ืžืึทื ื“ืึทื˜ืึธืจื™ ืจืขื›ื˜ ืคืึทืจืฉืคึผืจื™ื™ื˜ื•ื ื’ ืžืึธื“ืขืœ ืื™ืŸ FreeBSD

ื”ืงื“ืžื”

ืฆื• ืฆื•ืฉื˜ืขืœืŸ ืึทืŸ ื ืึธืš ืžื“ืจื’ื” ืคื•ืŸ ืกืขืจื•ื•ืขืจ ื–ื™ื›ืขืจื”ื™ื™ื˜, ืื™ืจ ืงืขื ืขืŸ ื ื•ืฆืŸ ืžืึทื ื“ืึทื˜ ืžืึธื“ืขืœ ืฆื•ื˜ืจื™ื˜ ืคืึทืจืฉืคึผืจื™ื™ื˜ื•ื ื’. ื“ื™ ื•ื™ืกื’ืึทื‘ืข ื•ื•ืขื˜ ื‘ืึทืฉืจื™ื™ึทื‘ืŸ ื•ื•ื™ ืื™ืจ ืงืขื ืขืŸ ืœื•ื™ืคืŸ ืึทืคึผืึทื˜ืฉื™ ืื™ืŸ ืึท ื˜ื•ืจืžืข ืžื™ื˜ ืึทืงืกืขืก ื‘ืœื•ื™ื– ืฆื• ื“ื™ ืงืึทืžืคึผืึธื•ื ืึทื ืฅ ื•ื•ืึธืก ื“ืึทืจืคืŸ ืึทืงืกืขืก ืคึฟืึทืจ ืึทืคึผืึทื˜ืฉื™ ืื•ืŸ ืคืคึผ ืฆื• ืึทืจื‘ืขื˜ืŸ ืจื™ื›ื˜ื™ืง. ืžื™ื˜ ื“ืขื ืคึผืจื™ื ืฆื™ืคึผ, ืื™ืจ ืงืขื ืขืŸ ื‘ืึทื’ืจืขื ืขืฆืŸ ื ื™ื˜ ื‘ืœื•ื™ื– ืึทืคึผืึทื˜ืฉื™, ืึธื‘ืขืจ ืื•ื™ืš ืงื™ื™ืŸ ืื ื“ืขืจืข ืึธื ืœื™ื™ื’ืŸ.

ื˜ืจืึทื™ื ื™ื ื’

ื“ืขืจ ืื•ืคึฟืŸ ืื™ื– ื‘ืœื•ื™ื– ืคึผืึทืกื™ืง ืคึฟืึทืจ ื“ื™ ufs ื˜ืขืงืข ืกื™ืกื˜ืขื ืื™ืŸ ื“ืขื ื‘ื™ื™ึทืฉืคึผื™ืœ, zfs ื•ื•ืขื˜ ื–ื™ื™ืŸ ื’ืขื•ื•ื™ื™ื ื˜ ืื™ืŸ ื“ื™ ื”ื•ื™ืคึผื˜ ืกื™ืกื˜ืขื, ืื•ืŸ ufs ืื™ืŸ ื“ื™ ื˜ื•ืจืžืข. ื“ืขืจ ืขืจืฉื˜ืขืจ ืฉืจื™ื˜ ืื™ื– ืฆื• ืจื™ื‘ื™ืœื“ ื“ื™ ืงืขืจืŸ ื•ื•ืขืŸ ืื™ืจ ื™ื ืกื˜ืึทืœื™ืจืŸ FreeBSD, ื™ื ืกื˜ืึทืœื™ืจืŸ ื“ื™ ืžืงื•ืจ ืงืึธื“.
ื ืึธืš ื“ื™ ืกื™ืกื˜ืขื ืื™ื– ืื™ื ืกื˜ืึทืœื™ืจืŸ, ืจืขื“ืึทื’ื™ืจืŸ ื“ื™ ื˜ืขืงืข:

/usr/src/sys/amd64/conf/GENERIC

ืื™ืจ ื ืึธืจ ื“ืึทืจืคึฟืŸ ืฆื• ืœื™ื™ื’ืŸ ืื™ื™ืŸ ืฉื•ืจื” ืฆื• ื“ืขื ื˜ืขืงืข:

options     MAC_MLS

ื“ื™ mls / ื”ื•ื™ืš ืคื™ืจืžืข ื•ื•ืขื˜ ื”ืึธื‘ืŸ ืึท ื“ืึธืžื™ื ืึทื ื˜ ืฉื˜ืขืœืข ืื™ื‘ืขืจ ื“ื™ mls / ื ื™ื“ืขืจื™ืง ืคื™ืจืžืข, ืึทืคึผืœืึทืงื™ื™ืฉืึทื ื– ื•ื•ืึธืก ื•ื•ืขื˜ ื–ื™ื™ืŸ ืœืึธื ื˜ืฉื˜ ืžื™ื˜ ื“ื™ mls / ื ื™ื“ืขืจื™ืง ืคื™ืจืžืข ื•ื•ืขื˜ ื ื™ืฉื˜ ืงืขื ืขืŸ ืฆื• ืึทืงืกืขืก ื˜ืขืงืขืก ื•ื•ืึธืก ื”ืึธื‘ืŸ ื“ื™ mls / ื”ื•ื™ืš ืคื™ืจืžืข. ืžืขืจ ื“ืขื˜ืึทื™ืœืก ื•ื•ืขื’ืŸ ืึทืœืข ื‘ื ื™ืžืฆื ื˜ืึทื’ืก ืื™ืŸ ื“ื™ FreeBSD ืกื™ืกื˜ืขื ืงืขื ืขืŸ ื–ื™ื™ืŸ ื’ืขืคึฟื•ื ืขืŸ ืื™ืŸ ื“ืขื ืคื™ืจืขืจืฉืึทืคื˜.
ื•ื•ื™ื™ึทื˜ืขืจ, ื’ื™ื™ืŸ ืฆื• ื“ื™ /usr/src ื•ื•ืขื’ื•ื•ื™ื™ึทื–ืขืจ:

cd /usr/src

ืฆื• ืึธื ื”ื™ื™ื‘ืŸ ื‘ื•ื™ืขืŸ ื“ืขื ืงืขืจืŸ, ืœื•ื™ืคืŸ (ืื™ืŸ ื“ื™ j ืฉืœื™ืกืœ, ืกืคึผืขืฆื™ืคื™ืฆื™ืจืŸ ื“ื™ ื ื•ืžืขืจ ืคื•ืŸ ืงืึธืจืขืก ืื™ืŸ ื“ื™ ืกื™ืกื˜ืขื):

make -j 4 buildkernel KERNCONF=GENERIC

ื ืึธืš ื“ื™ ืงืขืจืŸ ืื™ื– ืงืึทืžืคึผื™ื™ืœื“, ืขืก ืžื•ื–ืŸ ื–ื™ื™ืŸ ืื™ื ืกื˜ืึทืœื™ืจืŸ:

make installkernel KERNCONF=GENERIC

ื ืึธืš ื™ื ืกื˜ืึธืœื™ื ื’ ื“ื™ ืงืขืจืŸ, ื˜ืึธืŸ ื ื™ื˜ ืงืึทืžื™ืฉ ืฆื• ืจืขื‘ืึธืึธื˜ ื“ื™ ืกื™ืกื˜ืขื, ื•ื•ื™ื™ึทืœ ืขืก ืื™ื– ื ื™ื™ื˜ื™ืง ืฆื• ืึทืจื™ื‘ืขืจืคื™ืจืŸ ื“ื™ ื‘ืึทื ื™ืฆืขืจ ืฆื• ื“ื™ ืœืึธื’ื™ืŸ ืงืœืึทืก, ื ืึธืš ืงืึทื ืคื™ื’ื™ืขืจื“ ืขืก ืคืจื™ืขืจ. ืจืขื“ืึทื’ื™ืจืŸ ื“ื™ /etc/login.conf ื˜ืขืงืข, ืื™ืŸ ื“ืขื ื˜ืขืงืข ืื™ืจ ื“ืึทืจืคึฟืŸ ืฆื• ืจืขื“ืึทื’ื™ืจืŸ ื“ื™ ืคืขืœื™ืงื™ื™ึทื˜ ืœืึธื’ื™ืŸ ืงืœืึทืก, ื‘ืจืขื ื’ืขืŸ ืขืก ืฆื• ื“ื™ ืคืึธืจืขื:

default:
        :passwd_format=sha512:
        :copyright=/etc/COPYRIGHT:
        :welcome=/etc/motd:
        :setenv=MAIL=/var/mail/$,BLOCKSIZE=K:
        :path=/sbin /bin /usr/sbin /usr/bin /usr/local/sbin /usr/local/bin ~/bin:
        :nologin=/var/run/nologin:
        :cputime=unlimited:
        :datasize=unlimited:
        :stacksize=unlimited:
        :memorylocked=64K:
        :memoryuse=unlimited:
        :filesize=unlimited:
        :coredumpsize=unlimited:
        :openfiles=unlimited:
        :maxproc=unlimited:
        :sbsize=unlimited:
        :vmemoryuse=unlimited:
        :swapuse=unlimited:
        :pseudoterminals=unlimited:
        :kqueues=unlimited:
        :umtxp=unlimited:
        :priority=0:
        :ignoretime@:
        :umask=022:
        :label=mls/equal:

