So if I understand this correctly, now instead of bricking the system it will just fuck up the bootloader, even if the bootloader is completely unrelated to the linux install you are `rm -rf /sys`ing. Since the useful efivars that set up bootloaders must be on the whitelist.
It's an improvement, but it seems like we should do this in addition to default mounting read only.
replies(1):