summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorLennart Poettering <lennart@poettering.net>2010-04-10 21:46:51 +0200
committerLennart Poettering <lennart@poettering.net>2010-04-10 21:46:51 +0200
commite8536954c58f66eb4ab47596c6b39f12f20da42a (patch)
tree3e6d0ac98493c210e5b81a9fed38f3cb16bb9ab0
parent18149b9f57f8971ebc7d6401fc0a08a3173bcb29 (diff)
downloadsystemd-e8536954c58f66eb4ab47596c6b39f12f20da42a.tar.gz
mount-setup: disable device, execution, suid on device file systems
-rw-r--r--mount-setup.c4
1 files changed, 2 insertions, 2 deletions
diff --git a/mount-setup.c b/mount-setup.c
index 8cb77669f3..8ad37f860b 100644
--- a/mount-setup.c
+++ b/mount-setup.c
@@ -43,8 +43,8 @@ enum {
static const char *table[] = {
"proc", "/proc", "proc", NULL,
"sysfs", "/sys", "sysfs", NULL,
- "devtmps", "/dev", "devtmpfs", "mode=755",
- "tmpfs", "/dev/shm", "tmpfs", "mode=1777",
+ "devtmps", "/dev", "devtmpfs", "mode=755,noexec,nosuid",
+ "tmpfs", "/dev/shm", "tmpfs", "mode=1777,nodev,noexec,nosuid",
"devpts", "/dev/pts", "devpts", NULL,
"cgroup", "/cgroup/debug", "cgroup", "debug",
"debugfs", "/sys/kernel/debug", "debugfs", NULL,