public inbox for development@lists.ipfire.org
 help / color / mirror / Atom feed
* [PATCH v2] Core Update 170: Harden mount options of /boot on existing installations
@ 2022-07-13 19:46 Peter Müller
  2022-07-13 19:48 ` Peter Müller
  0 siblings, 1 reply; 8+ messages in thread
From: Peter Müller @ 2022-07-13 19:46 UTC (permalink / raw)
  To: development

[-- Attachment #1: Type: text/plain, Size: 953 bytes --]

The second version of this patch uses @ instead of / for sed delimiters,
which makes the command less hard to read. Since Core Update 170 already
requires a reboot at this point, the respective directive is omitted.

Signed-off-by: Peter Müller <peter.mueller(a)ipfire.org>
---
 config/rootfiles/core/170/update.sh | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/config/rootfiles/core/170/update.sh b/config/rootfiles/core/170/update.sh
index 7dde03060..78a4709bc 100644
--- a/config/rootfiles/core/170/update.sh
+++ b/config/rootfiles/core/170/update.sh
@@ -110,6 +110,9 @@ chown nobody:nobody /var/lib/ipblocklist
 # Start services
 /etc/init.d/rc.d/unbound start
 
+# Harden mount options of /boot
+sed -e -i "s@[[:space:]]*\/boot[[:space:]]*auto[[:space:]]*defaults[[:space:]]*@ \/boot    auto defaults,nodev,noexec,nosuid   @g" /etc/fstab
+
 # This update needs a reboot...
 touch /var/run/need_reboot
 
-- 
2.35.3

^ permalink raw reply	[flat|nested] 8+ messages in thread

end of thread, other threads:[~2022-07-28 19:41 UTC | newest]

Thread overview: 8+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2022-07-13 19:46 [PATCH v2] Core Update 170: Harden mount options of /boot on existing installations Peter Müller
2022-07-13 19:48 ` Peter Müller
2022-07-14  9:34   ` Michael Tremer
2022-07-14 10:15     ` Peter Müller
2022-07-14 10:17       ` Michael Tremer
2022-07-14 10:19         ` Peter Müller
2022-07-28 13:29           ` Peter Müller
2022-07-28 19:41             ` Michael Tremer

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox