Skip to content

How can I firejail the whole operating system? [answer: you can't] #4163

Closed Answered by rusty-snake
paolus4 asked this question in Q&A
Discussion options

You must be logged in to vote

What should I do to firejail the entire Linux first?

TL;DR: Not possible, use a LMS like SELinux or AppArmor.

It's difficult to "Firejail the whole operating system" because:

  1. What's "the whole operating system"? Everything in the userspace, only the user session or is the kernel included. And what's with the boot loader, the UEFI/BIOS and IME or PSP? Strictly speaking is "Linux" only the kernel and you can not protect it from the userspace, because ring4 is inferior to ring0.
  2. So what's if we just want to jail the userspace? With a custom pid1 that starts firejail it's maybe possible, however that would be very hacky and does not work together with systemd and point 3 and 4.
  3. So let's sa…

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by rusty-snake
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants
Converted from issue

This discussion was converted from issue #4162 on April 04, 2021 16:11.