Firejail 0.9.72 ืฉื—ืจื•ืจ ื‘ื™ื“ื•ื“ ื™ื™ืฉื•ืžื™ื

ืคื•ืจืกื ืฉื—ืจื•ืจื• ืฉืœ ืคืจื•ื™ืงื˜ Firejail 0.9.72, ื”ืžืคืชื— ืžืขืจื›ืช ืœื‘ื™ืฆื•ืข ืžื‘ื•ื“ื“ ืฉืœ ืืคืœื™ืงืฆื™ื•ืช ื’ืจืคื™ื•ืช, ืงื•ื ืกื•ืœื•ืช ื•ืฉืจืชื™ื, ื”ืžืืคืฉืจืช ืœืžื–ืขืจ ืืช ื”ืกื™ื›ื•ืŸ ืฉืœ ืคื’ื™ืขื” ื‘ืžืขืจื›ืช ื”ืจืืฉื™ืช ื‘ืขืช ื”ืคืขืœืช ืชื•ื›ื ื™ื•ืช ืœื ืžื”ื™ืžื ื•ืช ืื• ืฉืขืœื•ืœื•ืช ืœื”ื™ื•ืช ืคื’ื™ืขื•ืช. ื”ืชื•ื›ื ื™ืช ื›ืชื•ื‘ื” ื‘-C, ืžื•ืคืฆืช ืชื—ืช ืจื™ืฉื™ื•ืŸ GPLv2 ื•ื™ื›ื•ืœื” ืœืคืขื•ืœ ื‘ื›ืœ ื”ืคืฆืช ืœื™ื ื•ืงืก ืขื ืœื™ื‘ื” ื™ืฉื ื” ืž-3.0. ื—ื‘ื™ืœื•ืช ืžื•ื›ื ื•ืช ืขื Firejail ืžื•ื›ื ื•ืช ื‘ืคื•ืจืžื˜ื™ื ืฉืœ deb (Debian, Ubuntu) ื•-rpm (CentOS, Fedora).

ืœืฆื•ืจืš ื‘ื™ื“ื•ื“, Firejail ืžืฉืชืžืฉ ื‘ืžืจื—ื‘ื™ ืฉืžื•ืช (ืžืจื—ื‘ื™ ืฉืžื•ืช), AppArmor ื•ืกื™ื ื•ืŸ ืฉื™ื—ื•ืช ืžืขืจื›ืช (seccomp-bpf) ื‘ืœื™ื ื•ืงืก. ืœืื—ืจ ื”ื”ืคืขืœื”, ื”ืชื•ื›ื ื™ืช ื•ื›ืœ ืชื”ืœื™ื›ื™ ื”ืฆืืฆื ืฉืœื” ืžืฉืชืžืฉื™ื ื‘ื™ื™ืฆื•ื’ื™ื ื ืคืจื“ื™ื ืฉืœ ืžืฉืื‘ื™ ื”ืœื™ื‘ื” ื›ื’ื•ืŸ ืžื—ืกื ื™ืช ื”ืจืฉืช, ื˜ื‘ืœืช ื”ืชื”ืœื™ืš ื•ื ืงื•ื“ื•ืช ื”ื˜ืขื™ื ื”. ื ื™ืชืŸ ืœืฉืœื‘ ื™ื™ืฉื•ืžื™ื ื”ืชืœื•ื™ื™ื ื–ื” ื‘ื–ื” ืœืืจื’ื– ื—ื•ืœ ืžืฉื•ืชืฃ ืื—ื“. ืื ืชืจืฆื”, ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘-Firejail ื’ื ืœื”ืคืขืœืช ืžื›ื•ืœื•ืช Docker, LXC ื•-OpenVZ.

ื‘ืฉื•ื ื” ืžื›ืœื™ ื‘ื™ื“ื•ื“ ืงื•ื ื˜ื™ื™ื ืจื™ื, Firejail ื”ื•ื ืคืฉื•ื˜ ื‘ื™ื•ืชืจ ืœื”ื’ื“ืจื” ื•ืื™ื ื• ืžืฆืจื™ืš ื”ื›ื ืช ืชืžื•ื ืช ืžืขืจื›ืช โ€“ ื”ืจื›ื‘ ื”ืงื•ื ื˜ื™ื™ื ืจ ื ื•ืฆืจ ืชื•ืš ื›ื“ื™ ืชื ื•ืขื” ืขืœ ื‘ืกื™ืก ื”ืชื•ื›ืŸ ืฉืœ ืžืขืจื›ืช ื”ืงื‘ืฆื™ื ื”ื ื•ื›ื—ื™ืช ื•ื ืžื—ืง ืœืื—ืจ ืกื™ื•ื ื”ืืคืœื™ืงืฆื™ื”. ื›ืœื™ื ื’ืžื™ืฉื™ื ืžืกื•ืคืงื™ื ืœื”ื’ื“ืจืช ื›ืœืœื™ ื’ื™ืฉื” ืœืžืขืจื›ืช ืงื‘ืฆื™ื, ืืชื” ื™ื›ื•ืœ ืœืงื‘ื•ืข ืื™ืœื• ืงื‘ืฆื™ื ื•ืกืคืจื™ื•ืช ืžื•ืชืจื™ื ืื• ืžื•ื ืขื™ื ื’ื™ืฉื”, ืœื—ื‘ืจ ืžืขืจื›ื•ืช ืงื‘ืฆื™ื ื–ืžื ื™ื•ืช (tmpfs) ืœื ืชื•ื ื™ื, ืœื”ื’ื‘ื™ืœ ื’ื™ืฉื” ืœืงื‘ืฆื™ื ืื• ืกืคืจื™ื•ืช ืœืงืจื™ืื” ื‘ืœื‘ื“, ืœืฉืœื‘ ืกืคืจื™ื•ืช ื‘ืืžืฆืขื•ืช bind-mount ื•ืฉื›ื‘ื•ืช-ืขืœ.

ืœืžืกืคืจ ืจื‘ ืฉืœ ื™ื™ืฉื•ืžื™ื ืคื•ืคื•ืœืจื™ื™ื, ื›ื•ืœืœ Firefox, Chromium, VLC ื•-Transmission, ื™ืฉ ืคืจื•ืคื™ืœื™ ื‘ื™ื“ื•ื“ ืฉื™ื—ื•ืช ืžืขืจื›ืช ืžื•ื’ื“ืจื™ื ืžืจืืฉ. ื›ื“ื™ ืœืงื‘ืœ ืืช ื”ื”ืจืฉืื•ืช ื”ื ื“ืจืฉื•ืช ืœื”ื’ื“ืจืช ืกื‘ื™ื‘ืช ืืจื’ื– ื—ื•ืœ, ืงื•ื‘ืฅ ื”ื”ืคืขืœื” ืฉืœ firejail ืžื•ืชืงืŸ ืขื ื“ื’ืœ ื”ืฉื•ืจืฉ SUID (ื”ื”ืจืฉืื•ืช ืžืชืืคืกื•ืช ืœืื—ืจ ื”ืืชื—ื•ืœ). ื›ื“ื™ ืœื”ืคืขื™ืœ ืชื•ื›ื ื™ืช ื‘ืžืฆื‘ ื‘ื™ื“ื•ื“, ืžืกืคื™ืง ืœืฆื™ื™ืŸ ืืช ืฉื ื”ื™ื™ืฉื•ื ื›ืืจื’ื•ืžื ื˜ ืœื›ืœื™ ื”ืฉื™ืจื•ืช ืฉืœ firejail, ืœืžืฉืœ, "firejail firefox" ืื• "sudo firejail /etc/init.d/nginx start".

ื‘ืžื”ื“ื•ืจื” ื”ื—ื“ืฉื”:

  • ื ื•ืกืฃ ืžืกื ืŸ ืงืจื™ืื•ืช ืžืขืจื›ืช seccomp ื›ื“ื™ ืœื—ืกื•ื ื™ืฆื™ืจืช ืžืจื—ื‘ ืฉืžื•ืช (ื ื•ืกืคื” ืืคืฉืจื•ืช "--restrict-namespaces" ื›ื“ื™ ืœื”ืคืขื™ืœ). ื˜ื‘ืœืื•ืช ืงืจื™ืื•ืช ืžืขืจื›ืช ื•ืงื‘ื•ืฆื•ืช seccomp ืžืขื•ื“ื›ื ื•ืช.
  • ืžืฉื•ืคืจ ืžืฆื‘ force-nonewprivs (NO_NEW_PRIVS) ื›ื“ื™ ืœืžื ื•ืข ืžืชื”ืœื™ื›ื™ื ื—ื“ืฉื™ื ืœืงื‘ืœ ื”ืจืฉืื•ืช ื ื•ืกืคื•ืช.
  • ื ื•ืกืคื” ืืช ื”ื™ื›ื•ืœืช ืœื”ืฉืชืžืฉ ื‘ืคืจื•ืคื™ืœื™ AppArmor ืžืฉืœืš (ืืคืฉืจื•ืช "--apparmor" ืžื•ืฆืขืช ืœื—ื™ื‘ื•ืจ).
  • ืžืขืจื›ืช ืžืขืงื‘ ื”ืชืขื‘ื•ืจื” ื‘ืจืฉืช nettrace, ื”ืžืฆื™ื’ื” ืžื™ื“ืข ืขืœ IP ื•ืขื•ืฆืžืช ื”ืชืขื‘ื•ืจื” ืžื›ืœ ื›ืชื•ื‘ืช, ืชื•ืžื›ืช ื‘-ICMP ื•ืžืฆื™ืขื” ืืคืฉืจื•ื™ื•ืช "-dnstrace", "--icmptrace" ื•-"--snitrace".
  • ื”ื•ืกืจื• ื”ืคืงื•ื“ื•ืช --cgroup ื•- --shell (ื‘ืจื™ืจืช ื”ืžื—ื“ืœ ื”ื™ื --shell=none). ื‘ื ื™ื™ืช Firetunnel ื ืขืฆืจืช ื›ื‘ืจื™ืจืช ืžื—ื“ืœ. ื”ืฉื‘ืชืช ื”ื’ื“ืจื•ืช chroot, private-lib ื•-tracelog ื‘-/etc/firejail/firejail.config. ื”ื•ืกืจื” ื”ืชืžื™ื›ื” ื‘-grsecurity.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”