ืฉื—ืจื•ืจ ืฉืœ Bubblewrap 0.6, ืฉื›ื‘ื” ืœื™ืฆื™ืจืช ืกื‘ื™ื‘ื•ืช ืžื‘ื•ื“ื“ื•ืช

ื’ืจืกื” ืฉืœ ื›ืœื™ื ืœืืจื’ื•ืŸ ื”ืขื‘ื•ื“ื” ืฉืœ ืกื‘ื™ื‘ื•ืช ืžื‘ื•ื“ื“ื•ืช ื–ืžื™ื ื” Bubblewrap 0.6, ื”ืžืฉืžืฉืช ื‘ื“ืจืš ื›ืœืœ ืœื”ื’ื‘ืœืช ื™ื™ืฉื•ืžื™ื ื‘ื•ื“ื“ื™ื ืฉืœ ืžืฉืชืžืฉื™ื ื—ืกืจื™ ื”ืจืฉืื•ืช. ื‘ืคื•ืขืœ, Bubblewrap ืžืฉืžืฉ ืืช ืคืจื•ื™ืงื˜ Flatpak ื›ืฉื›ื‘ื” ืœื‘ื™ื“ื•ื“ ื™ื™ืฉื•ืžื™ื ืฉื”ื•ืฉืงื• ืžื—ื‘ื™ืœื•ืช. ืงื•ื“ ื”ืคืจื•ื™ืงื˜ ื›ืชื•ื‘ ื‘-C ื•ืžื•ืคืฅ ืชื—ืช ืจื™ืฉื™ื•ืŸ LGPLv2+.

ืœืฆื•ืจืš ื‘ื™ื“ื•ื“, ื ืขืฉื” ืฉื™ืžื•ืฉ ื‘ื˜ื›ื ื•ืœื•ื’ื™ื•ืช ื•ื™ืจื˜ื•ืืœื™ื–ืฆื™ื” ืžืกื•ืจืชื™ื•ืช ืฉืœ ืžื™ื›ืœ ืœื™ื ื•ืงืก, ื”ืžื‘ื•ืกืกื•ืช ืขืœ ืฉื™ืžื•ืฉ ื‘ืงื‘ื•ืฆื•ืช cgroups, ืžืจื—ื‘ื™ ืฉืžื•ืช, Seccomp ื•-SELinux. ื›ื“ื™ ืœื‘ืฆืข ืคืขื•ืœื•ืช ืžื•ืจืฉื•ืช ืœื”ื’ื“ืจืช ืงื•ื ื˜ื™ื™ื ืจ, Bubblewrap ืžื•ืคืขืœ ืขื ื–ื›ื•ื™ื•ืช ืฉื•ืจืฉ (ืงื•ื‘ืฅ ื”ืคืขืœื” ืขื ื“ื’ืœ suid) ื•ืœืื—ืจ ืžื›ืŸ ืžืืคืก ืืช ื”ื”ืจืฉืื•ืช ืœืื—ืจ ืืชื—ื•ืœ ื”ืžื™ื›ืœ.

ื”ืคืขืœืช ืžืจื—ื‘ื™ ืฉืžื•ืช ืžืฉืชืžืฉื™ื ื‘ืžืขืจื›ืช ืžืจื—ื‘ ื”ืฉืžื•ืช, ื”ืžืืคืฉืจืช ืœืš ืœื”ืฉืชืžืฉ ื‘ืกื˜ ื ืคืจื“ ืžืฉืœืš ืฉืœ ืžื–ื”ื™ื ื‘ืงื•ื ื˜ื™ื™ื ืจื™ื, ืื™ื ื” ื ื“ืจืฉืช ืœืฆื•ืจืš ื”ืคืขื•ืœื”, ืžื›ื™ื•ื•ืŸ ืฉื”ื™ื ืื™ื ื” ืคื•ืขืœืช ื›ื‘ืจื™ืจืช ืžื—ื“ืœ ื‘ื”ืคืฆื•ืช ืจื‘ื•ืช (Bubblewrap ืžืžื•ืงื ื›ื™ื™ืฉื•ื suid ืžื•ื’ื‘ืœ ืฉืœ ืชืช-ืงื‘ื•ืฆืช ื™ื›ื•ืœื•ืช ืฉืœ ืžืจื—ื‘ื™ ืฉืžื•ืช ืžืฉืชืžืฉื™ื - ื›ื“ื™ ืœื ืœื›ืœื•ืœ ืืช ื›ืœ ืžื–ื”ื™ ื”ืžืฉืชืžืฉื™ื ื•ื”ืชื”ืœื™ื›ื™ื ืžื”ืกื‘ื™ื‘ื”, ืžืœื‘ื“ ื”ื ื•ื›ื—ื™ืช, ื ืขืฉื” ืฉื™ืžื•ืฉ ื‘ืžืฆื‘ื™ื CLONE_NEWUSER ื•-CLONE_NEWPID). ืœื”ื’ื ื” ื ื•ืกืคืช, ืชื•ื›ื ื™ื•ืช ื”ืžื•ืคืขืœื•ืช ืชื—ืช Bubblewrap ืžื•ืคืขืœื•ืช ื‘ืžืฆื‘ PR_SET_NO_NEW_PRIVS, ื”ืื•ืกืจ ืขืœ ืจื›ื™ืฉืช ื”ืจืฉืื•ืช ื—ื“ืฉื•ืช, ืœืžืฉืœ, ืื ืงื™ื™ื ื“ื’ืœ setuid.

ื‘ื™ื“ื•ื“ ื‘ืจืžืช ืžืขืจื›ืช ื”ืงื‘ืฆื™ื ืžืชื‘ืฆืข ืขืœ ื™ื“ื™ ื™ืฆื™ืจืช ืžืจื—ื‘ ืฉืžื•ืช ื˜ืขื™ื ื” ื—ื“ืฉ ื›ื‘ืจื™ืจืช ืžื—ื“ืœ, ืฉื‘ื• ื ื•ืฆืจืช ืžื—ื™ืฆืช ืฉื•ืจืฉ ืจื™ืงื” ื‘ืืžืฆืขื•ืช tmpfs. ื‘ืžื™ื“ืช ื”ืฆื•ืจืš, ืžื—ื™ืฆื•ืช FS ื—ื™ืฆื•ื ื™ื•ืช ืžื—ื•ื‘ืจื•ืช ืœืžื—ื™ืฆื” ื–ื• ื‘ืžืฆื‘ "mount โ€”bind" (ืœื“ื•ื’ืžื”, ื›ืืฉืจ ืžื•ืคืขืœืช ืขื ื”ืืคืฉืจื•ืช "bwrap โ€”ro-bind /usr /usr", ืžื—ื™ืฆืช /usr ืžื•ืขื‘ืจืช ืžื”ืžืขืจื›ืช ื”ืจืืฉื™ืช ื‘ืžืฆื‘ ืงืจื™ืื” ื‘ืœื‘ื“). ื™ื›ื•ืœื•ืช ื”ืจืฉืช ืžื•ื’ื‘ืœื•ืช ืœื’ื™ืฉื” ืœืžืžืฉืง ื”ืœื•ืœืื” ืขื ื‘ื™ื“ื•ื“ ืžื—ืกื ื™ืช ืจืฉืช ื‘ืืžืฆืขื•ืช ื”ื“ื’ืœื™ื CLONE_NEWNET ื•-CLONE_NEWUTS.

ื”ื”ื‘ื“ืœ ื”ืขื™ืงืจื™ ืžืคืจื•ื™ืงื˜ Firejail ื”ื“ื•ืžื”, ื”ืžืฉืชืžืฉ ื’ื ื‘ืžื•ื“ืœ ื”ื”ืฉืงื” ืฉืœ setuid, ื”ื•ื ืฉื‘-Bubblewrap ืฉื›ื‘ืช ื™ืฆื™ืจืช ื”ืžื™ื›ืœื™ื ื›ื•ืœืœืช ืจืง ืืช ื”ื™ื›ื•ืœื•ืช ื”ืžื™ื ื™ืžืœื™ื•ืช ื”ื“ืจื•ืฉื•ืช, ื•ืืช ื›ืœ ื”ืคื•ื ืงืฆื™ื•ืช ื”ืžืชืงื“ืžื•ืช ื”ื ื—ื•ืฆื•ืช ืœื”ืคืขืœืช ื™ื™ืฉื•ืžื™ื ื’ืจืคื™ื™ื, ืื™ื ื˜ืจืืงืฆื™ื” ืขื ืฉื•ืœื—ืŸ ื”ืขื‘ื•ื“ื” ื•ื‘ืงืฉื•ืช ืกื™ื ื•ืŸ. ืœ-Pulsaudio, ื”ื•ืขื‘ืจ ืœืฆื“ Flatpak ื•ื‘ื•ืฆืข ืœืื—ืจ ืื™ืคื•ืก ื”ื”ืจืฉืื•ืช. Firejail, ืœืขื•ืžืช ื–ืืช, ืžืฉืœื‘ืช ืืช ื›ืœ ื”ืคื•ื ืงืฆื™ื•ืช ื”ืงืฉื•ืจื•ืช ื‘ืงื•ื‘ืฅ ื”ืคืขืœื” ืื—ื“, ืžื” ืฉืžืงืฉื” ืขืœ ื”ื‘ื™ืงื•ืจืช ื•ืชื—ื–ื•ืงืช ื”ืื‘ื˜ื—ื” ื‘ืจืžื” ื”ืžืชืื™ืžื”.

