mirror of
https://github.com/Kicksecure/security-misc.git
synced 2025-04-26 08:39:12 -04:00
41 lines
2.5 KiB
Plaintext
41 lines
2.5 KiB
Plaintext
# <file system> <mount point> <type> <options> <dump> <pass>
|
|
|
|
/dev/disk/by-uuid/26ada0c0-1165-4098-884d-aafd2220c2c6 / auto nofail,defaults,errors=remount-ro 0 1
|
|
|
|
proc /proc proc nofail,defaults 0 0
|
|
|
|
/dev /dev devtmpfs nofail,bind,remount,nosuid,noexec 0 0
|
|
#udev /dev devtmpfs defaults,nosuid,noexec 0 0
|
|
|
|
## noexec optional
|
|
/dev/shm /dev/shm tmpfs nofail,nosuid,nodev,noexec 0 0
|
|
#tmpfs /dev/shm tmpfs defaults,nosuid,nodev,noexec 0 0
|
|
|
|
## nodev,nosuid,noexec as per:
|
|
## https://www.debian.org/doc/manuals/securing-debian-manual/ch04s10.en.html
|
|
## Commented out by default to prevent warning:
|
|
## mount: /mnt/cdrom: mount point does not exist.
|
|
#/dev/cdrom /mnt/cdrom iso9660 nofail,ro,users,nodev,nosuid,noexec 0 0
|
|
|
|
/boot /boot none nofail,bind,nosuid,nodev,noexec 0 0
|
|
|
|
## noexec optional
|
|
/tmp /tmp tmpfs nofail,bind,nosuid,nodev,noexec 0 0
|
|
#tmpfs /tmp tmpfs defaults,nodev,nosuid,noexec 0 0
|
|
|
|
/var /var none nofail,bind,nosuid,nodev 0 0
|
|
|
|
## noexec optional
|
|
/var/tmp /var/tmp none nofail,bind,nosuid,nodev,noexec 0 0
|
|
|
|
/var/log /var/log none nofail,bind,nosuid,nodev,noexec 0 0
|
|
|
|
## noexec optional
|
|
/run /run none nofail,bind,nosuid,nodev,noexec 0 0
|
|
|
|
## noexec optional
|
|
/home /home none nofail,bind,nosuid,nodev,noexec 0 0
|
|
|
|
## TODO:
|
|
#/sys
|