flash-images: Harden mount options of /boot
Commit Message
Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
---
lfs/flash-images | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
Comments
Reviewed-by: Michael Tremer <michael.tremer@ipfire.org>
> On 11 Jun 2022, at 07:47, Peter Müller <peter.mueller@ipfire.org> wrote:
>
> Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
> ---
> lfs/flash-images | 4 ++--
> 1 file changed, 2 insertions(+), 2 deletions(-)
>
> diff --git a/lfs/flash-images b/lfs/flash-images
> index 3cf81fb6d..8a033c310 100644
> --- a/lfs/flash-images
> +++ b/lfs/flash-images
> @@ -1,7 +1,7 @@
> ###############################################################################
> # #
> # IPFire.org - A linux based firewall #
> -# Copyright (C) 2007-2021 IPFire Team <info@ipfire.org> #
> +# Copyright (C) 2007-2022 IPFire Team <info@ipfire.org> #
> # #
> # This program is free software: you can redistribute it and/or modify #
> # it under the terms of the GNU General Public License as published by #
> @@ -167,7 +167,7 @@ endif
>
> # Create /etc/fstab
> printf "$(FSTAB_FMT)" "$$(blkid -o value -s UUID $(PART_BOOT))" "/boot" \
> - "auto" "defaults" 1 2 > $(MNThdd)/etc/fstab
> + "auto" "defaults,nodev,noexec,nosuid" 1 2 > $(MNThdd)/etc/fstab
> ifeq "$(EFI)" "1"
> printf "$(FSTAB_FMT)" "$$(blkid -o value -s UUID $(PART_EFI))" "/boot/efi" \
> "auto" "defaults" 1 2 >> $(MNThdd)/etc/fstab
> --
> 2.35.3
@@ -1,7 +1,7 @@
###############################################################################
# #
# IPFire.org - A linux based firewall #
-# Copyright (C) 2007-2021 IPFire Team <info@ipfire.org> #
+# Copyright (C) 2007-2022 IPFire Team <info@ipfire.org> #
# #
# This program is free software: you can redistribute it and/or modify #
# it under the terms of the GNU General Public License as published by #
@@ -167,7 +167,7 @@ endif
# Create /etc/fstab
printf "$(FSTAB_FMT)" "$$(blkid -o value -s UUID $(PART_BOOT))" "/boot" \
- "auto" "defaults" 1 2 > $(MNThdd)/etc/fstab
+ "auto" "defaults,nodev,noexec,nosuid" 1 2 > $(MNThdd)/etc/fstab
ifeq "$(EFI)" "1"
printf "$(FSTAB_FMT)" "$$(blkid -o value -s UUID $(PART_EFI))" "/boot/efi" \
"auto" "defaults" 1 2 >> $(MNThdd)/etc/fstab