Make /run nosuid,noexec

This was not sufficiently locked down.

Fix #720

Signed-off-by: Justin Cormack <justin.cormack@docker.com>
This commit is contained in:
Justin Cormack 2016-11-23 12:08:53 +00:00
parent f2b8beb0ee
commit 80c9cee485

View File

@ -1 +1 @@
tmpfs /run tmpfs defaults,nodev,relatime,size=10%,mode=755 0 0
tmpfs /run tmpfs defaults,nodev,nosuid,noexec,relatime,size=10%,mode=755 0 0