ืžื•ื“ืœ ื—ืœื•ืงืช ื–ื›ื•ื™ื•ืช ื—ื•ื‘ื” ื‘- FreeBSD

ืžื‘ื•ื

ื›ื“ื™ ืœืกืคืง ืจืžื” ื ื•ืกืคืช ืฉืœ ืื‘ื˜ื—ืช ืฉืจืช, ืืชื” ื™ื›ื•ืœ ืœื”ืฉืชืžืฉ ืžื•ื“ืœ ืžื ื“ื˜ ื”ืคืฆืช ื’ื™ืฉื”. ืคืจืกื•ื ื–ื” ื™ืชืืจ ื›ื™ืฆื“ ืืชื” ื™ื›ื•ืœ ืœื”ืจื™ืฅ ืืคืืฆ'ื™ ื‘ื›ืœื ืขื ื’ื™ืฉื” ืจืง ืœืื•ืชื ืจื›ื™ื‘ื™ื ืฉื“ื•ืจืฉื™ื ื’ื™ืฉื” ื›ื“ื™ ืฉ-apache ื•-php ื™ืคืขืœื• ื›ื”ืœื›ื”. ื‘ืืžืฆืขื•ืช ืขื™ืงืจื•ืŸ ื–ื”, ืืชื” ื™ื›ื•ืœ ืœื”ื’ื‘ื™ืœ ืœื ืจืง ืืช ืืคืืฆ'ื™, ืืœื ื’ื ื›ืœ ืžื—ืกื ื™ืช ืื—ืจืช.

ื”ื“ืจื›ื”

ืฉื™ื˜ื” ื–ื• ืžืชืื™ืžื” ืจืง ืœืžืขืจื›ืช ื”ืงื‘ืฆื™ื ufs; ื‘ื“ื•ื’ืžื” ื–ื•, ื”-zfs ื™ืฉืžืฉื• ื‘ืžืขืจื›ืช ื”ืจืืฉื™ืช, ื•-ufs ื‘ื›ืœื, ื‘ื”ืชืืžื”. ื”ืฆืขื“ ื”ืจืืฉื•ืŸ ื”ื•ื ืœื‘ื ื•ืช ืžื—ื“ืฉ ืืช ื”ืœื™ื‘ื”; ื‘ืขืช ื”ืชืงื ืช FreeBSD, ื”ืชืงืŸ ืืช ืงื•ื“ ื”ืžืงื•ืจ.
ืœืื—ืจ ื”ืชืงื ืช ื”ืžืขืจื›ืช, ืขืจื•ืš ืืช ื”ืงื•ื‘ืฅ:

/usr/src/sys/amd64/conf/GENERIC

ืืชื” ืจืง ืฆืจื™ืš ืœื”ื•ืกื™ืฃ ืฉื•ืจื” ืื—ืช ืœืงื•ื‘ืฅ ื”ื–ื”:

options     MAC_MLS

ืœืชื•ื•ื™ืช mls/high ืชื”ื™ื” ืขืžื“ื” ื“ื•ืžื™ื ื ื˜ื™ืช ืขืœ ืคื ื™ ื”ืชื•ื•ื™ืช mls/low, ืืคืœื™ืงืฆื™ื•ืช ืฉื™ื•ืฉืงื• ืขื ื”ืชื•ื•ื™ืช mls/low ืœื ื™ื•ื›ืœื• ืœื’ืฉืช ืœืงื‘ืฆื™ื ื‘ืขืœื™ ื”ืชื•ื•ื™ืช mls/high. ืคืจื˜ื™ื ื ื•ืกืคื™ื ืขืœ ื›ืœ ื”ืชื’ื™ื ื”ื–ืžื™ื ื™ื ื‘ืžืขืจื›ืช FreeBSD ื ื™ืชืŸ ืœืžืฆื•ื ื›ืืŸ ืžื“ืจื™ืš.
ืœืื—ืจ ืžื›ืŸ, ืขื‘ื•ืจ ืืœ ืกืคืจื™ื™ืช /usr/src:

cd /usr/src

ื›ื“ื™ ืœื”ืชื—ื™ืœ ืœื‘ื ื•ืช ืืช ื”ืœื™ื‘ื”, ื”ืคืขืœ (ื‘ืžืคืชื— j, ืฆื™ื™ืŸ ืืช ืžืกืคืจ ื”ืœื™ื‘ื•ืช ื‘ืžืขืจื›ืช):

make -j 4 buildkernel KERNCONF=GENERIC

ืœืื—ืจ ื”ื™ื“ื•ืจ ืฉืœ ื”ืงืจื ืœ, ื™ืฉ ืœื”ืชืงื™ืŸ ืื•ืชื•:

make installkernel KERNCONF=GENERIC

ืœืื—ืจ ื”ืชืงื ืช ื”ืœื™ื‘ื”, ืืœ ืชืžื”ืจ ืœืืชื—ืœ ืืช ื”ืžืขืจื›ืช, ืžื›ื™ื•ื•ืŸ ืฉื™ืฉ ืฆื•ืจืš ืœื”ืขื‘ื™ืจ ืžืฉืชืžืฉื™ื ืœืžื—ืœืงืช ื”ื›ื ื™ืกื”, ืœืื—ืจ ืฉื”ื’ื“ื™ืจ ืื•ืชื” ื‘ืขื‘ืจ. ืขืจื•ืš ืืช ื”ืงื•ื‘ืฅ /etc/login.conf, ื‘ืงื•ื‘ืฅ ื”ื–ื” ืืชื” ืฆืจื™ืš ืœืขืจื•ืš ืืช ืžื—ืœืงืช ื”ื›ื ื™ืกื” ื”ืžื•ื’ื“ืจืช ื›ื‘ืจื™ืจืช ืžื—ื“ืœ, ื”ื‘ื ืื•ืชื• ืœื˜ื•ืคืก:

default:
        :passwd_format=sha512:
        :copyright=/etc/COPYRIGHT:
        :welcome=/etc/motd:
        :setenv=MAIL=/var/mail/$,BLOCKSIZE=K:
        :path=/sbin /bin /usr/sbin /usr/bin /usr/local/sbin /usr/local/bin ~/bin:
        :nologin=/var/run/nologin:
        :cputime=unlimited:
        :datasize=unlimited:
        :stacksize=unlimited:
        :memorylocked=64K:
        :memoryuse=unlimited:
        :filesize=unlimited:
        :coredumpsize=unlimited:
        :openfiles=unlimited:
        :maxproc=unlimited:
        :sbsize=unlimited:
        :vmemoryuse=unlimited:
        :swapuse=unlimited:
        :pseudoterminals=unlimited:
        :kqueues=unlimited:
        :umtxp=unlimited:
        :priority=0:
        :ignoretime@:
        :umask=022:
        :label=mls/equal:

ื”ืฉื•ืจื” :label=mls/equal ืชืืคืฉืจ ืœืžืฉืชืžืฉื™ื ื”ื—ื‘ืจื™ื ื‘ื›ื™ืชื” ื–ื• ืœื’ืฉืช ืœืงื‘ืฆื™ื ื”ืžืกื•ืžื ื™ื ื‘ืชื•ื•ื™ืช ื›ืœืฉื”ื™ (mls/low, mls/high). ืœืื—ืจ ื”ืžื ื™ืคื•ืœืฆื™ื•ืช ื”ืœืœื•, ืขืœื™ืš ืœื‘ื ื•ืช ืžื—ื“ืฉ ืืช ืžืกื“ ื”ื ืชื•ื ื™ื ื•ืœืžืงื ืืช ืžืฉืชืžืฉ ื”ืฉื•ืจืฉ (ื›ืžื• ื’ื ืืช ืืœื• ืฉื–ืงื•ืงื™ื ืœื•) ื‘ืžื—ืœืงืช ื”ื”ืชื—ื‘ืจื•ืช ื”ื–ื•:

cap_mkdb /etc/login.conf
pw usermod root -L default

ื›ื“ื™ ืฉื”ืžื“ื™ื ื™ื•ืช ืชื—ื•ืœ ืจืง ืขืœ ืงื‘ืฆื™ื, ืขืœื™ืš ืœืขืจื•ืš ืืช ื”ืงื•ื‘ืฅ /etc/mac.conf, ื•ืœื”ืฉืื™ืจ ื‘ื• ืจืง ืฉื•ืจื” ืื—ืช:

default_labels file ?mls

ืืชื” ื’ื ืฆืจื™ืš ืœื”ื•ืกื™ืฃ ืืช ืžื•ื“ื•ืœ mac_mls.ko ืœื”ืคืขืœื” ืื•ื˜ื•ืžื˜ื™ืช:

echo 'mac_mls_load="YES"' >> /boot/loader.conf

ืœืื—ืจ ืžื›ืŸ, ืืชื” ื™ื›ื•ืœ ืœืืชื—ืœ ืืช ื”ืžืขืจื›ืช ื‘ื‘ื˜ื—ื”. ืื™ืš ืœื™ืฆื•ืจ ื›ืœื ืืชื” ื™ื›ื•ืœ ืœืงืจื•ื ืื•ืชื• ื‘ืื—ื“ ื”ืคืจืกื•ืžื™ื ืฉืœื™. ืื‘ืœ ืœืคื ื™ ื™ืฆื™ืจืช ื›ืœื, ืืชื” ืฆืจื™ืš ืœื”ื•ืกื™ืฃ ื›ื•ื ืŸ ืงืฉื™ื— ื•ืœื™ืฆื•ืจ ืขืœื™ื• ืžืขืจื›ืช ืงื‘ืฆื™ื ื•ืœืืคืฉืจ ื‘ื• ืจื™ื‘ื•ื™ ืชื•ื•ื™ื•ืช, ืœื™ืฆื•ืจ ืžืขืจื›ืช ืงื‘ืฆื™ื ufs2 ืขื ื’ื•ื“ืœ ืืฉื›ื•ืœ ืฉืœ 64kb:

newfs -O 2 -b 64kb /dev/ada1
tunefs -l enable /dev/ada1

ืœืื—ืจ ื™ืฆื™ืจืช ืžืขืจื›ืช ื”ืงื‘ืฆื™ื ื•ื”ื•ืกืคืช ืจื™ื‘ื•ื™ ืชื•ื•ื™ืช, ืขืœื™ืš ืœื”ื•ืกื™ืฃ ืืช ื”ื›ื•ื ืŸ ื”ืงืฉื™ื— ืœ-/etc/fstab, ื”ื•ืกืฃ ืืช ื”ืฉื•ืจื” ืœืงื•ื‘ืฅ ื”ื–ื”:

/dev/ada1               /jail  ufs     rw              0       1

ื‘-Mountpoint, ืฆื™ื™ืŸ ืืช ื”ืกืคืจื™ื™ื” ืฉื‘ื” ืชืขืœื” ืืช ื”ื›ื•ื ืŸ ื”ืงืฉื™ื—; ื‘-Pass, ื”ืงืคื“ ืœืฆื™ื™ืŸ 1 (ื‘ืื™ื–ื” ืจืฆืฃ ื”ื›ื•ื ืŸ ื”ืงืฉื™ื— ื”ื–ื” ื™ื™ื‘ื“ืง) - ื–ื” ื”ื›ืจื—ื™, ืžื›ื™ื•ื•ืŸ ืฉืžืขืจื›ืช ื”ืงื‘ืฆื™ื ufs ืจื’ื™ืฉื” ืœื”ืคืกืงื•ืช ื—ืฉืžืœ ืคืชืื•ืžื™ื•ืช . ืœืื—ืจ ื”ืฉืœื‘ื™ื ื”ื‘ืื™ื, ื”ืชืงืŸ ืืช ื”ื“ื™ืกืง:

mount /dev/ada1 /jail

ื”ืชืงืŸ ืืช ื”ื›ืœื ื‘ืกืคืจื™ื™ื” ื–ื•. ืœืื—ืจ ืฉื”ื›ืœื ืคื•ืขืœ, ืขืœื™ืš ืœื‘ืฆืข ื‘ื• ืืช ืื•ืชืŸ ืžื ื™ืคื•ืœืฆื™ื•ืช ื›ืžื• ื‘ืžืขืจื›ืช ื”ืจืืฉื™ืช ืขื ื”ืžืฉืชืžืฉื™ื ื•ื”ืงื‘ืฆื™ื /etc/login.conf, /etc/mac.conf.

ื”ืชืืžื”

ืœืคื ื™ ื”ืชืงื ืช ื”ืชื’ื™ื ื”ื“ืจื•ืฉื™ื, ืื ื™ ืžืžืœื™ืฅ ืœื”ืชืงื™ืŸ ืืช ื›ืœ ื”ื—ื‘ื™ืœื•ืช ื”ื“ืจื•ืฉื•ืช; ื‘ืžืงืจื” ืฉืœื™, ื”ืชื’ื™ื ื™ื•ื’ื“ืจื• ืชื•ืš ื”ืชื—ืฉื‘ื•ืช ื‘ื—ื‘ื™ืœื•ืช ื”ื‘ืื•ืช:

mod_php73-7.3.4_1              PHP Scripting Language
php73-7.3.4_1                  PHP Scripting Language
php73-ctype-7.3.4_1            The ctype shared extension for php
php73-curl-7.3.4_1             The curl shared extension for php
php73-dom-7.3.4_1              The dom shared extension for php
php73-extensions-1.0           "meta-port" to install PHP extensions
php73-filter-7.3.4_1           The filter shared extension for php
php73-gd-7.3.4_1               The gd shared extension for php
php73-gettext-7.3.4_1          The gettext shared extension for php
php73-hash-7.3.4_1             The hash shared extension for php
php73-iconv-7.3.4_1            The iconv shared extension for php
php73-json-7.3.4_1             The json shared extension for php
php73-mysqli-7.3.4_1           The mysqli shared extension for php
php73-opcache-7.3.4_1          The opcache shared extension for php
php73-openssl-7.3.4_1          The openssl shared extension for php
php73-pdo-7.3.4_1              The pdo shared extension for php
php73-pdo_sqlite-7.3.4_1       The pdo_sqlite shared extension for php
php73-phar-7.3.4_1             The phar shared extension for php
php73-posix-7.3.4_1            The posix shared extension for php
php73-session-7.3.4_1          The session shared extension for php
php73-simplexml-7.3.4_1        The simplexml shared extension for php
php73-sqlite3-7.3.4_1          The sqlite3 shared extension for php
php73-tokenizer-7.3.4_1        The tokenizer shared extension for php
php73-xml-7.3.4_1              The xml shared extension for php
php73-xmlreader-7.3.4_1        The xmlreader shared extension for php
php73-xmlrpc-7.3.4_1           The xmlrpc shared extension for php
php73-xmlwriter-7.3.4_1        The xmlwriter shared extension for php
php73-xsl-7.3.4_1              The xsl shared extension for php
php73-zip-7.3.4_1              The zip shared extension for php
php73-zlib-7.3.4_1             The zlib shared extension for php
apache24-2.4.39 

ื‘ื“ื•ื’ืžื” ื–ื•, ืชื•ื•ื™ื•ืช ื™ื•ื’ื“ืจื• ืชื•ืš ื”ืชื—ืฉื‘ื•ืช ื‘ืชืœื•ืช ืฉืœ ื—ื‘ื™ืœื•ืช ืืœื•. ื›ืžื•ื‘ืŸ, ืืชื” ื™ื›ื•ืœ ืœืขืฉื•ืช ืืช ื–ื” ืคืฉื•ื˜ ื™ื•ืชืจ: ืขื‘ื•ืจ ื”ืชื™ืงื™ื” /usr/local/lib ื•ื”ืงื‘ืฆื™ื ื”ืžืžื•ืงืžื™ื ื‘ืกืคืจื™ื™ื” ื–ื•, ื”ื’ื“ืจ ืืช ื”ืชื•ื•ื™ื•ืช mls/low ื•ื—ื‘ื™ืœื•ืช ืฉื”ื•ืชืงื ื• ืœืื—ืจ ืžื›ืŸ (ืœื“ื•ื’ืžื”, ื”ืจื—ื‘ื•ืช ื ื•ืกืคื•ืช ืขื‘ื•ืจ php) ื™ื•ื›ืœื• ืœื’ืฉืช ื”ืกืคืจื™ื•ืช ื‘ืกืคืจื™ื™ื” ื”ื–ื•, ืื‘ืœ ื ืจืื” ืœื™ ืฉืขื“ื™ืฃ ืœืกืคืง ื’ื™ืฉื” ืจืง ืœืงื‘ืฆื™ื ื”ื ื—ื•ืฆื™ื. ืขืฆื•ืจ ืืช ื”ื›ืœื ื•ื”ื’ื“ืจ ืชื•ื•ื™ื•ืช mls/high ื‘ื›ืœ ื”ืงื‘ืฆื™ื:

setfmac -R mls/high /jail

ื‘ืขืช ื”ื’ื“ืจืช ืกื™ืžื ื™ื, ื”ืชื”ืœื™ืš ื™ื•ืคืกืง ืื setfmac ื ืชืงืœ ื‘ืงื™ืฉื•ืจื™ื ืงืฉื™ื—ื™ื, ื‘ื“ื•ื’ืžื” ืฉืœื™ ืžื—ืงืชื™ ืงื™ืฉื•ืจื™ื ืงืฉื™ื—ื™ื ื‘ืกืคืจื™ื•ืช ื”ื‘ืื•ืช:

/var/db/etcupdate/current/
/var/db/etcupdate/current/etc
/var/db/etcupdate/current/usr/share/openssl/man/en.ISO8859-15
/var/db/etcupdate/current/usr/share/man/en.ISO8859-15
/var/db/etcupdate/current/usr/share/man/en.UTF-8
/var/db/etcupdate/current/usr/share/nls
/etc/ssl
/usr/local/etc
/usr/local/etc/fonts/conf.d
/usr/local/openssl

ืœืื—ืจ ื”ื’ื“ืจืช ื”ืชื•ื•ื™ื•ืช, ืขืœื™ืš ืœื”ื’ื“ื™ืจ ืืช ื”ืชื•ื•ื™ื•ืช mls/low ืขื‘ื•ืจ apache, ื”ื“ื‘ืจ ื”ืจืืฉื•ืŸ ืฉืืชื” ืฆืจื™ืš ืœืขืฉื•ืช ื”ื•ื ืœื‘ืจืจ ืื™ืœื• ืงื‘ืฆื™ื ื ื“ืจืฉื™ื ื›ื“ื™ ืœื”ืคืขื™ืœ ืืช apache:

ldd /usr/local/sbin/httpd

ืœืื—ืจ ื‘ื™ืฆื•ืข ืคืงื•ื“ื” ื–ื•, ืชืœื•ืชื™ื•ืช ื™ื•ืฆื’ื• ืขืœ ื”ืžืกืš, ืืš ื”ื’ื“ืจืช ื”ืชื•ื•ื™ื•ืช ื”ื“ืจื•ืฉื•ืช ื‘ืงื‘ืฆื™ื ืืœื• ืœื ืชืกืคื™ืง, ืžืื—ืจ ื•ืœืกืคืจื™ื•ืช ื‘ื”ืŸ ืžืžื•ืงืžื™ื ืงื‘ืฆื™ื ืืœื• ื™ืฉ ืืช ื”ืชื•ื•ื™ืช mls/high, ื›ืš ืฉื’ื ืกืคืจื™ื•ืช ืืœื• ืฆืจื™ื›ื•ืช ืœื”ื™ื•ืช ืžืชื•ื™ื’ื•ืช mls/ื ืžื•ืš. ื‘ืขืช ื”ื”ืคืขืœื”, apache ืชื•ืฆื™ื ื’ื ืืช ื”ืงื‘ืฆื™ื ื”ื“ืจื•ืฉื™ื ืœื”ืคืขืœืชื•, ื•ืขื‘ื•ืจ php ื ื™ืชืŸ ืœืžืฆื•ื ืืช ื”ืชืœื•ืช ื”ืœืœื• ื‘ื™ื•ืžืŸ httpd-error.log.

setfmac mls/low /
setfmac mls/low /usr/local/lib/libpcre.so.1
setfmac mls/low /usr/local/lib/libaprutil-1.so.0
setfmac mls/low /usr/local/lib/libdb-5.3.so.0
setfmac mls/low /usr/local/lib/libgdbm.so.6
setfmac mls/low /usr/local/lib/libexpat.so.1
setfmac mls/low /usr/local/lib/libapr-1.so.0
setfmac mls/low /lib/libcrypt.so.5
setfmac mls/low /lib/libthr.so.3
setfmac mls/low /lib/libc.so.7
setfmac mls/low /usr/local/lib/libintl.so.8
setfmac mls/low /var
setfmac mls/low /var/run
setfmac mls/low /var/log
setfmac mls/low /var/log/httpd-access.log
setfmac mls/low /var/log/httpd-error.log
setfmac mls/low /var/run/httpd.pid
setfmac mls/low /lib
setfmac mls/low /lib/libcrypt.so.5
setfmac mls/low /usr/local/lib/db5/libdb-5.3.so.0
setfmac mls/low /usr/local/lib/db5/libdb-5.3.so.0.0.0
setfmac mls/low /usr/local/lib/db5
setfmac mls/low /usr/local/lib
setfmac mls/low /libexec
setfmac mls/low /libexec/ld-elf.so.1
setfmac  mls/low /dev
setfmac  mls/low /dev/random
setfmac  mls/low /usr/local/libexec
setfmac  mls/low /usr/local/libexec/apache24
setfmac  mls/low /usr/local/libexec/apache24/*
setfmac  mls/low /etc/pwd.db
setfmac  mls/low /etc/passwd
setfmac  mls/low /etc/group
setfmac  mls/low /etc/
setfmac  mls/low /usr/local/etc
setfmac -R mls/low /usr/local/etc/apache24
setfmac mls/low /usr
setfmac mls/low /usr/local
setfmac mls/low /usr/local/sbin
setfmac mls/low /usr/local/sbin/*
setfmac -R mls/low /usr/local/etc/rc.d/
setfmac mls/low /usr/local/sbin/htcacheclean
setfmac mls/low /var/log/httpd-access.log
setfmac mls/low /var/log/httpd-error.log
setfmac -R mls/low /usr/local/www
setfmac mls/low /usr/lib
setfmac mls/low /tmp
setfmac -R mls/low /usr/local/lib/php
setfmac -R mls/low /usr/local/etc/php
setfmac mls/low /usr/local/etc/php.conf
setfmac mls/low /lib/libelf.so.2
setfmac mls/low /lib/libm.so.5
setfmac mls/low /usr/local/lib/libxml2.so.2
setfmac mls/low /lib/libz.so.6
setfmac mls/low /usr/lib/liblzma.so.5
setfmac mls/low /usr/local/lib/libiconv.so.2
setfmac mls/low /usr/lib/librt.so.1
setfmac mls/low /lib/libthr.so.3
setfmac mls/low /usr/local/lib/libpng16.so.16
setfmac mls/low /usr/lib/libbz2.so.4
setfmac mls/low /usr/local/lib/libargon2.so.0
setfmac mls/low /usr/local/lib/libpcre2-8.so.0
setfmac mls/low /usr/local/lib/libsqlite3.so.0
setfmac mls/low /usr/local/lib/libgd.so.6
setfmac mls/low /usr/local/lib/libjpeg.so.8
setfmac mls/low /usr/local/lib/libfreetype.so
setfmac mls/low /usr/local/lib/libfontconfig.so.1
setfmac mls/low /usr/local/lib/libtiff.so.5
setfmac mls/low /usr/local/lib/libwebp.so.7
setfmac mls/low /usr/local/lib/libjbig.so.2
setfmac mls/low /usr/lib/libssl.so.8
setfmac mls/low /lib/libcrypto.so.8
setfmac mls/low /usr/local/lib/libzip.so.5
setfmac mls/low /etc/resolv.conf

ืจืฉื™ืžื” ื–ื• ืžื›ื™ืœื” ืชื’ื™ื•ืช mls/low ืขื‘ื•ืจ ื›ืœ ื”ืงื‘ืฆื™ื ื”ื ื—ื•ืฆื™ื ืœืคืขื•ืœื” ื ื›ื•ื ื” ืฉืœ ื”ืฉื™ืœื•ื‘ ืฉืœ apache ื•-php (ืขื‘ื•ืจ ืื•ืชืŸ ื—ื‘ื™ืœื•ืช ืฉืžื•ืชืงื ื•ืช ื‘ื“ื•ื’ืžื” ืฉืœื™).

