Bug#1113774: marked as done (Disabling -fcf-protection in sudo for bookworm)

"Debian Bug Tracking System" <[email protected]> Thu, 04 Dec 2025 14:49:01 +0000
Newsgroups gmane.linux.debian.devel.ctte
Message-ID <handler.1113774.D1113774.17648596433797274.ackdone@bugs.debian.org>
This is a multi-part message in MIME format...

------------=_1764859741-3798719-0
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain; charset="utf-8"

Your message dated Thu, 4 Dec 2025 15:47:15 +0100
with message-id <[email protected]>
and subject line Debian Technical Committee: Bug#1113774: Disabling -fcf-pr=
otection in sudo for bookworm
has caused the Debian Bug report #1113774,
regarding Disabling -fcf-protection in sudo for bookworm
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


--=20
1113774: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=3D1113774
Debian Bug Tracking System
Contact [email protected] with problems

------------=_1764859741-3798719-0
Content-Type: message/rfc822
Content-Disposition: inline
Content-Transfer-Encoding: 7bit

Received: (at submit) by bugs.debian.org; 2 Sep 2025 12:33:14 +0000
X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02
	(2024-03-25) on buxtehude.debian.org
X-Spam-Level: 
X-Spam-Status: No, score=-15.2 required=4.0 tests=BAYES_00,
	BODY_INCLUDES_PACKAGE,DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,
	DKIM_VALID_EF,HAS_PACKAGE,SPF_HELO_NONE,SPF_PASS autolearn=ham
	autolearn_force=no version=4.0.1-bugs.debian.org_2005_01_02
X-Spam-Bayes: score:0.0000 Tokens: new, 82; hammy, 150; neutral, 127; spammy,
	0. spammytokens: hammytokens:0.000-+--bookworm, 0.000-+--UD:kernel.org,
	 0.000-+--fcf-protection, 0.000-+--fcfprotection, 0.000-+--Bookworm
Return-path: <[email protected]>
Received: from 12.mo533.mail-out.ovh.net ([178.33.248.79]:38383)
	by buxtehude.debian.org with esmtps (TLS1.3:ECDHE_X25519__RSA_PSS_RSAE_SHA256__AES_256_GCM:256)
	(Exim 4.96)
	(envelope-from <[email protected]>)
	id 1utQCG-000gho-1d
	for [email protected];
	Tue, 02 Sep 2025 12:33:14 +0000
Received: from director1.derp.mail-out.ovh.net (director1.derp.mail-out.ovh.net [51.68.80.175])
	by mo533.mail-out.ovh.net (Postfix) with ESMTPS id 4cGPw70FDgz5x27;
	Tue,  2 Sep 2025 12:20:38 +0000 (UTC)
Received: from director1.derp.mail-out.ovh.net (director1.derp.mail-out.ovh.net. [127.0.0.1])
        by director1.derp.mail-out.ovh.net (inspect_sender_mail_agent) with SMTP
        for <[email protected]>; Tue,  2 Sep 2025 12:20:38 +0000 (UTC)
Received: from mta7.priv.ovhmail-u1.ea.mail.ovh.net (unknown [10.110.37.24])
	by director1.derp.mail-out.ovh.net (Postfix) with ESMTPS id 4cGPw53r2fz5xPF;
