āĻĢā§āϰāĻŋāĻŦāĻŋāĻāϏāĻĄāĻŋ-āϤ⧇ āĻŦāĻžāĻ§ā§āϝāϤāĻžāĻŽā§‚āϞāĻ• āĻ…āϧāĻŋāĻ•āĻžāϰ āĻŦāĻŋāϤāϰāĻŖ āĻŽāĻĄā§‡āϞ

āĻ­ā§‚āĻŽāĻŋāĻ•āĻž

āϏāĻžāĻ°ā§āĻ­āĻžāϰ āύāĻŋāϰāĻžāĻĒāĻ¤ā§āϤāĻž āĻāĻ•āϟāĻŋ āĻ…āϤāĻŋāϰāĻŋāĻ•ā§āϤ āĻ¸ā§āϤāϰ āĻĒā§āϰāĻĻāĻžāύ āĻ•āϰāϤ⧇, āφāĻĒāύāĻŋ āĻŦā§āϝāĻŦāĻšāĻžāϰ āĻ•āϰāϤ⧇ āĻĒāĻžāϰ⧇āύ āĻŽā§āϝāĻžāĻ¨ā§āĻĄā§‡āϟ āĻŽāĻĄā§‡āϞ āĻ…ā§āϝāĻžāĻ•ā§āϏ⧇āϏ āĻŦāĻŋāϤāϰāĻŖāĨ¤ āĻāχ āĻĒā§āϰāĻ•āĻžāĻļāύāĻžāϟāĻŋ āĻŦāĻ°ā§āĻŖāύāĻž āĻ•āϰāĻŦ⧇ āĻ•āĻŋāĻ­āĻžāĻŦ⧇ āφāĻĒāύāĻŋ āĻāĻ•āϟāĻŋ āĻ•āĻžāϰāĻžāĻ—āĻžāϰ⧇ āĻ…ā§āϝāĻžāĻĒāĻžāϚāĻŋ āϚāĻžāϞāĻžāϤ⧇ āĻĒāĻžāϰ⧇āύ āĻļ⧁āϧ⧁āĻŽāĻžāĻ¤ā§āϰ āϏ⧇āχ āωāĻĒāĻžāĻĻāĻžāύāϗ⧁āϞāĻŋāϤ⧇ āĻ…ā§āϝāĻžāĻ•ā§āϏ⧇āϏ āϏāĻš āϝ⧇āϗ⧁āϞāĻŋ āϏāĻ āĻŋāĻ•āĻ­āĻžāĻŦ⧇ āĻ•āĻžāϜ āĻ•āϰāĻžāϰ āϜāĻ¨ā§āϝ apache āĻāĻŦāĻ‚ php-āĻāϰ āĻ…ā§āϝāĻžāĻ•ā§āϏ⧇āϏ āĻĒā§āϰāϝāĻŧā§‹āϜāύ⧎ āĻāχ āύ⧀āϤāĻŋ āĻŦā§āϝāĻŦāĻšāĻžāϰ āĻ•āϰ⧇, āφāĻĒāύāĻŋ āĻļ⧁āϧ⧁āĻŽāĻžāĻ¤ā§āϰ Apache āύāϝāĻŧ, āĻ…āĻ¨ā§āϝ āϕ⧋āύ⧋ āĻ¸ā§āĻŸā§āϝāĻžāĻ•āϕ⧇āĻ“ āϏ⧀āĻŽāĻžāĻŦāĻĻā§āϧ āĻ•āϰāϤ⧇ āĻĒāĻžāϰ⧇āύāĨ¤

āĻĒā§āϰāĻļāĻŋāĻ•ā§āώāĻŖ

āĻāχ āĻĒāĻĻā§āϧāϤāĻŋāϟāĻŋ āĻļ⧁āϧ⧁āĻŽāĻžāĻ¤ā§āϰ ufs āĻĢāĻžāχāϞ āϏāĻŋāĻ¸ā§āĻŸā§‡āĻŽā§‡āϰ āϜāĻ¨ā§āϝ āωāĻĒāϝ⧁āĻ•ā§āϤ; āĻāχ āωāĻĻāĻžāĻšāϰāϪ⧇, zfs āĻĒā§āϰāϧāĻžāύ āϏāĻŋāĻ¸ā§āĻŸā§‡āĻŽā§‡ āĻāĻŦāĻ‚ ufs āϝāĻĨāĻžāĻ•ā§āϰāĻŽā§‡ āĻœā§‡āϞ⧇ āĻŦā§āϝāĻŦāĻšāĻžāϰ āĻ•āϰāĻž āĻšāĻŦ⧇āĨ¤ āĻĒā§āϰāĻĨāĻŽ āϧāĻžāĻĒ āĻšāϞ āĻ•āĻžāĻ°ā§āύ⧇āϞ āĻĒ⧁āύāĻ°ā§āύāĻŋāĻ°ā§āĻŽāĻžāĻŖ āĻ•āϰāĻž; FreeBSD āχāύāĻ¸ā§āϟāϞ āĻ•āϰāĻžāϰ āϏāĻŽāϝāĻŧ, āϏ⧋āĻ°ā§āϏ āϕ⧋āĻĄāϟāĻŋ āχāύāĻ¸ā§āϟāϞ āĻ•āϰ⧁āύāĨ¤
āϏāĻŋāĻ¸ā§āĻŸā§‡āĻŽ āχāύāĻ¸ā§āϟāϞ āĻ•āϰāĻžāϰ āĻĒāϰ⧇, āĻĢāĻžāχāϞāϟāĻŋ āϏāĻŽā§āĻĒāĻžāĻĻāύāĻž āĻ•āϰ⧁āύ:

/usr/src/sys/amd64/conf/GENERIC

āφāĻĒāύāĻžāϕ⧇ āĻāχ āĻĢāĻžāχāϞāϟāĻŋāϤ⧇ āĻļ⧁āϧ⧁āĻŽāĻžāĻ¤ā§āϰ āĻāĻ•āϟāĻŋ āϞāĻžāχāύ āϝ⧋āĻ— āĻ•āϰāϤ⧇ āĻšāĻŦ⧇:

options     MAC_MLS

āĻāĻŽāĻāϞāĻāϏ/āύāĻŋāĻŽā§āύ āϞ⧇āĻŦ⧇āϞ⧇āϰ āωāĻĒāϰ āĻāĻŽāĻāϞāĻāϏ/āĻšāĻžāχ āϞ⧇āĻŦ⧇āϞ⧇āϰ āĻāĻ•āϟāĻŋ āĻĒā§āϰāĻ­āĻžāĻŦāĻļāĻžāϞ⧀ āĻ…āĻŦāĻ¸ā§āĻĨāĻžāύ āĻĨāĻžāĻ•āĻŦ⧇, āĻāĻŽāĻāϞāĻāϏ/āύāĻŋāĻŽā§āύ āϞ⧇āĻŦ⧇āϞ āĻĻāĻŋāϝāĻŧ⧇ āϚāĻžāϞ⧁ āĻ•āϰāĻž āĻ…ā§āϝāĻžāĻĒā§āϞāĻŋāϕ⧇āĻļāύāϗ⧁āϞāĻŋ āĻāĻŽāĻāϞāĻāϏ/āĻšāĻžāχ āϞ⧇āĻŦ⧇āϞāϝ⧁āĻ•ā§āϤ āĻĢāĻžāχāϞāϗ⧁āϞāĻŋāϤ⧇ āĻ…ā§āϝāĻžāĻ•ā§āϏ⧇āϏ āĻ•āϰāϤ⧇ āϏāĻ•ā§āώāĻŽ āĻšāĻŦ⧇ āύāĻžāĨ¤ āĻĢā§āϰāĻŋāĻŦāĻŋāĻāϏāĻĄāĻŋ āϏāĻŋāĻ¸ā§āĻŸā§‡āĻŽā§‡ āωāĻĒāϞāĻŦā§āϧ āϏāĻŽāĻ¸ā§āϤ āĻŸā§āϝāĻžāĻ— āϏāĻŽā§āĻĒāĻ°ā§āϕ⧇ āφāϰāĻ“ āĻŦāĻŋāĻļāĻĻ āĻāϤ⧇ āĻĒāĻžāĻ“āϝāĻŧāĻž āϝāĻžāĻŦ⧇ āύāĻŋāĻ°ā§āĻĻ⧇āĻļāĻŋāĻ•āĻž.
āĻĒāϰāĻŦāĻ°ā§āϤ⧀, /usr/src āĻĄāĻŋāϰ⧇āĻ•ā§āϟāϰāĻŋāϤ⧇ āϝāĻžāύ:

cd /usr/src

āĻ•āĻžāĻ°ā§āύ⧇āϞ āϤ⧈āϰāĻŋ āĻļ⧁āϰ⧁ āĻ•āϰāϤ⧇, āϚāĻžāϞāĻžāύ (j āϕ⧀-āϤ⧇, āϏāĻŋāĻ¸ā§āĻŸā§‡āĻŽā§‡ āϕ⧋āϰ⧇āϰ āϏāĻ‚āĻ–ā§āϝāĻž āωāĻ˛ā§āϞ⧇āĻ– āĻ•āϰ⧁āύ):

make -j 4 buildkernel KERNCONF=GENERIC

āĻ•āĻžāĻ°ā§āύ⧇āϞ āĻ•āĻŽā§āĻĒāĻžāχāϞ āĻ•āϰāĻžāϰ āĻĒāϰ⧇, āĻāϟāĻŋ āχāύāĻ¸ā§āϟāϞ āĻ•āϰāĻž āφāĻŦāĻļā§āϝāĻ•:

make installkernel KERNCONF=GENERIC

āĻ•āĻžāĻ°ā§āύ⧇āϞ āχāύāĻ¸ā§āϟāϞ āĻ•āϰāĻžāϰ āĻĒāϰ⧇, āϏāĻŋāĻ¸ā§āĻŸā§‡āĻŽāϟāĻŋ āĻĒ⧁āύāϰāĻžāϝāĻŧ āĻŦ⧁āϟ āĻ•āϰāĻžāϰ āϜāĻ¨ā§āϝ āϤāĻžāĻĄāĻŧāĻžāĻšā§āĻĄāĻŧā§‹ āĻ•āϰāĻŦ⧇āύ āύāĻž, āϝ⧇āĻšā§‡āϤ⧁ āĻŦā§āϝāĻŦāĻšāĻžāϰāĻ•āĻžāϰ⧀āĻĻ⧇āϰ āϞāĻ—āχāύ āĻ•ā§āϞāĻžāϏ⧇ āĻ¸ā§āĻĨāĻžāύāĻžāĻ¨ā§āϤāϰ āĻ•āϰāĻž āĻĒā§āϰāϝāĻŧā§‹āϜāύ, āĻāϟāĻŋ āĻĒā§‚āĻ°ā§āĻŦ⧇ āĻ•āύāĻĢāĻŋāĻ—āĻžāϰ āĻ•āϰāĻž āĻšāϝāĻŧ⧇āϛ⧇āĨ¤ /etc/login.conf āĻĢāĻžāχāϞāϟāĻŋ āϏāĻŽā§āĻĒāĻžāĻĻāύāĻž āĻ•āϰ⧁āύ, āĻāχ āĻĢāĻžāχāϞāϟāĻŋāϤ⧇ āφāĻĒāύāĻžāϕ⧇ āĻĄāĻŋāĻĢāĻ˛ā§āϟ āϞāĻ—āχāύ āĻ•ā§āϞāĻžāϏ āϏāĻŽā§āĻĒāĻžāĻĻāύāĻž āĻ•āϰāϤ⧇ āĻšāĻŦ⧇, āĻĢāĻ°ā§āĻŽāϟāĻŋāϤ⧇ āφāύ⧁āύ:

default:
        :passwd_format=sha512:
        :copyright=/etc/COPYRIGHT:
        :welcome=/etc/motd:
        :setenv=MAIL=/var/mail/$,BLOCKSIZE=K:
        :path=/sbin /bin /usr/sbin /usr/bin /usr/local/sbin /usr/local/bin ~/bin:
        :nologin=/var/run/nologin:
        :cputime=unlimited:
        :datasize=unlimited:
        :stacksize=unlimited:
        :memorylocked=64K:
        :memoryuse=unlimited:
        :filesize=unlimited:
        :coredumpsize=unlimited:
        :openfiles=unlimited:
        :maxproc=unlimited:
        :sbsize=unlimited:
        :vmemoryuse=unlimited:
        :swapuse=unlimited:
        :pseudoterminals=unlimited:
        :kqueues=unlimited:
        :umtxp=unlimited:
        :priority=0:
        :ignoretime@:
        :umask=022:
        :label=mls/equal:

āϞāĻžāχāύ :label=mls/equal āĻŦā§āϝāĻŦāĻšāĻžāϰāĻ•āĻžāϰ⧀āĻĻ⧇āϰ āϝāĻžāϰāĻž āĻāχ āĻļā§āϰ⧇āĻŖā§€āϰ āϏāĻĻāĻ¸ā§āϝ āϏ⧇āχ āĻĢāĻžāχāϞāϗ⧁āϞāĻŋāϕ⧇ āϝ⧇āϕ⧋āύ āϞ⧇āĻŦ⧇āϞ (mls/low, mls/high) āĻĻāĻŋāϝāĻŧ⧇ āϚāĻŋāĻšā§āύāĻŋāϤ āĻĢāĻžāχāϞāϗ⧁āϞāĻŋ āĻ…ā§āϝāĻžāĻ•ā§āϏ⧇āϏ āĻ•āϰāĻžāϰ āĻ…āύ⧁āĻŽāϤāĻŋ āĻĻ⧇āĻŦ⧇āĨ¤ āĻāχ āĻŽā§āϝāĻžāύāĻŋāĻĒ⧁āϞ⧇āĻļāύ⧇āϰ āĻĒāϰ⧇, āφāĻĒāύāĻžāϕ⧇ āĻĄāĻžāϟāĻžāĻŦ⧇āϏ āĻĒ⧁āύāĻ°ā§āύāĻŋāĻ°ā§āĻŽāĻžāĻŖ āĻ•āϰāϤ⧇ āĻšāĻŦ⧇ āĻāĻŦāĻ‚ āĻāχ āϞāĻ—āχāύ āĻ•ā§āϞāĻžāϏ⧇ āϰ⧁āϟ āĻŦā§āϝāĻŦāĻšāĻžāϰāĻ•āĻžāϰ⧀āϕ⧇ (āĻĒāĻžāĻļāĻžāĻĒāĻžāĻļāĻŋ āϝāĻžāĻĻ⧇āϰ āĻāϟāĻŋ āĻĒā§āϰāϝāĻŧā§‹āϜāύ) āĻ¸ā§āĻĨāĻžāĻĒāύ āĻ•āϰāϤ⧇ āĻšāĻŦ⧇:

cap_mkdb /etc/login.conf
pw usermod root -L default

āύ⧀āϤāĻŋ āĻļ⧁āϧ⧁āĻŽāĻžāĻ¤ā§āϰ āĻĢāĻžāχāϞāϗ⧁āϞāĻŋāϤ⧇ āĻĒā§āϰāϝāĻŧā§‹āĻ— āĻ•āϰāĻžāϰ āϜāĻ¨ā§āϝ, āφāĻĒāύāĻžāϕ⧇ /etc/mac.conf āĻĢāĻžāχāϞāϟāĻŋ āϏāĻŽā§āĻĒāĻžāĻĻāύāĻž āĻ•āϰāϤ⧇ āĻšāĻŦ⧇, āĻāϤ⧇ āĻļ⧁āϧ⧁āĻŽāĻžāĻ¤ā§āϰ āĻāĻ•āϟāĻŋ āϞāĻžāχāύ āϰ⧇āϖ⧇ āĻĻāĻŋāύ:

default_labels file ?mls

āĻāĻ›āĻžāĻĄāĻŧāĻžāĻ“ āφāĻĒāύāĻžāϕ⧇ āĻ…āĻŸā§‹āϰāĻžāύ⧇ mac_mls.ko āĻŽāĻĄāĻŋāωāϞ āϝ⧋āĻ— āĻ•āϰāϤ⧇ āĻšāĻŦ⧇:

echo 'mac_mls_load="YES"' >> /boot/loader.conf

āĻāϰ āĻĒāϰ⧇, āφāĻĒāύāĻŋ āύāĻŋāϰāĻžāĻĒāĻĻ⧇ āϏāĻŋāĻ¸ā§āĻŸā§‡āĻŽāϟāĻŋ āĻĒ⧁āύāϰāĻžāϝāĻŧ āĻŦ⧁āϟ āĻ•āϰāϤ⧇ āĻĒāĻžāϰ⧇āύāĨ¤ āĻ•āĻŋāĻ­āĻžāĻŦ⧇ āϤ⧈āϰāĻŋ āĻ•āϰāĻŦ⧇āύ āĻœā§‡āϞ āφāĻĒāύāĻŋ āφāĻŽāĻžāϰ āĻĒā§āϰāĻ•āĻžāĻļāύāĻž āĻāĻ• āĻāϟāĻŋ āĻĒāĻĄāĻŧāϤ⧇ āĻĒāĻžāϰ⧇āύ. āĻ•āĻŋāĻ¨ā§āϤ⧁ āĻāĻ•āϟāĻŋ āĻœā§‡āϞ āϤ⧈āϰāĻŋ āĻ•āϰāĻžāϰ āφāϗ⧇, āφāĻĒāύāĻžāϕ⧇ āĻāĻ•āϟāĻŋ āĻšāĻžāĻ°ā§āĻĄ āĻĄā§āϰāĻžāχāĻ­ āϝ⧋āĻ— āĻ•āϰāϤ⧇ āĻšāĻŦ⧇ āĻāĻŦāĻ‚ āĻāϟāĻŋāϤ⧇ āĻāĻ•āϟāĻŋ āĻĢāĻžāχāϞ āϏāĻŋāĻ¸ā§āĻŸā§‡āĻŽ āϤ⧈āϰāĻŋ āĻ•āϰāϤ⧇ āĻšāĻŦ⧇ āĻāĻŦāĻ‚ āĻāϤ⧇ āĻŽāĻžāĻ˛ā§āϟāĻŋāϞ⧇āĻŦ⧇āϞ āϏāĻ•ā§āώāĻŽ āĻ•āϰāϤ⧇ āĻšāĻŦ⧇, 2kb āĻāϰ āĻ•ā§āϞāĻžāĻ¸ā§āϟāĻžāϰ āφāĻ•āĻžāϰ⧇āϰ āϏāĻžāĻĨ⧇ āĻāĻ•āϟāĻŋ ufs64 āĻĢāĻžāχāϞ āϏāĻŋāĻ¸ā§āĻŸā§‡āĻŽ āϤ⧈āϰāĻŋ āĻ•āϰāϤ⧇ āĻšāĻŦ⧇:

newfs -O 2 -b 64kb /dev/ada1
tunefs -l enable /dev/ada1

āĻĢāĻžāχāϞ āϏāĻŋāĻ¸ā§āĻŸā§‡āĻŽ āϤ⧈āϰāĻŋ āĻāĻŦāĻ‚ āĻŽāĻžāĻ˛ā§āϟāĻŋāϞ⧇āĻŦ⧇āϞ āϝ⧋āĻ— āĻ•āϰāĻžāϰ āĻĒāϰ⧇, āφāĻĒāύāĻžāϕ⧇ /etc/fstab-āĻ āĻšāĻžāĻ°ā§āĻĄ āĻĄā§āϰāĻžāχāĻ­ āϝ⧋āĻ— āĻ•āϰāϤ⧇ āĻšāĻŦ⧇, āĻāχ āĻĢāĻžāχāϞāϟāĻŋāϤ⧇ āϞāĻžāχāύ āϝ⧋āĻ— āĻ•āϰ⧁āύ:

/dev/ada1               /jail  ufs     rw              0       1

āĻŽāĻžāωāĻ¨ā§āϟāĻĒāϝāĻŧ⧇āĻ¨ā§āĻŸā§‡, āφāĻĒāύāĻŋ āϝ⧇ āĻĄāĻŋāϰ⧇āĻ•ā§āϟāϰāĻŋāϤ⧇ āĻšāĻžāĻ°ā§āĻĄ āĻĄā§āϰāĻžāχāĻ­āϟāĻŋ āĻŽāĻžāωāĻ¨ā§āϟ āĻ•āϰāĻŦ⧇āύ āϤāĻž āύāĻŋāĻ°ā§āĻĻāĻŋāĻˇā§āϟ āĻ•āϰ⧁āύ; āĻĒāĻžāϏ⧇, 1 āύāĻŋāĻ°ā§āĻĻāĻŋāĻˇā§āϟ āĻ•āϰāϤ⧇ āϭ⧁āϞāĻŦ⧇āύ āύāĻž (āĻāχ āĻšāĻžāĻ°ā§āĻĄ āĻĄā§āϰāĻžāχāĻ­āϟāĻŋ āϕ⧀ āĻ•ā§āϰāĻŽāĻžāύ⧁āϏāĻžāϰ⧇ āĻšā§‡āĻ• āĻ•āϰāĻž āĻšāĻŦ⧇) - āĻāϟāĻŋ āĻĒā§āϰāϝāĻŧā§‹āϜāύ⧀āϝāĻŧ, āϝ⧇āĻšā§‡āϤ⧁ ufs āĻĢāĻžāχāϞ āϏāĻŋāĻ¸ā§āĻŸā§‡āĻŽ āĻšāĻ āĻžā§Ž āĻĒāĻžāĻ“āϝāĻŧāĻžāϰ āĻ•āĻžāĻŸā§‡āϰ āϜāĻ¨ā§āϝ āϏāĻ‚āĻŦ⧇āĻĻāύāĻļā§€āϞāĨ¤ . āĻāχ āĻĒāĻĻāĻ•ā§āώ⧇āĻĒ⧇āϰ āĻĒāϰ⧇, āĻĄāĻŋāĻ¸ā§āĻ• āĻŽāĻžāωāĻ¨ā§āϟ āĻ•āϰ⧁āύ:

mount /dev/ada1 /jail

āĻāχ āĻĄāĻŋāϰ⧇āĻ•ā§āϟāϰāĻŋāϤ⧇ āĻœā§‡āϞ āχāύāĻ¸ā§āϟāϞ āĻ•āϰ⧁āύāĨ¤ āĻœā§‡āϞāϟāĻŋ āϚāϞāĻžāϰ āĻĒāϰ⧇, āφāĻĒāύāĻžāϕ⧇ āĻŦā§āϝāĻŦāĻšāĻžāϰāĻ•āĻžāϰ⧀āĻĻ⧇āϰ āĻāĻŦāĻ‚ āĻĢāĻžāχāϞāϗ⧁āϞāĻŋāϰ āϏāĻžāĻĨ⧇ āĻŽā§‚āϞ āϏāĻŋāĻ¸ā§āĻŸā§‡āĻŽā§‡āϰ āĻŽāϤ⧋ āĻāĻ•āχ āĻŽā§āϝāĻžāύāĻŋāĻĒ⧁āϞ⧇āĻļāύāϗ⧁āϞāĻŋ āĻ•āϰāϤ⧇ āĻšāĻŦ⧇ /etc/login.conf, /etc/mac.conf⧎

āϏāĻŽāĻ¨ā§āĻŦāϝāĻŧ

āĻĒā§āϰāϝāĻŧā§‹āϜāύ⧀āϝāĻŧ āĻŸā§āϝāĻžāĻ— āχāύāĻ¸ā§āϟāϞ āĻ•āϰāĻžāϰ āφāϗ⧇, āφāĻŽāĻŋ āϏāĻŽāĻ¸ā§āϤ āĻĒā§āϰāϝāĻŧā§‹āϜāύ⧀āϝāĻŧ āĻĒā§āϝāĻžāϕ⧇āϜ āχāύāĻ¸ā§āϟāϞ āĻ•āϰāĻžāϰ āĻĒāϰāĻžāĻŽāĻ°ā§āĻļ āĻĻāĻŋāĻšā§āĻ›āĻŋ; āφāĻŽāĻžāϰ āĻ•ā§āώ⧇āĻ¤ā§āϰ⧇, āĻāχ āĻĒā§āϝāĻžāϕ⧇āϜāϗ⧁āϞāĻŋāϕ⧇ āĻŦāĻŋāĻŦ⧇āϚāύāĻžāϝāĻŧ āϰ⧇āϖ⧇ āĻŸā§āϝāĻžāĻ—āϗ⧁āϞāĻŋ āϏ⧇āϟ āĻ•āϰāĻž āĻšāĻŦ⧇:

mod_php73-7.3.4_1              PHP Scripting Language
php73-7.3.4_1                  PHP Scripting Language
php73-ctype-7.3.4_1            The ctype shared extension for php
php73-curl-7.3.4_1             The curl shared extension for php
php73-dom-7.3.4_1              The dom shared extension for php
php73-extensions-1.0           "meta-port" to install PHP extensions
php73-filter-7.3.4_1           The filter shared extension for php
php73-gd-7.3.4_1               The gd shared extension for php
php73-gettext-7.3.4_1          The gettext shared extension for php
php73-hash-7.3.4_1             The hash shared extension for php
php73-iconv-7.3.4_1            The iconv shared extension for php
php73-json-7.3.4_1             The json shared extension for php
php73-mysqli-7.3.4_1           The mysqli shared extension for php
php73-opcache-7.3.4_1          The opcache shared extension for php
php73-openssl-7.3.4_1          The openssl shared extension for php
php73-pdo-7.3.4_1              The pdo shared extension for php
php73-pdo_sqlite-7.3.4_1       The pdo_sqlite shared extension for php
php73-phar-7.3.4_1             The phar shared extension for php
php73-posix-7.3.4_1            The posix shared extension for php
php73-session-7.3.4_1          The session shared extension for php
php73-simplexml-7.3.4_1        The simplexml shared extension for php
php73-sqlite3-7.3.4_1          The sqlite3 shared extension for php
php73-tokenizer-7.3.4_1        The tokenizer shared extension for php
php73-xml-7.3.4_1              The xml shared extension for php
php73-xmlreader-7.3.4_1        The xmlreader shared extension for php
php73-xmlrpc-7.3.4_1           The xmlrpc shared extension for php
php73-xmlwriter-7.3.4_1        The xmlwriter shared extension for php
php73-xsl-7.3.4_1              The xsl shared extension for php
php73-zip-7.3.4_1              The zip shared extension for php
php73-zlib-7.3.4_1             The zlib shared extension for php
apache24-2.4.39 

āĻāχ āωāĻĻāĻžāĻšāϰāϪ⧇, āĻāχ āĻĒā§āϝāĻžāϕ⧇āĻœā§‡āϰ āύāĻŋāĻ°ā§āĻ­āϰāϤāĻž āĻŦāĻŋāĻŦ⧇āϚāύāĻž āĻ•āϰ⧇ āϞ⧇āĻŦ⧇āϞ āϏ⧇āϟ āĻ•āϰāĻž āĻšāĻŦ⧇āĨ¤ āĻ…āĻŦāĻļā§āϝāχ, āφāĻĒāύāĻŋ āĻāϟāĻŋ āφāϰāĻ“ āϏāĻšāϜ āĻ•āϰāϤ⧇ āĻĒāĻžāϰ⧇āύ: /usr/local/lib āĻĢā§‹āĻ˛ā§āĻĄāĻžāϰ āĻāĻŦāĻ‚ āĻāχ āĻĄāĻŋāϰ⧇āĻ•ā§āϟāϰāĻŋāϤ⧇ āĻ…āĻŦāĻ¸ā§āĻĨāĻŋāϤ āĻĢāĻžāχāϞāϗ⧁āϞāĻŋāϰ āϜāĻ¨ā§āϝ, mls/low āϞ⧇āĻŦ⧇āϞ āϏ⧇āϟ āĻ•āϰ⧁āύ āĻāĻŦāĻ‚ āĻĒāϰāĻŦāĻ°ā§āϤ⧀ āχāύāĻ¸ā§āϟāϞ āĻ•āϰāĻž āĻĒā§āϝāĻžāϕ⧇āϜāϗ⧁āϞāĻŋ (āωāĻĻāĻžāĻšāϰāĻŖāĻ¸ā§āĻŦāϰ⧂āĻĒ, php-āĻāϰ āϜāĻ¨ā§āϝ āĻ…āϤāĻŋāϰāĻŋāĻ•ā§āϤ āĻāĻ•ā§āϏāĻŸā§‡āύāĻļāύ) āĻ…ā§āϝāĻžāĻ•ā§āϏ⧇āϏ āĻ•āϰāϤ⧇ āϏāĻ•ā§āώāĻŽ āĻšāĻŦ⧇āĨ¤ āĻāχ āĻĄāĻŋāϰ⧇āĻ•ā§āϟāϰāĻŋāϰ āĻŽāĻ§ā§āϝ⧇ āϞāĻžāχāĻŦā§āϰ⧇āϰāĻŋ, āĻ•āĻŋāĻ¨ā§āϤ⧁ āĻāϟāĻŋ āφāĻŽāĻžāϰ āĻ•āĻžāϛ⧇ āĻ­āĻžāϞ āĻŽāύ⧇ āĻšāϝāĻŧ āĻļ⧁āϧ⧁āĻŽāĻžāĻ¤ā§āϰ āϏ⧇āχ āĻĢāĻžāχāϞāϗ⧁āϞāĻŋāϤ⧇ āĻ…ā§āϝāĻžāĻ•ā§āϏ⧇āϏ āĻĒā§āϰāĻĻāĻžāύ āĻ•āϰ⧇ āϝāĻž āĻĒā§āϰāϝāĻŧā§‹āϜāύ⧀āϝāĻŧāĨ¤ āĻœā§‡āϞ āĻŦāĻ¨ā§āϧ āĻ•āϰ⧁āύ āĻāĻŦāĻ‚ āϏāĻŽāĻ¸ā§āϤ āĻĢāĻžāχāϞ⧇ āĻāĻŽāĻāϞāĻāϏ/āĻšāĻžāχ āϞ⧇āĻŦ⧇āϞ āϏ⧇āϟ āĻ•āϰ⧁āύ:

setfmac -R mls/high /jail

āϚāĻŋāĻšā§āύ āϏ⧇āϟ āĻ•āϰāĻžāϰ āϏāĻŽāϝāĻŧ, āϏ⧇āϟāĻāĻĢāĻŽā§āϝāĻžāĻ• āĻšāĻžāĻ°ā§āĻĄ āϞāĻŋāĻ™ā§āϕ⧇āϰ āϏāĻŽā§āĻŽā§āĻ–ā§€āύ āĻšāϞ⧇ āĻĒā§āϰāĻ•ā§āϰāĻŋāϝāĻŧāĻžāϟāĻŋ āĻŦāĻ¨ā§āϧ āĻšāϝāĻŧ⧇ āϝāĻžāĻŦ⧇, āφāĻŽāĻžāϰ āωāĻĻāĻžāĻšāϰāϪ⧇ āφāĻŽāĻŋ āύāĻŋāĻŽā§āύāϞāĻŋāĻ–āĻŋāϤ āĻĄāĻŋāϰ⧇āĻ•ā§āϟāϰāĻŋāϗ⧁āϞāĻŋāϤ⧇ āĻšāĻžāĻ°ā§āĻĄ āϞāĻŋāĻ™ā§āĻ•āϗ⧁āϞāĻŋ āĻŽā§āϛ⧇ āĻĻāĻŋāϝāĻŧ⧇āĻ›āĻŋ:

/var/db/etcupdate/current/
/var/db/etcupdate/current/etc
/var/db/etcupdate/current/usr/share/openssl/man/en.ISO8859-15
/var/db/etcupdate/current/usr/share/man/en.ISO8859-15
/var/db/etcupdate/current/usr/share/man/en.UTF-8
/var/db/etcupdate/current/usr/share/nls
/etc/ssl
/usr/local/etc
/usr/local/etc/fonts/conf.d
/usr/local/openssl

āϞ⧇āĻŦ⧇āϞāϗ⧁āϞāĻŋ āϏ⧇āϟ āĻ•āϰāĻžāϰ āĻĒāϰ⧇, āφāĻĒāύāĻžāϕ⧇ āĻ…ā§āϝāĻžāĻĒāĻžāϚāĻŋāϰ āϜāĻ¨ā§āϝ āĻāĻŽāĻāϞāĻāϏ/āϞ⧋ āϞ⧇āĻŦ⧇āϞ āϏ⧇āϟ āĻ•āϰāϤ⧇ āĻšāĻŦ⧇, āφāĻĒāύāĻžāϕ⧇ āĻĒā§āϰāĻĨāĻŽā§‡ āϝāĻž āĻ•āϰāϤ⧇ āĻšāĻŦ⧇ āϤāĻž āĻšāϞ āĻ…ā§āϝāĻžāĻĒāĻžāϚāĻŋ āĻļ⧁āϰ⧁ āĻ•āϰāĻžāϰ āϜāĻ¨ā§āϝ āϕ⧋āύ āĻĢāĻžāχāϞāϗ⧁āϞāĻŋāϰ āĻĒā§āϰāϝāĻŧā§‹āϜāύ āϤāĻž āϖ⧁āρāĻœā§‡ āĻŦ⧇āϰ āĻ•āϰ⧁āύ:

ldd /usr/local/sbin/httpd

āĻāχ āĻ•āĻŽāĻžāĻ¨ā§āĻĄāϟāĻŋ āĻ•āĻžāĻ°ā§āϝāĻ•āϰ āĻ•āϰāĻžāϰ āĻĒāϰ⧇, āύāĻŋāĻ°ā§āĻ­āϰāϤāĻžāϗ⧁āϞāĻŋ āĻ¸ā§āĻ•ā§āϰāĻŋāύ⧇ āĻĒā§āϰāĻĻāĻ°ā§āĻļāĻŋāϤ āĻšāĻŦ⧇, āϤāĻŦ⧇ āĻāχ āĻĢāĻžāχāϞāϗ⧁āϞāĻŋāϤ⧇ āĻĒā§āϰāϝāĻŧā§‹āϜāύ⧀āϝāĻŧ āϞ⧇āĻŦ⧇āϞ āϏ⧇āϟ āĻ•āϰāĻž āϝāĻĨ⧇āĻˇā§āϟ āĻšāĻŦ⧇ āύāĻž, āϝ⧇āĻšā§‡āϤ⧁ āĻāχ āĻĢāĻžāχāϞāϗ⧁āϞāĻŋ āϝ⧇ āĻĄāĻŋāϰ⧇āĻ•ā§āϟāϰāĻŋāϗ⧁āϞāĻŋāϤ⧇ āĻ…āĻŦāĻ¸ā§āĻĨāĻŋāϤ āϏ⧇āϗ⧁āϞāĻŋāϤ⧇ mls/āĻšāĻžāχ āϞ⧇āĻŦ⧇āϞ āϰāϝāĻŧ⧇āϛ⧇, āϤāĻžāχ āĻāχ āĻĄāĻŋāϰ⧇āĻ•ā§āϟāϰāĻŋāϗ⧁āϞāĻŋāϕ⧇āĻ“ āϞ⧇āĻŦ⧇āϞ āĻ•āϰāĻž āĻĻāϰāĻ•āĻžāϰāĨ¤ āĻŽāĻŋāϞāĻŋ/āĻ•āĻŽāĨ¤ āĻļ⧁āϰ⧁ āĻ•āϰāĻžāϰ āϏāĻŽāϝāĻŧ, āĻ…ā§āϝāĻžāĻĒāĻžāϚāĻŋ āĻāϟāĻŋ āϚāĻžāϞāĻžāύ⧋āϰ āϜāĻ¨ā§āϝ āĻĒā§āϰāϝāĻŧā§‹āϜāύ⧀āϝāĻŧ āĻĢāĻžāχāϞāϗ⧁āϞāĻŋāĻ“ āφāωāϟāĻĒ⧁āϟ āĻ•āϰāĻŦ⧇ āĻāĻŦāĻ‚ php-āĻāϰ āϜāĻ¨ā§āϝ āĻāχ āύāĻŋāĻ°ā§āĻ­āϰāϤāĻžāϗ⧁āϞāĻŋ httpd-error.log āϞāϗ⧇ āĻĒāĻžāĻ“āϝāĻŧāĻž āϝāĻžāĻŦ⧇āĨ¤

setfmac mls/low /
setfmac mls/low /usr/local/lib/libpcre.so.1
setfmac mls/low /usr/local/lib/libaprutil-1.so.0
setfmac mls/low /usr/local/lib/libdb-5.3.so.0
setfmac mls/low /usr/local/lib/libgdbm.so.6
setfmac mls/low /usr/local/lib/libexpat.so.1
setfmac mls/low /usr/local/lib/libapr-1.so.0
setfmac mls/low /lib/libcrypt.so.5
setfmac mls/low /lib/libthr.so.3
setfmac mls/low /lib/libc.so.7
setfmac mls/low /usr/local/lib/libintl.so.8
setfmac mls/low /var
setfmac mls/low /var/run
setfmac mls/low /var/log
setfmac mls/low /var/log/httpd-access.log
setfmac mls/low /var/log/httpd-error.log
setfmac mls/low /var/run/httpd.pid
setfmac mls/low /lib
setfmac mls/low /lib/libcrypt.so.5
setfmac mls/low /usr/local/lib/db5/libdb-5.3.so.0
setfmac mls/low /usr/local/lib/db5/libdb-5.3.so.0.0.0
setfmac mls/low /usr/local/lib/db5
setfmac mls/low /usr/local/lib
setfmac mls/low /libexec
setfmac mls/low /libexec/ld-elf.so.1
setfmac  mls/low /dev
setfmac  mls/low /dev/random
setfmac  mls/low /usr/local/libexec
setfmac  mls/low /usr/local/libexec/apache24
setfmac  mls/low /usr/local/libexec/apache24/*
setfmac  mls/low /etc/pwd.db
setfmac  mls/low /etc/passwd
setfmac  mls/low /etc/group
setfmac  mls/low /etc/
setfmac  mls/low /usr/local/etc
setfmac -R mls/low /usr/local/etc/apache24
setfmac mls/low /usr
setfmac mls/low /usr/local
setfmac mls/low /usr/local/sbin
setfmac mls/low /usr/local/sbin/*
setfmac -R mls/low /usr/local/etc/rc.d/
setfmac mls/low /usr/local/sbin/htcacheclean
setfmac mls/low /var/log/httpd-access.log
setfmac mls/low /var/log/httpd-error.log
setfmac -R mls/low /usr/local/www
setfmac mls/low /usr/lib
setfmac mls/low /tmp
setfmac -R mls/low /usr/local/lib/php
setfmac -R mls/low /usr/local/etc/php
setfmac mls/low /usr/local/etc/php.conf
setfmac mls/low /lib/libelf.so.2
setfmac mls/low /lib/libm.so.5
setfmac mls/low /usr/local/lib/libxml2.so.2
setfmac mls/low /lib/libz.so.6
setfmac mls/low /usr/lib/liblzma.so.5
setfmac mls/low /usr/local/lib/libiconv.so.2
setfmac mls/low /usr/lib/librt.so.1
setfmac mls/low /lib/libthr.so.3
setfmac mls/low /usr/local/lib/libpng16.so.16
setfmac mls/low /usr/lib/libbz2.so.4
setfmac mls/low /usr/local/lib/libargon2.so.0
setfmac mls/low /usr/local/lib/libpcre2-8.so.0
setfmac mls/low /usr/local/lib/libsqlite3.so.0
setfmac mls/low /usr/local/lib/libgd.so.6
setfmac mls/low /usr/local/lib/libjpeg.so.8
setfmac mls/low /usr/local/lib/libfreetype.so
setfmac mls/low /usr/local/lib/libfontconfig.so.1
setfmac mls/low /usr/local/lib/libtiff.so.5
setfmac mls/low /usr/local/lib/libwebp.so.7
setfmac mls/low /usr/local/lib/libjbig.so.2
setfmac mls/low /usr/lib/libssl.so.8
setfmac mls/low /lib/libcrypto.so.8
setfmac mls/low /usr/local/lib/libzip.so.5
setfmac mls/low /etc/resolv.conf

āĻāχ āϤāĻžāϞāĻŋāĻ•āĻžāϝāĻŧ āϏāĻŽāĻ¸ā§āϤ āĻĢāĻžāχāϞ⧇āϰ āϜāĻ¨ā§āϝ āĻāĻŽāĻāϞāĻāϏ/āϞ⧋ āĻŸā§āϝāĻžāĻ— āϰāϝāĻŧ⧇āϛ⧇ āϝāĻž āĻ…ā§āϝāĻžāĻĒāĻžāϚāĻŋ āĻāĻŦāĻ‚ āĻĒāĻŋāĻāχāϚāĻĒāĻŋ āϏāĻŽāĻ¨ā§āĻŦāϝāĻŧ⧇āϰ āϏāĻ āĻŋāĻ• āĻ…āĻĒāĻžāϰ⧇āĻļāύ⧇āϰ āϜāĻ¨ā§āϝ āĻĒā§āϰāϝāĻŧā§‹āϜāύ⧀āϝāĻŧ (āφāĻŽāĻžāϰ āωāĻĻāĻžāĻšāϰāϪ⧇ āχāύāĻ¸ā§āϟāϞ āĻ•āϰāĻž āĻĒā§āϝāĻžāϕ⧇āĻœā§‡āϰ āϜāĻ¨ā§āϝ)āĨ¤

āĻāĻŽāĻāϞāĻāϏ/āχāϕ⧁āϝāĻŧāĻžāϞ āϞ⧇āϭ⧇āϞ⧇ āϚāĻžāϞāĻžāύ⧋āϰ āϜāĻ¨ā§āϝ āĻœā§‡āϞ āĻ•āύāĻĢāĻŋāĻ—āĻžāϰ āĻ•āϰāĻž āĻāĻŦāĻ‚ āĻāĻŽāĻāϞāĻāϏ/āύāĻŋāĻŽā§āύ āϞ⧇āϭ⧇āϞ⧇ āĻ…ā§āϝāĻžāĻĒāĻžāϚāĻŋ āĻ•āύāĻĢāĻŋāĻ—āĻžāϰ āĻ•āϰāĻžāĨ¤ āĻœā§‡āϞ āĻļ⧁āϰ⧁ āĻ•āϰāϤ⧇, āφāĻĒāύāĻžāϕ⧇ /etc/rc.d/āĻœā§‡āϞ āĻ¸ā§āĻ•ā§āϰāĻŋāĻĒā§āĻŸā§‡ āĻĒāϰāĻŋāĻŦāĻ°ā§āϤāύ āĻ•āϰāϤ⧇ āĻšāĻŦ⧇, āĻāχ āĻ¸ā§āĻ•ā§āϰāĻŋāĻĒā§āĻŸā§‡ jail_start āĻĢāĻžāĻ‚āĻļāύāϗ⧁āϞāĻŋ āϖ⧁āρāĻœā§‡ āĻŦ⧇āϰ āĻ•āϰāϤ⧇ āĻšāĻŦ⧇, āĻĢāĻ°ā§āĻŽāϟāĻŋāϤ⧇ āĻ•āĻŽāĻžāĻ¨ā§āĻĄ āϭ⧇āϰāĻŋāϝāĻŧ⧇āĻŦāϞ āĻĒāϰāĻŋāĻŦāĻ°ā§āϤāύ āĻ•āϰāϤ⧇ āĻšāĻŦ⧇:

command="setpmac mls/equal $jail_program"

setpmac āĻ•āĻŽāĻžāĻ¨ā§āĻĄāϟāĻŋ āĻĒā§āϰāϝāĻŧā§‹āϜāύ⧀āϝāĻŧ āĻ•ā§āώāĻŽāϤāĻž āĻ¸ā§āϤāϰ⧇ āĻāĻ•ā§āϏāĻŋāĻ•āĻŋāωāĻŸā§‡āĻŦāϞ āĻĢāĻžāχāϞ āϚāĻžāϞāĻžāϝāĻŧ, āĻāχ āĻ•ā§āώ⧇āĻ¤ā§āϰ⧇ mls/āϏāĻŽāĻžāύ, āϝāĻžāϤ⧇ āϏāĻŽāĻ¸ā§āϤ āϞ⧇āĻŦ⧇āϞ⧇ āĻ…ā§āϝāĻžāĻ•ā§āϏ⧇āϏ āĻĨāĻžāϕ⧇āĨ¤ āĻ…ā§āϝāĻžāĻĒāĻžāϚāĻŋāϤ⧇ āφāĻĒāύāĻžāϕ⧇ āĻ¸ā§āϟāĻžāĻ°ā§āϟāφāĻĒ āĻ¸ā§āĻ•ā§āϰāĻŋāĻĒā§āϟ /usr/local/etc/rc.d/apache24 āϏāĻŽā§āĻĒāĻžāĻĻāύāĻž āĻ•āϰāϤ⧇ āĻšāĻŦ⧇āĨ¤ apache24_prestart āĻĢāĻžāĻ‚āĻļāύ āĻĒāϰāĻŋāĻŦāĻ°ā§āϤāύ āĻ•āϰ⧁āύ:

apache24_prestart() {
        apache24_checkfib
        apache24_precmd
        eval "setpmac mls/low" ${command} ${apache24_flags}
}

В āĻĻāĻžāĻĒā§āϤāϰāĻŋāĻ• āĻŽā§āϝāĻžāύ⧁āϝāĻŧāĻžāϞāϟāĻŋāϤ⧇ āĻ…āĻ¨ā§āϝ āĻāĻ•āϟāĻŋ āωāĻĻāĻžāĻšāϰāĻŖ āϰāϝāĻŧ⧇āϛ⧇, āĻ•āĻŋāĻ¨ā§āϤ⧁ āφāĻŽāĻŋ āĻāϟāĻŋ āĻŦā§āϝāĻŦāĻšāĻžāϰ āĻ•āϰāϤ⧇ āĻ…āĻ•ā§āώāĻŽ āĻ›āĻŋāϞāĻžāĻŽ āĻ•āĻžāϰāĻŖ āφāĻŽāĻŋ setpmac āĻ•āĻŽāĻžāĻ¨ā§āĻĄ āĻŦā§āϝāĻŦāĻšāĻžāϰ āĻ•āϰāϤ⧇ āĻ…āĻ•ā§āώāĻŽāϤāĻž āϏāĻŽā§āĻĒāĻ°ā§āϕ⧇ āĻāĻ•āϟāĻŋ āĻŦāĻžāĻ°ā§āϤāĻž āĻĒ⧇āϝāĻŧ⧇āĻ›āĻŋāϞāĻžāĻŽāĨ¤

āωāĻĒāϏāĻ‚āĻšāĻžāϰ

āĻ…ā§āϝāĻžāĻ•ā§āϏ⧇āϏ āĻŦāĻŋāϤāϰāϪ⧇āϰ āĻāχ āĻĒāĻĻā§āϧāϤāĻŋāϟāĻŋ āĻ…ā§āϝāĻžāĻĒāĻžāϚāĻŋāϤ⧇ āĻāĻ•āϟāĻŋ āĻ…āϤāĻŋāϰāĻŋāĻ•ā§āϤ āĻ¸ā§āϤāϰ⧇āϰ āϏ⧁āϰāĻ•ā§āώāĻž āϝ⧋āĻ— āĻ•āϰāĻŦ⧇ (āϝāĻĻāĻŋāĻ“ āĻāχ āĻĒāĻĻā§āϧāϤāĻŋāϟāĻŋ āĻ…āĻ¨ā§āϝ āϕ⧋āύāĻ“ āĻ¸ā§āĻŸā§āϝāĻžāϕ⧇āϰ āϜāĻ¨ā§āϝ āωāĻĒāϝ⧁āĻ•ā§āϤ), āϝāĻž āĻāĻ•āχ āϏāĻŽāϝāĻŧ⧇, āĻĒā§āϰāĻļāĻžāϏāϕ⧇āϰ āϜāĻ¨ā§āϝ āĻāϟāĻŋ āĻ¸ā§āĻŦāĻšā§āĻ›āĻ­āĻžāĻŦ⧇ āĻāĻŦāĻ‚ āĻ…āϞāĻ•ā§āώāĻŋāϤāĻ­āĻžāĻŦ⧇ āϘāϟāĻŦ⧇āĨ¤

āĻāχ āĻĒā§āϰāĻ•āĻžāĻļāύāĻžāϟāĻŋ āϞāĻŋāĻ–āϤ⧇ āφāĻŽāĻžāϕ⧇ āϏāĻžāĻšāĻžāĻ¯ā§āϝ āĻ•āϰ⧇āϛ⧇ āĻāĻŽāύ āωāĻ¤ā§āϏāϗ⧁āϞāĻŋāϰ āϤāĻžāϞāĻŋāĻ•āĻž:

https://www.freebsd.org/doc/ru_RU.KOI8-R/books/handbook/mac.html

āωāĻ¤ā§āϏ: www.habr.com

āĻāĻ•āϟāĻŋ āĻŽāĻ¨ā§āϤāĻŦā§āϝ āϜ⧁āĻĄāĻŧ⧁āύ