ื”ืžื’ืข ื”ืื—ืจื•ืŸ ื™ื”ื™ื” ืœื”ื’ื“ื™ืจ ืืช ื”ื›ืœื ืœืจื•ืฅ ื‘ืจืžืช mls/ืฉื•ื•ื”, ื•-apache ื‘ืจืžืช mls/ื ืžื•ื›ื”. ื›ื“ื™ ืœื”ืชื—ื™ืœ ืืช ื”ื›ืœื, ืขืœื™ืš ืœื‘ืฆืข ืฉื™ื ื•ื™ื™ื ื‘ืกืงืจื™ืคื˜ /etc/rc.d/jail, ืœืžืฆื•ื ืืช ืคื•ื ืงืฆื™ื•ืช jail_start ื‘ืกืงืจื™ืคื˜ ื–ื”, ืœืฉื ื•ืช ืืช ืžืฉืชื ื” ื”ืคืงื•ื“ื” ืœืฆื•ืจื”:

command="setpmac mls/equal $jail_program"

ื”ืคืงื•ื“ื” setpmac ืžืจื™ืฆื” ืืช ืงื•ื‘ืฅ ื”ื”ืคืขืœื” ื‘ืจืžืช ื”ื™ื›ื•ืœืช ื”ื ื“ืจืฉืช, ื‘ืžืงืจื” ื–ื” mls/equal, ืขืœ ืžื ืช ืœืงื‘ืœ ื’ื™ืฉื” ืœื›ืœ ื”ืชื•ื•ื™ื•ืช. ื‘-apache ืืชื” ืฆืจื™ืš ืœืขืจื•ืš ืืช ืกืงืจื™ืคื˜ ื”ืืชื—ื•ืœ /usr/local/etc/rc.d/apache24. ืฉื ื” ืืช ื”ืคื•ื ืงืฆื™ื” apache24_prestart:

apache24_prestart() {
        apache24_checkfib
        apache24_precmd
        eval "setpmac mls/low" ${command} ${apache24_flags}
}

ะ’ ืจืฉืžื™ืช ื”ืžื“ืจื™ืš ืžื›ื™ืœ ื“ื•ื’ืžื” ื ื•ืกืคืช, ืืš ืœื ื”ืฆืœื—ืชื™ ืœื”ืฉืชืžืฉ ื‘ื• ื›ื™ ื›ืœ ื”ื–ืžืŸ ืงื™ื‘ืœืชื™ ื”ื•ื“ืขื” ืขืœ ื—ื•ืกืจ ื”ื™ื›ื•ืœืช ืœื”ืฉืชืžืฉ ื‘ืคืงื•ื“ื” setpmac.

ืคืœื˜

ืฉื™ื˜ื” ื–ื• ืฉืœ ื”ืคืฆืช ื’ื™ืฉื” ืชื•ืกื™ืฃ ืจืžืช ืื‘ื˜ื—ื” ื ื•ืกืคืช ืœ-apache (ืื ื›ื™ ืฉื™ื˜ื” ื–ื• ืžืชืื™ืžื” ืœื›ืœ ืžื—ืกื ื™ืช ืื—ืจืช), ืฉื‘ื ื•ืกืฃ ืคื•ืขืœืช ื‘ื›ืœื, ื‘ืžืงื‘ื™ืœ, ืขื‘ื•ืจ ื”ืžื ื”ืœ ื›ืœ ื–ื” ื™ืงืจื” ื‘ืฉืงื™ืคื•ืช ื•ื‘ืื•ืคืŸ ื‘ืœืชื™ ืžื•ืจื’ืฉ.

ืจืฉื™ืžืช ืžืงื•ืจื•ืช ืฉืขื–ืจื• ืœื™ ื‘ื›ืชื™ื‘ืช ืคืจืกื•ื ื–ื”:

https://www.freebsd.org/doc/ru_RU.KOI8-R/books/handbook/mac.html

ืžืงื•ืจ: www.habr.com

ื”ื•ืกืคืช ืชื’ื•ื‘ื”