	Tue,  2 Sep 2025 12:20:37 +0000 (UTC)
Received: from orca.pet (unknown [10.1.6.9])
	by mta7.priv.ovhmail-u1.ea.mail.ovh.net (Postfix) with ESMTPSA id E5B23B83364;
	Tue,  2 Sep 2025 12:20:31 +0000 (UTC)
Authentication-Results:garm.ovh; auth=pass (GARM-107S00155a661e3-20c9-426c-8d6f-027e381377b4,
                    B677A376967D575A53C78FE4FF5C940A066EF03B) [email protected]
X-OVh-ClientIp:79.117.41.176
Message-ID: <[email protected]>
Date: Tue, 2 Sep 2025 14:20:32 +0200
MIME-Version: 1.0
User-Agent: Mozilla Thunderbird
Content-Language: es-ES
To: [email protected]
Cc: Marc Haber <[email protected]>
From: Marcos Del Sol Vives <[email protected]>
Subject: Disabling -fcf-protection in sudo for bookworm
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 7bit
X-Ovh-Tracer-Id: 16218869636441855552
X-VR-SPAMSTATE: OK
X-VR-SPAMSCORE: 0
X-VR-SPAMCAUSE: gggruggvucftvghtrhhoucdtuddrgeeffedrtdeggddvgecutefuodetggdotefrodftvfcurfhrohhfihhlvgemucfqggfjpdevjffgvefmvefgnecuuegrihhlohhuthemucehtddtnecunecujfgurhepkfffgggfvfevhffutgfgsehtjeertddtvdejnecuhfhrohhmpeforghrtghoshcuffgvlhcuufholhcugghivhgvshcuoehmrghrtghoshesohhrtggrrdhpvghtqeenucggtffrrghtthgvrhhnpeekheefhefhieejfeeileektedtleehveeuvdelgfdtveeihedtjeehueejuedugeenucffohhmrghinhepuggvsghirghnrdhorhhgpdhkvghrnhgvlhdrohhrghdpghhithhhuhgsrdgtohhmnecukfhppeduvdejrddtrddtrddupdejledruddujedrgedurddujeeinecuvehluhhsthgvrhfuihiivgeptdenucfrrghrrghmpehinhgvthepuddvjedrtddrtddruddpmhgrihhlfhhrohhmpehmrghrtghoshesohhrtggrrdhpvghtpdhnsggprhgtphhtthhopeefpdhrtghpthhtohepshhusghmihhtsegsuhhgshdruggvsghirghnrdhorhhgpdhrtghpthhtohepmhgrrhgtohhssehorhgtrgdrphgvthdprhgtphhtthhopehmhhdo
 uggvsghirghnqdhkvghrnhgvlhesiihughhstghhlhhushdruggvpdfovfetjfhoshhtpehmohehfeefmgdpmhhouggvpehsmhhtphhouhht
DKIM-Signature: a=rsa-sha256; bh=UEOUBuCRnUuaxRaWr+Npi9Q480iCMRwW6bY1Z2uWwh0=;
 c=relaxed/relaxed; d=orca.pet; h=From; s=ovhmo-selector-1; t=1756815639;
 v=1;
 b=axH+sVkco7asSZdkAvsPw/cBiB9NGbveO0SFKJEBUpIjQDNOlMwXy4BjOTm1eECy74r5v4ro
 oRqHVKzQccadiMeVQhB+Jngt/2OJ4YR70SXsr7eQ5SupYkcZevSrboWiKiOli8L30c0sixl1zfF
 a823KX9UWQmVYUQQUXy0YIm7ycXZCnDNZIx1fsDm9NSQRv0Chyw1FtRTVCdYM+GMxU2Q2GUdk+4
 zBR+gSQIefjxG/Z660uRjxGn3hy1MFYZ3XHi6waCJxjtWGcV1EfzecICSqWpoY8yIuY+SfNMvcv
 Q7l5m1yLsfAV46dpRnIlFprstgXj2WYMxgV17EDjlenlA==
X-Greylist: delayed 391 seconds by postgrey-1.37 at buxtehude; Tue, 02 Sep 2025 12:33:12 UTC
Delivered-To: [email protected]

Package: tech-ctte
Severity: normal

Currently "sudo" in Bookworm is broken on i686 for some i686-like
processors such as a Vortex86DX3 I own and VIA processors others have
(https://lists.debian.org/debian-devel/2023/10/msg00118.html), causing a
SIGILL if you attempt to run on them.

The issue is that sudo in bookworm is compiled with "-fcf-protection=full",
which causes binaries to contain ENDBR32 instructions. These are part of
Indirect Branch Tracking, a mechanism introduced by Intel's CET meant to
harden against exploits using return-oriented programming.

END32s are part of a formely-reserved chunk of instructions called
"hintable NOPs". These, to my knowledge, were only defined in US patent
US5701442A but not on the software design manual, where they appeared as
"reserved". Thus these processors do what in general reserved instructions
should do - raise an exception.

Disabling a security mechanism for these uncommon processors would be
probably a bad idea, but the thing is that this mechanism is _not_
supported by the Linux kernel in user mode. Thus, the compilation with
IBT just increases the size of the binaries at best, and prevents running
the binary at worst.

For user-mode, and only in 64-bit mode (but not on native 32-bit system,
neither when running 32-bit applications on a 64-bit kernel), Linux uses
another mechanism that does not require new instructions called shadow
stacks.

This is documented in the Kernel's own page about CET:
https://docs.kernel.org/arch/x86/shstk.html#cet-background
There it explicitely says that the protections are only available in 64-bit
modes, and further analysis of the kernel's code I've done confirms that
being the case:
https://lore.kernel.org/all/[email protected]/

I've submitted a patch against upstream sudo that has been accepted
(https://github.com/sudo-project/sudo/pull/468) that enables the
compilation with -fcf-protection only for 64-bit mode, but the current sudo
Debian maintainer has refused to accept a patch for "bookworm" that fixes
this issue, being concerned that it could lower the overall security of the
binary.

As part of an effort to handle these ENDBR32s in the kernel and ignore
them, H. Peter Anvin (a major x86 arch maintainer in the Linux kernel)
confirmed that 32-bit user-mode applications do not gain any security from
using ENDBR32, and that just disabling the IBT protection for them
would be the best approach:
https://lore.kernel.org/all/[email protected]/

Since bookworm is the last i686 release, I think it'd make sense to fix
this issue.

Greetings,
Marcos

------------=_1764859741-3798719-0
Content-Type: message/rfc822
Content-Disposition: inline
Content-Transfer-Encoding: 7bit

Received: (at 1113774-done) by bugs.debian.org; 4 Dec 2025 14:47:23 +0000
X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02
	(2024-03-25) on buxtehude.debian.org
X-Spam-Level: 
X-Spam-Status: No, score=-11.7 required=4.0 tests=BAYES_00,FROMDEVELOPER,
	HAS_BUG_NUMBER,HEADER_FROM_DIFFERENT_DOMAINS,RCVD_IN_DNSWL_MED,
	SPF_HELO_NONE,SPF_PASS,X_DEBBUGS_NO_ACK autolearn=ham
	autolearn_force=no version=4.0.1-bugs.debian.org_2005_01_02
X-Spam-Bayes: score:0.0000 Tokens: new, 13; hammy, 150; neutral, 256; spammy,
	0. spammytokens: hammytokens:0.000-+--trixie, 0.000-+--bookworm,
	0.000-+--HX-Debbugs-No-Ack:please, 0.000-+--UD:kernel.org,
	0.000-+--UD:m4
Return-path: <[email protected]>
Received: from goedel.df7cb.de ([49.13.90.212]:42324)
	by buxtehude.debian.org with esmtps (TLS1.3:ECDHE_X25519__RSA_PSS_RSAE_SHA256__AES_256_GCM:256)
	(Exim 4.96)
	(envelope-from <[email protected]>)
	id 1vRAc5-00Fvpn-0H
	for [email protected];
	Thu, 04 Dec 2025 14:47:23 +0000
Received: from msg.df7cb.de (unknown [IPv6:2a02:908:1472:9340:f0ad:fc6e:9c86:f1dc])
	by goedel.df7cb.de (Postfix) with ESMTPSA id B28AF1D9;
	Thu, 04 Dec 2025 14:47:15 +0000 (UTC)
Date: Thu, 4 Dec 2025 15:47:15 +0100
From: Christoph Berg <[email protected]>
To: [email protected],
	Marc Haber <[email protected]>,
	Marcos Del Sol Vives <[email protected]>
Subject: Debian Technical Committee: Bug#1113774: Disabling -fcf-protection
 in sudo for bookworm
Message-ID: <[email protected]>
Mail-Followup-To: Christoph Berg <[email protected]>,
	[email protected],
	Marc Haber <[email protected]>,
	Marcos Del Sol Vives <[email protected]>
References: <[email protected]>
 <[email protected]>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <[email protected]>
X-Debbugs-No-Ack: please