ื“ื™ ืฉื•ืจื” :label=mls/equal ื•ื•ืขื˜ ืœืึธื–ืŸ ื•ืกืขืจืก ื•ื•ืืก ื–ืขื ืขืŸ ืžื™ื˜ื’ืœื™ื“ืขืจ ืคื•ืŸ ื“ืขื ืงืœืึทืก ืฆื• ืึทืงืกืขืก ื˜ืขืงืขืก ื•ื•ืึธืก ื–ืขื ืขืŸ ืื ื’ืขืฆื™ื™ื›ื ื˜ ืžื™ื˜ ืงื™ื™ืŸ ืคื™ืจืžืข (mls/low, mls/high). ื ืึธืš ื“ื™ ืžืึทื ื™ืคึผื™ืึทืœื™ื™ืฉืึทื ื–, ืื™ืจ ื“ืึทืจืคึฟืŸ ืฆื• ืจื™ื‘ื™ืœื“ ื“ื™ ื“ืึทื˜ืึทื‘ื™ื™ืก ืื•ืŸ ืฉื˜ืขืœืŸ ื“ื™ ื•ื•ืึธืจืฆืœ ื‘ืึทื ื™ืฆืขืจ (ื•ื•ื™ ื’ืขื–ื•ื ื˜ ื•ื•ื™ ื“ื™ ื•ื•ืืก ื“ืึทืจืคึฟืŸ ืขืก) ืื™ืŸ ื“ืขื ืœืึธื’ื™ืŸ ืงืœืึทืก:

cap_mkdb /etc/login.conf
pw usermod root -L default

ื›ึผื“ื™ ื“ื™ ืคึผืึธืœื™ื˜ื™ืง ื–ืึธืœ ืึธื ื•ื•ืขื ื“ืŸ ื‘ืœื•ื™ื– ืื•ื™ืฃ ื˜ืขืงืขืก, ืื™ืจ ื“ืึทืจืคึฟืŸ ืฆื• ืจืขื“ืึทื’ื™ืจืŸ ื“ื™ /etc/mac.conf ื˜ืขืงืข, ืื•ืŸ ืœืึธื–ืŸ ื‘ืœื•ื™ื– ืื™ื™ืŸ ืฉื•ืจื” ืื™ืŸ ืขืก:

default_labels file ?mls

ืื™ืจ ืื•ื™ืš ื“ืึทืจืคึฟืŸ ืฆื• ืœื™ื™ื’ืŸ ื“ื™ mac_mls.ko ืžืึธื“ื•ืœืข ืฆื• ืึทื•ื˜ืึธืจื•ืŸ:

echo 'mac_mls_load="YES"' >> /boot/loader.conf

ื ืึธืš ื“ืขื, ืื™ืจ ืงืขื ืขืŸ ื‘ืขืฉืึธืœืขื ืจื™ืกื˜ืึทืจื˜ ื“ื™ ืกื™ืกื˜ืขื. ื•ื•ื™ ืฆื• ืฉืึทืคึฟืŸ ื˜ื•ืจืžืข ืื™ืจ ืงืขื ืขืŸ ืœื™ื™ืขื ืขืŸ ืขืก ืื™ืŸ ืื™ื™ื ืขืจ ืคื•ืŸ ืžื™ื™ืŸ ืื•ื™ืกื’ืื‘ืขืก. ืึธื‘ืขืจ ืื™ื™ื“ืขืจ ืื™ืจ ืฉืึทืคึฟืŸ ืึท ื˜ื•ืจืžืข, ืื™ืจ ื“ืึทืจืคึฟืŸ ืฆื• ืœื™ื™ื’ืŸ ืึท ืฉื•ื•ืขืจ ืคืึธืจ ืื•ืŸ ืฉืึทืคึฟืŸ ืึท ื˜ืขืงืข ืกื™ืกื˜ืขื ืื•ื™ืฃ ืขืก ืื•ืŸ ื’ืขื‘ืŸ ืžืึทืœื˜ื™ืœืึทื‘ืขืœ ืื•ื™ืฃ ืขืก, ืฉืึทืคึฟืŸ ืึท ufs2 ื˜ืขืงืข ืกื™ืกื˜ืขื ืžื™ื˜ ืึท ืงื ื•ื™ืœ ื’ืจื™ื™ืก ืคื•ืŸ 64 ืงื‘:

newfs -O 2 -b 64kb /dev/ada1
tunefs -l enable /dev/ada1

ื ืึธืš ืงืจื™ื™ื™ื˜ื™ื ื’ ื“ื™ ื˜ืขืงืข ืกื™ืกื˜ืขื ืื•ืŸ ืึทื“ื™ื ื’ ืžื•ืœื˜ื™ืœืึทื‘ืขืœ, ืื™ืจ ื“ืึทืจืคึฟืŸ ืฆื• ืœื™ื™ื’ืŸ ื“ื™ ืฉื•ื•ืขืจ ืคืึธืจ ืฆื• /etc/fstab, ืœื™ื™ื’ืŸ ื“ื™ ืฉื•ืจื” ืฆื• ื“ืขื ื˜ืขืงืข:

/dev/ada1               /jail  ufs     rw              0       1

ืื™ืŸ Mountpoint, ืกืคึผืขืฆื™ืคื™ืฆื™ืจืŸ ื“ื™ ื•ื•ืขื’ื•ื•ื™ื™ึทื–ืขืจ ืื™ืŸ ื•ื•ืึธืก ืื™ืจ ื•ื•ืขื˜ ืึธื ืงืœืึทืคึผืŸ ื“ื™ ืฉื•ื•ืขืจ ืคืึธืจ ืื™ืŸ ืคึผืึทืก, ื–ื™ื™ืŸ ื–ื™ื›ืขืจ ืฆื• ืกืคึผืขืฆื™ืคื™ืฆื™ืจืŸ 1 (ืื™ืŸ ื•ื•ืึธืก ืกื™ืงื•ื•ืึทื ืก ื“ืขื ืฉื•ื•ืขืจ ืคืึธืจ ื•ื•ืขื˜ ื–ื™ื™ืŸ ืึธืคึผื’ืขืฉื˜ืขืœื˜) - ื“ืึธืก ืื™ื– ื ื™ื™ื˜ื™ืง, ื•ื•ื™ื™ึทืœ ื“ื™ ufs ื˜ืขืงืข ืกื™ืกื˜ืขื ืื™ื– ืฉืคึผื™ืจืขื•ื•ื“ื™ืง ืฆื• ืคึผืœื•ืฆืขืžื“ื™ืง ืžืึทื›ื˜ ืงืึทืฅ; . ื ืึธืš ื“ื™ ืกื˜ืขืคึผืก, ืึธื ืงืœืึทืคึผืŸ ื“ื™ ื“ื™ืกืง:

mount /dev/ada1 /jail

ื™ื ืกื˜ืึทืœื™ืจืŸ ื˜ื•ืจืžืข ืื™ืŸ ื“ืขื ื•ื•ืขื’ื•ื•ื™ื™ึทื–ืขืจ. ื ืึธืš ื“ื™ ื˜ื•ืจืžืข ืื™ื– ืคืœื™ืกื ื“ื™ืง, ืื™ืจ ื“ืึทืจืคึฟืŸ ืฆื• ื˜ืึธืŸ ื“ื™ ื–ืขืœื‘ืข ืžืึทื ื™ืคึผื™ืึทืœื™ื™ืฉืึทื ื– ืื™ืŸ ืขืก ื•ื•ื™ ืื™ืŸ ื“ื™ ื”ื•ื™ืคึผื˜ ืกื™ืกื˜ืขื ืžื™ื˜ ื ื™ืฆืขืจืก ืื•ืŸ ื“ื™ ื˜ืขืงืขืก /etc/login.conf, /etc/mac.conf.

Customize

ืื™ื™ื“ืขืจ ืื™ืจ ื™ื ืกื˜ืึทืœื™ืจืŸ ื“ื™ ื ื™ื™ื˜ื™ืง ื˜ืึทื’ืก, ืื™ืš ืจืขืงืึธืžืขื ื“ื™ืจืŸ ืฆื• ื™ื ืกื˜ืึทืœื™ืจืŸ ืึทืœืข ื“ื™ ื ื™ื™ื˜ื™ืง ืคึผืึทืงืึทื“ื–ืฉืึทื– ืื™ืŸ ืžื™ื™ืŸ ืคืึทืœ, ื“ื™ ื˜ืึทื’ืก ื•ื•ืขื˜ ื–ื™ื™ืŸ ืฉื˜ืขืœืŸ ืื™ืŸ ื—ืฉื‘ื•ืŸ ื“ื™ ืคึผืึทืงืึทื“ื–ืฉืึทื–:

mod_php73-7.3.4_1              PHP Scripting Language
php73-7.3.4_1                  PHP Scripting Language
php73-ctype-7.3.4_1            The ctype shared extension for php
php73-curl-7.3.4_1             The curl shared extension for php
php73-dom-7.3.4_1              The dom shared extension for php
php73-extensions-1.0           "meta-port" to install PHP extensions
php73-filter-7.3.4_1           The filter shared extension for php
php73-gd-7.3.4_1               The gd shared extension for php
php73-gettext-7.3.4_1          The gettext shared extension for php
php73-hash-7.3.4_1             The hash shared extension for php
php73-iconv-7.3.4_1            The iconv shared extension for php
php73-json-7.3.4_1             The json shared extension for php
php73-mysqli-7.3.4_1           The mysqli shared extension for php
php73-opcache-7.3.4_1          The opcache shared extension for php
php73-openssl-7.3.4_1          The openssl shared extension for php
php73-pdo-7.3.4_1              The pdo shared extension for php
php73-pdo_sqlite-7.3.4_1       The pdo_sqlite shared extension for php
php73-phar-7.3.4_1             The phar shared extension for php
php73-posix-7.3.4_1            The posix shared extension for php
php73-session-7.3.4_1          The session shared extension for php
php73-simplexml-7.3.4_1        The simplexml shared extension for php
php73-sqlite3-7.3.4_1          The sqlite3 shared extension for php
php73-tokenizer-7.3.4_1        The tokenizer shared extension for php
php73-xml-7.3.4_1              The xml shared extension for php
php73-xmlreader-7.3.4_1        The xmlreader shared extension for php
php73-xmlrpc-7.3.4_1           The xmlrpc shared extension for php
php73-xmlwriter-7.3.4_1        The xmlwriter shared extension for php
php73-xsl-7.3.4_1              The xsl shared extension for php
php73-zip-7.3.4_1              The zip shared extension for php
php73-zlib-7.3.4_1             The zlib shared extension for php
apache24-2.4.39 

