MS_NOSUID|MS_NOEXEC|MS_NODEV, NULL, },
// Make /proc/sys read-only (except /proc/sys/net)
- { "/proc/sys", "proc/sys", "bind", MS_BIND|MS_REC, NULL, },
- { "/proc/sys/net", "proc/sys/net", "bind", MS_BIND|MS_REC, NULL, },
+ { "/proc/sys", "proc/sys", "bind", MS_BIND|MS_REC, NULL, },
+ { "/proc/sys/net", "proc/sys/net", "bind", MS_BIND|MS_REC, NULL, },
{ "/proc/sys", "proc/sys", "bind",
MS_BIND|MS_RDONLY|MS_NOSUID|MS_NOEXEC|MS_NODEV|MS_REMOUNT, NULL, },
// Deny write access to /proc/sysrq-trigger (can be used to restart the host)
- { "/proc/sysrq-trigger", "proc/sysrq-trigger", "bind", MS_BIND|MS_REC, NULL, },
+ { "/proc/sysrq-trigger", "proc/sysrq-trigger", "bind", MS_BIND|MS_REC, NULL, },
{ "/proc/sysrq-trigger", "proc/sysrq-trigger", "bind",
MS_BIND|MS_RDONLY|MS_NOSUID|MS_NOEXEC|MS_NODEV|MS_REMOUNT, NULL, },
// Make /proc/irq read-only
- { "/proc/irq", "proc/irq", "bind", MS_BIND|MS_REC, NULL, },
+ { "/proc/irq", "proc/irq", "bind", MS_BIND|MS_REC, NULL, },
{ "/proc/irq", "proc/irq", "bind",
MS_BIND|MS_RDONLY|MS_NOSUID|MS_NOEXEC|MS_NODEV|MS_REMOUNT, NULL, },
// Make /proc/bus read-only
- { "/proc/bus", "proc/bus", "bind", MS_BIND|MS_REC, NULL, },
+ { "/proc/bus", "proc/bus", "bind", MS_BIND|MS_REC, NULL, },
{ "/proc/bus", "proc/bus", "bind",
MS_BIND|MS_RDONLY|MS_NOSUID|MS_NOEXEC|MS_NODEV|MS_REMOUNT, NULL, },
// Bind-Mount /sys ready-only
- { "/sys", "sys", "bind", MS_BIND|MS_REC, NULL, },
+ { "/sys", "sys", "bind", MS_BIND|MS_REC, NULL, },
{ "/sys", "sys", "bind",
MS_BIND|MS_RDONLY|MS_NOSUID|MS_NOEXEC|MS_NODEV|MS_REMOUNT, NULL, },
// Create a new /dev
- { "pakfire_dev", "dev", "tmpfs", MS_NOSUID|MS_NOEXEC,
+ { "pakfire_dev", "dev", "tmpfs", MS_NOSUID|MS_NOEXEC,
"mode=0755,size=4m,nr_inodes=64k", },
- { "/dev/pts", "dev/pts", "bind", MS_BIND, NULL, },
+ { "/dev/pts", "dev/pts", "bind", MS_BIND, NULL, },
+
+ // Mount /dev/mqueue
+ { "mqueue", "dev/mqueue", "mqueue",
+ MS_NOSUID|MS_NOEXEC|MS_NODEV, NULL },
// Create a new /run
- { "pakfire_tmpfs", "run", "tmpfs", MS_NOSUID|MS_NOEXEC|MS_NODEV,
+ { "pakfire_tmpfs", "run", "tmpfs", MS_NOSUID|MS_NOEXEC|MS_NODEV,
"mode=755,size=4m,nr_inodes=1k", },
// The end