From nobody Tue Oct 12 12:21:26 2021 X-Original-To: freebsd-current@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 1BFF318070E6 for ; Tue, 12 Oct 2021 12:21:30 +0000 (UTC) (envelope-from gljennjohn@gmail.com) Received: from mail-wr1-x436.google.com (mail-wr1-x436.google.com [IPv6:2a00:1450:4864:20::436]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (2048 bits) client-digest SHA256) (Client CN "smtp.gmail.com", Issuer "GTS CA 1O1" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4HTFBx1vPZz3k4S for ; Tue, 12 Oct 2021 12:21:29 +0000 (UTC) (envelope-from gljennjohn@gmail.com) Received: by mail-wr1-x436.google.com with SMTP id o20so66202095wro.3 for ; Tue, 12 Oct 2021 05:21:29 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20210112; h=date:from:to:subject:message-id:in-reply-to:references:reply-to :mime-version:content-transfer-encoding; bh=L/D93UD2UUopE6QAMLh+iKUbWnm4JUzx9fRVRCXR8lY=; b=QY/r7NT8zHdzX7bXN1rxcfmfY5FJtZL8Ue6xROhmvo6/iBCvzdOxTPI/j1Aqz1gy2m mt/yCFWbzWBtEOAXvGN6VEVoHAfzNfrnDMprtoa5Zjtqz5yUG573Vh9a0PZzPamFzEo3 WSQnRr51DhWUkRd6WRjQ0TUcH8MTvameo4zATHd3Vi6xIMehXNzDyRX6p2upe1lhm782 EKlIturp9l4BMfkkIY0e4yGAzQAEDRxO3gSz9l5HTjC10WK2wbiy58tW2PIRURRfg7PU MqEMVzPGdt1c4zMvZccjdUUfhznSOHLBp1CzWmOQrEGiZMa5pj/l50AUCSmw6smAHPGu X0aA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=x-gm-message-state:date:from:to:subject:message-id:in-reply-to :references:reply-to:mime-version:content-transfer-encoding; bh=L/D93UD2UUopE6QAMLh+iKUbWnm4JUzx9fRVRCXR8lY=; b=lQVGKOGoFvLxp92bwt03mPvsBehaBeTClBBBsMWDX5WIw8+u1P7V8OaY1LxulzjK+/ ZOD7/FCOfexmFrojIGJcxjZlTFH3mDClynoQSfg14s/fo00SvLkfaH5Xl31ke1QctVxe Bb9U0MZAhjH8jxocUi6X4UpVoDTE6Jq6dvtji9Nnbsa70lZ+XgeauBTp5sggWcNM6hIf FH1fhaZZpu/II7BQhEP3sW4zlLvaRPsRWKGCpX8WaleQy8aQ9zN+n2E4cuvOHmgl6gaf TWa1Ob3LKIw67g2eVf9FZFnJ5IlVmdWpEAY95GzPrStD1jnMmvAGlpq+WrZZbBk62guR /Nzg== X-Gm-Message-State: AOAM531vOSuLeuvXqTcNeAn7K3nFZ9t+4HPlQMCdwUCdt0HselS1PFU8 C028lVQEfUhXXDPpu6N5rbU9qTYvhaQ= X-Google-Smtp-Source: ABdhPJw0O1R9H743uM7oXtSyo3ogWqsiPKRZUErCAYgUg1ZhpxRoal2j42BA5GcXYVbZu0PTflbY7A== X-Received: by 2002:a5d:47cb:: with SMTP id o11mr31142763wrc.184.1634041288128; Tue, 12 Oct 2021 05:21:28 -0700 (PDT) Received: from ernst.home (p5b3becad.dip0.t-ipconnect.de. [91.59.236.173]) by smtp.gmail.com with ESMTPSA id e16sm8820991wrw.17.2021.10.12.05.21.27 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 12 Oct 2021 05:21:27 -0700 (PDT) Date: Tue, 12 Oct 2021 14:21:26 +0200 From: Gary Jennejohn To: freebsd-current@freebsd.org Subject: Re: [HEADSUP] making /bin/sh the default shell for root Message-ID: <20211012142126.66036897@ernst.home> In-Reply-To: References: <6B2E21D5-0DF1-4BCC-A27C-DFFBB201FB52@gmail.com> Reply-To: gljennjohn@gmail.com X-Mailer: Claws Mail 3.18.0 (GTK+ 2.24.33; amd64-portbld-freebsd14.0) List-Id: Discussions about the use of FreeBSD-current List-Archive: https://lists.freebsd.org/archives/freebsd-current List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-freebsd-current@freebsd.org MIME-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit X-Rspamd-Queue-Id: 4HTFBx1vPZz3k4S X-Spamd-Bar: - Authentication-Results: mx1.freebsd.org; dkim=pass header.d=gmail.com header.s=20210112 header.b="QY/r7NT8"; dmarc=pass (policy=none) header.from=gmail.com; spf=pass (mx1.freebsd.org: domain of gljennjohn@gmail.com designates 2a00:1450:4864:20::436 as permitted sender) smtp.mailfrom=gljennjohn@gmail.com X-Spamd-Result: default: False [-1.99 / 15.00]; HAS_REPLYTO(0.00)[gljennjohn@gmail.com]; RCVD_VIA_SMTP_AUTH(0.00)[]; R_SPF_ALLOW(-0.20)[+ip6:2a00:1450:4000::/36:c]; FREEMAIL_FROM(0.00)[gmail.com]; REPLYTO_ADDR_EQ_FROM(0.00)[]; TO_DN_NONE(0.00)[]; RCVD_COUNT_THREE(0.00)[3]; DKIM_TRACE(0.00)[gmail.com:+]; DMARC_POLICY_ALLOW(-0.50)[gmail.com,none]; NEURAL_HAM_SHORT(-1.00)[-1.000]; RECEIVED_SPAMHAUS_PBL(0.00)[91.59.236.173:received]; FROM_EQ_ENVFROM(0.00)[]; MIME_TRACE(0.00)[0:+]; FREEMAIL_ENVFROM(0.00)[gmail.com]; ASN(0.00)[asn:15169, ipnet:2a00:1450::/32, country:US]; DWL_DNSWL_NONE(0.00)[gmail.com:dkim]; ARC_NA(0.00)[]; NEURAL_HAM_MEDIUM(-0.98)[-0.976]; R_DKIM_ALLOW(-0.20)[gmail.com:s=20210112]; FROM_HAS_DN(0.00)[]; TO_MATCH_ENVRCPT_ALL(0.00)[]; MIME_GOOD(-0.10)[text/plain]; FREEMAIL_REPLYTO(0.00)[gmail.com]; PREVIOUSLY_DELIVERED(0.00)[freebsd-current@freebsd.org]; RCPT_COUNT_ONE(0.00)[1]; NEURAL_SPAM_LONG(0.99)[0.989]; RCVD_IN_DNSWL_NONE(0.00)[2a00:1450:4864:20::436:from]; RCVD_TLS_ALL(0.00)[] X-ThisMailContainsUnwantedMimeParts: N On Tue, 12 Oct 2021 06:59:00 -0400 grarpamp wrote: > > No. The system shell is supposed to make the system usable > > by the users. Actually, the real problem is that the easiest way > > to shoot one's own foot is by changing the language (say, the > > shell) spoken by default by FreeBSD. > > Well, the FreeBSD system speaks sh for its own use, this is clearly > documented as the shell called by init(8), and later by rc(8), > it should probably be the root:0 entry at least for consistancy. > No other shell is called by the FreeBSD system there. > Whatever the users want for their own shells is really up > to them to decide after that. > > "Default" is bit of low context word, as there is no falling > back to some shell occuring, no filling in for some missing > option, etc. Maybe use word "shipped" or "root" instead. > > Everyone said they already do, and will continue to, > exec whatever shell they like, whether after login, > or by changing the entry. So in addition to the user > being ultimately responsible for their own box and usage, > this well announced entry for UPDATING cannot therein > really be responsible for any user self-shooting. > > > This is non-sense. > > Well, FreeBSD does not add every shell in base, > does not add every app to base, etc. > Some reasons for those limits should be obvious. > This update gives further distilling clarity by > limiting the number of shipped uid 0 entries to 1, > with that 1 being sh. > > > Every unix user should know that it's > > possible to changing the used shell by using > > chsh and this includes root. > > Then for every user, this update is not a problem. > I've been using UNIX both privately and professionally since 1984 and I must admit that I never heard of chsh before seeing this e-mail. I simply use vipw; it's the logical way to do this sort of thing IMHO. But I suppose that this is the way to go for users who don't have root access (which I always have). > > BTW, toor default to sh, not tcsh. > > No one said that the toor entry does not use sh. > -- Gary Jennejohn