noexec mount-option with selinux?

Marten Lehmann lehmann at cnm.de
Wed May 10 09:13:44 UTC 2006


Hello,

I would like to mount the /tmp directory with the noexec option, so that no
files can be executed directly from /tmp. But the problem is, that I don't
have a separate partition for /tmp. It would be useless to create one, because
the users on this system have strict quota limits, which wouldn't apply on a
separate /tmp partition.

Lots of example policies only show ways to restrict certain applications. But
is there a way to restrict access to the /tmp directory in general, too?

Regards
Marten





More information about the fedora-selinux-list mailing list