void-linux / void-linux/void-packages

[RFC] explicitly allow setuid and setgid permissions in templates

Open
#32,156 8 comments 1 reaction 1 assignee View on GitHub

@paper42 is already working on this.

Since May 30, 2022.

enhancement xbps-src
Dominant language
Shell
Stars
3.4k
Forks
2.8k
Avg merge
2d 5h
Merged PRs (30d)
299

Description

There are no checks for setuid and setgid permissions right now which could potentially be a security risk.

a) setugid=yes allows both setuid and setgid permissions in all files in the package
b) setugid="usr/bin/su" per-file rules

split setuid and setgid rules
c) setuid=yes; setgid=yes
d) setuid="usr/bin/su"; setgid=""

I will prepare a post-install hook when it's decided which method is preferred. I like c) the most, because there are some packages providing just setgid binaries without needing setuid (mlocate). b) and d) sound too verbose to me and if a package provides a set{u,g}id binary, the whole package is trusted.

I would also like to ask someone with access to the binary repository to post here which packages have set{u,g}id binaries.

cc @ericonr

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.