I think one problem with changing this in systemd is that generators are allowed to be placed in /run [1]. While mounting /run noexec would not affect interpreted generators like bash scripts, it would prevent binary executable generators from being placed in /run.
If we find it necessary, we could carry a delta for this in Ubuntu, but I am not sure this is a change upstream will accept.
I think one problem with changing this in systemd is that generators are allowed to be placed in /run [1]. While mounting /run noexec would not affect interpreted generators like bash scripts, it would prevent binary executable generators from being placed in /run.
If we find it necessary, we could carry a delta for this in Ubuntu, but I am not sure this is a change upstream will accept.
[1] https:/ /www.freedeskto p.org/software/ systemd/ man/systemd. generator. html