Re: Games Team policy on games being setgid

Antoine Le Gonidec <[email protected]> Sun, 28 Dec 2025 20:24:17 +0100
Newsgroups gmane.linux.debian.devel.games
Message-ID <[email protected]>
--V5OOTVwoEWgf8cEJ
Content-Type: text/plain; charset=utf-8
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

Le Sun, Dec 28, 2025 at 03:46:52PM +0000, Simon McVittie a =C3=A9crit :
> Suggested policy
> ----------------
>=20
> Perhaps something like this:
>=20
> Games should not be setuid or setcap.
>=20
> New games should not be setgid.
>=20
> Existing games should only be setgid games if not doing so would result in
> data loss or a serious loss of functionality. Ideally, they should migrate
> data into $HOME so that they do not need to continue to be setgid in every
> future Debian release.
>=20
> Games that are setgid games should read the data that they need to read, =
and
> then irreversibly drop privileges (for example setresgid() setting the
> effective and saved gids equal to the real gid), before calling into
> non-trivial dependency libraries.
>=20
> Games should not be setgid if their upstream developer does not
> intentionally support this.

I would have gone with something much simpler:

> Games should not be setuid, setgid or setcap.

Done. That=E2=80=99s the full policy.

There is no reasonable excuse for video games to run with elevated privileg=
es.

Shared saved games and high score tables on multi users system in particula=
r are not worth it,
I even doubt such multi users system used to run video games are a real thi=
ng in the first place.

--V5OOTVwoEWgf8cEJ
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----

iHUEABYKAB0WIQSUsdxM90hewW6X7Jhja3j5HOuA2AUCaVGD3QAKCRBja3j5HOuA
2JBBAP9wQoCHTv4irurikwlzojD4yuy6NpZTZ/wRBJliUMGasgD/Say4lYzfD/F9
Y6WrsZQ91G3Fyr7RdFH+2ALIO2VPhwA=
=86Wz
-----END PGP SIGNATURE-----

--V5OOTVwoEWgf8cEJ--