Subject: pkg/24560: /etc/security doesn't parse /etc/exports correctly
To: None <>
From: None <>
List: netbsd-bugs
Date: 02/26/2004 00:41:22
>Number:         24560
>Category:       pkg
>Synopsis:       /etc/security doesn't parse /etc/exports correctly
>Confidential:   no
>Severity:       non-critical
>Priority:       medium
>Responsible:    pkg-manager
>State:          open
>Class:          sw-bug
>Submitter-Id:   net
>Arrival-Date:   Wed Feb 25 23:42:00 UTC 2004
>Originator:     Jukka Salmi
>Release:        NetBSD 1.6ZK
System: NetBSD 1.6ZK NetBSD 1.6ZK (HIMO) #0: Wed Feb 18 00:27:09 CET 2004 i386
Architecture: i386
Machine: i386
Checking of /etc/exports in /etc/security (check_nfs) is not done correctly.
Several things are wrongly assumed:

- only one directory can be specified per entry
- logical lines are physical lines
- the host set starts with a minus sign (-)

But the following is true:

- several directories can be may be specified per entry
- lines can be continued using \ because src/usr.sbin/mountd/mountd.c,
  line 1043, read /etc/exports using fparseln(3).
- the host set can be specified as -network=... -mask=...

An /etc/exports entry as follows:

/a/directory /another/dir \
  -ro -maproot=nobody:nobody -network= -mask=

is syntactically correct and doen't export the directories globally, but
results in the following text being output during /etc/security execution:

Checking for globally exported file systems.
File system -ro globally exported, read-write.

I'll send a patch in a minute...