ืคื™ื™ืขืจื“ื–ืฉื™ื™ืœ 0.9.78 ืึทืคึผืœื™ืงืึทืฆื™ืข ืื™ื–ืึธืœืึทืฆื™ืข ืžืขืœื“ื•ื ื’

ืคื™ื™ืขืจื“ื–ืฉื™ื™ืœ 0.9.78 ืื™ื– ืืจื•ื™ืกื’ืขื’ืขื‘ืŸ ื’ืขื•ื•ืืจืŸ. ืขืก ืื ื˜ื•ื•ื™ืงืœื˜ ื ืกื™ืกื˜ืขื ืคืืจ ืืคื’ืขื–ื•ื ื“ืขืจื˜ืข ืื•ื™ืกืคื™ืจื•ื ื’ ืคื•ืŸ ื’ืจืืคื™ืฉืข, ืงืื ืกืืœ, ืื•ืŸ ืกืขืจื•ื•ืขืจ ืืคืœื™ืงืืฆื™ืขืก, ืžื™ื ื™ืžื™ื–ื™ืจื ื“ื™ื’ ื“ืขื ืจื™ื–ื™ืงืข ืคื•ืŸ โ€‹โ€‹ืงืืžืคืจืืžื™ื˜ื™ืจืŸ ื“ืขื ื”ืื•ืกื˜ ืกื™ืกื˜ืขื ื•ื•ืขืŸ ืžืขืŸ ืœื•ื™ืคื˜ ื ื™ืฉื˜-ืคืืจื˜ืจื•ื™ื˜ืข ืื“ืขืจ ืคืื˜ืขื ืฆื™ืขืœ ืฉื•ื•ืื›ืข ืคืจืื’ืจืืžืขืŸ. ื“ื™ ืคืจืื’ืจืื ืื™ื– ื’ืขืฉืจื™ื‘ืŸ ืื™ืŸ C, ืคืืจืฉืคืจื™ื™ื˜ ืื•ื ื˜ืขืจ ื“ืขืจ GPLv2 ืœื™ืฆืขื ืฅ, ืื•ืŸ ืœื•ื™ืคื˜ ืื•ื™ืฃ ื™ืขื“ืขืจ ืคืืจืฉืคืจื™ื™ื˜ื•ื ื’. Linux ืžื™ื˜ ืึท ืงืขืจื ืขืœ ืขืœื˜ืขืจ ื•ื•ื™ 3.0. ื’ืจื™ื™ื˜ืข ืคึผืึทืงืึทื“ื–ืฉืึทื– ืžื™ื˜ Firejail ื•ื•ืขืจืŸ ืฆื•ื’ืขื’ืจื™ื™ื˜ ืื™ืŸ deb ืคึฟืึธืจืžืึทื˜ืŸ (Debian, Ubuntu) ืื•ืŸ ืจืคึผื (CentOS, ืคืขื“ืึธืจืึท).

