Bug#1113774: Debian Technical Committee: Bug#1113774: Disabling -fcf-protection in sudo for bookworm

Paul Tagliamonte <[email protected]> Mon, 5 Jan 2026 13:14:42 -0500
Newsgroups gmane.linux.debian.devel.ctte
Message-ID <20260105181442.GA125705__18204.0954403178$1767637049$gmane$org@dc.cant.vote>
--2qAmImSpd/WNYW9O
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

On Sun, Jan 04, 2026 at 06:59:12AM +0100, Marc Haber wrote:
>Of course, people now demand that fix in Trixie as well (see=20
>#1004894). I expected this to happen. People are never satisfied with=20
>what they get. What does the ctte think about that?

My 2c here is that that bug self-resolved to a sensible place. I agree=20
with zeha's read on-thread.

Just to put it out there -- If someone can find a system which is:

  1. An amd64 processor that meets our ISA baseline
  2. Running a clean trixie amd64 install (not a i386 franken-install)
  3. Which produces an invalid opcode error when running sudo:i386

I'd be interested in learning more about that CPU and what may be going=20
on with the host. I do not believe this happens on systems that meet our=20
baseline for trixie. I would be interested in being proven wrong.

That being said:

I suspect our calculus (this compiler flag change as discussed is a=20
security noop in the way we talked about) still applies to trixie. This=20
flag change seems to be to be "fine" to backport to trixie, technically.

*HOWEVER*, I'd be interested in use-cases for why people would install=20
sudo:i386 within trixie amd64 or later at all, and rational on why we=20
even ship it for a port that's no longer bootable.

My personal instinct as a package maintainer would be to RM sudo [i386],
although, perhaps I don't understand something important. I'd be=20
interested in learning what that misunderstanding is.

   paultag

--=20
   =E2=A2=80=E2=A3=B4=E2=A0=BE=E2=A0=BB=E2=A2=B6=E2=A3=A6=E2=A0=80         =
      Paul Tagliamonte <paultag>
   =E2=A3=BE=E2=A0=81=E2=A2=A0=E2=A0=92=E2=A0=80=E2=A3=BF=E2=A1=81  https:/=
/people.debian.org/~paultag | https://pault.ag/
   =E2=A2=BF=E2=A1=84=E2=A0=98=E2=A0=B7=E2=A0=9A=E2=A0=8B        Debian, th=
e universal operating system.
   =E2=A0=88=E2=A0=B3=E2=A3=84=E2=A0=80=E2=A0=80  4096R / FEF2 EB20 16E6 A8=
56 B98C  E820 2DCD 6B5D E858 ADF3

--2qAmImSpd/WNYW9O
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQIzBAABCgAdFiEEt+z0Ld/ZiscwHAYrEQGtWoE2mtcFAmlb/44ACgkQEQGtWoE2
mteyiA//YfhgNEQMhChZb1JrrzypWzlFkXO+t6m1UKoqe+KlP3wFzBfldT7FuPB/
mO24qwz4aAPnzHeAe0XwtLF43hMkAOqc/2+AvPATymo0yT7QzaDbY4QRUDdk/a4L
QOZri41y+c+A9peEBb1KiblfARQRSnnr+tbeTaJitOIZVFB2KI/UcgsgPUuB7TH5
VSL4GbT+wjfzDbqsjGVeETaTlaDi6xo5fEmgS1wNob0EmsBddct3gvKxdwrAL8XV
M4r1leMmHEnfxT1RiJJGgQ2YcPqC40hVHlV5/ye4zyeObG7Hke8AZcOBgsWFee9R
yq3B0Z+8wqbEYmvtvdr8by6H2RPUYggitgDeY5mElMPJw1bWZCkoq6G19IDHMqLS
+4AK9IfgOtNQCVPwVMz0YCDXIaTNUR79/CIG/CTGYTjccRRcq/tvwUuaYM2Fc5pG
4QdK5r/GpTusNl5HYS9XdECGef6SlkjIsL5qDVWxxZWLmXCMWTWbeArCOVqU2o/F
z80AeVcc5bsOjd+N71PyIUXJ+kWk8JDUvGg/bqOcxAx2xccTUKdvRqDGWbdPR04b
61Je3QWAdRqnD5EOC1VxdvU9vV5JaDOczJUeLwoAwhMi+O/67tCmz/AbLJ0rJnKl
TlzW53uUiYUKA4bQGS2pFZsOLhMLJN4j7vV9C4cYY2R7vHyvKoY=
=aGWg
-----END PGP SIGNATURE-----

--2qAmImSpd/WNYW9O--