1# $OpenBSD: special,v 1.129 2023/09/19 15:02:55 naddy Exp $ 2# 3# Hand-crafted mtree specification for the dangerous files. 4# 5 6. type=dir mode=0755 uname=root gname=wheel 7 8dev type=dir mode=0755 uname=root gname=wheel 9fd type=dir mode=0555 uname=root gname=wheel ignore 10.. #dev/fd 11kmem type=char mode=0640 uname=root gname=kmem 12mem type=char mode=0640 uname=root gname=kmem 13.. #dev 14 15etc type=dir mode=0755 uname=root gname=wheel 16acme-client.conf type=file mode=0644 uname=root gname=wheel optional 17bgpd.conf type=file mode=0600 uname=root gname=wheel optional 18chio.conf type=file mode=0644 uname=root gname=operator optional 19crontab type=file mode=0600 uname=root gname=wheel optional 20csh.cshrc type=file mode=0644 uname=root gname=wheel optional 21csh.login type=file mode=0644 uname=root gname=wheel optional 22csh.logout type=file mode=0644 uname=root gname=wheel optional 23daily type=file mode=0644 uname=root gname=wheel 24daily.local type=file mode=0644 uname=root gname=wheel optional 25dhcpd.conf type=file mode=0644 uname=root gname=wheel optional 26dvmrpd.conf type=file mode=0600 uname=root gname=wheel optional 27exports type=file mode=0644 uname=root gname=wheel optional 28fbtab type=file mode=0644 uname=root gname=wheel 29fstab type=file mode=0644 uname=root gname=wheel 30ftpchroot type=file mode=0644 uname=root gname=wheel optional 31ftpusers type=file mode=0644 uname=root gname=wheel 32group type=file mode=0644 uname=root gname=wheel 33hostapd.conf type=file mode=0600 uname=root gname=wheel optional 34hosts type=file mode=0644 uname=root gname=wheel 35httpd.conf type=file mode=0644 uname=root gname=wheel optional 36ifstated.conf type=file mode=0644 uname=root gname=wheel optional 37iked type=dir mode=0755 uname=root gname=wheel 38.. #iked 39iked.conf type=file mode=0600 uname=root gname=wheel optional 40inetd.conf type=file mode=0644 uname=root gname=wheel optional 41ipsec.conf type=file mode=0600 uname=root gname=wheel optional 42isakmpd type=dir mode=0755 uname=root gname=wheel 43isakmpd.conf type=file mode=0600 uname=root gname=wheel optional 44isakmpd.policy type=file mode=0600 uname=root gname=wheel optional 45.. #isakmpd 46ldapd.conf type=file mode=0600 uname=root gname=wheel optional 47ldpd.conf type=file mode=0600 uname=root gname=wheel optional 48login.conf type=file mode=0644 uname=root gname=wheel 49login.conf.d type=dir mode=0755 uname=root gname=wheel 50.. #login.conf.d 51login_ldap.conf type=file mode=0640 uname=root gname=auth optional 52mail.rc type=file mode=0644 uname=root gname=wheel 53mailer.conf type=file mode=0644 uname=root gname=wheel 54master.passwd type=file mode=0600 uname=root gname=wheel 55monthly type=file mode=0644 uname=root gname=wheel 56monthly.local type=file mode=0644 uname=root gname=wheel optional 57mrouted.conf type=file mode=0644 uname=root gname=wheel optional 58mail type=dir mode=0755 uname=root gname=wheel 59aliases type=file mode=0644 uname=root gname=wheel optional 60aliases.db type=file mode=0644 uname=root gname=wheel optional 61secrets type=file mode=0640 uname=root gname=_smtpd optional 62secrets.db type=file mode=0640 uname=root gname=_smtpd optional 63smtpd.conf type=file mode=0644 uname=root gname=wheel 64spamd.conf type=file mode=0644 uname=root gname=wheel optional 65.. #mail 66mtree type=dir mode=0755 uname=root gname=wheel 67special type=file mode=0600 uname=root gname=wheel 68.. #mtree 69moduli type=file mode=0644 