{"id":54610,"date":"2019-12-30T00:00:00","date_gmt":"2019-12-29T21:00:00","guid":{"rendered":"https:\/\/prohoster.info\/blog\/blog_prohoster\/vypusk-sistemy-izolyatsii-prilozhenij-firejail-0-9-62"},"modified":"2020-02-18T14:02:39","modified_gmt":"2020-02-18T11:02:39","slug":"vypusk-sistemy-izolyatsii-prilozhenij-firejail-0-9-62","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/news\/vypusk-sistemy-izolyatsii-prilozhenij-firejail-0-9-62","title":{"rendered":"Release of the Firejail 0.9.62 application isolation system","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>After six months of development <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/netblue30\/firejail\/releases\/tag\/0.9.62\">is available<\/a><\/noindex> project release <noindex><a rel=\"nofollow\" href=\"https:\/\/firejail.wordpress.com\/\">Firejail 0.9.62<\/a><\/noindex>, within which a system for the isolated execution of graphical, console, and server applications is developed. Using Firejail minimizes the risk of compromising the main system when running untrusted or potentially vulnerable programs. The program is written in C, <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/netblue30\/firejail\">is distributed<\/a><\/noindex> under the GPLv2 license and can operate on any Linux distribution with a kernel newer than 3.0. Ready-made packages for Firejail <noindex><a rel=\"nofollow\" href=\"https:\/\/sourceforge.net\/projects\/firejail\/files\/firejail\/\">are prepared<\/a><\/noindex> are available in deb (Debian, Ubuntu) and rpm (CentOS, Fedora) formats.<\/p>\n<p>For isolation in Firejail <noindex><a rel=\"nofollow\" href=\"https:\/\/firejail.wordpress.com\/features-3\/\">it uses<\/a><\/noindex>  namespaces, AppArmor, and system call filtering (seccomp-bpf) in Linux. Once launched, the program and all its child processes use separate views of kernel resources, such as the network stack, process table, and mount points. Related applications can be grouped into a single shared sandbox. Firejail can also be used to run Docker, LXC, and OpenVZ containers if desired. <\/p>\n<p>Unlike container isolation tools, Firejail is extremely <noindex><a rel=\"nofollow\" href=\"https:\/\/firejail.wordpress.com\/documentation-2\/basic-usage\/\">simple<\/a><\/noindex> in configuration and does not require a system image preparation \u2014 the container's contents are formed on-the-fly based on the current filesystem and deleted after the application finishes. Flexible access rule configuration tools are provided for the filesystem, allowing you to specify which files and directories are allowed or denied access, connect temporary filesystems (tmpfs) for data, restrict file or directory access to read-only, and combine directories through bind-mount and overlayfs.<\/p>\n<p>For many popular applications, including Firefox, Chromium, VLC, and Transmission, ready-made <noindex><a rel=\"nofollow\" href=\"https:\/\/firejail.wordpress.com\/documentation-2\/building-custom-profiles\/\">profiles<\/a><\/noindex> isolation of system calls. To gain the privileges necessary to configure the isolated environment, the firejail executable is installed with the SUID root flag (privileges are dropped after initialization). To run a program in isolation, simply specify the application name as an argument to the firejail utility, for example, \"firejail firefox\" or \"sudo firejail \/etc\/init.d\/nginx start.\" <\/p>\n<p>In the new release:<\/p>\n<ul>\n<li class=\"l\"> In the configuration file \/etc\/firejail\/firejail.config <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/netblue30\/firejail\/blob\/master\/etc\/firejail.config#L38\">has added<\/a><\/noindex> configuration of file-copy-limit, which allows you to limit the size of files that will be copied into memory when using the \"--private-*\" options (by default, the limit is set to 500MB).