Iprojekthi ye-Openwall ipapashe ukukhululwa kwemodyuli ye-LKRG 0.9.0 kernel (Linux I-Kernel Runtime Guard, eyenzelwe ukubona nokuthintela ukuhlaselwa kunye nokwaphulwa kobume be-kernel. Umzekelo, imodyuli inokukhusela kutshintsho olungagunyaziswanga kwi-kernel esebenzayo kwaye izame ukutshintsha amalungelo eenkqubo zomsebenzisi (ukufumanisa i-exploits). Imodyuli ifanelekile ukukhusela kwi-exploits ye-kernel vulnerability eyaziwayo. Linux (umzekelo, kwiimeko apho ukuhlaziya i-kernel yenkqubo kuyingxaki) kunye nokulwa nokuxhathisa ubuthathaka obungaziwayo. Ikhowudi yeprojekthi isasazwa phantsi kwelayisenisi ye-GPLv2.
Phakathi kotshintsho kwinguqulelo entsha:
- Ukuhambelana neekernel kuyaqinisekiswa Linux ukusuka kwi-5.8 ukuya kwi-5.12, kunye nee-kernel ezizinzileyo eziyi-5.4.87 nezamva (eziquka iimpawu ezintsha ezivela kwii-kernel eziyi-5.8 nezamva) kunye nee-kernel ezivela kwiinguqulelo ze-RHEL ukuya kuthi ga kwi-8.4, ngelixa zigcina inkxaso yazo zonke iinguqulelo ze-kernel ezixhaswe ngaphambili, ezifana nee-kernel ezivela kwi-RHEL 7;
- Kongeze amandla okwakha i-LKRG kungekuphela nje njengemodyuli yangaphandle, kodwa nanjengenxalenye yomthi we-kernel Linux, kuquka ukufakwa kwayo kumfanekiso we-kernel;
- Inkxaso eyongeziweyo yeekernel ezininzi ezongezelelweyo kunye noqwalaselo lwenkqubo;
- Ukulungisa iimpazamo ezininzi ezibalulekileyo kunye neentsilelo kwi-LKRG;
- Ukuphunyezwa kwamanye amacandelo e-LKRG kwenziwe lula kakhulu;
- Utshintsho lwenziwe lula ngakumbi inkxaso kunye nokulungiswa kwe-LKRG;
- Ukuvavanya i-LKRG, ukudibanisa kunye ne-out-of-tree kunye ne-mkosi yongezwe;
- Indawo yokugcina iprojekthi isusiwe kwiBitBucket ukuya kwiGitHub kwaye ukuhlanganiswa okuqhubekayo kongezwe kusetyenziswa iiGitHub Actions kunye ne-mkosi, kubandakanya ukujonga ukwakhiwa kwe-LKRG kunye nokulayisha kwii-kernel ezikhutshiweyo. Ubuntu, kunye nezo zibonelelwe yiprojekthi Ubuntu Ukwakhiwa kwemihla ngemihla kwee-kernel zamva nje eziphambili.
Abaphuhlisi abaninzi ababengazange bathathe inxaxheba kule projekthi ngaphambili banegalelo ngokuthe ngqo kule nguqulelo ye-LKRG (ngezicelo zokutsala kwiGitHub). Ngokukodwa, uBoris Lukashev wongeze amandla okwakha njengenxalenye yomthi we-kernel. Linuxkunye noVitaly Chikunov ovela kwi-ALT Linux — ukuhlanganiswa ne-mkosi kunye ne-GitHub Actions.
Ngokubanzi, nangona ukongezwa okubalulekileyo, inani lemigca ye-LKRG yekhowudi liye lancitshiswa kancinane okwesibini ngokulandelelana (kwaye kwancitshiswa ngaphambili phakathi kweenguqu ze-0.8 kunye ne-0.8.1).
Okwangoku, iphakheji ye-LKRG ikwi-Arch Linux sele ihlaziyiwe ukuya kwinguqulelo 0.9.0, kwaye ezinye iipakeji ezininzi zisebenzisa iinguqulelo zamva nje ze-git ze-LKRG kwaye kusenokwenzeka ukuba ihlaziywe ukuya kwinguqulelo 0.9.0 nangaphezulu kungekudala.
Ukongeza, sinokuphawula upapasho lwakutsha nje oluvela kubaphuhlisi be-Aurora OS (ukuguqulwa kwesiRashiya kweSailfish OS) malunga nokomelezwa okunokwenzeka kweLKRG kusetyenziswa i-ARM TrustZone.
Ngolwazi oluthe kratya malunga ne-LKRG, jonga isibhengezo senguqulo 0.8 kunye nengxoxo eyenzeka ngoko.
umthombo: opennet.ru
