projects
/
oweals
/
procd.git
/ commitdiff
commit
grep
author
committer
pickaxe
?
search:
re
summary
|
shortlog
|
log
|
commit
| commitdiff |
tree
raw
|
patch
| inline |
side by side
(parent:
25b58f2
)
jail: Add MS_NODEV MS_NOEXEC MS_NOSUID mount options where needed
author
Etienne CHAMPETIER
<champetier.etienne@gmail.com>
Thu, 8 Oct 2015 20:01:44 +0000
(20:01 +0000)
committer
John Crispin
<blogic@openwrt.org>
Thu, 8 Oct 2015 16:19:02 +0000
(18:19 +0200)
this completes
fafbf7338ec8304f2a0ec0ba76048fba2c01c07e
Signed-off-by: Etienne CHAMPETIER <champetier.etienne@gmail.com>
jail/jail.c
patch
|
blob
|
history
diff --git
a/jail/jail.c
b/jail/jail.c
index f459a5ee6e798d71dbd7299c486b5ef0b980ac7f..56dc9cab7337d829e5b10b192cdb50fb04f3ef88 100644
(file)
--- a/
jail/jail.c
+++ b/
jail/jail.c
@@
-193,11
+193,11
@@
static int build_jail_fs()
rmdir("/old");
if (opts.procfs) {
mkdir("/proc", 0755);
- mount("proc", "/proc", "proc", MS_NOATIME, 0);
+ mount("proc", "/proc", "proc", MS_NOATIME
| MS_NODEV | MS_NOEXEC | MS_NOSUID
, 0);
}
if (opts.sysfs) {
mkdir("/sys", 0755);
- mount("sysfs", "/sys", "sysfs", MS_NOATIME, 0);
+ mount("sysfs", "/sys", "sysfs", MS_NOATIME
| MS_NODEV | MS_NOEXEC | MS_NOSUID
, 0);
}
if (opts.ronly)
mount(NULL, "/", NULL, MS_RDONLY | MS_REMOUNT, 0);