ืืืืืืจื ืฉื Fedora 40 ืืฆืืขื ืืคืขืืช ืืืืจืืช ืืืืื ืขืืืจ ืฉืืจืืชื ืืขืจืืช ืืขืจืืช ืืืืคืขืืื ืืืจืืจืช ืืืื, ืืื ืื ืฉืืจืืชืื ืขื ืืืฉืืืื ืงืจืืืืื ืืืฉืืื ืืืื PostgreSQL, Apache httpd, Nginx ื-MariaDB. ืฆืคืื ืฉืืฉืื ืื ืืืืืจ ืืฉืืขืืชืืช ืืช ืืืืืช ืืืคืฆื ืืชืฆืืจืช ืืจืืจืช ืืืืื ืืืืคืฉืจ ืืกืืืช ื ืงืืืืช ืชืืจืคื ืื ืืืืขืืช ืืฉืืจืืชื ืืืขืจืืช. ืืืฆืขื ืืจื ื ืืื ื ืขื ืืื ืืขืืช ืืืืื ืฉื FESCo (Fedora Engineering Steering Committee), ืฉืืืจืืืช ืขื ืืืืง ืืืื ื ืฉื ืคืืชืื ืืคืฆืช ืคืืืจื. ืืฆืขื ืขืฉืืื ืืืืืืืช ืื ืืืืื ืชืืืื ืืืืงืืจืช ืืงืืืื.
ืืืืจืืช ืืืืืฆืืช ืืืคืขืืช:
- PrivateTmp=yes - ืืชื ืกืคืจืืืช ื ืคืจืืืช ืขื ืงืืฆืื ืืื ืืื.
- ProtectSystem=yes/full/strict โ ืืขื ืืช ืืขืจืืช ืืงืืฆืื ืืืฆื ืงืจืืื ืืืื (ืืืฆื "ืืื" - /etc/, ืืืฆื strict - ืื ืืขืจืืืช ืืงืืฆืื ืืืื /dev/, /proc/ ื-/sys/).
- ProtectHome=ืื - ืืื ืข ืืืฉื ืืกืคืจืืืช ืืืืช ืฉื ืืืฉืชืืฉ.
- PrivateDevices=yes - ืืฉืืจืช ืืืฉื ืจืง ื-/dev/null, /dev/zero ื-/dev/random
- ProtectKernelTunables=yes - ืืืฉื ืืงืจืืื ืืืื ืื /proc/sys/, /sys/, /proc/acpi, /proc/fs, /proc/irq ืืื'.
- ProtectKernelModules=ืื - ืืกืืจ ืืืขืื ืืืืืื ืืืื.
- ProtectKernelLogs=ืื - ืืืกืจ ืขื ืืืฉื ืืืืืจ ืขื ืืืื ื ืืืื.
- ProtectControlGroups=ืื - ืืืฉืช ืงืจืืื ืืืื ืื /sys/fs/cgroup/
- NoNewPrivileges=ืื - ืืืกืืจ ืขื ืืขืืืช ืืจืฉืืืช ืืืืฆืขืืช ืืืื setuid, setgid ื-capabilities.
- PrivateNetwork=yes - ืืืงืื ืืืจืื ืฉืืืช ื ืคืจื ืฉื ืืืกื ืืช ืืจืฉืช.
- ProtectClock=ืื - ืืกืืจ ืืฉื ืืช ืืช ืืฉืขื.
- ProtectHostname=yes - ืืืกืจ ืขื ืฉืื ืื ืฉื ืืืืจื.
- ProtectProc=invisible - ืืกืชืจืช ืชืืืืืื ืฉื ืื ืฉืื ืืืจืื ื-/proc.
- User= - ืฉื ื ืืฉืชืืฉ
ืื ืืกืฃ, ืชืืื ืืฉืงืื ืืืคืขืื ืืช ืืืืืจืืช ืืืืืช:
- CapabilityBoundingSet=
- DevicePolicy=ืกืืืจ
- KeyringMode=ืคืจืื
- LockPersonality=ืื
- MemoryDenyWriteExecute=ืื
- ืืฉืชืืฉืื ืคืจืืืื=ืื
- RemoveIPC=ืื
- RestrictAddressFamilies=
- RestrictNamespaces=ืื
- RestrictRealtime=ืื
- RestrictSUIDSGID=ืื
- SystemCallFilter=
- SystemCallArchitectures=ืืงืืจื
ืืงืืจ: OpenNet.ru