-
-
Notifications
You must be signed in to change notification settings - Fork 12.7k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
firejail [Error: the sandbox is not setuid root] #15970
Comments
The Nix store cannot contain setuid binaries, so you need to set let # syntax highlighting
security.setuidPrograms = [ "firejail" ]; in your |
Thanks a lot! |
To me, that trace suggests that the upstream profile for chromium fails to mesh with NixOS somehow, I don't know off hand what it could be exactly. Two things: 1) you could try bumping firejail (0.9.38 is old) and see if that helps; and/or 2) write your own profiles. Perhaps something like |
@danykey you could start out by using |
I tried It crashes immediately with any programs(with or without profile) |
Hrm, never seen that with firejail and I've used it quite a bit for testing. |
@7c6f434c is the maintainer, they may know more. |
I would try |
Thanks! So, with --nosound is working. But I need sound for Skype and browsers. I had check /etc/pulse/client.conf and no something strange found. It's contans two rows and seems are correct:
Could you check your pulse client config? |
Firejail currently does not support symbolic link in place of I have created an issue asking about it in netblue30/firejail project (see netblue30/firejail#571). Following override hot-fixes the problem (at least for version 0.9.38) for me (last line is added by the override)
|
Incredible thanks! I will test. |
FYI, It is now fixed in netblue30/firejail. |
gives
so now its just {
programs.firejail.enable = true;
|
Issue description
Can't run firejail. It throws "Error: the sandbox is not setuid root" all the time with any arguments. May be something misconfigured?
Steps to reproduce
Install and run
firejail
Technical details
The text was updated successfully, but these errors were encountered: