Volume 142 November, 2018 Firejail: Easy Sandbox on Pclinuxos
Total Page:16
File Type:pdf, Size:1020Kb
Volume 142 November, 2018 Firejail: Easy Sandbox On PCLinuxOS GIMP Tutorial: How To Apply A Sepia Tone Short Topix: Linux Is Changing The Face Of End-User Computing PCLinuxOS Family Member Spotlight: Martin Goose ANGRYsearch Microsoft Open Sources 60,000 Patents To Help Linux The Death Bell Tolls For G+ ms_meme's Nook: I Just Care For PCLinuxOS PCLinuxOS Recipe Corner: Mini Mozzarella Stuffed Turkey Zucchini Meatball Orechiette And more inside ... In This Issue... 3 From The Chief Editor's Desk 4 Firejail, Easy Sandbox On PCLinuxOS The PCLinuxOS name, logo and colors are the trademark of 7 Screenshot Showcase Texstar. 8 Short Topix: The PCLinuxOS Magazine is a monthly online publication containing PCLinuxOS-related materials. It is published Linux Is Changing The Face Of End-User Computing primarily for members of the PCLinuxOS community. The magazine staff is comprised of volunteers from the 15 GIMP Tutorial: How To Apply A Sepia Tone PCLinuxOS community. 17 Screenshot Showcase Visit us online at http://www.pclosmag.com 18 ms_meme's Nook: Booting From Both Sides This release was made possible by the following volunteers: 19 PCLinuxOS Family Member Spotlight: Martin Goose Chief Editor: Paul Arnote (parnote) Assistant Editor: Meemaw 21 Screenshot Showcase Artwork: Sproggy, Timeth, ms_meme, Meemaw Magazine Layout: Paul Arnote, Meemaw, ms_meme 22 Microsoft Open Sources Over 60,000 Patents HTML Layout: YouCanToo To Help Linux Staff: ms_meme CgBoy 23 Screenshot Showcase Meemaw YouCanToo Gary L. Ratliff, Sr. Pete Kelly 25 PCLinuxOS Recipe Corner Daniel Meiß-Wilhelm phorneker daiashi Khadis Thok 26 ANGRYsearch Alessandro Ebersol Smileeb 27 Screenshot Showcase Contributors: 28 The Death Bell Tolls For Google+ 30 ms_meme's Nook: I Just Care For PCLinuxOS 31 Screenshot Showcase The PCLinuxOS Magazine is released under the Creative 32 PCLinuxOS Bonus Recipe Corner Commons Attribution-NonCommercial-Share-Alike 3.0 Unported license. Some rights are reserved. 33 PCLinuxOS Puzzled Partitions Copyright © 2018. 37 More Screenshot Showcase PCLinuxOS Magazine Page 2 From The Chief Editor's Desk … Since I’ve never had the Around my part of the world, through a minefield littered with unexploded opportunity to travel outside of it will wear you down. And ordnance. the U.S., I haven’t quick. I started noticing it not experienced the world outside long after it reared its ugly I appreciate when someone is direct and honest of the U.S. bubble, so to head. I was working night about things with me. But then again, that’s how speak. But, I do know that for shift at the hospital then, and things were when I grew up. You were expected to the past two decades here in we had victims of a motor deal with the truth, however raw it may be or the U.S., there has been a vehicle accident coming in by regardless of how bad it made you feel. But in war waged. It’s a cultural war, ambulance to the emergency today’s PC world, we’re more concerned about of sorts. It’s a war of words. room. I made the “mistake” someone’s feelings than with being truthful. Back And … it’s exhausting! of calling it a motor vehicle then, learning to deal with one’s shortcomings and accident. I was quickly human frailties built character. It taught you It’s called “political corrected by one of the PC perseverance, and allowed for personal correctness,” PC for short. police. “It’s a motor vehicle introspection on how you might be able to improve There are an awful lot of collision, not a motor vehicle on those shortcomings to become a better person. people who want to see it go accident,” the PC minded away. A recent poll (PDF, 160 person stated. “By calling it But today, people don’t seem to be interested in pages), called “Hidden Tribes: an accident, it sounds like becoming a better person. Each little camp wants all A Study of America’s you’re trying to place blame.” the other camps to bend to their will and way of Polarized Landscape,” shows thinking. Tolerance is nonexistent. For each, it’s that 80% of Americans are Say WHAT? either their way or the highway. It’s little to no tired of political correctness, wonder why we can’t come together on even the and wish that it would go That was my reaction then, simplest, most basic challenges facing us. Division away. Young, old, liberal, and it remains my reaction has become the new norm, and that division is firmly conservative, rich, poor … now. An accident is an rooted in the PC culture. there seems to be agreement accident. It is what it is. It on at least this. doesn’t help that I’ve never ************** really been good at “sugar It didn’t take me very long to coating” things. I tend more This month’s cover image