none /proc proc defaults,noauto,hidepid=2,gid=17 0 0
none /sys sysfs defaults,noauto,gid=17 0 0
none /sys/fs/cgroup tmpfs noauto,nosuid,nodev,noexec,mode=755 0 0
-none /proc/bus/usb usbfs defaults,noauto,devgid=78,devmode=0664 0 0
-none /sys/kernel/debug debugfs defaults,noauto 0 0
+none /proc/bus/usb usbfs noauto,devgid=78,devmode=0664 0 0
+none /sys/kernel/debug debugfs noauto,nodev,noexec 0 0
+none /sys/firmware/efi/efivars efivarfs noauto,nosuid,nodev,noexec 0 0
+
devpts /dev/pts devpts gid=5,mode=620 0 0
none /dev/shm tmpfs mode=1777,nosuid,nodev,noexec 0 0