nixos/firejail: allow to pass options to firejail
This commit is contained in:
parent
a371c10711
commit
6fa1646268
@ -11,10 +11,20 @@ let
|
|||||||
}
|
}
|
||||||
''
|
''
|
||||||
mkdir -p $out/bin
|
mkdir -p $out/bin
|
||||||
${lib.concatStringsSep "\n" (lib.mapAttrsToList (command: binary: ''
|
${lib.concatStringsSep "\n" (lib.mapAttrsToList (command: value:
|
||||||
|
let
|
||||||
|
opts = if builtins.isAttrs value
|
||||||
|
then value
|
||||||
|
else { executable = value; profile = null; extraArgs = []; };
|
||||||
|
args = lib.escapeShellArgs (
|
||||||
|
(optional (opts.profile != null) "--profile=${toString opts.profile}")
|
||||||
|
++ opts.extraArgs
|
||||||
|
);
|
||||||
|
in
|
||||||
|
''
|
||||||
cat <<_EOF >$out/bin/${command}
|
cat <<_EOF >$out/bin/${command}
|
||||||
#! ${pkgs.runtimeShell} -e
|
#! ${pkgs.runtimeShell} -e
|
||||||
exec /run/wrappers/bin/firejail ${binary} "\$@"
|
exec /run/wrappers/bin/firejail ${args} -- ${toString opts.executable} "\$@"
|
||||||
_EOF
|
_EOF
|
||||||
chmod 0755 $out/bin/${command}
|
chmod 0755 $out/bin/${command}
|
||||||
'') cfg.wrappedBinaries)}
|
'') cfg.wrappedBinaries)}
|
||||||
@ -25,12 +35,38 @@ in {
|
|||||||
enable = mkEnableOption "firejail";
|
enable = mkEnableOption "firejail";
|
||||||
|
|
||||||
wrappedBinaries = mkOption {
|
wrappedBinaries = mkOption {
|
||||||
type = types.attrsOf types.path;
|
type = types.attrsOf (types.either types.path (types.submodule {
|
||||||
|
options = {
|
||||||
|
executable = mkOption {
|
||||||
|
type = types.path;
|
||||||
|
description = "Executable to run sandboxed";
|
||||||
|
example = literalExample "''${lib.getBin pkgs.firefox}/bin/firefox";
|
||||||
|
};
|
||||||
|
profile = mkOption {
|
||||||
|
type = types.nullOr types.path;
|
||||||
|
default = null;
|
||||||
|
description = "Profile to use";
|
||||||
|
example = literalExample "''${pkgs.firejail}/etc/firejail/firefox.profile";
|
||||||
|
};
|
||||||
|
extraArgs = mkOption {
|
||||||
|
type = types.listOf types.str;
|
||||||
|
default = [];
|
||||||
|
description = "Extra arguments to pass to firejail";
|
||||||
|
example = [ "--private=~/.firejail_home" ];
|
||||||
|
};
|
||||||
|
};
|
||||||
|
}));
|
||||||
default = {};
|
default = {};
|
||||||
example = literalExample ''
|
example = literalExample ''
|
||||||
{
|
{
|
||||||
firefox = "''${lib.getBin pkgs.firefox}/bin/firefox";
|
firefox = {
|
||||||
mpv = "''${lib.getBin pkgs.mpv}/bin/mpv";
|
executable = "''${lib.getBin pkgs.firefox}/bin/firefox";
|
||||||
|
profile = "''${pkgs.firejail}/etc/firejail/firefox.profile";
|
||||||
|
};
|
||||||
|
mpv = {
|
||||||
|
executable = "''${lib.getBin pkgs.mpv}/bin/mpv";
|
||||||
|
profile = "''${pkgs.firejail}/etc/firejail/mpv.profile";
|
||||||
|
};
|
||||||
}
|
}
|
||||||
'';
|
'';
|
||||||
description = ''
|
description = ''
|
||||||
|
@ -11,6 +11,10 @@ import ./make-test-python.nix ({ pkgs, ...} : {
|
|||||||
enable = true;
|
enable = true;
|
||||||
wrappedBinaries = {
|
wrappedBinaries = {
|
||||||
bash-jailed = "${pkgs.bash}/bin/bash";
|
bash-jailed = "${pkgs.bash}/bin/bash";
|
||||||
|
bash-jailed2 = {
|
||||||
|
executable = "${pkgs.bash}/bin/bash";
|
||||||
|
extraArgs = [ "--private=~/firejail-home" ];
|
||||||
|
};
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|
||||||
@ -53,6 +57,11 @@ import ./make-test-python.nix ({ pkgs, ...} : {
|
|||||||
)
|
)
|
||||||
machine.fail("sudo -u alice bash-jailed -c 'cat ~/my-secrets/secret' | grep -q s3cret")
|
machine.fail("sudo -u alice bash-jailed -c 'cat ~/my-secrets/secret' | grep -q s3cret")
|
||||||
|
|
||||||
|
# Test extraArgs
|
||||||
|
machine.succeed("sudo -u alice mkdir /home/alice/firejail-home")
|
||||||
|
machine.succeed("sudo -u alice bash-jailed2 -c 'echo test > /home/alice/foo'")
|
||||||
|
machine.fail("sudo -u alice cat /home/alice/foo")
|
||||||
|
machine.succeed("sudo -u alice cat /home/alice/firejail-home/foo | grep test")
|
||||||
|
|
||||||
# Test path acl with firejail executable
|
# Test path acl with firejail executable
|
||||||
machine.succeed("sudo -u alice firejail -- bash -c 'cat ~/public' | grep -q publ1c")
|
machine.succeed("sudo -u alice firejail -- bash -c 'cat ~/public' | grep -q publ1c")
|
||||||
|
Loading…
Reference in New Issue
Block a user