From owner-freebsd-arch@freebsd.org Fri Dec 25 07:42:04 2015 Return-Path: Delivered-To: freebsd-arch@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 9690DA51F28 for ; Fri, 25 Dec 2015 07:42:04 +0000 (UTC) (envelope-from alfred@freebsd.org) Received: from elvis.mu.org (elvis.mu.org [IPv6:2001:470:1f05:b76::196]) by mx1.freebsd.org (Postfix) with ESMTP id 8C68A186E for ; Fri, 25 Dec 2015 07:42:04 +0000 (UTC) (envelope-from alfred@freebsd.org) Received: from Alfreds-MacBook-Pro-2.local (unknown [IPv6:2601:645:8001:cee1:9588:e363:4596:bb7e]) by elvis.mu.org (Postfix) with ESMTPSA id BB07D345A936; Thu, 24 Dec 2015 23:42:03 -0800 (PST) Subject: Re: Expanding _PATH_DEFPATH To: freebsd-arch@freebsd.org, Jilles Tjoelker References: <20151224231349.GA5821@stack.nl> From: Alfred Perlstein Organization: FreeBSD Message-ID: <567CF34B.4030404@freebsd.org> Date: Thu, 24 Dec 2015 23:42:03 -0800 User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.11; rv:38.0) Gecko/20100101 Thunderbird/38.4.0 MIME-Version: 1.0 In-Reply-To: <20151224231349.GA5821@stack.nl> Content-Type: text/plain; charset=windows-1252; format=flowed Content-Transfer-Encoding: 7bit X-BeenThere: freebsd-arch@freebsd.org X-Mailman-Version: 2.1.20 Precedence: list List-Id: Discussion related to FreeBSD architecture List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 25 Dec 2015 07:42:04 -0000 On 12/24/15 3:13 PM, Jilles Tjoelker wrote: > In there is a #define _PATH_DEFPATH which is set to > /usr/bin:/bin. This does not include /sbin, /usr/sbin and ports > (/usr/local/bin and /usr/local/sbin) directories and is therefore often > insufficient. > > This is rarely a problem because _PATH_DEFPATH is overridden by > /etc/login.conf, ~/.login_conf and/or shell startup files. _PATH_DEFPATH > is still used as a default by execlp(), execvp(), posix_spawnp() and sh > if PATH is not set, and by cron. > > Especially the latter is a common trap (most recently in PR 204813). We > can fix it for 99% by changing _PATH_DEFPATH to > /sbin:/bin:/usr/sbin:/usr/bin:/usr/local/sbin:/usr/local/bin > This is the path in the default class in the default /etc/login.conf, > excluding ~/bin which would not be expanded properly in a string > constant. > > For consistency, the _PATH_DEFPATH for RESCUE below and in 3 man pages > (exec.3, posix_spawn.3, crontab.5) need to be adjusted as well. > I have stubbed toes against this silly restricted path so many times that this would be a welcome change. However before changing the PATH please consult secteam to make sure it's safe. I might recommend for the time being going with the suggestion in the PR which asks that a friendly note be added to files. This would be more "safe" until secteam can analyze. -Alfred