@@ -1074,18 +1074,18 @@ static int mount_all(const char *dest, bool userns) {
10741074 } MountPoint ;
10751075
10761076 static const MountPoint mount_table [] = {
1077- { "proc" , "/proc" , "proc" , NULL , MS_NOSUID |MS_NOEXEC |MS_NODEV , true, true },
1078- { "/proc/sys" , "/proc/sys" , NULL , NULL , MS_BIND , true, true }, /* Bind mount first */
1079- { NULL , "/proc/sys" , NULL , NULL , MS_BIND |MS_RDONLY |MS_REMOUNT , true, true }, /* Then, make it r/o */
1080- { "sysfs" , "/sys" , "sysfs" , NULL , MS_RDONLY |MS_NOSUID |MS_NOEXEC |MS_NODEV , true, false },
1081- { "tmpfs" , "/sys/fs/cgroup" , "tmpfs" , "mode=755" , MS_NOSUID |MS_NOEXEC |MS_NODEV |MS_STRICTATIME , true, false },
1082- { "tmpfs" , "/dev" , "tmpfs" , "mode=755" , MS_NOSUID |MS_STRICTATIME , true, false },
1083- { "tmpfs" , "/dev/shm" , "tmpfs" , "mode=1777" , MS_NOSUID |MS_NODEV |MS_STRICTATIME , true, false },
1084- { "tmpfs" , "/run" , "tmpfs" , "mode=755" , MS_NOSUID |MS_NODEV |MS_STRICTATIME , true, false },
1085- { "tmpfs" , "/tmp" , "tmpfs" , "mode=1777" , MS_STRICTATIME , true, false },
1077+ { "proc" , "/proc" , "proc" , NULL , MS_NOSUID |MS_NOEXEC |MS_NODEV , true, true },
1078+ { "/proc/sys" , "/proc/sys" , NULL , NULL , MS_BIND , true, true }, /* Bind mount first */
1079+ { NULL , "/proc/sys" , NULL , NULL , MS_BIND |MS_RDONLY |MS_NOSUID | MS_NOEXEC | MS_NODEV | MS_REMOUNT , true, true }, /* Then, make it r/o */
1080+ { "sysfs" , "/sys" , "sysfs" , NULL , MS_RDONLY |MS_NOSUID |MS_NOEXEC |MS_NODEV , true, false },
1081+ { "tmpfs" , "/sys/fs/cgroup" , "tmpfs" , "mode=755" , MS_NOSUID |MS_NOEXEC |MS_NODEV |MS_STRICTATIME , true, false },
1082+ { "tmpfs" , "/dev" , "tmpfs" , "mode=755" , MS_NOSUID |MS_STRICTATIME , true, false },
1083+ { "tmpfs" , "/dev/shm" , "tmpfs" , "mode=1777" , MS_NOSUID |MS_NODEV |MS_STRICTATIME , true, false },
1084+ { "tmpfs" , "/run" , "tmpfs" , "mode=755" , MS_NOSUID |MS_NODEV |MS_STRICTATIME , true, false },
1085+ { "tmpfs" , "/tmp" , "tmpfs" , "mode=1777" , MS_STRICTATIME , true, false },
10861086#ifdef HAVE_SELINUX
1087- { "/sys/fs/selinux" , "/sys/fs/selinux" , NULL , NULL , MS_BIND , false, false }, /* Bind mount first */
1088- { NULL , "/sys/fs/selinux" , NULL , NULL , MS_BIND |MS_RDONLY |MS_REMOUNT , false, false }, /* Then, make it r/o */
1087+ { "/sys/fs/selinux" , "/sys/fs/selinux" , NULL , NULL , MS_BIND , false, false }, /* Bind mount first */
1088+ { NULL , "/sys/fs/selinux" , NULL , NULL , MS_BIND |MS_RDONLY |MS_NOSUID | MS_NOEXEC | MS_NODEV | MS_REMOUNT , false, false }, /* Then, make it r/o */
10891089#endif
10901090 };
10911091
0 commit comments