ืฉื—ืจื•ืจ ืžื•ื“ื•ืœ LKRG 0.9.2 ืœื”ื’ื ื” ืžืคื ื™ ื ื™ืฆื•ืœ ืฉืœ ืคื’ื™ืขื•ื™ื•ืช ื‘ืœื™ื‘ืช ืœื™ื ื•ืงืก

ืคืจื•ื™ืงื˜ Openwall ืคืจืกื ืืช ื”ืฉื—ืจื•ืจ ืฉืœ ืžื•ื“ื•ืœ ื”ืœื™ื‘ื” LKRG 0.9.2 (Linux Kernel Runtime Guard), ืฉื ื•ืขื“ ืœื–ื”ื•ืช ื•ืœื—ืกื•ื ื”ืชืงืคื•ืช ื•ื”ืคืจื•ืช ืฉืœืžื•ืช ืžื‘ื ื™ ื”ืœื™ื‘ื”. ืœื“ื•ื’ืžื”, ื”ืžื•ื“ื•ืœ ื™ื›ื•ืœ ืœื”ื’ืŸ ืžืคื ื™ ืฉื™ื ื•ื™ื™ื ืœื ืžื•ืจืฉื™ื ื‘ืงืจื ืœ ื”ืคื•ืขืœ ื•ื ื™ืกื™ื•ื ื•ืช ืœืฉื ื•ืช ืืช ื”ื”ืจืฉืื•ืช ืฉืœ ืชื”ืœื™ื›ื™ ื”ืžืฉืชืžืฉ (ื–ื™ื”ื•ื™ ืฉื™ืžื•ืฉ ื‘ื ื™ืฆื•ืœ). ื”ืžื•ื“ื•ืœ ืžืชืื™ื ื”ืŸ ืœืืจื’ื•ืŸ ื”ื’ื ื” ืžืคื ื™ ื ื™ืฆื•ืœ ืฉืœ ืคืจืฆื•ืช ืœื™ื‘ืช ืœื™ื ื•ืงืก ื™ื“ื•ืขื•ืช ื›ื‘ืจ (ืœื“ื•ื’ืžื”, ื‘ืžืฆื‘ื™ื ืฉื‘ื”ื ืงืฉื” ืœืขื“ื›ืŸ ืืช ื”ืœื™ื‘ื” ื‘ืžืขืจื›ืช), ื•ื”ืŸ ืœืžื ื™ืขืช ื ื™ืฆื•ืœ ืฉืœ ืคืจืฆื•ืช ืฉืขื“ื™ื™ืŸ ืœื ื™ื“ื•ืขื•ืช. ืงื•ื“ ื”ืคืจื•ื™ืงื˜ ืžื•ืคืฅ ืชื—ืช ืจื™ืฉื™ื•ืŸ GPLv2. ื ื™ืชืŸ ืœืงืจื•ื ืขืœ ื”ืžืืคื™ื™ื ื™ื ืฉืœ ื™ื™ืฉื•ื LKRG ื‘ื”ื•ื“ืขื” ื”ืจืืฉื•ื ื” ืขืœ ื”ืคืจื•ื™ืงื˜.

ื‘ื™ืŸ ื”ืฉื™ื ื•ื™ื™ื ื‘ื’ืจืกื” ื”ื—ื“ืฉื”:

  • ืชืื™ืžื•ืช ืžืกื•ืคืงืช ืขื ืœื™ื‘ื•ืช ืœื™ื ื•ืงืก ืž-5.14 ืขื“ 5.16-rc, ื›ืžื• ื’ื ืขื ืขื“ื›ื•ื ื™ื ืœื’ืจืขื™ื ื™ LTS 5.4.118+, 4.19.191+ ื•-4.14.233+.
  • ื ื•ืกืคื” ืชืžื™ื›ื” ืขื‘ื•ืจ ืชืฆื•ืจื•ืช CONFIG_SECCOMP ืฉื•ื ื•ืช.
  • ื ื•ืกืคื” ืชืžื™ื›ื” ื‘ืคืจืžื˜ืจ ื”ืœื™ื‘ื” "nolkrg" ื›ื“ื™ ืœื‘ื˜ืœ ืืช LKRG ื‘ื–ืžืŸ ื”ืืชื—ื•ืœ.
  • ืชื•ืงืŸ ื—ื™ื•ื‘ื™ ืฉื’ื•ื™ ืขืงื‘ ืžืฆื‘ ืžื™ืจื•ืฅ ื‘ืขืช ืขื™ื‘ื•ื“ SECCOMP_FILTER_FLAG_TSYNC.
  • ืฉื™ืคืจ ืืช ื”ื™ื›ื•ืœืช ืœื”ืฉืชืžืฉ ื‘ื”ื’ื“ืจื” CONFIG_HAVE_STATIC_CALL ื‘ืœื™ื‘ืช ืœื™ื ื•ืงืก 5.10+ ื›ื“ื™ ืœื—ืกื•ื ืชื ืื™ ืžื™ืจื•ืฅ ื‘ืขืช ืคืจื™ืงืช ืžื•ื“ื•ืœื™ื ืื—ืจื™ื.
  • ืฉืžื•ืช ื”ืžื•ื“ื•ืœื™ื ืฉื ื—ืกืžื• ื‘ืขืช ืฉื™ืžื•ืฉ ื‘ื”ื’ื“ืจื” lkrg.block_modules=1 ื ืฉืžืจื™ื ื‘ื™ื•ืžืŸ.
  • ื”ื˜ืžืขื” ืฉืœ ื”ื’ื“ืจื•ืช sysctl ื‘ืงื•ื‘ืฅ /etc/sysctl.d/01-lkrg.conf
  • ื ื•ืกืฃ ืงื•ื‘ืฅ ืชืฆื•ืจื” dkms.conf ืขื‘ื•ืจ ืžืขืจื›ืช DKMS (ืชืžื™ื›ื” ื‘-Dynamic Kernel Module) ื”ืžืฉืžืฉืช ืœื‘ื ื™ื™ืช ืžื•ื“ื•ืœื™ื ืฉืœ ืฆื“ ืฉืœื™ืฉื™ ืœืื—ืจ ืขื“ื›ื•ืŸ ืœื™ื‘ื”.
  • ืชืžื™ื›ื” ืžืฉื•ืคืจืช ื•ืžืขื•ื“ื›ื ืช ื‘ื‘ื ื™ื™ืช ืคื™ืชื•ื—ื™ื ื•ืžืขืจื›ื•ืช ืื™ื ื˜ื’ืจืฆื™ื” ืžืชืžืฉื›ื•ืช.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”