ื‘ืžื”ื“ื•ืจื” ื”ื—ื“ืฉื”:

  • ื ื•ืกืคื” ืชืžื™ื›ื” ืœืžืขืจื›ืช ื”ื”ืจื›ื‘ื” ืฉืœ Meson. ื”ืชืžื™ื›ื” ื‘ื‘ื ื™ื™ื” ืขื ื›ืœื™ ืื•ื˜ื•ืžื˜ื™ ื ืฉืžืจื” ืœืขืช ืขืชื”, ืืš ืชื•ืกืจ ื‘ืžื”ื“ื•ืจื” ืขืชื™ื“ื™ืช.
  • ื”ื˜ืžืขื” ืืคืฉืจื•ืช "--add-seccomp" ื›ื“ื™ ืœื”ื•ืกื™ืฃ ื™ื•ืชืจ ืžืชื•ื›ื ื™ืช seccomp ืื—ืช. ื ื•ืกืคื” ืื–ื”ืจื” ืฉืื ืชืฆื™ื™ืŸ ืฉื•ื‘ ืืช ื”ืืคืฉืจื•ืช "--seccomp", ืจืง ื”ืคืจืžื˜ืจ ื”ืื—ืจื•ืŸ ื™ื•ื—ืœ.
  • ื”ืขื ืฃ ื”ืจืืฉื™ ื‘ืžืื’ืจ git ืฉื•ื ื” ืœ-main.
  • ื ื•ืกืคื” ืชืžื™ื›ื” ื—ืœืงื™ืช ื‘ืžืคืจื˜ REUSE, ื”ืžืื—ื“ ืืช ื”ืชื”ืœื™ืš ืฉืœ ืฆื™ื•ืŸ ืžื™ื“ืข ืขืœ ืจื™ืฉื™ื•ืŸ ื•ื–ื›ื•ื™ื•ืช ื™ื•ืฆืจื™ื. ืœืงื•ื‘ืฆื™ ืงื•ื“ ืจื‘ื™ื ื ื•ืกืคื• ื›ื•ืชืจื•ืช SPDX-License-Identifier. ื”ืงืคื“ื” ืขืœ ื”ื ื—ื™ื•ืช REUSE ืžืงืœื” ืขืœ ืงื‘ื™ืขื” ืื•ื˜ื•ืžื˜ื™ืช ืฉืœ ืื™ื–ื” ืจื™ืฉื™ื•ืŸ ื—ืœ ืขืœ ืื™ืœื• ื—ืœืงื™ื ืฉืœ ืงื•ื“ ื”ืืคืœื™ืงืฆื™ื”.
  • ื ื•ืกืฃ ื‘ื“ื™ืงืช ื”ืขืจืš ืฉืœ ืžื•ื ื” ื”ืืจื’ื•ืžื ื˜ื™ื ืฉืœ ืฉื•ืจืช ื”ืคืงื•ื“ื” (argc) ื•ื™ื™ืฉื ื™ืฆื™ืืช ื—ื™ืจื•ื ืื ื”ืžื•ื ื” ื”ื•ื ืืคืก. ื”ืฉื™ื ื•ื™ ืขื•ื–ืจ ืœื—ืกื•ื ื‘ืขื™ื•ืช ืื‘ื˜ื—ื” ื”ื ื’ืจืžื•ืช ืžื˜ื™ืคื•ืœ ืœื ื ื›ื•ืŸ ื‘ืืจื’ื•ืžื ื˜ื™ื ืฉืœ ืฉื•ืจืช ื”ืคืงื•ื“ื” ืฉืขื‘ืจื•, ื›ื’ื•ืŸ CVE-2021-4034 ื‘-Polkit.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”