ื ื ื™ื™ึทืข ื‘ื•ื™ืขืŸ ืคื•ืŸ Slackware ืื™ื– ืฆื•ื’ืขื’ืจื™ื™ื˜ ื•ื•ื™ ืึท ื˜ื™ื™ืœ ืคื•ืŸ ื“ื™ TinyWare ืคึผืจื•ื™ืขืงื˜

ืคึผืจืึธื™ืขืงื˜ ืึทืกืขืžื‘ืœื™ื– ื–ืขื ืขืŸ ืฆื•ื’ืขื’ืจื™ื™ื˜ TinyWare, ื‘ืื–ื™ืจื˜ ืื•ื™ืฃ ื“ื™ 32-ื‘ื™ืกืœ ื•ื•ืขืจืกื™ืข ืคื•ืŸ โ€‹โ€‹โ€‹โ€‹Slackware-Current ืื•ืŸ ืฉื™ืคึผื˜ ืžื™ื˜ 32- ืื•ืŸ 64-ื‘ื™ืกืœ ื•ื•ืขืจื™ืึทื ืฅ ืคื•ืŸ ื“ื™ Linux 4.19 ืงืขืจืŸ. ื’ืจื™ื™ืก ื™ืกืึธ ื‘ื™ืœื“ 800 ืžืขื’ืื‘ื™ื™ื˜ืŸ.

ื”ื•ื™ืคึผื˜ ืขื ื“ืขืจื•ื ื’ืขืŸ, ืงืึทืžืคึผืขืจื“ ืžื™ื˜ ื“ืขืจ ืึธืจื™ื’ื™ื ืขืœ Slackware:

  • ื™ื™ึทื ืžืึธื ื˜ื™ืจื•ื ื’ ืื•ื™ืฃ 4 ืคึผืึทืจื˜ื™ืฉืึทื ื– "/", "/ ืฉื˜ื™ื•ื•ืœ", "/ ื•ื•ืึทืจ" ืื•ืŸ "/ ื”ื™ื™ื". ื“ื™ "/" ืื•ืŸ "/ ืฉื˜ื™ื•ื•ืœ" ืคึผืึทืจื˜ื™ืฉืึทื ื– ื–ืขื ืขืŸ ืžืึธื•ื ื˜ืขื“ ืื™ืŸ ืœื™ื™ืขื ืขืŸ-ื‘ืœื•ื™ื– ืžืึธื“ืข, ืื•ืŸ "/ ื”ื™ื™ื" ืื•ืŸ "/ ื•ื•ืึทืจ" ื–ืขื ืขืŸ ืžืึธื•ื ื˜ืขื“ ืื™ืŸ ื ืึธืขืงืกืขืง ืžืึธื“ืข;
  • ืงืขืจื ืขืœ ืœืึทื˜ืข CONFIG_SETCAP. ื“ื™ ืกืขื˜ืงืึทืคึผ ืžืึธื“ื•ืœืข ืงืขื ืขืŸ ื“ื™ืกื™ื™ื‘ืึทืœ ืกืคึผืขืกื™ืคื™ืขื“ ืกื™ืกื˜ืขื ืงื™ื™ืคึผืึทื‘ื™ืœืึทื˜ื™ื– ืึธื“ืขืจ ื’ืขื‘ืŸ ื–ื™ื™ ืคึฟืึทืจ ืึทืœืข ื™ื•ื–ืขืจื–. ื“ืขืจ ืžืึธื“ื•ืœืข ืื™ื– ืงืึทื ืคื™ื’ื™ืขืจื“ ื“ื•ืจืš ื“ื™ ืกื•ืคึผืขืจื•ืกืขืจ ื‘ืฉืขืช ื“ื™ ืกื™ืกื˜ืขื ืื™ื– ืคืœื™ืกื ื“ื™ืง ื“ื•ืจืš ื“ื™ sysctl ืฆื•ื‘ื™ื ื“ ืึธื“ืขืจ /proc/sys/setcap ื˜ืขืงืขืก ืื•ืŸ ืงืขื ืขืŸ ื–ื™ื™ืŸ ืคืึทืจืคืจื•ื™ืจืŸ ืคื•ืŸ ืžืื›ืŸ ืขื ื“ืขืจื•ื ื’ืขืŸ ื‘ื™ื– ื“ืขืจ ื•ื•ื™ื™ึทื˜ืขืจ ืจืขื‘ืึธืึธื˜.
    ืื™ืŸ ื ืึธืจืžืึทืœ ืžืึธื“ืข, CAP_CHOWN(0), CAP_DAC_OVERRIDE(1), CAP_DAC_READ_SEARCH(2), CAP_FOWNER(3) ืื•ืŸ 21(CAP_SYS_ADMIN) ื–ืขื ืขืŸ ืคืึทืจืงืจื™ืคึผืœื˜ ืื™ืŸ ื“ื™ ืกื™ืกื˜ืขื. ื“ื™ ืกื™ืกื˜ืขื ืื™ื– ืื•ืžื’ืขืงืขืจื˜ ืฆื• ื–ื™ื™ืŸ ื ืึธืจืžืึทืœ ืฉื˜ืึทื˜ ืžื™ื˜ ื“ื™ ื˜ื™ื™ื ื™ื•ื•ืึทืจืข-ื‘ืขืคืึธืจืขื“ืžื™ืŸ ื‘ืึทืคึฟืขืœ (ืžืึทื•ื ื˜ื™ื ื’ ืื•ืŸ ืงื™ื™ืคึผืึทื‘ื™ืœืึทื˜ื™ื–). ื‘ืึทื–ื™ืจื˜ ืื•ื™ืฃ ื“ื™ ืžืึธื“ื•ืœืข, ืื™ืจ ืงืขื ืขืŸ ืึทื ื˜ื•ื•ื™ืงืœืขืŸ ื“ื™ ื›ืึทืจื ืึทืก ืคื•ืŸ ื–ื™ื›ืขืจ ืœืขื•ื•ืขืœืก.

