execute: set PR_SET_NO_NEW_PRIVS also in case the exec memory protection is used
authorLennart Poettering <lennart@poettering.net>
Wed, 22 Jun 2016 23:33:07 +0000 (01:33 +0200)
committerLennart Poettering <lennart@poettering.net>
Wed, 22 Jun 2016 23:33:07 +0000 (01:33 +0200)
commit686d9ba614adfef22b1eedc6d1565e18e8778829
treeabbadf30732d5d8d643c944022e9b1b9fc3e2cad
parent03857c43ce099e50fbb78dd4b32eb75759b83ae0
execute: set PR_SET_NO_NEW_PRIVS also in case the exec memory protection is used

This was forgotten when MemoryDenyWriteExecute= was added: we should set NNP in
all cases when we set seccomp filters.
src/core/execute.c