Sailjail blocks internet connection

Edit:

As you can read below, DNS is configured correctly and also resolves correctly. I found out that this problem has to do with the sailjail. If I disable sandboxing for individual apps, they also have an internet connection again. Sailjail blocks internet connection - #13 by davodego

So far, this works except for the weather app and the browser. If I add “Sandboxing=Disabled” to the *.desktop file, they ask for SailJail permissions again when I start it, and the internet remains inaccessible.
For whatever reason, a change in name resolution, as I describe below, interferes with SailJail’s operations.
Does anyone have any idea how I can appease SailJail by letting the apps back online?

EndEdit

I need help, I broke DNS… somehow.
I wanted to run the cellular connection through other DNS servers (with tracking blocker). To do this, I followed the instructions: How to change dns on mobile network - #13 by ohnonot
But that didn’t work with my VPN, or rather, the apps couldn’t find the internet after /etc/resolv.conf was no longer a symlink and the VPN was also on.
The VPN should only resolve on the LAN and the new DNS servers that were listed in resolv.conf should resolve everything else on the WAN.
So I deleted /etc/resolve.conf and restored the symlink:

ln -s /var/run/systemd/resolve/resolv.conf /etc/resolv.conf

Now the domain name resolution is totally weird. The Android apps have no problems finding their servers (Nextcloud, Tusky, Banking, eBay, DHL, etc.). It’s mixed in the SFOS apps. The browser can’t find anything anymore, neither via mobile phone, Wi-Fi, nor VPN. Storeman can find the internet, ChumGUI too, and SFOS Forum, weather, and Fahrplan can’t. Whether I’m on Wi-Fi or on the mobile network.

Connmanctl shows the correct DNS servers. On the console, I can query everything correctly with nslookup (as root), ping works too.
I am at a loss.
I really didn’t do anything more than the standalone resolv.conf and back again.
Does anyone have any ideas?
Can I simply delete the connman files, and connman creates them again? Or is there any way I can reset connman and systemd-resolved so that it gets the defaults again?

Did you perchance update to 5.1?

Could you show?
cat /etc/resolv.conf

On WiFi:

# This file is managed by man:systemd-resolved(8). Do not edit.
#
# This is a dynamic resolv.conf file for connecting local clients directly to
# all known uplink DNS servers. This file lists all configured search domains.
#
# Third party programs must not access this file directly, but only through the
# symlink at /etc/resolv.conf. To manage man:resolv.conf(5) in a different way,
# replace this symlink by a static file or a different symlink.
#
# See man:systemd-resolved.service(8) for details about the supported modes of
# operation for /etc/resolv.conf.

nameserver 192.168.1.XXY
nameserver 192.168.1.XXX

XXY is my nameserver, bind9 on ubuntu 24.04 and XXX is the fritzBox Router.

On cellular connection:

# This file is managed by man:systemd-resolved(8). Do not edit.
#
# This is a dynamic resolv.conf file for connecting local clients directly to
# all known uplink DNS servers. This file lists all configured search domains.
#
# Third party programs must not access this file directly, but only through the
# symlink at /etc/resolv.conf. To manage man:resolv.conf(5) in a different way,
# replace this symlink by a static file or a different symlink.
#
# See man:systemd-resolved.service(8) for details about the supported modes of
# operation for /etc/resolv.conf.

nameserver 94.140.14.14
nameserver 176.9.93.198

First is the AdGuard DNS-Server, second is dnsforge DNS Server.

systemd-resolve shows on Wifi:

systemd-resolve --status
Global
          DNSSEC NTA: 10.in-addr.arpa
                      16.172.in-addr.arpa
                      168.192.in-addr.arpa
                      17.172.in-addr.arpa
                      18.172.in-addr.arpa
                      19.172.in-addr.arpa
                      20.172.in-addr.arpa
                      21.172.in-addr.arpa
                      22.172.in-addr.arpa
                      23.172.in-addr.arpa
                      24.172.in-addr.arpa
                      25.172.in-addr.arpa
                      26.172.in-addr.arpa
                      27.172.in-addr.arpa
                      28.172.in-addr.arpa
                      29.172.in-addr.arpa
                      30.172.in-addr.arpa
                      31.172.in-addr.arpa
                      corp
                      d.f.ip6.arpa
                      home
                      internal
                      intranet
                      lan
                      local
                      private
                      test

Link 15 (p2p0)
      Current Scopes: none
       LLMNR setting: yes
MulticastDNS setting: no
      DNSSEC setting: no
    DNSSEC supported: no

Link 14 (wlan0)
      Current Scopes: DNS LLMNR/IPv4 LLMNR/IPv6
       LLMNR setting: yes
MulticastDNS setting: no
      DNSSEC setting: no
    DNSSEC supported: no
         DNS Servers: 192.168.1.XXY
                      192.168.1.XXX

Link 13 (rmnet_data5)
      Current Scopes: none
       LLMNR setting: yes
MulticastDNS setting: no
      DNSSEC setting: no
    DNSSEC supported: no

Link 12 (rmnet_data4)
      Current Scopes: none
       LLMNR setting: yes
MulticastDNS setting: no
      DNSSEC setting: no
    DNSSEC supported: no

Link 11 (rmnet_data3)
      Current Scopes: none
       LLMNR setting: yes
MulticastDNS setting: no
      DNSSEC setting: no
    DNSSEC supported: no

Link 10 (rmnet_data2)
      Current Scopes: none
       LLMNR setting: yes
MulticastDNS setting: no
      DNSSEC setting: no
    DNSSEC supported: no

Link 9 (rmnet_data1)
      Current Scopes: none
       LLMNR setting: yes
MulticastDNS setting: no
      DNSSEC setting: no
    DNSSEC supported: no

Link 8 (rmnet_data0)
      Current Scopes: none
       LLMNR setting: yes
MulticastDNS setting: no
      DNSSEC setting: no
    DNSSEC supported: no

Link 7 (rmnet_ipa0)
      Current Scopes: none
       LLMNR setting: yes
MulticastDNS setting: no
      DNSSEC setting: no
    DNSSEC supported: no

Link 6 (ip6tnl0)
      Current Scopes: none
       LLMNR setting: yes
MulticastDNS setting: no
      DNSSEC setting: no
    DNSSEC supported: no

Link 5 (sit0)
      Current Scopes: none
       LLMNR setting: yes
MulticastDNS setting: no
      DNSSEC setting: no
    DNSSEC supported: no

Link 4 (ip6_vti0)
      Current Scopes: none
       LLMNR setting: yes
MulticastDNS setting: no
      DNSSEC setting: no
    DNSSEC supported: no

Link 3 (ip_vti0)
      Current Scopes: none
       LLMNR setting: yes
MulticastDNS setting: no
      DNSSEC setting: no
    DNSSEC supported: no

Link 2 (bond0)
      Current Scopes: none
       LLMNR setting: yes
MulticastDNS setting: no
      DNSSEC setting: no
    DNSSEC supported: no

Not by chance, I have 5.1.0.11.

I do not have original system but /etc/resolv.conf should be symlinked:
ln -s /run/systemd/resolve/stub-resolv.conf /etc/resolv.conf
and you should see:
nameserver 127.0.0.53

1 Like

I’ve come this far.

I have the given nameservers removed with

connmanctl config <service_id> --nameservers

(leave it blank behind “nameservers”)

and have the symlink from /etc/resolv.conf to
/var/run/systemd/resolve/stub-resolv.conf set.

cat /etc/resolv.conf
# This file is managed by man:systemd-resolved(8). Do not edit.
#
# This is a dynamic resolv.conf file for connecting local clients to the
# internal DNS stub resolver of systemd-resolved. This file lists all
# configured search domains.
#
# Run "systemd-resolve --status" to see details about the uplink DNS servers
# currently in use.
#
# Third party programs must not access this file directly, but only through the
# symlink at /etc/resolv.conf. To manage man:resolv.conf(5) in a different way,
# replace this symlink by a static file or a different symlink.
#
# See man:systemd-resolved.service(8) for details about the supported modes of
# operation for /etc/resolv.conf.

nameserver 127.0.0.53

But, no changes. SFOS Browser can’t display any site; IronFox AppSupport Browser can display any site.

Show
systemctl status systemd-resolved
and
ss -l4np

systemctl status systemd-resolved
● systemd-resolved.service - Network Name Resolution
   Loaded: loaded (/usr/lib/systemd/system/systemd-resolved.service; enabled; vendor preset: enabled)
   Active: active (running) since Fri 2026-07-31 19:32:05 CEST; 27min ago
     Docs: man:systemd-resolved.service(8)
           https://www.freedesktop.org/wiki/Software/systemd/resolved
           https://www.freedesktop.org/wiki/Software/systemd/writing-network-configuration-managers
           https://www.freedesktop.org/wiki/Software/systemd/writing-resolver-clients
 Main PID: 1218 (systemd-resolve)
   Status: "Processing requests..."
   Memory: 940.0K
   CGroup: /system.slice/systemd-resolved.service
           └─1218 /usr/lib/systemd/systemd-resolved

Warning: Journal has been rotated since unit was started. Log output is incomplete or unavailable.
ss -l4np
Netid          State           Recv-Q           Send-Q                     Local Address:Port                      Peer Address:Port          Process                                              
udp            UNCONN          0                0                                0.0.0.0:8080                           0.0.0.0:*              users:(("cnss-daemon",pid=3747,fd=11))              
udp            UNCONN          0                0                          127.0.0.53%lo:53                             0.0.0.0:*              users:(("systemd-resolve",pid=1218,fd=16))          
udp            UNCONN          0                0                                0.0.0.0:54308                          0.0.0.0:*              users:(("harbour-sailfis",pid=5773,fd=31))          
udp            UNCONN          0                0                                0.0.0.0:5355                           0.0.0.0:*              users:(("systemd-resolve",pid=1218,fd=11))          
udp            UNCONN          0                0                                0.0.0.0:39144                          0.0.0.0:*              users:(("connmand",pid=4848,fd=19))                 
tcp            LISTEN          0                128                            127.0.0.1:8553                           0.0.0.0:*              users:(("systemd",pid=5191,fd=34))                  
tcp            LISTEN          0                128                              0.0.0.0:5355                           0.0.0.0:*              users:(("systemd-resolve",pid=1218,fd=12))       

and I have this output from the browser, started from the terminal:

avaScript error: resource://gre/modules/SearchS
ervice.jsm, line 213: Error: Something tried to
use the search service before it's been properly
intialized. Please examine the stack trace to f
igure out what and where to fix it:
_ensureInitialized@resource://gre/modules/Search
Service.jsm:213:15
_getEngineDefault@resource://gre/modules/SearchS
ervice.jsm:2178:10
get defaultEngine@resource://gre/modules/SearchS
ervice.jsm:2310:17
keywordToURI@resource://gre/modules/URIFixup.jsm
:496:1
tryKeywordFixupForURIInfo@resource://gre/modules
/URIFixup.jsm:730:41
keywordURIFixup@resource://gre/modules/URIFixup.
jsm:946:12
getFixupURIInfo@resource://gre/modules/URIFixup.
jsm:421:7

JavaScript error: resource://gre/modules/SearchS
ervice.jsm, line 213: Error: Something tried to
use the search service before it's been properly
intialized. Please examine the stack trace to f
igure out what and where to fix it:
_ensureInitialized@resource://gre/modules/Search
Service.jsm:213:15
_getEngineDefault@resource://gre/modules/SearchS
ervice.jsm:2178:10
get defaultEngine@resource://gre/modules/SearchS
ervice.jsm:2310:17
keywordToURI@resource://gre/modules/URIFixup.jsm
:496:1
tryKeywordFixupForURIInfo@resource://gre/modules
/URIFixup.jsm:730:41
getFixupURIInfo@resource://gre/modules/URIFixup.
jsm:438:32

JavaScript error: resource://gre/modules/URIFixu
p.jsm, line 443: NS_ERROR_MALFORMED_URI: Couldn'
t build a valid uri

All looks good. Please restart the phone.

I’ve done it several times, it doesn’t help.

This time as well? Please do it. You have done too much strange things.

Can this be a SailJail problem?

When I start 9Gag from the app launcher, an error message appears saying “api.9gag.com not found”. If I start it from the terminal, it works. It’s the same with the sfos-forum-viewer. It doesn’t work from the app launcher, but it does work from the terminal.

If I disable SailJail for the app (Sandboxing=Disabled) then it starts too.

Yes, I know, I try too much and take too many risks. I just wanted to bypass the provider’s DNS servers.
The restart didn’t change anything.

Ok. So, native SFOS apps uses /etc/resolv.conf to resolv DNS. Please install dig or drill and test
drill @127.0.0.53 jolla.com
Should it does resolve correctly and you have nameserver=127.0.0.53 in /etc/resolv.conf you are alone with your issue.

rill @127.0.0.53 jolla.com
;; ->>HEADER<<- opcode: QUERY, rcode: NOERROR, id: 36969
;; flags: qr rd ra ; QUERY: 1, ANSWER: 3, AUTHORITY: 0, ADDITIONAL: 0 
;; QUESTION SECTION:
;; jolla.com.   IN      A

;; ANSWER SECTION:
jolla.com.      300     IN      A       34.240.159.13
jolla.com.      300     IN      A       54.195.105.17
jolla.com.      300     IN      A       3.248.4.134

;; AUTHORITY SECTION:

;; ADDITIONAL SECTION:

;; Query time: 41 msec
;; SERVER: 127.0.0.53
;; WHEN: Sat Aug  1 10:35:06 2026
;; MSG SIZE  rcvd: 75

All correct.

So yes, I’ve created another great problem for myself.

Because of the progress on my problem, I have adjusted the intial post, the problem is more SailJail and not DNS.