Comment 2 for bug 1991661

Revision history for this message
Nick Rosbrook (enr0n) wrote :

I think one problem with changing this in systemd is that generators are allowed to be placed in /run [1]. While mounting /run noexec would not affect interpreted generators like bash scripts, it would prevent binary executable generators from being placed in /run.

If we find it necessary, we could carry a delta for this in Ubuntu, but I am not sure this is a change upstream will accept.

[1] https://www.freedesktop.org/software/systemd/man/systemd.generator.html