Release of the Firejail 0.9.62 application isolation system

After six months of development is available project release Firejail 0.9.62, within which a system for the isolated execution of graphical, console, and server applications is developed. Using Firejail minimizes the risk of compromising the main system when running untrusted or potentially vulnerable programs. The program is written in C, is distributed under the GPLv2 license and can operate on any Linux distribution with a kernel newer than 3.0. Ready-made packages for Firejail are prepared are available in deb (Debian, Ubuntu) and rpm (CentOS, Fedora) formats.

For isolation in Firejail it uses namespaces, AppArmor, and system call filtering (seccomp-bpf) in Linux. Once launched, the program and all its child processes use separate views of kernel resources, such as the network stack, process table, and mount points. Related applications can be grouped into a single shared sandbox. Firejail can also be used to run Docker, LXC, and OpenVZ containers if desired.

Unlike container isolation tools, Firejail is extremely simple in configuration and does not require a system image to be prepared — the container's composition is dynamically formed based on the current filesystem content and removed after the application has finished running. Flexible tools are provided for setting filesystem access rules, allowing you to specify which files and directories are permitted or denied access, connect temporary filesystems (tmpfs) for data, restrict access to files or directories to read-only, and merge directories using bind-mount and overlayfs.

For many popular applications, including Firefox, Chromium, VLC, and Transmission, ready-made profiles isolation of system calls. To obtain the privileges necessary for configuring an isolated environment, the firejail executable file is set with the SUID root flag (privileges are dropped after initialization). To run an application in isolation, it is sufficient to specify the application name as an argument to the firejail utility, for example, 'firejail firefox' or 'sudo firejail /etc/init.d/nginx start'.

In the new release:

  • In the configuration file /etc/firejail/firejail.config has added the file-copy-limit setting, which allows you to restrict the size of files that will be copied into memory when using the '--private-*' options (the default limit is set to 500MB).
  • Templates for creating new application restriction profiles have been added to the directory /usr/share/doc/firejail.
  • Debugger usage is permitted in profiles.
  • System call filtering has been improved using the seccomp mechanism.
  • Automatic detection of compiler flags has been provided.
  • The chroot call is now executed not based on the path but using mount points based on the file descriptor.
  • The directory /usr/share has been whitelisted in various profiles.
  • New helper scripts gdb-firejail.sh and sort.py have been added to the contrib section.
  • Protection during the execution of privileged code (SUID) has been enhanced.
  • New conditional attributes HAS_X11 and HAS_NET have been implemented for profiles to check for the presence of an X server and network access.
  • Profiles for isolated application launch have been added (the total number of profiles has reached 884):
    • i2p,
    • tor-browser (AUR),
    • Zulip,
    • rsync,
    • signal-cli,
    • tcpdump,
    • tshark,
    • qgis,
    • OpenArena,
    • godot,
    • klatexformula,
    • klatexformula_cmdl,
    • links,
    • xlinks,
    • pandoc,
    • teams-for-linux,
    • gnome-sound-recorder,
    • newsbeuter,
    • keepassxc-cli,
    • keepassxc-proxy,
    • rhythmbox-client,
    • jerry,
    • zeal,
    • mpg123,
    • conplay,
    • mpg123.bin,
    • mpg123-alsa,
    • mpg123-id3dump,
    • out123,
    • mpg123-jack,
    • mpg123-nas,
    • mpg123-openal,
    • mpg123-oss,
    • mpg123-portaudio,
    • mpg123-pulse,
    • mpg123-strip,
    • pavucontrol-qt,
    • gnome-characters,
    • gnome-character-map,
    • Whalebird,
    • tb-starter-wrapper,
    • bzcat,
    • kiwix-desktop,
    • bzcat,
    • zstd,
    • pzstd,
    • zstdcat,
    • zstdgrep,
    • zstdless,
    • zstdmt,
    • unzstd,
    • ar,
    • gnome-latex,
    • pngquant,
    • kalgebra,
    • kalgebramobile,
    • amuled,
    • kfind,
    • profanity,
    • audio-recorder,
    • cameramonitor,
    • ddgtk,
    • drawio,
    • unf,
    • gmpc,
    • electron-mail,
    • gist,
    • gist-paste.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster