Bug#1113774: Disabling -fcf-protection in sudo for bookworm

Paul Tagliamonte <[email protected]> Tue, 2 Sep 2025 11:28:22 -0400
Newsgroups gmane.linux.debian.devel.ctte
Message-ID <20250902152822.GA221330__43199.3712017842$1756827088$gmane$org@dc.cant.vote>
On Tue, Sep 02, 2025 at 05:14:27PM +0200, Christoph Berg wrote:
>Re: Stefano Rivera
>> It seems that the intention of the new instruction was to be interpreted as
>> a NOP on older hardware, but that obviously didn't happen on these non-Intel
>> CPUs.
>
>https://lists.debian.org/debian-devel/2023/10/msg00120.html states
>these processors are unsupported.

It's tough because the link is gone now (since it was /testing/ at the 
time that email was sent) -- but in reply, Ben adds[1]

> Sorry, the page I linked is for testing ("trixie", which will become
> Debian 13).  Debian 12 "bookworm" is supposed to still support this
> CPU.

I also appreciate the detail about this CPU instruction being disused on 
all bin:i386 even if the kernel is amd64.

I've grown a bit more sympathetic to the argument here; but I'm still 
not 100% what to think of this.

The natural outcome here seems to be:

   a) do nothing as-is, some fraction of supported but non-intel CPUs will
      get runtime failures, since we've altered the ISA baseline and 
      never realized it due to popularity

   b) remove this flag from sudo specifically, fixing sudo specifically 
      in bookworm (oldstable)

   c) change all i386 package flags for bookworm specifically (oldstable) 
      and binNMU the whole archive, FTBFS and all

   d) declare bookworm i386 retroactively always was a different ISA baseline
      ("We have always been at war with Eastasia")

It seems to me that option "c" here is a nonstarter, even though it's 
likely the correct way to go about this. If bookworm was still testing 
and we found this, I can't imagine we'd do anything *except* that route 
(to Marc's point -- which, I think that's right -- why is sudo 
special-cased here besides "it's run a lot" and why isn't this 
archive-wide if it's truely a noop?)

[1]: https://lists.debian.org/debian-devel/2023/10/msg00128.html

-- 
   ⢀⣴⠾⠻⢶⣦⠀               Paul Tagliamonte <paultag>
   ⣾⠁⢠⠒⠀⣿⡁  https://people.debian.org/~paultag | https://pault.ag/
   ⢿⡄⠘⠷⠚⠋        Debian, the universal operating system.
   ⠈⠳⣄⠀⠀  4096R / FEF2 EB20 16E6 A856 B98C  E820 2DCD 6B5D E858 ADF3
signature.asc (application/pgp-signature, 488 B)
-----BEGIN PGP SIGNATURE-----

iQEzBAABCgAdFiEE8rctyP6kE7DHa+fOytLPCmgIXzIFAmi3DRQACgkQytLPCmgI
XzKs8wf9HgMEssSbEP3AkPIDT/XHdxHDjD7Syh45wUWg5B8Y0RTsu2LDseY3vYsG
ZRGz55/8yESOaJEhLCRXU9m4iVuQLpOEFe3iPJa82OrTFqOkheM0yFAq6oc5QmCz
Pv4bMwLtl3D2mrv3+fJFo9Y0rIc1BnP4NV2q214nogAptyjjMRSlPGxHQNPYZ+vf
VNY4EPyppL4k00+yYMubgcuX2CjDIt7E/pe3+XvxYnFp7+hmSGcWg6P+ijNODyuQ
kZGeLw4xXsAVbON65jPnn1xdYI7pbBrhymHQ+DgmF0KuSHoRT7VmCH0Yd5T+XL62
0W/lt1A3f/QqoQmiR5ROdZGeM4fFLw==
=QsVM
-----END PGP SIGNATURE-----