ืื™ืŸ ื“ืขื ื‘ื™ื™ึทืฉืคึผื™ืœ, ืœืึทื‘ืขืœืก ื•ื•ืขื˜ ื–ื™ื™ืŸ ืฉื˜ืขืœืŸ ืื™ืŸ ื—ืฉื‘ื•ืŸ ื“ื™ ื“ื™ืคึผืขื ื“ืึทื ืกื™ื– ืคื•ืŸ ื“ื™ ืคึผืึทืงืึทื“ื–ืฉืึทื–. ื“ืึธืš, ืื™ืจ ืงืขื ืขืŸ ื˜ืึธืŸ ื“ืึธืก ืกื™ืžืคึผืœืขืจ: ืคึฟืึทืจ ื“ื™ /usr/local/lib ื˜ืขืงืข ืื•ืŸ ื“ื™ ื˜ืขืงืขืก ืื™ืŸ ื“ืขื ื•ื•ืขื’ื•ื•ื™ื™ึทื–ืขืจ, ืฉื˜ืขืœืŸ ื“ื™ ืžืœืก/ื ื™ื“ืขืจื™ืง ืœืึทื‘ืขืœืก ืื•ืŸ ืกืึทื‘ืกืึทืงื•ื•ืึทื ื˜ ืื™ื ืกื˜ืึทืœื™ืจืŸ ืคึผืึทืงืึทื“ื–ืฉืึทื– (ืคึฟืึทืจ ื‘ื™ื™ึทืฉืคึผื™ืœ, ื ืึธืš ื™ืงืกื˜ืขื ืฉืึทื ื– ืคึฟืึทืจ ืคืคึผ) ืงืขื ืขืŸ ืึทืงืกืขืก ื“ื™ ืœื™ื™ื‘ืจืขืจื™ื– ืื™ืŸ ื“ืขื ื•ื•ืขื’ื•ื•ื™ื™ึทื–ืขืจ, ืึธื‘ืขืจ ืขืก ืžื™ื™ื ื˜ ื‘ืขืกืขืจ ืฆื• ืžื™ืจ ืฆื•ืฉื˜ืขืœืŸ ืึทืงืกืขืก ื‘ืœื•ื™ื– ืฆื• ื“ื™ ื ื™ื™ื˜ื™ืง ื˜ืขืงืขืก. ื”ืึทืœื˜ืŸ ื˜ื•ืจืžืข ืื•ืŸ ืฉื˜ืขืœืŸ mls / ื”ื•ื™ืš ืœืึทื‘ืขืœืก ืื•ื™ืฃ ืึทืœืข ื˜ืขืงืขืก:

setfmac -R mls/high /jail

ื•ื•ืขืŸ ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ืžืึทืจืงืก, ื“ืขืจ ืคึผืจืึธืฆืขืก ื•ื•ืขื˜ ื–ื™ื™ืŸ ืกื˜ืึทืคึผื˜ ืื•ื™ื‘ setfmac ื™ื ืงืึทื•ื ื˜ืขืจื– ืฉื•ื•ืขืจ ืคึฟืึทืจื‘ื™ื ื“ื•ื ื’ืขืŸ, ืื™ืŸ ืžื™ื™ืŸ ื‘ื™ื™ึทืฉืคึผื™ืœ ืื™ืš ืื•ื™ืกื’ืขืžืขืงื˜ ืฉื•ื•ืขืจ ืคึฟืึทืจื‘ื™ื ื“ื•ื ื’ืขืŸ ืื™ืŸ ื“ื™ ืคืืœื’ืขื ื“ืข ื“ื™ื™ืจืขืงื˜ืขืจื™ื–:

/var/db/etcupdate/current/
/var/db/etcupdate/current/etc
/var/db/etcupdate/current/usr/share/openssl/man/en.ISO8859-15
/var/db/etcupdate/current/usr/share/man/en.ISO8859-15
/var/db/etcupdate/current/usr/share/man/en.UTF-8
/var/db/etcupdate/current/usr/share/nls
/etc/ssl
/usr/local/etc
/usr/local/etc/fonts/conf.d
/usr/local/openssl

