core20 icon indicating copy to clipboard operation
core20 copied to clipboard

static/writable-paths: set safer options for tmpfs mounts

Open alfonsosanchezbeato opened this issue 2 years ago • 1 comments

Set safer options for mount points backed by tmpfs, so we make sure that nosuid,nodev are set. The options are the default ones recommended by systemd (see /usr/share/systemd/tmp.mount) and we were actually using them already for /tmp in the initramfs.

alfonsosanchezbeato avatar Nov 26 '21 14:11 alfonsosanchezbeato

I've removed the change for /var/lib/sudo as anyway that folder can be used only by root.

alfonsosanchezbeato avatar Nov 29 '21 08:11 alfonsosanchezbeato