noexec on /dev/shm

Bill Nottingham notting at redhat.com
Tue Dec 14 19:09:51 UTC 2010


Miloslav Trmač (mitr at volny.cz) said: 
> So the design was to
> 1) change the setting in the C reimplementation

The design was to pick a default... it's actually been that way since the
initial implementation and that *is* the default on some other distributions.

It probably should be relnoted, sure.

> 2) add a new facility that will revert the setting to its original value

No, the facility is intended to apply fstab settings to any early mounted
filesystem, including filesystems mounted in initramfs, etc. This is
actually something that didn't exist before - for example, in earlier
Fedora releases, for some filesystems you were stuck with whatever
options rc.sysinit or dracut mounted them with, regardless of what's
in /etc/fstab.

Bill


More information about the devel mailing list