ืคื™ื™ืขืจื“ื–ืฉื™ื™ืœ ื ื™ืฆื˜ ื ืขื™ื-ืกืคึผื™ื™ืกื™ื–, ืึทืคึผืึทืจืžืึธืจ, ืื•ืŸ ืกื™ืกื˜ืขื ืจื•ืฃ ืคึฟื™ืœื˜ืขืจื™ื ื’ (ืกืขืงืึธืžืคึผ-ื‘ืคึผืฃ) ืคึฟืึทืจ ืื™ื–ืึธืœืึทืฆื™ืข. Linuxืึทืžืึธืœ ืœืึธื ื˜ืฉื˜, ื ื•ืฆืŸ ืึท ืคึผืจืึธื’ืจืึทื ืื•ืŸ ืึทืœืข ืื™ืจืข ืงื™ื ื“ ืคึผืจืึธืฆืขืกืŸ ื‘ืึทื–ื•ื ื“ืขืจืข ืจืขืคึผืจืขื–ืขื ื˜ืึทืฆื™ืขืก ืคื•ืŸ ืงืขืจื ืขืœ ืจืขืกื•ืจืกืŸ, ืึทื–ืึท ื•ื•ื™ ื“ื™ ื ืขืฅ ืกื˜ืขืง, ืคึผืจืึธืฆืขืก ื˜ืึทื‘ืขืœืข, ืื•ืŸ ืžืึธื•ื ื˜ ืคื•ื ืงื˜ืŸ. ืื™ื ื˜ืขืจ-ืึธืคึผื”ืขื ื’ื™ืงืข ืึทืคึผืœืึทืงื™ื™ืฉืึทื ื– ืงืขื ืขืŸ ื–ื™ื™ืŸ ืงืึทืžื‘ื™ื™ื ื“ ืื™ืŸ ืึท ืื™ื™ืŸ ื’ืขื˜ื™ื™ืœื˜ ื–ืึทืžื“ืงืึทืกื˜ืŸ. ืคื™ื™ืขืจื“ื–ืฉื™ื™ืœ ืงืขืŸ ืื•ื™ืš ื–ื™ื™ืŸ ื’ืขื ื™ืฆื˜ ืฆื• ืœื•ื™ืคืŸ ื“ืึธืงืขืจ, LXC, ืื•ืŸ OpenVZ ืงืึทื ื˜ื™ื™ื ืขืจื–.

ืื ื“ืขืจืฉ ื•ื•ื™ ืงืื ื˜ืขื™ื ืขืจ ืื™ื–ืืœื™ืจื•ื ื’ ืžื›ืฉื™ืจื™ื, ืื™ื– ืคื™ื™ืขืจื“ื–ืฉื™ื™ืœ ื’ืืจ ืคืฉื•ื˜ ืฆื• ืงืื ืคื™ื’ื•ืจื™ืจืŸ ืื•ืŸ ืคืืจืœืื ื’ื˜ ื ื™ืฉื˜ ืฆื• ืฆื•ื’ืจื™ื™ื˜ืŸ ื ืกื™ืกื˜ืขื ื‘ื™ืœื“โ€”ื“ื™ ืื™ื ื”ืืœื˜ ืคื•ื ืขื ืงืื ื˜ืขื™ื ืขืจ ื•ื•ืขืจื˜ ื’ืขื ืขืจื™ืจื˜ ืื•ื™ืคืŸ ืคืœืืฅ ื‘ืื–ื™ืจื˜ ืื•ื™ืฃ ื“ื™ ืื™ื ื”ืืœื˜ ืคื•ื ืขื ื™ืขืฆื˜ื™ื’ืŸ ืคื™ื™ืœ ืกื™ืกื˜ืขื ืื•ืŸ ื•ื•ืขืจื˜ ืื•ื™ืกื’ืขืžืขืงื˜ ื ืื›ื“ืขื ื•ื•ืืก ื“ื™ ืืคืœื™ืงืืฆื™ืข ืขื ื“ื™ื’ื˜ ื–ื™ืš. ืคืœืขืงืกื™ื‘ืœืข ืคื™ื™ืœ ืกื™ืกื˜ืขื ืฆื•ื˜ืจื™ื˜ ืจื•ืœืก ื•ื•ืขืจืŸ ืฆื•ื’ืขืฉื˜ืขืœื˜, ื•ื•ืืก ืขืจืžืขื’ืœื™ื›ื˜ ืื™ื™ืš ืฆื• ื“ืขืคื™ื ื™ืจืŸ ื•ื•ืขืœื›ืข ืคื™ื™ืœืŸ ืื•ืŸ ื“ื™ืจืขืงื˜ืืจื™ืขืก ื–ืขื ืขืŸ ืขืจืœื•ื™ื‘ื˜ ืื“ืขืจ ื’ืขืœื™ื™ืงื ื˜ ืฆื•ื˜ืจื™ื˜, ืžืื•ื ื˜ืŸ ืฆื™ื™ื˜ื•ื•ื™ื™ืœื™ื’ืข ืคื™ื™ืœ ืกื™ืกื˜ืขืžืขืŸ (tmpfs) ืคืืจ ื“ืื˜ื, ื‘ืื’ืจืขื ืขืฆืŸ ืฆื•ื˜ืจื™ื˜ ืฆื• ืคื™ื™ืœืŸ ืื“ืขืจ ื“ื™ืจืขืงื˜ืืจื™ืขืก ืฆื• ื ืืจ ืœื™ื™ืขื ืขืŸ, ืื•ืŸ ืงืืžื‘ื™ื ื™ืจืŸ ื“ื™ืจืขืงื˜ืืจื™ืขืก ื ื™ืฆื ื“ื™ื’ ื‘ื™ื ื“-ืžืื•ื ื˜ ืื•ืŸ ืื™ื‘ืขืจืœืืฃ.

