ืžื™ืงืจื•ืกื•ืคื˜ ืคืจืกืžื” ืขื“ื›ื•ืŸ ืœื”ืคืฆืช ืœื™ื ื•ืงืก CBL-Mariner

ืžื™ืงืจื•ืกื•ืคื˜ ืคืจืกืžื” ืขื“ื›ื•ืŸ ืœืขืจื›ืช ื”ื”ืคืฆื” CBL-Mariner 2.0.20221029 (Common Base Linux Mariner), ื”ืžืคื•ืชื—ืช ื›ืคืœื˜ืคื•ืจืžืช ื‘ืกื™ืก ืื•ื ื™ื‘ืจืกืœื™ืช ืขื‘ื•ืจ ืกื‘ื™ื‘ื•ืช ืœื™ื ื•ืงืก ื”ืžืฉืžืฉื•ืช ื‘ืชืฉืชื™ืช ืขื ืŸ, ืžืขืจื›ื•ืช ืงืฆื” ื•ืฉื™ืจื•ืชื™ื ืฉื•ื ื™ื ืฉืœ ืžื™ืงืจื•ืกื•ืคื˜. ื”ืคืจื•ื™ืงื˜ ื ื•ืขื“ ืœืื—ื“ ืืช ืคืชืจื•ื ื•ืช ืœื™ื ื•ืงืก ืฉืœ ืžื™ืงืจื•ืกื•ืคื˜ ื•ืœืคืฉื˜ ืืช ื”ืชื—ื–ื•ืงื” ืฉืœ ืžืขืจื›ื•ืช ืœื™ื ื•ืงืก ืœืžื˜ืจื•ืช ืฉื•ื ื•ืช ืขื“ื›ื ื™ื•ืช. ื”ืคื™ืชื•ื—ื™ื ืฉืœ ื”ืคืจื•ื™ืงื˜ ืžื•ืคืฆื™ื ืชื—ืช ืจื™ืฉื™ื•ืŸ MIT. ื—ื‘ื™ืœื•ืช ื ื•ืฆืจื•ืช ืขื‘ื•ืจ ืืจื›ื™ื˜ืงื˜ื•ืจื•ืช aarch64 ื•-x86_64. ืชืžื•ื ืช ISO ื ื™ืชื ืช ืœืืชื—ื•ืœ ื”ื•ื›ื ื” (1.1 GB) ืขื‘ื•ืจ ืืจื›ื™ื˜ืงื˜ื•ืจืช x86_64.

ื‘ื’ืจืกื” ื”ื—ื“ืฉื”:

  • ื’ืจืกืื•ืช ื—ื‘ื™ืœื” ืžืขื•ื“ื›ื ื•ืช, ื›ื•ืœืœ ืžื”ื“ื•ืจื•ืช ืžื•ืฆืขื•ืช ืฉืœ ืœื™ื‘ืช ืœื™ื ื•ืงืก 5.15.74, PHP 8.1.11, nodejs 16.17.1, cassandra 4.0.7, dbus 1.15.2, expat 2.5.0, mysql 8.0.31, terraform 1.32.2, tidy 5.8.0, wireshark 3.4.16, nginx 1.22.1.
  • ื ื•ืกืคื• ื—ื‘ื™ืœื•ืช ื—ื“ืฉื•ืช cairomm 1.12.0, cpptest 1.1.2, k-exec-tools, kernel-drivers-gpu, libcroco 0.6.13, python-google-auth-oauthlib, sgx-backwards-compatability.
  • ื›ืœื•ืœื™ื ืžื•ื“ื•ืœื™ื ืœืฉื™ื ื•ื™ ืืœื’ื•ืจื™ืชื ื‘ืงืจืช ื”ื’ื•ื“ืฉ TCP (TCP Congestion).
  • ืชื™ืงื•ื ื™ ื”ืคื’ื™ืขื•ืช ื”ื•ืขื‘ืจื• ืœื—ื‘ื™ืœื•ืช libtar, unbound, aspell, libtiff, redis, livepatch, libtasn1, PHP, nodejs, dbus, expat, mod_wsgi, wireshark, nginx, mysql, terraform.

ื”ืคืฆืช CBL-Mariner ืžืกืคืงืช ืกื˜ ืกื˜ื ื“ืจื˜ื™ ืงื˜ืŸ ืฉืœ ื—ื‘ื™ืœื•ืช ื‘ืกื™ืกื™ื•ืช ื”ืžืฉืžืฉื•ืช ื›ื‘ืกื™ืก ืื•ื ื™ื‘ืจืกืœื™ ืœื™ืฆื™ืจืช ืชื›ื•ืœืช ืงื•ื ื˜ื™ื™ื ืจื™ื, ืกื‘ื™ื‘ื•ืช ืžืืจื—ื•ืช ื•ืฉื™ืจื•ืชื™ื ื”ืคื•ืขืœื™ื ื‘ืชืฉืชื™ื•ืช ืขื ืŸ ื•ื‘ืžื›ืฉื™ืจื™ ืงืฆื”. ื ื™ืชืŸ ืœื™ืฆื•ืจ ืคืชืจื•ื ื•ืช ืžื•ืจื›ื‘ื™ื ื•ืžื™ื•ื—ื“ื™ื ื™ื•ืชืจ ืขืœ ื™ื“ื™ ื”ื•ืกืคืช ื—ื‘ื™ืœื•ืช ื ื•ืกืคื•ืช ืขืœ ื’ื‘ื™ CBL-Mariner, ืืš ื”ื‘ืกื™ืก ืœื›ืœ ื”ืžืขืจื›ื•ืช ื”ืœืœื• ื ืฉืืจ ื–ื”ื”, ืžื” ืฉืžืงืœ ืขืœ ื”ืชื—ื–ื•ืงื” ื•ื”ืขื“ื›ื•ื ื™ื. ืœื“ื•ื’ืžื”, CBL-Mariner ืžืฉืžืฉ ื›ื‘ืกื™ืก ืœื”ืคืฆืช ื”ืžื™ื ื™ WSLg, ื”ืžืกืคืงืช ืจื›ื™ื‘ื™ ืžื—ืกื ื™ืช ื’ืจืคื™ืงื” ืœื”ืคืขืœืช ื™ื™ืฉื•ืžื™ GUI ืฉืœ Linux ื‘ืกื‘ื™ื‘ื•ืช ื”ืžื‘ื•ืกืกื•ืช ืขืœ ืชืช-ืžืขืจื›ืช WSL2 (Windows Subsystem for Linux). ืคื•ื ืงืฆื™ื•ื ืœื™ื•ืช ืžื•ืจื—ื‘ืช ื‘-WSLg ืžื•ืฉื’ืช ื‘ืืžืฆืขื•ืช ื”ื›ืœืœืช ื—ื‘ื™ืœื•ืช ื ื•ืกืคื•ืช ืขื Weston Composite Server, XWayland, PulseAudio ื•-FreeRDP.

ืžืขืจื›ืช ื”ื‘ื ื™ื™ื” ืฉืœ CBL-Mariner ืžืืคืฉืจืช ืœืš ืœื™ืฆื•ืจ ื’ื ื—ื‘ื™ืœื•ืช RPM ื‘ื•ื“ื“ื•ืช ื”ืžื‘ื•ืกืกื•ืช ืขืœ ืงื‘ืฆื™ SPEC ื•ืงื•ื“ ืžืงื•ืจ, ื•ื’ื ืชืžื•ื ื•ืช ืžืขืจื›ืช ืžื•ื ื•ืœื™ื˜ื™ื•ืช ืฉื ื•ืฆืจื• ื‘ืืžืฆืขื•ืช ืขืจื›ืช ื”ื›ืœื™ื rpm-ostree ื•ืžืชืขื“ื›ื ื•ืช ืžื‘ื—ื™ื ื” ืื˜ื•ืžื™ืช ืžื‘ืœื™ ืœื”ืชืคืฆืœ ืœื—ื‘ื™ืœื•ืช ื ืคืจื“ื•ืช. ื‘ื”ืชืื ืœื›ืš, ืฉื ื™ ืžื•ื“ืœื™ื ืฉืœ ืžืกื™ืจืช ืขื“ื›ื•ื ื™ื ื ืชืžื›ื™ื: ื‘ืืžืฆืขื•ืช ืขื“ื›ื•ืŸ ื—ื‘ื™ืœื•ืช ื‘ื•ื“ื“ื•ืช ื•ื“ืจืš ื‘ื ื™ื™ื” ืžื—ื“ืฉ ื•ืขื“ื›ื•ืŸ ืฉืœ ืชืžื•ื ืช ื”ืžืขืจื›ืช ื›ื•ืœื”. ื–ืžื™ืŸ ืžืื’ืจ ืฉืœ ื›-3000 ื—ื‘ื™ืœื•ืช RPM ืžื•ื‘ื ื•ืช ืžืจืืฉ ืฉื‘ื”ืŸ ืชื•ื›ืœื• ืœื”ืฉืชืžืฉ ื›ื“ื™ ืœื‘ื ื•ืช ืชืžื•ื ื•ืช ืžืฉืœื›ื ืขืœ ืกืžืš ืงื•ื‘ืฅ ืชืฆื•ืจื”.

