From 5444dd98c769e3597681ae10c7f65a999f84eff5 Mon Sep 17 00:00:00 2001 From: Lennart Poettering Date: Fri, 2 Mar 2018 12:55:24 +0100 Subject: [PATCH] mount-setup: change bpf mount mode to 0700 (#8334) After discussing with the kernel folks, we agreed to default to 0700 for this. Better safe than sorry. --- src/core/mount-setup.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/core/mount-setup.c b/src/core/mount-setup.c index 7786e22ca..8fb0a1dea 100644 --- a/src/core/mount-setup.c +++ b/src/core/mount-setup.c @@ -124,7 +124,7 @@ static const MountPoint mount_table[] = { { "efivarfs", "/sys/firmware/efi/efivars", "efivarfs", NULL, MS_NOSUID|MS_NOEXEC|MS_NODEV, is_efi_boot, MNT_NONE }, #endif - { "bpf", "/sys/fs/bpf", "bpf", NULL, MS_NOSUID|MS_NOEXEC|MS_NODEV, + { "bpf", "/sys/fs/bpf", "bpf", "mode=700", MS_NOSUID|MS_NOEXEC|MS_NODEV, NULL, MNT_NONE, }, #else { "cgroup", "/sys/fs/cgroup/elogind", "cgroup", "none,name=elogind,release_agent="SYSTEMD_CGROUP_AGENT_PATH",xattr", MS_NOSUID|MS_NOEXEC|MS_NODEV, -- 2.30.2