is by Randi Hausken of discover that this to just state things the way Bærum, Norway, and is used under the Creative “phenomenon” has tentacles they are. Facts are facts. You Commons Attribution-Share Alike 2.0 Generic that reach far and wide, can sugar coat any kind of license. The image was found on Wikimedia across international borders. I found one article from excrement you want all you want, but it will still taste Commons. the Daily Mail in the U.K. (it didn’t require too much like excrement when or if you take a bite. searching) that talks about the PC madness. Until next month, I bid you peace, happiness, Ironically, most of the examples cited seemed to be The PC movement has gone to extremes. It’s insane serenity and prosperity. And please … be kind to one from the U.S., where the PC madness has turned and impossible. There’s hardly anything you can say another. Or at least agree to disagree … and move into PC insanity. that doesn’t offend someone, somewhere, no matter along to more productive endeavors. how careful you are. It’s like walking on eggshells PCLinuxOS Magazine Page 3 Firejail: Easy Sandbox On PCLinuxOS by Alessandro Ebersol (Agent Smith) of the 3.x kernel or later. The sandbox is lightweight, Thus, each of these namespaces acts in a way to the overhead is low. There are no complicated create a capsule, where an application can be configuration files to edit, no open socket encapsulated and have the illusion that only it has all connection, no daemon running in the background. the resources of the system. All security features are implemented directly in the Linux kernel and are available on any Linux I will not dwell too much on each one of the computer. The program is released under GPL v2 namespaces components, since it is not the scope license. of this text, but, to speak about Firejail. If you are interested in delving into the namespaces, I suggest To understand how it works we have to analyze what reading this article. are the namespaces and what is sec-comp-bpf. Seccomp-bpf Protecting environments on Linux is one of the most Namespaces notable features of the operating system. One of the Seccomp-bpf stands for secure computing mode. It best known techniques is the Chroot, a virtual Much is said about containers. In fact, it is one of is a simple but effective sandbox simulation tool environment created to run applications safely. But today's hot technologies, since it allows the creation introduced in the Linux 3.5 kernel. It allows the user Chroot is quite complicated to set up, and its use is of extremely simple virtual machines. The abstract to connect a system call filter (syscall) to a process not that easy. But let's say you need features like the purpose of containers is actually to provide a group and all its descendants, thus reducing the attack ones Chroot can offer, as a security solution for your of processes with the illusion that they are the only surface of the kernel. Seccomp filters are expressed desktop. How to achieve it? Have all the trouble processes in the system. When deployed, this in the Berkeley Packet Filter (BPF) format. setting up Chroot for everyday situations? In fact, feature has the potential to deliver many practical there is already an easy solution to security benefits, such as light virtualization and problems in Linux, which is called Firejail. checkpoint/restore. Resources To give processes in a container the illusion that • Linux namespaces: The main technology behind What does Firejail do? there are no other processes in the system, several FireJail is Linux Namespaces. This lightweight global system resources must be involved in technology is the first step to isolate the Firejail uses the implementation of namespaces and abstractions that make it appear that each container application. sec-comp-bpf on Linux to create isolation between has its own resource instance. This has been applications, the file system, and the operating achieved with the addition of "namespaces" to • Filesystem container: The application containers system's resources, creating a sandbox that various global resources. Each namespace provides are created automatically when the sandbox is effectively isolates applications from the operating an isolated view of a specific global resource for the started and destroyed when the sandbox is closed. system. It allows a process and all its spawns to set of processes that are members of this have their own particular view of the kernel namespace. The namespaces began to be • Security filters: The following security filters are resources, shared globally, such as the network implemented in the kernel 2.6.23 and have reached currently implemented - seccomp-bpf, protocol, stack, the process table, and the assembly table.