Lines 377-382
int mount_setup(bool loaded_policy) {
Link Here
|
377 |
nftw("/dev/shm", nftw_cb, 64, FTW_MOUNT|FTW_PHYS|FTW_ACTIONRETVAL); |
377 |
nftw("/dev/shm", nftw_cb, 64, FTW_MOUNT|FTW_PHYS|FTW_ACTIONRETVAL); |
378 |
nftw("/run", nftw_cb, 64, FTW_MOUNT|FTW_PHYS|FTW_ACTIONRETVAL); |
378 |
nftw("/run", nftw_cb, 64, FTW_MOUNT|FTW_PHYS|FTW_ACTIONRETVAL); |
379 |
|
379 |
|
|
|
380 |
/* Temporarily remount the root cgroup filesystem to give it a proper label. */ |
381 |
(void) mount("tmpfs", "/sys/fs/cgroup", "tmpfs", MS_REMOUNT|MS_NOSUID|MS_NOEXEC|MS_NODEV|MS_STRICTATIME, "mode=755"); |
382 |
label_fix("/sys/fs/cgroup", false, false); |
383 |
nftw("/sys/fs/cgroup", nftw_cb, 64, FTW_MOUNT|FTW_PHYS|FTW_ACTIONRETVAL); |
384 |
(void) mount("tmpfs", "/sys/fs/cgroup", "tmpfs", MS_REMOUNT|MS_NOSUID|MS_NOEXEC|MS_NODEV|MS_STRICTATIME|MS_RDONLY, "mode=755"); |
385 |
|
380 |
after_relabel = now(CLOCK_MONOTONIC); |
386 |
after_relabel = now(CLOCK_MONOTONIC); |
381 |
|
387 |
|
382 |
log_info("Relabelled /dev and /run in %s.", |
388 |
log_info("Relabelled /dev and /run in %s.", |