1999-08-27 23:37:10 +00:00
|
|
|
# $FreeBSD$
|
1999-08-23 05:12:43 +00:00
|
|
|
#
|
2001-06-26 13:50:33 +00:00
|
|
|
# Please see the file src/etc/mtree/README before making changes to this file.
|
1993-06-20 13:41:45 +00:00
|
|
|
#
|
|
|
|
|
1994-09-19 01:40:40 +00:00
|
|
|
/set type=dir uname=root gname=wheel mode=0755
|
1995-05-17 09:31:17 +00:00
|
|
|
.
|
1998-09-19 18:50:27 +00:00
|
|
|
bin
|
1994-09-19 01:40:40 +00:00
|
|
|
..
|
1998-09-30 22:27:27 +00:00
|
|
|
boot
|
1999-03-10 03:33:17 +00:00
|
|
|
defaults
|
|
|
|
..
|
2014-09-03 21:59:07 +00:00
|
|
|
dtb
|
2019-02-07 18:54:25 +00:00
|
|
|
allwinner tags=package=runtime
|
|
|
|
..
|
2018-03-19 16:16:12 +00:00
|
|
|
overlays tags=package=runtime
|
|
|
|
..
|
2019-02-07 18:54:25 +00:00
|
|
|
rockchip tags=package=runtime
|
|
|
|
..
|
2014-09-03 21:59:07 +00:00
|
|
|
..
|
2021-03-06 01:57:50 +00:00
|
|
|
efi
|
|
|
|
..
|
2005-12-11 15:21:18 +00:00
|
|
|
firmware
|
|
|
|
..
|
2020-07-10 01:50:15 +00:00
|
|
|
loader.conf.d tags=package=bootloader
|
|
|
|
..
|
2018-02-13 17:42:10 +00:00
|
|
|
lua
|
|
|
|
..
|
2001-02-15 12:25:48 +00:00
|
|
|
kernel
|
|
|
|
..
|
|
|
|
modules
|
|
|
|
..
|
2019-02-18 01:57:47 +00:00
|
|
|
uboot
|
|
|
|
..
|
2007-04-08 23:59:39 +00:00
|
|
|
zfs
|
|
|
|
..
|
1998-09-30 22:27:27 +00:00
|
|
|
..
|
2003-03-11 11:14:34 +00:00
|
|
|
dev mode=0555
|
1994-09-19 01:40:40 +00:00
|
|
|
..
|
1995-05-17 09:31:17 +00:00
|
|
|
etc
|
2002-06-10 04:47:26 +00:00
|
|
|
X11
|
|
|
|
..
|
2018-12-13 12:58:42 +00:00
|
|
|
authpf
|
|
|
|
..
|
2014-08-17 09:44:42 +00:00
|
|
|
autofs
|
|
|
|
..
|
2003-10-26 19:09:12 +00:00
|
|
|
bluetooth
|
|
|
|
..
|
2016-10-31 18:20:12 +00:00
|
|
|
cron.d
|
|
|
|
..
|
1999-08-24 03:51:34 +00:00
|
|
|
defaults
|
|
|
|
..
|
2008-12-17 19:12:30 +00:00
|
|
|
devd
|
|
|
|
..
|
2014-02-21 07:26:49 +00:00
|
|
|
dma
|
|
|
|
..
|
2005-12-29 14:40:22 +00:00
|
|
|
gss
|
|
|
|
..
|
2020-12-21 22:36:31 +00:00
|
|
|
kyua tags=package=tests
|
2020-03-23 19:01:23 +00:00
|
|
|
..
|
1999-08-24 03:51:34 +00:00
|
|
|
mail
|
|
|
|
..
|
1995-05-17 09:31:17 +00:00
|
|
|
mtree
|
2004-07-21 10:14:10 +00:00
|
|
|
..
|
2014-05-20 03:00:20 +00:00
|
|
|
newsyslog.conf.d
|
|
|
|
..
|
2004-07-27 12:31:38 +00:00
|
|
|
ntp mode=0700
|
1995-05-17 09:31:17 +00:00
|
|
|
..
|
2001-12-05 21:11:24 +00:00
|
|
|
pam.d
|
|
|
|
..
|
2001-02-15 12:25:48 +00:00
|
|
|
periodic
|
|
|
|
daily
|
|
|
|
..
|
|
|
|
monthly
|
|
|
|
..
|
2001-12-07 23:57:39 +00:00
|
|
|
security
|
|
|
|
..
|
2001-02-15 12:25:48 +00:00
|
|
|
weekly
|
|
|
|
..
|
|
|
|
..
|
2013-10-26 16:19:14 +00:00
|
|
|
pkg
|
|
|
|
..
|
1995-05-17 09:31:17 +00:00
|
|
|
ppp
|
1994-09-19 01:40:40 +00:00
|
|
|
..
|
2014-08-23 10:51:37 +00:00
|
|
|
rc.conf.d
|
|
|
|
..
|
2001-06-22 07:26:08 +00:00
|
|
|
rc.d
|
|
|
|
..
|
2005-05-30 20:51:13 +00:00
|
|
|
security
|
|
|
|
..
|
2001-02-15 12:25:48 +00:00
|
|
|
ssh
|
|
|
|
..
|
|
|
|
ssl
|
|
|
|
..
|
2016-11-01 01:41:24 +00:00
|
|
|
syslog.d
|
|
|
|
..
|
2007-04-06 02:13:30 +00:00
|
|
|
zfs
|
2021-02-18 11:08:20 +00:00
|
|
|
compatibility.d
|
|
|
|
..
|
2007-04-06 02:13:30 +00:00
|
|
|
..
|
1994-09-19 01:40:40 +00:00
|
|
|
..
|
2003-08-17 07:48:09 +00:00
|
|
|
lib
|
2016-02-25 18:23:40 +00:00
|
|
|
casper
|
|
|
|
..
|
2004-05-20 10:29:26 +00:00
|
|
|
geom
|
|
|
|
..
|
2018-12-06 22:58:26 +00:00
|
|
|
nvmecontrol
|
|
|
|
..
|
2003-08-17 07:48:09 +00:00
|
|
|
..
|
|
|
|
libexec
|
2011-03-18 12:18:52 +00:00
|
|
|
resolvconf
|
|
|
|
..
|
2003-08-17 07:48:09 +00:00
|
|
|
..
|
2006-05-10 18:53:15 +00:00
|
|
|
media
|
|
|
|
..
|
1995-05-17 09:31:17 +00:00
|
|
|
mnt
|
1994-09-19 01:40:40 +00:00
|
|
|
..
|
2017-05-25 08:34:24 +00:00
|
|
|
net
|
|
|
|
..
|
1994-09-19 01:40:40 +00:00
|
|
|
proc mode=0555
|
|
|
|
..
|
2003-06-29 18:35:37 +00:00
|
|
|
rescue
|
|
|
|
..
|
Restrict default /root permissions
Remove world-readability from the root directory. Sensitive information may be
stored in /root and we diverge here from normative administrative practice, as
well as installation defaults of other Unix-alikes. The wheel group is still
permitted to read the directory.
750 is no more restrictive than defaults for the rest of the open source
Unix-alike world. In particular, Ben Woods surveyed DragonFly, NetBSD,
OpenBSD, ArchLinux, CentOS, Debian, Fedora, Slackware, and Ubuntu. None have a
world-readable /root by default.
Submitted by: Gordon Bergling <gbergling AT gmail.com>
Reviewed by: ian, myself
Discussed with: emaste (informal approval)
Relnotes: sure?
Differential Revision: https://reviews.freebsd.org/D23392
2020-06-04 16:04:19 +00:00
|
|
|
root mode=0750
|
1994-09-19 01:40:40 +00:00
|
|
|
..
|
1998-09-19 18:50:27 +00:00
|
|
|
sbin
|
1994-09-19 01:40:40 +00:00
|
|
|
..
|
1998-12-16 05:45:58 +00:00
|
|
|
tmp mode=01777
|
1994-09-19 01:40:40 +00:00
|
|
|
..
|
1995-05-17 09:31:17 +00:00
|
|
|
usr
|
1994-09-19 01:40:40 +00:00
|
|
|
..
|
1995-05-17 09:31:17 +00:00
|
|
|
var
|
1994-09-19 01:40:40 +00:00
|
|
|
..
|
1993-06-20 13:41:45 +00:00
|
|
|
..
|