Subject: bin/12729: /etc/rc.d scripts are not monitored by /etc/changelist or mtree
To: None <gnats-bugs@gnats.netbsd.org>
From: None <windsor@warthog.com>
List: netbsd-bugs
Date: 04/23/2001 17:45:20
>Number:         12729
>Category:       bin
>Synopsis:       /etc/rc.d scripts are not monitored by /etc/changelist or mtree
>Confidential:   no
>Severity:       serious
>Priority:       high
>Responsible:    bin-bug-people
>State:          open
>Class:          sw-bug
>Submitter-Id:   net
>Arrival-Date:   Mon Apr 23 15:48:00 PDT 2001
>Closed-Date:
>Last-Modified:
>Originator:     Rob Windsor <windsor@warthog.com>
>Release:        -current, something using /etc/rc.d
>Organization:
Nose Pickers Anonymous
>Environment:
blah.
System: NetBSD apollo 1.5U NetBSD 1.5U (SUN4M_CURRENT) #0: Fri Apr 20 23:48:35 CDT 2001 rwroot@apollo:/usr/src/sys/arch/sparc/compile/SUN4M_CURRENT sparc
Architecture:	sparc
Machine:	sparc
>Description:
	Once again, src/etc/changelist and src/etc/mtree/special are
	grossly behind the development curve.  These are valid audit
	files that need to be kept up to date.  (Perhaps now is a good
	time to point out ignored-pr security/6548.)

	Of great security concern are the boot files in /etc/rc.d.

	The resolution of this problem will trigger a bug covered in
	bin/12727 with /var/backups files.

>How-To-Repeat:
	er.. look at the files?

>Fix:
	Add relevant data to src/etc/changelist and src/etc/mtree/special

>Release-Note:
>Audit-Trail:
>Unformatted: