Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.bugs.dist > #1270849 > unrolled thread

Bug#1113774: Disabling -fcf-protection in sudo for bookworm

Started byChristoph Berg <myon@debian.org>
First post2025-11-19 20:40 +0100
Last post2026-01-05 23:50 +0100
Articles 11 — 7 participants

Back to article view | Back to linux.debian.bugs.dist

This discussion starts older than the indexed window; earlier articles aren't shown. The article labeled Started by below is the oldest one visible, not the original post.


Contents

  Bug#1113774: Disabling -fcf-protection in sudo for bookworm Christoph Berg <myon@debian.org> - 2025-11-19 20:40 +0100
    Bug#1113774: Disabling -fcf-protection in sudo for bookworm Paul Tagliamonte <paultag@debian.org> - 2025-11-19 21:20 +0100
    Bug#1113774: Disabling -fcf-protection in sudo for bookworm Christoph Berg <myon@debian.org> - 2025-11-19 21:40 +0100
    Bug#1113774: Disabling -fcf-protection in sudo for bookworm Timo Röhling <roehling@debian.org> - 2025-11-20 11:00 +0100
    Bug#1113774: Disabling -fcf-protection in sudo for bookworm Matthew Vernon <matthew@debian.org> - 2025-11-20 12:10 +0100
    Bug#1113774: Disabling -fcf-protection in sudo for bookworm Stefano Rivera <stefanor@debian.org> - 2025-11-20 15:00 +0100
    Bug#1113774: Disabling -fcf-protection in sudo for bookworm Helmut Grohne <helmut@subdivi.de> - 2025-11-23 22:50 +0100
      Bug#1113774: Disabling -fcf-protection in sudo for bookworm Christoph Berg <myon@debian.org> - 2025-11-23 23:10 +0100
    Bug#1113774: Debian Technical Committee: Bug#1113774: Disabling -fcf-protection in sudo for bookworm Marc Haber <mh+debian-packages@zugschlus.de> - 2026-01-04 07:10 +0100
      Bug#1113774: Debian Technical Committee: Bug#1113774: Disabling -fcf-protection in sudo for bookworm Helmut Grohne <helmut@subdivi.de> - 2026-01-05 22:40 +0100
      Bug#1113774: Debian Technical Committee: Bug#1113774: Disabling -fcf-protection in sudo for bookworm Timo Röhling <roehling@debian.org> - 2026-01-05 23:50 +0100

#1270849 — Bug#1113774: Disabling -fcf-protection in sudo for bookworm

FromChristoph Berg <myon@debian.org>
Date2025-11-19 20:40 +0100
SubjectBug#1113774: Disabling -fcf-protection in sudo for bookworm
Message-ID<LSWc1-ecyM-1@gated-at.bofh.it>
In #1113774, Marcos Del Sol Vives is asking the committee about the compiler
flags used for sudo in bookworm on the i386 architecture. The sudo version
there is enabling `-fcf-protection` when supported by the compiler:

https://sources.debian.org/src/sudo/1.9.13p3-1%2Bdeb12u2/m4/hardening.m4#L108-L114

The problem is, that on his machine, a Vortex86DX3, the generated ENDBR
instructions, which live in an opcode region declared as NOPs in earlier
architecture specs, are not ignored, but raise exceptions and cause sudo to
abort.

There is a lot of evidence that Control-flow Enforcement Technology (CET or
cf-protection) is only meant to be enabled on 64-bit binaries and is
ineffective elsewhere:
* https://docs.kernel.org/next/x86/shstk.html
* https://lkml.org/lkml/2025/9/1/1704

One part of the thread was discussing the usefulness of this feature even in
64-bit environments (the kernel only half-supports it in userland) which has
led to https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1113864 being filed on
dpkg-dev, but this is not relevant to the TC question. In fact, dpkg-dev is
only emitting -fcf-protection on amd64 and not on i386. A large part of the
thread assumed the default bookworm compiler flags had that problem, but it's
actually upstream sudo adding -fcf-protection.

Around the time of the discussion, upstream sudo included a change that limits
-fcf-protection to x86_64: https://github.com/sudo-project/sudo/pull/468

The question if Vortex86DX3 is part of bookworm's i386 architecture baseline
was raised. In https://lists.debian.org/debian-devel/2023/10/msg00120.html Ben
Hutchings confirms that ENDBR32 should be ignored by i686-conformant
processors, and that i686 is required for bookworm. (He corrects himself in the
next mail saying this would apply to trixie only, but again corrects himself
saying this applies to bookworm indeed.) This seems to indicate that
Vortex86DX3 is not i686-conformant. The submitter claims the CPU is conformant,
citing https://psc.informatik.uni-jena.de/hw/p-pro-3.pdf page 417 as saying
ENDBR32 was "reserved".

https://www.debian.org/releases/bookworm/i386/release-notes/ch-information.en.html#i386-is-i686

Debian trixie bumps the compiler baseline for i386 such that this CPU is
definitely no longer supported so this issue is solely about bookworm.

The TL;DR summary of the problem is: in Debian bookworm, the sudo package is
using -fcf-protection on i386 (where it should be a no-op), but this breaks
sudo on this Vortex86DX3 CPU (that should ignore ENDBR32 but does not).

The TC has been discussing the issue with all involved parties and Marc, the
sudo maintainer has agreed to accept advice, so we will just do that instead of
overruling him.

I am calling for votes on this ballot:

  [A] The TC advises the sudo maintainer to update the sudo package in bookworm
  such that on the i386 architecture, the `-fcf-protection` compiler flag is no
  longer used.

  [F] Further discussion.

Christoph

[toc] | [next] | [standalone]


#1270856

FromPaul Tagliamonte <paultag@debian.org>
Date2025-11-19 21:20 +0100
Message-ID<LSWOJ-ed3G-1@gated-at.bofh.it>
In reply to#1270849

[Multipart message — attachments visible in raw view] — view raw

On Wed, Nov 19, 2025 at 08:31:28PM +0100, Christoph Berg wrote:
>I am calling for votes on this ballot:
>
>  [A] The TC advises the sudo maintainer to update the sudo package in bookworm
>  such that on the i386 architecture, the `-fcf-protection` compiler flag is no
>  longer used.
>
>  [F] Further discussion.

I'm incredibly grateful to patient explinations from Marcos; it took me 
a second to catch up, but I understand it now thanks to your 
explanations and refs.

This bug winds up with me feeling pretty good about Debian, all in all. 
Marc is doing an exceptional job maintaining sudo, and the thought that 
has gone into his cautious approach to changes from upstream is not lost
on me.

I don't see any technical reason why this isn't a safe and Debian 
policy-aligned change to those running sudo on i386.

In addition, upstream has accepted a similar patch.

Last note: At the end of the day, what we do with bookworm is ultimately 
up to the (old?)stable release managers -- bookworm (albeit the last 
full "i386" [read: i686] release), is still now oldstable. While it's 
not officially EOL until June 2026, there is still work to be done to 
socalize this change further in order to actually update bookworm.

Thank you both very much.

I vote A > F

-- 
   ⢀⣴⠾⠻⢶⣦⠀               Paul Tagliamonte <paultag>
   ⣾⠁⢠⠒⠀⣿⡁  https://people.debian.org/~paultag | https://pault.ag/
   ⢿⡄⠘⠷⠚⠋        Debian, the universal operating system.
   ⠈⠳⣄⠀⠀  4096R / FEF2 EB20 16E6 A856 B98C  E820 2DCD 6B5D E858 ADF3

[toc] | [prev] | [next] | [standalone]


#1270857

FromChristoph Berg <myon@debian.org>
Date2025-11-19 21:40 +0100
Message-ID<LSX86-edb0-9@gated-at.bofh.it>
In reply to#1270849

[Multipart message — attachments visible in raw view] — view raw

Re: To 1113774@bugs.debian.org
> I am calling for votes on this ballot:
> 
>   [A] The TC advises the sudo maintainer to update the sudo package in bookworm
>   such that on the i386 architecture, the `-fcf-protection` compiler flag is no
>   longer used.
> 
>   [F] Further discussion.

I vote A > F.

Christoph

[toc] | [prev] | [next] | [standalone]


#1270909

FromTimo Röhling <roehling@debian.org>
Date2025-11-20 11:00 +0100
Message-ID<LT9Ch-elLI-5@gated-at.bofh.it>
In reply to#1270849

[Multipart message — attachments visible in raw view] — view raw

Hi,

On Wed, 19 Nov 2025 20:31:28 +0100 Christoph Berg <myon@debian.org> 
wrote:
> I am calling for votes on this ballot:
> 
>   [A] The TC advises the sudo maintainer to update the sudo package in bookworm
>   such that on the i386 architecture, the `-fcf-protection` compiler flag is no
>   longer used.
> 
>   [F] Further discussion.

I vote A > F.


Cheers
Timo


-- 
⢀⣴⠾⠻⢶⣦⠀   ╭────────────────────────────────────────────────────╮
⣾⠁⢠⠒⠀⣿⡁   │ Timo Röhling                                       │
⢿⡄⠘⠷⠚⠋⠀   │ 9B03 EBB9 8300 DF97 C2B1  23BF CC8C 6BDD 1403 F4CA │
⠈⠳⣄⠀⠀⠀⠀   ╰────────────────────────────────────────────────────╯

[toc] | [prev] | [next] | [standalone]


#1270915

FromMatthew Vernon <matthew@debian.org>
Date2025-11-20 12:10 +0100
Message-ID<LTaI1-emHM-11@gated-at.bofh.it>
In reply to#1270849

[Multipart message — attachments visible in raw view] — view raw

Hi,

On Wed, 19 Nov 2025 19:31:28 +0000,
Christoph Berg wrote:
> I am calling for votes on this ballot:
>
>   [A] The TC advises the sudo maintainer to update the sudo package in bookworm
>   such that on the i386 architecture, the `-fcf-protection` compiler flag is no
>   longer used.
>
>   [F] Further discussion.

I vote:
A > F

Thanks,

Matthew

[toc] | [prev] | [next] | [standalone]


#1270923

FromStefano Rivera <stefanor@debian.org>
Date2025-11-20 15:00 +0100
Message-ID<LTdmx-eocV-3@gated-at.bofh.it>
In reply to#1270849

[Multipart message — attachments visible in raw view] — view raw

Hi Christoph (2025.11.19_20:31:28_+0100)
>I am calling for votes on this ballot:
>
>  [A] The TC advises the sudo maintainer to update the sudo package in bookworm
>  such that on the i386 architecture, the `-fcf-protection` compiler flag is no
>  longer used.
>
>  [F] Further discussion.

I vote:
  A > F

-- 
Stefano Rivera
   http://tumbleweed.org.za/
   +1 415 683 3272

[toc] | [prev] | [next] | [standalone]


#1271337

FromHelmut Grohne <helmut@subdivi.de>
Date2025-11-23 22:50 +0100
Message-ID<LUq81-feZL-29@gated-at.bofh.it>
In reply to#1270849

[Multipart message — attachments visible in raw view] — view raw

Hi Christoph,

On Wed, Nov 19, 2025 at 08:31:28PM +0100, Christoph Berg wrote:
> The TC has been discussing the issue with all involved parties and Marc, the
> sudo maintainer has agreed to accept advice, so we will just do that instead of
> overruling him.

Thank you for the summary. With the exception of the interaction with
Ben (which I appear to have missed), it accurately matches my
understanding of the matter at hand. A minor aspect missing in the
summary is that -fcf-protection is actually controlling two distinct
features with one flag, one of which poses the problem we've been
discussing. The other feature likewise does not apply to i386.
Therefore, this addition does not affect the conclusion.

> I am calling for votes on this ballot:
> 
>   [A] The TC advises the sudo maintainer to update the sudo package in bookworm
>   such that on the i386 architecture, the `-fcf-protection` compiler flag is no
>   longer used.
> 
>   [F] Further discussion.

I vote A > F.

Helmut

[toc] | [prev] | [next] | [standalone]


#1271352

FromChristoph Berg <myon@debian.org>
Date2025-11-23 23:10 +0100
Message-ID<LUqro-ffnx-7@gated-at.bofh.it>
In reply to#1271337
Re: Helmut Grohne
> A minor aspect missing in the
> summary is that -fcf-protection is actually controlling two distinct
> features with one flag, one of which poses the problem we've been
> discussing. The other feature likewise does not apply to i386.
> Therefore, this addition does not affect the conclusion.

Thanks, I should have mentioned that in the summary. I left it out
from the ballot because only half-disabling the feature would likely
not make the clean, "obviously correct" patch that Marc wanted.

Christoph

[toc] | [prev] | [next] | [standalone]


#1276991 — Bug#1113774: Debian Technical Committee: Bug#1113774: Disabling -fcf-protection in sudo for bookworm

FromMarc Haber <mh+debian-packages@zugschlus.de>
Date2026-01-04 07:10 +0100
SubjectBug#1113774: Debian Technical Committee: Bug#1113774: Disabling -fcf-protection in sudo for bookworm
Message-ID<M9ptn-7Vrw-1@gated-at.bofh.it>
In reply to#1270849
unarchive 1113774
thanks

On Thu, Dec 04, 2025 at 04:39:43PM +0100, Marc Haber wrote:
>I would also like information whether I could expect the binaries for 
>non-i386 architectures to be identical even after the patch was 
>applied.

They are. Thank you, reproducible builds. That was a huge help.

>I won't have time before christmas to dive into the technical 
>discussion as deeply as I would.

Of course, people now demand that fix in Trixie as well (see #1004894). 
I expected this to happen. People are never satisfied with what they 
get. What does the ctte think about that?

Greetings
Marc

-- 
-----------------------------------------------------------------------------
Marc Haber         | "I don't trust Computers. They | Mailadresse im Header
Leimen, Germany    |  lose things."    Winona Ryder | Fon: *49 6224 1600402
Nordisch by Nature |  How to make an American Quilt | Fax: *49 6224 1600421

[toc] | [prev] | [next] | [standalone]


#1277215 — Bug#1113774: Debian Technical Committee: Bug#1113774: Disabling -fcf-protection in sudo for bookworm

FromHelmut Grohne <helmut@subdivi.de>
Date2026-01-05 22:40 +0100
SubjectBug#1113774: Debian Technical Committee: Bug#1113774: Disabling -fcf-protection in sudo for bookworm
Message-ID<Ma0sV-8krc-17@gated-at.bofh.it>
In reply to#1276991
Hi Marc,

These are my own opinions and not a formal statement of the CTTE.

On Sun, Jan 04, 2026 at 06:59:12AM +0100, Marc Haber wrote:
> Of course, people now demand that fix in Trixie as well (see #1004894). I
> expected this to happen. People are never satisfied with what they get. What
> does the ctte think about that?

Our release notes have been very explicit about unsupporting i386. The
discussion seems to have reached a point where it is clear that Debian
does not support the configuration in question.

That said, making software work outside the specification that we
consider supported can be valuable. It then becomes a question of
trading costs (risks) and effort against benefit. A sudo update is not
free of charge.

You lowered the severity of the bug to minor and given the unsupported
configuration that feels appropriate to me. If the submitter is
providing an improvement (bearing part of the cost) and the cost of
including such an improvement is acceptable, then by all means do it.
What is acceptable is the interesting question here. Asking the release
team to review another stable update would exceed the cost in my opinion
(not considering your own effort here). In contrast, piggy-backing the
change onto an update of sudo for other reasons would seem ok-ish to me,
because the risks are now very well understood.

You may evaluate the costs differently than I do and reach the
conclusion that the update is not worth the effort (as you closed the
bug wontfix). Saying "no" is part of a maintainers duties and in this
instance I would have difficulties challenging your "no". Indeed, one
reason that made me recommend fixing bookworm was that it was the last
release to support i386 as a standalone architecture, so people would
likely end up being stuck on bookworm.

Helmut

[toc] | [prev] | [next] | [standalone]


#1277237 — Bug#1113774: Debian Technical Committee: Bug#1113774: Disabling -fcf-protection in sudo for bookworm

FromTimo Röhling <roehling@debian.org>
Date2026-01-05 23:50 +0100
SubjectBug#1113774: Debian Technical Committee: Bug#1113774: Disabling -fcf-protection in sudo for bookworm
Message-ID<Ma1yF-8lbW-3@gated-at.bofh.it>
In reply to#1276991

[Multipart message — attachments visible in raw view] — view raw

Hi Marc,

* Marc Haber <mh+debian-packages@zugschlus.de> [2026-01-04 06:59]:
>Of course, people now demand that fix in Trixie as well (see #1004894). 
>I expected this to happen. People are never satisfied with what they 
>get. What does the ctte think about that?
As far as I am concerned, you have final authority here. If you feel 
particularly generous, you can apply the fix, but I don't see the need 
if the only affected hardware does not satisfy the trixie baseline 
requirements anyway.


Cheers
Timo

-- 
⢀⣴⠾⠻⢶⣦⠀   ╭────────────────────────────────────────────────────╮
⣾⠁⢠⠒⠀⣿⡁   │ Timo Röhling                                       │
⢿⡄⠘⠷⠚⠋⠀   │ 9B03 EBB9 8300 DF97 C2B1  23BF CC8C 6BDD 1403 F4CA │
⠈⠳⣄⠀⠀⠀⠀   ╰────────────────────────────────────────────────────╯

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.bugs.dist


csiph-web