ื ืึธืš ื“ื™ ืœืึทื‘ืขืœืก ื–ืขื ืขืŸ ื‘ืึทืฉื˜ื™ืžื˜, ืื™ืจ ื“ืึทืจืคึฟืŸ ืฆื• ืฉื˜ืขืœืŸ ื“ื™ ืžืœืก / ื ื™ื“ืขืจื™ืง ืœืึทื‘ืขืœืก ืคึฟืึทืจ ืึทืคึผืึทื˜ืฉื™, ื“ืขืจ ืขืจืฉื˜ืขืจ ื–ืึทืš ืื™ืจ ื“ืึทืจืคึฟืŸ ืฆื• ื˜ืึธืŸ ืื™ื– ืฆื• ื’ืขืคึฟื™ื ืขืŸ ื•ื•ืึธืก ื˜ืขืงืขืก ื–ืขื ืขืŸ ื“ืืจืฃ ืฆื• ืึธื ื”ื™ื™ื‘ืŸ ืึทืคึผืึทื˜ืฉื™:

ldd /usr/local/sbin/httpd

ื ืึธืš ืขืงืกืึทืงื™ื•ื˜ื™ื ื’ ื“ืขื ื‘ืึทืคึฟืขืœ, ื“ื™ ื“ืขืคึผืขื ื“ืึทื ืกื™ื– ื•ื•ืขื˜ ื–ื™ื™ืŸ ื’ืขื•ื•ื™ื–ืŸ ืื•ื™ืฃ ื“ืขื ืขืงืจืึทืŸ, ืึธื‘ืขืจ ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ื“ื™ ื ื™ื™ื˜ื™ืง ืœืึทื‘ืขืœืก ืื•ื™ืฃ ื“ื™ ื˜ืขืงืขืก ื•ื•ืขื˜ ื ื™ืฉื˜ ื–ื™ื™ืŸ ื’ืขื ื•ื’, ื•ื•ื™ื™ึทืœ ื“ื™ ื“ื™ืจืขืงื˜ืขืจื™ื– ืื™ืŸ ื•ื•ืึธืก ื“ื™ ื˜ืขืงืขืก ื–ืขื ืขืŸ ืœื™ื’ืŸ ื”ืึธื‘ืŸ ื“ื™ ืžืœืก / ื”ื•ื™ืš ืคื™ืจืžืข, ืึทื–ื•ื™ ื“ื™ ื“ื™ืจืขืงื˜ืขืจื™ื– ืžื•ื–ืŸ ืื•ื™ืš ื–ื™ื™ืŸ ืžื™ื˜ืŸ ื ืึธืžืขืŸ. mls/low. ื•ื•ืขืŸ ืื™ืจ ืึธื ื”ื™ื™ื‘, ืึทืคึผืึทื˜ืฉื™ ื•ื•ืขื˜ ืื•ื™ืš ืึทืจื•ื™ืกืคื™ืจืŸ ื“ื™ ื˜ืขืงืขืก ื•ื•ืึธืก ื–ืขื ืขืŸ ื ื™ื™ื˜ื™ืง ืฆื• ืœื•ื™ืคืŸ ืขืก, ืื•ืŸ ืคึฟืึทืจ php ื“ื™ ื“ื™ืคึผืขื ื“ืึทื ืกื™ื– ืงืขื ืขืŸ ื–ื™ื™ืŸ ื’ืขืคึฟื•ื ืขืŸ ืื™ืŸ ื“ื™ httpd-error.log ืงืœืึธืฅ.

setfmac mls/low /
setfmac mls/low /usr/local/lib/libpcre.so.1
setfmac mls/low /usr/local/lib/libaprutil-1.so.0
setfmac mls/low /usr/local/lib/libdb-5.3.so.0
setfmac mls/low /usr/local/lib/libgdbm.so.6
setfmac mls/low /usr/local/lib/libexpat.so.1
setfmac mls/low /usr/local/lib/libapr-1.so.0
setfmac mls/low /lib/libcrypt.so.5
setfmac mls/low /lib/libthr.so.3
setfmac mls/low /lib/libc.so.7
setfmac mls/low /usr/local/lib/libintl.so.8
setfmac mls/low /var
setfmac mls/low /var/run
setfmac mls/low /var/log
setfmac mls/low /var/log/httpd-access.log
setfmac mls/low /var/log/httpd-error.log
setfmac mls/low /var/run/httpd.pid
setfmac mls/low /lib
setfmac mls/low /lib/libcrypt.so.5
setfmac mls/low /usr/local/lib/db5/libdb-5.3.so.0
setfmac mls/low /usr/local/lib/db5/libdb-5.3.so.0.0.0
setfmac mls/low /usr/local/lib/db5
setfmac mls/low /usr/local/lib
setfmac mls/low /libexec
setfmac mls/low /libexec/ld-elf.so.1
setfmac  mls/low /dev
setfmac  mls/low /dev/random
setfmac  mls/low /usr/local/libexec
setfmac  mls/low /usr/local/libexec/apache24
setfmac  mls/low /usr/local/libexec/apache24/*
setfmac  mls/low /etc/pwd.db
setfmac  mls/low /etc/passwd
setfmac  mls/low /etc/group
setfmac  mls/low /etc/
setfmac  mls/low /usr/local/etc
setfmac -R mls/low /usr/local/etc/apache24
setfmac mls/low /usr
setfmac mls/low /usr/local
setfmac mls/low /usr/local/sbin
setfmac mls/low /usr/local/sbin/*
setfmac -R mls/low /usr/local/etc/rc.d/
setfmac mls/low /usr/local/sbin/htcacheclean
setfmac mls/low /var/log/httpd-access.log
setfmac mls/low /var/log/httpd-error.log
setfmac -R mls/low /usr/local/www
setfmac mls/low /usr/lib
setfmac mls/low /tmp
setfmac -R mls/low /usr/local/lib/php
setfmac -R mls/low /usr/local/etc/php
setfmac mls/low /usr/local/etc/php.conf
setfmac mls/low /lib/libelf.so.2
setfmac mls/low /lib/libm.so.5
setfmac mls/low /usr/local/lib/libxml2.so.2
setfmac mls/low /lib/libz.so.6
setfmac mls/low /usr/lib/liblzma.so.5
setfmac mls/low /usr/local/lib/libiconv.so.2
setfmac mls/low /usr/lib/librt.so.1
setfmac mls/low /lib/libthr.so.3
setfmac mls/low /usr/local/lib/libpng16.so.16
setfmac mls/low /usr/lib/libbz2.so.4
setfmac mls/low /usr/local/lib/libargon2.so.0
setfmac mls/low /usr/local/lib/libpcre2-8.so.0
setfmac mls/low /usr/local/lib/libsqlite3.so.0
setfmac mls/low /usr/local/lib/libgd.so.6
setfmac mls/low /usr/local/lib/libjpeg.so.8
setfmac mls/low /usr/local/lib/libfreetype.so
setfmac mls/low /usr/local/lib/libfontconfig.so.1
setfmac mls/low /usr/local/lib/libtiff.so.5
setfmac mls/low /usr/local/lib/libwebp.so.7
setfmac mls/low /usr/local/lib/libjbig.so.2
setfmac mls/low /usr/lib/libssl.so.8
setfmac mls/low /lib/libcrypto.so.8
setfmac mls/low /usr/local/lib/libzip.so.5
setfmac mls/low /etc/resolv.conf

ื“ื™ ืจืฉื™ืžื” ื›ึผื•ืœืœ mls / ื ื™ื“ืขืจื™ืง ื˜ืึทื’ืก ืคึฟืึทืจ ืึทืœืข ื˜ืขืงืขืก ื•ื•ืึธืก ื–ืขื ืขืŸ ื ื™ื™ื˜ื™ืง ืคึฟืึทืจ ื“ื™ ืจื™ื›ื˜ื™ืง ืึธืคึผืขืจืึทืฆื™ืข ืคื•ืŸ โ€‹โ€‹ื“ื™ ืึทืคึผืึทื˜ืฉื™ ืื•ืŸ ืคืคึผ ืงืึธืžื‘ื™ื ืึทืฆื™ืข (ืคึฟืึทืจ ื“ื™ ืคึผืึทืงืึทื“ื–ืฉืึทื– ื•ื•ืึธืก ื–ืขื ืขืŸ ืื™ื ืกื˜ืึทืœื™ืจืŸ ืื™ืŸ ืžื™ื™ืŸ ื‘ื™ื™ึทืฉืคึผื™ืœ).

ื“ื™ ืœืขืฆื˜ ืคืึทืจื‘ื™ื ื“ืŸ ื•ื•ืขื˜ ื–ื™ื™ืŸ ืฆื• ืงืึทื ืคื™ื’ื™ืขืจ ื˜ื•ืจืžืข ืฆื• ืœื•ื™ืคืŸ ืื•ื™ืฃ ื“ื™ ืžืœืก / ื’ืœื™ื™ึทืš ืžื“ืจื’ื”, ืื•ืŸ ืึทืคึผืึทื˜ืฉื™ ืื•ื™ืฃ ื“ื™ ืžืœืก / ื ื™ื“ืขืจื™ืง ืžื“ืจื’ื”. ืฆื• ืึธื ื”ื™ื™ื‘ืŸ ื˜ื•ืจืžืข, ืื™ืจ ื“ืึทืจืคึฟืŸ ืฆื• ืžืึทื›ืŸ ืขื ื“ืขืจื•ื ื’ืขืŸ ืฆื• ื“ื™ /etc/rc.d/jail ืฉืจื™ืคื˜, ื’ืขืคึฟื™ื ืขืŸ ื“ื™ jail_start ืคืึทื ื’ืงืฉืึทื ื– ืื™ืŸ ื“ืขื ืฉืจื™ืคื˜, ื˜ื•ื™ืฉืŸ ื“ื™ ื‘ืึทืคึฟืขืœ ื‘ื™ื™ึทื˜ืขื•ื•ื“ื™ืง ืฆื• ื“ื™ ืคืึธืจืขื:

command="setpmac mls/equal $jail_program"

