with whitelist-run-common.inc No internet access with whitelist-run-common.inc (OpenSUSE) Sep 2, 2024
@kmk3 kmk3 changed the title No internet access with whitelist-run-common.inc (OpenSUSE) No internet access with whitelist-run-common.inc (OpenSUSE) (resolv.conf) Sep 2, 2024
@kmk3 kmk3 moved this to Done (on RELNOTES) in Release 0.9.70 Sep 2, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working networking Issues related to networking features (--net=, etc)
Projects
Status: Done (on RELNOTES)
Development

No branches or pull requests

7 participants