Debian中配置Firejail隔离不可信脚本,限制仅访问指定非敏感目录
Got it, let's fix this Firejail configuration so your untrusted script can't poke around your home directory, and only access the safe paths you want. The issue with your original command is that --caps.drop=all only removes Linux capabilities—it doesn't restrict filesystem access at all, which is why you could still see /home/porton/.
Here's how to lock things down properly, with both quick command-line options and a reusable profile for future use:
Quick Command-Line Test
First, let's verify the restriction works with a one-off command. Run this:
firejail --private --bind /usr --tmpfs /tmp --noprofile ls /home/porton/
You should see an error like ls: cannot access '/home/porton/': No such file or directory—that's exactly what we want. Let's break down each parameter:
--private: Creates an isolated root filesystem (empty by default) so none of your host's directories are visible unless explicitly bound.--bind /usr: Mounts your host's/usrdirectory into the container's/usr—this gives the script access to system binaries/libraries.--tmpfs /tmp: Sets up an empty, temporarytmpfsfor/tmp—any data written here vanishes when the container exits, and it's isolated from your host's/tmp.--noprofile: Skips Firejail's default profiles, which might include unintended access rules.
Reusable Firejail Profile
For repeated use, create a custom profile so you don't have to type all those parameters every time.
- Create a profile file (either in
~/.config/firejail/for your user, or/etc/firejail/for system-wide use):nano ~/.config/firejail/untrusted-script.profile - Paste this configuration:
# Profile for running untrusted scripts with minimal filesystem access private bind /usr tmpfs /tmp # Explicitly block access to sensitive directories (redundant with --private, but safe to add) noaccess /home noaccess /root noaccess /var/log noaccess /var/lib # Remove all Linux capabilities (matches your original --caps.drop=all) caps.drop all # Optional: Disable network if the script doesn't need internet access net none # Optional: Restrict to a single CPU core if you want to limit resource usage cpu 1 - Save the file, then run your script with:
firejail --profile=untrusted-script.profile /path/to/your/untrusted-script.sh
Alternative: Bubblewrap (Lightweight Isolation)
If you prefer a more minimal tool without Firejail's profile system, Bubblewrap (often pre-installed on Debian) works great. Try this command:
bwrap --ro-bind /usr /usr --tmpfs /tmp --proc /proc --dev /dev --unshare-all --caps-drop-all /path/to/your/untrusted-script.sh
--ro-bind /usr /usr: Mounts/usrread-only (extra safety, since scripts shouldn't modify system files)--tmpfs /tmp: Isolated empty/tmp--proc /procand--dev /dev: Mount necessary virtual filesystems for basic script functionality--unshare-all: Isolates all namespaces (filesystem, PID, network, etc.)--caps-drop-all: Removes all capabilities
Verification Tip
Always test the restrictions first with a simple command like ls /home or cat /home/porton/.bashrc to confirm the script can't access sensitive data before running the actual untrusted code.
内容的提问来源于stack exchange,提问作者porton