ื”ื”ืคืฆื” ื›ื•ืœืœืช ืจืง ืืช ื”ืจื›ื™ื‘ื™ื ื”ื“ืจื•ืฉื™ื ื‘ื™ื•ืชืจ ื•ื”ื™ื ืžื•ืชืืžืช ืœืฆืจื™ื›ืช ื–ื™ื›ืจื•ืŸ ืžื™ื ื™ืžืœื™ืช ื•ืฆืจื™ื›ืช ืฉื˜ื— ื“ื™ืกืง, ื›ืžื• ื’ื ืœืžื”ื™ืจื•ืช ื˜ืขื™ื ื” ื’ื‘ื•ื”ื”. ื”ื”ืคืฆื” ื‘ื•ืœื˜ืช ื’ื ื‘ื”ื›ืœืœืช ืžื ื’ื ื•ื ื™ื ื ื•ืกืคื™ื ืฉื•ื ื™ื ืœืฉื™ืคื•ืจ ื”ืื‘ื˜ื—ื”. ื”ืคืจื•ื™ืงื˜ ื ื•ืงื˜ ื‘ื’ื™ืฉืช "ืื‘ื˜ื—ื” ืžืจื‘ื™ืช ื›ื‘ืจื™ืจืช ืžื—ื“ืœ". ืืคืฉืจ ืœืกื ืŸ ืงืจื™ืื•ืช ืžืขืจื›ืช ื‘ืืžืฆืขื•ืช ืžื ื’ื ื•ืŸ seccomp, ืœื”ืฆืคื™ืŸ ืžื—ื™ืฆื•ืช ื“ื™ืกืง ื•ืœืืžืช ื—ื‘ื™ืœื•ืช ื‘ืืžืฆืขื•ืช ื—ืชื™ืžื” ื“ื™ื’ื™ื˜ืœื™ืช.

ืžื•ืคืขืœื™ื ืžืฆื‘ื™ ืืงืจืื™ ืฉืœ ืžืจื—ื‘ ื›ืชื•ื‘ื•ืช ื”ื ืชืžื›ื™ื ื‘ืœื™ื‘ืช ืœื™ื ื•ืงืก, ื›ืžื• ื’ื ืžื ื’ื ื•ื ื™ ื”ื’ื ื” ืžืคื ื™ ื”ืชืงืคื•ืช ืกื™ืžืœื™ื ืง, mmap, /dev/mem ื•-/dev/kmem. ืื–ื•ืจื™ ื”ื–ื™ื›ืจื•ืŸ ื”ืžื›ื™ืœื™ื ืžืงื˜ืขื™ื ืขื ื ืชื•ื ื™ ืœื™ื‘ื” ื•ืžื•ื“ื•ืœ ืžื•ื’ื“ืจื™ื ืœืžืฆื‘ ืงืจื™ืื” ื‘ืœื‘ื“ ื•ื‘ื™ืฆื•ืข ืงื•ื“ ืืกื•ืจ. ืืคืฉืจื•ืช ืื•ืคืฆื™ื•ื ืœื™ืช ื”ื™ื ืœื‘ื˜ืœ ื˜ืขื™ื ืช ืžื•ื“ื•ืœื™ ืœื™ื‘ื” ืœืื—ืจ ืืชื—ื•ืœ ื”ืžืขืจื›ืช. ืขืจื›ืช ื”ื›ืœื™ื iptables ืžืฉืžืฉืช ืœืกื™ื ื•ืŸ ืžื ื•ืช ืจืฉืช. ื‘ืฉืœื‘ ื”ื‘ื ื™ื™ื”, ื”ื’ื ื” ืžืคื ื™ ื”ืฆืคืช ืžื—ืกื ื™ืช, ื’ืœื™ืฉืช ืžืื’ืจ ื•ื‘ืขื™ื•ืช ืขื™ืฆื•ื‘ ืžื—ืจื•ื–ืช ืžื•ืคืขืœืช ื›ื‘ืจื™ืจืช ืžื—ื“ืœ (_FORTIFY_SOURCE, -fstack-protector, -Wformat-security, relro).

ืžืขืจื›ืช ืžื ื”ืœ ื”ืžืขืจื›ืช ืžืฉืžืฉืช ืœื ื™ื”ื•ืœ ืฉื™ืจื•ืชื™ื ื•ืœืืชื—ื•ืœ. ืžื ื”ืœื™ ื—ื‘ื™ืœื•ืช RPM ื•-DNF ืžืกื•ืคืงื™ื ืœื ื™ื”ื•ืœ ื—ื‘ื™ืœื•ืช. ืฉืจืช SSH ืื™ื ื• ืžื•ืคืขืœ ื›ื‘ืจื™ืจืช ืžื—ื“ืœ. ื›ื“ื™ ืœื”ืชืงื™ืŸ ืืช ื”ื”ืคืฆื”, ืžืกื•ืคืง ืžืชืงื™ืŸ ืฉื™ื›ื•ืœ ืœืขื‘ื•ื“ ื”ืŸ ื‘ืžืฆื‘ื™ ื˜ืงืกื˜ ื•ื”ืŸ ื‘ืžืฆื‘ ื’ืจืคื™. ื”ืžืชืงื™ืŸ ืžืกืคืง ืืคืฉืจื•ืช ื”ืชืงื ื” ืขื ืกื˜ ืžืœื ืื• ื‘ืกื™ืกื™ ืฉืœ ื—ื‘ื™ืœื•ืช, ื•ืžืฆื™ืข ืžืžืฉืง ืœื‘ื—ื™ืจืช ืžื—ื™ืฆืช ื“ื™ืกืง, ื‘ื—ื™ืจืช ืฉื ืžืืจื— ื•ื™ืฆื™ืจืช ืžืฉืชืžืฉื™ื.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”