Fedora 40 ืžืชื›ื ื ืช ืœืืคืฉืจ ื‘ื™ื“ื•ื“ ืฉื™ืจื•ืชื™ ืžืขืจื›ืช

ื”ืžื”ื“ื•ืจื” ืฉืœ Fedora 40 ืžืฆื™ืขื” ื”ืคืขืœืช ื”ื’ื“ืจื•ืช ื‘ื™ื“ื•ื“ ืขื‘ื•ืจ ืฉื™ืจื•ืชื™ ืžืขืจื›ืช ืžืขืจื›ืช ื”ืžื•ืคืขืœื™ื ื›ื‘ืจื™ืจืช ืžื—ื“ืœ, ื›ืžื• ื’ื ืฉื™ืจื•ืชื™ื ืขื ื™ื™ืฉื•ืžื™ื ืงืจื™ื˜ื™ื™ื ืœืžืฉื™ืžื” ื›ื’ื•ืŸ PostgreSQL, Apache httpd, Nginx ื•-MariaDB. ืฆืคื•ื™ ืฉื”ืฉื™ื ื•ื™ ื™ื’ื‘ื™ืจ ืžืฉืžืขื•ืชื™ืช ืืช ืื‘ื˜ื—ืช ื”ื”ืคืฆื” ื‘ืชืฆื•ืจืช ื‘ืจื™ืจืช ื”ืžื—ื“ืœ ื•ื™ืืคืฉืจ ื—ืกื™ืžืช ื ืงื•ื“ื•ืช ืชื•ืจืคื” ืœื ื™ื“ื•ืขื•ืช ื‘ืฉื™ืจื•ืชื™ ื”ืžืขืจื›ืช. ื”ื”ืฆืขื” ื˜ืจื ื ื‘ื—ื ื” ืขืœ ื™ื“ื™ ื•ืขื“ืช ื”ื™ื’ื•ื™ ืฉืœ FESCo (Fedora Engineering Steering Committee), ืฉืื—ืจืื™ืช ืขืœ ื”ื—ืœืง ื”ื˜ื›ื ื™ ืฉืœ ืคื™ืชื•ื— ื”ืคืฆืช ืคื“ื•ืจื”. ื”ืฆืขื” ืขืฉื•ื™ื” ืœื”ื™ื“ื—ื•ืช ื’ื ื‘ืžื”ืœืš ืชื”ืœื™ืš ื”ื‘ื™ืงื•ืจืช ื‘ืงื”ื™ืœื”.

ื”ื’ื“ืจื•ืช ืžื•ืžืœืฆื•ืช ืœื”ืคืขืœืช:

  • PrivateTmp=yes - ืžืชืŸ ืกืคืจื™ื•ืช ื ืคืจื“ื•ืช ืขื ืงื‘ืฆื™ื ื–ืžื ื™ื™ื.
  • ProtectSystem=yes/full/strict โ€” ื˜ืขืŸ ืืช ืžืขืจื›ืช ื”ืงื‘ืฆื™ื ื‘ืžืฆื‘ ืงืจื™ืื” ื‘ืœื‘ื“ (ื‘ืžืฆื‘ "ืžืœื" - /etc/, ื‘ืžืฆื‘ strict - ื›ืœ ืžืขืจื›ื•ืช ื”ืงื‘ืฆื™ื ืžืœื‘ื“ /dev/, /proc/ ื•-/sys/).
  • ProtectHome=ื›ืŸ - ืžื•ื ืข ื’ื™ืฉื” ืœืกืคืจื™ื•ืช ื”ื‘ื™ืช ืฉืœ ื”ืžืฉืชืžืฉ.
  • PrivateDevices=yes - ื”ืฉืืจืช ื’ื™ืฉื” ืจืง ืœ-/dev/null, /dev/zero ื•-/dev/random
  • ProtectKernelTunables=yes - ื’ื™ืฉื” ืœืงืจื™ืื” ื‘ืœื‘ื“ ืืœ /proc/sys/, /sys/, /proc/acpi, /proc/fs, /proc/irq ื•ื›ื•'.
  • ProtectKernelModules=ื›ืŸ - ืืกื•ืจ ืœื˜ืขื•ืŸ ืžื•ื“ื•ืœื™ ืœื™ื‘ื”.
  • ProtectKernelLogs=ื›ืŸ - ืื•ืกืจ ืขืœ ื’ื™ืฉื” ืœืžืื’ืจ ืขื ื™ื•ืžื ื™ ืœื™ื‘ื”.
  • ProtectControlGroups=ื›ืŸ - ื’ื™ืฉืช ืงืจื™ืื” ื‘ืœื‘ื“ ืืœ /sys/fs/cgroup/
  • NoNewPrivileges=ื›ืŸ - ืื™ืกื•ืจ ืขืœ ื”ืขืœืืช ื”ืจืฉืื•ืช ื‘ืืžืฆืขื•ืช ื“ื’ืœื™ setuid, setgid ื•-capabilities.
  • PrivateNetwork=yes - ืžื™ืงื•ื ื‘ืžืจื—ื‘ ืฉืžื•ืช ื ืคืจื“ ืฉืœ ืžื—ืกื ื™ืช ื”ืจืฉืช.
  • ProtectClock=ื›ืŸ - ืืกื•ืจ ืœืฉื ื•ืช ืืช ื”ืฉืขื”.
  • ProtectHostname=yes - ืื•ืกืจ ืขืœ ืฉื™ื ื•ื™ ืฉื ื”ืžืืจื—.
  • ProtectProc=invisible - ื”ืกืชืจืช ืชื”ืœื™ื›ื™ื ืฉืœ ืื ืฉื™ื ืื—ืจื™ื ื‘-/proc.
  • User= - ืฉื ื” ืžืฉืชืžืฉ

ื‘ื ื•ืกืฃ, ืชื•ื›ืœ ืœืฉืงื•ืœ ืœื”ืคืขื™ืœ ืืช ื”ื”ื’ื“ืจื•ืช ื”ื‘ืื•ืช:

  • CapabilityBoundingSet=
  • DevicePolicy=ืกื’ื•ืจ
  • KeyringMode=ืคืจื˜ื™
  • LockPersonality=ื›ืŸ
  • MemoryDenyWriteExecute=ื›ืŸ
  • ืžืฉืชืžืฉื™ื ืคืจื˜ื™ื™ื=ื›ืŸ
  • RemoveIPC=ื›ืŸ
  • RestrictAddressFamilies=
  • RestrictNamespaces=ื›ืŸ
  • RestrictRealtime=ื›ืŸ
  • RestrictSUIDSGID=ื›ืŸ
  • SystemCallFilter=
  • SystemCallArchitectures=ืžืงื•ืจื™

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”