In the upstream bug, I've suggested the following workaround: A possibility for NetworkManager would be to write a dns-change dispatcher script that does a
firejail --put=... /etc/resolv.conf /etc/resolv.conf for each sandbox having a private etc. If it is not possible to identify such sandboxes, perhaps do a --get first to see if an update is needed for the sandbox (there is a race condition, but I don't think that there would be an issue in practice). -- Vincent Lefèvre <[email protected]> - Web: <https://www.vinc17.net/> 100% accessible validated (X)HTML - Blog: <https://www.vinc17.net/blog/> Work: CR INRIA - computer arithmetic / Pascaline project (LIP, ENS-Lyon)

