ืžื‘ื ื” ื—ื“ืฉ ืฉืœ Slackware ื”ื•ื›ืŸ ื›ื—ืœืง ืžืคืจื•ื™ืงื˜ TinyWare

ื”ื•ื›ื ื• ืžื›ืœื•ืœื™ ื”ืคืจื•ื™ืงื˜ TinyWare, ืžื‘ื•ืกืก ืขืœ ื’ืจืกืช 32 ืกื™ื‘ื™ื•ืช ืฉืœ Slackware-Current ื•ื ืฉืœื— ืขื ื’ืจืกืื•ืช 32 ื•-64 ืกื™ื‘ื™ื•ืช ืฉืœ ืœื™ื‘ืช ืœื™ื ื•ืงืก 4.19. ื’ื•ื“ืœ ืชืžื•ื ืช iso 800 ืžื’ื”-ื‘ื™ื™ื˜.

ื”ืขื™ืงืจื™ ืฉื™ื ื•ื™ื™ื, ื‘ื”ืฉื•ื•ืื” ืœ-Slackware ื”ืžืงื•ืจื™:

  • ื”ืชืงื ื” ืขืœ 4 ืžื—ื™ืฆื•ืช "/", "/boot", "/var" ื•-"/home". ื”ืžื—ื™ืฆื•ืช "/" ื•-"/boot" ื ื˜ืขื ื•ืช ื‘ืžืฆื‘ ืงืจื™ืื” ื‘ืœื‘ื“, ื•-"/home" ื•-"/var" ื ื˜ืขื ื•ืช ื‘ืžืฆื‘ noexec;
  • ืชื™ืงื•ืŸ ืœื™ื‘ื” CONFIG_SETCAP. ืžื•ื“ื•ืœ setcap ื™ื›ื•ืœ ืœื”ืฉื‘ื™ืช ืืช ื™ื›ื•ืœื•ืช ื”ืžืขืจื›ืช ืฉืฆื•ื™ื ื• ืื• ืœืืคืฉืจ ืื•ืชืŸ ืขื‘ื•ืจ ื›ืœ ื”ืžืฉืชืžืฉื™ื. ื”ืžื•ื“ื•ืœ ืžื•ื’ื“ืจ ืขืœ ื™ื“ื™ ืžืฉืชืžืฉ ื”ืขืœ ื‘ื–ืžืŸ ืฉื”ืžืขืจื›ืช ืคื•ืขืœืช ื“ืจืš ืžืžืฉืง sysctl ืื• ืงื‘ืฆื™ /proc/sys/setcap ื•ื ื™ืชืŸ ืœื”ืงืคื™ื ืื•ืชื• ืžื‘ื™ืฆื•ืข ืฉื™ื ื•ื™ื™ื ื•ืขื“ ืœืืชื—ื•ืœ ื”ื‘ื.
    ื‘ืžืฆื‘ ืจื’ื™ืœ, CAP_CHOWN(0), CAP_DAC_OVERRIDE(1), CAP_DAC_READ_SEARCH(2), CAP_FOWNER(3) ื•-21(CAP_SYS_ADMIN) ืžื•ืฉื‘ืชื™ื ื‘ืžืขืจื›ืช. ื”ืžืขืจื›ืช ืžื•ื—ื–ืจืช ืœืžืฆื‘ื” ื”ืจื’ื™ืœ ื‘ืืžืฆืขื•ืช ืคืงื•ื“ืช tinyware-beforadmin (ื”ืจื›ื‘ื” ื•ื™ื›ื•ืœื•ืช). ื‘ื”ืชื‘ืกืก ืขืœ ื”ืžื•ื“ื•ืœ, ืืชื” ื™ื›ื•ืœ ืœืคืชื— ืืช ื”ืจืชืžื” ืฉืœ ืจืžื•ืช ืžืื•ื‘ื˜ื—ื•ืช.

  • ืชื™ืงื•ืŸ ืœื™ื‘ื” PROC_RESTRICT_ACCESS. ืืคืฉืจื•ืช ื–ื• ืžื’ื‘ื™ืœื” ืืช ื”ื’ื™ืฉื” ืœืกืคืจื™ื•ืช /proc/pid ื‘ืžืขืจื›ืช ื”ืงื‘ืฆื™ื /proc ืž-555 ืœ-750, ื‘ืขื•ื“ ืฉื”ืงื‘ื•ืฆื” ืฉืœ ื›ืœ ื”ืกืคืจื™ื•ืช ืžื•ืงืฆื™ืช ืœ-root. ืœื›ืŸ, ืžืฉืชืžืฉื™ื ืจื•ืื™ื ืจืง ืืช ื”ืชื”ืœื™ื›ื™ื ืฉืœื”ื ืขื ื”ืคืงื•ื“ื” "ps". Root ืขื“ื™ื™ืŸ ืจื•ืื” ืืช ื›ืœ ื”ืชื”ืœื™ื›ื™ื ื‘ืžืขืจื›ืช.
  • CONFIG_FS_ADVANCED_CHOWN ืชื™ืงื•ืŸ ืœื™ื‘ื” ื›ื“ื™ ืœืืคืฉืจ ืœืžืฉืชืžืฉื™ื ืจื’ื™ืœื™ื ืœืฉื ื•ืช ื‘ืขืœื•ืช ืขืœ ืงื‘ืฆื™ื ื•ืกืคืจื™ื•ืช ืžืฉื ื” ื‘ืชื•ืš ื”ืกืคืจื™ื•ืช ืฉืœื”ื.
  • ื›ืžื” ืฉื™ื ื•ื™ื™ื ื‘ื”ื’ื“ืจื•ืช ื‘ืจื™ืจืช ื”ืžื—ื“ืœ (ืœืžืฉืœ UMASK ืžื•ื’ื“ืจ ืœ-077).

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”