add filesystem hardening (mounting external filesystems read-only, nosuid, and so on)
[schsh.git] / schroot / schsh / schsh-hardening
1 # Describes how to re-mount some filesystems, if they happen to exist
2 # Format: Mount-Point <TAB> remount-options
3 /                               bind,ro,nosuid,noexec
4 /bin                    bind,ro,nosuid,nodev
5 /lib                    bind,ro,nosuid,nodev
6 /lib64                  bind,ro,nosuid,nodev
7 /usr/bin                bind,ro,nosuid,nodev
8 /usr/lib                bind,ro,nosuid,nodev
9 /usr/lib64              bind,ro,nosuid,nodev
10 /usr/share              bind,ro,nosuid,nodev
11 /usr/local/bin  bind,ro,nosuid,nodev
12 /data                   bind,rw,nosuid,nodev,noexec