Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.bugs.dist > #1270849 > unrolled thread
| Started by | Christoph Berg <myon@debian.org> |
|---|---|
| First post | 2025-11-19 20:40 +0100 |
| Last post | 2026-01-05 23:50 +0100 |
| Articles | 11 — 7 participants |
Back to article view | Back to linux.debian.bugs.dist
This discussion starts older than the indexed window; earlier articles aren't shown. The article labeled Started by
below is the oldest one visible, not the original post.
Bug#1113774: Disabling -fcf-protection in sudo for bookworm Christoph Berg <myon@debian.org> - 2025-11-19 20:40 +0100
Bug#1113774: Disabling -fcf-protection in sudo for bookworm Paul Tagliamonte <paultag@debian.org> - 2025-11-19 21:20 +0100
Bug#1113774: Disabling -fcf-protection in sudo for bookworm Christoph Berg <myon@debian.org> - 2025-11-19 21:40 +0100
Bug#1113774: Disabling -fcf-protection in sudo for bookworm Timo Röhling <roehling@debian.org> - 2025-11-20 11:00 +0100
Bug#1113774: Disabling -fcf-protection in sudo for bookworm Matthew Vernon <matthew@debian.org> - 2025-11-20 12:10 +0100
Bug#1113774: Disabling -fcf-protection in sudo for bookworm Stefano Rivera <stefanor@debian.org> - 2025-11-20 15:00 +0100
Bug#1113774: Disabling -fcf-protection in sudo for bookworm Helmut Grohne <helmut@subdivi.de> - 2025-11-23 22:50 +0100
Bug#1113774: Disabling -fcf-protection in sudo for bookworm Christoph Berg <myon@debian.org> - 2025-11-23 23:10 +0100
Bug#1113774: Debian Technical Committee: Bug#1113774: Disabling -fcf-protection in sudo for bookworm Marc Haber <mh+debian-packages@zugschlus.de> - 2026-01-04 07:10 +0100
Bug#1113774: Debian Technical Committee: Bug#1113774: Disabling -fcf-protection in sudo for bookworm Helmut Grohne <helmut@subdivi.de> - 2026-01-05 22:40 +0100
Bug#1113774: Debian Technical Committee: Bug#1113774: Disabling -fcf-protection in sudo for bookworm Timo Röhling <roehling@debian.org> - 2026-01-05 23:50 +0100
| From | Christoph Berg <myon@debian.org> |
|---|---|
| Date | 2025-11-19 20:40 +0100 |
| Subject | Bug#1113774: Disabling -fcf-protection in sudo for bookworm |
| Message-ID | <LSWc1-ecyM-1@gated-at.bofh.it> |
In #1113774, Marcos Del Sol Vives is asking the committee about the compiler flags used for sudo in bookworm on the i386 architecture. The sudo version there is enabling `-fcf-protection` when supported by the compiler: https://sources.debian.org/src/sudo/1.9.13p3-1%2Bdeb12u2/m4/hardening.m4#L108-L114 The problem is, that on his machine, a Vortex86DX3, the generated ENDBR instructions, which live in an opcode region declared as NOPs in earlier architecture specs, are not ignored, but raise exceptions and cause sudo to abort. There is a lot of evidence that Control-flow Enforcement Technology (CET or cf-protection) is only meant to be enabled on 64-bit binaries and is ineffective elsewhere: * https://docs.kernel.org/next/x86/shstk.html * https://lkml.org/lkml/2025/9/1/1704 One part of the thread was discussing the usefulness of this feature even in 64-bit environments (the kernel only half-supports it in userland) which has led to https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1113864 being filed on dpkg-dev, but this is not relevant to the TC question. In fact, dpkg-dev is only emitting -fcf-protection on amd64 and not on i386. A large part of the thread assumed the default bookworm compiler flags had that problem, but it's actually upstream sudo adding -fcf-protection. Around the time of the discussion, upstream sudo included a change that limits -fcf-protection to x86_64: https://github.com/sudo-project/sudo/pull/468 The question if Vortex86DX3 is part of bookworm's i386 architecture baseline was raised. In https://lists.debian.org/debian-devel/2023/10/msg00120.html Ben Hutchings confirms that ENDBR32 should be ignored by i686-conformant processors, and that i686 is required for bookworm. (He corrects himself in the next mail saying this would apply to trixie only, but again corrects himself saying this applies to bookworm indeed.) This seems to indicate that Vortex86DX3 is not i686-conformant. The submitter claims the CPU is conformant, citing https://psc.informatik.uni-jena.de/hw/p-pro-3.pdf page 417 as saying ENDBR32 was "reserved". https://www.debian.org/releases/bookworm/i386/release-notes/ch-information.en.html#i386-is-i686 Debian trixie bumps the compiler baseline for i386 such that this CPU is definitely no longer supported so this issue is solely about bookworm. The TL;DR summary of the problem is: in Debian bookworm, the sudo package is using -fcf-protection on i386 (where it should be a no-op), but this breaks sudo on this Vortex86DX3 CPU (that should ignore ENDBR32 but does not). The TC has been discussing the issue with all involved parties and Marc, the sudo maintainer has agreed to accept advice, so we will just do that instead of overruling him. I am calling for votes on this ballot: [A] The TC advises the sudo maintainer to update the sudo package in bookworm such that on the i386 architecture, the `-fcf-protection` compiler flag is no longer used. [F] Further discussion. Christoph
[toc] | [next] | [standalone]
| From | Paul Tagliamonte <paultag@debian.org> |
|---|---|
| Date | 2025-11-19 21:20 +0100 |
| Message-ID | <LSWOJ-ed3G-1@gated-at.bofh.it> |
| In reply to | #1270849 |
[Multipart message — attachments visible in raw view] — view raw
On Wed, Nov 19, 2025 at 08:31:28PM +0100, Christoph Berg wrote: >I am calling for votes on this ballot: > > [A] The TC advises the sudo maintainer to update the sudo package in bookworm > such that on the i386 architecture, the `-fcf-protection` compiler flag is no > longer used. > > [F] Further discussion. I'm incredibly grateful to patient explinations from Marcos; it took me a second to catch up, but I understand it now thanks to your explanations and refs. This bug winds up with me feeling pretty good about Debian, all in all. Marc is doing an exceptional job maintaining sudo, and the thought that has gone into his cautious approach to changes from upstream is not lost on me. I don't see any technical reason why this isn't a safe and Debian policy-aligned change to those running sudo on i386. In addition, upstream has accepted a similar patch. Last note: At the end of the day, what we do with bookworm is ultimately up to the (old?)stable release managers -- bookworm (albeit the last full "i386" [read: i686] release), is still now oldstable. While it's not officially EOL until June 2026, there is still work to be done to socalize this change further in order to actually update bookworm. Thank you both very much. I vote A > F -- ⢀⣴⠾⠻⢶⣦⠀ Paul Tagliamonte <paultag> ⣾⠁⢠⠒⠀⣿⡁ https://people.debian.org/~paultag | https://pault.ag/ ⢿⡄⠘⠷⠚⠋ Debian, the universal operating system. ⠈⠳⣄⠀⠀ 4096R / FEF2 EB20 16E6 A856 B98C E820 2DCD 6B5D E858 ADF3
[toc] | [prev] | [next] | [standalone]
| From | Christoph Berg <myon@debian.org> |
|---|---|
| Date | 2025-11-19 21:40 +0100 |
| Message-ID | <LSX86-edb0-9@gated-at.bofh.it> |
| In reply to | #1270849 |
[Multipart message — attachments visible in raw view] — view raw
Re: To 1113774@bugs.debian.org > I am calling for votes on this ballot: > > [A] The TC advises the sudo maintainer to update the sudo package in bookworm > such that on the i386 architecture, the `-fcf-protection` compiler flag is no > longer used. > > [F] Further discussion. I vote A > F. Christoph
[toc] | [prev] | [next] | [standalone]
| From | Timo Röhling <roehling@debian.org> |
|---|---|
| Date | 2025-11-20 11:00 +0100 |
| Message-ID | <LT9Ch-elLI-5@gated-at.bofh.it> |
| In reply to | #1270849 |
[Multipart message — attachments visible in raw view] — view raw
Hi, On Wed, 19 Nov 2025 20:31:28 +0100 Christoph Berg <myon@debian.org> wrote: > I am calling for votes on this ballot: > > [A] The TC advises the sudo maintainer to update the sudo package in bookworm > such that on the i386 architecture, the `-fcf-protection` compiler flag is no > longer used. > > [F] Further discussion. I vote A > F. Cheers Timo -- ⢀⣴⠾⠻⢶⣦⠀ ╭────────────────────────────────────────────────────╮ ⣾⠁⢠⠒⠀⣿⡁ │ Timo Röhling │ ⢿⡄⠘⠷⠚⠋⠀ │ 9B03 EBB9 8300 DF97 C2B1 23BF CC8C 6BDD 1403 F4CA │ ⠈⠳⣄⠀⠀⠀⠀ ╰────────────────────────────────────────────────────╯
[toc] | [prev] | [next] | [standalone]
| From | Matthew Vernon <matthew@debian.org> |
|---|---|
| Date | 2025-11-20 12:10 +0100 |
| Message-ID | <LTaI1-emHM-11@gated-at.bofh.it> |
| In reply to | #1270849 |
[Multipart message — attachments visible in raw view] — view raw
Hi, On Wed, 19 Nov 2025 19:31:28 +0000, Christoph Berg wrote: > I am calling for votes on this ballot: > > [A] The TC advises the sudo maintainer to update the sudo package in bookworm > such that on the i386 architecture, the `-fcf-protection` compiler flag is no > longer used. > > [F] Further discussion. I vote: A > F Thanks, Matthew
[toc] | [prev] | [next] | [standalone]
| From | Stefano Rivera <stefanor@debian.org> |
|---|---|
| Date | 2025-11-20 15:00 +0100 |
| Message-ID | <LTdmx-eocV-3@gated-at.bofh.it> |
| In reply to | #1270849 |
[Multipart message — attachments visible in raw view] — view raw
Hi Christoph (2025.11.19_20:31:28_+0100) >I am calling for votes on this ballot: > > [A] The TC advises the sudo maintainer to update the sudo package in bookworm > such that on the i386 architecture, the `-fcf-protection` compiler flag is no > longer used. > > [F] Further discussion. I vote: A > F -- Stefano Rivera http://tumbleweed.org.za/ +1 415 683 3272
[toc] | [prev] | [next] | [standalone]
| From | Helmut Grohne <helmut@subdivi.de> |
|---|---|
| Date | 2025-11-23 22:50 +0100 |
| Message-ID | <LUq81-feZL-29@gated-at.bofh.it> |
| In reply to | #1270849 |
[Multipart message — attachments visible in raw view] — view raw
Hi Christoph, On Wed, Nov 19, 2025 at 08:31:28PM +0100, Christoph Berg wrote: > The TC has been discussing the issue with all involved parties and Marc, the > sudo maintainer has agreed to accept advice, so we will just do that instead of > overruling him. Thank you for the summary. With the exception of the interaction with Ben (which I appear to have missed), it accurately matches my understanding of the matter at hand. A minor aspect missing in the summary is that -fcf-protection is actually controlling two distinct features with one flag, one of which poses the problem we've been discussing. The other feature likewise does not apply to i386. Therefore, this addition does not affect the conclusion. > I am calling for votes on this ballot: > > [A] The TC advises the sudo maintainer to update the sudo package in bookworm > such that on the i386 architecture, the `-fcf-protection` compiler flag is no > longer used. > > [F] Further discussion. I vote A > F. Helmut
[toc] | [prev] | [next] | [standalone]
| From | Christoph Berg <myon@debian.org> |
|---|---|
| Date | 2025-11-23 23:10 +0100 |
| Message-ID | <LUqro-ffnx-7@gated-at.bofh.it> |
| In reply to | #1271337 |
Re: Helmut Grohne > A minor aspect missing in the > summary is that -fcf-protection is actually controlling two distinct > features with one flag, one of which poses the problem we've been > discussing. The other feature likewise does not apply to i386. > Therefore, this addition does not affect the conclusion. Thanks, I should have mentioned that in the summary. I left it out from the ballot because only half-disabling the feature would likely not make the clean, "obviously correct" patch that Marc wanted. Christoph
[toc] | [prev] | [next] | [standalone]
| From | Marc Haber <mh+debian-packages@zugschlus.de> |
|---|---|
| Date | 2026-01-04 07:10 +0100 |
| Subject | Bug#1113774: Debian Technical Committee: Bug#1113774: Disabling -fcf-protection in sudo for bookworm |
| Message-ID | <M9ptn-7Vrw-1@gated-at.bofh.it> |
| In reply to | #1270849 |
