| #
1.2 |
|
04-May-2005 |
hubertf |
No devices on /usr -> mount -o nodev No setuid programs in /var -> mount -o nodev,nosuid
Adding "noexec" in various places may cause too much damage (e.g. for running DEINSTALL scripts from /var/db/pkg, configure scripts, etc).
Inspired by OpenBSD's afterboot(8) manpage.
|