Skip to content

Firejail blocks access to conda #1

Description

@tomasris

This is a very good idea, and it works on a system with Python installed, but Anaconda is installed in the home directory, and firejail blocks access to conda files and scripts. All the packages needed for work are also installed there, rather than in any directory where the user works with Python scripts. I would appreciate any advice you can offer.
This helped:
keep-shell-rc # enable for firejail >0.9.66
By default, when using a private home directory, firejail
copies files from the system's user home template
(/etc/skel) into it, which overrides attempts to whitelist
the original files (such as ~/.bashrc and ~/.zshrc). This
option disables this feature, and enables the user to
whitelist the original files

Activity

  1. githubnemo commented on Oct 24, 2025

    @githubnemo
    Owner

    Yes, I'm not using conda as much, so this is a bit untested. I've tried adding rudimentary support for it but I expect to run into trouble in some places.

    Once you create a python sandbox using create-python-sandbox and enter it using firejail --profile=python-env-<sandbox_name> --tab bash this shell will have CONDA_ENVS_PATH set to ~/envs/<sandbox_name>/conda. (The prefix ~/envs/ can be overridden by setting PYSANDBOX_ENVS_PATH before calling create-python-sandbox).

    This is crucial, you have to have your conda envs in the $CONDA_ENVS_PATH - this directory is whitelisted and persistent. Having the environments separate from the conda installation is a good thing since you would not want to update the base installation from inside a sandbox which might be hijacked.

    I decided not to force a default installation dir whitelist for anaconda. For this there exists the option of a user override via python-env-template.local in ~/.config/firejail/.

    For example an excerpt of my ~/.config/firejail/python-env-template.local which is included in every sandbox profile:

    # Enable read-only access to (mini)forge/conda directory
    whitelist ${HOME}/Code/conda
    read-only ${HOME}/Code/conda
    whitelist ${HOME}/bin/conda
    whitelist ${HOME}/bin/mamba
    

    You can do something similar to allow read only(!) access to the conda installation dir.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions