{"id":53324,"date":"2019-11-29T00:00:00","date_gmt":"2019-11-28T21:00:00","guid":{"rendered":"https:\/\/prohoster.info\/blog\/blog_prohoster\/vypusk-bubblewrap-0-4-0-proslojki-dlya-sozdaniya-izolirovannyh-okruzhenij"},"modified":"2020-02-18T14:01:13","modified_gmt":"2020-02-18T11:01:13","slug":"vypusk-bubblewrap-0-4-0-proslojki-dlya-sozdaniya-izolirovannyh-okruzhenij","status":"publish","type":"post","link":"https:\/\/prohoster.info\/de\/blog\/news\/vypusk-bubblewrap-0-4-0-proslojki-dlya-sozdaniya-izolirovannyh-okruzhenij","title":{"rendered":"Ver\u00f6ffentlichung von Bubblewrap 0.4.0, einer Schicht zur Erstellung von isolierten Umgebungen","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/containers\/bubblewrap\/releases\/tag\/v0.4.0\">Verf\u00fcgbar<\/a><\/noindex> Neue Ausgabe des Tools <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/containers\/bubblewrap\/\">Bubblewrap 0.4.0<\/a><\/noindex>, das zur Organisation der Arbeit in isolierten Umgebungen unter Linux gedacht ist und auf Anwendungsebene f\u00fcr nicht privilegierte Benutzer funktioniert. In der Praxis wird Bubblewrap vom Flatpak-Projekt als Layer zur Isolation von aus Paketen gestarteten Anwendungen verwendet. Der Projektcode ist in C geschrieben und <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/containers\/bubblewrap\/\">wird verbreitet<\/a><\/noindex> unter der Lizenz LGPLv2+.<\/p>\n<p>Zur Isolation werden traditionelle Linux-Technologien der Container-Virtualisierung verwendet, die auf cgroups, Namensr\u00e4umen (namespaces), Seccomp und SELinux basieren. Um privilegierte Operationen zur Konfiguration des Containers durchzuf\u00fchren, wird Bubblewrap mit Root-Rechten (ausf\u00fchrbare Datei mit suid-Flag) gestartet, gefolgt von einem R\u00fccksetzen der Privilegien nach Abschluss der Initialisierung des Containers. <\/p>\n<p>Die Aktivierung im System der Benutzer-ID-Namensr\u00e4ume, die es erm\u00f6glichen, in Containern ein eigenes Set von Identifikatoren zu verwenden, ist nicht erforderlich, da sie standardm\u00e4\u00dfig in vielen Distributionen nicht funktioniert (Bubblewrap wird als eingeschr\u00e4nkte SUID-Implementierung eines Untersets der M\u00f6glichkeiten von Benutzer-Namensr\u00e4umen positioniert &#8212; um alle Benutzer- und Prozess-IDs aus der Umgebung auszuschlie\u00dfen, au\u00dfer der aktuellen, werden die Modi CLONE_NEWUSER und CLONE_NEWPID verwendet). Zum zus\u00e4tzlichen Schutz wird das Ausf\u00fchrbare unter der Kontrolle von<br \/>\n Bubblewrap gestarteten Programme im PR_SET_NO_NEW_PRIVS-Modus ausgef\u00fchrt, der das Erlangen neuer Privilegien verbietet, beispielsweise im Falle eines Setuid-Flags. <\/p>\n<p>Die Isolierung auf Dateisystemebene erfolgt durch standardm\u00e4\u00dfige Erstellung eines neuen Namensraums f\u00fcr Einh\u00e4ngepunkte (mount namespace), in dem mit tmpfs eine leere Wurzelpartition erstellt wird. In diese Partition werden bei Bedarf Partitionen des externen Dateisystems im &#171;mount &#8212;bind&#187;-Modus angeh\u00e4ngt (zum Beispiel beim Start mit der Option &#171;bwrap &#8212;ro-bind \/usr \/usr&#187; wird die Partition \/usr aus dem Hauptsystem im Nur-Lese-Modus weitergereicht). Die Netzwerkf\u00e4higkeiten werden auf den Zugriff auf das Loopback-Interface mit Isolation des Netzwerkstacks durch die Flags CLONE_NEWNET und CLONE_NEWUTS eingeschr\u00e4nkt.<\/p>\n<p>Ein Hauptunterschied zu einem \u00e4hnlichen Projekt  <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=50760\">Firejail<\/a><\/noindex>, das ebenfalls das Startmodell mit Setuid verwendet, unterscheidet sich darin, dass in Bubblewrap die Schicht zur Erstellung von Containern nur das notwendige Minimum an Funktionalit\u00e4t enth\u00e4lt, w\u00e4hrend alle erweiterten Funktionen, die f\u00fcr den Betrieb grafischer Anwendungen, die Interaktion mit dem Desktop und die Filterung von Anfragen an Pulseaudio erforderlich sind, auf die Seite von Flatpak ausgelagert und bereits nach dem Abbau von Privilegien ausgef\u00fchrt werden. Firejail hingegen vereint alle begleitenden Funktionen in einer ausf\u00fchrbaren Datei, was die \u00dcberpr\u00fcfung und Aufrechterhaltung der Sicherheitsstandards kompliziert. <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=45824\">auf einem angemessenen Niveau.<\/a><\/noindex>.<\/p>\n<p>Die neue Ver\u00f6ffentlichung zeichnet sich durch die Implementierung der Unterst\u00fctzung f\u00fcr die Verbindung bestehender Benutzer-Namensr\u00e4ume und Prozess-Namensr\u00e4ume aus. Zur Verwaltung der Verbindung der Namensr\u00e4ume wurden die Flags &#171;&#8212;userns&#187;, &#171;&#8212;userns2&#187; und &#171;&#8212;pidns&#187; hinzugef\u00fcgt.<br \/>\nDiese Funktion funktioniert nicht im Setuid-Modus und erfordert die Anwendung eines separaten Modus, der ohne Erwerb von root-Rechten arbeiten kann, jedoch die Aktivierung<br \/>\nvon Benutzer-Namespaces im System erforderlich macht (standardm\u00e4\u00dfig in Debian und RHEL\/CentOS deaktiviert) und schlie\u00dft nicht die M\u00f6glichkeit ein, <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=46281\">der Ausnutzung<\/a><\/noindex> <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=47407\">potenziell<\/a><\/noindex> <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=45632\">verbleibend.<\/a><\/noindex> <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=49649\">F\u00fcnf<\/a><\/noindex> f\u00fcr die Einschr\u00e4nkung der &#171;user namespaces&#187;. Zu den neuen Funktionen von Bubblewrap 0.4 z\u00e4hlt auch die M\u00f6glichkeit, mit der C-Bibliothek musl anstelle von glibc zu kompilieren, sowie die Unterst\u00fctzung zur Speicherung von Informationen \u00fcber Namensr\u00e4ume in einer Statistikdatei im JSON-Format.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Quelle: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51947\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0414\u043e\u0441\u0442\u0443\u043f\u0435\u043d \u043d\u043e\u0432\u044b\u0439 \u0432\u044b\u043f\u0443\u0441\u043a \u0438\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u0430\u0440\u0438\u044f Bubblewrap 0.4.0, \u043f\u0440\u0435\u0434\u043d\u0430\u0437\u043d\u0430\u0447\u0435\u043d\u043d\u043e\u0433\u043e \u0434\u043b\u044f \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u0438 \u0440\u0430\u0431\u043e\u0442\u044b \u0438\u0437\u043e\u043b\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u0445 \u043e\u043a\u0440\u0443\u0436\u0435\u043d\u0438\u0439 \u0432 Linux \u0438 \u0444\u0443\u043d\u043a\u0446\u0438\u043e\u043d\u0438\u0440\u0443\u044e\u0449\u0438\u0439 \u043d\u0430 \u0443\u0440\u043e\u0432\u043d\u0435 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439 \u043d\u0435\u043f\u0440\u0438\u0432\u0438\u043b\u0435\u0433\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u0445 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439. \u041d\u0430 \u043f\u0440\u0430\u043a\u0442\u0438\u043a\u0435 Bubblewrap \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442\u0441\u044f \u043f\u0440\u043e\u0435\u043a\u0442\u043e\u043c Flatpak \u0432 \u043a\u0430\u0447\u0435\u0441\u0442\u0432\u0435 \u043f\u0440\u043e\u0441\u043b\u043e\u0439\u043a\u0438 \u0434\u043b\u044f \u0438\u0437\u043e\u043b\u044f\u0446\u0438\u0438 \u0437\u0430\u043f\u0443\u0441\u043a\u0430\u0435\u043c\u044b\u0445 \u0438\u0437 \u043f\u0430\u043a\u0435\u0442\u043e\u0432 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439. \u041a\u043e\u0434 \u043f\u0440\u043e\u0435\u043a\u0442\u0430 \u043d\u0430\u043f\u0438\u0441\u0430\u043d \u043d\u0430 \u044f\u0437\u044b\u043a\u0435 \u0421\u0438 \u0438 \u0440\u0430\u0441\u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u044f\u0435\u0442\u0441\u044f \u043f\u043e\u0434 \u043b\u0438\u0446\u0435\u043d\u0437\u0438\u0435\u0439 LGPLv2+. \u0414\u043b\u044f \u0438\u0437\u043e\u043b\u044f\u0446\u0438\u0438 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044e\u0442\u0441\u044f \u0442\u0440\u0430\u0434\u0438\u0446\u0438\u043e\u043d\u043d\u044b\u0435 \u0434\u043b\u044f Linux \u0442\u0435\u0445\u043d\u043e\u043b\u043e\u0433\u0438\u0438 \u043a\u043e\u043d\u0442\u0435\u0439\u043d\u0435\u0440\u043d\u043e\u0439 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-53324","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0414\u043e\u0441\u0442\u0443\u043f\u0435\u043d \u043d\u043e\u0432\u044b\u0439 \u0432\u044b\u043f\u0443\u0441\u043a \u0438\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u0430\u0440\u0438\u044f\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/de\/blog\/news\/vypusk-bubblewrap-0-4-0-proslojki-dlya-sozdaniya-izolirovannyh-okruzhenij\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"de_DE\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0412\u044b\u043f\u0443\u0441\u043a Bubblewrap 0.4.0, \u043f\u0440\u043e\u0441\u043b\u043e\u0439\u043a\u0438 \u0434\u043b\u044f \u0441\u043e\u0437\u0434\u0430\u043d\u0438\u044f \u0438\u0437\u043e\u043b\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u0445 \u043e\u043a\u0440\u0443\u0436\u0435\u043d\u0438\u0439 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0414\u043e\u0441\u0442\u0443\u043f\u0435\u043d \u043d\u043e\u0432\u044b\u0439 \u0432\u044b\u043f\u0443\u0441\u043a \u0438\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u0430\u0440\u0438\u044f\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/de\/blog\/news\/vypusk-bubblewrap-0-4-0-proslojki-dlya-sozdaniya-izolirovannyh-okruzhenij\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-11-28T21:00:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-02-18T11:01:13+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Die Ver\u00f6ffentlichung von Bubblewrap 0.4.0, einer Schicht zur Erstellung isolierter Umgebungen | ProHoster","description":"Eine neue Version des Tools ist verf\u00fcgbar.","canonical_url":"https:\/\/prohoster.info\/de\/blog\/news\/vypusk-bubblewrap-0-4-0-proslojki-dlya-sozdaniya-izolirovannyh-okruzhenij","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"de_DE","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0412\u044b\u043f\u0443\u0441\u043a Bubblewrap 0.4.0, \u043f\u0440\u043e\u0441\u043b\u043e\u0439\u043a\u0438 \u0434\u043b\u044f \u0441\u043e\u0437\u0434\u0430\u043d\u0438\u044f \u0438\u0437\u043e\u043b\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u0445 \u043e\u043a\u0440\u0443\u0436\u0435\u043d\u0438\u0439 | ProHoster","og:description":"\u0414\u043e\u0441\u0442\u0443\u043f\u0435\u043d \u043d\u043e\u0432\u044b\u0439 \u0432\u044b\u043f\u0443\u0441\u043a \u0438\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u0430\u0440\u0438\u044f","og:url":"https:\/\/prohoster.info\/de\/blog\/news\/vypusk-bubblewrap-0-4-0-proslojki-dlya-sozdaniya-izolirovannyh-okruzhenij","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-11-28T21:00:00+00:00","article:modified_time":"2020-02-18T11:01:13+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"53324","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-24 06:56:20","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 20:27:38","updated":"2026-01-24 06:56:20","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/53324","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/comments?post=53324"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/53324\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/media?parent=53324"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/categories?post=53324"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/tags?post=53324"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}