(Bcc'ing -devel for information)

Re: To [email protected]
> In #1113774, Marcos Del Sol Vives is asking the committee about the compiler
> flags used for sudo in bookworm on the i386 architecture. The sudo version
> there is enabling `-fcf-protection` when supported by the compiler:
> 
> https://sources.debian.org/src/sudo/1.9.13p3-1%2Bdeb12u2/m4/hardening.m4#L108-L114
> 
> The problem is, that on his machine, a Vortex86DX3, the generated ENDBR
> instructions, which live in an opcode region declared as NOPs in earlier
> architecture specs, are not ignored, but raise exceptions and cause sudo to
> abort.
> 
> There is a lot of evidence that Control-flow Enforcement Technology (CET or
> cf-protection) is only meant to be enabled on 64-bit binaries and is
> ineffective elsewhere:
> * https://docs.kernel.org/next/x86/shstk.html
> * https://lkml.org/lkml/2025/9/1/1704
> 
> One part of the thread was discussing the usefulness of this feature even in
> 64-bit environments (the kernel only half-supports it in userland) which has
> led to https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1113864 being filed on
> dpkg-dev, but this is not relevant to the TC question. In fact, dpkg-dev is
> only emitting -fcf-protection on amd64 and not on i386. A large part of the
> thread assumed the default bookworm compiler flags had that problem, but it's
> actually upstream sudo adding -fcf-protection.
> 
> Around the time of the discussion, upstream sudo included a change that limits
> -fcf-protection to x86_64: https://github.com/sudo-project/sudo/pull/468
> 
> The question if Vortex86DX3 is part of bookworm's i386 architecture baseline
> was raised. In https://lists.debian.org/debian-devel/2023/10/msg00120.html Ben
> Hutchings confirms that ENDBR32 should be ignored by i686-conformant
> processors, and that i686 is required for bookworm. (He corrects himself in the
> next mail saying this would apply to trixie only, but again corrects himself
> saying this applies to bookworm indeed.) This seems to indicate that
> Vortex86DX3 is not i686-conformant. The submitter claims the CPU is conformant,
> citing https://psc.informatik.uni-jena.de/hw/p-pro-3.pdf page 417 as saying
> ENDBR32 was "reserved".
> 
> https://www.debian.org/releases/bookworm/i386/release-notes/ch-information.en.html#i386-is-i686
> 
> Debian trixie bumps the compiler baseline for i386 such that this CPU is
> definitely no longer supported so this issue is solely about bookworm.
> 
> The TL;DR summary of the problem is: in Debian bookworm, the sudo package is
> using -fcf-protection on i386 (where it should be a no-op), but this breaks
> sudo on this Vortex86DX3 CPU (that should ignore ENDBR32 but does not).
> 
> The TC has been discussing the issue with all involved parties and Marc, the
> sudo maintainer has agreed to accept advice, so we will just do that instead of
> overruling him.
> 
> I am calling for votes on this ballot:
> 
>   [A] The TC advises the sudo maintainer to update the sudo package in bookworm
>   such that on the i386 architecture, the `-fcf-protection` compiler flag is no
>   longer used.
> 
>   [F] Further discussion.

With 6 votes in favor and none against, option A was accepted by the
committee.

Marc, do you need anything else from us?

Christoph
------------=_1764859741-3798719-0--