Bug#1113774: Disabling -fcf-protection in sudo for bookworm

Marc Haber <[email protected]> Wed, 3 Sep 2025 13:11:12 +0200
Newsgroups gmane.linux.debian.devel.ctte
Message-ID <aLgiUNeXEBWJfSzw__20971.8952699163$1756898012$gmane$org@torres.zugschlus.de>
Hi,

On Tue, Sep 02, 2025 at 11:28:22AM -0400, Paul Tagliamonte wrote:
>The natural outcome here seems to be:
>
>  a) do nothing as-is, some fraction of supported but non-intel CPUs will
>     get runtime failures, since we've altered the ISA baseline and      
>never realized it due to popularity
>
>  b) remove this flag from sudo specifically, fixing sudo specifically      
>in bookworm (oldstable)
>
>  c) change all i386 package flags for bookworm specifically 
>(oldstable)      and binNMU the whole archive, FTBFS and all
>
>  d) declare bookworm i386 retroactively always was a different ISA baseline
>     ("We have always been at war with Eastasia")

What I don't understand is why those people running those rather exotic 
machines don't just run another privilege escalation tool like runas or 
compile their own sudo package.

I would be willing to provide a signed and patched sudo outside the 
debian archive (we still do have people.debian.org, right?) to get this 
settled if we can't find consensus that the change is indeed harmless.

Greetings
Marc