Is it possible that libspice-client-glib-2.0-8 should merely Recommend: spice-client-glib-usb-acl-helper, rather than Depend: ing on it?
spice-client-glib-usb-acl-helper is one of the few setuid binaries on debian systems, and if it isn't installed, it seems like the attack surface would be reduced. I'd be a perfectly happy spice-client user *without* the ability to redirect USB devices to the VM i'm playing with, if it meant i didn't have to worry about yet another setuid binary on my system. --dkg
signature.asc
Description: PGP signature