[OpenWrt-Devel] [PATCH procd] jail: Add MS_NODEV MS_NOEXEC MS_NOSUID mount options where needed

Etienne CHAMPETIER champetier.etienne at gmail.com
Thu Oct 8 16:01:44 EDT 2015


this completes fafbf7338ec8304f2a0ec0ba76048fba2c01c07e

Signed-off-by: Etienne CHAMPETIER <champetier.etienne at gmail.com>
---
 jail/jail.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/jail/jail.c b/jail/jail.c
index f459a5e..56dc9ca 100644
--- a/jail/jail.c
+++ b/jail/jail.c
@@ -193,11 +193,11 @@ static int build_jail_fs()
 	rmdir("/old");
 	if (opts.procfs) {
 		mkdir("/proc", 0755);
-		mount("proc", "/proc", "proc", MS_NOATIME, 0);
+		mount("proc", "/proc", "proc", MS_NOATIME | MS_NODEV | MS_NOEXEC | MS_NOSUID, 0);
 	}
 	if (opts.sysfs) {
 		mkdir("/sys", 0755);
-		mount("sysfs", "/sys", "sysfs", MS_NOATIME, 0);
+		mount("sysfs", "/sys", "sysfs", MS_NOATIME | MS_NODEV | MS_NOEXEC | MS_NOSUID, 0);
 	}
 	if (opts.ronly)
 		mount(NULL, "/", NULL, MS_RDONLY | MS_REMOUNT, 0);
-- 
1.9.1
_______________________________________________
openwrt-devel mailing list
openwrt-devel at lists.openwrt.org
https://lists.openwrt.org/cgi-bin/mailman/listinfo/openwrt-devel



More information about the openwrt-devel mailing list