αž‚αŸ†αžšαžΌαž…αŸ‚αž€αž…αžΆαž™αžŸαž·αž‘αŸ’αž’αž·αž‡αžΆαž€αžΆαžαž–αŸ’αžœαž€αž·αž…αŸ’αž…αž“αŸ…αž€αŸ’αž“αž»αž„ FreeBSD

αžŸαŸαž…αž€αŸ’αžαžΈαžŽαŸ‚αž“αžΆαŸ†

αžŠαžΎαž˜αŸ’αž”αžΈαž•αŸ’αžαž›αŸ‹αž€αž˜αŸ’αžšαž·αžαž”αž“αŸ’αžαŸ‚αž˜αž“αŸƒαžŸαž»αžœαžαŸ’αžαž·αž—αžΆαž–αž˜αŸ‰αžΆαžŸαŸŠαžΈαž“αž˜αŸ αž’αŸ’αž“αž€αž’αžΆαž…αž”αŸ’αžšαžΎ αž‚αŸ†αžšαžΌαž’αžΆαžŽαžαŸ’αžαž· αž…αžΌαž›αžŠαŸ†αžŽαžΎαžšαž€αžΆαžšαž…αŸ‚αž€αž…αžΆαž™αŸ” αž€αžΆαžšαž”αŸ„αŸ‡αž–αž»αž˜αŸ’αž—αž•αŸ’αžŸαžΆαž™αž“αŸαŸ‡αž“αžΉαž„αžšαŸ€αž”αžšαžΆαž”αŸ‹αž–αžΈαžšαž”αŸ€αž”αžŠαŸ‚αž›αž’αŸ’αž“αž€αž’αžΆαž…αžŠαŸ†αžŽαžΎαžšαž€αžΆαžš apache αž“αŸ…αž€αŸ’αž“αž»αž„αž‚αž»αž€αžŠαŸ„αž™αž…αžΌαž›αž”αŸ’αžšαžΎαžαŸ‚αžŸαž˜αžΆαžŸαž’αžΆαžαž»αž‘αžΆαŸ†αž„αž“αŸ„αŸ‡αžŠαŸ‚αž›αžαŸ’αžšαžΌαžœαž€αžΆαžšαž€αžΆαžšαž…αžΌαž›αž”αŸ’αžšαžΎαžŸαž˜αŸ’αžšαžΆαž”αŸ‹αž”αŸ’αžšαžαž·αž”αžαŸ’αžαž·αž€αžΆαžšαžαŸ’αžšαžΉαž˜αžαŸ’αžšαžΌαžœαž“αŸƒ apache αž“αž·αž„ php αŸ” αžŠαŸ„αž™αž”αŸ’αžšαžΎαž‚αŸ„αž›αž€αžΆαžšαžŽαŸαž“αŸαŸ‡ αž’αŸ’αž“αž€αž’αžΆαž…αž€αŸ†αžŽαžαŸ‹αž˜αž·αž“αžαŸ’αžšαžΉαž˜αžαŸ‚ Apache αž”αŸ‰αž»αžŽαŸ’αžŽαŸ„αŸ‡αž‘αŸ αž”αŸ‰αž»αž“αŸ’αžαŸ‚αž€αŸαž˜αžΆαž“αž‡αž„αŸ‹αž•αŸ’αžŸαŸαž„αž‘αŸ€αžαž•αž„αžŠαŸ‚αžšαŸ”

αž€αžΆαžšαžšαŸ€αž”αž…αŸ†

αžœαž·αž’αžΈαžŸαžΆαžŸαŸ’αžšαŸ’αžαž“αŸαŸ‡αž‚αžΊαžŸαž˜αžšαž˜αŸ’αž™αžŸαž˜αŸ’αžšαžΆαž”αŸ‹αžαŸ‚αž”αŸ’αžšαž–αŸαž“αŸ’αž’αž―αž€αžŸαžΆαžš ufs αž€αŸ’αž“αž»αž„αž§αž‘αžΆαž αžšαžŽαŸαž“αŸαŸ‡ zfs αž“αžΉαž„αžαŸ’αžšαžΌαžœαž”αžΆαž“αž”αŸ’αžšαžΎαž“αŸ…αž€αŸ’αž“αž»αž„αž”αŸ’αžšαž–αŸαž“αŸ’αž’αž˜αŸ αž“αž·αž„ ufs αž“αŸ…αž€αŸ’αž“αž»αž„αž‚αž»αž€αžšαŸ€αž„αŸ—αžαŸ’αž›αž½αž“αŸ” αž‡αŸ†αž αžΆαž“αžŠαŸ†αž”αžΌαž„αž‚αžΊαžαŸ’αžšαžΌαžœαž”αž„αŸ’αž€αžΎαžαžαžΊαžŽαŸ‚αž›αž‘αžΎαž„αžœαž·αž‰ αž“αŸ…αž–αŸαž›αžŠαŸ†αž‘αžΎαž„ FreeBSD αžŠαŸ†αž‘αžΎαž„αž€αžΌαžŠαž”αŸ’αžšαž—αž–αŸ”
αž”αž“αŸ’αž‘αžΆαž”αŸ‹αž–αžΈαžŠαŸ†αž‘αžΎαž„αž”αŸ’αžšαž–αŸαž“αŸ’αž’αžšαž½αž… αž€αŸ‚αžŸαž˜αŸ’αžšαž½αž›αž―αž€αžŸαžΆαžšαŸ–

/usr/src/sys/amd64/conf/GENERIC

αž’αŸ’αž“αž€β€‹αžαŸ’αžšαžΌαžœβ€‹αžαŸ‚β€‹αž”αž“αŸ’αžαŸ‚αž˜β€‹αž˜αž½αž™β€‹αž”αž“αŸ’αž‘αžΆαžαŸ‹β€‹αž‘αŸ…β€‹αž―αž€αžŸαžΆαžšβ€‹αž“αŸαŸ‡αŸ–

options     MAC_MLS

αžŸαŸ’αž›αžΆαž€ mls/high αž“αžΉαž„αž˜αžΆαž“αž‘αžΈαžαžΆαŸ†αž„αž›αŸαž…αž’αŸ’αž›αŸ„αž‡αžΆαž„αžŸαŸ’αž›αžΆαž€ mls/low αž€αž˜αŸ’αž˜αžœαž·αž’αžΈαžŠαŸ‚αž›αž“αžΉαž„αžαŸ’αžšαžΌαžœαž”αžΆαž“αžŠαžΆαž€αŸ‹αž±αŸ’αž™αžŠαŸ†αžŽαžΎαžšαž€αžΆαžšαž‡αžΆαž˜αž½αž™αžŸαŸ’αž›αžΆαž€ mls/low αž“αžΉαž„αž˜αž·αž“αž’αžΆαž…αž…αžΌαž›αž”αŸ’αžšαžΎαž―αž€αžŸαžΆαžšαžŠαŸ‚αž›αž˜αžΆαž“αžŸαŸ’αž›αžΆαž€ mls/high αž”αžΆαž“αž‘αŸαŸ” αž–αŸαžαŸŒαž˜αžΆαž“αž›αž˜αŸ’αž’αž·αžαž”αž“αŸ’αžαŸ‚αž˜αž’αŸ†αž–αžΈαžŸαŸ’αž›αžΆαž€αžŠαŸ‚αž›αž˜αžΆαž“αž“αŸ…αž€αŸ’αž“αž»αž„αž”αŸ’αžšαž–αŸαž“αŸ’αž’ FreeBSD αž’αžΆαž…αžšαž€αž”αžΆαž“αž“αŸ…αž€αŸ’αž“αž»αž„αž“αŸαŸ‡αŸ” αž—αžΆαž–αž‡αžΆαž’αŸ’αž“αž€αžŠαžΉαž€αž“αžΆαŸ†.
αž”αž“αŸ’αž‘αžΆαž”αŸ‹αž˜αž€αž…αžΌαž›αž‘αŸ…αž€αžΆαž“αŸ‹αžαž /usr/srcαŸ–

cd /usr/src

αžŠαžΎαž˜αŸ’αž”αžΈαž…αžΆαž”αŸ‹αž•αŸ’αžαžΎαž˜αž”αž„αŸ’αž€αžΎαžαžαžΊαžŽαŸ‚αž› αžŸαžΌαž˜αžŠαŸ†αžŽαžΎαžšαž€αžΆαžš (αž€αŸ’αž“αž»αž„αž‚αŸ’αžšαžΆαž”αŸ‹αž…αž»αž… j αž”αž‰αŸ’αž‡αžΆαž€αŸ‹αž…αŸ†αž“αž½αž“αžŸαŸ’αž“αžΌαž›αž“αŸ…αž€αŸ’αž“αž»αž„αž”αŸ’αžšαž–αŸαž“αŸ’αž’)αŸ–

make -j 4 buildkernel KERNCONF=GENERIC

αž”αž“αŸ’αž‘αžΆαž”αŸ‹αž–αžΈαžαžΊαžŽαŸ‚αž›αžαŸ’αžšαžΌαžœαž”αžΆαž“αž…αž„αž€αŸ’αžšαž„ αžœαžΆαžαŸ’αžšαžΌαžœαžαŸ‚αžŠαŸ†αž‘αžΎαž„αŸ–

make installkernel KERNCONF=GENERIC

αž”αž“αŸ’αž‘αžΆαž”αŸ‹αž–αžΈαžŠαŸ†αž‘αžΎαž„αžαžΊαžŽαŸ‚αž› αžŸαžΌαž˜αž€αž»αŸ†αž”αŸ’αžšαž‰αžΆαž”αŸ‹αž”αŸ’αžšαž‰αžΆαž›αŸ‹αž…αžΆαž”αŸ‹αž•αŸ’αžŠαžΎαž˜αž”αŸ’αžšαž–αŸαž“αŸ’αž’αž‘αžΎαž„αžœαž·αž‰ αž–αŸ’αžšαŸ„αŸ‡αž…αžΆαŸ†αž”αžΆαž…αŸ‹αžαŸ’αžšαžΌαžœαž•αŸ’αž‘αŸαžšαž’αŸ’αž“αž€αž”αŸ’αžšαžΎαž”αŸ’αžšαžΆαžŸαŸ‹αž‘αŸ…αžαŸ’αž“αžΆαž€αŸ‹αž…αžΌαž› αžŠαŸ„αž™αž”αžΆαž“αž€αŸ†αžŽαžαŸ‹αžšαž…αž“αžΆαžŸαž˜αŸ’αž–αŸαž“αŸ’αž’αžœαžΆαž–αžΈαž˜αž»αž“αž˜αž€αŸ” αž€αŸ‚αžŸαž˜αŸ’αžšαž½αž›αž―αž€αžŸαžΆαžš /etc/login.conf αž€αŸ’αž“αž»αž„αž―αž€αžŸαžΆαžšαž“αŸαŸ‡αž’αŸ’αž“αž€αžαŸ’αžšαžΌαžœαž€αŸ‚αžŸαž˜αŸ’αžšαž½αž›αžαŸ’αž“αžΆαž€αŸ‹αž…αžΌαž›αž›αŸ†αž“αžΆαŸ†αžŠαžΎαž˜ αž“αžΆαŸ†αžœαžΆαž‘αŸ…αž‡αžΆαž‘αž˜αŸ’αžšαž„αŸ‹αŸ–

default:
        :passwd_format=sha512:
        :copyright=/etc/COPYRIGHT:
        :welcome=/etc/motd:
        :setenv=MAIL=/var/mail/$,BLOCKSIZE=K:
        :path=/sbin /bin /usr/sbin /usr/bin /usr/local/sbin /usr/local/bin ~/bin:
        :nologin=/var/run/nologin:
        :cputime=unlimited:
        :datasize=unlimited:
        :stacksize=unlimited:
        :memorylocked=64K:
        :memoryuse=unlimited:
        :filesize=unlimited:
        :coredumpsize=unlimited:
        :openfiles=unlimited:
        :maxproc=unlimited:
        :sbsize=unlimited:
        :vmemoryuse=unlimited:
        :swapuse=unlimited:
        :pseudoterminals=unlimited:
        :kqueues=unlimited:
        :umtxp=unlimited:
        :priority=0:
        :ignoretime@:
        :umask=022:
        :label=mls/equal:

αž”αž“αŸ’αž‘αžΆαžαŸ‹ :label=mls/equal αž“αžΉαž„αž’αž“αž»αž‰αŸ’αž‰αžΆαžαž±αŸ’αž™αž’αŸ’αž“αž€αž”αŸ’αžšαžΎαž”αŸ’αžšαžΆαžŸαŸ‹αžŠαŸ‚αž›αž‡αžΆαžŸαž˜αžΆαž‡αž·αž€αž“αŸƒαžαŸ’αž“αžΆαž€αŸ‹αž“αŸαŸ‡αž…αžΌαž›αž”αŸ’αžšαžΎαž―αž€αžŸαžΆαžšαžŠαŸ‚αž›αžαŸ’αžšαžΌαžœαž”αžΆαž“αžŸαž˜αŸ’αž‚αžΆαž›αŸ‹αžŠαŸ„αž™αžŸαŸ’αž›αžΆαž€αžŽαžΆαž˜αž½αž™ (mls/low, mls/high)αŸ” αž”αž“αŸ’αž‘αžΆαž”αŸ‹αž–αžΈαž§αž”αžΆαž™αž€αž›αž‘αžΆαŸ†αž„αž“αŸαŸ‡ αž’αŸ’αž“αž€αžαŸ’αžšαžΌαžœαž”αž„αŸ’αž€αžΎαžαž˜αžΌαž›αžŠαŸ’αž‹αžΆαž“αž‘αž·αž“αŸ’αž“αž“αŸαž™αž‘αžΎαž„αžœαž·αž‰ αž αžΎαž™αžŠαžΆαž€αŸ‹αž’αŸ’αž“αž€αž”αŸ’αžšαžΎαž”αŸ’αžšαžΆαžŸαŸ‹ root (αž€αŸαžŠαžΌαž…αž‡αžΆαž’αŸ’αž“αž€αžŠαŸ‚αž›αžαŸ’αžšαžΌαžœαž€αžΆαžšαžœαžΆ) αž“αŸ…αž€αŸ’αž“αž»αž„αžαŸ’αž“αžΆαž€αŸ‹αž…αžΌαž›αž“αŸαŸ‡αŸ–

cap_mkdb /etc/login.conf
pw usermod root -L default

αžŠαžΎαž˜αŸ’αž”αžΈαž±αŸ’αž™αž‚αŸ„αž›αž€αžΆαžšαžŽαŸαž’αž“αž»αžœαžαŸ’αžαž…αŸ†αž–αŸ„αŸ‡αžαŸ‚αž―αž€αžŸαžΆαžš αž’αŸ’αž“αž€αžαŸ’αžšαžΌαžœαž€αŸ‚αžŸαž˜αŸ’αžšαž½αž›αž―αž€αžŸαžΆαžš /etc/mac.conf αžŠαŸ„αž™αž‘αž»αž€αžαŸ‚αž”αž“αŸ’αž‘αžΆαžαŸ‹αž˜αž½αž™αž“αŸ…αž€αŸ’αž“αž»αž„αžœαžΆαŸ–

default_labels file ?mls

αž’αŸ’αž“αž€αž€αŸαžαŸ’αžšαžΌαžœαž”αž“αŸ’αžαŸ‚αž˜αž˜αŸ‰αžΌαžŒαž»αž› mac_mls.ko αžŠαžΎαž˜αŸ’αž”αžΈαžŠαŸ†αžŽαžΎαžšαž€αžΆαžšαžŸαŸ’αžœαŸαž™αž”αŸ’αžšαžœαžαŸ’αžαž·αŸ–

echo 'mac_mls_load="YES"' >> /boot/loader.conf

αž”αž“αŸ’αž‘αžΆαž”αŸ‹αž–αžΈαž“αŸαŸ‡ αž’αŸ’αž“αž€αž’αžΆαž…αž…αžΆαž”αŸ‹αž•αŸ’αžŠαžΎαž˜αž”αŸ’αžšαž–αŸαž“αŸ’αž’αž‘αžΎαž„αžœαž·αž‰αžŠαŸ„αž™αžŸαž»αžœαžαŸ’αžαž·αž—αžΆαž–αŸ” αžšαž”αŸ€αž”αž”αž„αŸ’αž€αžΎαž αž–αž“αŸ’αž’αž“αžΆαž‚αžΆαžš αž’αŸ’αž“αž€αž’αžΆαž…αž’αžΆαž“αžœαžΆαž“αŸ…αž€αŸ’αž“αž»αž„αž€αžΆαžšαž”αŸ„αŸ‡αž–αž»αž˜αŸ’αž–αž•αŸ’αžŸαžΆαž™αžšαž”αžŸαŸ‹αžαŸ’αž‰αž»αŸ†αŸ” αž”αŸ‰αž»αž“αŸ’αžαŸ‚αž˜αž»αž“αž–αŸαž›αž”αž„αŸ’αž€αžΎαžαž‚αž»αž€ αž’αŸ’αž“αž€αžαŸ’αžšαžΌαžœαž”αž“αŸ’αžαŸ‚αž˜ hard drive αž“αž·αž„αž”αž„αŸ’αž€αžΎαžαž”αŸ’αžšαž–αŸαž“αŸ’αž’αž―αž€αžŸαžΆαžšαž“αŸ…αž›αžΎαžœαžΆ αž αžΎαž™αž”αžΎαž€ multilabel αž“αŸ…αž›αžΎαžœαžΆ αž”αž„αŸ’αž€αžΎαžαž”αŸ’αžšαž–αŸαž“αŸ’αž’αž―αž€αžŸαžΆαžš ufs2 αžŠαŸ‚αž›αž˜αžΆαž“αž‘αŸ†αž αŸ† cluster 64kbαŸ–

newfs -O 2 -b 64kb /dev/ada1
tunefs -l enable /dev/ada1

αž”αž“αŸ’αž‘αžΆαž”αŸ‹αž–αžΈαž”αž„αŸ’αž€αžΎαžαž”αŸ’αžšαž–αŸαž“αŸ’αž’αž―αž€αžŸαžΆαžš αž“αž·αž„αž”αž“αŸ’αžαŸ‚αž˜ multilabel αž’αŸ’αž“αž€αžαŸ’αžšαžΌαžœαž”αž“αŸ’αžαŸ‚αž˜ hard drive αž‘αŸ… /etc/fstab αž”αž“αŸ’αžαŸ‚αž˜αž”αž“αŸ’αž‘αžΆαžαŸ‹αž‘αŸ…αž―αž€αžŸαžΆαžšαž“αŸαŸ‡αŸ–

