Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- [INFO] + [BUG]
- apple.com <=== Bug
- /bin/bash
- /bin/csh
- /bin/ksh
- /bin/sh
- /bin/tcsh
- /bin/zsh
- Hosts localhost Apple
- +++++++++++++++++++++++++++++++++++++++
- 127.0.0.1 localhost
- 255.255.255.255 broadcasthost
- ::1 localhost
- +++++++++++++++++++++++++++++++++++++++
- ftpusers
- +++++++++++++++++++++++++++++++++++++++++++
- # list of users disallowed any ftp access.
- # read by ftpd(8).
- Administrator [allowed]
- administrator [allowed]
- root <=== critical
- uucp
- daemon
- unknown
- www <==== eror
- Make File for sub dir, and instal_file for -c -m 644 ftpusers [i see for all anything bug]
- Makefile [plain text]
- Destination = $(DSTROOT)/private/etc
- # Common Makefile
- include $(MAKEFILEPATH)/CoreOS/ReleaseControl/Common.make
- # Subdirectories with their own makefiles
- SubDirs =
- install::
- $(_v) for subdir in $(SubDirs); do \
- (cd "$$subdir" && $(MAKE) $@ Destination="$(Destination)/$$subdir"); \
- done
- install:: install-sysconf install-files
- install-sysconf:
- @echo "Installing $(Destination)"
- $(_v) $(INSTALL_DIRECTORY) "$(Destination)"
- $(_v) $(INSTALL_FILE) -c -m 644 afpovertcp.cfg "$(Destination)/afpovertcp.cfg"
- $(_v) $(INSTALL_FILE) -c -m 644 /dev/null "$(Destination)/find.codes"
- $(_v) $(INSTALL_FILE) -c -m 644 ftpusers "$(Destination)/ftpusers"
- $(_v) $(INSTALL_FILE) -c -m 644 fstab.hd "$(Destination)/fstab.hd"
- $(_v) $(INSTALL_FILE) -c -m 644 gettytab "$(Destination)/gettytab"
- $(_v) $(INSTALL_FILE) -c -m 644 /dev/null "$(Destination)/hosts.lpd"
- $(_v) $(INSTALL_FILE) -c -m 644 /dev/null "$(Destination)/hosts.equiv"
- $(_v) $(INSTALL_FILE) -c -m 644 kern_loader.conf "$(Destination)/kern_loader.conf"
- $(_v) $(INSTALL_FILE) -c -m 644 motd "$(Destination)/motd"
- $(_v) $(INSTALL_FILE) -c -m 644 /dev/null "$(Destination)/rmtab"
- $(_v) $(INSTALL_FILE) -c -m 644 shells "$(Destination)/shells"
- $(_v) $(INSTALL_FILE) -c -m 644 syslog.conf "$(Destination)/syslog.conf"
- ifeq "$(RC_RELEASE)" "Darwin"
- $(_v) cat ttys | sed -e 's/^console/##console/' -e 's/^#console/console/' > "$(Destination)/ttys"
- $(_v) chmod 644 "$(Destination)/ttys" ; chown root:wheel "$(Destination)/ttys"
- else
- $(_v) $(INSTALL_FILE) -c -m 644 ttys "$(Destination)/ttys"
- endif
- $(_v) $(INSTALL_FILE) -c -m 644 /dev/null "$(Destination)/xtab"
- $(_v) $(LN) -s /var/run/resolv.conf "$(Destination)"
- # We should stop installing the files which are pulled into NetInfo, but we should
- # first make sure that doesn't break anything.
- # - at boot time, we (possibly nominal) errors messages if master.passwd is missing.
- # - syslogd doesn't like it if services is missing.
- install-files:
- $(_v) $(INSTALL_FILE) -c -m 644 group "$(Destination)/group"
- $(_v) $(INSTALL_FILE) -c -m 644 hosts "$(Destination)/hosts"
- $(_v) $(INSTALL_FILE) -c -m 600 master.passwd "$(Destination)/master.passwd"
- $(_v) $(INSTALL_FILE) -c -m 644 networks "$(Destination)/networks"
- $(_v) $(INSTALL_FILE) -c -m 644 passwd "$(Destination)/passwd"
- $(_v) $(INSTALL_FILE) -c -m 644 protocols "$(Destination)/protocols"
- $(_v) $(INSTALL_FILE) -c -m 644 rpc "$(Destination)/rpc"
- $(_v) $(INSTALL_FILE) -c -m 644 services "$(Destination)/services"
- +++++++++++++++++++++++++++++++++++++++++++
- The sandbox
- bsd.sb [plain text]
- ;;
- ;; common rules for various BSD daemons
- ;; Copyright (c) 2007 Apple Inc. All Rights reserved.
- ;;
- ;; WARNING: The sandbox rules in this file currently constitute
- ;; Apple System Private Interface and are subject to change at any time and
- ;; without notice. The contents of this file are also auto-generated and not
- ;; user editable; it may be overwritten at any time.
- ;;
- (version 1)
- (debug deny)
- ;; allow processes to traverse symlinks
- (allow file-read-metadata)
- (allow file-read-data file-read-metadata
- (regex
- ; Allow reading system dylibs and frameworks
- #"^/usr/lib/.*\.dylib$"
- #"^/usr/lib/info/.*\.so$"
- #"^/System/"
- #"^/private/var/db/dyld/"
- #"^(/private)?/etc/hosts\.(allow|deny)$"
- ))
- (allow file-read-data file-write-data
- (regex
- ; Allow files accessed by system dylibs and frameworks
- #"^/dev/null$"
- #"^(/private)?/var/run/syslog$"
- #"^/dev/u?random$"
- #"^/dev/autofs_nowait$"
- #"^/dev/dtracehelper$"
- #"/\.CFUserTextEncoding$"
- #"^(/private)?/etc/localtime$"
- #"^/usr/share/nls/"
- #"^/usr/share/zoneinfo/"
- ))
- (allow file-ioctl
- (regex
- ; Allow access to dtracehelper by dyld
- #"^/dev/dtracehelper$"))
- (allow mach-lookup
- (global-name "com.apple.bsd.dirhelper")
- (global-name "com.apple.system.DirectoryService.libinfo_v1")
- (global-name "com.apple.system.DirectoryService.membership_v1")
- (global-name "com.apple.system.logger")
- (global-name "com.apple.system.notification_center"))
- (allow ipc-posix-shm) ; Libnotify
- (allow sysctl-read)
- (allow signal (target self))
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement