Firejail 0.9.60 ืฉื—ืจื•ืจ ื‘ื™ื“ื•ื“ ื™ื™ืฉื•ืžื™ื

ืจืื” ืืช ื”ืื•ืจ ืฉื—ืจื•ืจ ื”ืคืจื•ื™ืงื˜ Firejail 0.9.60, ืฉื‘ืชื•ื›ื” ืžืคืชื—ื™ื ืžืขืจื›ืช ืœื‘ื™ืฆื•ืข ืžื‘ื•ื“ื“ ืฉืœ ื™ื™ืฉื•ืžื™ ื’ืจืคื™ืงื”, ืงื•ื ืกื•ืœื” ื•ืฉืจืช. ื”ืฉื™ืžื•ืฉ ื‘-Firejail ืžืืคืฉืจ ืœืš ืœืžื–ืขืจ ืืช ื”ืกื™ื›ื•ืŸ ืœืคื’ื™ืขื” ื‘ืžืขืจื›ืช ื”ืจืืฉื™ืช ื‘ืขืช ื”ืคืขืœืช ืชื•ื›ื ื™ื•ืช ืœื ืืžื™ื ื•ืช ืื• ืคื’ื™ืขื•ืช. ื”ืชื•ื›ื ื™ืช ื›ืชื•ื‘ื” ื‘ืฉืคืช C, ืžื•ืคืฅ ืขืœ ื™ื“ื™ ืžื•ืจืฉื” ืชื—ืช GPLv2 ื•ื™ื›ื•ืœื” ืœืคืขื•ืœ ื‘ื›ืœ ื”ืคืฆืช ืœื™ื ื•ืงืก ืขื ืœื™ื‘ื” ื™ืฉื ื” ืž-3.0. ื—ื‘ื™ืœื•ืช ืžื•ื›ื ื•ืช ืขื Firejail ืžื•ึผื›ึธืŸ ื‘ืคื•ืจืžื˜ื™ื ืฉืœ deb (Debian, Ubuntu) ื•-rpm (CentOS, Fedora).

ืœื‘ื™ื“ื•ื“ ื‘-Firejail ืžืฉืžืฉื™ื ืžืจื—ื‘ื™ ืฉืžื•ืช, AppArmor ื•ืกื™ื ื•ืŸ ืฉื™ื—ื•ืช ืžืขืจื›ืช (seccomp-bpf) ื‘ืœื™ื ื•ืงืก. ืœืื—ืจ ื”ื”ืฉืงื”, ื”ืชื•ื›ื ื™ืช ื•ื›ืœ ืชื”ืœื™ื›ื™ ื”ืฆืืฆื ืฉืœื” ืžืฉืชืžืฉื™ื ื‘ืชืฆื•ื’ื•ืช ื ืคืจื“ื•ืช ืฉืœ ืžืฉืื‘ื™ ื”ืœื™ื‘ื”, ื›ื’ื•ืŸ ืžื—ืกื ื™ืช ื”ืจืฉืช, ื˜ื‘ืœืช ื”ืชื”ืœื™ืš ื•ื ืงื•ื“ื•ืช ื”ื˜ืขื™ื ื”. ื ื™ืชืŸ ืœืฉืœื‘ ื™ื™ืฉื•ืžื™ื ื”ืชืœื•ื™ื™ื ื–ื” ื‘ื–ื” ืœืืจื’ื– ื—ื•ืœ ืžืฉื•ืชืฃ ืื—ื“. ืื ืชืจืฆื”, ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘-Firejail ื’ื ืœื”ืคืขืœืช ืžื›ื•ืœื•ืช Docker, LXC ื•-OpenVZ.

ื‘ื ื™ื’ื•ื“ ืœื›ืœื™ ื‘ื™ื“ื•ื“ ืžื™ื›ืœื™ื, Firejail ื”ื•ื ืžืื•ื“ ืคืฉื•ื˜ ื‘ืชืฆื•ืจื” ื•ืื™ื ื• ืžืฆืจื™ืš ื”ื›ื ืช ืชืžื•ื ืช ืžืขืจื›ืช - ื”ืจื›ื‘ ื”ืงื•ื ื˜ื™ื™ื ืจ ื ื•ืฆืจ ืขืœ ื‘ืกื™ืก ื”ืชื•ื›ืŸ ืฉืœ ืžืขืจื›ืช ื”ืงื‘ืฆื™ื ื”ื ื•ื›ื—ื™ืช ื•ื ืžื—ืง ืœืื—ืจ ื”ืฉืœืžืช ื”ืืคืœื™ืงืฆื™ื”. ืžืกื•ืคืงื™ื ืืžืฆืขื™ื ื’ืžื™ืฉื™ื ืœื”ื’ื“ืจืช ื›ืœืœื™ ื’ื™ืฉื” ืœืžืขืจื›ืช ื”ืงื‘ืฆื™ื; ื ื™ืชืŸ ืœืงื‘ื•ืข ืื™ืœื• ืงื‘ืฆื™ื ื•ืกืคืจื™ื•ืช ืžื•ืชืจื™ื ืื• ืžื•ื ืขื™ื ื’ื™ืฉื”, ืœื—ื‘ืจ ืžืขืจื›ื•ืช ืงื‘ืฆื™ื ื–ืžื ื™ื•ืช (tmpfs) ืœื ืชื•ื ื™ื, ืœื”ื’ื‘ื™ืœ ืืช ื”ื’ื™ืฉื” ืœืงื‘ืฆื™ื ืื• ืกืคืจื™ื•ืช ืœืงืจื™ืื” ื‘ืœื‘ื“, ืœืฉืœื‘ ืกืคืจื™ื•ืช ื‘ืืžืฆืขื•ืช ื—ื™ื‘ื•ืจ ืœื—ื™ื‘ื•ืจ ื•ืฉื›ื‘ื•ืช-ืขืœ.

ืขื‘ื•ืจ ืžืกืคืจ ืจื‘ ืฉืœ ื™ื™ืฉื•ืžื™ื ืคื•ืคื•ืœืจื™ื™ื, ื›ื•ืœืœ Firefox, Chromium, VLC ื•-Transmission, ืžื•ื›ื ื™ื ืคืจื•ืคื™ืœื™ื ื‘ื™ื“ื•ื“ ืฉื™ื—ื•ืช ืžืขืจื›ืช. ื›ื“ื™ ืœื”ืคืขื™ืœ ืชื•ื›ื ื™ืช ื‘ืžืฆื‘ ื‘ื™ื“ื•ื“, ืคืฉื•ื˜ ืฆื™ื™ืŸ ืืช ืฉื ื”ื™ื™ืฉื•ื ื›ืืจื’ื•ืžื ื˜ ืœืชื•ื›ื ื™ืช ื”ืฉื™ืจื•ืช ืฉืœ Firejail, ืœื“ื•ื’ืžื”, "firejail firefox" ืื• "sudo firejail /etc/init.d/nginx start".

ื‘ืžื”ื“ื•ืจื” ื”ื—ื“ืฉื”:

  • ืชื•ืงื ื” ืคื’ื™ืขื•ืช ื”ืžืืคืฉืจืช ืœืชื”ืœื™ืš ื–ื“ื•ื ื™ ืœืขืงื•ืฃ ืืช ืžื ื’ื ื•ืŸ ื”ื’ื‘ืœืช ืฉื™ื—ื•ืช ื”ืžืขืจื›ืช. ื”ืžื”ื•ืช ืฉืœ ื”ืคื’ื™ืขื•ืช ื”ื™ื ืฉืžืกื ื ื™ Seccomp ืžื•ืขืชืงื™ื ืœืกืคืจื™ื™ืช /run/firejail/mnt, ื”ื ื™ืชื ืช ืœื›ืชื™ื‘ื” ื‘ืชื•ืš ื”ืกื‘ื™ื‘ื” ื”ืžื‘ื•ื“ื“ืช. ืชื”ืœื™ื›ื™ื ื–ื“ื•ื ื™ื™ื ื”ืคื•ืขืœื™ื ื‘ืžืฆื‘ ื‘ื™ื“ื•ื“ ื™ื›ื•ืœื™ื ืœืฉื ื•ืช ืงื‘ืฆื™ื ืืœื•, ืžื” ืฉื™ื’ืจื•ื ืœืชื”ืœื™ื›ื™ื ื—ื“ืฉื™ื ื”ืคื•ืขืœื™ื ื‘ืื•ืชื” ืกื‘ื™ื‘ื” ืœื”ืชื‘ืฆืข ืœืœื ื”ื—ืœืช ืžืกื ืŸ ืงืจื™ืื•ืช ื”ืžืขืจื›ืช;
  • ืžืกื ืŸ memory-deny-write-execute ืžื‘ื˜ื™ื— ืฉื”ืงืจื™ืื” "memfd_create" ื—ืกื•ืžื”;
  • ื ื•ืกืคื” ืืคืฉืจื•ืช ื—ื“ืฉื” "private-cwd" ื›ื“ื™ ืœืฉื ื•ืช ืืช ืกืคืจื™ื™ืช ื”ืขื‘ื•ื“ื” ืœื›ืœื;
  • ื ื•ืกืคื” ืืคืฉืจื•ืช "--nodbus" ืœื—ืกื™ืžืช ืฉืงืขื™ D-Bus;
  • ื”ื—ื–ื™ืจื” ืชืžื™ื›ื” ืขื‘ื•ืจ CentOS 6;
  • ื”ื•ืคืกืง ืชืžื™ื›ื” ื‘ื—ื‘ื™ืœื•ืช ื‘ืคื•ืจืžื˜ื™ื Flatpak ะธ ืœืฆืœื.
    ืžืกื•ืžืŸืฉื”ื—ื‘ื™ืœื•ืช ื”ืœืœื• ืฆืจื™ื›ื•ืช ืœื”ืฉืชืžืฉ ื‘ื›ืœื™ ืขื‘ื•ื“ื” ืžืฉืœื”ืŸ;

  • ืคืจื•ืคื™ืœื™ื ื—ื“ืฉื™ื ื ื•ืกืคื• ื›ื“ื™ ืœื‘ื•ื“ื“ 87 ืชื•ื›ื ื™ื•ืช ื ื•ืกืคื•ืช, ื›ื•ืœืœ mypaint, nano, xfce4-mixer, gnome-keyring, redshift, font-manager, gconf-editor, gsettings, freeciv, lincity-ng, openttd, torcs, tremulous, warsow, freemind, kid3, freecol, opencity, utox, freeoffice-planmaker, freeoffice-presentations, freeoffice-textmaker, inkview, meteo-qt, ktouch, yelp ื•ืงื ื˜ื˜ื”.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”