tree 4581d307b0448d6833af7718bab7db81ad8e19a5
parent 221c768c97d088bd81757885f63d70ff4aa5d339
author Nicholas Bishop <nicholasbishop@google.com> 1655159118 -0400
committer Chromeos LUCI <chromeos-scoped@luci-project-accounts.iam.gserviceaccount.com> 1656006503 +0000

installer: improve EFI system partition mount in postinst

The boot partition gets mounted on reven during postinst to install or
update the legacy and UEFI bootloaders. Update this code to set the
nodev, noexec, and nosuid flags to improve security. Also update the
code to use the mount and umount syscalls directly instead of invoking
/bin/mount and /bin/umount.

BUG=b:235873557
TEST=cros_workon_make --install --test chromeos-installer
TEST=build_image --board=reven
TEST=Run reven installer, verify it boots in both legacy and UEFI modes

Change-Id: Icd7c4e700999d02ba12faf79fd5eedf424d34ffc
Reviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/3702667
Commit-Queue: Nicholas Bishop <nicholasbishop@google.com>
Reviewed-by: Jae Hoon Kim <kimjae@chromium.org>
Reviewed-by: Mike Frysinger <vapier@chromium.org>
Reviewed-by: Jorge Lucangeli Obes <jorgelo@chromium.org>
Tested-by: Nicholas Bishop <nicholasbishop@google.com>
(cherry picked from commit 9b117f88ca3c79e07ac52ea5dd730823b94775e6)
Reviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform2/+/3721276
Auto-Submit: Nicholas Bishop <nicholasbishop@google.com>