ืคึฟืึทืจ ืึท ื’ืจื•ื™ืก ื ื•ืžืขืจ ืคื•ืŸ ืคืึธืœืงืก ืึทืคึผืœืึทืงื™ื™ืฉืึทื ื–, ืึทืจื™ื™ึทื ื’ืขืจืขื›ื ื˜ ืคื™ืจืขืคืึธืงืก, ืงืจืึธื•ืžื™ืึทื, ื•ื•ืœืง ืื•ืŸ ื˜ืจืึทื ืกืžื™ืกื™ืข, ืคืึทืจื˜ื™ืง ืกื™ืกื˜ืขื ืจื•ืคืŸ ืืคื’ืขื–ื•ื ื“ืขืจื˜ืงื™ื™ื˜ ืคึผืจืึธื•ืคื™ื™ืœื– ื–ืขื ืขืŸ ืฆื•ื’ืขื’ืจื™ื™ื˜. ืฆื• ื‘ืึทืงื•ืžืขืŸ ื“ื™ ืคึผืจื™ื•ื•ื™ืœืึทื“ื–ืฉืึทื– ื ื™ื™ื˜ื™ืง ืฆื• ืฉื˜ืขืœืŸ ืึท ื–ืึทืžื“ื‘ืึธืงืกืขื“ ืกื•ื•ื™ื•ื•ืข, ื“ื™ ืคื™ืจืขื“ื–ืฉืึทื™ืœ ืขืงืกืขืงื•ื˜ืึทื‘ืœืข ืื™ื– ืื™ื ืกื˜ืึทืœื™ืจืŸ ืžื™ื˜ ื“ื™ SUID ื•ื•ืึธืจืฆืœ ืคืึธืŸ (ืคึผืจื™ื•ื•ื™ืœืึทื“ื–ืฉืึทื– ื–ืขื ืขืŸ ื‘ืึทืฉื˜ืขื˜ื™ืง ื ืึธืš ื™ื ื™ื˜ื™ืึทืœื™ื–ื™ื™ืฉืึทืŸ). ืฆื• ืœื•ื™ืคืŸ ืึท ืคึผืจืึธื’ืจืึทื ืื™ืŸ ืืคื’ืขื–ื•ื ื“ืขืจื˜ืงื™ื™ื˜ ืžืึธื“ืข, ืคืฉื•ื˜ ืกืคึผืขืฆื™ืคื™ืฆื™ืจืŸ ื“ื™ ืึทืคึผืœืึทืงื™ื™ืฉืึทืŸ ื ืึธืžืขืŸ ื•ื•ื™ ืึทืŸ ืึทืจื’ื•ืžืขื ื˜ ืฆื• ื“ื™ ืคื™ื™ืจื“ื–ืฉืึทื™ืœ ื ื•ืฆืŸ, ืœืžืฉืœ, "firejail firefox" ืึธื“ืขืจ "sudo firejail /etc/init.d/nginx start".

ืื™ืŸ ื“ื™ ื ื™ื™ึทืข ืžืขืœื“ื•ื ื’:

  • ื“ื™ arg-max-count, arg-max-len, env-max-count, ืื•ืŸ env-max-len ืึธืคึผืฆื™ืขืก ื–ืขื ืขืŸ ืฆื•ื’ืขื’ืขื‘ืŸ ื’ืขื•ื•ืึธืจืŸ ืฆื• ื“ืขืจ firejail.config ืงืึธื ืคื™ื’ื•ืจืึทืฆื™ืข ื˜ืขืงืข ืฆื• ืขื ื“ืขืจืŸ ื“ื™ ืœื™ืžื™ื˜ืŸ ืื•ื™ืฃ ื“ืขืจ ืฆืึธืœ ืื•ืŸ ื’ืจื™ื™ืก ืคื•ืŸ ืงืึธืžืึทื ื“-ืœื™ื ื™ืข ืึธืคึผืฆื™ืขืก ืื•ืŸ ืกื‘ื™ื‘ื” ื•ื•ืขืจื™ืึทื‘ืึทืœืŸ. ื“ื•ืจืš ืคืขืœื™ืงื™ื™ึทื˜, ื“ื™ ืฆืึธืœ ืคื•ืŸ ืึทืจื’ื•ืžืขื ื˜ืŸ ืื™ื– ืœื™ืžื™ื˜ืขื“ ืฆื• 128, ื“ื™ ืฆืึธืœ ืคื•ืŸ ืกื‘ื™ื‘ื” ื•ื•ืขืจื™ืึทื‘ืึทืœืŸ ืื™ื– ืœื™ืžื™ื˜ืขื“ ืฆื• 256, ืื•ืŸ ื“ื™ ื’ืจื™ื™ืก ืคื•ืŸ ื™ืขื“ืŸ ืึทืจื’ื•ืžืขื ื˜ ืื™ื– PATH_MAX ืคึฟื•ืŸ limits.h (ืื™ืŸ Linux 40196) + 32.
  • ืฆื•ื’ืขื’ืขื‘ืŸ ื“ื™ "--xephyr-extra-params" ืึธืคึผืฆื™ืข ืฆื• ืกืคึผืขืฆื™ืคึฟื™ืฆื™ืจืŸ ื ืึธืš ืึธืคึผืฆื™ืขืก ืฆื• Xephyr (ื’ืขื ื™ืฆื˜ ืฆื• ืฉืึทืคึฟืŸ X11 ื–ืึทืžื“ืงืึทืกื˜ืŸ ืกื‘ื™ื‘ื•ืช ืžื™ื˜ ื–ื™ื™ืขืจ ืื™ื™ื’ืขื ืขื X ืกืขืจื•ื•ืขืจ ื•ื•ืึธืก ืœื•ื™ืคึฟื˜ ืื™ืŸ ืึท ืคึฟืขื ืฆื˜ืขืจ) ืื•ื™ืฃ ื“ืขืจ ืงืึธืžืึทื ื“ ืœื™ื ื™ืข ืึธืŸ ืฆื• ืžืึธื“ื™ืคึฟื™ืฆื™ืจืŸ firejail.config.
  • ื“ื™ bwrap (bubblewrap) ื ื•ืฆืœืขื›ืงื™ื™ื˜ ืื™ื ืกื˜ืืœื™ืจื˜ ืื™ืŸ ื“ืขืจ ื–ืึทืžื“ืงืึทืกื˜ืŸ ืกื‘ื™ื‘ื” ืื™ื– ื’ืขื•ื•ืึธืจืŸ ืขืจื–ืขืฆื˜ ืžื™ื˜ ื“ืขืจ fbwrap ืžื™ื˜ืœื•ื•ืขืจ, ื•ื•ืึธืก ืœืึธื ื˜ืฉื˜ ืคึผืจืึธื’ืจืึทืžืขืŸ ืึธืŸ ืกืึทื ื“ื‘ืึธืงืกื™ื ื’ ืฆื• ืกืึธืœื•ื•ืขืŸ ืคึผืจืึธื‘ืœืขืžืขืŸ ืžื™ื˜ Firefox, Thunderbird, ืื•ืŸ GIMP ืœืึธื ื˜ืฉื™ื ื’ ืฆื•ืœื™ื‘ glycin 2.0.0 ื•ื•ืึธืก ื•ื•ืขืจื˜ ื’ืขืจื•ืคืŸ ืคึฟื•ืŸ gdk-pixbuf2 ื ื™ืฆื ื“ื™ืง bwrap. ื“ื™ "--allow-bwrap" ืึธืคึผืฆื™ืข ืื™ื– ืฆื•ื’ืขื’ืขื‘ืŸ ื’ืขื•ื•ืึธืจืŸ ืฆื• ืงืึธืคึผื™ืจืŸ bwrap ืึทื ืฉื˜ืึธื˜ ื“ื™ ืžื™ื˜ืœื•ื•ืขืจ.
  • ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงื˜ ืกื™ืกื˜ืขื ืจื•ืฃ ื˜ืึทื‘ืขืœืขืก ืคึฟืึทืจ seccomp. ื ืฒึทืข ืกื™ืกื˜ืขื ืจื•ืคืŸ, ื•ื•ื™ epoll_pwait2 ืื•ืŸ futex_wait, ื–ืขื ืขืŸ ืฆื•ื’ืขื’ืขื‘ืŸ ื’ืขื•ื•ืึธืจืŸ.
  • ื“ื™ "--disable-globalcfg" ื‘ื™ืœื“ ืืคืฆื™ืข ืื™ื– ืืจืืคื’ืขื ื•ืžืขืŸ ื’ืขื•ื•ืืจืŸ, ืื•ืŸ ืฉื˜ื™ืฆืข ืคืืจ overlayfs ("--overlay") ืื•ืŸ IDS (Intrusion Detection System, "--ids") ืžืึธื“ื•ืก ืื™ื– ืืคื’ืขืฉื˜ืขืœื˜ ื’ืขื•ื•ืืจืŸ.
  • ืฆื•ื’ืขื’ืขื‘ืŸ ืื™ื–ืึธืœืึทืฆื™ืข ืคึผืจืึธื•ืคื™ื™ืœืŸ ืคึฟืึทืจ ื“ื™ ne ื˜ืขืงืกื˜ ืจืขื“ืึทืงื˜ืึธืจ (ื˜ืขืงืกื˜ ืจืขื“ืึทืงื˜ืึธืจ), ื˜ืจื™ื•ื•ืึทืœืขื ื˜ ื‘ืœืขื˜ืขืจืขืจ, โ€‹โ€‹ืื•ืŸ OpenRA, quakespasm, gzdoom, lzdoom, ืื•ืŸ uzdoom ืฉืคึผื™ืœ ืขื ื“ื–ืฉื™ื ืก.
  • ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงื˜ืข ืคึผืจืึธืคึฟื™ืœืŸ ืคึฟืึทืจ ื˜ืึทื ื“ืขืจื‘ืขืจื“, ื•ื•ื™ื™ืŸ, ืงื•ื•ื˜ืขื‘ืจืึทื•ื–ืขืจ, ืคึฟืฒึทืขืจืคึฟืึธืงืก, ื’ืึธื“ืึธื˜, ื•ื•ื•ืกืง, ืžื•ืœืฐืึทื“-ื‘ืจืึทื•ื–ืขืจ, ื‘ืœื™ื ืง, ืกื˜ื™ื, ssh, ื‘ืจื™ื™ื•ื• ืื•ืŸ ื”ืขืฉืงืึทื˜.

ืžืงื•ืจ: opennet.ru

ืงื•ื™ืคืŸ ืคืึทืจืœืึธื–ืœืขืš ื”ืึธืกื˜ื™ื ื’ ืคึฟืึทืจ ื–ื™ื™ื˜ืœืขืš ืžื™ื˜ DDoS ืฉื•ืฅ, VPS VDS ืกืขืจื•ื•ืขืจืก ๐Ÿ”ฅ ืงื•ื™ืคื˜ ืคืึทืจืœืขืกืœืขื›ืข ื•ื•ืขื‘ื–ื™ื™ื˜ืœ ื”ืึธืกื˜ื™ื ื’ ืžื™ื˜ DDoS ืฉื•ืฅ, VPS VDS ืกืขืจื•ื•ืขืจืก | ProHoster