From owner-freebsd-security@freebsd.org Tue Jun 1 03:54:40 2021 Return-Path: Delivered-To: freebsd-security@mailman.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mailman.nyi.freebsd.org (Postfix) with ESMTP id 57A926386F1 for ; Tue, 1 Jun 2021 03:54:40 +0000 (UTC) (envelope-from gordon@tetlows.org) Received: from mail-pj1-x1036.google.com (mail-pj1-x1036.google.com [IPv6:2607:f8b0:4864:20::1036]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (2048 bits) client-digest SHA256) (Client CN "smtp.gmail.com", Issuer "GTS CA 1O1" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4FvJFW41Pyz4Whl for ; Tue, 1 Jun 2021 03:54:39 +0000 (UTC) (envelope-from gordon@tetlows.org) Received: by mail-pj1-x1036.google.com with SMTP id o17-20020a17090a9f91b029015cef5b3c50so640285pjp.4 for ; Mon, 31 May 2021 20:54:39 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:content-transfer-encoding:from:mime-version :subject:date:message-id:references:cc:in-reply-to:to; bh=HyqG6wo8sqVo6Se9QOTmWVFSQUUX6+4AXm0MdCc2MvE=; b=bDdX1IfpInIDwAcK9akFpF34fqyVCvRqNv+/03XpiNv92eTjcEbROzs0++G6Z/sSBM 6qcadzKBhz6ZU0QJlnxO1wY2qH6qIlCDFxGZregoVj0NWzzX6aXliv+IApa3vAt+Ew6N eaU8Gm5JLYpia++o4E3WKEME8hn94MIlZbV5SM22xYfDE+YXz5yhlgcsKigDP6yYM03W fot9v1XDI7NzfxZr9yqRTyROvm9DAxtZ2wLlYFmUOe7HMv8jnrXa/nkEizA3Amk4YNF1 W9zT54ZSsvXy8EeQffr8TysjGJeSHfQ5ztjf8ZLp4fFVjYalZ6wli95fWeGAAgWmAVr8 uWHA== X-Gm-Message-State: AOAM531RcBT3x+hkxpxEKWOtKVwY17XYCY3oimQfYUS4IPKwXH8kPw83 wjS+XIh4g+SJMht34H6k+cwNfj2bvKkR X-Google-Smtp-Source: ABdhPJxbnn1132avuaRRA05qnZMWHHr/cHaubqyvW0fhU0KYVXg8KDpJgewaqyrmfLytiKC/O32pBA== X-Received: by 2002:a17:902:d104:b029:105:fff1:74ad with SMTP id w4-20020a170902d104b0290105fff174admr5353681plw.69.1622519677654; Mon, 31 May 2021 20:54:37 -0700 (PDT) Received: from smtpclient.apple (2603-8001-5e40-d300-6439-803d-7312-571d.res6.spectrum.com. [2603:8001:5e40:d300:6439:803d:7312:571d]) by smtp.gmail.com with ESMTPSA id k7sm699422pjj.46.2021.05.31.20.54.37 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Mon, 31 May 2021 20:54:37 -0700 (PDT) Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable From: Gordon Tetlow Mime-Version: 1.0 (1.0) Subject: Re: sysrc bug Date: Mon, 31 May 2021 20:54:35 -0700 Message-Id: References: Cc: Fas Xmut , freebsd-security@freebsd.org In-Reply-To: To: Roger Marquis X-Mailer: iPhone Mail (18F72) X-Rspamd-Queue-Id: 4FvJFW41Pyz4Whl X-Spamd-Bar: --- X-Spamd-Result: default: False [-3.50 / 15.00]; RCVD_VIA_SMTP_AUTH(0.00)[]; TO_DN_SOME(0.00)[]; MV_CASE(0.50)[]; R_SPF_ALLOW(-0.20)[+ip6:2607:f8b0:4000::/36]; RCVD_COUNT_THREE(0.00)[3]; DKIM_TRACE(0.00)[tetlows.org:+]; DMARC_POLICY_ALLOW(-0.50)[tetlows.org,quarantine]; NEURAL_HAM_SHORT(-1.00)[-0.999]; FROM_EQ_ENVFROM(0.00)[]; MIME_TRACE(0.00)[0:+]; RBL_DBL_DONT_QUERY_IPS(0.00)[2607:f8b0:4864:20::1036:from]; ASN(0.00)[asn:15169, ipnet:2607:f8b0::/32, country:US]; MID_RHS_MATCH_FROM(0.00)[]; ARC_NA(0.00)[]; NEURAL_HAM_MEDIUM(-1.00)[-1.000]; R_DKIM_ALLOW(-0.20)[tetlows.org:s=google]; FREEFALL_USER(0.00)[gordon]; FROM_HAS_DN(0.00)[]; RCPT_COUNT_THREE(0.00)[3]; NEURAL_HAM_LONG(-1.00)[-1.000]; MIME_GOOD(-0.10)[text/plain]; PREVIOUSLY_DELIVERED(0.00)[freebsd-security@freebsd.org]; SPAMHAUS_ZRD(0.00)[2607:f8b0:4864:20::1036:from:127.0.2.255]; TO_MATCH_ENVRCPT_SOME(0.00)[]; RCVD_IN_DNSWL_NONE(0.00)[2607:f8b0:4864:20::1036:from]; FREEMAIL_CC(0.00)[protonmail.com,freebsd.org]; RCVD_TLS_ALL(0.00)[]; MAILMAN_DEST(0.00)[freebsd-security] X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.34 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 01 Jun 2021 03:54:40 -0000 > On May 31, 2021, at 16:07, Roger Marquis wrote: >=20 > =EF=BB=BF >>=20 >> Also, changing the root shell is bad for many reasons and I'm not >> surprised that something doesn't work. >=20 > Surprised this old myth is still being repeated. Having used various > root shells in FreeBSD and other Unux/Linux systems for decades I have to > ask specifically what said reasons are, particularly considering > /usr/sbin/sysrc starts with "#!/bin/sh" (as does and should every system > shell script). It=E2=80=99s likely due to the quoting behavior of newlines passed as the ar= gument when he ran the script, which varies between shell implementations. A= s I said, I=E2=80=99m not surprised something broke because many utilities a= re not tested with different shell behaviors. I also believe if we have a reproducible test case, we should go ahead and f= ix it. Gordon=