On 8/5/25 4:23 AM, Haelwenn (lanodan) Monnier wrote:

> I think it's a bit awkward to enable caps to disable suid,
> they are quite different and that means USE=caps can mean granting
> additional privileges instead of getting rid of suid.
> 
> And it's not just future, like I'm noticing those two from a quick
> grep caps profiles/use.local.desc
> 
> dev-util/bpftool:caps - Use sys-libs/libcap to enable unprivileged run
> support
> media-tv/kodi:caps - Use sys-libs/libcap to bind to privileged ports as
> non-root
> 
> Instead I think ones like htop should have IUSE=suid, like bubblewrap
> does for example.


I think this is a false comparison, because htop is not designed to be
setuid and doing so anyway was:

a) a tragic horror
b) accidental

It does not need and should not add a USE flag to enable security
vulnerabilities. Packages which "need" setuid and are designed for it
but can use caps instead don't need a USE flag either, because "neither
caps nor setuid" does not make sense.

bubblewrap can use either a kernel boot option (insecure_userns) or
setuid and the former cannot be modeled as a USE flag or build option at
all. That is why it gets its own USE flag.


-- 
Eli Schwartz

Attachment: OpenPGP_signature.asc
Description: OpenPGP digital signature

Reply via email to