\n<li class=\"l\"> Templates for creating new application restriction profiles have been added to the directory \/usr\/share\/doc\/firejail.\n<li class=\"l\"> Debugger usage is permitted in profiles.\n<li class=\"l\"> System call filtering has been improved using the seccomp mechanism.\n<li class=\"l\"> Automatic detection of compiler flags has been provided.\n<li class=\"l\"> The chroot call is now executed not based on the path but using mount points based on the file descriptor.\n<li class=\"l\"> The directory \/usr\/share has been whitelisted in various profiles.\n<li class=\"l\"> New helper scripts gdb-firejail.sh and sort.py have been added to the contrib section.\n<li class=\"l\"> Protection during the execution of privileged code (SUID) has been enhanced.\n<li class=\"l\"> New conditional attributes HAS_X11 and HAS_NET have been implemented for profiles to check for the presence of an X server and network access.\n<li class=\"l\"> Profiles for isolated application launch have been added (the total number of profiles has reached 884):\n<ul>\n<li>i2p,\n<li>tor-browser (AUR),\n<li>Zulip,\n<li>rsync,\n<li>signal-cli,\n<li>tcpdump,\n<li>tshark,\n<li>qgis,\n<li>OpenArena,\n<li>godot,\n<li>klatexformula,\n<li>klatexformula_cmdl,\n<li>links,\n<li>xlinks,\n<li>pandoc,\n<li>teams-for-linux,\n<li>gnome-sound-recorder,\n<li>newsbeuter,\n<li>keepassxc-cli,\n<li>keepassxc-proxy,\n<li>rhythmbox-client,\n<li>jerry,\n<li>zeal,\n<li>mpg123,\n<li>conplay,\n<li>mpg123.bin,\n<li>mpg123-alsa,\n<li>mpg123-id3dump,\n<li>out123,\n<li>mpg123-jack,\n<li>mpg123-nas,\n<li>mpg123-openal,\n<li> mpg123-oss,\n<li>mpg123-portaudio,\n<li>mpg123-pulse,\n<li> mpg123-strip,\n<li>pavucontrol-qt,\n<li>gnome-characters,\n<li>gnome-character-map,\n<li>Whalebird,\n<li>tb-starter-wrapper,\n<li>bzcat,\n<li>kiwix-desktop,\n<li>bzcat,\n<li>zstd,\n<li>pzstd,\n<li>zstdcat,\n<li>zstdgrep,\n<li>zstdless,\n<li>zstdmt,\n<li>unzstd,\n<li>ar,\n<li>gnome-latex,\n<li> pngquant,\n<li>kalgebra,\n<li>kalgebramobile,\n<li>amuled,\n<li>kfind,\n<li>profanity,\n<li>audio-recorder,\n<li>cameramonitor,\n<li>ddgtk,\n<li>drawio,\n<li>unf,\n<li>gmpc,\n<li>electron-mail,\n<li>gist,\n<li>gist-paste.\n<\/ul>\n<\/ul>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Source: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=52115\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041f\u043e\u0441\u043b\u0435 \u0448\u0435\u0441\u0442\u0438 \u043c\u0435\u0441\u044f\u0446\u0435\u0432 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u043a\u0438 \u0434\u043e\u0441\u0442\u0443\u043f\u0435\u043d \u0440\u0435\u043b\u0438\u0437 \u043f\u0440\u043e\u0435\u043a\u0442\u0430 Firejail 0.9.62, \u0432 \u0440\u0430\u043c\u043a\u0430\u0445 \u043a\u043e\u0442\u043e\u0440\u043e\u0433\u043e \u0440\u0430\u0437\u0432\u0438\u0432\u0430\u0435\u0442\u0441\u044f \u0441\u0438\u0441\u0442\u0435\u043c\u0430 \u0434\u043b\u044f \u0438\u0437\u043e\u043b\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u043e\u0433\u043e \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f \u0433\u0440\u0430\u0444\u0438\u0447\u0435\u0441\u043a\u0438\u0445, \u043a\u043e\u043d\u0441\u043e\u043b\u044c\u043d\u044b\u0445 \u0438 \u0441\u0435\u0440\u0432\u0435\u0440\u043d\u044b\u0445 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439. \u041f\u0440\u0438\u043c\u0435\u043d\u0435\u043d\u0438\u0435 Firejail \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u043c\u0438\u043d\u0438\u043c\u0438\u0437\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u0440\u0438\u0441\u043a \u043a\u043e\u043c\u043f\u0440\u043e\u043c\u0435\u0442\u0430\u0446\u0438\u0438 \u043e\u0441\u043d\u043e\u0432\u043d\u043e\u0439 \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u043f\u0440\u0438 \u0437\u0430\u043f\u0443\u0441\u043a\u0435 \u043d\u0435 \u0437\u0430\u0441\u043b\u0443\u0436\u0438\u0432\u0430\u044e\u0449\u0438\u0445 \u0434\u043e\u0432\u0435\u0440\u0438\u044f \u0438\u043b\u0438 \u043f\u043e\u0442\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u0443\u044f\u0437\u0432\u0438\u043c\u044b\u0445 \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c. \u041f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u0430 \u043d\u0430\u043f\u0438\u0441\u0430\u043d\u0430 \u043d\u0430 \u044f\u0437\u044b\u043a\u0435 \u0421\u0438, \u0440\u0430\u0441\u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u044f\u0435\u0442\u0441\u044f \u043f\u043e\u0434 \u043b\u0438\u0446\u0435\u043d\u0437\u0438\u0435\u0439 GPLv2 \u0438 \u043c\u043e\u0436\u0435\u0442 \u0440\u0430\u0431\u043e\u0442\u0430\u0442\u044c \u0432 \u043b\u044e\u0431\u043e\u043c \u0434\u0438\u0441\u0442\u0440\u0438\u0431\u0443\u0442\u0438\u0432\u0435 Linux [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-54610","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041f\u043e\u0441\u043b\u0435 \u0448\u0435\u0441\u0442\u0438 \u043c\u0435\u0441\u044f\u0446\u0435\u0432 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u043a\u0438 \u0434\u043e\u0441\u0442\u0443\u043f\u0435\u043d \u0440\u0435\u043b\u0438\u0437 \u043f\u0440\u043e\u0435\u043a\u0442\u0430\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/news\/vypusk-sistemy-izolyatsii-prilozhenij-firejail-0-9-62\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0412\u044b\u043f\u0443\u0441\u043a \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u0438\u0437\u043e\u043b\u044f\u0446\u0438\u0438 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439 Firejail 0.9.62 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041f\u043e\u0441\u043b\u0435 \u0448\u0435\u0441\u0442\u0438 \u043c\u0435\u0441\u044f\u0446\u0435\u0432 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u043a\u0438 \u0434\u043e\u0441\u0442\u0443\u043f\u0435\u043d \u0440\u0435\u043b\u0438\u0437 \u043f\u0440\u043e\u0435\u043a\u0442\u0430\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/news\/vypusk-sistemy-izolyatsii-prilozhenij-firejail-0-9-62\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-12-29T21:00:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-02-18T11:02:39+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Release of the Firejail application isolation system 0.9.62 | ProHoster","description":"After six months of development, the project release is now available","canonical_url":"https:\/\/prohoster.info\/en\/blog\/news\/vypusk-sistemy-izolyatsii-prilozhenij-firejail-0-9-62","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0412\u044b\u043f\u0443\u0441\u043a \u0441\u0438\u0441\u0442\u0435\u043c\u044b \u0438\u0437\u043e\u043b\u044f\u0446\u0438\u0438 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0439 Firejail 0.9.62 | ProHoster","og:description":"\u041f\u043e\u0441\u043b\u0435 \u0448\u0435\u0441\u0442\u0438 \u043c\u0435\u0441\u044f\u0446\u0435\u0432 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u043a\u0438 \u0434\u043e\u0441\u0442\u0443\u043f\u0435\u043d \u0440\u0435\u043b\u0438\u0437 \u043f\u0440\u043e\u0435\u043a\u0442\u0430","og:url":"https:\/\/prohoster.info\/en\/blog\/news\/vypusk-sistemy-izolyatsii-prilozhenij-firejail-0-9-62","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-12-29T21:00:00+00:00","article:modified_time":"2020-02-18T11:02:39+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"54610","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-24 12:05:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 20:01:33","updated":"2026-01-24 12:05:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/54610","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=54610"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/54610\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=54610"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=54610"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=54610"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}