uname=root gname=wheel 70netstart type=file mode=0644 uname=root gname=wheel 71npppd type=dir mode=0755 uname=root gname=wheel 72npppd.conf type=file mode=0600 uname=root gname=wheel 73npppd-users type=file mode=0600 uname=root gname=wheel 74.. #npppd 75ntpd.conf type=file mode=0644 uname=root gname=wheel optional 76ospfd.conf type=file mode=0600 uname=root gname=wheel optional 77ospf6d.conf type=file mode=0600 uname=root gname=wheel optional 78passwd type=file mode=0644 uname=root gname=wheel 79pf.conf type=file mode=0600 uname=root gname=wheel optional 80printcap mode=0644 uname=root gname=wheel optional 81radiusd.conf type=file mode=0600 uname=root gname=wheel optional 82rc type=file mode=0644 uname=root gname=wheel 83rc.conf type=file mode=0644 uname=root gname=wheel 84rc.conf.local type=file mode=0644 uname=root gname=wheel optional 85rc.local type=file mode=0644 uname=root gname=wheel optional 86rc.securelevel type=file mode=0644 uname=root gname=wheel optional 87rc.shutdown type=file mode=0644 uname=root gname=wheel optional 88relayd.conf type=file mode=0600 uname=root gname=wheel optional 89remote type=file mode=0644 uname=root gname=wheel optional 90resolv.conf type=file mode=0644 uname=root gname=wheel optional 91resolv.conf.tail type=file mode=0644 uname=root gname=wheel optional 92rbootd.conf type=file mode=0644 uname=root gname=wheel optional 93ripd.conf type=file mode=0600 uname=root gname=wheel optional 94sasyncd.conf type=file mode=0600 uname=root gname=wheel optional 95sensorsd.conf type=file mode=0644 uname=root gname=wheel optional 96shells type=file mode=0644 uname=root gname=wheel 97skey type=dir mode=01730 uname=root gname=auth optional 98.. #skey 99snmpd.conf type=file mode=0600 uname=root gname=wheel optional 100soii.key type=file mode=0600 uname=root gname=wheel optional 101spwd.db type=file mode=0640 uname=root gname=_shadow 102ssh type=dir mode=0755 uname=root gname=wheel optional 103ssh_config type=file mode=0644 uname=root gname=wheel 104ssh_host_ecdsa_key type=file mode=0600 uname=root gname=wheel optional 105ssh_host_ecdsa_key.pub type=file mode=0644 uname=root gname=wheel optional 106ssh_host_ed25519_key type=file mode=0600 uname=root gname=wheel optional 107ssh_host_ed25519_key.pub type=file mode=0644 uname=root gname=wheel optional 108ssh_host_key type=file mode=0600 uname=root gname=wheel optional 109ssh_host_key.pub type=file mode=0644 uname=root gname=wheel optional 110ssh_host_rsa_key type=file mode=0600 uname=root gname=wheel optional 111ssh_host_rsa_key.pub type=file mode=0644 uname=root gname=wheel optional 112sshd_config type=file mode=0644 uname=root gname=wheel 113.. #ssh 114syslog.conf type=file mode=0644 uname=root gname=wheel 115ttys type=file mode=0644 uname=root gname=wheel 116vm.conf type=file mode=0644 uname=root gname=wheel optional 117weekly type=file mode=0644 uname=root gname=wheel 118weekly.local type=file mode=0644 uname=root gname=wheel optional 119ypldap.conf type=file mode=0600 uname=root gname=wheel optional 120.. #etc 121 122root type=dir mode=0700 uname=root gname=wheel 123.cshrc type=file mode=0644 uname=root gname=wheel 124.login type=file mode=0644 uname=root gname=wheel 125.profile type=file mode=0644 uname=root gname=wheel 126.rhosts type=file mode=0600 uname=root gname=wheel optional 127.ssh type=dir mode=0700 uname=root gname=wheel 128authorized_keys type=file mode=0600 uname=root gname=wheel 129.. #root/.ssh 130.. #root 131 