mount.2: Minor fixes to Topi Miettinen's patch

Signed-off-by: Michael Kerrisk <mtk.manpages@gmail.com>
This commit is contained in:
Michael Kerrisk 2021-06-20 15:54:10 +12:00
parent a4173b878c
commit 9593da4de3
1 changed files with 7 additions and 3 deletions

View File

@ -220,9 +220,13 @@ Do not allow programs to be executed from this filesystem.
.TP
.B MS_NOSUID
Do not honor set-user-ID and set-group-ID bits or file capabilities
when executing programs from this filesystem. In addition, SELinux domain
transitions require permission nosuid_transition, which in turn needs
also policy capability nnp_nosuid_transition.
when executing programs from this filesystem.
In addition, SELinux domain
transitions require the permission
.IR nosuid_transition ,
which in turn needs
also the policy capability
.IR nnp_nosuid_transition .
.\" (This is a security feature to prevent users executing set-user-ID and
.\" set-group-ID programs from removable disk devices.)
.TP