ktr(4): Add some sysctl descriptions for viewing with sysctl -d.
[dragonfly.git] / etc / defaults / rc.conf
blob8b95aac9a4387f3677bfdfb209e702d25ed97869
1 #!/bin/sh
4 # This is rc.conf - a file full of useful variables that you can set
5 # to change the default startup behavior of your system. You should
6 # not edit this file! Put any overrides into one of the ${rc_conf_files}
7 # instead and you will be able to update these defaults later without
8 # spamming your local configuration information.
10 # The ${rc_conf_files} files should only contain values which override
11 # values set in this file. This eases the upgrade path when defaults
12 # are changed and new features are added.
14 # All arguments must be in double or single quotes.
16 # $FreeBSD: src/etc/defaults/rc.conf,v 1.180 2003/06/26 09:50:50 smkelly Exp $
18 ##############################################################
19 ### Important initial Boot-time options ####################
20 ##############################################################
22 rc_debug="NO" # Set to YES to enable debugging output from rc.d
23 rc_info="YES" # Enables display of informational messages at boot.
24 rcshutdown_timeout="30" # Seconds to wait before terminating rc.shutdown
25 swapfile="NO" # Set to name of swapfile if aux swapfile desired.
26 apm_enable="NO" # Set to YES to enable APM BIOS functions (or NO).
27 apmd_enable="NO" # Run apmd to handle APM event from userland.
28 apmd_flags="" # Flags to apmd (if enabled).
29 battd_enable="NO" # Set to YES to have battd alert on 10% battery power remaining.
30 battd_flags="" # Flags to battd (if enabled).
31 powerd_enable="NO" # Run powerd to adjust CPU speed.
32 sensorsd_enable="NO" # Run sensorsd to monitor and log sensor state changes.
33 sensorsd_flags="" # additional flags for sensorsd(8).
34 hotplugd_enable="NO" # Run hotplugd to monitor devices hot plugging.
35 hotplugd_flags="" # additional flags for hotplugd(8)
36 pccard_ifconfig="NO" # Specialized pccard ethernet configuration (or NO).
37 pccard_ether_delay="5" # Delay before trying to start dhclient in pccard_ether
38 removable_interfaces="" # Removable network interfaces for /etc/pccard_ether.
39 local_startup="/usr/pkg/etc/rc.d /usr/local/etc/rc.d /usr/X11R6/etc/rc.d"
40 # startup script dirs.
41 script_name_sep=" " # Change if your startup scripts' names contain spaces
42 rc_conf_files="/etc/rc.conf /etc/rc.conf.local"
43 fsck_y_enable="NO" # Set to YES to do fsck -y if the initial preen fails.
44 netfs_types="nfs:NFS smbfs:SMB portalfs:PORTAL nwfs:NWFS" # Net filesystems.
45 extra_netfs_types="NO" # List of network extra filesystem types for delayed
46 # mount at startup (or NO).
47 devfs_config_files="/etc/defaults/devfs.conf /etc/devfs.conf"
48 # Config files for devfs(5)
50 ##############################################################
51 ### Network configuration sub-section ######################
52 ##############################################################
54 ### Basic network and firewall/security options: ###
56 # see 'man firewall' for an explanation of the default firewall rules
58 hostname="" # Set this!
59 nisdomainname="NO" # Set to NIS domain if using NIS (or NO).
60 dhclient_program="/sbin/dhclient" # Path to dhcp client program.
61 dhclient_flags="" # Additional flags to pass to dhcp client.
62 firewall_enable="NO" # Set to YES to enable firewall functionality
63 firewall_script="/etc/rc.firewall" # Which script to run to set up the firewall
64 firewall_type="UNKNOWN" # Firewall type (see /etc/rc.firewall)
65 firewall_trusted_nets="192.168.0.0/16" # list of trusted nets
66 firewall_trusted_interfaces="" # list of trusted interfaces e.g. "rl0 xl0"
67 firewall_allowed_icmp_types="0 3 8 11 12 13 14"
68 firewall_open_tcp_ports="22 25 53 80 113 443"
69 firewall_open_udp_ports="53"
70 firewall_quiet="NO" # Set to YES to suppress rule display
71 firewall_logging="NO" # Set to YES to enable events logging
72 firewall_flags="" # Flags passed to ipfw when type is a file
73 ip_portrange_first="NO" # Set first dynamically allocated port
74 ip_portrange_last="NO" # Set last dynamically allocated port
75 ipsec_enable="NO" # Set to YES to run setkey on ipsec_file
76 ipsec_file="/etc/ipsec.conf" # Name of config file for setkey
77 natd_program="/sbin/natd" # path to natd, if you want a different one.
78 natd_enable="NO" # Enable natd (if firewall_enable == YES).
79 natd_interface="" # Public interface or IPaddress to use.
80 natd_flags="" # Additional flags for natd.
81 pf_enable="NO" # Set to YES to enable packet filter (pf)
82 pf_rules="/etc/pf.conf" # rules definition file for pf
83 pf_program="/usr/sbin/pfctl" # where the pfctl program lives
84 pf_flags="" # additional flags for pfctl
85 pflog_enable="NO" # Set to YES to enable packet filter logging
86 pflog_logfile="/var/log/pflog" # where pflogd should store the logfile
87 pflog_program="/usr/sbin/pflogd" # where the pflogd program lives
88 pflog_flags="" # additional flags for pflogd
89 tcp_extensions="YES" # Set to NO to turn off RFC1323 extensions.
90 log_in_vain="0" # >=1 to log connects to ports w/o listeners.
91 tcp_keepalive="YES" # Enable stale TCP connection timeout (or NO).
92 # For the following option you need to have TCP_DROP_SYNFIN set in your
93 # kernel. Please refer to LINT and NOTES for details.
94 tcp_drop_synfin="NO" # Set to YES to drop TCP packets with SYN+FIN
95 # NOTE: this violates the TCP specification
96 icmp_drop_redirect="NO" # Set to YES to ignore ICMP REDIRECT packets
97 icmp_log_redirect="NO" # Set to YES to log ICMP REDIRECT packets
98 network_interfaces="auto" # List of network interfaces (or "auto").
99 cloned_interfaces="" # List of cloned network interfaces to create.
100 #cloned_interfaces="gif0 gif1 gif2 gif3" # Pre-cloning GENERIC config.
101 ifconfig_lo0="inet 127.0.0.1" # default loopback device configuration.
102 #ifconfig_lo0_alias0="inet 127.0.0.254 netmask 0xffffffff" # Sample alias entry.
103 #ifconfig_ed0_ipx="ipx 0x00010010" # Sample IPX address family entry.
104 #ifconfig_fxp0_name="net0" # Change interface name from fxp0 to net0.
106 # If you have any sppp(4) interfaces above, you might also want to set
107 # the following parameters. Refer to spppcontrol(8) for their meaning.
108 sppp_interfaces="" # List of sppp interfaces.
109 #sppp_interfaces="isp0" # example: sppp over ISDN
110 #spppconfig_isp0="authproto=chap myauthname=foo myauthsecret='top secret' hisauthname=some-gw hisauthsecret='another secret'"
111 gif_interfaces="NO" # List of GIF tunnels (or "NO").
112 #gif_interfaces="gif0 gif1" # Examples typically for a router.
113 # Choose correct tunnel addrs.
114 #gifconfig_gif0="10.1.1.1 10.1.2.1" # Examples typically for a router.
115 #gifconfig_gif1="10.1.1.2 10.1.2.2" # Examples typically for a router.
117 # User ppp configuration.
118 ppp_enable="NO" # Start user-ppp (or NO).
119 ppp_mode="auto" # Choice of "auto", "ddial", "direct" or "dedicated".
120 # For details see man page for ppp(8). Default is auto.
121 ppp_nat="YES" # Use PPP's internal network address translation or NO.
122 ppp_profile="papchap" # Which profile to use from /etc/ppp/ppp.conf.
123 ppp_user="root" # Which user to run ppp as
125 ### Network daemon (miscellaneous) ###
126 hostapd_enable="NO" # Run hostap daemon.
127 syslogd_enable="YES" # Run syslog daemon (or NO).
128 syslogd_program="/usr/sbin/syslogd" # path to syslogd, if you want a different one.
129 #syslogd_flags="-s" # Flags to syslogd (if enabled).
130 syslogd_flags="-ss" # Syslogd flags to not bind an inet socket
131 inetd_enable="NO" # Run the network daemon dispatcher (YES/NO).
132 inetd_program="/usr/sbin/inetd" # path to inetd, if you want a different one.
133 inetd_flags="-wW" # Optional flags to inetd
135 rwhod_enable="NO" # Run the rwho daemon (or NO).
136 rwhod_flags="" # Flags for rwhod
137 rarpd_enable="NO" # Run rarpd (or NO).
138 rarpd_flags="" # Flags to rarpd.
139 bootparamd_enable="NO" # Run bootparamd (or NO).
140 bootparamd_flags="" # Flags to bootparamd
141 pppoed_enable="NO" # Run the PPP over Ethernet daemon.
142 pppoed_provider="*" # Provider and ppp(8) config file entry.
143 pppoed_flags="-P /var/run/pppoed.pid" # Flags to pppoed (if enabled).
144 pppoed_interface="fxp0" # The interface that pppoed runs on.
145 sshd_enable="NO" # Enable sshd
146 sshd_program="/usr/sbin/sshd" # path to sshd, if you want a different one.
147 sshd_flags="" # Additional flags for sshd.
149 ftpd_enable="NO" # Run stand-alone ftp daemon (or NO).
150 ftpd_flags="" # Flags for ftpd, -D added implicitly.
152 ### Network File System (NFS): ###
153 ### Server-side options also need rpcbind_enable="YES" ###
155 ### NOTE: attribute cache timeouts only effect NFS lookup rpc's. If
156 ### the mtime matches the data cache is left intact.
158 amd_enable="NO" # Run amd service with $amd_flags (or NO).
159 amd_flags="-a /.amd_mnt -l syslog /host /etc/amd.map /net /etc/amd.map"
160 amd_map_program="NO" # Can be set to "ypcat -k amd.master"
161 nfs_client_enable="NO" # This host is an NFS client (or NO).
162 nfs_access_cache="5" # Client attribute cache timeout in seconds
163 #nfs_neg_cache="3" # Client attribute negative hit cache timeout
164 nfs_server_enable="NO" # This host is an NFS server (or NO).
165 nfs_server_flags="-u -t -n 4" # Flags to nfsd (if enabled).
166 mountd_enable="NO" # Run mountd (or NO).
167 mountd_flags="-r" # Flags to mountd (if NFS server enabled).
168 weak_mountd_authentication="NO" # Allow non-root mount requests to be served.
169 nfs_reserved_port_only="NO" # Provide NFS only on secure port (or NO).
170 nfs_bufpackets="" # bufspace (in packets) for client
171 rpc_lockd_enable="NO" # Run NFS rpc.lockd needed for client/server.
172 rpc_lockd_flags="" # Flags to rpc.lockd (if enabled).
173 rpc_statd_enable="NO" # Run NFS rpc.statd needed for client/server.
174 rpc_statd_flags="" # Flags to rpc.statd (if enabled).
175 rpc_umntall_enable="YES" # Run NFS rpc.umntall on boot and shutdown
176 rpcbind_enable="NO" # Run the portmapper service (YES/NO).
177 rpcbind_program="/usr/sbin/rpcbind" # path to rpcbind, if you want a different one.
178 rpcbind_flags="" # Flags to rpcbind (if enabled).
179 rpc_ypupdated_enable="NO" # Run if NIS master and SecureRPC (or NO).
180 keyserv_enable="NO" # Run the SecureRPC keyserver (or NO).
181 keyserv_flags="" # Flags to keyserv (if enabled).
183 ### Network Time Services options: ###
184 timed_enable="NO" # Run the time daemon (or NO).
185 timed_flags="" # Flags to timed (if enabled).
186 dntpd_enable="NO" # Run dntpd Network Time Protocol (or NO).
187 dntpd_program="/usr/sbin/dntpd" # path to dntpd, if you want a different one.
188 dntpd_flags="" # Flags to dntpd (if enabled) also server name(s)
190 # Bluetooth deamons and options:
191 btconfig_enable="NO" # Configure Bluetooth devices (or NO).
192 btconfig_devices="" # List of Bluetooth devices (or empty for all).
193 #btconfig_<device>="" # Parameters to pass to <device>.
194 btconfig_args="" # Parameters to pass to all devices.
195 sdpd_enable="NO" # Run the Service Discovery Profile daemon (or NO).
196 sdpd_flags="" # Flags to sdpd (if enabled).
197 bthcid_enable="NO" # Run the Bluetooth Link Key/PIN Code Manager (or NO).
198 bthcid_flags="" # Flags to bthcid (if enabled).
200 # Network Information Services (NIS) options: All need rpcbind_enable="YES" ###
201 nis_client_enable="NO" # We're an NIS client (or NO).
202 nis_client_flags="" # Flags to ypbind (if enabled).
203 nis_ypset_enable="NO" # Run ypset at boot time (or NO).
204 nis_ypset_flags="" # Flags to ypset (if enabled).
205 nis_server_enable="NO" # We're an NIS server (or NO).
206 nis_server_flags="" # Flags to ypserv (if enabled).
207 nis_ypxfrd_enable="NO" # Run rpc.ypxfrd at boot time (or NO).
208 nis_ypxfrd_flags="" # Flags to rpc.ypxfrd (if enabled).
209 nis_yppasswdd_enable="NO" # Run rpc.yppasswdd at boot time (or NO).
210 nis_yppasswdd_flags="" # Flags to rpc.yppasswdd (if enabled).
212 ### Network routing options: ###
213 defaultrouter="NO" # Set to default gateway (or NO).
214 static_routes="" # Set to static route list (or leave empty).
215 gateway_enable="NO" # Set to YES if this host will be a gateway.
216 router_enable="NO" # Set to YES to enable a routing daemon.
217 router_program="/sbin/routed" # Name of routing daemon to use if enabled.
218 router_flags="-q" # Flags for routing daemon.
219 mrouted_enable="NO" # Do multicast routing (see /etc/mrouted.conf).
220 mrouted_flags="" # Flags for multicast routing daemon.
221 ipxgateway_enable="NO" # Set to YES to enable IPX routing.
222 ipxrouted_enable="NO" # Set to YES to run the IPX routing daemon.
223 ipxrouted_flags="" # Flags for IPX routing daemon.
224 arpproxy_all="NO" # replaces obsolete kernel option ARP_PROXYALL.
225 forward_sourceroute="NO" # do source routing (only if gateway_enable is set to "YES")
226 accept_sourceroute="NO" # accept source routed packets to us
228 ### ATM interface options: ###
229 atm_enable="NO" # Configure ATM interfaces (or NO).
230 #atm_netif_hea0="atm 1" # Network interfaces for physical interface.
231 #atm_sigmgr_hea0="uni31" # Signalling manager for physical interface.
232 #atm_prefix_hea0="ILMI" # NSAP prefix (UNI interfaces only) (or ILMI).
233 #atm_macaddr_hea0="NO" # Override physical MAC address (or NO).
234 #atm_arpserver_atm0="0x47.0005.80.999999.9999.9999.9999.999999999999.00" # ATMARP server address (or local).
235 #atm_scsparp_atm0="NO" # Run SCSP/ATMARP on network interface (or NO).
236 atm_arps="" # Set to permanent ARP list (or leave empty).
238 ### ISDN interface options: (see also: /usr/share/examples/isdn) ###
239 isdn_enable="NO" # Enable the ISDN subsystem (or NO).
240 isdn_fsdev="NO" # Output device for fullscreen mode (or NO for daemon mode).
241 isdn_flags="-dn -d0x1f9" # Flags for isdnd
242 isdn_ttype="cons25" # terminal type for fullscreen mode
243 isdn_screenflags="NO" # screenflags for ${isdn_fsdev}
244 isdn_trace="NO" # Enable the ISDN trace subsystem (or NO).
245 isdn_traceflags="-f /var/tmp/isdntrace0" # Flags for isdntrace
247 ### Miscellaneous network options: ###
248 icmp_bmcastecho="NO" # respond to broadcast ping packets
250 ### IPv6 options: ###
251 ipv6_enable="NO" # Set to YES to set up for IPv6.
252 ipv6_network_interfaces="auto" # List of network interfaces (or "auto").
253 ipv6_defaultrouter="NO" # Set to IPv6 default gateway (or NO).
254 #ipv6_defaultrouter="2002:c058:6301::" # Use this for 6to4 (RFC 3068)
255 ipv6_static_routes="" # Set to static route list (or leave empty).
256 #ipv6_static_routes="xxx" # An example to set fec0:0000:0000:0006::/64
257 # route toward loopback interface.
258 #ipv6_route_xxx="fec0:0000:0000:0006:: -prefixlen 64 ::1"
259 ipv6_gateway_enable="NO" # Set to YES if this host will be a gateway.
260 ipv6_router_enable="NO" # Set to YES to enable an IPv6 routing daemon.
261 ipv6_router_program="/usr/sbin/route6d" # Name of IPv6 routing daemon.
262 ipv6_router_flags="" # Flags to IPv6 routing daemon.
263 #ipv6_router_flags="-l" # Example for route6d with only IPv6 site local
264 # addrs.
265 #ipv6_router_flags="-q" # If you want to run a routing daemon on an end
266 # node, you should stop advertisement.
267 #ipv6_network_interfaces="ed0 ep0" # Examples for router
268 # or static configuration for end node.
269 # Choose correct prefix value.
270 #ipv6_prefix_ed0="fec0:0000:0000:0001 fec0:0000:0000:0002" # Examples for rtr.
271 #ipv6_prefix_ep0="fec0:0000:0000:0003 fec0:0000:0000:0004" # Examples for rtr.
272 #ipv6_ifconfig_ed0="fec0:0:0:5::1 prefixlen 64" # Sample manual assign entry
273 #ipv6_ifconfig_ed0_alias0="fec0:0:0:5::2 prefixlen 64" # Sample alias entry.
274 ipv6_default_interface="NO" # Default output interface for scoped addrs.
275 # Now this works only for IPv6 link local
276 # multicast addrs.
277 rtadvd_enable="NO" # Set to YES to enable an IPv6 router
278 # advertisement daemon. If set to YES,
279 # this router becomes a possible candidate
280 # IPv6 default router for local subnets.
281 rtadvd_interfaces="" # Interfaces rtadvd sends RA packets.
282 rtsold_enable="NO" # Set to YES to enable an IPv6 routing
283 # solicitation daemon. This is used for
284 # automatic discovery of non-link local
285 # addresses.
286 rtsold_flags="-a" # Do autoprobing of outgoing interface.
287 mroute6d_enable="NO" # Do IPv6 multicast routing.
288 mroute6d_program="/usr/local/sbin/pim6dd" # Name of IPv6 multicast
289 # routing daemon. You need to
290 # install it from package or
291 # port.
292 mroute6d_flags="" # Flags to IPv6 multicast routing daemon.
293 stf_interface_ipv4addr="" # Local IPv4 addr for 6to4 IPv6 over IPv4
294 # tunneling interface. Specify this entry
295 # to enable 6to4 interface.
296 stf_interface_ipv4plen="0" # Prefix length for 6to4 IPv4 addr,
297 # to limit peer addr range. Effective value
298 # is 0-31.
299 stf_interface_ipv6_ifid="0:0:0:1" # IPv6 interface id for stf0.
300 # If you like, you can set "AUTO" for this.
301 stf_interface_ipv6_slaid="0000" # IPv6 Site Level Aggregator for stf0
302 ipv6_faith_prefix="NO" # Set faith prefix to enable a FAITH
303 # IPv6-to-IPv4 TCP translator. You also need
304 # faithd(8) setup.
305 ipv6_ipv4mapping="NO" # Set to "YES" to enable IPv4 mapped IPv6 addr
306 # communication. (like ::ffff:a.b.c.d)
307 ipv6_firewall_enable="NO" # Set to YES to enable IPv6 firewall
308 # functionality
309 ipv6_firewall_script="/etc/rc.firewall6" # Which script to run to set up the IPv6 firewall
310 ipv6_firewall_type="UNKNOWN" # IPv6 Firewall type (see /etc/rc.firewall6)
311 ipv6_firewall_quiet="NO" # Set to YES to suppress rule display
312 ipv6_firewall_logging="NO" # Set to YES to enable events logging
313 ipv6_firewall_flags="" # Flags passed to ip6fw when type is a file
315 ##############################################################
316 ### System console options #################################
317 ##############################################################
319 keymap="NO" # keymap in /usr/share/syscons/keymaps/* (or NO).
320 keyrate="NO" # keyboard rate to: slow, normal, fast (or NO).
321 keybell="NO" # See kbdcontrol(1) for options. Use "off" to disable.
322 keychange="NO" # function keys default values (or NO).
323 cursor="NO" # cursor type {normal|blink|destructive} (or NO).
324 scrnmap="NO" # screen map in /usr/share/syscons/scrnmaps/* (or NO).
325 font8x16="NO" # font 8x16 from /usr/share/syscons/fonts/* (or NO).
326 font8x14="NO" # font 8x14 from /usr/share/syscons/fonts/* (or NO).
327 font8x8="NO" # font 8x8 from /usr/share/syscons/fonts/* (or NO).
328 blanktime="300" # blank time (in seconds) or "NO" to turn it off.
329 saver="NO" # screen saver: Uses /modules/${saver}_saver.ko
330 moused_enable="NO" # Run the mouse daemon.
331 moused_type="auto" # See man page for rc.conf(5) for available settings.
332 moused_port="/dev/psm0" # Set to your mouse port.
333 moused_flags="" # Any additional flags to moused.
334 mousechar_start="NO" # if 0xd0-0xd3 default range is occupied in your
335 # language code table, specify alternative range
336 # start like mousechar_start=3, see vidcontrol(1)
337 vidhistory="" # Set video history buffer size
338 allscreens_flags="" # Set this vidcontrol mode for all virtual screens
339 allscreens_kbdflags="" # Set this kbdcontrol mode for all virtual screens
342 ##############################################################
343 ### Mail Transfer Agent (MTA) options ######################
344 ##############################################################
346 mta_start_script="/etc/rc.sendmail"
347 # Script to start your chosen MTA, called by /etc/rc.
348 # Settings for /etc/rc.sendmail:
349 sendmail_enable="NO" # Run the sendmail inbound daemon (YES/NO).
350 sendmail_flags="-L sm-mta -bd -q30m" # Flags to sendmail (as a server)
351 sendmail_submit_enable="YES" # Start a localhost-only MTA for mail submission
352 sendmail_submit_flags="-L sm-mta -bd -q30m -ODaemonPortOptions=Addr=localhost"
353 # Flags for localhost-only MTA
354 sendmail_outbound_enable="YES" # Dequeue stuck mail (YES/NO).
355 sendmail_outbound_flags="-L sm-queue -q30m" # Flags to sendmail (outbound only)
356 sendmail_msp_queue_enable="YES" # Dequeue stuck clientmqueue mail (YES/NO).
357 sendmail_msp_queue_flags="-L sm-msp-queue -Ac -q30m"
358 # Flags for sendmail_msp_queue daemon.
359 sendmail_rebuild_aliases="YES" # Run newaliases if necessary (YES/NO).
362 ##############################################################
363 ### Miscellaneous administrative options ###################
364 ##############################################################
366 mixer_enable="NO" # Manage mixer settings across reboots
367 cron_enable="YES" # Run the periodic job daemon.
368 cron_program="/usr/sbin/cron" # Which cron executable to run (if enabled).
369 cron_flags="" # Which options to pass to the cron daemon.
370 lpd_enable="NO" # Run the line printer daemon.
371 lpd_program="/usr/sbin/lpd" # path to lpd, if you want a different one.
372 lpd_flags="" # Flags to lpd (if enabled).
373 nscd_enable="NO" # Run the nsswitch caching daemon.
374 usbd_enable="NO" # Run the usbd daemon.
375 usbd_flags="" # Flags to usbd (if enabled).
376 devd_enable="NO" # Rund devd(8) daemon.
377 devd_flags="" # Flags to devd(8) (if enabled).
378 dumpdev="NO" # Device name to crashdump to (or NO).
379 dumpdir="/var/crash" # Directory where crash dumps are to be stored
380 savecore_flags="" # Used if dumpdev is enabled above, and present.
381 crashinfo_enable="YES" # Automatically generate crash dump summary.
382 crashinfo_program="/usr/sbin/crashinfo" # Script to generate crash dump summary.
383 enable_quotas="NO" # turn on quotas on startup (or NO).
384 check_quotas="YES" # Check quotas on startup (or NO).
385 accounting_enable="NO" # Turn on process accounting (or NO).
386 sysvipc_enable="NO" # Load System V IPC primitives at startup (or NO).
387 linux_enable="NO" # Linux binary compatibility loaded at startup (or NO).
388 clear_tmp_enable="NO" # Clear /tmp at startup.
389 ldconfig_insecure="NO" # Set to YES to disable ldconfig security checks
390 ldconfig_paths="/usr/lib /usr/lib/gcc* /usr/lib/compat /usr/pkg/lib /usr/local/lib"
391 # shared library search paths
392 kern_securelevel="-1" # range: -1..3 ; `-1' is the most insecure
393 update_motd="YES" # update version info in /etc/motd (or NO)
394 start_vinum="NO" # set to YES to start vinum
395 udevd_enable="NO" # Run udevd(8) daemon.
396 lvm_enable="NO" # Run LVM volume discovery.
397 rand_irqs="NO" # Stir the entropy pool (like "5 11" or NO).
398 dmesg_enable="YES" # Save dmesg(8) to /var/run/dmesg.boot
399 newsyslog_enable="NO" # Run newsyslog at startup.
400 newsyslog_flags="" # Flags to newsyslog (if enabled).
401 resident_enable="NO" # Process /etc/resident.conf
402 varsym_enable="NO" # Process /etc/varsym.conf
403 watchdogd_enable="NO" # Start the software watchdog daemon
405 ##############################################################
406 ### Jail Configuration #######################################
407 ##############################################################
409 jail_enable="NO" # Set to NO to disable starting of any jails
410 jail_list="" # Space separated list of names of jails
411 jail_set_hostname_allow="YES" # Allow root user in a jail to change its hostname
412 jail_socket_unixiproute_only="YES" # Route only TCP/IP within a jail
413 jail_sysvipc_allow="NO" # Allow SystemV IPC use from within a jail
416 # To use rc's built-in jail infrastructure create entries for
417 # each jail, specified in jail_list, with the following variables.
418 # NOTES:
419 # - replace 'example' with the jail's name.
420 # - except rootdir, hostname and ip, all of the following variables may be made
421 # global jail variables if you don't specify a jail name (ie. jail_interface).
423 #jail_example_rootdir="/usr/jail/default" # Jail's root directory
424 #jail_example_hostname="default.domain.com" # Jail's hostname
425 #jail_example_ip="192.168.0.10" # Jail's IP number
426 #jail_example_interface="" # Interface to create the IP alias on
427 #jail_example_exec_start="/bin/sh /etc/rc" # command to execute in jail for starting
428 #jail_example_exec_stop="/bin/sh /etc/rc.shutdown" # command to execute in jail for stopping
429 #jail_example_fdesc_enable="NO" # mount fdesc in the jail
430 #jail_example_procfs_enable="NO" # mount procfs in jail
431 #jail_example_mount_enable="NO" # mount/umount jail's fs
432 #jail_example_fstab="" # fstab(5) for mount/umount
433 #jail_example_flags="-l -U root" # flags for jail(8)
435 ##############################################################
436 ### VKernel options #########################################
437 ##############################################################
439 vkernel_enable="NO" # Set to YES to enable starting of vkernels
440 vkernel_list="" # Space separated list of names of vkernels
441 #vkernel_bin="/boot/kernel.VKERNEL" # Default path to the vkernel binary
442 #vkernel_kill_timeout="45" # Default timeout before a SIGKILL is issued
445 # Create an entry for each vkernel specified in vkernel_list
446 # replacing 'example' by the name of the vkernel.
448 #vkernel_example_bin="/boot/kernel.VKERNEL"
449 # Path to the vkernel binary
450 #vkernel_example_memsize="64m"
451 # Amount of memory for the vkernel
452 #vkernel_example_rootimg_list="/var/vkernel/rootimg.01"
453 # Space separated list of disk images
454 #vkernel_example_iface_list="auto:bridge0"
455 # Optional: space separated list network interfaces for the vkernel
456 #vkernel_example_logfile="/dev/null"
457 # Optional: path to the console log file
458 #vkernel_example_flags="-U"
459 # Optional: aditional flags to start the vkernel with
460 #vkernel_example_kill_timeout="45"
461 # Optional: timeout before SIGKILL is issued when stopping the vkernel
463 ##############################################################
464 ### Define source_rc_confs, the mechanism used by /etc/rc.* ##
465 ### scripts to source rc_conf_files overrides safely. ##
466 ##############################################################
468 if [ -z "${source_rc_confs_defined}" ]; then
469 source_rc_confs_defined=yes
470 source_rc_confs () {
471 local i sourced_files
472 for i in ${rc_conf_files}; do
473 case ${sourced_files} in
474 *:$i:*)
477 sourced_files="${sourced_files}:$i:"
478 if [ -r $i ]; then
479 . $i
482 esac
483 done