mirror of
https://github.com/vincentmli/bpfire.git
synced 2026-04-12 20:16:49 +02:00
Core Update 170: Harden mount options of /boot on existing installations
The second version of this patch uses @ instead of / for sed delimiters, which makes the command less hard to read. Since Core Update 170 already requires a reboot at this point, the respective directive is omitted. Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
This commit is contained in:
@@ -123,6 +123,9 @@ sed -i /etc/collectd.conf \
|
||||
/etc/init.d/rc.d/unbound start
|
||||
/etc/init.d/rc.d/suricata restart
|
||||
|
||||
# Harden mount options of /boot
|
||||
sed -e -i "s@[[:space:]]*\/boot[[:space:]]*auto[[:space:]]*defaults[[:space:]]*@ \/boot auto defaults,nodev,noexec,nosuid @g" /etc/fstab
|
||||
|
||||
# This update needs a reboot...
|
||||
touch /var/run/need_reboot
|
||||
|
||||
|
||||
Reference in New Issue
Block a user