summaryrefslogtreecommitdiff
path: root/update-initramfs.8
diff options
context:
space:
mode:
authorBen Hutchings <benh@debian.org>2020-12-09 18:04:33 +0100
committerBen Hutchings <benh@debian.org>2020-12-09 18:04:33 +0100
commit33c10ef43b03dc6d9ee09a46c598f6ee34ad0b81 (patch)
treebae3423e766424450721eabc0e40a6f4e3a9698c /update-initramfs.8
parentcbbbb1b73e72124ba517325c51e0ea4bd7139104 (diff)
init: Mount /dev without the noexec option
This partially reverts commit eb98d2ea110b "init: /dev can be noexec and /run nodev". The noexec option broke v86d (which we have a specific workaround for), and could also be a problem for SGX support in future. Using noexec here doesn't provide a security benefit in a default Debian configuration, since there are other writable directories on filesystems not mounted with this option. Those are also writable by all users, not just uid 0. The mount options can be overridden by an entry for /dev in /etc/fstab (at least when booting with systemd). References: https://lore.kernel.org/linux-sgx/20201209000321.GA62845@kernel.org/T/ Signed-off-by: Ben Hutchings <benh@debian.org>
Diffstat (limited to 'update-initramfs.8')
0 files changed, 0 insertions, 0 deletions