Commit eab570bc by Stéphane Graber

Revert "allow cgroupfs mounts under /sys/fs/cgroup"

This reverts commit 833bf9c2. This change wasn't actually safe and is now superseded by the cgns profile. Signed-off-by: 's avatarStéphane Graber <stgraber@ubuntu.com>
parent 6a814f48
...@@ -91,6 +91,5 @@ ...@@ -91,6 +91,5 @@
deny /sys/firmware/efi/efivars/** rwklx, deny /sys/firmware/efi/efivars/** rwklx,
deny /sys/kernel/security/** rwklx, deny /sys/kernel/security/** rwklx,
mount options=(move) /sys/fs/cgroup/cgmanager/ -> /sys/fs/cgroup/cgmanager.lower/, mount options=(move) /sys/fs/cgroup/cgmanager/ -> /sys/fs/cgroup/cgmanager.lower/,
mount fstype=cgroup -> /sys/fs/cgroup/**,
mount options=(ro, nosuid, nodev, noexec, remount, strictatime) -> /sys/fs/cgroup/, mount options=(ro, nosuid, nodev, noexec, remount, strictatime) -> /sys/fs/cgroup/,
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment