Bug#1113774: Debian Technical Committee: Bug#1113774: Disabling -fcf-protection in sudo for bookworm
Paul Tagliamonte <[email protected]> Mon, 5 Jan 2026 13:14:42 -0500
| Newsgroups | gmane.linux.debian.devel.ctte |
|---|---|
| Message-ID | <20260105181442.GA125705__18204.0954403178$1767637049$gmane$org@dc.cant.vote> |
--2qAmImSpd/WNYW9O
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable
On Sun, Jan 04, 2026 at 06:59:12AM +0100, Marc Haber wrote:
>Of course, people now demand that fix in Trixie as well (see=20
>#1004894). I expected this to happen. People are never satisfied with=20
>what they get. What does the ctte think about that?
My 2c here is that that bug self-resolved to a sensible place. I agree=20
with zeha's read on-thread.
Just to put it out there -- If someone can find a system which is:
1. An amd64 processor that meets our ISA baseline
2. Running a clean trixie amd64 install (not a i386 franken-install)
3. Which produces an invalid opcode error when running sudo:i386
I'd be interested in learning more about that CPU and what may be going=20
on with the host. I do not believe this happens on systems that meet our=20
baseline for trixie. I would be interested in being proven wrong.
That being said:
I suspect our calculus (this compiler flag change as discussed is a=20
security noop in the way we talked about) still applies to trixie. This=20
flag change seems to be to be "fine" to backport to trixie, technically.
*HOWEVER*, I'd be interested in use-cases for why people would install=20
sudo:i386 within trixie amd64 or later at all, and rational on why we=20
even ship it for a port that's no longer bootable.
My personal instinct as a package maintainer would be to RM sudo [i386],
although, perhaps I don't understand something important. I'd be=20
interested in learning what that misunderstanding is.
paultag
--=20
=E2=A2=80=E2=A3=B4=E2=A0=BE=E2=A0=BB=E2=A2=B6=E2=A3=A6=E2=A0=80 =
Paul Tagliamonte <paultag>
=E2=A3=BE=E2=A0=81=E2=A2=A0=E2=A0=92=E2=A0=80=E2=A3=BF=E2=A1=81 https:/=
/people.debian.org/~paultag | https://pault.ag/
=E2=A2=BF=E2=A1=84=E2=A0=98=E2=A0=B7=E2=A0=9A=E2=A0=8B Debian, th=
e universal operating system.
=E2=A0=88=E2=A0=B3=E2=A3=84=E2=A0=80=E2=A0=80 4096R / FEF2 EB20 16E6 A8=
56 B98C E820 2DCD 6B5D E858 ADF3
--2qAmImSpd/WNYW9O
Content-Type: application/pgp-signature; name="signature.asc"
-----BEGIN PGP SIGNATURE-----
iQIzBAABCgAdFiEEt+z0Ld/ZiscwHAYrEQGtWoE2mtcFAmlb/44ACgkQEQGtWoE2
mteyiA//YfhgNEQMhChZb1JrrzypWzlFkXO+t6m1UKoqe+KlP3wFzBfldT7FuPB/
mO24qwz4aAPnzHeAe0XwtLF43hMkAOqc/2+AvPATymo0yT7QzaDbY4QRUDdk/a4L
QOZri41y+c+A9peEBb1KiblfARQRSnnr+tbeTaJitOIZVFB2KI/UcgsgPUuB7TH5
VSL4GbT+wjfzDbqsjGVeETaTlaDi6xo5fEmgS1wNob0EmsBddct3gvKxdwrAL8XV
M4r1leMmHEnfxT1RiJJGgQ2YcPqC40hVHlV5/ye4zyeObG7Hke8AZcOBgsWFee9R
yq3B0Z+8wqbEYmvtvdr8by6H2RPUYggitgDeY5mElMPJw1bWZCkoq6G19IDHMqLS
+4AK9IfgOtNQCVPwVMz0YCDXIaTNUR79/CIG/CTGYTjccRRcq/tvwUuaYM2Fc5pG
4QdK5r/GpTusNl5HYS9XdECGef6SlkjIsL5qDVWxxZWLmXCMWTWbeArCOVqU2o/F
z80AeVcc5bsOjd+N71PyIUXJ+kWk8JDUvGg/bqOcxAx2xccTUKdvRqDGWbdPR04b
61Je3QWAdRqnD5EOC1VxdvU9vV5JaDOczJUeLwoAwhMi+O/67tCmz/AbLJ0rJnKl
TlzW53uUiYUKA4bQGS2pFZsOLhMLJN4j7vV9C4cYY2R7vHyvKoY=
=aGWg
-----END PGP SIGNATURE-----
--2qAmImSpd/WNYW9O--