unarchive 1113774 thanks On Thu, Dec 04, 2025 at 04:39:43PM +0100, Marc Haber wrote: >I would also like information whether I could expect the binaries for >non-i386 architectures to be identical even after the patch was >applied. They are. Thank you, reproducible builds. That was a huge help. >I won't have time before christmas to dive into the technical >discussion as deeply as I would. Of course, people now demand that fix in Trixie as well (see #1004894). I expected this to happen. People are never satisfied with what they get. What does the ctte think about that? Greetings Marc -- ----------------------------------------------------------------------------- Marc Haber | "I don't trust Computers. They | Mailadresse im Header Leimen, Germany | lose things." Winona Ryder | Fon: *49 6224 1600402 Nordisch by Nature | How to make an American Quilt | Fax: *49 6224 1600421
[toc] | [prev] | [next] | [standalone]
| From | Helmut Grohne <helmut@subdivi.de> |
|---|---|
| Date | 2026-01-05 22:40 +0100 |
| Subject | Bug#1113774: Debian Technical Committee: Bug#1113774: Disabling -fcf-protection in sudo for bookworm |
| Message-ID | <Ma0sV-8krc-17@gated-at.bofh.it> |
| In reply to | #1276991 |
Hi Marc, These are my own opinions and not a formal statement of the CTTE. On Sun, Jan 04, 2026 at 06:59:12AM +0100, Marc Haber wrote: > Of course, people now demand that fix in Trixie as well (see #1004894). I > expected this to happen. People are never satisfied with what they get. What > does the ctte think about that? Our release notes have been very explicit about unsupporting i386. The discussion seems to have reached a point where it is clear that Debian does not support the configuration in question. That said, making software work outside the specification that we consider supported can be valuable. It then becomes a question of trading costs (risks) and effort against benefit. A sudo update is not free of charge. You lowered the severity of the bug to minor and given the unsupported configuration that feels appropriate to me. If the submitter is providing an improvement (bearing part of the cost) and the cost of including such an improvement is acceptable, then by all means do it. What is acceptable is the interesting question here. Asking the release team to review another stable update would exceed the cost in my opinion (not considering your own effort here). In contrast, piggy-backing the change onto an update of sudo for other reasons would seem ok-ish to me, because the risks are now very well understood. You may evaluate the costs differently than I do and reach the conclusion that the update is not worth the effort (as you closed the bug wontfix). Saying "no" is part of a maintainers duties and in this instance I would have difficulties challenging your "no". Indeed, one reason that made me recommend fixing bookworm was that it was the last release to support i386 as a standalone architecture, so people would likely end up being stuck on bookworm. Helmut
[toc] | [prev] | [next] | [standalone]
| From | Timo Röhling <roehling@debian.org> |
|---|---|
| Date | 2026-01-05 23:50 +0100 |
| Subject | Bug#1113774: Debian Technical Committee: Bug#1113774: Disabling -fcf-protection in sudo for bookworm |
| Message-ID | <Ma1yF-8lbW-3@gated-at.bofh.it> |
| In reply to | #1276991 |
[Multipart message — attachments visible in raw view] — view raw
Hi Marc, * Marc Haber <mh+debian-packages@zugschlus.de> [2026-01-04 06:59]: >Of course, people now demand that fix in Trixie as well (see #1004894). >I expected this to happen. People are never satisfied with what they >get. What does the ctte think about that? As far as I am concerned, you have final authority here. If you feel particularly generous, you can apply the fix, but I don't see the need if the only affected hardware does not satisfy the trixie baseline requirements anyway. Cheers Timo -- ⢀⣴⠾⠻⢶⣦⠀ ╭────────────────────────────────────────────────────╮ ⣾⠁⢠⠒⠀⣿⡁ │ Timo Röhling │ ⢿⡄⠘⠷⠚⠋⠀ │ 9B03 EBB9 8300 DF97 C2B1 23BF CC8C 6BDD 1403 F4CA │ ⠈⠳⣄⠀⠀⠀⠀ ╰────────────────────────────────────────────────────╯
[toc] | [prev] | [standalone]
Back to top | Article view | linux.debian.bugs.dist
csiph-web