Comment 10 for bug 1881006

Revision history for this message
Steve Langasek (vorlon) wrote : Re: [Bug 1881006] Re: Incorrect ESP mount options

> however ESP are not system files. None of them are registered with dpkg
> for example, they are all installed/modified via additional tooling.

I don't consider "registered in the dpkg database" to be the relevant
measure of whether a file is a system file.

> On my machine I see Dell firmware storing diagnostic logs on the ESP,
> disclosing sensitive information around hardware state, that normally a
> non-root user would not be able to find out.

This, however, is persuasive. Of course the ESP can only have one set of
permissions for all files present, so the security settings need to be as
strict as required for the most sensitive files that may be present.