void-linux / void-linux/void-packages
[RFC] explicitly allow setuid and setgid permissions in templates
@paper42 is already working on this.
Since May 30, 2022.
- Dominant language
- Shell
- Stars
- 3.4k
- Forks
- 2.8k
- Avg merge
- 2d 5h
- Merged PRs (30d)
- 299
Description
There are no checks for setuid and setgid permissions right now which could potentially be a security risk.
a) setugid=yes allows both setuid and setgid permissions in all files in the package
b) setugid="usr/bin/su" per-file rules
split setuid and setgid rules
c) setuid=yes; setgid=yes
d) setuid="usr/bin/su"; setgid=""
I will prepare a post-install hook when it's decided which method is preferred. I like c) the most, because there are some packages providing just setgid binaries without needing setuid (mlocate). b) and d) sound too verbose to me and if a package provides a set{u,g}id binary, the whole package is trusted.
I would also like to ask someone with access to the binary repository to post here which packages have set{u,g}id binaries.
cc @ericonr
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Assessment
This issue has not been assessed yet.