| Name |
Last commit
|
Last update |
|---|---|---|
| .. | ||
| apparmor | ||
| bash | ||
| etc | ||
| init | ||
| selinux | ||
| sysconfig | ||
| templates | ||
| yum | ||
| Makefile.am | ||
| acinclude.m4 | ||
| ax_check_compile_flag.m4 | ||
| ax_check_link_flag.m4 | ||
| ax_pthread.m4 | ||
| tls.m4 |
RW bind mounts need to be restricted for some paths in
order to avoid MAC restriction bypasses, but read-only bind
mounts shouldn't have that problem.
Additionally, combinations of 'nosuid', 'nodev' and
'noexec' flags shouldn't be a problem either and are
required with newer systemd versions, so let's allow those
as long as they're combined with 'ro,remount,bind'.
Signed-off-by:
Wolfgang Bumiller <w.bumiller@proxmox.com>
| Name |
Last commit
|
Last update |
|---|---|---|
| .. | ||
| apparmor | Loading commit data... | |
| bash | Loading commit data... | |
| etc | Loading commit data... | |
| init | Loading commit data... | |
| selinux | Loading commit data... | |
| sysconfig | Loading commit data... | |
| templates | Loading commit data... | |
| yum | Loading commit data... | |
| Makefile.am | Loading commit data... | |
| acinclude.m4 | Loading commit data... | |
| ax_check_compile_flag.m4 | Loading commit data... | |
| ax_check_link_flag.m4 | Loading commit data... | |
| ax_pthread.m4 | Loading commit data... | |
| tls.m4 | Loading commit data... |