mount options=(rw,bind) /sy[^s]*{,/**},
mount options=(rw,bind) /sys?*{,/**},
+ # allow various ro-bind-*re*-mounts
+ mount options=(ro,remount,bind),
+ mount options=(ro,remount,bind,nosuid),
+ mount options=(ro,remount,bind,noexec),
+ mount options=(ro,remount,bind,nodev),
+ mount options=(ro,remount,bind,nosuid,noexec),
+ mount options=(ro,remount,bind,noexec,nodev),
+ mount options=(ro,remount,bind,nodev,nosuid),
+ mount options=(ro,remount,bind,nosuid,noexec,nodev),
+
# allow moving mounts except for /proc, /sys and /dev
mount options=(rw,move) /[^spd]*{,/**},
mount options=(rw,move) /d[^e]*{,/**},
mount options=(rw,bind) /sy[^s]*{,/**},
mount options=(rw,bind) /sys?*{,/**},
+ # allow various ro-bind-*re*-mounts
+ mount options=(ro,remount,bind),
+ mount options=(ro,remount,bind,nosuid),
+ mount options=(ro,remount,bind,noexec),
+ mount options=(ro,remount,bind,nodev),
+ mount options=(ro,remount,bind,nosuid,noexec),
+ mount options=(ro,remount,bind,noexec,nodev),
+ mount options=(ro,remount,bind,nodev,nosuid),
+ mount options=(ro,remount,bind,nosuid,noexec,nodev),
+
# allow moving mounts except for /proc, /sys and /dev
mount options=(rw,move) /[^spd]*{,/**},
mount options=(rw,move) /d[^e]*{,/**},
mount options=(rw,move) /s[^y]*{,/**},
mount options=(rw,move) /sy[^s]*{,/**},
mount options=(rw,move) /sys?*{,/**},
-
" mount options=(rw,bind) /sy[^s]*{,/**},\n"
" mount options=(rw,bind) /sys?*{,/**},\n"
"\n"
-" # allow read-only bind-mounts of anything except /proc, /sys and /dev\n"
-" mount options=(ro,remount,bind) -> /[^spd]*{,/**},\n"
-" mount options=(ro,remount,bind) -> /d[^e]*{,/**},\n"
-" mount options=(ro,remount,bind) -> /de[^v]*{,/**},\n"
-" mount options=(ro,remount,bind) -> /dev/.[^l]*{,/**},\n"
-" mount options=(ro,remount,bind) -> /dev/.l[^x]*{,/**},\n"
-" mount options=(ro,remount,bind) -> /dev/.lx[^c]*{,/**},\n"
-" mount options=(ro,remount,bind) -> /dev/.lxc?*{,/**},\n"
-" mount options=(ro,remount,bind) -> /dev/[^.]*{,/**},\n"
-" mount options=(ro,remount,bind) -> /dev?*{,/**},\n"
-" mount options=(ro,remount,bind) -> /p[^r]*{,/**},\n"
-" mount options=(ro,remount,bind) -> /pr[^o]*{,/**},\n"
-" mount options=(ro,remount,bind) -> /pro[^c]*{,/**},\n"
-" mount options=(ro,remount,bind) -> /proc?*{,/**},\n"
-" mount options=(ro,remount,bind) -> /s[^y]*{,/**},\n"
-" mount options=(ro,remount,bind) -> /sy[^s]*{,/**},\n"
-" mount options=(ro,remount,bind) -> /sys?*{,/**},\n"
+" # allow various ro-bind-*re*-mounts\n"
+" mount options=(ro,remount,bind),\n"
+" mount options=(ro,remount,bind,nosuid),\n"
+" mount options=(ro,remount,bind,noexec),\n"
+" mount options=(ro,remount,bind,nodev),\n"
+" mount options=(ro,remount,bind,nosuid,noexec),\n"
+" mount options=(ro,remount,bind,noexec,nodev),\n"
+" mount options=(ro,remount,bind,nodev,nosuid),\n"
+" mount options=(ro,remount,bind,nosuid,noexec,nodev),\n"
"\n"
" # allow moving mounts except for /proc, /sys and /dev\n"
" mount options=(rw,move) /[^spd]*{,/**},\n"