/dev/ada1               /jail  ufs     rw              0       1

αž“αŸ…αž€αŸ’αž“αž»αž„ Mountpoint αž”αž‰αŸ’αž‡αžΆαž€αŸ‹αžαžαžŠαŸ‚αž›αž’αŸ’αž“αž€αž“αžΉαž„αž—αŸ’αž‡αžΆαž”αŸ‹ hard drive αž€αŸ’αž“αž»αž„ Pass αžαŸ’αžšαžΌαžœαž”αŸ’αžšαžΆαž€αžŠαžαžΆαž”αž‰αŸ’αž‡αžΆαž€αŸ‹ 1 (αž€αŸ’αž“αž»αž„αž›αŸ†αžŠαžΆαž”αŸ‹αžŽαžΆαžŠαŸ‚αž› hard drive αž“αŸαŸ‡αž“αžΉαž„αžαŸ’αžšαžΌαžœαž”αžΆαž“αž–αž·αž“αž·αžαŸ’αž™) - αž“αŸαŸ‡αž‡αžΆαž€αžΆαžšαž…αžΆαŸ†αž”αžΆαž…αŸ‹ αžŠαŸ„αž™αžŸαžΆαžšαž”αŸ’αžšαž–αŸαž“αŸ’αž’αž―αž€αžŸαžΆαžš ufs αž„αžΆαž™αž“αžΉαž„αžŠαžΆαž…αŸ‹αž…αžšαž“αŸ’αžαž’αž‚αŸ’αž‚αž·αžŸαž“αžΈαž—αŸ’αž›αžΆαž˜αŸ—αŸ” . αž”αž“αŸ’αž‘αžΆαž”αŸ‹αž–αžΈαž‡αŸ†αž αžΆαž“αž‘αžΆαŸ†αž„αž“αŸαŸ‡ αžŠαŸ†αž‘αžΎαž„αžαžΆαžŸαŸ–

mount /dev/ada1 /jail

αžŠαŸ†αž‘αžΎαž„αž‚αž»αž€αž“αŸ…αž€αŸ’αž“αž»αž„αžαžαž“αŸαŸ‡αŸ” αž”αž“αŸ’αž‘αžΆαž”αŸ‹αž–αžΈαž‚αž»αž€αž€αŸ†αž–αž»αž„αžŠαŸ†αžŽαžΎαžšαž€αžΆαžš αž’αŸ’αž“αž€αžαŸ’αžšαžΌαžœαž’αŸ’αžœαžΎαž§αž”αžΆαž™αž€αž›αžŠαžΌαž…αž‚αŸ’αž“αžΆαž“αŸ…αž€αŸ’αž“αž»αž„αžœαžΆαžŠαžΌαž…αž“αŸ…αž€αŸ’αž“αž»αž„αž”αŸ’αžšαž–αŸαž“αŸ’αž’αž˜αŸαž‡αžΆαž˜αž½αž™αž’αŸ’αž“αž€αž”αŸ’αžšαžΎαž”αŸ’αžšαžΆαžŸαŸ‹ αž“αž·αž„αž―αž€αžŸαžΆαžš /etc/login.conf, /etc/mac.conf αŸ”

αž€αžΆαžšαž›αŸƒαžαž˜αŸ’αžšαžΌαžœ

αž˜αž»αž“αž–αŸαž›αžŠαŸ†αž‘αžΎαž„αžŸαŸ’αž›αžΆαž€αž…αžΆαŸ†αž”αžΆαž…αŸ‹ αžαŸ’αž‰αž»αŸ†αžŸαžΌαž˜αžŽαŸ‚αž“αžΆαŸ†αž±αŸ’αž™αžŠαŸ†αž‘αžΎαž„αž€αž‰αŸ’αž…αž”αŸ‹αž…αžΆαŸ†αž”αžΆαž…αŸ‹αž‘αžΆαŸ†αž„αž’αžŸαŸ‹ αž€αŸ’αž“αž»αž„αž€αžšαžŽαžΈαžšαž”αžŸαŸ‹αžαŸ’αž‰αž»αŸ† αžŸαŸ’αž›αžΆαž€αž“αžΉαž„αžαŸ’αžšαžΌαžœαž”αžΆαž“αž€αŸ†αžŽαžαŸ‹αžŠαŸ„αž™αž‚αž·αžαž‚αžΌαžšαž–αžΈαž€αž‰αŸ’αž…αž”αŸ‹αž‘αžΆαŸ†αž„αž“αŸαŸ‡αŸ–

mod_php73-7.3.4_1              PHP Scripting Language
php73-7.3.4_1                  PHP Scripting Language
php73-ctype-7.3.4_1            The ctype shared extension for php
php73-curl-7.3.4_1             The curl shared extension for php
php73-dom-7.3.4_1              The dom shared extension for php
php73-extensions-1.0           "meta-port" to install PHP extensions
php73-filter-7.3.4_1           The filter shared extension for php
php73-gd-7.3.4_1               The gd shared extension for php
php73-gettext-7.3.4_1          The gettext shared extension for php
php73-hash-7.3.4_1             The hash shared extension for php
php73-iconv-7.3.4_1            The iconv shared extension for php
php73-json-7.3.4_1             The json shared extension for php
php73-mysqli-7.3.4_1           The mysqli shared extension for php
php73-opcache-7.3.4_1          The opcache shared extension for php
php73-openssl-7.3.4_1          The openssl shared extension for php
php73-pdo-7.3.4_1              The pdo shared extension for php
php73-pdo_sqlite-7.3.4_1       The pdo_sqlite shared extension for php
php73-phar-7.3.4_1             The phar shared extension for php
php73-posix-7.3.4_1            The posix shared extension for php
php73-session-7.3.4_1          The session shared extension for php
php73-simplexml-7.3.4_1        The simplexml shared extension for php
php73-sqlite3-7.3.4_1          The sqlite3 shared extension for php
php73-tokenizer-7.3.4_1        The tokenizer shared extension for php
php73-xml-7.3.4_1              The xml shared extension for php
php73-xmlreader-7.3.4_1        The xmlreader shared extension for php
php73-xmlrpc-7.3.4_1           The xmlrpc shared extension for php
php73-xmlwriter-7.3.4_1        The xmlwriter shared extension for php
php73-xsl-7.3.4_1              The xsl shared extension for php
php73-zip-7.3.4_1              The zip shared extension for php
php73-zlib-7.3.4_1             The zlib shared extension for php
apache24-2.4.39 

αž€αŸ’αž“αž»αž„αž§αž‘αžΆαž αžšαžŽαŸαž“αŸαŸ‡ αžŸαŸ’αž›αžΆαž€αž“αžΉαž„αžαŸ’αžšαžΌαžœαž”αžΆαž“αž€αŸ†αžŽαžαŸ‹αžŠαŸ„αž™αž‚αž·αžαž‚αžΌαžšαž–αžΈαž—αžΆαž–αž’αžΆαžŸαŸ’αžšαŸαž™αž“αŸƒαž€αž‰αŸ’αž…αž”αŸ‹αž‘αžΆαŸ†αž„αž“αŸαŸ‡αŸ” αž‡αžΆαž€αžΆαžšαž–αž·αžαžŽαžΆαžŸαŸ‹ αž’αŸ’αž“αž€αž’αžΆαž…αž’αŸ’αžœαžΎαžœαžΆαž”αžΆαž“αž€αžΆαž“αŸ‹αžαŸ‚αžŸαžΆαž˜αž‰αŸ’αž‰αŸ– αžŸαž˜αŸ’αžšαžΆαž”αŸ‹αžαž /usr/local/lib αž“αž·αž„αž―αž€αžŸαžΆαžšαžŠαŸ‚αž›αž˜αžΆαž“αž“αŸ…αž€αŸ’αž“αž»αž„αžαžαž“αŸαŸ‡ αž€αŸ†αžŽαžαŸ‹αžŸαŸ’αž›αžΆαž€ mls/low αž“αž·αž„αž€αž‰αŸ’αž…αž”αŸ‹αžŠαŸ‚αž›αž”αžΆαž“αžŠαŸ†αž‘αžΎαž„αž‡αžΆαž”αž“αŸ’αžαž”αž“αŸ’αž‘αžΆαž”αŸ‹ (αž§αž‘αžΆαž αžšαžŽαŸ αž€αž˜αŸ’αž˜αžœαž·αž’αžΈαž”αž“αŸ’αžαŸ‚αž˜αžŸαž˜αŸ’αžšαžΆαž”αŸ‹ php) αž“αžΉαž„αž’αžΆαž…αž…αžΌαž›αž”αŸ’αžšαžΎαž”αžΆαž“αŸ” αž”αžŽαŸ’αžŽαžΆαž›αŸαž™αž“αŸ…αž€αŸ’αž“αž»αž„αžαžαž“αŸαŸ‡ αž”αŸ‰αž»αž“αŸ’αžαŸ‚αžœαžΆαž αžΆαž€αŸ‹αžŠαžΌαž…αž‡αžΆαž›αŸ’αž’αž‡αžΆαž„αžŸαž˜αŸ’αžšαžΆαž”αŸ‹αžαŸ’αž‰αž»αŸ†αž•αŸ’αžαž›αŸ‹αž€αžΆαžšαž…αžΌαž›αž”αŸ’αžšαžΎαžαŸ‚αž―αž€αžŸαžΆαžšαž‘αžΆαŸ†αž„αž“αŸ„αŸ‡αžŠαŸ‚αž›αž…αžΆαŸ†αž”αžΆαž…αŸ‹αŸ” αž”αž‰αŸ’αžˆαž”αŸ‹αž€αžΆαžšαž‡αžΆαž”αŸ‹αž‚αž»αž€ αž αžΎαž™αž€αŸ†αžŽαžαŸ‹ mls/high labels αž›αžΎαž―αž€αžŸαžΆαžšαž‘αžΆαŸ†αž„αž’αžŸαŸ‹αŸ–

setfmac -R mls/high /jail

αž“αŸ…αž–αŸαž›αž€αŸ†αžŽαžαŸ‹αžŸαž‰αŸ’αž‰αžΆ αžŠαŸ†αžŽαžΎαžšαž€αžΆαžšαž“αžΉαž„αžαŸ’αžšαžΌαžœαž”αžΆαž“αž”αž‰αŸ’αžˆαž”αŸ‹ αž”αŸ’αžšαžŸαž·αž“αž”αžΎ setfmac αž‡αž½αž”αž”αŸ’αžšαž‘αŸ‡αž“αžΉαž„αžαŸ†αžŽαž—αŸ’αž‡αžΆαž”αŸ‹αžšαžΉαž„ αž€αŸ’αž“αž»αž„αž§αž‘αžΆαž αžšαžŽαŸαžšαž”αžŸαŸ‹αžαŸ’αž‰αž»αŸ† αžαŸ’αž‰αž»αŸ†αž”αžΆαž“αž›αž»αž”αžαŸ†αžŽαžšαžΉαž„αž“αŸ…αž€αŸ’αž“αž»αž„αžαžαžαžΆαž„αž€αŸ’αžšαŸ„αž˜αŸ–

/var/db/etcupdate/current/
/var/db/etcupdate/current/etc
/var/db/etcupdate/current/usr/share/openssl/man/en.ISO8859-15
/var/db/etcupdate/current/usr/share/man/en.ISO8859-15
/var/db/etcupdate/current/usr/share/man/en.UTF-8
/var/db/etcupdate/current/usr/share/nls
/etc/ssl
/usr/local/etc
/usr/local/etc/fonts/conf.d
/usr/local/openssl

αž”αž“αŸ’αž‘αžΆαž”αŸ‹αž–αžΈαž€αŸ†αžŽαžαŸ‹αžŸαŸ’αž›αžΆαž€αžšαž½αž…αž αžΎαž™ αž’αŸ’αž“αž€αžαŸ’αžšαžΌαžœαž€αŸ†αžŽαžαŸ‹αžŸαŸ’αž›αžΆαž€ mls/low αžŸαž˜αŸ’αžšαžΆαž”αŸ‹ apache αžšαžΏαž„αžŠαŸ†αž”αžΌαž„αžŠαŸ‚αž›αž’αŸ’αž“αž€αžαŸ’αžšαžΌαžœαž’αŸ’αžœαžΎαž‚αžΊαžŸαŸ’αžœαŸ‚αž„αžšαž€αž―αž€αžŸαžΆαžšαžŽαžΆαžŠαŸ‚αž›αžαŸ’αžšαžΌαžœαž€αžΆαžšαžŠαžΎαž˜αŸ’αž”αžΈαž…αžΆαž”αŸ‹αž•αŸ’αžαžΎαž˜ apacheαŸ–

ldd /usr/local/sbin/httpd

αž”αž“αŸ’αž‘αžΆαž”αŸ‹αž–αžΈαž”αŸ’αžšαžαž·αž”αžαŸ’αžαž·αž–αžΆαž€αŸ’αž™αž”αž‰αŸ’αž‡αžΆαž“αŸαŸ‡ αž—αžΆαž–αž’αžΆαžŸαŸ’αžšαŸαž™αž“αžΉαž„αžαŸ’αžšαžΌαžœαž”αžΆαž“αž”αž„αŸ’αž αžΆαž‰αž“αŸ…αž›αžΎαž’αŸαž€αŸ’αžšαž„αŸ‹ αž”αŸ‰αž»αž“αŸ’αžαŸ‚αž€αžΆαžšαž€αŸ†αžŽαžαŸ‹αžŸαŸ’αž›αžΆαž€αž…αžΆαŸ†αž”αžΆαž…αŸ‹αž“αŸ…αž›αžΎαž―αž€αžŸαžΆαžšαž‘αžΆαŸ†αž„αž“αŸαŸ‡αž“αžΉαž„αž˜αž·αž“αž‚αŸ’αžšαž”αŸ‹αž‚αŸ’αžšαžΆαž“αŸ‹αž‘αŸ αžŠαŸ„αž™αžŸαžΆαžšαžαžαžŠαŸ‚αž›αž―αž€αžŸαžΆαžšαž‘αžΆαŸ†αž„αž“αŸαŸ‡αž˜αžΆαž“αž‘αžΈαžαžΆαŸ†αž„αž“αŸ…αž˜αžΆαž“αžŸαŸ’αž›αžΆαž€ mls/high αžŠαžΌαž…αŸ’αž“αŸαŸ‡αžαžαž‘αžΆαŸ†αž„αž“αŸαŸ‡αž€αŸαžαŸ’αžšαžΌαžœαžŠαžΆαž€αŸ‹αžŸαŸ’αž›αžΆαž€αž•αž„αžŠαŸ‚αžšαŸ” mls/αž‘αžΆαž”αŸ” αž“αŸ…αž–αŸαž›αž…αžΆαž”αŸ‹αž•αŸ’αžαžΎαž˜ apache αž€αŸαž“αžΉαž„αž”αž‰αŸ’αž…αŸαž‰αž―αž€αžŸαžΆαžšαžŠαŸ‚αž›αž…αžΆαŸ†αž”αžΆαž…αŸ‹αžŸαž˜αŸ’αžšαžΆαž”αŸ‹αžŠαŸ†αžŽαžΎαžšαž€αžΆαžšαžœαžΆ αž αžΎαž™αžŸαž˜αŸ’αžšαžΆαž”αŸ‹ php αž—αžΆαž–αž’αžΆαžŸαŸ’αžšαŸαž™αž‘αžΆαŸ†αž„αž“αŸαŸ‡αž’αžΆαž…αžšαž€αž”αžΆαž“αž“αŸ…αž€αŸ’αž“αž»αž„αž€αŸ†αžŽαžαŸ‹αž αŸαžαž» httpd-error.log αŸ”

setfmac mls/low /
setfmac mls/low /usr/local/lib/libpcre.so.1
setfmac mls/low /usr/local/lib/libaprutil-1.so.0
setfmac mls/low /usr/local/lib/libdb-5.3.so.0
setfmac mls/low /usr/local/lib/libgdbm.so.6
setfmac mls/low /usr/local/lib/libexpat.so.1
setfmac mls/low /usr/local/lib/libapr-1.so.0
setfmac mls/low /lib/libcrypt.so.5
setfmac mls/low /lib/libthr.so.3
setfmac mls/low /lib/libc.so.7
setfmac mls/low /usr/local/lib/libintl.so.8
setfmac mls/low /var
setfmac mls/low /var/run
setfmac mls/low /var/log
setfmac mls/low /var/log/httpd-access.log
setfmac mls/low /var/log/httpd-error.log
setfmac mls/low /var/run/httpd.pid
setfmac mls/low /lib
setfmac mls/low /lib/libcrypt.so.5
setfmac mls/low /usr/local/lib/db5/libdb-5.3.so.0
setfmac mls/low /usr/local/lib/db5/libdb-5.3.so.0.0.0
setfmac mls/low /usr/local/lib/db5
setfmac mls/low /usr/local/lib
setfmac mls/low /libexec
setfmac mls/low /libexec/ld-elf.so.1
setfmac  mls/low /dev
setfmac  mls/low /dev/random
setfmac  mls/low /usr/local/libexec
setfmac  mls/low /usr/local/libexec/apache24
setfmac  mls/low /usr/local/libexec/apache24/*
setfmac  mls/low /etc/pwd.db
setfmac  mls/low /etc/passwd
setfmac  mls/low /etc/group
setfmac  mls/low /etc/
setfmac  mls/low /usr/local/etc
setfmac -R mls/low /usr/local/etc/apache24
setfmac mls/low /usr
setfmac mls/low /usr/local
setfmac mls/low /usr/local/sbin
setfmac mls/low /usr/local/sbin/*
setfmac -R mls/low /usr/local/etc/rc.d/
setfmac mls/low /usr/local/sbin/htcacheclean
setfmac mls/low /var/log/httpd-access.log
setfmac mls/low /var/log/httpd-error.log
setfmac -R mls/low /usr/local/www
setfmac mls/low /usr/lib
setfmac mls/low /tmp
setfmac -R mls/low /usr/local/lib/php
setfmac -R mls/low /usr/local/etc/php
setfmac mls/low /usr/local/etc/php.conf
setfmac mls/low /lib/libelf.so.2
setfmac mls/low /lib/libm.so.5
setfmac mls/low /usr/local/lib/libxml2.so.2
setfmac mls/low /lib/libz.so.6
setfmac mls/low /usr/lib/liblzma.so.5
setfmac mls/low /usr/local/lib/libiconv.so.2
setfmac mls/low /usr/lib/librt.so.1
setfmac mls/low /lib/libthr.so.3
setfmac mls/low /usr/local/lib/libpng16.so.16
setfmac mls/low /usr/lib/libbz2.so.4
setfmac mls/low /usr/local/lib/libargon2.so.0
setfmac mls/low /usr/local/lib/libpcre2-8.so.0
setfmac mls/low /usr/local/lib/libsqlite3.so.0
setfmac mls/low /usr/local/lib/libgd.so.6
setfmac mls/low /usr/local/lib/libjpeg.so.8
setfmac mls/low /usr/local/lib/libfreetype.so
setfmac mls/low /usr/local/lib/libfontconfig.so.1
setfmac mls/low /usr/local/lib/libtiff.so.5
setfmac mls/low /usr/local/lib/libwebp.so.7
setfmac mls/low /usr/local/lib/libjbig.so.2
setfmac mls/low /usr/lib/libssl.so.8
setfmac mls/low /lib/libcrypto.so.8
setfmac mls/low /usr/local/lib/libzip.so.5
setfmac mls/low /etc/resolv.conf

αž”αž‰αŸ’αž‡αžΈαž“αŸαŸ‡αž˜αžΆαž“αžŸαŸ’αž›αžΆαž€ mls/low αžŸαž˜αŸ’αžšαžΆαž”αŸ‹αž―αž€αžŸαžΆαžšαž‘αžΆαŸ†αž„αž’αžŸαŸ‹αžŠαŸ‚αž›αž…αžΆαŸ†αž”αžΆαž…αŸ‹αžŸαž˜αŸ’αžšαžΆαž”αŸ‹αž”αŸ’αžšαžαž·αž”αžαŸ’αžαž·αž€αžΆαžšαžαŸ’αžšαžΉαž˜αžαŸ’αžšαžΌαžœαž“αŸƒαž€αžΆαžšαžšαž½αž˜αž”αž‰αŸ’αž…αžΌαž›αž‚αŸ’αž“αžΆ apache αž“αž·αž„ php (αžŸαž˜αŸ’αžšαžΆαž”αŸ‹αž€αž‰αŸ’αž…αž”αŸ‹αž‘αžΆαŸ†αž„αž“αŸ„αŸ‡αžŠαŸ‚αž›αžαŸ’αžšαžΌαžœαž”αžΆαž“αžŠαŸ†αž‘αžΎαž„αž€αŸ’αž“αž»αž„αž§αž‘αžΆαž αžšαžŽαŸαžšαž”αžŸαŸ‹αžαŸ’αž‰αž»αŸ†)αŸ”

αž€αžΆαžšαž”αŸ‰αŸ‡αž…αž»αž„αž€αŸ’αžšαŸ„αž™αž“αžΉαž„αžαŸ’αžšαžΌαžœαž”αžΆαž“αž€αŸ†αžŽαžαŸ‹αžšαž…αž“αžΆαžŸαž˜αŸ’αž–αŸαž“αŸ’αž’αž‚αž»αž€αž±αŸ’αž™αžŠαŸ†αžŽαžΎαžšαž€αžΆαžšαž“αŸ…αž€αž˜αŸ’αžšαž·αž mls/equal αž“αž·αž„ apache αž“αŸ…αž€αž˜αŸ’αžšαž·αž mls/low αŸ” αžŠαžΎαž˜αŸ’αž”αžΈαž…αžΆαž”αŸ‹αž•αŸ’αžαžΎαž˜αž‚αž»αž€ αž’αŸ’αž“αž€αžαŸ’αžšαžΌαžœαž’αŸ’αžœαžΎαž€αžΆαžšαž•αŸ’αž›αžΆαžŸαŸ‹αž”αŸ’αžαžΌαžšαž‘αŸ… /etc/rc.d/jail script αžŸαŸ’αžœαŸ‚αž„αžšαž€αž˜αž»αžαž„αžΆαžš jail_start αž€αŸ’αž“αž»αž„αžŸαŸ’αž‚αŸ’αžšαžΈαž”αž“αŸαŸ‡ αž”αŸ’αžαžΌαžšαž’αžαŸαžšαž–αžΆαž€αŸ’αž™αž”αž‰αŸ’αž‡αžΆαž‘αŸ…αž‡αžΆαž‘αž˜αŸ’αžšαž„αŸ‹αŸ–

command="setpmac mls/equal $jail_program"

αž–αžΆαž€αŸ’αž™αž”αž‰αŸ’αž‡αžΆ setpmac αžŠαŸ†αžŽαžΎαžšαž€αžΆαžšαž―αž€αžŸαžΆαžšαžŠαŸ‚αž›αž’αžΆαž…αž”αŸ’αžšαžαž·αž”αžαŸ’αžαž·αž”αžΆαž“αž“αŸ…αž€αž˜αŸ’αžšαž·αžαžŸαž˜αžαŸ’αžαž—αžΆαž–αžŠαŸ‚αž›αžαŸ’αžšαžΌαžœαž€αžΆαžš αž€αŸ’αž“αž»αž„αž€αžšαžŽαžΈαž“αŸαŸ‡ mls/equal αžŠαžΎαž˜αŸ’αž”αžΈαž˜αžΆαž“αžŸαž·αž‘αŸ’αž’αž·αž…αžΌαž›αž”αŸ’αžšαžΎαžŸαŸ’αž›αžΆαž€αž‘αžΆαŸ†αž„αž’αžŸαŸ‹αŸ” αž“αŸ…αž€αŸ’αž“αž»αž„ apache αž’αŸ’αž“αž€αžαŸ’αžšαžΌαžœαž€αŸ‚αžŸαž˜αŸ’αžšαž½αž›αžŸαŸ’αž‚αŸ’αžšαžΈαž”αž…αžΆαž”αŸ‹αž•αŸ’αžŠαžΎαž˜ /usr/local/etc/rc.d/apache24αŸ” αž•αŸ’αž›αžΆαžŸαŸ‹αž”αŸ’αžαžΌαžšαž˜αž»αžαž„αžΆαžš apache24_prestartαŸ–

apache24_prestart() {
        apache24_checkfib
        apache24_precmd
        eval "setpmac mls/low" ${command} ${apache24_flags}
}

Π’ αž‡αžΆαž•αŸ’αž›αžΌαžœαž€αžΆαžš αžŸαŸ€αžœαž—αŸ…αžŠαŸƒαž˜αžΆαž“αž§αž‘αžΆαž αžšαžŽαŸαž˜αž½αž™αž‘αŸ€αž αž”αŸ‰αž»αž“αŸ’αžαŸ‚αžαŸ’αž‰αž»αŸ†αž˜αž·αž“αž’αžΆαž…αž”αŸ’αžšαžΎαžœαžΆαž”αžΆαž“αž‘αŸ αžŠαŸ„αž™αžŸαžΆαžšαžαŸ’αž‰αž»αŸ†αž”αž“αŸ’αžαž‘αž‘αž½αž›αž”αžΆαž“αžŸαžΆαžšαž’αŸ†αž–αžΈαž’αžŸαž˜αžαŸ’αžαž—αžΆαž–αž€αŸ’αž“αž»αž„αž€αžΆαžšαž”αŸ’αžšαžΎαž–αžΆαž€αŸ’αž™αž”αž‰αŸ’αž‡αžΆ setpmac αŸ”

αžŸαŸαž…αž€αŸ’αžαžΈαžŸαž“αŸ’αž“αž·αžŠαŸ’αž‹αžΆαž“

αžœαž·αž’αžΈαžŸαžΆαžŸαŸ’αžšαŸ’αžαž“αŸƒαž€αžΆαžšαž…αŸ‚αž€αž…αžΆαž™αž€αžΆαžšαž…αžΌαž›αž”αŸ’αžšαžΎαž“αŸαŸ‡αž“αžΉαž„αž”αž“αŸ’αžαŸ‚αž˜αž€αž˜αŸ’αžšαž·αžαžŸαž»αžœαžαŸ’αžαž·αž—αžΆαž–αž”αž“αŸ’αžαŸ‚αž˜αž‘αŸ€αžαžŠαž›αŸ‹ apache (αž‘αŸ„αŸ‡αž”αžΈαž‡αžΆαžœαž·αž’αžΈαžŸαžΆαžŸαŸ’αžαŸ’αžšαž“αŸαŸ‡αž‚αžΊαžŸαž˜αžšαž˜αŸ’αž™αžŸαž˜αŸ’αžšαžΆαž”αŸ‹αž‡αž„αŸ‹αž•αŸ’αžŸαŸαž„αž‘αŸ€αžαž€αŸαžŠαŸ„αž™) αžŠαŸ‚αž›αž›αžΎαžŸαž–αžΈαž“αŸαŸ‡αž‘αŸ€αžαžŠαŸ†αžŽαžΎαžšαž€αžΆαžšαž“αŸ…αž€αŸ’αž“αž»αž„αž‚αž»αž€ αž€αŸ’αž“αž»αž„αž–αŸαž›αžαŸ‚αž˜αž½αž™αžŸαž˜αŸ’αžšαžΆαž”αŸ‹αž’αŸ’αž“αž€αž‚αŸ’αžšαž”αŸ‹αž‚αŸ’αžšαž„ αž’αŸ’αžœαžΈαŸ—αž‘αžΆαŸ†αž„αž’αžŸαŸ‹αž“αŸαŸ‡αž“αžΉαž„αž€αžΎαžαž‘αžΎαž„αžŠαŸ„αž™αžαž˜αŸ’αž›αžΆαž—αžΆαž– αž“αž·αž„αž˜αž·αž“αž’αžΆαž…αž€αžαŸ‹αžŸαž˜αŸ’αž‚αžΆαž›αŸ‹αž”αžΆαž“αŸ”

αž”αž‰αŸ’αž‡αžΈαž”αŸ’αžšαž—αž–αžŠαŸ‚αž›αž”αžΆαž“αž‡αž½αž™αžαŸ’αž‰αž»αŸ†αž€αŸ’αž“αž»αž„αž€αžΆαžšαžŸαžšαžŸαŸαžšαž€αžΆαžšαž”αŸ„αŸ‡αž–αž»αž˜αŸ’αž–αž•αŸ’αžŸαžΆαž™αž“αŸαŸ‡αŸ–

https://www.freebsd.org/doc/ru_RU.KOI8-R/books/handbook/mac.html

αž”αŸ’αžšαž—αž–: www.habr.com

αž”αž“αŸ’αžαŸ‚αž˜αž˜αžαž·αž™αŸ„αž”αž›αŸ‹