aboutsummaryrefslogtreecommitdiffstats
path: root/etc/inc/disable-exec.inc
diff options
context:
space:
mode:
Diffstat (limited to 'etc/inc/disable-exec.inc')
-rw-r--r--etc/inc/disable-exec.inc11
1 files changed, 11 insertions, 0 deletions
diff --git a/etc/inc/disable-exec.inc b/etc/inc/disable-exec.inc
new file mode 100644
index 000000000..ee3391730
--- /dev/null
+++ b/etc/inc/disable-exec.inc
@@ -0,0 +1,11 @@
1# This file is overwritten during software install.
2# Persistent customizations should go in a .local file.
3include disable-exec.local
4
5noexec ${HOME}
6noexec ${RUNUSER}
7noexec /dev/shm
8noexec /tmp
9# /var is noexec by default for unprivileged users
10# except there is a writable-var option, so just in case:
11noexec /var