ื“ื™ setpmac ื‘ืึทืคึฟืขืœ ืœื•ื™ืคื˜ ื“ื™ ืขืงืกืขืงื•ื˜ืึทื‘ืœืข ื˜ืขืงืข ืื•ื™ืฃ ื“ื™ ืคืืจืœืื ื’ื˜ ืคื™ื™ื™ืงื™ื™ื˜ ืžื“ืจื’ื”, ืื™ืŸ ื“ืขื ืคืึทืœ mls/equal, ืื™ืŸ ืกื“ืจ ืฆื• ื”ืึธื‘ืŸ ืึทืงืกืขืก ืฆื• ืึทืœืข ืœืึทื‘ืขืœืก. ืื™ืŸ ืึทืคึผืึทื˜ืฉื™ ืื™ืจ ื“ืึทืจืคึฟืŸ ืฆื• ืจืขื“ืึทื’ื™ืจืŸ ื“ื™ ืกื˜ืึทืจื˜ืึทืคึผ ืฉืจื™ืคื˜ /usr/local/etc/rc.d/apache24. ื˜ื•ื™ืฉืŸ ื“ื™ apache24_prestart ืคื•ื ืงืฆื™ืข:

apache24_prestart() {
        apache24_checkfib
        apache24_precmd
        eval "setpmac mls/low" ${command} ${apache24_flags}
}

ะ’ ื‘ืึทืึทืžื˜ืขืจ ื“ืขืจ ืžืึทื ื•ืึทืœ ื›ึผื•ืœืœ ืืŸ ืื ื“ืขืจ ื‘ื™ื™ึทืฉืคึผื™ืœ, ืึธื‘ืขืจ ืื™ืš ืงืขืŸ ื ื™ืฉื˜ ื ื•ืฆืŸ ืขืก ื•ื•ื™ื™ึทืœ ืื™ืš ื”ืึธื‘ ื‘ืึทืงื•ืžืขืŸ ืึท ืึธื ื–ืึธื’ ื•ื•ืขื’ืŸ ื“ื™ ื™ื ืึทื‘ื™ืœื™ื˜ื™ ืฆื• ื ื•ืฆืŸ ื“ื™ setpmac ื‘ืึทืคึฟืขืœ.

ืจืขื–ื•ืœื˜ืึทื˜

ื“ืขืจ ืื•ืคึฟืŸ ืคื•ืŸ ื“ื™ืกื˜ืจื™ื‘ื™ื•ื˜ื™ื ื’ ืึทืงืกืขืก ื•ื•ืขื˜ ืœื™ื™ื’ืŸ ืึทืŸ ื ืึธืš ื–ื™ื›ืขืจื”ื™ื™ื˜ ืžื“ืจื’ื” ืฆื• ืึทืคึผืึทื˜ืฉื™ (ื›ืึธื˜ืฉ ื“ืขื ืื•ืคึฟืŸ ืื™ื– ืคึผืึทืกื™ืง ืคึฟืึทืจ ืงื™ื™ืŸ ืื ื“ืขืจืข ืึธื ืœื™ื™ื’ืŸ), ื•ื•ืึธืก ืื™ืŸ ืึทื“ื™ืฉืึทืŸ ืœื•ื™ืคื˜ ืื™ืŸ ืึท ื˜ื•ืจืžืข, ืื™ืŸ ื“ืขืจ ื–ืขืœื‘ื™ืงืขืจ ืฆื™ื™ื˜, ืคึฟืึทืจ ื“ื™ ืึทื“ืžื™ื ื™ืกื˜ืจืึทื˜ืึธืจ ืึทืœืข ื“ืขื ื•ื•ืขื˜ ืคึผืึทืกื™ืจืŸ ื˜ืจืึทื ืกืคึผืขืจืึทื ื˜ ืื•ืŸ ืึทื ื ืึธื˜ื™ืกืึทื‘ืœื™.

ืจืฉื™ืžื” ืคื•ืŸ ืžืงื•ืจื™ื ื•ื•ืึธืก ื’ืขื”ืึธืœืคึฟืŸ ืžื™ืจ ืื™ืŸ ืฉืจื™ื™ื‘ืŸ ื“ืขื ื•ื™ืกื’ืึทื‘ืข:

https://www.freebsd.org/doc/ru_RU.KOI8-R/books/handbook/mac.html

ืžืงื•ืจ: www.habr.com

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’