sanebox: populate --sanebox-net-dev with the actual net device -- not the bridge
This commit is contained in:
parent
ffe599e5cb
commit
118ed5f950
|
@ -71,7 +71,7 @@ let
|
|||
whitelistPwd
|
||||
;
|
||||
netDev = if sandbox.net == "vpn" then
|
||||
vpn.bridgeDevice
|
||||
vpn.name
|
||||
else
|
||||
sandbox.net;
|
||||
dns = if sandbox.net == "vpn" then
|
||||
|
|
|
@ -574,7 +574,9 @@ firejailIngestPath() {
|
|||
esac
|
||||
}
|
||||
firejailIngestNetDev() {
|
||||
firejailFlags+=("--net=$1")
|
||||
# XXX: to use a VPN tunnel named `vpn-xyz`, we keep around and link it to a bridge `br-vpn-xyz` externally.
|
||||
# firejail can then spawn a veth from this bridge and namespace it that way.
|
||||
firejailFlags+=("--net=br-$1")
|
||||
}
|
||||
firejailIngestDns() {
|
||||
firejailFlags+=("--dns=$1")
|
||||
|
|
Loading…
Reference in New Issue
Block a user