From: Lennart Poettering Date: Sat, 10 Apr 2010 19:46:51 +0000 (+0200) Subject: mount-setup: disable device, execution, suid on device file systems X-Git-Tag: v1~551 X-Git-Url: https://www.chiark.greenend.org.uk/ucgi/~ianmdlvl/git?p=elogind.git;a=commitdiff_plain;h=e8536954c58f66eb4ab47596c6b39f12f20da42a mount-setup: disable device, execution, suid on device file systems --- diff --git a/mount-setup.c b/mount-setup.c index 8cb77669f..8ad37f860 100644 --- a/mount-setup.c +++ b/mount-setup.c @@ -43,8 +43,8 @@ enum { static const char *table[] = { "proc", "/proc", "proc", NULL, "sysfs", "/sys", "sysfs", NULL, - "devtmps", "/dev", "devtmpfs", "mode=755", - "tmpfs", "/dev/shm", "tmpfs", "mode=1777", + "devtmps", "/dev", "devtmpfs", "mode=755,noexec,nosuid", + "tmpfs", "/dev/shm", "tmpfs", "mode=1777,nodev,noexec,nosuid", "devpts", "/dev/pts", "devpts", NULL, "cgroup", "/cgroup/debug", "cgroup", "debug", "debugfs", "/sys/kernel/debug", "debugfs", NULL,