From owner-svn-src-head@freebsd.org Fri Jun 5 07:12:41 2020 Return-Path: Delivered-To: svn-src-head@mailman.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mailman.nyi.freebsd.org (Postfix) with ESMTP id 252F2342D7D; Fri, 5 Jun 2020 07:12:41 +0000 (UTC) (envelope-from danfe@freebsd.org) Received: from freefall.freebsd.org (freefall.freebsd.org [IPv6:2610:1c1:1:6074::16:84]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "freefall.freebsd.org", Issuer "Let's Encrypt Authority X3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 49dYkd0C3tz4HWg; Fri, 5 Jun 2020 07:12:41 +0000 (UTC) (envelope-from danfe@freebsd.org) Received: by freefall.freebsd.org (Postfix, from userid 1033) id F18271C83A; Fri, 5 Jun 2020 07:12:40 +0000 (UTC) Date: Fri, 5 Jun 2020 07:12:40 +0000 From: Alexey Dokuchaev To: Cy Schubert Cc: Conrad Meyer , src-committers@freebsd.org, svn-src-all@freebsd.org, svn-src-head@freebsd.org Subject: Re: svn commit: r361791 - head/etc/mtree Message-ID: <20200605071240.GA98879@FreeBSD.org> References: <202006041604.054G4KAb098395@repo.freebsd.org> <202006041619.054GJZ3C018924@slippy.cwsent.com> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <202006041619.054GJZ3C018924@slippy.cwsent.com> X-BeenThere: svn-src-head@freebsd.org X-Mailman-Version: 2.1.33 Precedence: list List-Id: SVN commit messages for the src tree for head/-current List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 05 Jun 2020 07:12:41 -0000 On Thu, Jun 04, 2020 at 09:19:35AM -0700, Cy Schubert wrote: > In message <202006041604.054G4KAb098395@repo.freebsd.org>, Conrad Meyer > writes: > > New Revision: 361791 > > URL: https://svnweb.freebsd.org/changeset/base/361791 > > > > Log: > > Restrict default /root permissions > > > > ... > > @@ -117,7 +117,7 @@ > > .. > > rescue > > .. > > - root > > + root mode=0750 > > .. > > Recent CIS benchmarks recommend 0700. Please, let's keep a reasonable balance between security and usability. I often visit /root as a regular user (wheel'ed), and 0700 would make it real PITA. ./danfe