  • ืงืึธืจ ืœืึทื˜ืข PROC_RESTRICT_ACCESS. ื“ืขืจ ืึธืคึผืฆื™ืข ืœื™ืžืึทืฅ ืึทืงืกืขืก ืฆื• ื“ื™ /proc/pid ื“ื™ืจืขืงื˜ืขืจื™ื– ืื™ืŸ ื“ื™ /proc ื˜ืขืงืข ืกื™ืกื˜ืขื ืคึฟื•ืŸ 555 ืฆื• 750, ื‘ืฉืขืช ื“ื™ ื’ืจื•ืคึผืข ืคื•ืŸ โ€‹โ€‹โ€‹โ€‹ืึทืœืข ื“ื™ืจืขืงื˜ืขืจื™ื– ืื™ื– ืึทืกื™ื™ื ื“ ืฆื• ื•ื•ืึธืจืฆืœ. ื“ืขืจื™ื‘ืขืจ, ื ื™ืฆืขืจืก ื–ืขืŸ ื‘ืœื•ื™ื– ื–ื™ื™ืขืจ ืคึผืจืึทืกืขืกืึทื– ืžื™ื˜ ื“ื™ "ืคึผืก" ื‘ืึทืคึฟืขืœ. ื•ื•ืึธืจืฆืœ ื ืึธืš ื–ืขื˜ ืึทืœืข ืคึผืจืึทืกืขืกืึทื– ืื™ืŸ ื“ื™ ืกื™ืกื˜ืขื.
  • CONFIG_FS_ADVANCED_CHOWN ืงืขืจืŸ ืœืึทื˜ืข ืฆื• ืœืึธื–ืŸ ืจืขื’ื•ืœืขืจ ื ื™ืฆืขืจืก ืฆื• ื˜ื•ื™ืฉืŸ ืึธื•ื ืขืจืฉื™ืคึผ ืคื•ืŸ ื˜ืขืงืขืก ืื•ืŸ ืกื•ื‘ื“ื™ืจืขืงื˜ืึธืจื™ืขืก ืื™ืŸ ื–ื™ื™ืขืจ ื“ื™ืจืขืงื˜ืขืจื™ื–.
  • ืขื˜ืœืขื›ืข ืขื ื“ืขืจื•ื ื’ืขืŸ ืฆื• ืคืขืœื™ืงื™ื™ึทื˜ ืกืขื˜ื˜ื™ื ื’ืก (ืœืžืฉืœ UMASK ืฉื˜ืขืœืŸ ืฆื• 077).

ืžืงื•ืจ: opennet.ru

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’