132sbin type=dir mode=0755 uname=root gname=wheel ignore 133.. #sbin 134 135usr type=dir mode=0755 uname=root gname=wheel 136bin type=dir mode=0755 uname=root gname=wheel ignore 137.. #usr/bin 138games type=dir mode=0755 uname=root gname=wheel optional 139.. #usr/games 140include type=dir mode=0755 uname=root gname=bin ignore 141.. #usr/include 142lib type=dir mode=0755 uname=root gname=wheel ignore 143.. #usr/lib 144libdata type=dir mode=0755 uname=root gname=wheel ignore 145.. #usr/libdata 146libexec type=dir mode=0755 uname=root gname=wheel 147auth type=dir mode=0750 uname=root gname=auth ignore 148.. #usr/libexec/auth 149.. #usr/libexec 150local type=dir mode=0755 uname=root gname=wheel 151bin type=dir mode=0755 uname=root gname=wheel ignore 152.. #usr/local/bin 153lib type=dir mode=0755 uname=root gname=wheel ignore 154.. #usr/local/lib 155.. #usr/local 156sbin type=dir mode=0755 uname=root gname=wheel ignore 157.. #usr/sbin 158share type=dir mode=0755 uname=root gname=wheel ignore 159.. #usr/share 160.. #usr 161 162var type=dir mode=0755 uname=root gname=wheel 163account type=dir mode=0755 uname=root gname=wheel 164acct type=file mode=0644 uname=root gname=wheel optional 165.. #var/account 166yp type=dir mode=0755 uname=root gname=wheel optional ignore 167.. #var/yp 168backups type=dir mode=0700 uname=root gname=wheel ignore 169.. #var/backups 170cron type=dir mode=0555 uname=root gname=wheel 171log type=file mode=0600 uname=root gname=wheel 172atjobs type=dir mode=01770 uname=root gname=crontab ignore 173.. #var/cron/atjobs 174tabs type=dir mode=01730 uname=root gname=crontab ignore 175.. #var/cron/tabs 176.. #var/cron 177db type=dir mode=0755 uname=root gname=wheel 178host.random type=file mode=0600 uname=root gname=wheel optional 179kvm_bsd.db type=file mode=0640 uname=root gname=kmem 180.. #var/db 181log type=dir mode=0755 uname=root gname=wheel 182authlog type=file mode=0640 uname=root gname=wheel 183secure type=file mode=0600 uname=root gname=wheel 184wtmp type=file mode=0644 uname=root gname=wheel 185lastlog type=file mode=0644 uname=root gname=wheel 186.. #var/log 187mail type=dir mode=0755 uname=root gname=wheel ignore 188.. #var/mail 189nsd type=dir mode=0755 uname=root gname=wheel 190etc type=dir mode=0750 uname=root gname=_nsd 191.. #var/nsd/etc 192.. #var/nsd 193run type=dir mode=0755 uname=root gname=wheel 194utmp type=file mode=0664 uname=root gname=utmp 195.. #var/run 196spool type=dir mode=0755 uname=root gname=wheel 197ftp type=dir mode=0555 uname=root gname=wheel optional 198bin type=dir mode=0511 uname=root gname=wheel optional 199.. #var/spool/ftp/bin 200etc type=dir mode=0511 uname=root gname=wheel optional 201group type=file mode=0444 uname=root gname=wheel optional 202localtime type=file mode=0444 uname=root gname=wheel optional 203master.passwd type=file mode=0400 uname=root gname=wheel optional 204spwd.db type=file mode=0400 uname=root gname=wheel optional 205motd type=file mode=0444 uname=root gname=wheel optional 206passwd type=file mode=0444 uname=root gname=wheel optional 207pwd.db type=file mode=0444 uname=root gname=wheel optional 208.. #var/spool/ftp/etc 209hidden type=dir mode=0111 uname=root gname=wheel optional ignore 210.. #var/spool/ftp/hidden 211pub type=dir mode=0555 uname=root gname=wheel optional ignore 212.. #var/spool/ftp/pub 213.. #var/spool/ftp 214output type=dir mode=0755 uname=root gname=wheel ignore 215.. #var/spool/output 216.. #var/spool 217