You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Debian中配置Firejail隔离不可信脚本,限制仅访问指定非敏感目录

Got it, let's fix this Firejail configuration so your untrusted script can't poke around your home directory, and only access the safe paths you want. The issue with your original command is that --caps.drop=all only removes Linux capabilities—it doesn't restrict filesystem access at all, which is why you could still see /home/porton/.

Here's how to lock things down properly, with both quick command-line options and a reusable profile for future use:

Quick Command-Line Test

First, let's verify the restriction works with a one-off command. Run this:

firejail --private --bind /usr --tmpfs /tmp --noprofile ls /home/porton/

You should see an error like ls: cannot access '/home/porton/': No such file or directory—that's exactly what we want. Let's break down each parameter:

  • --private: Creates an isolated root filesystem (empty by default) so none of your host's directories are visible unless explicitly bound.
  • --bind /usr: Mounts your host's /usr directory into the container's /usr—this gives the script access to system binaries/libraries.
  • --tmpfs /tmp: Sets up an empty, temporary tmpfs for /tmp—any data written here vanishes when the container exits, and it's isolated from your host's /tmp.
  • --noprofile: Skips Firejail's default profiles, which might include unintended access rules.

Reusable Firejail Profile

For repeated use, create a custom profile so you don't have to type all those parameters every time.

  1. Create a profile file (either in ~/.config/firejail/ for your user, or /etc/firejail/ for system-wide use):
    nano ~/.config/firejail/untrusted-script.profile
    
  2. Paste this configuration:
    # Profile for running untrusted scripts with minimal filesystem access
    private
    bind /usr
    tmpfs /tmp
    
    # Explicitly block access to sensitive directories (redundant with --private, but safe to add)
    noaccess /home
    noaccess /root
    noaccess /var/log
    noaccess /var/lib
    
    # Remove all Linux capabilities (matches your original --caps.drop=all)
    caps.drop all
    
    # Optional: Disable network if the script doesn't need internet access
    net none
    
    # Optional: Restrict to a single CPU core if you want to limit resource usage
    cpu 1
    
  3. Save the file, then run your script with:
    firejail --profile=untrusted-script.profile /path/to/your/untrusted-script.sh
    

Alternative: Bubblewrap (Lightweight Isolation)

If you prefer a more minimal tool without Firejail's profile system, Bubblewrap (often pre-installed on Debian) works great. Try this command:

bwrap --ro-bind /usr /usr --tmpfs /tmp --proc /proc --dev /dev --unshare-all --caps-drop-all /path/to/your/untrusted-script.sh
  • --ro-bind /usr /usr: Mounts /usr read-only (extra safety, since scripts shouldn't modify system files)
  • --tmpfs /tmp: Isolated empty /tmp
  • --proc /proc and --dev /dev: Mount necessary virtual filesystems for basic script functionality
  • --unshare-all: Isolates all namespaces (filesystem, PID, network, etc.)
  • --caps-drop-all: Removes all capabilities

Verification Tip

Always test the restrictions first with a simple command like ls /home or cat /home/porton/.bashrc to confirm the script can't access sensitive data before running the actual untrusted code.

内容的提问来源于stack exchange,提问作者porton

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 09:06:23