I'm far away my station and I dont open external links, but after last replies of the thread I just want to testify that I use /tmp on mfs since years and without need of full permissions on it both for foreground apps and for dev and non dev services.
-- dan pls connect by [email protected] or surf my bsd blog at bsd.numode.eu From: Crystal Kolipe <[email protected]> To: Sylvain Saboua <[email protected]> CC: Misc <[email protected]> Date: Aug 12, 2026 17:46:22 Subject: Re: Custom partition layout corrupts install ? +MFS question > On Wed, Aug 12, 2026 at 05:05:03PM +0200, Sylvain Saboua wrote: >> Here are the two pages I apply the instructions of to that end: >> https://dataswamp.org/~solene/2018-05-08-mfs-tmp.html > > The method described there to mount mfs on /tmp with 1777 permissions is very > naive, and yet people continue to keep doing it. > > The problem is that if your mfs fails to mount, or somehow becomes unmounted, > you're left with a 1777 world writable directory on the root volume. > > On a multi-user system, this can easily be abused to create hard links to > files in places such as /etc/ where normal users shouldn't be able to create > them. > > This in turn can open your system up to exploits. > > So _do not do this_, and please do not propogate the above suggestion. > > There are various more sensible ways to achieve a ram-based filesystem on > /tmp. > > Ideally, mount_mfs would allow the users to specify a mode for it's root in a > similar way to mount_tmpfs. I posted patches some time ago to implement this, > but despite some initial interest they never got into cvs and I got busy with > other things. > > Of course, if you're happy using tmpfs, (or my patches), that is one answer. > > Alternatively, and more practically, you can use the -P option to mount_mfs to > populate /tmp from an empty directory elsewhere that has 1777 permissions. > > Obviously, putting _that_ directory somewhere where it's world writable > properties cannot be abused is also a good idea. > > However, the simplest way to get an mfs on /tmp with 1777 is to add two lines > to /etc/rc, just after 'mount -a -t nonfs,vnd' : > > # Adjust permissions for /tmp if it is on an mfs filesystem > /bin/df -t mfs /tmp/ > /dev/null 2> /dev/null && { echo "/tmp on mfs, setting > permissons to 1777" ; chmod 1777 /tmp/ ; } > > Now you can leave the permissions for /tmp on the real root filesystem alone, > and have a mfs mount in /etc/fstab: > > swap /tmp mfs rw,nodev,nosuid,-s=512m 0 0

