orjail: [Bug] "Replacing resolv.conf" fails without error
When /etc/resolv.conf -> /run/systemd/resolve/stub-resolv.conf no replacement and dns leaking via systemd-resolved nameserver 127.0.0.53.
About this issue
- Original URL
- State: open
- Created 3 years ago
- Comments: 23
using
/etc/netns/orjail/resolv.confdoes not solve the issue: as pointed out here https://unix.stackexchange.com/questions/418304/why-do-linux-bind-mounts-disappear-if-the-mount-points-inode-changes:What about mount-binding the whole /etc and replacing relevant files (resolv.conf/nsswitch.conf)? This is pratically how firejail does this
This is done in 8bdfe759fb6e1ef461f7e195c54e1a56f37da0a2, I’m confident this is the way to go.
interesting thread: https://github.com/slingamn/namespaced-openvpn/issues/7
-> https://github.com/slingamn/namespaced-openvpn#dns-hardening