Bug#1113774: Disabling -fcf-protection in sudo for bookworm

Christoph Berg <[email protected]> Fri, 5 Dec 2025 18:06:37 +0100
Newsgroups gmane.linux.debian.devel.ctte
Message-ID <aTMRHbuL_M9uk4S5__36910.5285777309$1764954566$gmane$org@msg.df7cb.de>
Re: James Addison
> Even so: does this mean that we should be careful about disabling
> fcf-protection=branch on a broader/default basis?

The question was entirely only about bookworm. In bookworm, none of
the fcf-protection bits are enabled by default. It was solely active
in sudo because upstream enabled it.

I believe the question of disabling fcf-protection is not relevant for
any other bookworm package. The "unstable" part of that question
should be discussed on -devel, not in this bug.

Christoph