Page MenuHomePhabricator

ParrotOS's Firejail Code
Open, NormalPublic

Description

ParrotOS have made a lot of progress in making firejail a general usable solution out of the box while supporting a ton of programs and surviving upgrades. This ticket is for taking advantage of their code and merging it in our distro.

https://forums.whonix.org/t/install-firejail-firetools-by-default/5363/4
https://forums.whonix.org/t/check-parrot-os-sandboxing-code/5361/5
https://forums.whonix.org/t/firejail-seccomp-more-options-for-program-containment/1030/65

Details

Impact
Normal

Event Timeline

HulaHoop triaged this task as Normal priority.Jun 26 2018, 5:12 AM
HulaHoop created this task.

@HulaHoop that doesnt mean we dont install firejail by default.

with or without parrot profiles. because firejail by default it has their own profiles.

firejail is enough for Whonix-GW
firejail + firetools for Whonix-WS

I disagree. Firetools makes administration easier and has a place on both VMs.

No problem, but needs to add the commands manually to firetools in the GW.

as Firetools doesnt has the graphical icons for non-graphical programs e.g Tor. (and even some graphical programs e.g Tor Browser).

needs some extra steps , but hope no big deal.